Of everything in the ISO 9001:2026 revision, one addition will cause more argument in more management reviews than all the others combined: quality culture. The revision asks top management to demonstrate leadership and commitment by actively promoting a quality culture, integrity and ethical behaviour, and it ties the quality management system more tightly to the organisation's strategic direction. It is a short piece of text. It is also the first requirement in the standard's history that cannot be satisfied by writing a better procedure.
Most of the other changes in the 2026 edition are the kind quality managers can absorb in an afternoon. Risks and opportunities are separated more clearly, so the measures addressing each are considered on their own terms. The 2024 climate change amendment is folded fully into the text rather than bolted on. Clause 3 gains a limited set of terms and definitions. The core framework, the process approach and the fundamental requirements survive intact — this is a clarifying revision, not a restructuring one.
Culture is the exception. It is the one requirement where the obvious response is also the wrong one.
The trap almost everyone will fall into
The obvious response is to write a Quality Culture Policy. It will be one to three pages. It will say that quality is everyone's responsibility, that the organisation values integrity, that employees are encouraged to raise concerns without fear of reprisal, and that leadership is committed to continual improvement. It will be approved by the CEO, released as a controlled document, and pushed to everyone as read-and-acknowledge training.
And it will fail the moment an auditor asks a second question.
The problem is not that the policy is dishonest. The problem is that a policy is a declaration, and the requirement is about behaviour. Publishing a document that asserts a culture exists is evidence that you know the requirement exists. It is not evidence that the culture does. Worse, an unsupported culture policy actively increases your exposure: you have now made a documented claim about how your organisation behaves, and every record in your QMS is a potential counter-example to it.
This is where the distinction matters, and it is worth being blunt about it. Under ISO 9001:2015, the gap between what your documents said and what your organisation did was mostly a process conformity question, audited process by process. Under the 2026 edition, that same gap becomes evidence about your culture. A policy that says concerns can be raised freely, sitting next to a deviation log with three entries in two years across eight hundred people, is not a neutral finding. It is a contradiction, and contradictions are exactly what a competent auditor is trained to pull on.
Three layers of evidence, and why most organisations only have one
It helps to think about culture evidence in three layers.
The declared layer is what your organisation says about itself: the policy, the quality objectives, the CEO's town-hall slides, the code of conduct, the values on the intranet. Almost every organisation has this layer, and most have it in abundance.
The operated layer is what your management system actually does: how decisions get made when quality and schedule conflict, how deviations are raised and what happens to the person who raises them, how long corrective actions stay open, whether repeat findings recur, whether management review minutes show quality influencing a strategic decision or merely reporting on one.
The experienced layer is what people in the organisation believe to be true: whether they think reporting a problem is safe, whether they think the SOP describes what they actually do, whether they believe leadership would back them if they stopped a shipment.
Auditors have always sampled the operated layer. What the 2026 revision changes is the purpose of that sampling. Evidence from the operated layer is no longer only about whether a process conforms; it is the primary means of testing whether the declared layer is true. And when the two disagree, the declared layer loses.
Where document-level evidence breaks down
Here is the uncomfortable structural point. Culture is not visible in any single document. It is visible only in the relationships between documents and records — and that is precisely the view most quality organisations do not have.
Consider what a real culture finding looks like in practice:
- The quality policy commits to prevention over detection, but ninety per cent of corrective actions close with an inspection step added and no process change. Neither the policy nor any individual CAPA record is defective. The pattern across two hundred CAPAs is the finding.
- The escalation procedure says any employee can halt a process on quality grounds. Every recorded halt in three years was initiated by someone with a manager title. No document is wrong. The distribution is the finding.
- Management review inputs include customer complaints, but the resulting actions in the last four reviews were all assigned to Quality, none to Operations or Engineering. Each set of minutes looks complete. The ownership pattern across reviews is the finding.
- A revised work instruction was released fourteen months ago; the training records show completion at ninety-eight per cent; the deviation reports still reference the old step numbering. Every artefact is individually in order. The mismatch between them is the finding.
Notice what these have in common. In each case, every individual document passes review. The evidence only exists when you can hold hundreds of documents and records in view at once and see how they relate — which policy claims which behaviour, which record contradicts it, which pattern repeats. A human auditor with a five-day audit window and a sampling plan will catch some of these. They will not catch most of them, and they cannot demonstrate coverage.
That is the real reason quality culture is hard to evidence. It is not that culture is unmeasurable. It is that measuring it requires reading everything, and reading everything has never been possible.
Six evidence patterns that actually hold up
If you want to arrive at your first ISO 9001:2026 audit with something better than a policy, these are the patterns worth building now. None of them require new bureaucracy; all of them use records you already generate.
1. The trade-off trail. Find the decisions where quality genuinely competed with cost, schedule or a customer commitment, and show how they were resolved. A single well-documented case where the organisation absorbed a delay to fix a quality problem — with the reasoning, the approver and the outcome recorded — is worth more than any policy statement. Management review minutes and change control records are usually where these live, if anyone has thought to tag them.
2. Speak-up volume and distribution. Track who raises deviations, near-misses and concerns, not just how many. Healthy cultures produce reports from across the hierarchy and across functions. A reporting distribution concentrated in the quality department is itself a finding — and it is far better for you to have found it than the auditor.
3. CAPA depth, not CAPA count. Classify your corrective actions by whether they changed a process, a design, a supplier or a training requirement, versus whether they added an inspection or a reminder. The ratio is a direct, defensible proxy for whether prevention is genuinely valued. Track it over time.
4. Repeat findings. Recurrence of the same finding across audit cycles is the single most damaging culture signal there is, because it demonstrates that the system records problems without resolving them. Conversely, a documented reduction in recurrence is one of the strongest positive culture arguments available to you.
5. Awareness with comprehension. Read-and-acknowledge training records prove distribution, not understanding, and auditors know it. Awareness evidence that carries weight shows people can describe how their work affects quality outcomes — captured through short competence checks, shop-floor interviews recorded as records, or onboarding assessments.
6. Documented-versus-lived process. Sample a handful of processes and compare what the procedure says with what the records show actually happened. Where they differ, the honest response is to fix one or the other and record why. An organisation that can show it systematically hunts for this gap is demonstrating exactly the culture the standard is asking about.
Where PEDCO AuditPro fits
This is, structurally, the problem PEDCO AuditPro was built for. The platform ingests your QMS as a whole — procedures, policies, work instructions, records and the connections between them — classifies each document before it enters the knowledge graph, and represents the result as a graph of processes, requirements and evidence rather than a pile of files.
That representation is what makes culture evidence tractable. Because the graph holds relationships rather than documents in isolation, PEDCO AuditPro can surface the contradictions that individual document review misses: a policy commitment with no supporting records anywhere in the corpus, procedures that reference revisions that no longer exist, requirements that every document claims to satisfy and no record demonstrates, clusters of findings that keep returning under different labels. Every observation carries its evidence chain back to the source document, because a culture argument you cannot trace is a culture argument you cannot defend.
The Copilot side matters here too. The questions that expose culture are open questions — where does our leadership commitment actually show up in records, which of our stated commitments have the thinnest evidence, what changed in behaviour after our last management review — and those are not queries you can express in a document management system's search box. They are queries against a model of your QMS.
None of this manufactures a culture you do not have. That is the point. What it does is tell you, before an auditor does, which of your declarations the rest of your management system fails to support — while there is still time to fix the substance rather than the wording.
What to do between now and your transition audit
ISO 9001:2026 is expected to publish in September 2026, with a three-year transition running to September 2029. That sounds generous, and for the mechanical changes it is. For culture it is not, because culture evidence is retrospective: the records that will support your argument in 2028 are the ones you are generating this quarter.
Four things worth starting now:
- Do not write the policy first. Inventory the culture claims you have already made across existing documents, then check which ones your records support. Write the policy last, and write it to match what you can prove.
- Instrument the six patterns above. Most require nothing more than a classification field on records you already keep. Adding them now buys you two years of trend data before your transition audit.
- Run a contradiction sweep. Deliberately look for places where your documented commitments and your operational records disagree. Treat each one as a finding and process it through your normal CAPA route — an auditor who sees you self-identifying these is being shown the culture requirement in action.
- Put culture on the management review agenda as an input, not a report-out. The revision ties the QMS to strategic direction; management review is where that link is either evidenced or absent.
The organisations that will struggle with this clause are the ones that treat it as a documentation exercise and produce a policy in week one. The ones that will pass comfortably are the ones that spend the transition period making their records tell a consistent story — and then write the policy that story supports.

