
What is the PDCA cycle?
The PDCA Cycle (Plan-Do-Check-Act) is a simple yet powerful methodology organisations use to achieve continuous improvement and operational excellence. It is the engine inside every ISO management system — if you have read the clauses of ISO 27001, ISO 22301 or ISO 9001, you have seen PDCA wearing a suit.
- Plan — establish objectives and the processes necessary to deliver results in accordance with requirements
- Do — implement the plan and execute the processes
- Check — monitor and measure processes against policies, objectives and requirements; report the results
- Act — take actions to continually improve process performance
*PDCA turns plans into action, action into insight, and insight into continuous improvement.*
Purpose of the PDCA cycle
- Drives continuous improvement in processes, products and services
- Helps organisations adapt to changes effectively
- Enhances efficiency, reduces risks and waste
- Improves customer satisfaction
- Supports a culture of learning and accountability
- Ensures alignment with organisational objectives and compliance requirements
PDCA in action: four management systems
| Plan | Do | Check | Act | |
|---|---|---|---|---|
| **Information security (ISO 27001)** | Identify security risks and controls | Implement security controls | Monitor and review control effectiveness | Address gaps and improve security measures |
| **Business continuity (ISO 22301)** | Conduct BIA and define recovery strategies | Implement BC plans and processes | Test, monitor and evaluate effectiveness | Improve plans based on lessons learned |
| **Quality management (ISO 9001)** | Define quality objectives and processes | Deliver products/services as per the plan | Measure performance and gather feedback | Take corrective actions and drive improvements |
| **IT service management (ISO 20000-1)** | Identify service requirements and plan improvements | Deliver and support IT services | Monitor service performance and SLAs | Improve service quality and efficiency |
Where can PDCA be used?
- In all management systems — ISO 9001, ISO 27001, ISO 22301, ISO 45001 and more
- In daily operations and process improvements
- In project management and service delivery
- In risk management and compliance activities
- In resolving issues and implementing corrective actions
PDCA is universal and can be applied at all levels of an organisation — from a single team's process fix to the board's annual management review.
Why PDCA matters
- Creates a structured approach to problem solving
- Encourages data-driven decision making
- Promotes consistency and standardisation
- Builds resilience and long-term success
- Helps achieve and maintain certification standards
Continuous improvement is not a one-time effort — it is a continuous cycle. This is also why auditors ask for evidence from *multiple* cycles: a single internal audit shows you ran Check once; corrective actions from that audit, reviewed by management, show the full loop turning.
See PDCA operating inside real audit work in our [ISO 27001 audit checklist](/blog/iso-27001-audit-checklist) and [ISO 22301 implementation roadmap](/blog/iso-22301-bcms-implementation-roadmap).
