ISO 9001:2015
Quality Management System
Consistent product and service quality, customer satisfaction and process control.
View ISO 9001:2015Certification guide
Buyers often ask for “ISO certification” as if it were one product. ICV Assessments certifies nine schemes — pick the system that matches quality, environment, safety, food, energy, medical devices or information security.
Use the cards and table below to compare every standard we offer, then open the service page or request a quotation. Integrated audits are possible when the same sites overlap.
Nine ISO schemes
All ICV schemes
Open the full service page for process, documents and FAQs for each standard below.
ISO 9001:2015
Consistent product and service quality, customer satisfaction and process control.
View ISO 9001:2015ISO 14001:2015
Environmental aspects, legal compliance, waste, emissions and pollution prevention.
View ISO 14001:2015ISO 45001:2018
Workplace hazards, injury prevention, legal OH&S duties and worker participation.
View ISO 45001:2018ISO 22000:2018
Food safety across the supply chain, PRPs, hazard control and traceability.
View ISO 22000:2018ISO 27001:2022
Confidentiality, integrity and availability of information; risk-based ISMS controls.
View ISO 27001:2022ISO 50001:2018
Energy performance, significant energy uses, metering, baselines and continual reduction.
View ISO 50001:2018ISO 13485:2016
QMS for medical devices: design (if in scope), production, sterile processes, complaints and vigilance.
View ISO 13485:2016HACCP
Identify food-safety hazards and control them at CCPs with monitoring and corrective action.
View HACCPGMP
Hygiene, premises, equipment, batch records and staff discipline in manufacturing.
View GMPSide by side
Scroll sideways on smaller screens. The standard name stays visible on the left.
| Standard | What it manages | Typical organisations | Why buyers ask for it | How it combines |
|---|---|---|---|---|
| ISO 9001:2015 Quality Management System | Consistent product and service quality, customer satisfaction and process control. | Any organisation: manufacturing, services, construction, education, trading. | Tenders, vendor registration, export customers. | Often the base system. Combine with 14001, 45001 or 27001 when those risks apply. |
| ISO 14001:2015 Environmental Management System | Environmental aspects, legal compliance, waste, emissions and pollution prevention. | Process industry, construction, logistics, energy, manufacturing. | ESG questionnaires, environmental consents, green supply-chain codes. | Pairs with 9001 and 45001 on the same sites (integrated EHS/QMS). |
| ISO 45001:2018 Occupational Health & Safety | Workplace hazards, injury prevention, legal OH&S duties and worker participation. | Construction, manufacturing, facilities, healthcare, logistics. | Principal contractor rules, labour compliance, insurance and client HSE gates. | Common with 9001 + 14001 for industrial and construction scopes. |
| ISO 22000:2018 Food Safety Management System | Food safety across the supply chain, PRPs, hazard control and traceability. | Food manufacturing, catering, packaging, storage and distribution. | Retailers, exporters, hospitality and food-service customers. | HACCP principles sit inside 22000. GMP may sit beside it for manufacturing hygiene. |
| ISO 27001:2022 Information Security Management | Confidentiality, integrity and availability of information; risk-based ISMS controls. | IT/SaaS, GCCs, BPOs, healthcare, any data-heavy operation. | Enterprise security reviews, cloud customers, privacy contracts. | Not a substitute for 9001. Many firms hold both: delivery quality + information security. |
| ISO 50001:2018 Energy Management System | Energy performance, significant energy uses, metering, baselines and continual reduction. | Plants, utilities, large buildings, energy-intensive manufacturing. | Energy cost programmes, group sustainability targets, utility customers. | Shares operational discipline with 14001; it is not an environmental certificate by itself. |
| ISO 13485:2016 Medical Device Quality Management | QMS for medical devices: design (if in scope), production, sterile processes, complaints and vigilance. | Device manufacturers, contract manufacturers, related service providers. | Regulators, hospital buyers, EU/US supply-chain partners. | Related to 9001 but not interchangeable. Device files and process validation are extra. |
| HACCP Hazard Analysis & Critical Control Points | Identify food-safety hazards and control them at CCPs with monitoring and corrective action. | Kitchens, processors, packers and food handlers of every size. | Food buyers, export markets and hygiene due-diligence checks. | Codex HACCP is the core method; ISO 22000 builds a full FSMS around it. |
| GMP Good Manufacturing Practice | Hygiene, premises, equipment, batch records and staff discipline in manufacturing. | Food, cosmetics, pharma-adjacent and related manufacturing. | Brand owners, regulators and contract-manufacturing customers. | Complements 9001 or 22000/HACCP. GMP is shop-floor practice, not a full ISO management system. |
Common choices
9001 is about meeting customer requirements for what you sell. 14001 is about controlling environmental impact of those operations. They are not substitutes. A factory often holds both.
45001 is not “9001 with safety”. It needs hazard identification, worker participation and legal OH&S duties. Construction and manufacturing commonly run 9001 + 45001 together.
HACCP controls hazards at CCPs. ISO 22000 is the full food-safety management system around that method, including PRPs and system review. Choose HACCP for a focused food-safety control study; choose 22000 when buyers want an FSMS certificate.
13485 is the medical-device QMS. Device files, sterile processes and complaint/vigilance rules go beyond generic 9001. Device manufacturers should not treat 9001 as a replacement.
14001 covers environmental aspects (waste, emissions, legal consents). 50001 is specifically energy performance — SEUs, EnPIs and energy review. Energy-intensive plants may hold both.
27001 protects information. 9001 protects delivery quality. SaaS, GCCs and BPOs often need 27001 first because enterprise buyers check the ISMS. 9001 can sit beside it for operations.
GMP is manufacturing hygiene, premises, equipment and batch discipline. 9001 is the broader management system. Food, cosmetics and similar plants often need GMP on the floor and 9001 for the organisation.
If quality, environment and safety share the same leadership and sites, one integrated audit can reduce duplicated time. You still implement each standard and receive three certificates.
FREQUENTLY ASKED QUESTIONS
Most first-time organisations start with ISO 9001 because it builds process discipline that 14001 and 45001 can reuse. Choose ISO 22000 or HACCP if you make or handle food, ISO 13485 for medical devices, ISO 27001 if information security is a buyer requirement, ISO 50001 for energy performance, and GMP for manufacturing hygiene.
Yes. Integrated audits are common for ISO 9001, 14001 and 45001 when the same sites and overlapping processes are in scope. Each standard still needs to be implemented, and you still receive one certificate per standard. Food (22000/HACCP), medical devices (13485) and information security (27001) usually need their own audit sampling.
No. HACCP is a hazard-control method. ISO 22000 is a full food-safety management system that includes HACCP plus PRPs, communication and continual improvement. Many food businesses hold HACCP first, then move to ISO 22000 when customers ask for a complete FSMS.
They share a process approach, but ISO 13485 adds device-specific requirements such as risk for medical devices, sterile production where applicable, traceability, complaint handling and regulatory alignment. A 9001 certificate does not replace 13485 for device manufacturers.
Sometimes. GMP focuses on how product is made and controlled on the shop floor. ISO 9001 covers the wider management system (customers, objectives, internal audit, management review). Food, cosmetics and similar manufacturers often run both.
No. Any organisation that handles sensitive information can define an ISMS scope — hospitals, shared services, manufacturers with OT/IT networks, as well as SaaS and GCCs.