Start a free trial
Menu

ISO 9001 requirements: what the standard actually asks for

The standard is 30 pages and most of the work is deciding what applies to you. Here is the mandatory documented information, clause by clause, and the four things the 2015 revision removed that people still build.

Search for what ISO 9001 requires and you will find two kinds of answer: a list of clause numbers that tells you nothing, or a consultant's page that implies you need far more than you do. The standard itself is 30 pages and most of the work is deciding what applies to you. This is what it actually asks for.

The seven clauses that carry requirements

ISO 9001:2015 has ten clauses. The first three are scope, references and terms; they contain no requirements. Everything auditable lives in clauses 4 to 10:

  • Clause 4, Context: who your interested parties are, what they expect, and where you have drawn the boundary of your quality management system.
  • Clause 5, Leadership: top management's accountability, a quality policy, and clear responsibilities.
  • Clause 6, Planning: the risks and opportunities that could stop you delivering, measurable quality objectives, and how you manage change.
  • Clause 7, Support: people, competence, infrastructure, measuring equipment, and documented information.
  • Clause 8, Operation: the work itself, from understanding a customer's requirement to controlling suppliers and releasing the product.
  • Clause 9, Performance evaluation: monitoring, internal audit and management review.
  • Clause 10, Improvement: what you do when something goes wrong.

An auditor works through these in order. Nothing in the list is exotic. The difficulty is almost never understanding a clause; it is producing the evidence that you have been doing it.

What must be written down

The 2015 revision replaced 'documents and records' with a single term, documented information, and stopped prescribing a document set. There is no required quality manual and no mandatory list of six procedures. What remains is a short list of things the standard says you must maintain or retain.

Maintained, meaning kept current:

  • The scope of the quality management system (4.3).
  • The quality policy (5.2) and the quality objectives (6.2).
  • Whatever documented information you decide is necessary for your processes to work (4.4.2). That judgement is yours, and an auditor will test it against what your people actually need to do the job.

Retained, meaning kept as evidence of what happened:

  • Calibration and measurement traceability (7.1.5.2).
  • Evidence of competence (7.2).
  • Review of customer requirements before you commit (8.2.3.2).
  • Design inputs, controls and outputs, where design applies to you (8.3).
  • Evaluation and monitoring of external providers (8.4.1).
  • Release of products and services, with the person who authorised it (8.6).
  • Nonconforming output and what you did about it (8.7.2).
  • Monitoring and measurement results (9.1.1), internal audit results (9.2.2), and management review outputs (9.3.3).
  • Nonconformities and corrective actions (10.2.2).

That is the whole mandatory set. Everything else is documentation you chose to keep, and the standard asks only that you control it: that it is available where the work happens, in a form people can use, protected from unintended change, and that you can tell one version from another. Document control is where most of the audit findings in this area come from, and almost none of them are about missing documents. They are about the wrong version being in use.

What ISO 9001 does not require

Four things people build because they believe the standard demands them:

  • A quality manual. Removed in 2015. Many organisations keep one because it is a useful map, which is a good reason. It is not a requirement.
  • Six documented procedures. That was the 2008 edition. The current standard lets you decide which processes need written procedures.
  • A management representative. The 2015 revision assigned those duties to top management rather than to a single appointed person.
  • Preventive action as a separate process. It was replaced by risk-based thinking in clause 6.1, which is meant to run through the system rather than sit beside it.

If your system contains these because a template had them, that is not a nonconformity. It is overhead you chose, and it is worth knowing you chose it.

How an auditor tests a requirement

A requirement is not met because a document says it is. An auditor samples: they pick a role, a process or an order and follow it end to end, asking for the evidence at each step. A stated requirement, the training that supports it, the record showing it was done, and the review that caught it when it was not.

This is why documentation that exists only to satisfy the standard tends to fail. It has no trail behind it. The procedures that pass are the ones people were following anyway, written down accurately. See how certification actually works for what happens in the audit itself, and the ISO 9001 overview for how the clauses map to a working management system.

A short check before your next audit

Take one process and answer five questions about it:

  1. Is it in scope, and does the scope statement say so?
  2. Is there a documented requirement for it, and does it match what people do?
  3. Are the people doing it competent, and is there evidence of that?
  4. Is there a record showing it happened, dated and attributable?
  5. When it last went wrong, is there a nonconformity and a corrective action closing it?

If any answer is no, that is the finding, and you have found it before an auditor did. That is the entire point of clause 9.