Knowledge base

ISO 9001:2026: documentation and compliance requirements

Everything ISO 9001:2026 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.

Prem Kumar Dvivedi · ١٢ سبتمبر ٢٠٢٦

This is what ISO 9001:2026 requires you to have, clause by clause, and what an auditor will ask to see for each of it. It covers 91 requirements across 7 areas.

It is deliberately not a checklist. A checklist asks whether you have something; this says what is required and what counts as evidence, which is the question that matters when you are building a system rather than testing one. If you would rather find out where you stand first, the same ground is covered by our free ISO 9001:2026 readiness assessment, which scores you out of 100.

4 Your organisation and what affects it

Clauses 4.1, 4.2, 4.3, 4.4.

You must have written down the things outside the company that could affect your quality — customers, competitors, suppliers, laws, technology, the economy.

Evidence: A short list or table of these issues. A note of when you last looked at it.

You must have written down the things inside the company that could affect your quality — skills, equipment, money, how you are organised, how people work.

Evidence: The same list, covering internal issues. Evidence it is reviewed, not written once.

You must have thought about whether climate change matters to your business, and written down your answer either way.

Evidence: A recorded decision. In the 2026 version this sits in the standard itself, not in an amendment. 'We looked at it and it does not affect us' is fine if it is written down.

You must have listed the people and organisations whose needs affect your quality — customers, staff, owners, suppliers, regulators.

Evidence: A list of these groups.

For each of them, you must have written down what they need from you, and which of those needs you have to meet.

Evidence: What each group expects, next to their name. Which expectations you have accepted as requirements.

You must have written down what your quality system covers — which products, services, sites and activities.

Evidence: A scope statement. Your certificate wording if you already hold one.

If you have left any part of the standard out, you must have written down which part and why.

Evidence: The exclusion and the reason. You can only leave out things that genuinely do not apply.

You must know what your main processes are, what goes into each one, what comes out, and who owns it.

Evidence: A process map or a simple list of processes with owners. How the processes connect.

You must know how well each process is performing, and you must have a way of measuring it.

Evidence: Measures for each process. Recent results.

5 Leadership

Clauses 5.1.1, 5.1.2, 5.2.1, 5.2.2, 5.3.

The owner must be able to or senior manager point to decisions in the last year that were made using the quality system.

Evidence: Management review notes. Approvals for money, people or equipment. Ask them directly.

People must be able to raise a problem or admit a mistake without being blamed for it.

Evidence: A way to speak up. Records that it gets used. Ask staff — this is the real test.

Senior managers must make sure people have the time, money, people and equipment the quality system needs.

Evidence: Budgets. Staffing decisions. Evidence a request for resources was acted on.

You must make sure you understand what the customer wants, including anything they expect but do not say.

Evidence: Order or contract records. Notes of what was agreed. Customer specifications.

Senior managers must actively encourage a culture where quality matters and people behave honestly.

Evidence: What leaders say and do. A code of conduct. Evidence of a decision taken on principle, not profit.

You must keep an eye on whether you are actually meeting customer requirements, and act when you are not.

Evidence: Delivery and quality data. Complaint records. Actions taken.

You must have a written quality policy that fits what your business does and matches where the business is heading.

Evidence: The policy, signed and dated. The link between it and your business plan or strategy.

The policy must promise to meet requirements and to keep improving.

Evidence: Both promises visible in the policy text.

Your people must know the policy exists and roughly what it says.

Evidence: Where it is displayed or shared. Ask a few staff — this is how an auditor checks it.

It must be clear who is responsible for what in the quality system.

Evidence: An organisation chart. Job descriptions or a simple responsibility list.

It must be clear who can stop work, hold a product, or escalate a problem.

Evidence: Written authority. Ask the people concerned whether they know they have it.

6 Planning

Clauses 6.1.1, 6.1.2, 6.1.3, 6.2.1, 6.2.2, 6.3.

You must have thought about what could go wrong, and what opportunities you could take, based on the issues in clause 4.

Evidence: A risk and opportunity list linked back to your context and interested parties.

You must have decided what to do about the significant risks, and done it.

Evidence: Actions with owners and dates. Evidence they were completed.

You must be able to answer: Separately from risks, do you look for opportunities to do better — and can you name one you acted on?

Evidence: An opportunity list kept apart from the risk list. One example you followed through, and what came of it.

You must check afterwards whether those actions actually worked.

Evidence: A review of the action. Evidence something changed as a result.

You must have set quality objectives, and they must be able to be measured.

Evidence: Written objectives with a target and a number. 'Improve quality' is not measurable.

The objectives must line up with the quality policy, and people must be aware of them.

Evidence: The link between policy and objectives. Evidence they were communicated.

For each objective, it must be clear what will be done, by whom, by when, with what, and how you will judge the result.

Evidence: An action plan covering all five points. Progress updates.

When you change something significant, you must plan the change rather than just letting it happen.

Evidence: Change records. What you considered: purpose, effects, resources, who is responsible.

7 Support — people, equipment and information

Clauses 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5.1, 7.1.5.2, 7.1.5, 7.1.6, 7.2, 7.3, 7.4, 7.5.1, 7.5.2, 7.5.3.

You must work out what you need — people, equipment, space, systems — to run the quality system.

Evidence: Resource planning. Budgets. Evidence of decisions when demand changed.

You must have enough of the right people to do the work properly.

Evidence: Staffing levels against workload. Cover arrangements for absence.

You must be able to answer: Are your buildings, equipment, vehicles and IT systems suitable, and are they maintained?

Evidence: Maintenance schedule and records. Service reports. Equipment list.

The must be working environment suitable — temperature, noise, cleanliness, lighting, and how people are treated.

Evidence: What conditions the work needs. Any monitoring you do. Housekeeping checks.

Where you measure or test things to prove they are right, the must be equipment suitable and looked after.

Evidence: A list of measuring equipment. Its condition and identification.

That equipment must be calibrated or checked against a recognised standard, at set intervals.

Evidence: Calibration certificates. A calibration schedule. Labels showing status.

If you rely on software or a digital tool to measure or control quality, you must have checked it gives the right answer.

Evidence: A validation record for the software. Test results. Who checked it and when.

If a piece of equipment is found to be wrong, you must check what you measured with it before, and act on it.

Evidence: Records of what was done about product already measured with faulty equipment.

You must have thought about the knowledge your business depends on, and what happens if the person holding it leaves.

Evidence: Written procedures. Training notes. Cross-training. Anything that captures know-how.

You must know what skills and experience each job needs.

Evidence: Job descriptions or a skills matrix stating the requirement.

You must be able to show that the people doing the work have those skills.

Evidence: Certificates, licences, CVs, training records, signed-off competence checks.

When someone is not competent yet, you must do something about it and check it worked.

Evidence: Training given. Evidence you checked afterwards, not just that they attended.

Your people must know the policy, the objectives that apply to them, how their work matters, and what happens if things go wrong.

Evidence: Induction and refresher material. Ask staff — this is tested by conversation, not paperwork.

Your people must know what standard of behaviour is expected of them.

Evidence: Induction and refresher material covering conduct and quality culture. Ask staff.

You must have decided what needs to be communicated about quality, to whom, when, and by whom.

Evidence: A simple communication plan or table. Evidence it happens.

You must have the documents and records the standard asks for, plus whatever else you need to run the business.

Evidence: A list of documents and records held.

When a document is created or changed, it must be checked and approved by the right person before people use it.

Evidence: Approval on the document — a signature, a system record, a version note.

People must be able to find the current version where they need it, and are old versions taken away.

Evidence: How documents are shared. Evidence old copies are removed from desks and shared drives.

Records must be kept safe, readable, and kept for as long as you said you would keep them.

Evidence: A retention list. Storage arrangements. Backups. Access controls.

8 Doing the work

Clauses 8.1, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.3.1, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.3.6, 8.4.1, 8.4.2, 8.4.3, 8.5.1, 8.5.2, 8.5.3, 8.5.4, 8.5.5, 8.5.6, 8.6, 8.7.

You must have planned how the work gets done — what has to happen, what 'good' looks like, and what records you will keep.

Evidence: Process documents, work instructions, drawings, specifications, acceptance criteria.

You must control work you have outsourced to someone else.

Evidence: What you agreed with them. Checks on what they deliver.

You must have a clear way for customers to place orders, ask questions, complain, and get information.

Evidence: Enquiry and order routes. Complaint handling. Customer contact records.

Before you offer a product or service, you must work out exactly what is required, including legal requirements.

Evidence: Specifications. Applicable regulations. Anything the customer expects without saying.

Before you accept an order, you must check you can actually do it.

Evidence: Order or contract review. A sign-off. Evidence capacity and capability were considered.

If the requirements change after the order, you must update your documents and tell the people affected.

Evidence: Amendment records. Evidence the change reached production, purchasing and despatch.

If you design anything, you must plan the design work — the stages, the checks and who does them.

Evidence: A design plan. If you do no design, answer N/A and write why.

The design must plan set the stages, who does what, how long it should take, and who needs to be involved.

Evidence: The plan showing stages, responsibilities, timing, and any customer or supplier involvement needed.

You must write down what the design has to achieve before you start.

Evidence: Design inputs: performance, legal requirements, previous similar designs, customer needs.

You must be able to answer: During design, do you review, verify and validate the work, and keep the records?

Evidence: Design review notes. Test or calculation results. Proof it works in real use.

The design must outputs say clearly what is acceptable and what is needed to make or deliver the thing.

Evidence: Drawings, specifications, acceptance criteria, handling and storage requirements.

Design changes must be controlled and approved before they take effect.

Evidence: Change records. Approval. What was done about product already made or in the field.

You must decide which suppliers and subcontractors you will use, based on written criteria.

Evidence: Approved supplier list. Selection criteria. Initial checks before first use.

You must review how your suppliers are performing, and act when one lets you down.

Evidence: Scorecards, ratings or review notes. Records of action taken on a poor supplier.

You must check what suppliers deliver before you use it.

Evidence: Goods-in inspection. Certificates checked. Evidence of what was verified.

You must tell suppliers clearly what you need — specification, quantity, qualifications, approvals.

Evidence: Purchase orders. Specifications sent. Quality requirements in the contract.

The must be work carried out under controlled conditions — right instructions, right equipment, right people, checks at the right points.

Evidence: Work instructions available at the job. Inspection points. Competent staff assigned.

You must be able to tell one item, batch or job from another, and you must be able to tell what has been checked and what has not.

Evidence: Labels, job numbers, batch numbers, status markings. Traceability records where needed.

You must look after property belonging to customers or suppliers while it is with you, and tell them if it is lost or damaged.

Evidence: Records of customer property held. Reports of loss or damage. This includes customer data and drawings.

You must protect the product or its parts during handling, storage, packing and delivery.

Evidence: Storage conditions. Packing method. Shelf life or stock rotation where relevant.

You must meet what you promised after delivery — warranty, servicing, support, disposal.

Evidence: Warranty terms. Service records. Support arrangements.

When a change is needed during production or service delivery, it must be reviewed and approved before it happens.

Evidence: Change records with who approved them and what was checked.

When you change how the work is done, you must check what else the change affects before you make it.

Evidence: Change records showing the knock-on effects considered: people, equipment, suppliers, documents.

There must be a check that the product or service meets requirements before it goes to the customer.

Evidence: Final inspection or release record. Who signed it off.

When something is wrong, it must be identified and held so it cannot be used or shipped by mistake.

Evidence: Quarantine area, labelling or system hold. Nonconformance reports.

There must be a written decision on what to do with it — scrap, rework, accept under concession, or return — and who decided.

Evidence: The disposition and who authorised it. Customer agreement where needed.

If it has already gone to the customer, you must act on it and tell them.

Evidence: Recall or notification records. Action taken.

9 Checking how you are doing

Clauses 9.1.1, 9.1.2, 9.1.3, 9.2.1, 9.2.2, 9.3.1, 9.3.2, 9.3.3.

You must have decided what you will measure, how, how often, and when you will look at the results.

Evidence: A monitoring plan or a KPI list with frequency.

You must find out what customers think of you.

Evidence: Surveys, complaint data, delivery performance, returns, meeting notes, repeat orders.

You must actually analyse the data, and does anything change as a result.

Evidence: Trend charts or reports. Actions taken from what the data showed.

You must audit your own quality system, and cover the whole standard over time.

Evidence: An audit programme. Audit reports. Findings raised.

The must be audit plan based on what matters and on past problems, rather than the same rotation every year.

Evidence: The reasoning behind the programme. More attention where there is more risk or past failure.

The auditors must be independent of the work they audit, and competent to do it.

Evidence: Auditor training. Who audited what. In a small firm: swapping with a colleague or using an outsider.

Audit findings must be fixed, and does someone check the fix worked.

Evidence: Corrective actions closed. Evidence of follow-up.

Senior management must review the quality system at planned intervals.

Evidence: Review dates and attendance over the last couple of years.

The review must cover everything the standard asks for.

Evidence: An agenda listing: previous actions, changes, performance, complaints, audit results, supplier performance, resources, risks, improvement.

The review must produce decisions and actions, not just minutes.

Evidence: Decisions on improvement, changes to the system, and resources. An action list with owners and dates.

10 Putting things right and getting better

Clauses 10.1, 10.2.1, 10.2.2, 10.3.

You must look for ways to improve, not only wait for problems.

Evidence: Improvement ideas register. Projects completed. Suggestions from staff.

When something goes wrong, you must deal with the immediate problem first.

Evidence: The correction: repair, replace, refund, redo.

You must then ask why it happened, rather than stopping at the fix.

Evidence: Root cause notes. A method such as 5 Whys. 'Operator error' is rarely a root cause.

You must check whether the same thing could happen somewhere else.

Evidence: Evidence you looked at other lines, sites, products or customers.

You must check later that the action actually worked.

Evidence: Follow-up record with a date, after enough time has passed to tell.

You must keep records of what went wrong, why, what you did, and the result.

Evidence: A corrective action log with all four.

You must be able to show that things are better this year than last.

Evidence: Trends over time. Fewer complaints or defects. Objectives achieved. Completed improvements.

Using this document

Nothing above asks for a manual, a template pack, or a filing system. It asks for decisions that have been taken deliberately and can be shown to have been taken — which is a far smaller job than most organisations expect, and a different one.

Length is not compliance. A procedure nobody follows is worse than no procedure, because an auditor finds the gap between the two. The test we apply is whether the person who has to do the job recognises their own work in what is written down.

What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 9001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles