ISO 9001, Quality Management, is the world’s most widely adopted management system standard, published by the International Organization for Standardization, with over one million certifications issued worldwide. It certifies that an organization runs a documented, consistent process for meeting requirements and improving over time. It says nothing about security. ISO 9001 and ISO 28000, already covered on this site, share the same underlying high-level structure, which makes the two easy to confuse even though they answer entirely different questions.
What ISO 9001 actually certifies
ISO 9001 is built around a specific, repeatable model for managing quality across an entire organization.
- The Plan-Do-Check-Act cycle, applied to the organization’s processes to drive continual improvement rather than a one-time fix.
- A process approach, treating the organization as a set of interacting processes managed toward a consistent, intended result.
- Risk-based thinking, made explicit in the 2015 revision, requiring the organization to identify what could cause its processes to deviate from planned results and address it proactively.
Why ISO 9001 and ISO 28000 are easy to confuse
Both standards follow the same Annex L high-level structure that ISO uses to harmonize its management system standards, so they read similarly and integrate easily within one organization. That structural similarity is exactly why the two get mistaken for covering the same ground.
- ISO 9001 asks whether a process consistently delivers its intended quality outcome, on time, to specification, meeting customer expectations.
- ISO 28000 asks whether that same process is protected against a security threat, theft, tampering, or deliberate interference, already covered in detail on this site.
- A company can hold a valid ISO 9001 certificate with zero security controls in place, since quality and security are simply not the same question.
What a quality certificate does not tell you
Seeing “ISO 9001 certified” on a courier’s or forwarder’s marketing material confirms their internal processes are documented, monitored, and improved over time. It confirms nothing about whether your specific high-value shipment is protected from an unattended parking stop, a mishandled customs hold, or deliberate tampering, the exact risks already covered under ISO 28000 and TAPA on this site.
Where the two standards genuinely work together
Because both use the same Annex L structure, an organization can integrate ISO 9001 and ISO 28000 into one combined management system rather than running them as separate, disconnected programs. Quality processes and security controls end up documented, audited, and improved under the same overarching framework, even though each answers its own distinct question.
Why this distinction matters when choosing a courier partner
A consistent, well-documented process is genuinely valuable, and an onboard courier mission benefits from exactly that kind of quality discipline: a repeatable brief, quote, and delivery process, done the same reliable way every time. But quality alone does not answer the security question. Continuous personal custody, already covered for the highest-risk shipments on this site, is the concrete control that answers it.
How OBC ONE combines quality process with real security
A typical mission runs through six steps with OBC ONE, most of which overlap to save time.
- Brief and quote. You share the shipment, its requirements, origin, destination, and the deadline. OBC ONE returns an all-in quote in under 15 minutes.
- Courier assignment. A vetted courier near the origin is dispatched immediately.
- Secure pickup. The shipment is collected directly, verified before departure.
- Personal custody in transit. The courier carries the shipment in the cabin, staying with it through every connection.
- Direct delivery. Handover happens with the named recipient, not a facility or depot.
- Proof of delivery. Timestamped confirmation for your records.
Why freight forwarders trust OBC ONE with both quality and security
Choosing the right partner starts with the business model. Many specialty couriers sell directly to shippers, which puts them in competition with the forwarders who might otherwise use them. OBC ONE is built the opposite way: we work exclusively for and with freight forwarders and time-critical desks. We never approach your clients directly and never compete with you.
That partner model is backed by real operator experience. OBC ONE was founded by an onboard courier who personally flew roughly three million kilometers over six years, so the network understands the difference between a documented process and a genuine security control. Forwarders use us because we deliver:
- An all-in quote in under 15 minutes, 24/7/365.
- 1,500+ vetted couriers positioned around major hubs worldwide.
- True door to door coverage, with import and export customs clearance and Importer of Record service in most markets.
- IATA certified dangerous goods capability for shipments that require it.
- One specialty, onboard courier and hand carry for time-critical missions, done at the highest standard.
How to choose a partner who understands both quality and security
- A consistent, repeatable process, not a one-off arrangement improvised per shipment.
- Genuine continuous custody, the concrete security control a quality certificate alone does not provide.
- Fast, transparent quoting, ideally with a named dispatcher accountable for the mission.
- Real network density near major hubs, so the courier is not delayed by being flown in first.
- A forwarder-only model, so your partner never becomes a competitor for your clients.
Frequently asked questions
What is ISO 9001?
ISO 9001 is the world’s most widely adopted management system standard, certifying that an organization runs a documented, consistent process for meeting requirements and improving over time, with over one million certifications issued worldwide.
Is ISO 9001 the same as ISO 28000?
No. Both share the same high-level Annex L structure, but ISO 9001 certifies quality, whether a process consistently delivers its intended outcome, while ISO 28000 certifies security, whether that process is protected against theft or tampering.
Can a company be ISO 9001 certified without any security controls?
Yes. ISO 9001 does not address security at all, so a valid quality certification says nothing about whether security measures are in place.
What is risk-based thinking in ISO 9001?
Introduced explicitly in the 2015 revision, risk-based thinking requires an organization to identify what could cause its processes to deviate from planned quality results and address it proactively, rather than only reacting after a nonconformance occurs.
Can ISO 9001 and ISO 28000 be implemented together?
Yes. Because both follow the same Annex L structure, an organization can integrate quality and security management into one combined system rather than running separate, disconnected programs.
Do you sell directly to shippers or buyers?
No. OBC ONE works exclusively with and for freight forwarders and time-critical desks. We act as a white label partner and never approach our clients’ customers directly.
Get a partner with both a reliable process and real custody
If you are a freight forwarder who wants consistent quality and genuine security in the same partner, OBC ONE gives you a straight answer, 24/7, worldwide and never a competitor. Contact our team for an all-in quote in under 15 minutes, or explore more time-critical logistics insights.



