Exemplar Global Certified Courses from USD 99. Ending Soon!

The ISO Standards Families Explained: A Practical Guide to the Major Standards

AW

Team @ Audit Workshop

13 min read
The ISO Standards Families Explained: A Practical Guide to the Major Standards

If you are new to ISO standards, the sheer number of them can feel overwhelming. ISO has published over 24,000 standards covering everything from food safety to road vehicles to information security. But most organisations, auditors, and quality professionals only need to understand a handful of families. Once you understand how the major ISO standards families are structured and what each one is designed to achieve, navigating the ISO landscape becomes much more manageable.

This guide walks through the most important ISO standards families, explains what they cover, and helps you understand how they relate to each other. Whether you are a quality manager deciding which standard to pursue, an auditor expanding your scope, or someone new to management systems, this is a practical starting point.

What Is an ISO Standards Family?

ISO standards are grouped into families, sometimes called series. Each family addresses a specific domain or discipline. Within a family, you typically find a core standard that sets out requirements, supported by guidance documents, vocabulary standards, and sector specific extensions.

For example, the ISO 9000 family includes ISO 9000 (vocabulary), ISO 9001 (requirements), and ISO 9004 (guidance for sustained success). The core standard, ISO 9001, is the one organisations certify to. The others provide context and support.

Understanding this structure helps you make sense of why there are so many ISO publications without feeling like you need to read all of them. In most cases, you only need to work directly with the requirements standard.

The ISO 9000 Family: Quality Management

The ISO 9000 family is the most widely adopted set of standards in the world. It provides a framework for quality management systems (QMS) and applies to virtually any organisation, regardless of size, sector, or product type.

ISO 9001: Requirements

ISO 9001 is the certification standard. It sets out what an organisation must do to demonstrate it consistently provides products and services that meet customer and regulatory requirements. The current edition is ISO 9001:2015, with a revision expected around 2026.

The standard is built around the Plan Do Check Act cycle and uses risk based thinking as a core principle. It covers everything from leadership commitment and planning through to operational control, monitoring, and continual improvement.

ISO 9000 and ISO 9004

ISO 9000 provides the vocabulary and definitions used across the family. If you ever encounter a term in ISO 9001 that is not immediately clear, ISO 9000 is where you look it up. ISO 9004 goes beyond the requirements of ISO 9001 and provides guidance for organisations that want to pursue long term organisational excellence, not just certification.

Who Needs It

ISO 9001 certification is required or preferred by clients across construction, manufacturing, professional services, healthcare, government supply chains, and many other sectors. It is often the first ISO standard an organisation pursues and the most common credential for quality auditors.

If you want to understand the quality family in depth, our article on ISO 9001 vs ISO 14001 vs ISO 45001 covers how the three main management system standards compare.

The ISO 14000 Family: Environmental Management

The ISO 14000 family addresses environmental management. The flagship standard is ISO 14001, which specifies requirements for an environmental management system (EMS). Organisations use it to identify and control their environmental impacts, meet compliance obligations, and pursue continual improvement in environmental performance.

ISO 14001: Requirements

ISO 14001 follows the same high level structure as ISO 9001, which makes it easier to implement alongside a QMS. The current edition is ISO 14001:2015, with ISO 14001:2026 now published and a transition deadline of April 2029.

The standard requires organisations to identify their environmental aspects and impacts, establish legal and other compliance obligations, set environmental objectives, and maintain operational controls. It also introduced the concept of a lifecycle perspective, requiring organisations to think about environmental impact beyond their own four walls.

Supporting Standards

The ISO 14000 family includes ISO 14004 (general guidance on EMS implementation), ISO 14015 (environmental assessments of sites), ISO 14031 (environmental performance evaluation), and several standards related to lifecycle assessment, environmental labelling, and greenhouse gas accounting.

ISO 14064, for example, covers greenhouse gas quantification and reporting, which is increasingly relevant as organisations face pressure to measure and disclose their carbon footprint. ISO 14067 addresses the carbon footprint of products specifically.

Who Needs It

ISO 14001 is relevant to any organisation with significant environmental aspects, including manufacturers, construction companies, transport operators, mining contractors, and facilities managers. It is also increasingly required by clients and government agencies as part of tender requirements.

The ISO 45000 Family: Occupational Health and Safety

The ISO 45000 family addresses occupational health and safety management. ISO 45001:2018 is the requirements standard, replacing the older OHSAS 18001 specification and, in Australia, effectively superseding AS/NZS 4801.

ISO 45001: Requirements

ISO 45001 provides a framework for managing OH&S risks and opportunities, preventing work related injury and ill health, and providing safe and healthy workplaces. Like ISO 9001 and ISO 14001, it uses the harmonised structure, making integration across the three standards straightforward.

A distinctive feature of ISO 45001 compared to its predecessors is the strong emphasis on worker participation and consultation. The standard expects workers to be actively involved in the OH&S management system, not just informed about it.

ISO 45003

ISO 45003 is a guidance document that addresses psychological health and safety at work. It does not have its own certification pathway but provides practical guidance for managing psychosocial risks within an ISO 45001 framework. Given the growing focus on mental health in Australian workplaces, this is increasingly relevant for organisations and auditors alike.

Who Needs It

ISO 45001 applies to any organisation that wants to systematically manage workplace health and safety. It is particularly common in high risk industries such as construction, mining, manufacturing, transport, and aged care. In Australia, it sits alongside but does not replace obligations under state and territory WHS legislation.

The ISO 27000 Family: Information Security

The ISO 27000 family is the most comprehensive set of standards for information security management. The core certification standard is ISO 27001, which specifies requirements for an information security management system (ISMS).

ISO 27001: Requirements

ISO 27001 requires organisations to assess information security risks and implement controls to address them. The standard includes Annex A, which lists 93 controls across four themes: organisational, people, physical, and technological. Organisations select applicable controls and document their decisions in a Statement of Applicability.

The current edition is ISO 27001:2022, which restructured Annex A significantly compared to the 2013 version and introduced 11 new controls covering areas such as threat intelligence, cloud service security, and data masking.

Supporting Standards in the 27000 Family

The ISO 27000 family is extensive. ISO 27000 provides vocabulary. ISO 27002 provides detailed implementation guidance for the Annex A controls. ISO 27005 covers information security risk management. ISO 27017 addresses cloud security. ISO 27018 focuses on protection of personally identifiable information in public clouds. ISO 27701 extends ISO 27001 to cover privacy information management.

For Australian organisations, ISO 27001 is increasingly relevant in the context of the Privacy Act, the Notifiable Data Breaches scheme, and APRA's CPS 234 prudential standard for financial services entities.

Who Needs It

ISO 27001 is relevant to any organisation that handles sensitive information, including technology companies, financial services firms, healthcare providers, law firms, government suppliers, and managed service providers. It is becoming a standard requirement in government and enterprise procurement.

The ISO 22000 Family: Food Safety

The ISO 22000 family addresses food safety management systems. ISO 22000 is the core requirements standard, applicable to any organisation in the food chain, from primary producers to retailers and food service operators.

ISO 22000: Requirements

ISO 22000 combines HACCP (Hazard Analysis and Critical Control Points) principles with the management system approach of ISO 9001. It requires organisations to identify food safety hazards, establish prerequisite programmes (PRPs), and implement a HACCP plan to control significant hazards.

The current edition is ISO 22000:2018. Like the management system standards above, it uses the harmonised structure.

FSSC 22000

FSSC 22000 is a certification scheme built on top of ISO 22000. It adds sector specific prerequisite programme requirements and is recognised by the Global Food Safety Initiative (GFSI). Many large food manufacturers and retailers require FSSC 22000 rather than ISO 22000 alone, particularly when supplying major supermarket chains.

Who Needs It

ISO 22000 is relevant to food manufacturers, processors, packaging companies, transport and storage operators, catering businesses, and ingredient suppliers. It is increasingly required by major buyers as a condition of supply.

The ISO 42000 Family: Artificial Intelligence

The ISO 42000 family is the newest of the major management system families. ISO 42001:2023 specifies requirements for an artificial intelligence management system (AIMS), providing a framework for organisations that develop, provide, or use AI systems to manage AI related risks responsibly.

ISO 42001: Requirements

ISO 42001 follows the harmonised structure and shares many structural similarities with ISO 27001. It requires organisations to define their AI context, assess AI related risks and opportunities, implement controls from Annex A, and conduct AI system impact assessments.

The standard is notable for its focus on responsible AI, addressing concerns about fairness, transparency, accountability, and human rights. As AI adoption accelerates across Australian organisations, ISO 42001 is likely to become increasingly significant for procurement and regulatory purposes.

Who Needs It

ISO 42001 is relevant to technology companies developing AI products, organisations deploying AI systems in operations, and any business that wants to demonstrate responsible AI governance. It is an emerging area for auditors, with demand for ISO 42001 auditor skills growing quickly.

The ISO 19011 Guideline: Auditing Management Systems

ISO 19011 is not a certification standard. It is a guideline that provides practical guidance for auditing management systems. It covers audit principles, managing an audit programme, conducting audits, and evaluating auditor competence.

The current edition is ISO 19011:2026, which updates the 2018 version with guidance on remote auditing, AI tools, data protection considerations, and updated expectations for nonconformity grading. Unlike the management system standards above, ISO 19011 applies immediately upon publication with no transition period.

Every practising auditor should be familiar with ISO 19011. It is the foundation of professional audit practice across all the management system families described in this article.

The Harmonised Structure: What Connects the Families

One of the most important developments in ISO standards in recent years is the harmonised structure, previously called Annex SL or the High Level Structure (HLS). This is a common framework that all new and revised management system standards must follow.

The harmonised structure means that ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22000, and ISO 42001 all share the same 10 clause structure. Clauses 1 to 3 cover scope, references, and terms. Clauses 4 to 10 cover the management system requirements: context, leadership, planning, support, operation, performance evaluation, and improvement.

This shared structure makes it significantly easier to implement multiple standards together in an integrated management system (IMS), and it makes it easier for auditors trained in one standard to pick up another. The core audit skills, the approach to evidence gathering, the interview techniques, and the way you assess conformity, all transfer directly.

For a deeper look at how the structure works, our article on what is the High Level Structure in ISO standards explains the clause by clause framework in plain language.

Sector Specific Extensions and Related Standards

Beyond the major families, there are sector specific standards that extend the core requirements for particular industries. Some worth knowing about include:

  • IATF 16949: Automotive quality management, building on ISO 9001 with additional requirements for automotive supply chains.
  • AS9100: Aerospace quality management, extending ISO 9001 for aviation, space, and defence sectors.
  • ISO 13485: Medical device quality management, a standalone standard with stricter requirements than ISO 9001 for regulatory compliance.
  • ISO 17025: Competence requirements for testing and calibration laboratories, used by labs seeking accreditation rather than certification.
  • ISO 50001: Energy management systems, helping organisations improve energy performance and reduce costs and emissions.
  • ISO 17100: Translation services, specifying requirements for the translation workflow including translator qualifications and revision processes.

These sector specific standards are often built on or alongside ISO 9001, and many organisations pursue them in addition to their core management system certifications.

Choosing the Right Standard for Your Organisation or Career

If you are an organisation deciding where to start, the answer usually comes down to what your clients and market require. ISO 9001 is the most common starting point. If you are in a high risk industry with significant environmental or safety obligations, ISO 14001 and ISO 45001 often follow. ISO 27001 is increasingly expected in technology and professional services sectors.

If you are an auditor or aspiring auditor, the same logic applies. Start with the standard most relevant to your industry background. ISO 9001 is the most transferable credential. From there, adding ISO 14001 or ISO 45001 significantly broadens your scope. Because of the harmonised structure, the learning curve for each additional standard is much shallower than the first.

Our article on ISO auditor career path from internal auditor to lead auditor provides practical guidance on how to build your credentials progressively across multiple standards.

How Audit Workshop Covers the Major Families

Audit Workshop delivers training across the three most widely required management system standards in Australia: ISO 9001, ISO 14001, and ISO 45001. Courses are available at Foundation, Internal Auditor, and Lead Auditor levels, delivered live online and as self paced options.

All Audit Workshop courses are built around real audit practice. The training draws on over 14 years of compliance experience and 500 or more external certification audits across Australia, the Middle East, and South Asia. You learn how audits actually work, not just what the clauses say.

If you are working out which standard to train in first, or whether to pursue an internal auditor or lead auditor qualification, our article on Foundation vs Internal Auditor course will help you make that decision with clarity.

Frequently Asked Questions

ISO has published over 24,000 standards, but the vast majority are technical or product specific standards that most quality and compliance professionals will never need to work with directly. For management system practitioners, the key families are ISO 9000 (quality), ISO 14000 (environment), ISO 45000 (safety), ISO 27000 (information security), ISO 22000 (food safety), and ISO 42001 (AI). Understanding these families and the harmonised structure that connects them is sufficient for most auditing and implementation work.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.