\n\n","wordCount":2964,"timeToRead":"PT9M","keywords":["iso 9001 required documents","iso 9001 documented information","iso 9001 checklist","iso 9001 mandatory documents","iso 9001 clause 7.5","industria","blog","RAG","IA","inteligencia artificial"]}
Industry

ISO 9001:2015 required documents by clause: the real checklist

IgeraIndustria Quality Team
August 2, 2026
9 min read
Quality manager reviewing ISO 9001 documented information and procedure files by clause

IgeraIndustria Quality Team  ·  Updated 2026-08-02  ·  9 min read

Direct answer

ISO 9001:2015 explicitly requires documented information in a specific set of places across clauses 4–10 — not a fixed list of named documents. The standard deliberately avoids mandating a "quality manual" or prescribed procedure titles. Most of what auditors expect to see beyond that minimum (a quality manual, detailed work instructions, a document register) is common practice, not a clause requirement. Knowing the difference stops you writing 40 procedures nobody asked for.

One of the most persistent myths about ISO 9001:2015 is that it requires a binder of mandatory procedures. It doesn't. The 2015 revision deliberately moved away from the prescriptive documentation demands of ISO 9001:2008 — there is no mandatory quality manual, no mandatory "six procedures," and no fixed template library. What the standard requires is documented information, a term that covers both documents you must maintain (keep current, like procedures) and records you must retain (keep as evidence, like audit reports). Some of it is genuinely mandatory; a lot of what organisations produce is there because it's useful, not because clause text demands it.

~24

explicit "documented information" requirements scattered across ISO 9001:2015 clauses 4 through 10 — the actual mandatory minimum, before any customer-specific or sector-specific additions

Source: ISO 9001:2015, cross-referenced clause by clause

Required vs. common practice: the distinction that saves you months

Every time the standard uses the phrase "documented information" tied to a specific clause, that is a genuine requirement — you must produce or retain something, though ISO 9001 does not dictate its format, length, or title. Everywhere else, if you see a procedure, template, or manual in someone's QMS, it's there because the organisation chose to document it — often because it reduces risk, supports training, or satisfies a customer or certification body auditor who expects to see it in practice, not because a clause number forces it.

This distinction matters commercially. Over-documenting wastes the internal labour hours that dominate certification cost (see our ISO 9001 certification guide for typical cost ranges), creates a maintenance burden every time a process changes, and gives auditors more surface area to find nonconformities in documents nobody actually uses. Under-documenting, on the other hand, risks failing the audit outright. The checklist below separates the two so you can decide deliberately, clause by clause.

Clause-by-clause checklist: what's mandated vs. optional

Clause Required documented information Common practice (not mandated)
4.3 Scope of the QMS, available and maintained as documented information A standalone "scope statement" document — many fold this into a quality manual instead
5.2.2 Quality policy, as documented information A framed wall poster or intranet page — format is entirely your choice
6.2.1 Quality objectives, as documented information A formal objectives tracking dashboard or balanced scorecard
7.1.5.1 Evidence of fitness for purpose of monitoring/measuring resources (where applicable) A dedicated calibration management system — a spreadsheet register satisfies the clause
7.2 Evidence of competence of persons doing work affecting quality performance Formal training matrices, competency frameworks, or skills-gap analyses
8.1 Documented information to the extent necessary to have confidence processes are carried out as planned, and to demonstrate conformity of products/services Detailed step-by-step work instructions for every task — required only where the absence of instruction would create risk
8.2.3 Results of the review of requirements for products and services, and any new requirements A standardised contract-review form template
8.3.2–8.3.6 Design and development inputs, controls, outputs, and changes (only if your organisation does design/development) Stage-gate design review templates, FMEA worksheets
8.4.1 Results of evaluation, monitoring of performance, and re-evaluation of external providers An approved-supplier list with scoring criteria and tiering
8.5.1 Documented information defining the characteristics of products/services and results to be achieved, to the extent necessary Full production travelers or router cards for every SKU
8.5.2 Means to identify outputs and traceability, where traceability is a requirement Barcode/serial-number traceability systems beyond what's required by contract or regulation
8.5.3 Records of customer/external provider property that is lost, damaged, or unsuitable, communicated to the owner A dedicated customer-property register (useful if volumes are high)
8.5.6 Results of the review of changes for production/service provision, personnel authorising, and necessary actions A formal engineering change order (ECO) system
8.6 Evidence of conformity with acceptance criteria and traceability to the person(s) authorising release Digital release/sign-off workflows with electronic signatures
8.7.2 Documented information on nonconformities, actions taken, concessions obtained, and the authority deciding the action A dedicated NCR (nonconformance report) form and log — the near-universal way organisations satisfy this
9.1.1 Evidence of the results of monitoring and measurement of QMS performance KPI dashboards, statistical process control charts
9.2.2 Evidence of the implementation of the internal audit programme and its results A formal audit schedule template, auditor competence matrix
9.3.3 Evidence of the results of management reviews A standing meeting-minutes template covering all nine required review inputs
10.2.2 Evidence of the nature of nonconformities, actions taken, and results of corrective action A dedicated CAPA (corrective and preventive action) form with root-cause analysis fields

What's conspicuously absent from the mandatory list

Three things organisations almost universally produce are not, strictly speaking, required by clause text:

  • A quality manual. ISO 9001:2008 required one explicitly; ISO 9001:2015 removed that requirement. Clause 4.3 requires the scope to be available as documented information, and clause 4.4 requires the QMS processes and their interactions to be documented "to the extent necessary" — many organisations satisfy both inside a manual-style document purely because auditors and staff find it a convenient single reference, not because a clause demands the word "manual."
  • A single master list / document register. Clause 7.5.3 requires documented information to be controlled — identified, reviewed, distributed, protected from unintended changes — but does not mandate a specific register format. A register is simply the most practical way most organisations demonstrate control.
  • Detailed work instructions for every task. Clause 8.1 requires documented information only "to the extent necessary" to have confidence processes are carried out as planned. For a task performed daily by an experienced operator with low error consequence, that threshold may be met with no written instruction at all — competence (clause 7.2) can substitute for documentation.

"To the extent necessary": the clause that does the real work

Clauses 7.5.1(b), 8.1, and 8.5.1 all use a version of the phrase "to the extent necessary" or "as necessary to support operation of processes." This is not vague drafting — it is a deliberate risk-based principle running through the entire 2015 revision. It means the correct amount of documentation is proportional to: the complexity of the process, the competence of the people performing it, the consequence of getting it wrong, and whether a customer, regulator, or sector scheme (IATF 16949, AS9100, ISO 13485) imposes a stricter requirement on top of ISO 9001's baseline.

This is precisely why two ISO 9001-certified companies of similar size can have wildly different documentation volumes — one with 15 controlled procedures, another with 150 — and both pass their audits. Auditors are trained to test whether documentation matches actual risk and practice, not to count pages.

A practical minimum-viable documentation set

For a first-time certification, most quality consultants and certification bodies (BSI, Bureau Veritas, SGS, TÜV, LRQA, DNV) will look for evidence covering, at minimum:

  • Defined QMS scope and the interaction of your key processes (clause 4)
  • A published quality policy and measurable objectives (clause 5, 6.2)
  • Risk and opportunity actions from your planning process (clause 6.1)
  • Evidence of competence, and a document control approach — however simple (clause 7)
  • Operational controls proportionate to your actual risk profile (clause 8)
  • Internal audit records, management review minutes, and nonconformity/corrective action records (clauses 9–10)

Getting this scoping decision right — what genuinely needs a controlled document versus what can be handled through competence and simple records — is exactly where internal teams lose the most time, because it requires cross-referencing your existing procedures against 24 scattered clause requirements manually. If you want a realistic budget for a consultancy-supported build-out that gets this scoping right the first time, our ISO 9001 certification cost calculator lets you calculate the exact cost for your company based on headcount, sites, and current documentation maturity — it takes two minutes and gives you a realistic budget range before you commit to a consultancy quote.

Where IgeraIndustria fits

Instead of manually cross-referencing your existing procedures against every clause requirement, IgeraIndustria indexes your documented information and answers clause-specific questions directly, citing the exact document, revision, and location. That turns a multi-day gap-analysis exercise into a conversation.

// IgeraIndustria RAG demo — gap analysis by clause

Quality Manager: Which of the 24 mandatory documented-information requirements in ISO 9001:2015 do we NOT currently have evidence for?

IgeraIndustria: Based on your indexed QMS documentation (last sync 2026-07-30), 22 of 24 requirements have matching evidence. Two gaps identified: Clause 7.1.5.1 (evidence of fitness for purpose of monitoring/measuring resources) — no calibration register found in your document index. Clause 8.4.1 (evaluation and re-evaluation of external providers) — your supplier list (SUP-LIST-004) exists but contains no re-evaluation dates after 2024-09. Recommend creating a calibration log and scheduling a supplier re-evaluation cycle before your next surveillance audit.

Practical tips for building your documentation set

  • Start from the 24-item mandatory list above and confirm you have evidence for each — this is your true floor, not a starting template to expand from.
  • For every additional document you're tempted to write, ask which clause 8.1/7.5.1(b) risk it mitigates. If you can't answer, question whether it earns its maintenance cost.
  • Keep records (retained evidence) separate in your thinking from procedures (maintained instructions) — auditors check both, but they fail for different reasons.
  • Reuse existing operational documents (work instructions, SOPs, forms) wherever possible instead of writing parallel "ISO versions" — auditors want to see the system you actually run, not a paper twin.
  • Revisit your document set at every management review — clause 10.2.2 corrective actions often reveal that a document is missing, unclear, or simply unused.

Frequently asked questions

Does ISO 9001:2015 require a quality manual?

No. The explicit quality manual requirement from ISO 9001:2008 was removed in the 2015 revision. Many organisations still produce one voluntarily because it's a convenient way to satisfy clause 4.3 (scope) and clause 4.4 (process interactions) in a single reference document, and auditors are used to finding information organised that way — but no clause names it as mandatory.

What is the difference between a "maintained" document and a "retained" record under ISO 9001?

Both are types of "documented information," but the standard's footnotes distinguish them by purpose. Maintained documents (e.g., procedures, policies) describe how something should be done and are kept current through revision control. Retained records (e.g., audit reports, nonconformity logs, management review minutes) are evidence that something happened, and by definition should not be edited after the fact — only retained for the period your organisation defines.

Can a small company get certified with very few written procedures?

Yes, provided the 24 explicit documented-information requirements are met and clause 8.1's "extent necessary" test is satisfied for your actual operations. Certification bodies routinely certify small organisations with lean documentation sets where competence, direct supervision, and simple records substitute for lengthy written procedures — the standard explicitly permits this.

Do design and development documentation requirements (clause 8.3) apply to every organisation?

No. Clause 8.3 applies only if your organisation actually designs and develops products or services — for example, engineering a bespoke part, not manufacturing to a customer-supplied drawing. If you only manufacture or supply to specifications provided by others, clause 8.3 can typically be excluded from your QMS scope, with justification recorded.

How long must ISO 9001 records be retained?

ISO 9001:2015 does not specify fixed retention periods — your organisation defines them based on legal, regulatory, customer, and business risk considerations, and documents that decision within your document control approach. Sector-specific schemes (e.g., AS9100, ISO 13485, IATF 16949) sometimes impose minimum retention periods on top of the ISO 9001 baseline, so check whether a stricter scheme applies to you.

Will an auditor fail us for having too much documentation?

Not directly — over-documentation is not itself a nonconformity. But excess, unmaintained, or unused documentation frequently becomes the source of findings: outdated revisions still in circulation, procedures nobody follows in practice (a conformity gap between documented and actual process), or clause 7.5.3 control failures caused by simply having too many documents to manage properly. Lean, accurate documentation is generally lower-risk than an extensive but poorly maintained set.

Not sure what your documentation gap-fill will cost? Calculate the exact cost for your company with our ISO 9001 certification cost calculator.

Calculate your ISO 9001 certification cost

Article reviewed by IgeraIndustria Quality Team, updated 2026-08-02. References: ISO 9001:2015 Quality management systems — Requirements, clauses 4–10; ISO 9000:2015 Fundamentals and vocabulary (definitions of documented information, maintain, retain).

#iso 9001 required documents#iso 9001 documented information#iso 9001 checklist#iso 9001 mandatory documents#iso 9001 clause 7.5

COMPARTIR

Comparte el conocimiento con tu red