Agile ISO: How to Combine Compliance with Rapid Process Improvement

A quality and compliance lead reading a precision dial gauge, illustrating how to combine ISO 9001 compliance with agile, rapid process improvement.

ISO compliance used to mean thick binders and a slow, painful process for changing how any task was done. The 2015 revision of ISO 9001 quietly changed that. It gave organizations far more freedom over how much they document and how they store it, which opens the door to software, rapid iteration, and work instructions built from the bottom up rather than dictated from the top down.

Agile ISO is our name for how you combine compliance with the rapid process improvement of a startup. It keeps the rigor and auditability that ISO 9001 demands while letting you build, run, and improve processes at speed. This guide explains what ISO is, what ISO 9000 and ISO 9001 actually ask for, why the current standard is agile friendly, and how to put Agile ISO into practice.

In this Process Street guide, we will cover:

  • What is ISO?
  • What is ISO 9000?
  • What is Agile ISO?
  • What is needed to support Agile ISO?
  • How to get started with Agile ISO in 5 easy steps

What is ISO?

When people talk about ISO they are talking about the International Organization for Standardization, which produces a wide range of standards that businesses can choose to comply with to demonstrate operational quality.

A catalog of ISO standard families showing ISO 9001 for quality and ISO 14001 for environmental management, each with a certification status.

ISO is headquartered in Geneva and works alongside the national standards bodies around the world that produce country specific standards. In the United States, that would be the American National Standards Institute and its range of affiliated bodies.

If you can demonstrate that the management structures in your business adhere to ISO 9000, then other businesses, nationally and globally, can see that you operate competently. That gives the companies you work with a degree of assurance that you operate at a high standard.

The same is true of the other ISO standards. To improve your environmental impact, you might decide to only do business with companies that can demonstrate compliance with ISO 14000, the family of standards for managing an organization while being aware of, and willing to tackle, its environmental impact.

You may have heard of ISO 9001 or ISO 14001. These sit at the heart of their respective families and define the management systems that underpin the rest of the standards in each family.

What is ISO 9000?

ISO 9000 is concerned with how well you run your business operations. It wants you to have a quality management system (QMS) and a set of quality assurance policies, and it tells you which documents to keep as records to demonstrate that you are taking this seriously.

The seven ISO 9001 management-system clauses, from Context of the Organization through Improvement, shown as an auditable control checklist.

That is the long and short of it.

A quality management system, defined

A quality management system is an attempt to align all of a business’s operations around achieving quality. For many businesses, the temptation is to reduce a QMS to a tidy chart they can show off, an image of every part of the business working in harmony. But having a diagram is not enough for ISO 9001. The system has to be implemented and functional throughout the company.

A quality management system is always more complicated than the graphics used to convey it. In its simplest form it breaks down into three and a half parts:

  1. Document how everything in your business works and how it aligns with your objectives.
  2. Document how you are going to continuously improve this in your business.
  3. Document what you have done and changed during those improvements, and update whatever you wrote for step 1.
  4. Repeat indefinitely.

It is all centered around the idea of quality. If you want a deeper discussion of quality in a business setting relevant to quality management systems, read this companion piece: How to Use The Deming Cycle for Continuous Quality Improvement.

Deming treats quality as something a business can build a theory around. That theory becomes the driving force for the business. The quality management system is the organizational tool that runs experiments on the assumptions in that theory and updates the theory accordingly.

Having a clear concept of quality in your business lets you measure whether something you did was good, in other words whether the outcome aligned with your idea of quality. For example, if someone offers to significantly reduce your costs by partnering with them, but product quality drops and environmental impact rises, what do you say? Deming would say the answer depends on your conception of quality.

A QMS in plain terms

A QMS is simply the set of policies you have for the company along with all the processes you follow to run it. It covers the measures you take to implement and improve those policies and processes. You need something like a quality policy in place so you can judge whether your improvements are actually improvements.

You will want things like:

  • Clear quality objectives.
  • A quality policy that has been communicated throughout the company.
  • A clear map of your organizational structure, ideally including who is responsible for what.
  • Proper documentation of your operating processes, think process manual, but one people actually use.
  • Documented efforts to improve product quality, and to understand what that means in the minds of your customers.
  • A system for improving processes, something that produces continuous improvement.
  • A single place where anyone can find all of this information, plus details of how that place is managed.

We will look at this in more detail next, but you get the idea of what a whole QMS looks like.

From a QMS to ISO 9001 compliance

Having a QMS gets you most of the way, but not all of it. To reach ISO 9001 you have to show you have implemented seven main sections. These are your policies, not your procedures.

  • Section 4, Context of the Organization. Document relevant information about your company and its position in the market: what kind of company you are, how you are structured, and the external factors around you. That includes other companies you work with, the customers you sell to, unions you consult, banks or investors you deal with, and your competition. These are all interested parties. Include the things that genuinely affect your QMS.
  • Section 5, Leadership. This expands on the structure. Having described how the organization is structured, document the responsible people within it and what they are accountable for, with reference to the specific procedures in your manual.
  • Section 6, Planning for the Quality Management System. This section is largely about your QMS methodology and how you implement it. You might weigh a properly implemented Deming cycle using PDSA against a Six Sigma technique like DMAIC. You could choose a methodology for constructing new processes, such as DFSS, or a predictive testing method like FMEA. Document which methods you will use and explain how they will be implemented.
  • Section 7, Support. How will you support this quality management system? Work out whether you need specialist software, machinery, or equipment for your team to run the QMS day to day, and what training staff need to do it properly. Add how you will document your procedures and communicate them, and the QMS as a whole, to everyone.
  • Section 8, Operation. Get specific about how you manage your processes. Cover the products or services you offer and how your procedures support them, show that a process sits behind every decision, and show that sufficient testing has taken place. Include how you decide whether a process succeeded, and what you do when you create defects or non-conforming outputs: record it, resolve it with the customer, and stop it happening again. Operation is the longest section, so see this fuller summary from the 9000 Store for more detail.
  • Section 9, Performance Evaluation. Decide how you will measure the performance of your QMS. What are your metrics? How will you analyze them? Who is responsible? In effect you build a quality management system for your quality management system, and it is systems all the way down. All of it has to accommodate internal audits and management reviews, so you need a schedule and a process for those too. ISO 19011:2026, the current edition, provides guidelines for auditing management systems, including remote and digital-evidence audits, and ISO 9004:2018 gives you a self-assessment tool for gauging how well your ISO 9000 implementation is going.
  • Section 10, Improvement. This is essentially a what we learned section with a bit of what we will do next. Record the changes you have made to the business thanks to the new quality management system, your considerations for future improvements, and the times things went wrong along with what you did to make sure they will not happen again.

Two quick notes on where the standard sits today. The current certifiable version is still ISO 9001:2015, now including the Amendment 1:2024 that folds climate action into the context of the organization. An updated ISO 9001:2026 is expected around September 2026 with mainly editorial refinements, a stronger emphasis on quality culture, and a transition period running to 2029. None of it changes the core point below.

Now that you know what ISO 9001 is and what you need to be compliant, we can look at making it function. This is the fun part.

What is Agile ISO?

Agile ISO is about taking the rigid old world of ISO standard operating procedures and replacing it with digital tools, where process iterations can be rapid and work instructions can be created from the bottom up, not only from the top down.

A comparison of a rigid static paper procedure manual on one side and a living, iterating digital workflow library on the other.

We are not storming the ISO Bastille. We are being invited in. The current ISO 9000 is the 2015 revision, which built on and adapted the 2008 version, and it carries a host of content that lets companies be far more agile and flexible in their approach.

The 2015 revision opened the door to agile

People wondered for a long time whether agile and ISO style approaches could be married together, and it turns out the architects of the 2015 version were thinking about the same thing.

The current versions let the organization itself judge how much documentation is required to achieve specific business goals from its processes.

“This enables each individual organization to determine the correct amount of documented information needed to demonstrate the effective planning, operation and control of its processes and the implementation and continual improvement of the effectiveness of its QMS.” – From the ISO/TC 176

The standard also lets organizations focus on aligning their operations with specific business goals rather than building one monolithic QMS that covers the whole company like a Frankenstein outsider. The QMS can be a set of integrated practices within departments or teams, to the extent that it serves strategic goals.

So if I wanted to run some PPC ads on social media, I could hire people who are good at it, give them a budget, and tell them to run ads and test until they come back with something that works. I would still be ISO compliant, despite no prior planning or process creation, as long as those ad managers adhere to the spirit of company policies.

The third point worth mentioning is that procedures can be stored digitally as well as on paper. No more dusty manuals nobody reads. Under the current standard, documented information can live in the cloud, and the 2015 shift from “documents and records” to “documented information” is exactly what makes a software-first QMS legitimate.

Cloud storage is what makes it agile

Once your procedures live in the cloud, you can use technology to get past the difficulties that used to come with ISO.

Both Nathan Sykes and the academics Tor Stalhane and Geir Kjetil Hanssen have made the point that fully conforming to ISO could create more paperwork and prior planning than an agile setup allows, and that the extra documentation could undo the benefits of agile process improvement. Their research found that a large share of ISO 9001 requirements are already satisfied by standard agile practice, and they propose underdocumenting procedures while still adhering to the quality policies and assurances ISO 9001 asks for. Their view is that you can pass the audit as long as you stay well aligned with strategic goals.

But you should not decide how documented a process needs to be on the basis of what agile theory says, nor on the basis of what a committee in Geneva says. You should decide it by the nature of that specific process.

Some processes need detailed procedure steps and extensive work instructions. Others need one but not the other. Every process is different, and your documentation should reflect your business needs and nothing else.

It is the agile vs waterfall debate. Some processes need planning out in detail from the start. Others can just get going and form a process as experimentation continues and different stakeholders weigh in on what works and what does not.

Agile ISO is about using software to build fully developed process libraries where you need them, while also being able to quickly build new processes in collaboration with others and iterate them rapidly over time. It is about doing both of these things and still earning ISO accreditation.

What is needed to support Agile ISO?

To enable Agile ISO in an organization you need software that can do several things:

A Process Street process library with a nested folder tree, managed permissions, and a revision history panel for each procedure.
  • Build rich process libraries with multiple folders, subfolders, and managed permissions.
  • Build large, detailed procedures filled with work instructions, media, and reference guides.
  • Interact dynamically with procedures as process instances, capturing information through form fields.
  • See when a process was followed, who followed it, and what progress was made.
  • See the revision history for a procedure, so you know how it was updated, when, and by whom.
  • Enforce specific procedural paths through features like stop tasks and conditional logic.
  • Quickly create new processes, assign them to individuals or teams, and collaborate on their construction and execution.
  • Update a process model and immediately push the new revision live for use.

With that feature set in place, you can bring the best of business process management, agile methodologies, and ISO standards into one practical method of process management.

Your process library acts as a living, complete process manual. Each procedure’s revision history records the date, time, and person. Procedures can be complex or simple, assigned or scheduled, even triggered automatically by the completion of other tasks. This library of digital SOPs is a manual that keeps itself current.

The best part is that when an employee sets out to complete a task, they just follow a checklist that walks them through the process. That raises process adherence, improves output, and builds accountability, because unlike a dusty procedure manual, these processes actually get followed.

This is also where modern tooling pulls ahead of the ISO world of a decade ago. A Compliance Operations Platform pairs governed documents with executable workflows and adds built-in AI that watches how work actually runs, flags missed steps and drift, and suggests improvements. Instead of finding gaps during an audit, you keep an audit-ready record continuously, which is exactly what an agile approach to ISO needs.

So how do we begin with this?

How to get started with Agile ISO in 5 easy steps

The answer, as you have probably guessed, is Process Street.

A Process Street workflow run turning an ISO procedure into governed tasks with an assignee, an approval step, and monitored progress.

Process Street does everything described above, and more. You create workflows and then run them, so the workflow acts as a process model and each run is a single instance of that model. That makes it simple to build processes and even simpler for employees to follow them: it is as easy as working through a checklist.

Process Street also connects directly to thousands of the systems you already use, and when you need an integration that does not exist yet, an AI agent can build it on the fly. That keeps your compliant workflows wired into the rest of your stack without waiting on engineering.

Here is what to do to become ISO compliant using our Agile ISO method:

  1. Build your processes in Process Street. If you do not already have documented processes, get your team members or team leaders to build out their own processes in Process Street. It should take very little time to create a rough skeleton with some accompanying work instructions. Keep it simple, then improve it over time.
  2. Create your folder architecture. Review our post on process libraries for inspiration. Use folders, subfolders, and tags, and manage permissions so that some folders (proprietary, financial, legal) stay private. Then move the workflows your teams created into their corresponding homes.
  3. Design your meta-processes. These are processes for improving processes, for risk assessment, for creating new processes, style guides, and so on. They manage your other processes. A couple of examples:
    1. FMEA Template: Failure Mode and Effects Analysis
    2. The Process for Optimizing a Process
  4. Write your policies. These are the sections we covered earlier: Context of the Organization, Operation, Support, and the rest. Draft them and get input from others in your company.
  5. Create your first official document. Keep a folder in your process library for your policies. You will not run these as workflows, but it makes sense to keep every document in one system. Both workflows and individual runs can be exported to PDF if you ever need to present the documents physically. Your first official document can be your quality management system mini-manual. Use this ISO 9000 structure template below to help you build it.

And there you have it. With Process Street you do not have to update every copy of a physical manual each time you want to make a small improvement. You can quickly create new and improved processes that are easy to follow and compliant with ISO.

If you are not sure what your processes will look like once they are in Process Street, browse this list of premade workflows to find something close to a process you already run. You can add any template to your Process Street account to test it and see how it works.

Sales processes

PPC checklists

Agile software processes

Inspection checklists

Property management checklists

Ready to make ISO compliance feel less like paperwork and more like the way you already work? Build your first workflow in Process Street and put Agile ISO into practice.

Get our posts & product updates earlier by simply subscribing

Take control of your workflows today