Back to Resources
    Guides

    The Definitive ISO Glossary: A Complete Reference for Compliance

    ByEditor·
    Share:
    The Definitive ISO Glossary: A Complete Reference for Compliance

    To navigate the path to certification successfully, your team must understand the precise language used by auditors and international standards. This glossary provides clear definitions for the technical terms you will encounter during your journey.

    A to C: Foundations of Certification

    Access Control: The systematic process of ensuring that only authorized individuals can view or use an organization's sensitive information or physical assets.

    Accreditation: The formal recognition by an authoritative body (such as ANAB) that a Certification Body is competent to perform specific audit tasks.

    Asset: Anything of value to an organization. In the context of ISO 27001, this includes data, software, physical property, and the reputation of the business.

    Business Continuity: The strategic capability of an organization to continue the delivery of products or services at acceptable predefined levels following a disruptive incident.

    Business Management System (BMS): A broad term for the framework of policies and processes used to guide a business. It can refer to a single standard or an integrated system combining several ISO standards.

    Calibration: The activity of checking the accuracy of a measuring instrument against a known standard to ensure its results are reliable.

    Certification: The result of a successful audit where a third party registrar confirms that an organization meets the requirements of a specific ISO standard.

    Compliance Obligations: The legal requirements that an organization must follow, along with any other requirements the business chooses to adopt.

    Configuration: The management and control of changes to a system or product to ensure its integrity is maintained over time.

    Conformity: The fulfillment of a requirement. When your processes match the rules of the standard, you are in a state of conformity.

    Context of the Organization: The internal and external factors that define the environment in which an organization operates and achieves its objectives.

    Continual Improvement: A recurring process of enhancing the management system to achieve improvements in overall performance and customer satisfaction.

    Corrective Action: A reactive process focused on identifying the root cause of a failure and implementing a permanent fix to prevent it from happening again.

    D to I: Operational Excellence and Auditing

    Design and Development: The structured process of creating new products or services, or making significant enhancements to existing ones, while maintaining strict version control.

    Documented Information: The modern term for all information that an organization must control and maintain, including digital files, paper records, and software logs.

    Effectiveness: A measure of whether your planned activities actually achieved the intended results.

    Emergency Preparedness: The planning and procedures implemented to prevent or respond to significant incidents, such as environmental spills or safety emergencies.

    Environmental Aspect: Any element of an organization's activities or products that interacts with the environment.

    Environmental Impact: Any change to the environment, whether harmful or beneficial, resulting from an organization's aspects.

    External Audit: An assessment conducted by an independent registrar to determine if an organization is compliant with a specific international standard.

    External Issues: Factors outside the direct control of the company, such as market trends, new laws, or economic shifts, that influence the management system.

    Hazard: A potential source of harm or a situation with a risk of injury, ill health, or damage to property.

    Hierarchy of Control: A systematic approach to managing risks by prioritizing elimination, substitution, engineering controls, and administrative changes before relying on personal protective equipment.

    Implementation: The practical stage where policies and procedures are moved from paper into the daily operations of the workforce.

    Interested Party: Often called a stakeholder, this is any person or group that can affect or be affected by the decisions of the organization.

    Internal Audit: A self-led, systematic review of processes to ensure the management system is functioning correctly before an external assessor arrives.

    Internal Issues: Factors within the direct control of the company, such as its culture, employee knowledge, and internal infrastructure.

    K to R: Performance and Risk

    Key Performance Indicator (KPI): A quantifiable measure used to evaluate the success of an organization in meeting its strategic and operational goals.

    Leadership: The actions taken by top management to demonstrate commitment to the management system and ensure it achieves its intended outcomes.

    Life Cycle Perspective: An approach in ISO 14001 that considers environmental impacts from the raw material stage through to production, use, and final disposal.

    Management Review: A formal, periodic evaluation by top management to ensure the management system remains suitable, adequate, and effective.

    Monitoring: The ongoing process of checking and observing the status of a system or activity to identify any deviations from the plan.

    Non-conformity: A specific instance where a requirement has not been fulfilled.

    Objective: A specific, measurable goal set by the organization to support its policy and strategic direction.

    Operational Control: The methods used by an organization to manage its processes and ensure they stay within defined limits.

    Preventive Action: A proactive approach to identifying potential failures before they occur. In newer standards, this is largely covered by risk-based thinking.

    Process Interaction: A description of how different departments and activities within a business work together to turn inputs into outputs.

    Risk: The effect of uncertainty on objectives. It can be a threat to be mitigated or an opportunity to be exploited.

    Risk Assessment: The overall process of identifying, analyzing, and evaluating risks to determine if they are acceptable.

    Risk-Based Thinking: A systematic approach across the entire management system that ensures risks and opportunities are considered at every stage.

    S to W: Standards and Workforce

    Scope: A formal statement that defines the boundaries of the management system, including the products, services, and locations covered.

    Statement of Applicability (SoA): A mandatory document in ISO 27001 that lists which security controls the organization has implemented and explains why others were excluded.

    Statutory and Regulatory Requirements: The legal rules and government regulations that an organization must follow to operate legally.

    Supplier Performance: The evaluation of an external provider's ability to deliver goods or services that meet the requirements of the organization.

    Validation: The process of ensuring that a product or service meets the needs of the end user in a real-world environment.

    Verification: The process of checking that a product or service meets the original technical specifications or drawings.

    Vulnerability: A weakness in a system or process that could be exploited by a threat to cause harm.

    Worker Participation: The involvement of staff in the decision-making process, particularly regarding health and safety management.

    Workplace: Any location where work-related activities are performed under the control of the organization.

    Frequently Asked Questions

    What does 'clause' mean in ISO standards?
    ISO standards are structured into numbered sections called clauses. The core requirements of most management system standards (ISO 9001, ISO 27001, ISO 45001 etc.) are contained in clauses 4 through 10. Each clause covers a specific area of the management system, such as leadership, planning, or performance evaluation.
    What is the difference between a major and minor non-conformance?
    A major non-conformance is a significant failure to meet a requirement of the standard, often indicating a complete absence of a required process or a systemic breakdown. A minor non-conformance is an isolated or less critical lapse. Major non-conformances must be resolved before a certificate can be issued; minor ones can sometimes be addressed after certification with a follow-up review.
    What does 'documented information' mean in ISO standards?
    Documented information is the modern ISO term for what was previously called documents and records. It covers any information your organisation is required to control and maintain, whether in paper or digital form. ISO standards specify which documented information is required (mandatory) and which is recommended (discretionary).
    What is the meaning of 'interested parties' in ISO terminology?
    Interested parties (sometimes called stakeholders) are any individuals or groups who can affect, or be affected by, your organisation's management system. This typically includes customers, employees, suppliers, regulators, and local communities. ISO standards require you to identify your interested parties and understand their relevant requirements.
    Share:

    Need Help With ISO Certification?

    Get quotes from accredited registrars and ISO experts.