Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

The Cost of Poor Quality: What Incidents Really Cost Across Safety, Environment, Security and AI

When businesses weigh up ISO certification, the first question is almost always “what will it cost?” We’ve answered that in detail for ISO 9001, ISO 27001 and ISO 42001. But there’s a second question that almost nobody asks, and it’s the one that actually decides whether certification is worth it: what is it costing you to operate without the system?

Quality professionals have a name for this in the ISO 9001 world: the cost of poor quality (COPQ). What’s less appreciated is that every other management system standard has its own version of the same iceberg. They just call it something different: incidents. A lost-time injury (ISO 45001), a pollution event (ISO 14001), a data breach (ISO 27001), an AI tool doing something it shouldn’t (ISO 42001). Different standards, same anatomy: a people cost, a reputation cost and a financial cost. The visible part is never the biggest part.

Cost of poor quality: the original iceberg

The classic cost of quality model splits your spend into four buckets: prevention (training, process design, planning), appraisal (inspection, testing, audits), internal failure (scrap, rework, downtime) and external failure (warranty claims, returns, complaints, lost customers). The first two are the cost of good quality. The last two are the cost of poor quality, and they dwarf the others in most businesses.

The numbers are confronting. ASQ estimates quality-related costs consume 15-20% of annual sales for many manufacturers, with research putting COPQ anywhere between 5% and 35% of revenue depending on complexity. World-class operators get it below 5%. Above the waterline you can see scrap, rework and warranty claims. Below it sit the costs nobody books to a “quality” ledger: expediting freight to recover a late order, engineers pulled off projects to fight fires, quoting errors, excess inventory held “just in case”, customers who quietly never come back.

That’s why the old 1-10-100 rule survives every generation of management fashion: a dollar spent on prevention saves ten on correction and a hundred on failure. It’s also why ISO 9001 puts so much weight on nonconformance and corrective action. Every recorded nonconformance is a COPQ line item you can trace, cost and permanently remove with decent root cause analysis.

The same iceberg wears four other names

Safety incidents (ISO 45001)

Safe Work Australia’s Safer, Healthier, Wealthier research (modelled by Deloitte Access Economics) found that without work-related injury and illness, Australia’s economy would have been $28.6 billion larger every year: a cumulative $315 billion over the decade studied, and the equivalent of 185,500 full-time jobs. At the level of a single business, a serious injury means a person in pain and a family under stress first, then workers’ compensation premium hikes that persist for years, an understaffed crew, retraining, regulator attention and, for principal contractors, prequalification systems that now ask hard questions about your safety record.

Environmental incidents (ISO 14001)

The regulatory trend is unmistakable: penalties have moved from “cost of doing business” to genuinely existential. NSW’s strengthened environment protection laws now carry maximum corporate penalties of $10 million for the most serious pollution offences (asbestos waste offences alone jumped from $44,000 to $4 million), Victoria’s general environmental duty carries fines up to $1.8 million per offence, and on-the-spot fines for corporations have tripled. Then add clean-up costs, remediation, licence conditions or suspension, and the reputational damage of being the company named in the EPA’s media release.

Information security incidents (ISO 27001)

Start with the Australian numbers, because they are the most current and the least arguable. The OAIC recorded 1,205 notifiable data breaches in 2025, the highest since the scheme began in 2018, and an 8% rise on 2024. Of those, 716 were down to malicious or criminal activity. Which means 489 were not attacks at all: human error and process failure. You cannot buy a product that fixes those.

On the dollar cost, treat the published averages as an order of magnitude rather than a price list. IBM’s 2024 Cost of a Data Breach report put the average Australian breach at AUD $4.26 million, with Australian organisations taking 266 days to identify and contain an incident. That is nearly nine months of an attacker inside your systems. IBM’s 2025 report shows global costs easing as AI-assisted detection speeds up containment, so the number moves year to year. The order of magnitude does not: a serious breach is a seven-figure event, and phishing remains the most common way in, which is exactly why we treat awareness training (clause 7.3) as a control, not a formality. And under APP 11.3, “we didn’t have reasonable security measures” is no longer a defensible position. See our guide to securing personal information.

Australia doesn’t need hypotheticals here. We’ve watched the three layers play out at national scale. Optus (2022): data of around 9.5 million current and former customers accessed, more than $140 million set aside for remediation, and the privacy regulator now pursuing Federal Court action alleging it failed to take reasonable steps to protect the data. Medibank (2022): 9.7 million people’s records taken in a ransomware attack and published on the dark web, with well over $125 million in incident costs, a $250 million capital add-on imposed by APRA, OAIC penalty proceedings, and stolen data linked to thousands of fraud incidents. Qantas (2025): about 5.7 million customers’ details exposed through a third-party contact-centre platform (a textbook supplier-risk failure), with the data later released by the attackers, a representative complaint lodged seeking compensation, and executive bonuses cut in recognition of accountability. Three household names, three different failure modes (unprotected data, ransomware, third-party access), and in every case the reputational bill of headlines, churn and class actions kept running long after the technical incident closed. If it costs the giants that much with dedicated security teams, the proportional damage to a smaller business without a system is worse.

AI incidents (ISO 42001)

The newest category, and the fastest growing. AI incidents range from staff pasting confidential data into public models, to models producing wrong or discriminatory outputs that harm customers, to automated decisions nobody can explain to a regulator. IBM’s 2025 research found that breaches involving shadow AI cost US$670,000 more than the average. The governance gap behind that number is the damning part: 97% of organisations that suffered an AI-related security incident had no AI access controls in place, and 63% had no AI governance policy at all. The pattern from our shadow AI deep dive holds: most organisations can’t see the exposure, have no rules around it, and pay for it after the fact.

People, reputation, money: the three layers of every incident

The people cost comes first. Injured workers and their families. Teams burnt out by rework and firefighting. Staff who leave because working in a chaotic, unsafe or blame-driven environment is exhausting, taking their experience with them and adding recruitment and retraining to the bill. In every incident investigation we’ve run, the human toll surfaces before the financial one.

The reputation cost compounds quietly. Customers rarely announce their departure. They just stop ordering. Tenders start going elsewhere once your safety statistics, breach history or EPA record shows up in prequalification. IBM’s breach research consistently finds lost business among the largest cost components, bigger than the fines. And reputation damage has a long half-life: the incident makes the news in a day, and the search results last for years.

The financial cost is the layer you can finally see: scrap, premiums, penalties, ransom demands, legal fees, remediation. By the time it lands on a ledger, the first two layers have already been paid.

ISO mentoring and coaching from an experienced auditor
IBM’s 2025 research found breaches involving shadow AI cost organisations US$670,000 more than the average data breach.

Now compare that with the cost of the system

Here’s the comparison that matters. A full, certifiable management system (designed, implemented and audited) typically costs a small fraction of one serious incident, let alone a year of running at 15% COPQ. Put hard numbers side by side: our ISO 9001 certification cost guide (2026) against 15-20% of your sales; the ISO 27001 cost guide against a seven-figure breach; the ISO 45001 and ISO 14001 pathways against seven-figure penalties and years of loaded premiums. Certification isn’t the expensive option. Incidents are.

A management system attacks all three layers the same way: it shifts spend from failure to prevention. Risks identified before they become incidents; internal audits that find the weak points before the regulator, the attacker or the injury does; corrective action that stops the same failure recurring; and records that prove to customers, insurers and regulators that you run a controlled operation. If you’re running multiple standards, an integrated management system delivers this once, not four times.

The bottom line

Poor quality and incidents are the same problem in five uniforms: quality failures, injuries, pollution events, breaches and AI misfires. Each one bills you three times, in people, reputation and money, and the invoice is always larger below the waterline. The certification cost question has a known, fixed answer. The incident cost question doesn’t, and it compounds until you build the system that controls it.

Want to know what your risks would cost, and what a right-sized system to control them would? Talk to us: you’ll deal directly with an experienced ISO Lead Auditor, whether we build the system with you or mentor you while you build your own. Email hello@streamline.business. Built to certify first time.

Sources: ASQ, Cost of Quality; Safe Work Australia / Deloitte Access Economics, Safer, Healthier, Wealthier; NSW Environment Protection Legislation Amendment (Stronger Regulation and Penalties) Act 2024; OAIC Notifiable Data Breaches statistics, 6 July 2026; IBM Cost of a Data Breach Report (2024 and 2025 editions). Figures reviewed 12 July 2026.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • Quality inspector in an Australian machining workshop checking a machined aluminium component against a tablet record, with CNC machines and Australian flags behind
    How Much Does ISO 9001 Certification Cost in…
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • Tilt-shift miniature naval shipyard inspection bay with a submarine hull section on keel blocks and workers in hi-vis checking tagged components in a parts quarantine area
    ISO 19443: The Nuclear Supply Chain Standard, and…
  • ISO 9001 quality management inspection
    ISO 9001 Quality Management Consulting, Audits & Mentoring
  • Manager reviewing a budget spreadsheet
    ISO 27001 Certification Cost & Timeline in Australia…

Filed Under: Articles Tagged With: #certification, #informationsecurity, #iso42001, #iso9001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire