On 22 June 2026, ISO published ISO 30201:2026, Human resources management systems — Requirements. It is the first Type A management system standard to come out of ISO/TC 260 — the first HR standard written to be certified against rather than merely consulted. It is built on the Plan-Do-Check-Act cycle and follows the Harmonized Structure shared with ISO 9001, ISO 14001, and ISO 45001, which means it is designed to sit inside an organization’s integrated management system rather than beside it.
This is a consequential document. It is also, at twenty-three pages, a deliberately thin one — and the thinness is the design, not a defect.
Clause 8, Operation, enumerates fourteen process areas: operational planning and control, workforce planning, workforce allocation, remuneration and rewards, recruitment, onboarding, learning and development, knowledge management, talent management, performance management, succession planning, workforce mobility, exit from employment, and human capital reporting. Fourteen sub-clauses across roughly three pages. The standard’s own introduction is explicit about why: it positions itself as an overarching framework for HR management activities and for other TC 260 documents, pointing directly at Clause 8 as the place where that connection is made.
Clause 8, in other words, is an index. It establishes that a conforming organization must have a process. It delegates the question of what a defensible process looks like to the guidance standards that sit behind each function.
Diversity and inclusion is not among the fourteen.
Two readings, and a third
The first reading is political. ISO 30415:2021 carries “diversity and inclusion” in its title in a year when those words have become contested in one of ISO’s largest member markets. On this reading, the omission is a quiet accommodation.
The second reading is structural. D&I is not a life-cycle function in the way recruitment or succession planning is. It is cross-cutting. Cross-cutting concerns belong in Clause 4 (context and stakeholder needs), Clause 5 (leadership), and Clause 6 (risks and opportunities) — not in Operation. On this reading, nothing was avoided; a category was respected.
I am not going to adjudicate between them, and I would encourage anyone entering this conversation to resist the pull to do so. The drafting record is not public. Motive is not in evidence. And a claim about intent is the weakest ground to stand on, because it can be refuted by a single committee minute while the substantive argument it was carrying goes down with it.
Here is what does not depend on which reading is right:
The effect is the same either way. An organization pursuing certification to ISO 30201 will work from the requirement text and from Annex C, the conformity checklist that sets out suggested evidence. What is not named there is what an auditor is not obliged to ask about. Whether that outcome was chosen or inherited, it is the outcome.
That is a bounded claim. It survives any disclosure about how the document came to be written. Build the argument there.
“Not required” is the wrong axis
The rationalization is already predictable, and it will arrive in a reasonable voice: ISO 30415 was always guidance. ISO 30201 is requirements. If the requirements standard doesn’t reference it, it isn’t required. We can defer it.
This mistakes what a Type A management system standard does.
ISO 30201 does not tell an organization what its objectives should be — it says so in its own scope, explicitly declining to determine strategy or objectives. What it requires is that the organization understand its context, identify the needs and expectations of workers and other stakeholders, determine and address risks and opportunities, monitor and measure, and take corrective action on nonconformity. It requires a system that can demonstrate it is working.
Those requirements generate questions. ISO 30415 answers them.
If Clause 4.2 requires understanding worker and stakeholder needs, an organization has to be able to say whose needs, determined how, and with what evidence that the determination was not systematically skewed. If Clause 6.1 requires addressing risks, an organization has to identify the risk that its recruitment, allocation, promotion, and exit processes produce differential outcomes it cannot account for. If Clause 9 requires monitoring, measurement, and internal audit, an organization has to decide what it measures — and a measurement regime that cannot detect adverse impact is a measurement regime with a hole in it.
ISO 30415 supplies the vocabulary for exactly this work: adverse impact, bias, equity, fairness, accountability. Note what those terms are. They are not identity terms. They are process-control terms — the language of how you know a system is functioning as designed. They belong in an audit conversation because they describe failure modes, and a management system standard that could not accommodate them would be an incoherent management system standard.
The correct statement is not that ISO 30415 is optional under ISO 30201. It is that ISO 30201 asks questions an organization cannot answer well without it.
Exclusion is a nonconformity
There is a formulation I have been working with for several years, and this is the moment it stops being rhetorical and becomes operational:
DEI is not the defect — exclusion is.
That is not a slogan. It is a claim about where fault is located in a system. And it is the identical claim that every management system standard ever written already makes.
Consider what ISO 30201 does in Clause 10.2, Nonconformity and corrective action. When a system produces an output that does not conform, the standard does not permit an organization to locate the fault in the input material. It requires the organization to interrogate the process — determine the cause, establish whether similar nonconformities exist elsewhere, correct the process so the output changes, and verify the correction. That is the entire epistemology of a management system: defects are properties of systems, and systems are correctable.
Now apply it. When an organization’s intake, allocation logic, advancement criteria, or exit pattern produces outcomes it cannot account for, there are exactly two places to put the defect. Either the people are wrong, or the system is. Quality management answered that question in the 1950s. Safety management answered it again. ISO 30201 has now imported that answer into the management of human capability and made it certifiable.
This is why “not required” collapses on contact with the standard’s own logic. Exclusion is not an external social concern that a management system may elect to consider. Exclusion is a nonconformity in the HR management system — a process producing outputs that do not meet stated objectives, undetected because the measurement regime was never designed to see that class of failure. Clause 9 requires monitoring, measurement, and internal audit. Clause 10.2 requires correction of what is found. ISO 30415 is the instrument that makes this class of defect visible.
An organization that certifies to ISO 30201 while declining the guidance that would let it detect this failure mode has not built a compliant system. It has built a system with a blind spot and a certificate.
A three-layer stack
The clearest way to hold these instruments together is to stop treating them as competitors for the same ground.
ISO 30201 establishes what must exist. A system, with a policy, objectives, defined roles, worker consultation, operational processes across the life cycle, measurement, audit, and improvement. Requirements. Certifiable.
ISO 30415 establishes what good looks like inside that system. Its scope reaches further than the HR life cycle alone — into products and services, supply chain relationships, and relationships with external stakeholders — and it carries its own checklist of D&I actions in Annex A. Guidance. Auditable in practice, as the attestation market that has grown up around it demonstrates.
The Global Diversity, Equity and Inclusion Benchmarks establish where an organization actually stands. A maturity model, developed independently of ISO, that lets an organization locate itself on a progression rather than pass or fail a threshold.
Requirements, guidance, benchmarks. Three different jobs. An organization that certifies to 30201 and stops has built a system it cannot evaluate. An organization that benchmarks without a management system has diagnosis without infrastructure.
The architecture argument
There is a reading of ISO 30201 that I find more interesting than either the political or the structural one, and it is the reading closest to the work I have been doing.
By distributing people-management requirements across fourteen operational process areas — planning, allocation, reward, entry, development, knowledge, advancement, mobility, exit, reporting — ISO 30201 has done something the field has been slow to accept. It has treated the management of human capability as architecture: a set of load-bearing systems that must interoperate, not a program that sits alongside operations and reports on its activities.
That is the premise of the Architecture of Inclusion. Inclusion is not a function. It is a property of how the functions are engineered. It is established in the design of the intake, the allocation logic, the advancement criteria, the measurement regime — or it is not established at all, and no amount of programmatic effort at the periphery will install it retroactively.
The shift this requires is from a programmatic orientation to a social systems orientation — from asking what initiatives an organization runs to asking how its organizational system is designed and whether equitable outcomes are a structural feature of that design or an incidental byproduct of goodwill. Programs are budget lines, and budget lines are cut. Architecture is load-bearing. The distinction is not semantic; it is the difference between a commitment that survives a change in leadership and one that does not.
This is also the answer to the retreat of the past several years. What has been dismantled across a great many organizations is the programmatic layer — the councils, the trainings, the officers, the reporting lines that were always the most visible and the least structural. What has not been dismantled, because in most places it was never built, is the architecture.
ISO 30201 has now made that architectural claim in normative language, at global scale, without naming inclusion as its object.
I would rather have that than a named clause with no structure behind it.
Note in particular Clause 8.8: knowledge management, as a requirement of a certifiable HR management system. The eighth pillar of the Architecture of Inclusion is Knowledge Architecture and AI Stewardship — the argument that how an organization captures, structures, and increasingly automates its judgment about people is itself an equity system, and one that is currently being built faster than it is being governed. ISO 30201 has opened the clause. What goes into it is not yet settled.
What I am asking for
ISO 30415 entered systematic review on 15 April 2026 — two months before ISO 30201 published. The review is open. Its outcome is not decided.
Three things follow.
First, to practitioners. Do not accept the framing that an unnamed function is a discharged obligation. When someone tells you that D&I is not required under ISO 30201, ask them how they intend to satisfy Clauses 4.2, 6.1, and 9.1 without it. That is not a rhetorical question. It is an audit question, and it does not have a comfortable answer.
Second, to those building conformity infrastructure. The integration artifact that this moment needs does not require reopening either normative text. ISO 30415’s Annex A checklist and ISO 30201’s Annex C conformity checklist can be mapped against each other — action by action, indexed to Clause 8 sub-clause. That mapping puts equity-relevant evidence where auditors actually look, and it can be produced now, by anyone willing to do the work.
Third, to my colleagues in TC 260. The systematic review is the moment to decide whether ISO 30415 becomes the interpretive layer for a certification regime or drifts into the bibliography. Those are genuinely different institutional futures, and the second one is the default. Defaults do not require a decision. That is what makes them dangerous.
Effenus Henderson served on ISO/TC 260/WG 8, the working group responsible for ISO 30415:2021. He is the author of DEI Is Not the Defect — Exclusion Is and The Architecture of Inclusion: How Leaders Engineer Equity, Align Their Organizations, and Build Institutions That Last.
Note on sources. This statement is based on ISO 30201:2026’s published table of contents, foreword, introduction, and Clauses 1–3, together with the ISO catalogue records for both standards. It does not rely on the full requirement text of Clauses 4–10 or on Annexes A–C.


