What the standard actually requires
ISO 14001 asks an organisation to work out how its activities affect the environment, decide which of those effects matter, control them, and keep the obligations it is under.
The requirements follow the same clause structure as ISO 9001, with three things that are distinctive to it:
- Environmental aspects and impacts. You identify what your activities, products and services do to the environment — emissions, discharges, waste, land use, resource consumption — and determine which are significant. Everything else in the system follows from this determination, so an auditor examines it closely.
- Compliance obligations. Legal requirements that apply to you, plus obligations you have taken on voluntarily — a customer requirement, an industry commitment, a permit condition. You must know what they are, and you must evaluate whether you are meeting them, which is a requirement organisations frequently underestimate.
- A life cycle perspective. Not a life cycle assessment, which is a different and much larger undertaking, but a requirement to consider effects beyond your own gate: how what you procure was produced, and what happens to what you sell after you sell it.
Alongside these sit emergency preparedness, operational control, monitoring, internal audit and management review.
Do you actually need it?
It is usually worth it when you tender for government or large private contracts in the UAE, where it is frequently required; you hold environmental permits and want a systematic way of staying inside them; you are in construction, manufacturing, logistics, facilities or waste, where customers increasingly ask; or your parent company or investors require environmental reporting you cannot currently produce.
It is worth being clear about what it is not. ISO 14001 is not a sustainability certification, it is not a carbon standard, and it does not certify environmental performance. An organisation with significant environmental impacts can hold ISO 14001 legitimately, because the standard asks whether you manage those impacts, not whether they are small.
What a UMA certificate against ISO 14001 does and does not assert
It asserts that we audited your environmental management system against ISO 14001:2015, for the scope stated on the certificate, and that on the evidence we saw it conforms.
It does not assert that your operations are environmentally sound, that your emissions are within any particular limit, that you hold every permit you need, or that you comply with environmental law. The standard requires you to evaluate your compliance; certification is not a regulator’s finding that you are compliant, and it is not a defence to an enforcement action.
Nor does it make a product “green”. Certification is of the management system, and any claim on packaging that implies otherwise is a misuse of the mark.
How audit time is worked out for this standard
Audit duration for ISO 14001 is determined from the IAF MD 5 environmental management system table — a different table from the one used for ISO 9001, because environmental complexity does not scale with headcount the way quality processes do.
The inputs are the effective number of personnel and a complexity category reflecting the environmental significance of your sector and activities: a chemical plant and an accountancy practice of the same size sit in very different places. The number and nature of your sites also matters more here than in some other standards.
Where ISO 14001 is audited alongside ISO 9001 or ISO 45001, the shared parts of the management system are audited once. We show you the calculation with the quotation.
The cycle
Stage 1, then stage 2, then a certification decision taken by someone who had no part in the audit. Three years, with surveillance in each of the two intervening years — the first due within twelve months of the decision — and recertification before the three years are up.