Call Today! (800) 244-5409

News

ISO 13485: A Practical Guide for Medical Device Companies

If you manufacture, supply, or distribute medical devices, ISO 13485 is not optional in any market that matters. It is the quality management system standard regulators, notified bodies, and customers expect you to run your business on. And as of 2026, understanding it is more urgent than ever, because the U.S. Food and Drug Administration has rewritten its own device quality regulation to incorporate ISO 13485 by reference.

This guide walks through what ISO 13485 requirements actually ask of you, how the standard relates to the more familiar ISO 9001, where design controls and risk management fit, and who in the device supply chain needs to be certified. The goal is to give operations and quality leaders a clear, practical picture before you commit budget and calendar to an implementation.


What ISO 13485 Is — and How It Differs from ISO 9001

ISO 13485 is a stand-alone quality management system standard written specifically for organizations involved in the medical device life cycle. Although it shares DNA with ISO 9001 and follows a similar clause structure, it is not a sector supplement or an add-on. You certify to ISO 13485 in its own right, and a device company generally does not need to hold ISO 9001 as well.

The most important distinction is philosophical. ISO 9001 is built around risk-based thinking and gives organizations broad latitude to decide how much process and documentation their context requires. ISO 13485 deliberately narrows that flexibility. Where ISO 9001 lets you judge whether a documented procedure is necessary, ISO 13485 frequently tells you outright that one is required. Records, controls, and documented procedures are mandated across design, production, sterilization, complaint handling, and post-market activity.

That prescriptiveness reflects the stakes. A defective consumer product is a return; a defective medical device can injure a patient. So ISO 13485 trades ISO 9001’s adaptability for regulatory rigor. It expects traceability, formal document control, validated processes, and evidence that your system stays effective over the life of every product. If your team knows ISO 9001, the transition is real work rather than a simple relabeling.

If you are weighing the two standards for a mixed product portfolio, our ISO 9001 consulting and ISO 13485 consulting teams can help you decide what to certify and in what sequence.


Design Controls: Proving the Device Was Designed Right

For most device makers, design and development controls are the heart of ISO 13485 and the area auditors probe hardest. The standard requires a disciplined, documented flow from design inputs through outputs, verification, validation, transfer to production, and formal control of design changes.

In practice that means capturing user needs and regulatory requirements as measurable design inputs, translating them into design outputs that can be verified, and holding design reviews at planned stages with the right people in the room. Verification confirms the device meets its specifications. Validation confirms it meets the user’s actual needs under real conditions of use. Every one of these steps produces records, and those records must live in a coherent design history file that tells the full story of how the device came to be.

Design controls are also where ISO 13485 aligns most closely with FDA expectations, which makes getting them right a dual investment. Clean, well-structured design documentation satisfies your certification audit and puts you in far better shape for regulatory submissions and inspections. Weak documentation here is the single most common reason device QMS implementations stall.


Risk Management and ISO 14971

ISO 13485 requires you to apply risk management across the product realization process, but it does not spell out the method in detail. That is by design. The recognized companion standard, ISO 14971, defines how to identify hazards, estimate and evaluate risk, implement controls, and monitor residual risk throughout the device life cycle.

Treat the two standards as partners. ISO 13485 tells you that risk management must be woven into design, purchasing, production, and post-market surveillance. ISO 14971 gives you the framework to do it defensibly. Auditors will look for a living risk management file that traces each identified hazard to a control and to evidence that the control works, not a one-time document written to pass an audit and then shelved.

This is a genuine departure from ISO 9001’s lighter, more discretionary approach to risk. Under ISO 13485, risk management is a continuous, documented discipline that follows the product from concept through obsolescence, and post-market data is expected to feed back into your risk assessments.


Why FDA’s QMSR Now Incorporates ISO 13485

For decades, U.S. device manufacturers followed the FDA Quality System Regulation, known as the QSR, under 21 CFR Part 820. That regulation ran on a separate but parallel track to ISO 13485, forcing companies selling internationally to satisfy two overlapping systems.

The FDA has closed that gap. Under the Quality Management System Regulation (QMSR), the agency has amended Part 820 to incorporate ISO 13485 by reference, harmonizing U.S. requirements with the international standard. The final rule was published in early 2024 with a transition period, and it takes effect in 2026. When it does, conformance to ISO 13485 becomes the backbone of FDA quality expectations rather than a separate voluntary standard.

The practical takeaway is straightforward. A well-run ISO 13485 system is no longer just a passport to global markets; it increasingly maps to what the FDA itself now requires of device firms. Companies that build to ISO 13485 today are positioning themselves for the QMSR rather than facing a scramble later. If you sell into the U.S., treat ISO 13485 alignment as regulatory readiness, not merely a certificate.


Who Actually Needs ISO 13485

The standard reaches further up and down the supply chain than many companies assume. ISO 13485 applies to any organization involved in one or more stages of the medical device life cycle, which in practice includes:

  • Manufacturers — the most obvious case, covering firms that design, produce, and place finished devices on the market.
  • Component and material suppliers — organizations providing parts, subassemblies, sterilization, or contract manufacturing to device makers. Manufacturers increasingly require certified suppliers, so certification becomes a condition of doing business.
  • Distributors and importers — companies that store, handle, or move devices and must show they protect product integrity and maintain traceability.
  • Providers of associated services — including calibration, installation, and servicing organizations whose work affects device safety or performance.

If your customers are certified device manufacturers, the question is usually not whether you need ISO 13485 but when a customer will make it a purchase requirement. Getting ahead of that demand protects existing accounts and opens doors to new ones.


The EU MDR Context

Selling devices in Europe adds another layer. The EU Medical Device Regulation, or MDR, governs market access across the European Union and sets its own conformity assessment requirements. ISO 13485 is not the MDR, and certification to the standard does not by itself grant a CE mark.

That said, the two are deeply complementary. A quality management system conforming to ISO 13485 is the foundation most manufacturers use to demonstrate the QMS obligations the MDR imposes, and notified bodies will expect to see one. Think of ISO 13485 as necessary groundwork for EU market access rather than the whole staircase. If Europe is on your roadmap, build your ISO 13485 system with MDR expectations in mind so the two efforts reinforce each other instead of duplicating work.


Getting Implementation Right

An ISO 13485 implementation is more demanding than a typical ISO 9001 project, largely because of the mandatory documentation, design controls, and risk management the standard requires. A structured gap analysis at the outset shows exactly where your current practices fall short of ISO 13485 requirements, which is far cheaper than discovering those gaps during a registrar audit.

From there, the work is methodical: build or refine the QMS documentation, stand up compliant design controls, integrate ISO 14971 risk management, train your team, and run internal audits before the certification body arrives. At QRC we pair veteran ISO consultants with AI tooling that accelerates gap analysis, documentation drafting, and audit preparation — with our consultants accountable for every deliverable. You move faster without cutting the corners regulators care about. Explore how that works on our AI-powered ISO consulting page, and browse the full range of ISO consulting services if you support multiple standards.


Ready to map your path to ISO 13485 and QMSR readiness? Contact QRC or call (800) 244-5409 to talk through a gap analysis built for your device business.

AS9100 vs ISO 9001, AS9110 and AS9120: What Aerospace Suppliers Need to Know

If you supply parts, assemblies, or services to the aerospace and defense industry, sooner or later a customer will tell you that ISO 9001 alone is not enough. They want AS9100 — or, depending on what your business does to the product, AS9110 or AS9120. And if you have spent any time reading the two standards side by side, you have probably noticed something: they look almost identical for the first several pages, then AS9100 keeps going.

That is the whole story in one sentence. AS9100 is ISO 9001 with an aerospace layer bolted on top. Understanding exactly what that layer contains — and why it exists — is the difference between walking into your first registrar audit prepared and walking in hoping the auditor does not ask the wrong question. This article breaks down what AS9100 adds, how AS9100 compares with AS9110 and AS9120, who actually requires each one, and the realistic path from a general quality system to an aerospace-grade one.


The Short Version: AS9100 Contains ISO 9001

AS9100 is published by the SAE and maintained through the International Aerospace Quality Group (IAQG). It incorporates the full text of ISO 9001 verbatim, then adds requirements specific to aviation, space, and defense. When you read the standard, the aerospace additions are usually printed in a different format so you can see exactly where ISO 9001 ends and the aerospace content begins.

That means an AS9100-certified company is, by definition, also meeting every ISO 9001 requirement. The reverse is not true. A company certified to ISO 9001 has a solid quality management system, but it has not demonstrated the additional controls that aerospace customers consider non-negotiable — controls built up over decades of hard lessons about what happens when a single non-conforming part reaches a flying aircraft.

There is also a family of related standards worth knowing. AS9100 covers organizations that design and manufacture aviation, space, and defense products. AS9110 covers maintenance, repair, and overhaul (MRO) operations. AS9120 covers distributors and stockists — companies that buy, hold, and resell aerospace parts without manufacturing them. All three share the same ISO 9001 foundation and the same aerospace philosophy; they differ in which additional requirements apply to your role in the supply chain. Our AS9100, AS9110, and AS9120 implementation services cover all three.


AS9100 vs AS9110 vs AS9120: Which Applies to You

Suppliers comparing AS9100 vs AS9120 — or AS9100 vs AS9110 — are almost always asking one practical question: which certificate does my customer expect from a business like mine? The answer follows what your organization does to the product, not how big you are.

AS9100 applies if you design and/or manufacture aviation, space, and defense products. It is the broadest of the three and carries the full aerospace layer: configuration management, first article inspection, critical items and key characteristics, product safety.

AS9110 applies to maintenance, repair, and overhaul organizations. It keeps the ISO 9001 core and the aerospace philosophy, then adds the requirements that matter when you are returning an article to service rather than building it new — maintenance planning, human factors in maintenance error, technical data control, and airworthiness responsibilities.

AS9120 applies to distributors and stockists that buy, hold, split, and resell aerospace parts without manufacturing them. Its additions concentrate on the risks of a pass-through business: traceability back to the original manufacturer, control of records that travel with the part, counterfeit-part prevention, and correct handling, storage, and splitting of lots.

Because all three share the same ISO 9001 foundation, the comparison is less about which standard is harder and more about scope. Organizations that do more than one thing — a distributor that also performs light assembly, or a manufacturer with an in-house repair station — sometimes certify to more than one, or scope a single certificate carefully. If that is your situation, get the scope decided before you build the system, because rescoping after documentation is written is expensive.

QRC implements and maintains systems for all three: see AS9100, AS9110 & AS9120 consulting if you need the system built, or AS9100 training, including 16-hour internal auditor training and certification, if you need your own people able to run and audit it.


What AS9100 Adds That ISO 9001 Does Not Require

The aerospace layer is not a vague set of good intentions. It is a specific list of disciplines. These are the ones that most often catch suppliers off guard.

Risk Management

ISO 9001 asks you to think about risk in general terms — the well-known “risk-based thinking” language. AS9100 goes further and requires a defined, documented process for operational risk management: identifying risks in your products and processes, assigning them, mitigating them, and tracking them through the life of the program. Auditors expect to see evidence that risk is managed as an ongoing activity, not a box checked once during planning.

Configuration Management

This is one of the biggest additions and one of the most misunderstood. Configuration management means you can prove, at any point, exactly which revision of a design, drawing, or specification a given part was built to — and that changes were controlled, approved, and communicated. In an industry where a part might be manufactured years after it was designed and installed years after that, knowing the precise configuration is not paperwork for its own sake. It is traceability that can be reconstructed on demand.

Counterfeit-Part Prevention

AS9100 requires a documented process to prevent the use of counterfeit or suspect parts, particularly for purchased components and electronics. Counterfeit parts have caused real failures in defense and aerospace systems, so the standard expects controls around sourcing, verification, and handling of suspect material — a concern that ISO 9001 does not address at all.

First Article Inspection (FAI)

Before a production run, AS9100 requires a first article inspection: a complete, documented verification that the first manufactured part meets every drawing and specification requirement. The FAI is recorded on standardized forms (the AS9102 format) and becomes objective evidence that your process is capable of producing conforming parts before you build hundreds or thousands of them.

Special Requirements and Critical Items

AS9100 introduces defined terminology for critical items (features whose variation significantly affects safety, performance, or fit) and key characteristics (attributes that must be controlled because their variation affects the product). You are expected to identify these, flow them down to suppliers, and apply appropriate controls. This is where quality planning gets genuinely aerospace-specific.

Product Safety and Human Factors

Recent revisions of AS9100 added explicit requirements around product safety and awareness of human factors in non-conformances — recognizing that human error is a root cause worth managing directly rather than treating every defect as a purely mechanical problem.

The OASIS Database

This one is administrative but unavoidable. AS9100 certifications are registered in OASIS — the Online Aerospace Supplier Information System maintained by the IAQG. Your certification, your certification body, and your audit status are visible in OASIS to customers who want to verify you. Your registrar reports audit results there, and prime contractors routinely check it before awarding work. An ISO 9001 certificate lives in your filing cabinet; an AS9100 certificate lives in a database the whole industry can see.


Who Actually Requires AS9100

AS9100 is rarely something a company pursues purely for internal improvement. It is almost always driven by customer demand, and the demand flows downhill through the supply chain.

Prime contractors — the major airframe and engine manufacturers and their tier-one suppliers — require AS9100 of the companies they buy from. When a prime holds AS9100, the standard obligates them to flow aerospace quality requirements down to their own suppliers. So even if you are a small machine shop three tiers removed from the final aircraft, the requirement reaches you through your immediate customer.

The Department of Defense and its contractors frequently require AS9100 for aerospace and defense work, either by direct specification or through the prime contractors executing defense programs. If you are pursuing defense work, AS9100 often travels alongside other requirements — cybersecurity maturity chief among them. Suppliers heading in that direction should look at CMMC readiness in parallel, since the same customers tend to ask for both.

The practical test is simple: if your customers are in aviation, space, or defense, ask them directly what they require. Many suppliers discover they need AS9100 not because a regulation compels it, but because they cannot win or keep contracts without it. Certification becomes the price of admission to the aerospace supply chain.


The Path From ISO 9001 to AS9100

The good news for a company that already holds ISO 9001 is that you are not starting from zero. You have the foundation. The work is closing the gap between a general quality system and an aerospace one.

Start with a gap analysis. Map your existing ISO 9001 system against the AS9100 requirements and identify exactly which aerospace additions you are missing — risk management processes, configuration management, FAI procedures, counterfeit-part controls, and so on. A structured ISO gap analysis turns “we need AS9100” into a concrete, prioritized list of what to build.

Build the missing processes and documentation. Most of the effort is in the aerospace-specific disciplines above. This is where the documentation load is heaviest, and where AI-assisted drafting can genuinely accelerate the work without cutting corners. At QRC we use AI tooling to speed up gap analysis and generate first-draft procedures, while our veteran aerospace consultants stay accountable for every deliverable — because an auditor will hold a human accountable, and so do we. Proper documentation services keep the manual readable rather than bloated.

Implement, then verify with internal audits. New processes need to run long enough to produce records before your certification audit. Internal audits and a management review confirm the system is working as designed and surface problems while you still have time to fix them. If your team needs the skills, auditor training builds internal capability that pays off long after certification.

Choose an accredited registrar and complete the certification audit. AS9100 certification must come from a certification body accredited for the aerospace scheme, and the results are recorded in OASIS. Companies on our full-service program consistently pass their first registrar audit — a track record that matters most when a contract is riding on the outcome.

For companies already holding ISO 9001, the upgrade is typically faster than a first-time implementation because the management-system backbone is already in place. A full ISO 9001 implementation generally runs five to seven months; an AS9100 upgrade focuses that effort on the aerospace layer. If you are still building the ISO 9001 foundation itself, our ISO 9001 consulting and broader ISO consulting services cover the whole journey.


Making the Right Call

If you are weighing AS9100 vs ISO 9001, the decision usually is not really yours to make — your customers make it for you. What is in your control is how prepared you are when the requirement lands. Treat AS9100 as ISO 9001 plus a well-defined aerospace discipline, close the gap deliberately rather than scrambling, and the certification becomes a durable competitive advantage instead of a fire drill.

The suppliers who struggle are the ones who underestimate the aerospace layer — who assume their ISO 9001 system is “basically AS9100” and find out otherwise at the audit. The ones who succeed treat configuration management, risk, FAI, and counterfeit prevention as real capabilities worth building, because in aerospace, they are.

Ready to move from ISO 9001 to AS9100, or to certify from scratch? Contact QRC or call (800) 244-5409 to talk through your aerospace certification path with a consultant who has done it before.

Internal Audits vs Certification Audits: What’s the Difference and Why Both Matter

If your organization holds an ISO certificate, or is working toward one, two very different kinds of audit shape whether you keep it. One you run yourself. The other decides your certification. They are easy to confuse because both use the word “audit,” both check conformity against a standard, and both produce findings. But they answer different questions, involve different people, and carry very different consequences.

Read more

The ISO 9001 Certification Timeline: What Happens in Each Phase

The first question almost every quality manager asks us is the same one their CEO just asked them: how long does ISO 9001 take? The honest answer is five to seven months for most organizations that commit to the work. But that range hides a lot. Two companies of the same size can finish months apart depending on how clean their starting point is, how fast they make decisions, and how much of the documentation grind they try to carry alone.

This is a walkthrough of the actual arc — phase by phase — so you can see where the time goes, what you control, and what your registrar controls. It is a planning guide, not a sales page.


Phase 1: Gap Analysis (2-4 weeks)

Every credible ISO 9001 implementation starts here, and skipping it is the single most common way projects run long. A gap analysis compares what you already do against every clause of ISO 9001:2015 and produces a punch list of what is missing, what is close, and what is already compliant.

The good news for most companies: you are further along than you think. If you are already running a business that ships product and keeps customers, you have processes — they are just undocumented or informal. The gap analysis converts “we sort of do that” into a concrete scope of work.

What compresses it: a single knowledgeable point of contact, easy access to your existing procedures, and an assessor who knows your industry. AI-assisted review speeds this up materially — we use tooling to parse existing documents against the standard and flag gaps in hours instead of days, though a consultant still validates every finding. That is the whole premise of AI-powered ISO consulting: faster analysis, humans still accountable for the call.

What stretches it: multiple sites, a sprawling product line, or nobody internally who can answer “how do we actually do this today?”

Phase 2: Planning (1-2 weeks)

Short phase, high leverage. This is where the gap list becomes a project plan: who owns what, in what order, by when. You define the scope of your quality management system, name a management representative, and set the target date for your registrar audit.

Get this phase right and the rest of the project runs on rails. Rush it, and you discover in month four that nobody was ever assigned to write the calibration procedure.

What compresses it: visible executive sponsorship. When leadership signals the project matters, ownership gets accepted instead of dodged.

What stretches it: ambiguity about scope — especially deciding which sites, products, or divisions are in or out. Settle that now, not later.


Phase 3: Documentation (4-8 weeks)

This is the phase that scares people, and it is where do-it-yourself projects most often stall. ISO 9001 requires a defined set of documented information: a quality policy, objectives, and procedures covering your core processes. It does not require a three-ring binder the size of a phone book — that is a myth that outlived the 2008 version of the standard.

The goal is documentation that describes what you actually do, not aspirational fiction that falls apart the moment an auditor asks an operator about it. Documents that do not match reality are worse than no documents at all.

What compresses it: starting from proven templates instead of a blank page, and using documentation drafting support to produce first drafts fast. AI tooling is genuinely useful here — it can generate a tailored first draft of a procedure from your inputs in minutes, which your team then edits to fit how you truly operate. The draft is a starting point, never the final word.

What stretches it: review bottlenecks. If every procedure waits three weeks for one busy executive to approve it, documentation becomes the longest phase in the project. Distribute review authority.

Phase 4: Implementation & Records Generation (4-8 weeks)

Writing a procedure and living by it are different things. This phase is where the QMS goes from paper to practice. Your team follows the new procedures, and — critically — generates the records that prove it. Audit trails, corrective action logs, training records, management review minutes, supplier evaluations.

Here is the hard constraint most timelines underestimate: registrars want to see evidence that the system has been running for a period of time, typically two to three months of records, before they will certify. You cannot compress this by working harder. The system has to actually operate long enough to produce a track record.

What compresses it: rolling implementation clause-by-clause as documents are approved, rather than waiting for every procedure to be final before anyone starts using anything.

What stretches it: weak adoption. If people quietly revert to the old way, you reach audit day with a beautiful document set and no records to back it up. This is the phase where good employee training pays for itself.


Phase 5: Internal Audit & Management Review (2-3 weeks)

Before a registrar ever sets foot in your building, the standard requires you to audit yourself. A trained internal auditor checks every process against the standard and your own procedures, then logs findings and corrective actions. Management review follows: leadership formally reviews the QMS performance, objectives, and audit results.

Do not treat this as a formality. A rigorous internal audit is your dress rehearsal — it surfaces the nonconformities your registrar would otherwise find, while you still have time to fix them quietly. Clients we take through this properly are the ones who consistently pass their first registrar audit.

What compresses it: having internal auditors trained earlier in the project instead of scrambling at the end.

What stretches it: internal audits that go too easy and miss real problems, which just moves the pain to the registrar’s audit where it costs you.

Phase 6: Stage 1 & Stage 2 Registrar Audits (2-6 weeks apart)

The certification audit comes in two parts, and this phase belongs to your registrar’s calendar, not yours.

Stage 1 is a documentation and readiness review. The auditor confirms your QMS is in place and you are ready for the full assessment. They may flag gaps to close before Stage 2.

Stage 2 is the real thing — an on-site audit where the registrar tests whether your system works in practice, interviewing staff and sampling records. Clear it, and certification follows.

The gap between the two stages is usually a few weeks to a couple of months, driven mainly by registrar scheduling and how many findings you have to close. An experienced consultant helps you prepare for both and stands beside you during the audit itself.

What compresses it: booking your registrar early — good ones are scheduled out weeks in advance.

What stretches it: major nonconformities at Stage 2, which require formal corrective action and sometimes a follow-up visit before the certificate issues.


So, How Long Does ISO 9001 Really Take?

Add the phases and you land in that five-to-seven-month window. The single biggest variable is not company size — it is decision speed and how much of the documentation and audit-prep load you try to shoulder alone. A focused team with the right support finishes near five months. A team fitting the project into the margins of their day job drifts toward seven or beyond.

The phases are sequential for a reason, but the smart move is to prepare downstream work early — train auditors before you need them, book the registrar before documentation is done — so nothing waits on nothing.

Ready to map your own timeline? Talk to a QRC consultant about a gap analysis and a realistic schedule for your organization — contact us or call (800) 244-5409.

How Much Does ISO 9001 Certification Cost?

It is the first question almost every executive asks, and the honest answer frustrates people: it depends. Not because consultants are dodging the number, but because “ISO 9001 certification” is not one purchase. It is three separate costs that get lumped together, and the size of each one is driven by decisions you make about your own organization.

The good news is that once you understand what those three buckets are and what pushes each one up or down, you can forecast your total with real confidence—and avoid the expensive mistakes that turn a five-month project into an eighteen-month one. This is a breakdown of where the money actually goes, written for the person who has to justify the budget.


The three costs hiding inside “certification cost”

When someone quotes you a single figure for ISO 9001, be skeptical. A complete picture always has three distinct line items, and they are paid to three different places.

Registrar (certification body) audit fees. This is the only cost that buys you the actual certificate. An accredited, independent registrar audits your Quality Management System over two stages, issues the certificate if you pass, and returns for surveillance audits in years two and three before a full recertification in year three. You pay this no matter how you prepare. Registrar fees are priced largely on audit days, which scale with your headcount, number of sites, and the complexity of your scope. This fee is not negotiable in the way consulting is—it is set by the certification body’s day-rate and the size of your operation.

Consulting and implementation support. This is the cost of getting ready—the gap analysis, the documented processes, the internal audits, the management review, and the coaching that gets your team through the registrar audit on the first attempt. Unlike the registrar fee, this cost is highly variable, because it depends entirely on how much of the work you do yourself versus how much you hand off. It is also the bucket where the right partner saves you the most money downstream.

Internal labor. The cost everyone forgets. Your own people spend hours documenting processes, gathering records, training staff, and sitting in audits. This time is real money even though no invoice ever shows it, and on a DIY-heavy project it is frequently the largest of the three buckets. Underestimating it is the single most common budgeting error we see.


What makes the number go up

Two companies in the same industry can see very different totals. Here is what separates them.

Size and headcount. More employees means more audit days for the registrar and more people to train and bring into the system. A 30-person shop and a 300-person manufacturer are not in the same tier.

Number of sites. Multiple locations multiply audit time and coordination. A single-site operation is dramatically simpler—and cheaper—than a business with three plants and a distribution center, each of which the registrar may need to sample.

Scope and process complexity. A company with tightly regulated processes, design and development activities, or complex supply chains has more to document and more to audit than a straightforward distributor. The broader and more intricate your scope, the more hours every phase takes.

The state of your existing documentation. This is the wildcard. If you already run disciplined processes with records and work instructions, a gap analysis may reveal you are two-thirds of the way there. If you are starting from scattered tribal knowledge and nothing written down, the documentation workload—and therefore the cost—climbs sharply. A gap analysis is the cheapest money you can spend, because it converts “it depends” into a scoped, defensible estimate before you commit to anything larger.


Where do the general ranges land?

Public estimates for ISO 9001 vary widely, and any figure you see online should be treated as a loose industry ballpark rather than a quote. As a general frame, small organizations tend to land at the lower end of published ranges, while large multi-site manufacturers with complex scopes land considerably higher. Registrar fees, consulting support, and internal labor each move independently within that range depending on the drivers above.

We do not publish a single price here on purpose, because a number without your headcount, site count, and documentation state attached is meaningless—and a firm that quotes you a flat fee before understanding your operation is guessing. A short scoping conversation produces a far more accurate estimate than any published average.


How AI-assisted consulting lowers the consulting bucket

Of the three cost buckets, consulting hours are the one where the right approach makes the biggest difference—and where the industry has changed most in the last few years.

Historically, a huge share of consulting time went into the labor-intensive middle of a project: mapping your current processes against the standard, drafting the quality manual and dozens of procedures from a blank page, and assembling audit-preparation materials. That is exactly the work that AI-assisted consulting compresses. AI tooling accelerates gap analysis, generates first-draft documentation tailored to your processes rather than generic templates, and speeds audit preparation—so the same milestones are reached in fewer billable hours.

The distinction that matters: AI drafts, humans decide. Every deliverable is still reviewed, corrected, and owned by an experienced consultant who is accountable for it. You are not paying for a chatbot; you are paying for veteran judgment that spends its time on the parts that require judgment, while the mechanical drafting gets done faster. The net effect is a shorter timeline—a typical ISO 9001 implementation runs about five to seven months—and a smaller consulting invoice for the same first-pass result.


The hidden cost of the DIY and template shortcut

The cheapest-looking path is to buy a template document kit, fill in your company name, and self-certify readiness. It looks like it saves the entire consulting bucket. It rarely does.

Generic, template-only documentation is the classic false economy. If your quality manual could belong to any company, it describes a system your people do not actually follow—and auditors notice within the first hour. The failure modes are predictable and expensive:

  • A failed or delayed first audit. Major nonconformities push out your certificate, and the registrar charges for the follow-up visit to close them. You pay for the audit twice.
  • Rework. Documentation that does not match reality has to be rewritten, often under deadline pressure, frequently by bringing in the consultant you were trying to avoid.
  • Burned internal hours. Your team’s time spent chasing a template that was never going to pass is the most invisible loss of all—and it is time they were not spending on the business.

Organizations that prepare properly and pass their registrar audit on the first attempt almost always spend less in total than those who chase the lowest upfront number and then pay for rework, re-audits, and a delayed certificate. The goal is not the cheapest starting quote; it is the lowest total cost to a certificate you can actually keep through three years of surveillance audits.


Budgeting it honestly

If you want a number you can take to your leadership, do three things. Get a real gap analysis so the consulting and documentation scope is based on evidence, not a guess. Ask your registrar for a fee estimate based on your headcount and site count. And be honest about the internal hours your team will spend, because that bucket is real whether or not anyone invoices it.

Do that, and “how much does ISO 9001 cost” stops being a mystery and becomes a defensible forecast. Our full-service clients consistently pass their first registrar audit, which is the outcome that keeps total cost predictable—and that is the number worth optimizing for. Explore our full range of ISO consulting services to see where you fit.


Want a scoped estimate instead of a guess? Contact QRC or call (800) 244-5409 to talk through your headcount, sites, and documentation state—and get a realistic ISO 9001 budget you can stand behind.

What Is a Quality Management System? A Plain-English Guide for Executives

Ask ten people in your building what a quality management system is, and you may get ten different answers. The quality manager points to a shelf of binders. The plant supervisor points to the inspection station. The new hire points to a login screen nobody explained. None of them is entirely wrong, and all of them are missing the point.

A quality management system, or QMS, is not a document, a department, or a piece of software. It is the way your organization consistently delivers what it promises — captured clearly enough that the result does not depend on who happens to be in the room that day. This guide explains what a QMS actually is, what it is not, and how a standard like ISO 9001 turns a loose collection of good intentions into something you can run, measure, and prove.


What a Quality Management System Actually Is

At its simplest, a QMS is the set of processes, responsibilities, and controls an organization uses to meet customer requirements and improve over time. It answers a deceptively basic question: how do we make sure the thing we did well last quarter still gets done well next quarter, at scale, when the person who knew how to do it is on vacation?

Think of it less as a filing cabinet and more as the operating system your quality runs on. It defines who owns each process, how work moves from one hand to the next, what “good” looks like at each step, and what happens when something goes wrong. When it works, quality stops being heroic — the result of one talented individual catching problems — and becomes structural, built into how work flows.

That distinction matters to executives because heroics do not scale and do not survive turnover. A real QMS lets you grow headcount, add a shift, or open a second location without watching quality drift.


The Core Elements Every QMS Shares

Whatever industry you are in, a functioning quality management system is built from the same handful of building blocks. Understanding them helps you tell a real system from a decorative one.

Defined processes

Everything starts with processes — the repeatable sequences of steps that turn inputs into outputs. A QMS makes these explicit rather than tribal. Instead of “Maria knows how the returns work,” you have a defined process with clear inputs, owners, and hand-offs. This is the load-bearing element; documentation and audits only matter because they support the processes underneath.

Documentation that carries knowledge

Documentation exists to capture what people need to do the work correctly and consistently — procedures, work instructions, forms, and records. The goal is not volume. The best documentation is lean enough that people actually use it and detailed enough that a competent newcomer could follow it. If you want the deeper mechanics of getting this balance right, our overview of ISO documentation services walks through how to document without drowning.

Key performance indicators

You cannot manage what you do not measure. A QMS defines metrics — scrap rate, on-time delivery, customer complaints, first-pass yield — that tell you whether processes are actually performing. Good KPIs are tied to objectives leadership cares about, not vanity numbers collected because they are easy.

Internal audits

Audits are the system checking itself. Internal audits verify that what you wrote down is what you actually do, and that what you do is actually working. They surface gaps before a customer or a registrar does. Done as a genuine improvement tool rather than a box-tick, they are one of the highest-return activities in the whole system. Our audit services and auditor training exist precisely because most organizations under-invest here.

Management review

This is the element executives most often skip and most need. Management review is the recurring meeting where leadership looks at the KPIs, the audit findings, the customer feedback, and the open corrective actions, then decides what to change. It is where the QMS connects to the business. Without it, a quality system becomes a self-contained bureaucracy that runs parallel to how the company is actually managed — which is exactly how quality initiatives quietly die.


What a QMS Is Not

Here is where a lot of money gets wasted. A quality management system is not a binder of downloaded templates. Buy a “complete ISO 9001 document kit” online, fill in your company name, and you have a stack of paper that describes a business you do not run. It will pass no serious audit and prevent no real defect, because none of it reflects how work actually moves through your building.

A QMS is also not a one-time project you finish and shelve. It is a living system that decays without attention. And it is not the same thing as certification. Certification is a snapshot — an external body confirming your system meets a standard on the day they visit. The QMS is the thing that has to keep working the other 364 days a year. Plenty of organizations chase the certificate and neglect the system; they are the ones scrambling before every surveillance audit.

If a term in this space trips you up — from “nonconformity” to “corrective action” to “management representative” — our glossary of quality terms keeps the jargon in plain English.


How ISO 9001 Formalizes the System

You could build a quality management system entirely from scratch. Most organizations do not, because ISO 9001 already provides a proven, internationally recognized framework for exactly these elements. It is the world’s most widely used quality standard, and it exists so that you do not have to reinvent the structure of good management.

ISO 9001 organizes the pieces above into a coherent whole built on a few core ideas: a process approach, risk-based thinking, and continual improvement through the plan-do-check-act cycle. It requires you to define your processes, document what matters, set measurable objectives, audit yourself, and hold management reviews — the same fundamentals, now with a common language your customers and registrars recognize.

The same architecture underpins the sector standards built on top of ISO 9001, so the investment carries over as you grow: AS9100 for aerospace, IATF 16949 for automotive, and ISO 13485 for medical devices all share the QMS backbone and layer industry-specific requirements on top. The next revision, often referred to as ISO 9001:2026, is expected to sharpen the standard’s treatment of areas like climate considerations and technology, but the fundamentals of a well-run QMS are not expected to change.


The Business Case, Framed Honestly

A well-built QMS is not a cost center in disguise. Done right, it reduces waste and rework, shortens the time new employees take to become productive, makes customer and regulatory requirements traceable, and turns quality problems into data you can act on instead of arguments you keep having. For companies selling into aerospace, automotive, medical, or government supply chains, a certified QMS is frequently the price of admission.

That said, be realistic. A QMS will not fix a broken product strategy or a toxic culture, and a poorly implemented one adds paperwork without adding value. The returns come from building a system that reflects how you actually work — which is why the upfront gap analysis matters so much, and why leaning on AI-assisted tooling for the heavy documentation and audit-prep work can compress a typical implementation from a year-long slog to a focused five-to-seven-month effort, with people still accountable for every deliverable.


Not sure where your organization stands, or whether your current system would survive an audit? QRC has helped more than 1,000 organizations build quality systems that hold up. Contact us or call (800) 244-5409 to talk it through.

How to Choose an ISO Consultant: 8 Questions to Ask

Hiring an ISO consultant is one of those decisions that looks simple until you start comparing proposals. Two firms quote wildly different prices for what sounds like the same work. One promises certification in 90 days; another says six months. One sends a polished template package; another wants to spend a week walking your floor before writing a word.

The difference between a good consultant and a bad one rarely shows up in the sales pitch. It shows up eight months later, when your registrar auditor opens a manual that reads like it belongs to another company, or when your “certified” management system quietly falls apart because nobody in-house ever understood it.

This is a buyer’s guide, not a sales page. The eight questions below are the ones that actually separate consultants who will get you certified and leave you stronger from the ones who will sell you a binder. Ask all of them before you sign anything.


1. Have you implemented this exact standard in my industry?

“ISO experience” is not a monolith. ISO 9001 for a machine shop, ISO 13485 for a medical device manufacturer, AS9100 for an aerospace supplier, and ISO/IEC 27001 for a software company share a common backbone, but the risks, the documentation auditors expect, and the failure points are completely different.

A consultant who has run twenty ISO 9001 projects but has never touched ISO 13485 will learn your regulatory environment on your dime. Ask specifically: how many organizations like mine, implementing this specific standard, have you taken through certification? Vague answers about “decades in quality” are a warning sign. You want a number and a few examples.

If you operate under a sector scheme such as AS9100 or IATF 16949, this question matters even more. Those standards layer industry-specific requirements on top of ISO 9001, and a generalist will miss them.

2. What is your first-audit pass rate?

The whole point of hiring a consultant is to get certified on the first attempt. A failed certification audit, or a stage 2 audit that closes with a pile of major nonconformities, costs you re-audit fees, months of delay, and internal credibility.

Ask directly: of the clients you have guided through a full implementation, how many passed their initial registrar audit? A confident firm will answer without flinching. At QRC, clients who use the full-service implementation program consistently achieve certification on their first registrar audit, and that track record is exactly the kind of claim you should ask any consultant to back up with specifics.

Be reasonably skeptical of anyone who claims a literal 100% with no context. Ask what happens if you don’t pass, and get the answer in writing.

3. Who actually does the work: the person in the room, or a junior behind them?

Consulting firms sometimes win the contract with a seasoned expert and then hand delivery to a junior associate you never met in the sales meeting. The senior name on the proposal shows up for the kickoff call and disappears.

Ask who will be on-site or on your calls week to week, what their background is, and whether that person stays with you through certification. Continuity matters. An implementation is a relationship built over months, and swapping consultants midway forces you to re-explain your operation every time.

4. Do you write from templates, or do you build the system around how we actually work?

This is the single biggest red flag to watch for. Template mills sell the same quality manual to every client, change the logo, and call it a management system. The document set looks complete, but it describes a company that isn’t yours. Auditors spot the mismatch immediately, and worse, your team can’t follow procedures that don’t reflect reality.

A good consultant starts with a gap analysis: they look at what you already do, compare it to the standard, and build documentation around your real processes. Templates are a fine starting skeleton. They should never be the finished product. Ask to see a redacted example of a manual they produced for a company in your sector and judge how tailored it looks.

5. Who owns the documentation when the engagement ends?

You would be surprised how often this comes up too late. Some consultants keep your quality manual, procedures, and forms in their own proprietary system or make the “living” versions dependent on their continued involvement. When you try to leave, you discover you can’t easily take your own management system with you.

Insist on a clear answer: you own every document, in an editable format, with no strings attached. A legitimate consultant wants you self-sufficient. Ownership of your ISO documentation should never be a bargaining chip.

6. What happens after we’re certified?

Certification is the starting line, not the finish. ISO certificates run on a three-year cycle with annual surveillance audits, and your system has to keep breathing the whole time: internal audits, management reviews, corrective actions, and updates as your business changes.

Ask whether the consultant offers post-certification support and internal auditor training so your own team can carry the system forward. A consultant who is only interested in the initial implementation and vanishes at certification leaves you exposed at your first surveillance audit. The best engagements aim to make you independent while remaining available when you need a check-in.

7. How do you use AI, and where does a human stay accountable?

This is a newer question, and a fair one to ask in 2026. AI tooling can genuinely accelerate the mechanical parts of an ISO project: drafting first-pass documentation, cross-referencing clauses during a gap analysis, flagging inconsistencies before an audit, and monitoring compliance between reviews.

The right answer is that AI speeds up the tedious work while a veteran consultant reviews, tailors, and stands behind every deliverable. The wrong answer is either “we don’t use it at all” (you may be paying for slow manual work) or “AI writes your whole manual” (nobody accountable, and auditors will notice the generic output). QRC’s approach pairs experienced ISO consultants with AI tooling so the drafting moves faster, but a human expert owns the result. Ask any firm to be specific about where the machine helps and where a person signs off.

8. How do you price the work, and what isn’t included?

ISO consulting is priced in a few common ways: fixed project fee, monthly retainer, hourly, or per-deliverable. None is automatically better, but each hides different risks. Fixed-fee protects you from overruns but can tempt a consultant to cut corners. Hourly aligns effort but can balloon. Retainers are predictable but can drift on indefinitely.

What matters is knowing the total cost and what falls outside it. Ask what is not included: registrar fees (which you always pay separately to the certification body, never to the consultant), travel, extra revision rounds, training, or surveillance support. Get the scope in writing. A firm that gives you a clear, itemized answer respects your budget; one that stays vague is setting up a change order later.


Frequently Asked Questions

How much does an ISO consultant cost?

Costs vary widely by standard, company size, and how much of your system already exists. Small ISO 9001 implementations can run a few thousand dollars in consulting fees; larger or multi-site programs, or sector standards like AS9100 and ISO 13485, cost more. Always confirm that registrar (certification body) fees are separate from consulting fees, and ask for an itemized scope before comparing quotes.

How long does ISO 9001 certification take with a consultant?

A typical full ISO 9001 implementation runs about five to seven months from kickoff to certification audit, depending on your starting point, company size, and how quickly your team can dedicate time to the project. A good consultant will give you a realistic timeline after a gap analysis, not a number pulled from a sales script.

Can’t I just do ISO certification myself without a consultant?

You can, and some organizations do. The trade-off is time and risk: self-implementation usually takes longer, and first-audit failures are more common when nobody on the team has run a certification before. A consultant is worth it when the cost of delay, a failed audit, or an internal team that can’t spare the hours outweighs the fee.

What’s the biggest red flag when hiring an ISO consultant?

Generic, template-only documentation. If a consultant hands you a quality manual that could belong to any company and never invested time understanding how you actually operate, both your auditor and your own staff will struggle with it. Insist on a system built around your real processes.


QRC has helped more than 1,000 organizations implement ISO-compliant management systems since 1992, and every engagement is led by a veteran consultant who stays accountable for the result. If you’re weighing your options, learn more about our team or explore our full range of ISO consulting services, then call us with your questions before you sign with anyone.

Call (800) 244-5409
Local: (408) 371-9995
Contact Us

ISO 45001 vs OHSAS 18001: What Changed and Why It Still Matters

If your occupational health and safety management system still traces its DNA back to OHSAS 18001, it is time for a candid conversation. OHSAS 18001 was formally withdrawn in September 2021. The transition standard, ISO 45001, is now the only internationally recognized standard for occupational health and safety management, and any organization still operating an OHSAS-era system is working from a framework that no longer exists in the eyes of registrars, customers, and regulators.

The difference between ISO 45001 and OHSAS 18001 is more than a change of name and number. ISO 45001 rebuilt the standard on a modern structure, elevated the role of leadership, made worker participation a formal requirement, and shifted the entire mindset from reacting to hazards toward proactively managing risk. This article walks through what actually changed, why those changes matter, and what companies still running legacy safety systems should do next.


The short history: how OHSAS 18001 gave way to ISO 45001

OHSAS 18001 was first published in 1999 and revised in 2007. For nearly two decades it was the default benchmark for occupational health and safety management, but it was never a true ISO standard. It was developed by a consortium of national standards bodies and certification organizations to fill a gap that ISO had not yet addressed.

ISO 45001 was published in March 2018 as the first genuine ISO standard for occupational health and safety. Organizations certified to OHSAS 18001 were given a migration window to transition. That window closed in September 2021, when OHSAS 18001 was officially withdrawn. Certificates issued against it are no longer valid, and accredited registrars no longer audit against it.

In practical terms, an OHSAS 18001 certificate today carries no accredited standing. If your safety system was built around that standard and has not been updated, you are running a management system that the certification world has retired.


Annex SL: the structural change under the hood

The most fundamental difference between ISO 45001 and OHSAS 18001 is invisible on the surface but shapes everything above it. ISO 45001 is built on Annex SL, the common high-level structure that ISO now uses across its major management system standards, including ISO 9001 for quality and ISO 14001 for environmental management.

Annex SL organizes every standard around the same ten clauses: context of the organization, leadership, planning, support, operation, performance evaluation, and improvement, among others. OHSAS 18001 used its own older structure that did not align with these standards.

Why does this matter? Because most organizations do not run a single management system in isolation. A manufacturer might hold ISO 9001, ISO 14001, and ISO 45001 at the same time. Under the shared Annex SL structure, those systems can be integrated into one coherent framework rather than three disconnected sets of binders. Common clauses mean common processes for document control, internal audits, management review, and corrective action. That integration reduces duplication, lowers the cost of maintaining certification, and makes audits considerably less painful. If you already run an ISO 9001 quality system, aligning safety under the same structure is far easier than it was under OHSAS 18001.


Leadership: safety moves into the boardroom

OHSAS 18001 allowed organizations to delegate safety to a management representative, often a single safety officer who owned the system and answered for it. ISO 45001 removed that escape hatch.

Under ISO 45001, top management is explicitly accountable for the effectiveness of the occupational health and safety management system. Leadership must demonstrate commitment, integrate safety requirements into core business processes, provide the resources the system needs, and take an active role in directing and supporting it. Safety is no longer a compliance function parked in a corner of the org chart. It is a leadership responsibility woven into how the business is run.

This shift reflects a hard-won lesson from decades of workplace incidents: safety cultures succeed or fail based on what leadership visibly prioritizes. When executives own safety outcomes, the rest of the organization follows. When safety is delegated and forgotten, gaps appear.


Worker participation: the people doing the work get a formal voice

One of the most significant additions in ISO 45001 is the requirement for genuine worker participation and consultation. OHSAS 18001 touched on consultation, but ISO 45001 makes it a structural requirement rather than an afterthought.

The reasoning is straightforward. The people performing a task usually understand its hazards better than anyone reviewing it from a desk. ISO 45001 requires organizations to consult workers when identifying hazards, assessing risks, and determining controls, and to actively remove barriers that discourage them from participating, including fear of reprisal, language differences, and lack of time.

For non-managerial workers in particular, the standard calls for meaningful involvement in decisions that affect their safety. This is not a box to tick. Auditors will look for evidence that workers genuinely contribute to the system and that their input shapes real decisions.


Risk versus hazard: a shift in mindset

Perhaps the deepest conceptual change is how ISO 45001 frames the goal of the system. OHSAS 18001 was largely hazard-focused and reactive. It concentrated on identifying hazards and controlling them, often after an incident had already revealed the gap.

ISO 45001 is risk-based and proactive. It asks organizations to think in terms of both risks and opportunities, and to understand the broader context in which the organization operates before deciding how to act. That means considering the needs and expectations of workers and other interested parties, anticipating how changes in the business could introduce new risks, and building prevention into planning rather than bolting controls on afterward.

This risk-based thinking mirrors the approach ISO 9001 introduced for quality management. Instead of documenting a fixed set of procedures and hoping they cover every scenario, the organization continually evaluates where things could go wrong and directs its attention accordingly. The result is a safety system that adapts as the business changes rather than one that only responds after something has already gone wrong.


A side-by-side summary

  • Status: OHSAS 18001 was withdrawn in September 2021. ISO 45001 is the only recognized international standard for occupational health and safety.
  • Structure: OHSAS 18001 used its own older format. ISO 45001 uses the Annex SL high-level structure shared with ISO 9001 and ISO 14001, enabling integrated management systems.
  • Leadership: OHSAS 18001 permitted delegation to a management representative. ISO 45001 holds top management directly accountable.
  • Worker involvement: OHSAS 18001 mentioned consultation. ISO 45001 requires formal worker participation and the removal of barriers to it.
  • Orientation: OHSAS 18001 was hazard-focused and reactive. ISO 45001 is risk-based, proactive, and context-aware.

What companies on legacy OHSAS-style systems should do now

If your organization never formally migrated to ISO 45001, or if your safety system still looks and feels like an OHSAS 18001 program, the practical path forward is clear.

Start with an honest gap analysis. Compare your current safety documentation and practices against the requirements of ISO 45001, clause by clause. In most legacy systems, the biggest gaps show up in the newer requirements: understanding organizational context, demonstrating active leadership involvement, documenting worker consultation, and applying risk-based thinking rather than a static hazard register.

From there, the work usually falls into a few areas. Leadership needs to be brought into the system in a visible, documented way. Worker participation processes need to be built or formalized. Risk and opportunity assessment needs to replace or supplement the older hazard-only approach. And if you already hold ISO 9001 or ISO 14001, this is the moment to integrate safety into a single management system under the shared Annex SL structure rather than maintaining it separately.

None of this requires starting from scratch. A well-run OHSAS 18001 system already contains much of what ISO 45001 asks for. The migration is largely a matter of restructuring existing content, closing specific gaps, and demonstrating the leadership and worker involvement the newer standard expects. Organizations that approach it methodically, ideally with a gap analysis up front, typically find the transition far more manageable than they feared.

The bottom line is that OHSAS 18001 is gone, and the reasons it was replaced still matter. ISO 45001 exists because the older, reactive, delegated approach to safety left too many gaps. Moving to it is not just a certification formality. It is an opportunity to build a safety system that leadership owns, that workers help shape, and that anticipates risk instead of merely responding to harm.

QRC’s ISO 45001 consulting team helps organizations migrate legacy safety systems, close the gaps that matter, and integrate occupational health and safety with existing ISO 9001 and ISO 14001 systems. To see where your current system stands, a structured gap analysis is the right first step. Call (800) 244-5409 or contact us to talk it through.