IgeraIndustria Quality Team · Updated 2026-08-02 · 9 min read
ISO 9001:2015 explicitly requires documented information in a specific set of places across clauses 4–10 — not a fixed list of named documents. The standard deliberately avoids mandating a "quality manual" or prescribed procedure titles. Most of what auditors expect to see beyond that minimum (a quality manual, detailed work instructions, a document register) is common practice, not a clause requirement. Knowing the difference stops you writing 40 procedures nobody asked for.
One of the most persistent myths about ISO 9001:2015 is that it requires a binder of mandatory procedures. It doesn't. The 2015 revision deliberately moved away from the prescriptive documentation demands of ISO 9001:2008 — there is no mandatory quality manual, no mandatory "six procedures," and no fixed template library. What the standard requires is documented information, a term that covers both documents you must maintain (keep current, like procedures) and records you must retain (keep as evidence, like audit reports). Some of it is genuinely mandatory; a lot of what organisations produce is there because it's useful, not because clause text demands it.
~24
explicit "documented information" requirements scattered across ISO 9001:2015 clauses 4 through 10 — the actual mandatory minimum, before any customer-specific or sector-specific additions
Source: ISO 9001:2015, cross-referenced clause by clause
Required vs. common practice: the distinction that saves you months
Every time the standard uses the phrase "documented information" tied to a specific clause, that is a genuine requirement — you must produce or retain something, though ISO 9001 does not dictate its format, length, or title. Everywhere else, if you see a procedure, template, or manual in someone's QMS, it's there because the organisation chose to document it — often because it reduces risk, supports training, or satisfies a customer or certification body auditor who expects to see it in practice, not because a clause number forces it.
This distinction matters commercially. Over-documenting wastes the internal labour hours that dominate certification cost (see our ISO 9001 certification guide for typical cost ranges), creates a maintenance burden every time a process changes, and gives auditors more surface area to find nonconformities in documents nobody actually uses. Under-documenting, on the other hand, risks failing the audit outright. The checklist below separates the two so you can decide deliberately, clause by clause.
Clause-by-clause checklist: what's mandated vs. optional
| Clause | Required documented information | Common practice (not mandated) |
|---|---|---|
| 4.3 | Scope of the QMS, available and maintained as documented information | A standalone "scope statement" document — many fold this into a quality manual instead |
| 5.2.2 | Quality policy, as documented information | A framed wall poster or intranet page — format is entirely your choice |
| 6.2.1 | Quality objectives, as documented information | A formal objectives tracking dashboard or balanced scorecard |
| 7.1.5.1 | Evidence of fitness for purpose of monitoring/measuring resources (where applicable) | A dedicated calibration management system — a spreadsheet register satisfies the clause |
| 7.2 | Evidence of competence of persons doing work affecting quality performance | Formal training matrices, competency frameworks, or skills-gap analyses |
| 8.1 | Documented information to the extent necessary to have confidence processes are carried out as planned, and to demonstrate conformity of products/services | Detailed step-by-step work instructions for every task — required only where the absence of instruction would create risk |
| 8.2.3 | Results of the review of requirements for products and services, and any new requirements | A standardised contract-review form template |
| 8.3.2–8.3.6 | Design and development inputs, controls, outputs, and changes (only if your organisation does design/development) | Stage-gate design review templates, FMEA worksheets |
| 8.4.1 | Results of evaluation, monitoring of performance, and re-evaluation of external providers | An approved-supplier list with scoring criteria and tiering |
| 8.5.1 | Documented information defining the characteristics of products/services and results to be achieved, to the extent necessary | Full production travelers or router cards for every SKU |
| 8.5.2 | Means to identify outputs and traceability, where traceability is a requirement | Barcode/serial-number traceability systems beyond what's required by contract or regulation |
| 8.5.3 | Records of customer/external provider property that is lost, damaged, or unsuitable, communicated to the owner | A dedicated customer-property register (useful if volumes are high) |
| 8.5.6 | Results of the review of changes for production/service provision, personnel authorising, and necessary actions | A formal engineering change order (ECO) system |
| 8.6 | Evidence of conformity with acceptance criteria and traceability to the person(s) authorising release | Digital release/sign-off workflows with electronic signatures |
| 8.7.2 | Documented information on nonconformities, actions taken, concessions obtained, and the authority deciding the action | A dedicated NCR (nonconformance report) form and log — the near-universal way organisations satisfy this |
| 9.1.1 | Evidence of the results of monitoring and measurement of QMS performance | KPI dashboards, statistical process control charts |
| 9.2.2 | Evidence of the implementation of the internal audit programme and its results | A formal audit schedule template, auditor competence matrix |
| 9.3.3 | Evidence of the results of management reviews | A standing meeting-minutes template covering all nine required review inputs |
| 10.2.2 | Evidence of the nature of nonconformities, actions taken, and results of corrective action | A dedicated CAPA (corrective and preventive action) form with root-cause analysis fields |