
March 2026 marks a decisive broadening of the governance agenda. If February was about making governance measurable and auditable, March is about extending that governance into the real operating systems of organizations: risk, resilience, innovation, circularity, data, platforms, people, and sustainability performance.
This month shows a clear shift from isolated management systems toward integrated capability systems — where organizations must not only manage risks and opportunities but also demonstrate the ability to adapt, recover, innovate, protect data, reduce waste, and deliver sustainable outcomes.
Three themes dominate the March:
Risk, resilience, and continuity become board-level operating capabilities — with major movement around ISO 31000, ISO 22301, ISO 22316, and related business continuity standards.
Sustainability becomes more operational and evidence-based — with new, advanced work on the SDGs, circularity, decarbonization, environmental claims, EPDs, biodiversity, food loss and waste, and sustainable finance.
Digital trust moves deeper into platforms, cloud, AI, privacy, cybersecurity, and data quality — with standards emerging for dataspace trust frameworks, cloud support for AI services, privacy-by-design audits, secure software development, and data quality vocabulary.
For top management, March delivers a clear message: governance is no longer only about control. It is about building organizations that can perform, adapt, recover, and prove their impact.
Newly published standards
ISO/IEC 27000:2026 – Information security, cybersecurity and privacy protection — Information security management systems — Overview
Updates the conceptual foundation of the ISO/IEC 27000 family. As cybersecurity, privacy, cloud services, AI, and information governance increasingly overlap, a common understanding of information-security management becomes essential for consistent implementation across organizations.
ISO/IEC 27017:2026 – Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services
Updates one of the most important cloud-security standards. Cloud services are now part of the core operating infrastructure of many organizations, making the allocation of security responsibilities between cloud providers and customers increasingly important.
The new edition reinforces the connection between general information-security controls and the specific governance challenges created by cloud environments.
ISO/IEC TR 31700-2:2026 – Consumer protection — Privacy by design for consumer goods and services — Part 2: Use cases
Provides practical use cases for implementing privacy by design in consumer products and services.
The work is particularly relevant as privacy needs to be considered throughout product development rather than addressed only through legal notices or controls introduced after a system has already been designed.
ISO/TR 42505:2026 – Sharing economy — Shared manufacturing — Concepts and models
Extends sharing-economy concepts into manufacturing. Shared manufacturing creates new questions around assets, responsibilities, information exchange, quality, capacity, and trust between organizations participating in common production ecosystems.
Standards at publication stage
ISO 9001 – Quality management systems — Requirements
The next edition of the world’s most widely recognized quality-management standard has reached publication stage.
This is one of the most significant ISO developments of 2026. ISO 9001 provides the management-system foundation used by organizations across industries to consistently meet requirements, manage processes, improve performance, and create customer confidence.
The new edition follows the publication of ISO 9000:2026 and represents the next step in modernizing the ISO quality-management family for an environment increasingly shaped by digitalization, data, sustainability, changing stakeholder expectations, and complex value networks.
ISO 14002-3 – Environmental management systems — Guidelines for using ISO 14001 to address environmental aspects and conditions within an environmental topic area — Part 3: Climate
Provides specific guidance for applying ISO 14001 to climate-related environmental aspects and conditions.
The development is important because it connects the general environmental-management framework of ISO 14001 with one of the most strategically significant environmental challenges facing organizations.
It reinforces the idea that climate needs to be integrated into normal environmental-management processes rather than treated as a separate sustainability programme.
ISO 45010 – Occupational health and safety management — Menstruation and menopause in the workplace — Guidance
Extends occupational health and safety guidance into an area increasingly recognized as relevant to workplace inclusion, well-being, and organizational support.
The standard illustrates how occupational health and safety management continues to broaden beyond traditional physical hazards toward a more comprehensive understanding of workforce health and working conditions.
ISO 30439 – Human resource management — Safe handling of data
Addresses the governance of HR information.
As organizations collect increasing amounts of employee data through digital HR platforms, analytics, AI tools, recruitment systems, and performance-management technologies, the responsible handling of that information becomes an increasingly important HR governance issue.
Final Draft International Standards (FDIS): Editorials before publication
ISO/FDIS 22316 – Security and resilience — Organizational resilience — Guidelines
The revision of ISO 22316 is approaching publication and reinforces resilience as a strategic organizational capability.
Organizational resilience is broader than business continuity. It concerns an organization’s ability to anticipate change, respond to disruption, adapt, and continue creating value under changing conditions.
The revision is particularly relevant in an environment shaped by cyber risk, geopolitical uncertainty, supply-chain disruption, climate impacts, and accelerating technological change.
ISO/FDIS 30441 – Human resource management — Workplace well-being — Guidelines for thriving workplaces
Moves workplace well-being beyond isolated initiatives toward a more structured organizational approach.
The focus on thriving workplaces reflects a broader change in HR standardization: organizations increasingly need to consider employee experience, organizational conditions, health, engagement, and sustainable performance together.
ISO/IEC FDIS 27091 – Cybersecurity and Privacy — Artificial Intelligence — Privacy protection
Connects two rapidly developing governance areas: AI and privacy.
AI systems can create new privacy risks because of the scale of data processing, model behaviour, inference capabilities, and difficulties in understanding how information is used. Specific guidance on privacy protection for AI therefore represents an important addition to the wider AI assurance landscape.
ISO/FDIS 37304 – Compliance management systems — Requirements for bodies providing audit and certification of compliance management systems
Strengthens the assurance infrastructure around compliance management.
As organizations increasingly use management systems to structure compliance responsibilities, consistent requirements for bodies auditing and certifying those systems become important for credibility and market confidence.
Draft International Standards (DIS): Nearing publication
uly brings notable activity around environmental management, diversity, product information, and climate governance.
ISO/DIS 14002-4 – Environmental management systems — Guidelines for using ISO 14001 to address environmental aspects and conditions within an environmental topic area — Part 4: Resources and waste
Extends the ISO 14002 series into resources and waste.
The work provides organizations with more specific guidance for translating ISO 14001 into action around resource use and waste management — areas increasingly connected with circular economy strategies, efficiency, lifecycle thinking, and regulatory expectations.
Together with ISO 14002-3 on climate, the series shows how the general ISO 14001 framework is increasingly being supported by topic-specific implementation guidance.
ISO/DIS 37401 – Diversity management systems — Requirements with guidance for use
Moves diversity management toward a formal management-system approach.
The development reflects the wider expansion of management-system thinking into organizational culture, people management, and social governance. It provides a structured way of connecting policies and commitments with responsibilities, processes, objectives, and continual improvement.
ISO/DIS 22132 – Guidelines for barcode usage in trade documents
Addresses the use of barcodes in trade documentation.
The standard is relevant to the continued digitalization of trade processes, where machine-readable information can reduce manual handling, improve data accuracy, and support more efficient connections between physical flows and business documentation.
ISO/DGuide 84 – Guidelines for addressing climate change in standards
An important development at the standards-system level.
Rather than addressing climate only through dedicated environmental standards, the guide provides a framework for considering climate-change implications across standards development more generally.
This reflects the increasing recognition that climate considerations may be relevant across infrastructure, products, services, management systems, supply chains, and technology standards.
Committee Drafts (CD): Key Standards in Progress
July shows particularly strong activity around innovation, AI, service excellence, and operational improvement.
ISO/CD 56002 – Innovation management — Innovation management system — Guidance
The revision of one of the central standards in the ISO 56000 family continues.
Innovation management is increasingly being treated as a systematic organizational capability rather than something dependent on isolated projects or creative individuals. ISO 56002 provides a framework for connecting innovation with leadership, strategy, culture, processes, and organizational learning.
ISO/CD 56012 – Innovation management — Innovation Ecosystem Management — Guidance
Extends innovation management beyond the individual organization.
Modern innovation increasingly takes place through ecosystems involving customers, suppliers, research organizations, startups, technology providers, and public actors. Managing those relationships therefore becomes an important capability in its own right.
Together with ISO 56002, the project reflects a shift from managing individual innovation activities toward managing innovation systems and ecosystems.
ISO/IEC CD TS 25568 – Artificial Intelligence — Guidance on addressing risks in generative AI systems
One of the most important AI developments of the month.
Generative AI introduces risks that differ in some respects from traditional software and analytical AI systems, including unpredictable outputs, synthetic content, model misuse, information leakage, and difficulties in validating system behaviour.
Dedicated guidance therefore represents an important step toward more mature governance of generative AI.
ISO/CD 24082 – Service excellence — Designing excellent service to achieve outstanding customer experiences — Requirements and guidance
Moves service excellence toward systematic design.
Rather than focusing only on measuring customer satisfaction after delivery, the standard addresses how organizations can intentionally design services to create stronger customer experiences.
ISO/CD 26258 – Guidelines of tools and techniques application for Six Sigma, Lean and Lean Six Sigma
Develops structured guidance around established operational-improvement methodologies.
The project reinforces the continued importance of systematic improvement, process efficiency, variation reduction, and evidence-based problem solving within modern management systems.
ISO/CD TS 56010 – Innovation management — Illustrative examples of ISO 56000
Supports implementation of the ISO innovation-management framework through practical examples, helping organizations translate concepts into operational practices.
New work items and early-stage developments
July’s new projects show an increasingly connected agenda around people, IT governance, innovation, sustainability, and organizational capability.
1. HR management becomes measurable
ISO/NP TS 30403 – Human resource metrics
A notable development following the rapid expansion of the ISO HR-management portfolio.
Organizations increasingly use workforce data to understand recruitment, retention, competence, performance, productivity, well-being, and organizational capability. Common approaches to HR metrics can help organizations move from fragmented indicators toward more structured measurement.
This is especially significant as workforce decisions become increasingly data-driven.
The challenge will not simply be to collect more HR data, but to identify which measures genuinely support organizational decisions and performance.
2. ISO 30201 moves from requirements toward implementation
The development follows closely after ISO 30201 reached publication.
Where ISO 30201 establishes requirements for an HR management system, this new work will provide guidance on implementation.
Together with new work on HR metrics, workplace well-being, safe handling of HR data, and technology integration, a more complete HR management-system ecosystem is beginning to emerge.
3. IT governance gets a new model and framework
ISO/IEC NP 38502 – Information technology — Governance of IT — Model and Framework
One of the most strategically important new projects of July.
Organizations increasingly depend on IT not simply as operational support but as the infrastructure through which strategy, services, data, customer relationships, AI, and business models are delivered.
Governance therefore needs to address how technology decisions are made, who is accountable, how investments support organizational objectives, and how risks and opportunities are managed.
The development of a new IT-governance model and framework reflects the increasing importance of treating digital technology as a board-level governance capability.
4. Circular economy becomes measurable
ISO/WD 59020 – Circular economy — Measuring and assessing circularity performance
A major development in the ISO 59000 circular-economy family.
Circular economy strategies ultimately need mechanisms for determining whether organizations, products, and value networks are actually becoming more circular.
Measurement therefore represents a critical transition from circularity as an ambition toward circularity as a performance discipline.
Organizations increasingly need to connect material flows, reuse, recycling, lifetime extension, resource efficiency, and business-model changes with indicators that can support decisions and demonstrate progress.
5. Biodiversity establishes a common language
ISO/WD 13208 – Biodiversity — Vocabulary
Biodiversity standardization continues to build its foundations.
Common terminology may appear basic, but it is essential before organizations can develop interoperable measurement, reporting, monitoring, assessment, and management practices.
Together with earlier work on biodiversity measurement and monitoring, ISO is gradually creating the conceptual and measurement infrastructure required for more systematic biodiversity governance.
6. Innovation moves toward ecosystem and intellectual-property governance
The revision of ISO 56005 reinforces the relationship between innovation and intellectual-property management.
As organizations collaborate more widely and innovation increasingly takes place across ecosystems, questions around ownership, access, protection, licensing, and use of intellectual assets become more strategically important.
Combined with ISO 56012 on innovation ecosystems and the revision of ISO 56002, this shows a clear maturation of the ISO innovation-management portfolio.
7. Security evaluations become reusable
Addresses an important efficiency challenge in digital assurance.
Products and systems may need to demonstrate conformity against multiple requirements, schemes, customers, or regulatory frameworks. Repeating similar evaluations creates cost and complexity.
The ability to reuse credible evaluation results could therefore become an important part of more efficient assurance ecosystems — provided confidence, scope, and comparability can be maintained.
8. Project management focuses on professional competence
ISO/WD 21515 – Project, programme and portfolio management — Competency framework for professionals
Extends the ISO project-management portfolio into professional competence.
Processes and governance frameworks are only effective when the people responsible for applying them have appropriate capability.
A common competency framework can therefore help connect project-management standards with professional development, organizational capability, and workforce planning.
9. Financial and operational asset management become more closely aligned
Addresses a persistent organizational challenge: financial decision-making and operational asset management are often separated even though they concern the same assets.
Better alignment can improve investment decisions, lifecycle planning, risk management, performance, and the understanding of long-term value.
This is particularly relevant for organizations managing infrastructure, buildings, industrial assets, and other capital-intensive systems.
10. E-commerce moves deeper into transaction assurance
ISO/AWI 32124 – Transaction assurance in E-commerce — Guidance for implementing live commerce
Extends e-commerce standardization into live-commerce environments.
As digital commerce becomes more immediate, interactive, and platform-based, organizations need mechanisms for establishing trust around sellers, transactions, information, and consumer interactions.
The project reflects the wider trend toward bringing assurance directly into digital transactions rather than treating trust as something established only outside the transaction itself.
Looking Ahead
July 2026 shows that many areas of standardization are moving from general frameworks toward measurable organizational capability. Quality management is entering its next generation with ISO 9001 at publication stage. Human-resource management is developing requirements, implementation guidance, metrics, well-being frameworks, and data-governance standards. Circular economy work is moving toward measuring actual circularity performance, while biodiversity is building the common vocabulary needed for future measurement and assessment. At the same time, cybersecurity and IT governance are expanding from operational security controls toward wider questions of technology governance, cloud responsibility, privacy, AI risk, and assurance.
Another clear development is that management disciplines are becoming more interconnected. Digital transformation affects quality, HR, privacy, cybersecurity, innovation, and service design simultaneously. Climate considerations increasingly influence environmental management as well as the standards-development process itself. Innovation requires not only ideas but ecosystems, intellectual-property management, competencies, and structured processes. Resilience depends on technology, people, suppliers, knowledge, and organizational adaptability. This makes it increasingly difficult to manage quality, sustainability, technology, people, and risk as separate governance systems.
For top management, the implication is that the next stage of organizational maturity will depend on connecting these capabilities. Leaders need common frameworks, but they also need reliable metrics, competent people, clear governance, trusted technology, and evidence that systems produce the intended results. The emerging ISO landscape increasingly supports this shift from isolated management disciplines toward an integrated organizational architecture for performance, resilience, innovation, sustainability, and trust. At StandardsHero, we will continue translating these developments into actionable leadership guidance — helping organizations understand not only which standards are changing, but how they fit together to shape the management systems of the future.