Knowledge base

ISO 9001:2026: Documentation and Compliance Requirements

A simple, clause-by-clause guide to what ISO 9001:2026 expects an organisation to document and what an auditor may ask to see as evidence.

Prem Kumar Dvivedi · 12. September 2026

4. Understanding Your Organisation and Its Context

Clauses 4.1, 4.2, 4.3 and 4.4

Understanding external issues

You should identify the external factors that may affect your quality performance, such as customers, competitors, suppliers, laws, technology and economic conditions.

Evidence an auditor may ask for:

A simple list or table of these issues, along with evidence that it is reviewed regularly.

Understanding internal issues

You should identify internal factors that can affect quality, such as employee skills, equipment, finances, organisation structure and working methods.

Evidence:

A record of these internal issues and proof that they are reviewed and updated when necessary.

Considering climate change

You need to consider whether climate change is relevant to your organisation and record your conclusion.

Evidence:

A documented decision explaining whether climate change affects your organisation and, where relevant, what action is being taken.

Identifying interested parties

You should identify the people and organisations that can affect your quality system or have expectations from your organisation. These may include customers, employees, owners, suppliers and regulators.

Evidence:

A list of relevant interested parties.

Understanding their requirements

For each interested party, identify what they expect from your organisation and which requirements you need to meet.

Evidence:

A record showing the expectations of each interested party and the requirements that apply to your organisation.

Defining the scope of the quality management system

You should clearly define what your quality management system covers, including relevant products, services, locations and activities.

Evidence:

A documented scope statement and, where applicable, your existing certificate wording.

Justifying non-applicable requirements

If any requirement of the standard does not apply to your organisation, you should document which requirement it is and explain why it is not applicable.

Evidence:

A documented justification showing why the requirement does not apply.

Identifying your processes

You should identify the main processes in your organisation, what goes into each process, what comes out of it and who is responsible for it.

Evidence:

A process map or a simple list showing processes, responsibilities and their connections.

Measuring process performance

You should know how well your processes are working and have suitable methods to measure their performance.

Evidence:

KPIs or other performance measures and recent results.

________________________________________

5. Leadership

Clauses 5.1.1, 5.1.2, 5.2.1, 5.2.2 and 5.3

Leadership involvement

Top management should be able to show how the quality management system is used when making business decisions.

Evidence:

Management review records, resource approvals, staffing decisions and other examples of management involvement.

Encouraging people to report problems

Employees should feel comfortable raising problems, reporting mistakes and identifying risks without fear of blame.

Evidence:

A defined way for employees to raise concerns and records showing that issues are addressed. Auditors may also speak directly with employees.

Providing necessary resources

Top management should ensure that the quality system has enough people, time, money, equipment and other resources.

Evidence:

Budgets, recruitment or staffing decisions, equipment purchases and records showing that resource requirements were addressed.

Understanding customer requirements

You should understand what your customers require, including requirements that may not be directly stated but are necessary for the product or service.

Evidence:

Contracts, purchase orders, customer specifications and records of agreed requirements.

Promoting a quality culture

Leaders should demonstrate through their actions that quality, integrity and meeting requirements are important.

Evidence:

Management communications, code of conduct, quality initiatives and examples of decisions that support quality.

Monitoring customer requirements

You should regularly check whether customer requirements are being met and take action when they are not.

Evidence:

Delivery records, quality data, complaints and corrective actions.

Establishing a quality policy

You should have a documented quality policy that reflects your business activities and direction.

Evidence:

A current, approved and dated quality policy and evidence that it supports the organisation's business objectives.

Commitment to meeting requirements and improving

The quality policy should include a commitment to meeting applicable requirements and continually improving the quality management system.

Evidence:

Both commitments clearly included in the quality policy.

Making the policy understood

Employees should know that the quality policy exists and understand its basic purpose.

Evidence:

Training, induction material, internal communication or workplace displays. Auditors may ask employees about it.

Defining responsibilities

Everyone should understand who is responsible for different parts of the quality management system.

Evidence:

Organisation charts, job descriptions, responsibility matrices or similar records.

Defining authority

People should know who has the authority to stop work, hold a product or escalate a quality problem when necessary.

Evidence:

Defined responsibilities and authority, supported by employee awareness.

________________________________________

6. Planning

Clauses 6.1.1, 6.1.2, 6.1.3, 6.2.1, 6.2.2 and 6.3

Identifying risks and opportunities

You should identify risks and opportunities based on your organisation's context and the needs of interested parties.

Evidence:

A risk and opportunity assessment linked to the issues identified in Clause 4.

Taking action on significant risks

You should decide what action is needed for important risks and actually implement those actions.

Evidence:

Action plans showing responsibilities, deadlines and completion status.

Identifying opportunities for improvement

Risk management should not be the only focus. You should also identify opportunities to improve your products, services or processes.

Evidence:

Records of improvement opportunities and examples of opportunities that were acted upon.

Checking whether actions worked

After taking action, you should check whether it achieved the intended result.

Evidence:

Follow-up reviews and evidence showing whether the situation improved.

Setting quality objectives

You should establish measurable quality objectives.

Evidence:

Written objectives with clear targets and measurable results. For example, "reduce customer complaints by 10%" is measurable; "improve quality" is not.

Connecting objectives with the quality policy

Your quality objectives should support your quality policy and be communicated to relevant employees.

Evidence:

A clear connection between the policy and objectives, plus communication or training records.

Planning how objectives will be achieved

For each objective, define what needs to be done, who will do it, when it will be completed, what resources are required and how success will be measured.

Evidence:

An action plan and progress records.

Planning changes

When a significant change is made, you should plan it rather than allowing the change to happen without proper consideration.

Evidence:

Change management records covering the purpose, possible effects, resources and responsibilities.

________________________________________

7. Support — People, Resources and Information

Clauses 7.1.1 to 7.5.3

Providing resources

You should determine what resources are needed to operate and maintain your quality management system.

Evidence:

Resource plans, budgets and records showing how changing business needs are addressed.

Providing competent people

You should have enough people with the right skills to perform the required work.

Evidence:

Staffing records, workload analysis and arrangements for employee absence.

Infrastructure

Your buildings, equipment, vehicles, IT systems and other infrastructure should be suitable and properly maintained.

Evidence:

Maintenance schedules, service records and equipment lists.

Work environment

The working environment should support effective work. This may include suitable temperature, lighting, cleanliness, noise levels and working conditions.

Evidence:

Defined requirements, monitoring records and workplace inspection records where relevant.

Monitoring and measuring equipment

Where equipment is used to measure or verify quality, it should be suitable and properly maintained.

Evidence:

A list of measuring equipment and records showing its condition and identification.

Calibration and verification

Measuring equipment should be calibrated or verified at appropriate intervals against recognised standards.

Evidence:

Calibration certificates, schedules and identification labels.

Validating software and digital tools

If software or digital tools are used to measure, monitor or control quality, you should make sure they work correctly.

Evidence:

Validation records, test results and information about who performed the validation and when.

Dealing with faulty equipment

If measuring equipment is found to be inaccurate or faulty, you should check whether previous results may have been affected and take appropriate action.

Evidence:

Records showing what was checked and what action was taken.

Managing organisational knowledge

You should identify important knowledge that your organisation depends on and consider how that knowledge will be retained if key employees leave.

Evidence:

Procedures, training records, work instructions, cross-training and other knowledge-sharing methods.

Defining competence requirements

You should know what skills, qualifications and experience are needed for each role.

Evidence:

Job descriptions, competency requirements or a skills matrix.

Demonstrating competence

You should be able to show that people performing work are competent.

Evidence:

Certificates, licences, CVs, training records and competency assessments.

Addressing competence gaps

When someone does not yet have the required competence, you should provide suitable training or other support and check whether it was effective.

Evidence:

Training records and evidence of competency evaluation after training.

Employee awareness

Employees should understand the quality policy, relevant objectives, how their work contributes to quality and what may happen when requirements are not met.

Evidence:

Induction and refresher training. Auditors may also discuss these topics directly with employees.

Quality culture and expected behaviour

Employees should understand the behaviour and standards expected of them.

Evidence:

Induction programmes, training materials, codes of conduct and employee discussions.

Communication

You should determine what quality-related information needs to be communicated, to whom, when and by whom.

Evidence:

A communication plan or simple communication matrix, supported by relevant records.

Documented information

You should maintain the documented information required by ISO 9001 and any additional documents and records needed to operate your business effectively.

Evidence:

A list or system showing the documents and records maintained.

Creating and approving documents

New documents and changes to existing documents should be reviewed and approved before they are used.

Evidence:

Approvals, electronic workflow records, signatures or version-control information.

Controlling document versions

Employees should have access to the current version of documents they need, while obsolete versions should be controlled or removed.

Evidence:

Document control procedures, electronic controls and evidence that outdated copies are not being used.

Protecting records

Records should remain readable, secure and available for the required retention period.

Evidence:

Retention schedules, storage arrangements, backups and access controls.

________________________________________

8. Operation — Doing the Work

Clauses 8.1 to 8.7

Planning and controlling operations

You should plan how work will be performed, what requirements must be met and what records need to be maintained.

Evidence:

Process documents, work instructions, drawings, specifications and acceptance criteria.

Controlling outsourced processes

Processes performed by external providers should also be properly controlled.

Evidence:

Agreements, specifications, supplier requirements and checks on delivered work.

Customer communication

Customers should have clear ways to place orders, ask questions, provide feedback, make complaints and receive information.

Evidence:

Communication channels, enquiry records, order records and complaint-handling records.

Understanding product and service requirements

Before providing a product or service, you should identify all relevant requirements, including legal and regulatory requirements.

Evidence:

Specifications, contracts, regulations and customer requirements.

Reviewing orders and contracts

Before accepting an order, you should confirm that your organisation has the capability and resources to meet the requirements.

Evidence:

Contract or order review records and approval records.

Managing changes in requirements

If customer requirements change after an order is accepted, the relevant documents should be updated and the change communicated to affected people.

Evidence:

Change records and evidence that the updated information reached relevant departments.

________________________________________

Design and Development

Planning design activities

If your organisation designs products or services, you should plan the design process, including stages, responsibilities, reviews and checks.

Evidence:

A documented design plan. If design does not apply, document why.

Defining design inputs

Before starting design work, you should identify what the design needs to achieve.

Evidence:

Customer requirements, performance requirements, legal requirements and relevant previous designs.

Reviewing and testing the design

During design, the organisation should review, verify and validate the design as appropriate.

Evidence:

Design review records, calculations, test results and validation records.

Defining design outputs

Design outputs should clearly explain what the product or service needs to meet and what is required for production or delivery.

Evidence:

Drawings, specifications, acceptance criteria and handling or storage requirements.

Controlling design changes

Design changes should be reviewed, approved and properly controlled before implementation.

Evidence:

Change records, approvals and records showing how existing products or services were handled.

________________________________________

Managing External Providers and Suppliers

Selecting suppliers

Suppliers and subcontractors should be selected using defined criteria.

Evidence:

Approved supplier lists, supplier evaluation criteria and initial evaluation records.

Monitoring supplier performance

Supplier performance should be reviewed and action should be taken when performance does not meet requirements.

Evidence:

Supplier ratings, scorecards, review records and corrective actions.

Checking purchased products and services

You should verify that products or services received from suppliers meet your requirements.

Evidence:

Incoming inspection records, certificates and verification records.

Communicating requirements to suppliers

Suppliers should clearly understand what you require from them.

Evidence:

Purchase orders, specifications, contracts and quality requirements.

________________________________________

Production and Service Delivery

Controlled working conditions

Work should be performed under controlled conditions using suitable instructions, equipment, competent people and appropriate inspection points.

Evidence:

Work instructions, inspection records and competency records.

Identification and traceability

Where necessary, you should be able to identify products, batches, jobs or services and know their inspection or approval status.

Evidence:

Labels, job numbers, batch numbers, status markings and traceability records.

Protecting customer and supplier property

Customer or supplier property should be protected while it is under your control.

Evidence:

Records of property received and records of any loss or damage. This can include data, drawings and other information.

Protecting products

Products should be protected during handling, storage, packaging and delivery.

Evidence:

Storage requirements, packaging methods, shelf-life controls and stock rotation records where applicable.

Post-delivery activities

You should meet applicable post-delivery requirements such as warranty, servicing, support, maintenance or disposal.

Evidence:

Warranty conditions, service records and support arrangements.

Controlling operational changes

Changes made during production or service delivery should be reviewed and approved before implementation.

Evidence:

Change records showing approval and evaluation.

Checking the impact of changes

Before changing a process, consider how the change may affect people, equipment, suppliers, documents and other activities.

Evidence:

Change records showing the impacts considered.

Final release

Products or services should be checked before being released to the customer.

Evidence:

Inspection, testing or release records showing who approved the release.

________________________________________

Controlling Nonconforming Outputs

Identifying problems

When a product or service does not meet requirements, it should be clearly identified and controlled to prevent unintended use or delivery.

Evidence:

Quarantine areas, labels, system blocks and nonconformance reports.

Deciding what to do with nonconforming outputs

There should be a documented decision on whether the item will be corrected, reworked, scrapped, returned or accepted under an approved concession.

Evidence:

Disposition records and approval from the responsible person or customer where required.

Dealing with problems after delivery

If a nonconforming product or service has already reached the customer, appropriate action should be taken and the customer informed where necessary.

Evidence:

Customer notifications, recall records and corrective action records.

________________________________________

9. Performance Evaluation — Checking How You Are Doing

Clauses 9.1.1 to 9.3.3

Deciding what to measure

You should determine what needs to be measured, how it will be measured, how often it will be measured and when results will be reviewed.

Evidence:

A monitoring plan, KPI list or similar record.

Monitoring customer satisfaction

You should collect information about how customers view your products and services.

Evidence:

Customer surveys, complaints, returns, delivery performance, meetings and repeat business information.

Analysing performance data

It is not enough to collect data. You should analyse it and take action when the results show a problem or an opportunity.

Evidence:

Reports, trends, KPI analysis and actions taken.

Internal audits

You should audit your quality management system and ensure that all relevant requirements are covered over time.

Evidence:

An internal audit programme, audit reports and recorded findings.

Planning audits based on risk

Your audit programme should consider the importance of processes, risks and previous problems rather than simply following the same schedule every year.

Evidence:

The reason behind the audit frequency and scope, particularly where risks or previous failures are higher.

Auditor competence and independence

Internal auditors should be competent and should be independent from the activities they audit.

Evidence:

Auditor training records, audit assignments and evidence of independence.

Correcting audit findings

Audit findings should be addressed, and the organisation should check whether the corrective action was effective.

Evidence:

Corrective action records and follow-up verification.

Management review

Top management should review the quality management system at planned intervals.

Evidence:

Management review schedules, attendance records and meeting records.

What management review should cover

Management review should consider the information required by the standard, including previous actions, changes, performance, customer feedback, audits, suppliers, resources, risks and improvement.

Evidence:

A management review agenda or records covering the required inputs.

Taking decisions and actions

Management review should result in decisions and actions, not simply meeting minutes.

Evidence:

Action plans, assigned responsibilities, deadlines and decisions regarding resources or improvements.

________________________________________

10. Corrective Action and Continual Improvement

Clauses 10.1, 10.2.1, 10.2.2 and 10.3

Looking for improvement

You should actively identify opportunities to improve instead of waiting for problems to occur.

Evidence:

Improvement projects, employee suggestions, improvement registers and completed initiatives.

Correcting problems immediately

When something goes wrong, first deal with the immediate problem.

Evidence:

Records of repair, replacement, rework, refund or other immediate correction.

Finding the root cause

After correcting the problem, determine why it happened so that it does not happen again.

Evidence:

Root cause analysis, such as the 5 Whys or another suitable method.

Checking for similar problems

Consider whether the same problem could occur elsewhere in the organisation.

Evidence:

Records showing that other products, processes, locations or customers were considered.

Checking corrective action effectiveness

After corrective action has been implemented, check whether it actually solved the problem.

Evidence:

A follow-up review conducted after sufficient time has passed to confirm effectiveness.

Keeping corrective action records

You should maintain records showing what happened, why it happened, what action was taken and what the result was.

Evidence:

A corrective action or nonconformance log containing these details.

Demonstrating improvement

You should be able to demonstrate that your quality performance is improving over time.

Evidence:

Performance trends, reduced complaints or defects, achieved objectives and completed improvement initiatives.

________________________________________

How to Use This Guide

ISO 9001:2026 does not mean that you need to create a large manual, a huge collection of templates or unnecessary paperwork.

The focus is on making decisions, implementing them and being able to demonstrate that they are working.

Good documentation should support the way your organisation actually works. More documents do not automatically mean better compliance.

A long procedure that employees do not follow can create more problems than a simple procedure that reflects actual working practices.

The key question is:

Does your documented system reflect what your people actually do, and can you show evidence that it is working?

That is what makes documentation useful — and what helps demonstrate effective implementation during an audit.


What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 9001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles