Silicon Valley’s Leading ISO 9001 Consultants: 30+ Years of Audit-Ready Expertise
30+ years of practical implementation, auditing, and training expertise.
Quality Resource Center (QRC) is a team of ISO 9001 consultants based in San Jose, California, with over 35 years of experience helping organizations achieve certification, improve operational performance, and reduce business risk.
Since the early 1990s, QRC has supported global clients across regulated and high-tech industries with practical, audit-ready management systems—not generic templates.
Trusted ISO 9001 Consultants Since 1992
QRC provides end-to-end ISO consulting, training, implementation, and auditing services for organizations pursuing certification or strengthening existing management systems. Our consultants work alongside leadership teams to implement systems that meet certification requirements while supporting efficiency, scalability, and long-term performance. Most engagements begin with ISO 9001 consulting services, the quality management standard behind most first-time certifications, and expand from there into aerospace, medical device, environmental, automotive, or information security requirements.
- ISO consulting and implementation
- Internal audits and readiness assessments
- ISO internal auditor training and certification
- Management and executive training
- Ongoing system maintenance and improvement support
Whether you require turnkey ISO consulting, targeted audit support, or internal auditor training, QRC delivers structured, proven solutions aligned with certification and business objectives.
Why Organizations Choose QRC
- Over three decades of ISO consulting experience
- Silicon Valley–based with nationwide reach
- Registrar-aware, audit-ready methodologies
- Minimal disruption to daily operations
- Practical systems built for real-world use
Schedule Your Complimentary Consultation
ISO Standards We Support
Quality & Aerospace
- ISO 9001 Quality Management Systems
- AS9100 / AS9110 / AS9120 Aerospace Quality
- IATF 16949 Automotive Quality
Medical Devices & Data Security
Environmental, Safety & Sustainability
- ISO 14001 Environmental Management
- ISO 45001 Occupational Health & Safety
- R2, RIOS & e-Stewards Recycling Standards
Specialized Support
- ISO 9001:2026 Transition Support
- ISO Gap Analysis
- ISO Documentation Services
- ISO Consultants in California
Three Decades of Client Results
Quality Resource Center has delivered elite client services for more than three decades, with more than 1,000 satisfied customers across a wide range of businesses and markets—from Silicon Valley manufacturers and aerospace suppliers to medical device and electronics recycling companies.
Our clients stay with us because our systems pass audits and keep working afterward. See the client logos and program examples in the sidebar, or ask us for references in your industry during your consultation.
The AI-Powered QRC Advantage
QRC pairs 35 years of hands-on auditing experience with AI-assisted documentation, gap analysis, and readiness review—so your management system gets built faster, with fewer internal hours spent writing procedures, and without the boilerplate that registrars flag.
Learn how AI-powered ISO consulting works
Schedule Your Complimentary Consultation
QRC Video InsightsFor the latest insights, guidance, and developments in ISO standards and management systems, visit the Quality Resource Center YouTube channel.
QRC News & Insights
ISO 9001:2015 Transitions – Embracing the Challenge and Lessons Learned So Far
Editor’s note (2026): this article was written during the transition from ISO 9001:2008 to ISO 9001:2015 and reflects the standard as it stood then. ISO 9001:2015 is the edition in force today, with ISO 9001:2026 in development. For current requirements and transition planning see our ISO 9001 consulting services.
Quality Resource Center proudly announces the successful completion of our 100th ISO 9001:2015 project. During that time, we have learned a lot…
It’s estimated that less than 25 percent of the more than one million organizations certified globally have made the transition to ISO 9001:2015 (as of mid-2017). The September 2018 deadline is approaching and your quality management system (QMS) isn’t going to transition itself. But there is so much to consider; Where to begin? How do you start? What happens next? This paper will assist you in answering those questions.
As with any successful project, start by defining your objectives and create a plan to achieve them. The main objective is to identify the additional as well as modified requirements within the standard and then demonstrate compliance to them during your organization’s transition audit.
But how? What does that involve? These steps can be invaluable in your successful transition to ISO 9001:2015.
Step 1: Get 39,000 Foot View
The fact that your Organization is transitioning means you are already working with an accredited Certification Body (CB), or Registrar. It is important to note that they too had to develop a plan, vetted by their accreditation body, to facilitate the transition. In other words, your Registrar will may have their own analysis for the transition. So, talk to your registrar. Better yet, contact Quality Resource Center, the industry’s oldest and most successful ISO 9001 consulting firm, with over 25 years of operation, and let us talk to them.
This type of guidance will give you valuable information on issues and challenges that may affect your organization’s transition:
• Deadlines – No later than Sept. 14, 2018, however it may be earlier based on your CB’s policies.
• Audits – It might be possible to have your transition conducted as part of a regularly scheduled surveillance or recertification. Some CB’s may offer separate standalone transition audits. In either case, determine what this audit will involve and how it will be conducted. Additional time may be added to address the changes, they may require additional preparation, and it will cover specific new elements of the new standard. Having your ISO 9001:2015 Internal Audits and Management Review conducted by Quality Resource Center can provide great value; having the industry’s premiere Audit teams prepare you for your Registrar audits can identify embarrassing and painful findings at the internal level and guard against ugly exposure and the consequences of same at your surveillance or re-certification audits. Studies show that outsourcing these activities to Quality Resource Center can result in as much as 85% reductions in time and cost, and greatly enhance your chances for a trouble free Registration audit process.
• Existing Certifications – You will want to maintain your existing ISO 9001:2008 certification until your organization has successfully completed the transition— but what will that entail? When does your current registration expire? How can you best achieve a seamless transition?
• Get Trained by Professionals – Gain a working knowledge of the standard. Your CB will give you a glimpse of what to expect in the new standard (and what they might expect from you), from the new clause structure to the new requirements. Quality Resource Center offers invaluable expertise in this area. If you plan on doing your own Audits, they will need training and certification. Quality Resource Center offers superior training and certification services.
Once you have an outline of the project and potential impacts, begin to fill in your plan. Target the audit date at which you wish to have your transition, then backfill the dates from there to develop a roadmap. Be sure to communicate with your CB to align expectations and availability for your transition audit, and make sure your target date works within the deadlines, gives you enough time to address any potential non-conformances, doesn’t risk any lapse of coverage, etc.
Finally, work on how you’ll address the new structure; start thinking about some of the major changes such as risk and context. Prioritize, prioritize, and, finally, prioritize. . Communicate the agreed upon schedule and plan to your organization, and ask for feedback.
Best advice is to have Quality Resource Center prepare your plan, and commit it to paper with a professional Gantt chart.
Step 2: Do Your Homework – Study the Standard
Read and comprehend the standard. You cannot address requirements you haven’t even read. It’s not a lengthy;
Get the companion ISO 9000 document, it provides guidance on terms and fundamental concepts used in the new standard.
The standard can also be a bit vague, however; that’s again where you should consult with a Quality Resource Center professional. QRC can provide expert knowledge regarding topics like the context of the organization, leadership, risks and opportunities, organizational knowledge, and other critical areas and changes pertinent for transition, and in many cases offer interpretive guidance on the expected outcomes related to these changes.
GAP analysis can cut through the interpretation of minor wording changes and get to the changes that need to be addressed within your organization’s QMS. Quality Resource offers a very cost effective GAP analysis that can identify all areas of concern.
Once the focal points have been identified, utilize the standard to determine the actual requirement and key deliverables. You may find existing processes that address these elements. Utilize them wherever possible. The key to successful deployment of ISO 9001:2015 is alignment with your actual business activities.
Regarding documentation (or documented information) – It is important to note that while the new standard does not require any specific documented procedures. However, documented information in the form of procedures, forms, records, etc. are beneficial for any new or changed requirements. Having objective evidence to review during a transition audit will avoid unnecessary back and forth.
Step 3: Implement, Operate, and Review
Once the key elements of the new standard are identified and the plan to address them has been developed, the required changes and improvements to your QMS need to be deployed. Take time to communicate the changes to the organization to ensure their understanding. Next, the new and updated QMS needs review and correction, similar to the preparation for your initial registrar audits. Identify and work with the appropriate players, especially process owners, throughout the organization to verify and validate changes, and take the time to review everything again before your transition audit. A month or two prior to your scheduled transition audit, conduct your own internal audit to the new requirements, then follow that up with a management review to go over the results and determine the effectiveness of the updated QMS. Again, a good rule of thumb here would be to give enough time to react to any internal audit findings or management review actions items prior to your transition audit. Quality Resource Center can offer valuable assistance in this endeavor.
Registrars have requirements for internal preparations and reviews such as this, and some may even have tools to use. Consider the checklist transition tools they may have developed for your use; look for any transition checklists, transition audit plans, or transition requirements to leverage in your own internal audits. Quality Resource Center offers a valuable tool set that is extremely cost-effective.
Look for any lessons learned that might help you avoid pitfalls and/or showstoppers.
Here are a few for consideration:
• Have Quality Resource Center convert your existing documentation and upgrade to fit the new standard. Renumbering your documents is not required, but it is a very good idea, especially for your Quality Manual and your QOP’s. Don’t unilaterally eliminate all your documentation, nor your management representative, nor your quality manual! While you have the flexibility to do so (either partly or completely) if it fits the context of your organization, remember that just because the new standard is silent on such things doesn’t prohibit you from keeping such approaches if they work for your organization. It will aid great in your Internal Audits, Management Review, Improvements, and Registrar Audits.
New areas to consider include –
• Context of the Organization (sub-clause 4.1) – This must be addressed within management review as a minimum. Additional consideration may be adding support to this in your quality manual you do retain, or other planning components of your QMS. In short, the context of your organization should drive the approach your QMS (and all applicable processes) takes.
• Leadership (sub-clause 5.1) – Expect auditors to ask for time with top management, see their active involvement in the QMS, and the applicable processes (e.g. objectives, resources, and management reviews).
• Organizational Knowledge (sub-clause 7.1.6) – While this is a new requirement it cannot be overlooked. Auditors will expect to see this addressed in some fashion, and it is an ever-evolving process. Focus on getting it up and running without being overwhelmed by the potential; create a process that can be expanded and improved upon in the future.
• Risks and Opportunities (sub-clause 6.1) – This is one of most important areas to consider getting professional training and help with. Risk is an intricate part of the new standard, and there are a variety of tools available. Quality Resource Center can help you identify the tools that will work best for you, and assist you in completing the process.
• And About Those Risks – Risk, specifically risk-based thinking is likely everyone’s No. 1 topic when discussing ISO 9001:2015—it is a given. But how will you demonstrate it? Is it simply by addressing sub-clause 6.1? That is part of it, as would be the inclusion of it in Management Review (sub-clause 9.3.2.e).But it shouldn’t stop there. It is not sufficient to solely consider product-focused risks via Failure Mode and Effects Analysis (FMEA) process. Incorporate risk into the language of any and all processes and departments. View every process in the context of risk, and understand that the actions to address identified risks will yield improvements, which again is synonymous with the overall intent of ISO 9001:2015.
Finally, remember that Quality Resource Center is the recognized industry leader in the upgrade, deployment, and implementation of ISO 9001:2015. We offer a rich skill set that that not only increases your chance for success in your project, it also offers maximum value and cost efficiency.
Experience the Difference that 25 years of Total ISO Solutions offers.
QRC has carried organizations through the transition from start to certificate — see our ISO 9001 consulting services.
Call (800) 244-5409 or request a consultation.
International Standards Upgrades and Direction Forward
2015 and 2016 have seen major revisions of many of the very important and popular international quality management systems standards –
- ISO 9001:2015 – Released in September, 2015 in conjunction with Annex SL
– Upgrades no later than 2018 - ISO 14001:2015 – Released in September, 2015 in conjunction with Annex SL
– Upgrades no later than 2018 - AS9100D :2016 – Re-aligned with ISO 9001:2015 and Annex SL – Release by 2016
– Upgrades no later than 2018 - ISO 13485:2016 – Released in February 2016
– Upgrade no later than February 2019 - IATF 16949:2016 – Re-aligned with ISO 9001:2015 and Annex SL
– Release by Q4 of 2016; Upgrades no later than 2018
Alignment to Annex SL of these standards (other than ISO 13485:2016) has enabled new and upgraded systems to be easily integrated. This means that adding ISO 14001:2016 to and existing ISO 9001:2015 systems is easily achieved. Similar for upgrading ISO 9001:2016 to include AS9100D or IATF 16949:2016.
It also means that maintaining these systems is more straightforward than ever before. But much depends on the accurate and correct design and deployment of your new or upgraded systems.
Quality Resource Center offers unmatched expertise in these areas.
It also means that you will need additional training, and your auditors will need upgrades to their Auditor Certifications.
Here again, Quality Resource Center is the recognized industry leader.
Take advantage of our complimentary telephone consultation via our toll free line -1 800 244 5409 or simply drop us an email through this we portal.
Quality Resource Center – Experience the Difference.
QRC supports every standard listed here — see our ISO consulting services or start with ISO 9001 consulting.
Call (800) 244-5409 or request a consultation.
ISO 9001:2015 Risk Analysis
Key Questions –
- Why implement Risk Based Thinking?
- What does ISO 9001:2015 require?
- What is Risk Based Thinking?
- What is Risk?
- What is a simple Risk Tool?
- How does it integrate into the Process Approach?
- How do you make Risk Based Thinking a Continual Process Improvement activity?
ISO 9001:2015 Risk & Opportunities –
“4.4 Quality management system and its processes
The organization shall establish, implement, maintain and continually improve a quality management system, including the processes needed and their interactions, in accordance with the requirements of this International Standard.
“The organization shall determine the processes needed for the quality management system and their application throughout the organization and shall determine…
f) The risks and opportunities in accordance with the requirements of 6.1, and plan and implement the appropriate actions to address them;”
“6 planning for the Quality Management system
6.1 Actions to Address Risks and Opportunities
6.1.1 When Planning for the Quality Management System,
The organization shall consider the issues referred to in 4.1 and the requirements referred to in 4.2 and determine the risks and opportunities that need to be addressed to:
- Give assurance that the quality management system can achieve its intended result(s);
- Prevent, or reduce, undesired effects;
- Achieve continual improvement.
6.1.2 The Organization Shall Plan:
- a) Actions to address these risks and opportunities;
- b) How to integrate and implement the actions into its quality management system processes (see 4.4) and evaluate the effectiveness of these actions.
Actions taken to address risks and opportunities shall be proportionate to the potential impact on the conformity of products and services.”
The Main Objectives of International Standards are to provide confidence in the organization’s ability to consistently provide customers with conforming goods and services and enhance customer satisfaction
The concept of “risk” in the context of the ISO 9001:2015 international standard relates to the uncertainty in achieving these objectives.
What is “Risk Based Thinking”?
Risk-based thinking is something we all do automatically and often sub-consciously
The concept of risk has always been implicit in ISO 9001, but the ISO 9001:2015 makes it explicit and requires formal inclusion across the entire management system
Risk-based thinking is already part of the process approach Risk-based thinking enhances Preventive Action. Risk is often thought of only in the negative sense.
Risk-based thinking can also help to identify opportunities. This can be considered to be the positive side of risk
Why Should I adopt “Risk-Based Thinking”?
- To improve customer confidence and satisfaction
- To assure consistency of quality of goods and services
- To establish a proactive culture of prevention and improvement
- Successful companies intuitively take a risk- based approach
What Should I Do?
Identify what the risks and opportunities are in your organization
- Analyze and prioritize risks and opportunities in your organization and quantify them
- What is acceptable?
- What is unacceptable?
- Plan actions to address the risks by prioritizing them based on RPN numbers
- How can I avoid or eliminate the risk? Can it be designed out?
- How can I mitigate the risk? Increase detection? Reduce Occurrence?
- Implement the plan – take action based on priorities
- Check the effectiveness of the actions – and re-score your RPN’s.
- Learn from experience – continual improvement
Key Points to Remember
- Risk Based Thinking is Preventative Action
- Risk Based Thinking is everyone’s job
- Risk Based Thinking is not just the sole responsibility of management
- Risk Based Thinking is an integral part of the organizational DNA
What is Risk?
Risk is the possibility of events or activities impacting the organization’s strategic and operational objectives.
Risk Definitions
Risk can be defined by three (3) parameters
- Severity – The Seriousness of the harm
- Probability (or Occurrence) – The Probability that the harm will occur
- Detection – How well can the item be detected
Severity x Occurrence x Detection or “SOD” = Risk Priority Number or RPN
The Importance of a Risk (or FMEA) Worksheet
The risk worksheet, (example – FMEA), is essential, as it records identified risks, their severity, and the actions steps to be taken.
It can be a simple document, spreadsheet, or a database system, but the most effective format is a table.
A table presents a great deal of information in just a few pages.
There is no standard list of components that should be included in the risk worksheet. Some important ones include –
- Description of the Risk: A phrase that describes the risk.
- Risk Type (business, project, failure, yield, stage, etc.)
- Classification of the risk:
- Business risks relate to delivery of achieved benefit
- Project risks relate to the management of the project such as timeframes and resources
- Stage risks are risks associated with a specific stage of the plan.
- Likelihood of Occurrence: An assessment on how likely or often the risk will occur. Examples are:
- L-Low >30%)
- M-Medium (31-70%)
- H-High (>70%).
- Severity of Effect: Provides an assessment of the impact that the occurrence of this risk would have on the project.
- Detection – how well a risk can be detected via countermeasures
- Components of a Risk Worksheet (example – FMEA)
- Countermeasures: Actions to be taken to prevent, reduce, or transfer the risk. This may include production of contingency plans.
- Owner: The individual responsible for ensuring that risks are appropriately engaged with countermeasures undertaken.
- Status: Indicates whether this is a current risk or if risk can no longer arise and impact the project.
Other columns such as quantitative values can also be added if appropriate.
FMEA TEMPLATES ARE IDEAL MODELS FOR RISK ANALYSIS!
Integrating Risk Based Thinking with the Process Approach
Purpose of the Process Approach
The purpose of the process approach is to enhance an organization’s effectiveness and efficiency in achieving its defined objectives. This means enhancing customer satisfaction by meeting customer requirements. Effective Risk Management means integrating it into your Process & Interactions Map, and resulting KPI’s.
Integrating Risk Management into Management Review Input
“Top management shall review the organization’s quality management system, at planned intervals, to ensure its continuing suitability, adequacy, and effectiveness. The management review shall be planned and carried out taking into consideration – d) The effectiveness of actions taken to address risks and opportunities (see clause 6.1)”
If the organization has a formalized Management Review procedure it is very important to update it to include the elements of Risk Management into the procedure.
In summary, Risk Management with respect to ISO 9001:2015 compliance is not optional. It is an integral part of the overall QMS.
Quality Resource Center offers an array of training and services in this area. Contact QRC today.
Risk-based thinking is where most audits find gaps. QRC’s ISO 9001 consulting services and ISO gap analysis show you where yours are.
Call (800) 244-5409 or request a consultation.
Read all QRC news and insights
Speak With an ISO Expert
Tell us where you are—new certification, a transition, a failed audit, or a system that needs to be usable again—and we will tell you exactly what it takes.
Call (800) 244-5409

