Start a free trial
Menu

ISO 9001

ISO 9001 compliance software

Manufacturers and suppliers running a quality management system - including defence.

ISO 9001 is the international standard for quality management systems. ComplyTrain is structured around its clause structure, so your QMS is audit-ready by design.

ComplyTrain fully supports this standard

What ISO 9001 is

ISO 9001 is the international standard for a quality management system - the framework an organisation uses to consistently meet customer and regulatory requirements and to improve the way it works over time. Published by the International Organization for Standardization, it is the most widely held management-system certification in the world, with more than a million certified organisations across almost every sector.

At its core it asks one question in a rigorous way: can you show that your organisation reliably does what it says it does? The standard does not prescribe how you make your product or deliver your service. It sets out what a capable quality system must contain - defined processes, controlled information, competent people, managed risk and evidence of improvement - and leaves the specifics to you. It is worth being precise about words here: following ISO 9001, being compliant with it, and being certified to it are three different things, and we pull them apart in following, compliant, certified.

Why ISO 9001 exists

Quality that depends on individual heroics is fragile: it walks out of the door when a key person leaves, and it cannot be proven to a customer or an auditor after the fact. ISO 9001 exists to make quality a property of the system rather than of the person - repeatable, documented and demonstrable. To a buyer, a supplier's certificate is shorthand for "this organisation manages its work, so I do not have to inspect everything they send me." That is why, in regulated and safety-critical supply chains, it is frequently the price of being allowed to bid at all.

Who needs ISO 9001

ISO 9001 is sector-agnostic - used by manufacturers, engineering and construction firms, software and service companies, healthcare providers and public bodies. Organisations usually pursue it for one of three reasons:

  • A customer or tender requires it. Prime contractors, government buyers and large OEMs routinely make certification a condition of the contract.
  • It is the foundation for a sector standard. AQAP 2110 (NATO defence), AS9100 (aerospace) and IATF 16949 (automotive) are all built on ISO 9001 and add requirements on top - you cannot meet them without it.
  • The organisation wants the operational discipline - fewer defects, less rework, clearer accountability - that a managed quality system brings, independent of any certificate.

How the standard is structured

The current version, ISO 9001:2015, follows the "high-level structure" shared by all modern ISO management-system standards. Its requirements sit in clauses 4 to 10. Read as a list they can look abstract, so here is what each one actually asks of you in practice.

  • Clause 4 - Context of the organisation. Establish who you serve, who else has a stake in your quality (regulators, owners, key suppliers), and - the decision everything else rests on - the scope of your quality system: which activities and sites it covers. You also map your work as a set of processes, which is the groundwork for the process approach below.
  • Clause 5 - Leadership. Top management has to own the system, not delegate it to a quality manager in the corner. In practice that means a quality policy that means something, quality objectives that connect to the business, and clearly assigned responsibilities - evidenced by leaders actually engaging, not just signing a document.
  • Clause 6 - Planning. Identify the risks and opportunities to your quality and decide, deliberately, what you will do about them. This is also where you set measurable quality objectives and plan the changes to reach them, so improvement is planned rather than accidental.
  • Clause 7 - Support. The resources the system runs on: people and their competence, awareness of why the system matters, and the controlled documented information (clause 7.5) - one current version of each document, available where it is needed, with superseded versions withdrawn. Getting document control right removes a whole category of audit findings.
  • Clause 8 - Operation. The heart of the standard: how you plan, control and deliver your product or service. It covers customer requirements, design where relevant, control of external providers, and - importantly - how you handle work that does not conform, so a defect is contained and dealt with rather than shipped.
  • Clause 9 - Performance evaluation. How you check the system is working: monitoring and measurement, internal audit (clause 9.2), and management review (clause 9.3), where leadership examines the evidence and makes decisions. Internal audits are your own early-warning system; we cover how to run them in internal, external, second-party audits.
  • Clause 10 - Improvement. How you get better: handling nonconformities and corrective action (clause 10.2) - fixing not just the instance but the cause - and continual improvement over time. This is the clause that compounds: an organisation that genuinely closes root causes stops meeting the same problem twice.

Three ideas run through all of it. The process approach: manage your work as a set of connected processes with defined inputs, outputs and owners. The Plan-Do-Check-Act cycle: plan a change, do it, check the result, act on what you learn - the engine of continual improvement. And risk-based thinking, made explicit in the 2015 revision: anticipate what could go wrong and build the controls in, rather than reacting after a failure.

Underneath the clauses sit the seven quality management principles the standard is founded on: customer focus, leadership, engagement of people, the process approach, improvement, evidence-based decision-making and relationship management. They are the "why" behind the "what".

ISO 9001 and the sector standards

For many organisations ISO 9001 is not the destination but the foundation. Several of the standards that regulated industries actually require are built directly on top of it, adding sector-specific requirements to an ISO 9001-grade system:

  • AQAP 2110 - the NATO quality-assurance requirements for defence contractors. It assumes an ISO 9001 system and adds defence-specific expectations such as configuration management and provision for government quality assurance.
  • AS9100 - the aerospace quality standard. It incorporates ISO 9001 in full and layers on aerospace requirements including counterfeit-part prevention, first-article inspection and stricter risk and configuration control.
  • IATF 16949 - the automotive standard, built on ISO 9001 with a large body of additional requirements for the automotive supply chain.

The practical consequence is the same in each case: you cannot meet the sector standard without meeting ISO 9001 first. Building a genuine ISO 9001 system is therefore rarely wasted effort even when the eventual target is AS9100 or AQAP 2110 - it is the base the sector requirements bolt onto.

Getting certified - and staying certified

Certification is a defined, predictable process, not a black box: a gap analysis against the standard, building and operating the system long enough to generate evidence, then a two-stage audit by an accredited certification body (Stage 1 readiness, Stage 2 assessment in operation). It is not a one-off badge either - annual surveillance audits and a three-year recertification keep it live. We walk the whole road, step by step, in how certification works.

The one thing that determines whether all of this is painful or straightforward is whether your evidence accumulates as you work or has to be reconstructed before each audit - which is the case for keeping the system in one place rather than scattered across drives and inboxes.

Common misconceptions

  • It is not a product-quality mark. ISO 9001 certifies your management system, not your product - it says you make consistent, controlled products, not that a given product is the best on the market.
  • It is not a documentation exercise. The 2015 revision deliberately cut the mandatory-procedure list; you keep the documented information your processes actually need, not a binder assembled to satisfy an auditor.
  • It does not require software. The standard is technology-neutral. Software removes the friction of keeping records current and audit-ready, but the requirement is demonstrable control, however you achieve it.

The business case

Beyond winning the contracts that require it, a working ISO 9001 system pays back in fewer nonconformities and less firefighting, in faster and less painful audits, and in a shared, documented way of working that survives staff turnover. The cost of the standard is the discipline of running it; the cost of not having it, in a regulated supply chain, is not being in the room.

How ComplyTrain helps you meet it

ComplyTrain's quality management is built around the ISO 9001 clause structure, so your system lives where an auditor expects to find it - organised by the requirements it has to satisfy, rather than scattered across shared drives and inboxes:

  • Processes, controlled procedures and objectives, organised to the standard's structure, so clause 4's process map and clause 5's policy and objectives have a home rather than living in someone's head.
  • Nonconformities and corrective actions (CAPA) with evidence and due dates, so clause 10.2 is a tracked workflow from the problem to the verified fix, not a note that gets lost.
  • Internal audits, findings and follow-up, so the clause 9.2 programme is planned, its findings are closed out, and the trail is there at the next audit.
  • Management review, with its inputs already collated from the modules that produce them, so the clause 9.3 review is a decision-making meeting rather than a data-gathering scramble.
  • Controlled documents and competence records as the evidence behind it all - clause 7.5 document control and clause 7.2 competence, kept current as a by-product of the work.

Because the evidence is captured as you work, preparing for a certification or surveillance audit becomes a matter of showing what you already run, rather than assembling it the week before. ComplyTrain is structured around ISO 9001 - it does not make you certified (only an accredited body does that), but it is built to keep you audit-ready for the day they visit.

Questions

Does ISO 9001 certification require software?

No. ISO 9001 is about how you run your quality system, not which tools you use. But an auditor expects to see controlled documents, records, corrective actions and management review on demand - and that is exactly the work software removes the friction from. ComplyTrain keeps the evidence current as a by-product of the work.

What is the difference between being ISO 9001 compliant and being certified?

Compliant means you genuinely meet every requirement of the standard and can show the evidence; certified means an accredited third party has audited you and issued a certificate saying so. You can be compliant without being certified - but you cannot honestly describe self-assessed compliance in words that imply an outside body has verified it. We pull the two apart, along with simply "following" the standard, in following, compliant, certified.

How long does ISO 9001 certification take?

For most small and mid-sized organisations, three to six months from a standing start to the certification audit is realistic - longer if you are building the quality system from scratch, shorter if you already work in a disciplined way and only need to formalise it. The standard then requires annual surveillance audits, with a full recertification every three years. How certification works walks through each stage.

What does the certification audit involve?

An accredited certification body audits your management system in two stages. Stage 1 reviews your documentation and readiness; Stage 2 checks that what you documented is actually being done, through interviews, records and observation. Findings are raised as nonconformities you must close before the certificate is issued.

What happens in an ISO 9001 internal audit, and why does the standard require them?

Clause 9.2 requires you to audit your own management system periodically - your own people checking that what you do matches the standard and your procedures, and raising findings to fix. It is a requirement in its own right and your cheapest early-warning system: internal audits catch problems before a certification body or a customer does. Internal, external, second-party audits covers how to run an effective programme.

How much does ISO 9001 certification cost?

There are two costs, and the certification body's fee is usually the smaller one. That fee scales with the size and complexity of your organisation and recurs across the three-year cycle (initial audit plus surveillance). The larger cost is internal: the time to build the system, generate the evidence, and keep it current between audits. Treating compliance as an ongoing discipline rather than a pre-audit scramble is what keeps that second cost down.

Does ISO 9001 apply to software or service companies?

Yes. ISO 9001 is deliberately sector-agnostic - its requirements are about how you manage quality, not about manufacturing specifically. Software, engineering and service organisations hold it widely; a controlled development and release process, for example, maps naturally onto the standard's requirements for operation, documented information and improvement.

What is the difference between ISO 9001 and AQAP 2110 or AS9100?

ISO 9001 is the general quality-management standard. AQAP 2110 (NATO defence) and AS9100 (aerospace) are sector standards built directly on it - they require an ISO 9001-grade system and add requirements such as configuration management, government quality assurance or first-article inspection. Meeting the sector standard means meeting ISO 9001 first and layering the extra requirements on top.

We are a defence startup with no quality system yet. Where do we start?

Start with the quality module: it gives you the ISO 9001 clause structure, the record types and the review cadence out of the box, so you are building on the standard from day one instead of on a blank shared drive.

Implementation

How to implement ISO 9001 - a practical path

Certification is the end of a route, not a single event. The path is broadly the same whatever your sector.

  1. Scope and gap analysis

    Decide what the quality system covers, then compare how you work today against the clauses of the standard. The gaps are your plan.

  2. Define your processes and policy

    Set the quality policy and objectives, map your core processes with their owners, and put the documents and records they need under control.

  3. Operate the system

    Run the processes for long enough to generate real records - nonconformities raised and closed, competence logged, suppliers assessed. Auditors want evidence of use, not a fresh binder.

  4. Internal audit and management review

    Audit yourself against the standard to find gaps before the certification body does, then have leadership review performance and act on what it shows.

  5. Certification and surveillance

    An accredited body runs the Stage 1 and Stage 2 audits; you close any findings and the certificate is issued. Annual surveillance audits and a three-yearly recertification keep it live.

Manage your ISO 9001 compliance in one system

See how ComplyTrain maps to your framework on a 30-minute demo, walked through on your own processes. Or start a trial and we will set up a workspace to match what you are working on.