May 2026: Key Developments in ISO

May 2026 marks a strong shift from establishing governance frameworks toward proving that governance works.

Across quality, sustainability, cybersecurity, artificial intelligence, resilience, and product information, standards are increasingly focusing on the mechanisms that create evidence: auditing, logging, conformity assessment, measurement, traceability, monitoring, and reliable information.

This is particularly evident in the publication of ISO 19011:2026 for management system auditing and the updated ISO/IEC 15408 series for IT security evaluation. At the same time, AI system logging is approaching publication, sustainability work is moving deeper into chain of custody and Extended Producer Responsibility, and biodiversity standardization is beginning to address measurement and monitoring directly.

Three themes dominate May:

Assurance becomes core organizational infrastructure — with new or advanced standards for management-system auditing, IT security evaluation, AI logging, trustworthy electronic information, and conformity assessment.

Sustainability moves from ambition toward traceable evidence — through ecolabelling, SDG management systems, Extended Producer Responsibility, chain-of-custody models, biodiversity measurement, and resource-efficient software.

AI governance moves closer to operational systems — with work on AI logging, lightweight AI, hybrid inference, AI in space systems, and stronger links between AI governance and system architecture.

For top management, May delivers a clear message: organizations increasingly need to demonstrate not only that policies and management systems exist, but that decisions, claims, technologies, and processes can be measured, traced, audited, and trusted.

Newly published standards

ISO 19011:2026 – Guidelines for auditing management systems
One of the most significant management-system publications of the month. ISO 19011 provides the common foundation for auditing management systems and therefore plays a central role in how organizations evaluate whether governance frameworks actually work in practice.

ISO 9000:2026 – Quality management — Fundamentals and vocabulary
Updates one of the foundations of the ISO quality-management family. A shared understanding of quality concepts and terminology remains essential as quality management increasingly interacts with digitalization, sustainability, data, automation, and complex value networks.

ISO 14024:2026 – Environmental statements and programmes for products — Ecolabels
Strengthens the framework behind environmental labelling. As environmental claims receive greater scrutiny, credible ecolabels become increasingly important mechanisms for translating environmental performance into trusted product information.

ISO/IEC 15408-1:2026 – Evaluation criteria for IT security — Part 1: Introduction and general model

ISO/IEC 15408-2:2026 – Evaluation criteria for IT security — Part 2: Security functional components

ISO/IEC 15408-3:2026 – Evaluation criteria for IT security — Part 3: Security assurance components

ISO/IEC 15408-4:2026 – Evaluation criteria for IT security — Part 4: Framework for the specification of evaluation methods and activities
Together, the updated ISO/IEC 15408 series strengthens one of the central infrastructures for evaluating IT security.

The significance extends beyond cybersecurity teams. As organizations become dependent on digital products, platforms, AI systems, and connected supply chains, structured security evaluation increasingly becomes part of organizational assurance and digital trust.

ISO 15801:2026 – Document management — Electronically stored information — Requirements and guidance for trustworthiness and reliability
Addresses a fundamental governance question: can electronically stored information be trusted?

This becomes increasingly important as digital records are used as evidence for compliance, transactions, product information, audits, sustainability claims, and automated decision-making.

ISO/IEC TR 5259-6:2026 – Artificial intelligence — Data quality for analytics and machine learning — Part 6: Visualization framework for data quality
Extends the ISO/IEC 5259 work on AI data quality into visualization. Making data quality understandable and visible is important not only for technical teams but also for governance, assurance, and decision-making around AI systems.

ISO 28219:2026 – Packaging — Labelling and direct product marking with linear bar code and two-dimensional symbols
An important development for physical-digital identification. Reliable marking and machine-readable identification are becoming increasingly important as products connect to digital information, traceability systems, regulatory information, and automated supply chains.

ISO/IEC 26565:2026 – Software and systems engineering — Methods and tools for product line maturity framework
Supports organizations managing complex families of software and systems by providing a maturity-oriented framework for product-line engineering.

ISO/IEC/IEEE 23612:2026 – Software and systems engineering — Incident management
Strengthens the systematic management of incidents across software and systems environments, connecting operational governance with resilience, continuity, learning, and corrective action.

Final Draft International Standards (FDIS): Editorials before publication

ISO/UNDP 53001 – Management systems for United Nations Sustainable Development Goals (SDGs) — Requirements
One of the most strategically important management-system developments of 2026 continues toward publication. ISO/UNDP 53001 moves the Sustainable Development Goals from a broad strategic framework toward a structured management-system approach. The significance is considerable: organizations will have a more formal mechanism for translating SDG commitments into objectives, governance, implementation, measurement, and continual improvement.

ISO/IEC FDIS 24970 – Artificial intelligence — AI system logging
AI logging is a critical part of operational AI governance. Organizations cannot effectively investigate incidents, demonstrate accountability, monitor system behaviour, or support assurance without appropriate records of what an AI system has done. This standard represents another important step in moving AI governance from principles toward technical evidence.

Draft International Standards (DIS): Nearing publication

Committee Drafts (CD): Key Standards in Progress

May shows strong activity around resilience, AI architecture, sustainability evidence, and organizational performance.

ISO/CD 22301 – Security and resilience — Business continuity management systems — Requirements
The revision of one of the central standards for organizational continuity continues. Business continuity is increasingly connected to cyber incidents, supply chain disruptions, climate risks, infrastructure dependencies, and geopolitical uncertainty. The revision therefore has implications well beyond traditional continuity planning.

ISO/CD 22331 – Business continuity management systems — Guidelines for business continuity strategies and solutions
Complements ISO 22301 by focusing on how organizations translate continuity requirements into appropriate strategies and solutions. Together, the two projects reinforce the shift from continuity plans toward designed organizational resilience.

ISO/CD 14077 – Environmental management — Life cycle assessment — Requirements and guidelines for application of Chain of Custody models in Life Cycle Assessment
A particularly important development for credible sustainability information. Environmental information increasingly needs to move through complex value chains. Chain-of-custody models provide mechanisms for maintaining the connection between environmental attributes, materials, products, and claims. This links sustainability reporting directly with traceability and evidence.

ISO/IEC CD TS 42111 – Artificial intelligence — Guidance on lightweight AI systems
Extends AI standardization toward systems designed for constrained environments. As AI becomes embedded in devices, products, industrial equipment, and edge environments, governance and technical requirements need to work beyond large centralized AI platforms.

ISO/IEC CD TS 25258 – Artificial intelligence — Hybrid AI inference framework for AI systems
Addresses architectures where AI inference may be distributed or combined across different environments. This reflects a wider change in AI standardization: attention is increasingly shifting from individual models toward the architecture of complete AI-enabled systems.

ISO/CD 30442 – Human Resource Management — Performance Management — Guidelines Develops a more structured approach to performance management, connecting objectives, people, feedback, capability, and organizational results.

ISO/CD 37201 – Management systems to prevent and combat violence against women in organizations — Requirements with guidance for use
Shows the continued expansion of management-system thinking into social and organizational governance issues, providing structured requirements for prevention, response, leadership, and organizational responsibility.

ISO/CD 20671-5 – Brand evaluation — Part 5: Vocabulary
Continues the development of a common framework around brand evaluation and measurement, reinforcing the broader trend toward making previously intangible organizational assets more systematically defined and evaluated.

New work items and early-stage developments

May’s new projects reveal several important directions for future management and governance standards.

1. Sustainability becomes traceable across value chains

ISO/AWI 26259 – Circular Economy — Extended Producer Responsibility (EPR) — Requirements and guidelines for implementation

A potentially significant development for circular economy governance. Extended Producer Responsibility is becoming an increasingly important mechanism for connecting producers with the downstream impacts and end-of-life management of products. Standardization in this area could help establish more consistent approaches to responsibilities, implementation, information, and performance across value chains.

Combined with ISO 14077 on chain of custody, this points toward a broader development: circularity increasingly requires traceable responsibility. Organizations need to understand not only what happens to products, materials, and environmental attributes, but also who is responsible at different stages of the lifecycle.

2. Biodiversity moves toward measurement infrastructure

ISO/PWI 26799 – Biodiversity — Guidelines and requirements for Measurement, Data, Monitoring, and Assessment

An important early-stage development. Biodiversity governance cannot mature without credible mechanisms for measurement, data collection, monitoring, and assessment. The project therefore addresses one of the fundamental challenges in turning biodiversity commitments into measurable organizational action.

The direction resembles earlier developments in climate and environmental management: first establish terminology and principles, then develop measurement frameworks, and eventually build the assurance infrastructure needed to support credible claims and decisions.

3. AI governance expands into architecture and specialized environments

ISO/NP TS 26776 – Guidelines for the management of use of Artificial Intelligence (AI) for space systems

Shows how AI governance is beginning to move into sector-specific and high-consequence applications. Space systems combine autonomy, complex software, limited human intervention, high reliability requirements, and extreme operating conditions — making them an important environment for developing mature AI management approaches.

ISO/IEC/IEEE AWI 42020 – Enterprise, systems and software — Architecture processes

ISO/IEC/IEEE AWI 42030 – Enterprise, systems and software — Architecture evaluation framework

The revision of these architecture standards is particularly relevant as organizations increasingly need to govern systems that combine software, AI, data, cloud services, devices, platforms, and external dependencies. Good governance increasingly begins with architecture. If responsibilities, interfaces, dependencies, and system boundaries are unclear at the architectural level, they become difficult to manage later through policies and controls.

4. Digital infrastructure becomes a sustainability issue

ISO/IEC AWI TR 26806 – Information technology — IT and sustainability — Resource-efficient software landscape

A notable signal that sustainability is moving deeper into software and digital infrastructure. Software may appear intangible, but architectural choices, computation, storage, networks, hardware utilization, and software efficiency all influence resource consumption. As AI and cloud workloads grow, the resource efficiency of digital systems is likely to become an increasingly important part of sustainability governance.

5. Digital currencies require a common language

ISO/NP 26611 – Digital currencies — Taxonomy

Creates a foundation for more consistent discussion of digital currencies. Taxonomy may seem basic, but shared terminology is essential before interoperable rules, risk frameworks, reporting, technical standards, and regulatory approaches can develop. The work reflects the broader institutionalization of digital assets and currencies within financial infrastructure.

6. Regional resilience becomes an economic capability

ISO/AWI 22365 – Security and resilience — Community resilience — Guidelines for enhancing resilient regional economies

Extends resilience thinking beyond individual organizations. Supply chains, infrastructure, public services, businesses, institutions, and communities increasingly depend on each other. Regional economic resilience therefore requires coordination across organizational boundaries. This represents an important expansion of resilience from organizational continuity toward ecosystem resilience.

7. Consumer information becomes part of the trust infrastructure

ISO/IEC CD Guide 14 – Products and related services — Information for consumers

Consumer information is becoming increasingly important as products become more complex and more information is delivered digitally. Safety, sustainability, instructions, repair information, environmental claims, warranties, and product characteristics increasingly depend on organizations being able to provide information that is understandable, accessible, reliable, and connected to the correct product. The development connects closely with wider trends in product transparency, digital product information, and machine-readable identification.

8. Terminology remains critical infrastructure

ISO/AWI 29383 – Terminology policies — Development and implementation

As organizations increasingly depend on interoperable data, AI, automated processes, and cross-organizational information exchange, terminology becomes more than a documentation issue. Shared concepts and definitions form part of the infrastructure required for systems — and people — to interpret information consistently.

Looking Ahead

May 2026 reveals an increasingly clear pattern across the standards landscape: governance is becoming evidence-based. Management systems establish expectations, but organizations are increasingly expected to demonstrate that those expectations are actually being met. Auditing evaluates whether management systems work, logging creates records of system behaviour, security evaluation tests technical controls, chain of custody connects claims with materials and products, monitoring turns biodiversity commitments into measurable information, and trustworthy electronic records preserve evidence over time. Conformity assessment then provides structured ways of demonstrating that defined requirements have been fulfilled.

This development is particularly important for AI and sustainability, where the discussion is rapidly moving from commitments and principles toward proof. Organizations need to show that AI systems behave as intended, that decisions and incidents can be reconstructed, that environmental information relates to the correct product or material, and that sustainability attributes and responsibilities can be maintained across complex value chains. This is creating a new layer of organizational infrastructure built around identity, traceability, measurement, logging, auditing, and assurance.

For top management, the implication is significant. The next generation of governance will not primarily be defined by how many policies or management systems an organization has, but by whether it can produce trustworthy evidence that its systems, products, information, people, and value chains perform as intended. At StandardsHero, we will continue translating these developments into actionable leadership guidance — helping organizations understand how emerging standards are transforming governance from policies and commitments into measurable, auditable, and trustworthy organizational capability.