Understanding ISO: The MOST IMPORTANT concept in ISO management system standards

 

PDCA Cycle

Qudos Management
18 November 2025

The ISO Management System Standards provide frameworks that can help organizations to do things better. Depending on the topic, doing things better could mean being more productive, more secure, safer, more sustainable and so on. Achieving such improvements will help to make an organizations to be more resilient and successful. Qudos has been working with clients on standards-based management systems for over 25 years, and we firmly believe that an efficient, well-implemented system generates benefits that far out outweigh any costs. So, we thought we would share some information that will hopefully, unlock some of those potential benefits. We have put together Understanding ISO - A series of articles and videos that can help you really understand ISO management standards and use that knowledge to build a smarter management system for your organization.

The PDCA cycle is perhaps the most basic and well-known concept in management systems, and it underpins ALL of the relevant ISO standards.

The image below illustrates that for the ISO 27001 Information Security standard. Although each standard has minor differences, the principle and basic structure holds true for all ISO management system certification standards.

ISO 27001 Information Security and the PDCA cycle
ISO 27001 Information Security and the PDCA cycle

The reasoning behind the PDCA cycle

Although we may have our criticisms, most organizations generally do what they do well, and when it doesn't go well, they generally fix it. You'll notice that I use the term 'generally' a couple of times there. We are all aware of the exceptions that can and do occur. However, it's probably fair to say that generally (that word again) DO  perform their processes and when necessary ACT on any issues that arise. By following the relevant ISO standards, and organization can ensure that they more systematically DO things the way intended, and more reliably ACT on any issues. Perhaps even more importantly, they encourage working to PLANS and ensuring that appropriate CHECKS are performed. The PDCA cycle can be thought of in the big picture view of the entire system, and also on more granular level of an individual task or project.

Let's expand on those 4 steps a little.

PLAN

Set business goals and plan activities. Plans might include documented policies, objectives, procedures, schedules etc.

DO

The people in your organization should then perform tasks in accordance with those plans - after all, the plans represent what you believe to be the best way to carry out the tasks.

CHECK

You need to check whether everything is going to plan, and there are numerous mechanisms to do that.

These regular checks are by monitoring and measuring performance, by internal audits, and regular management reviews of the overall system These words may sound very foreboding to some, but they can be very straightforward and positive activities - more like a health check. These internal checks may also be supplemented by external audits by a certification body.

ACT

Where something is wrong or could be done better, you should encourage people to report it, provide suitable means, and then investigate / act on the report. Of course, action to 'put things right' will also occur in organizations that don't have a formal management system. However, often the same problems occur time and again because without a management system, there is a tendency to just take action to deal with the immediate effects of a problem.

One of the great benefits of a management system is the rigour to expand that action to include looking for similar instances of the same problem, taking steps to analyse the root causes, and then eliminate those causes. As your system evolves, it provides your organization with an ever-improving baseline. Where improvements have been made, it acts as a wedge to prevent the gains from being lost.

Of all the concepts used in management systems, the PDCA cycle stands out as the most important to know about and use in designing your management system.

 

The design of our Qudos3 IMS Software is aimed at supporting clients organizations through all stages of the PDCA cycle. As illustrated below.

Qudos3_IMS_Software_Modules_PDCA

The next article in this series is about the often misunderstood concepts of Nonconformity and Corrective Action. Although these are clumsily worded in ISO standards, they can really be used to your advantage. Hopefully, we can help you to achieve that.