Knowledge base

ISO 9001 Documentation: What you Actually Need

A short reference on what ISO 9001 requires you to document, and what it does not.

Neha Dvivedi · 16 août 2026

ISO 9001 Documentation: What You Actually Need

ISO 9001 does not require organisations to create large amounts of paperwork. The focus is on having the right information and records needed to run the Quality Management System (QMS) effectively.

Here is a simple guide to what ISO 9001 requires you to document—and what it does not.

1. Documents You Must Maintain

ISO 9001 requires you to maintain documented information for the following:

• Scope of the QMS – What parts of your organisation and activities are covered by the QMS.

• Quality Policy – Your organisation's commitment and direction towards quality.

• Quality Objectives – The quality goals your organisation wants to achieve.

• Information needed to operate your processes – Any documented information necessary to ensure processes are performed properly.

The last point is intentionally flexible. ISO 9001 does not tell you exactly how much documentation you need. You decide what is necessary based on your organisation, processes, risks and operations.

2. Records You Must Keep

Records provide evidence that activities were actually completed and requirements were met.

Depending on your organisation and processes, you need to retain records such as:

• Evidence that monitoring and measuring equipment is suitable for its intended use.

• Evidence that employees are competent to perform their work.

• Evidence that processes were carried out as planned.

• Evidence that products and services meet the required specifications.

• Results of reviews of product and service requirements.

• Design and development records, where applicable.

• Records of evaluation and monitoring of external suppliers.

• Traceability records, where required.

• Records of customer property that was lost, damaged or otherwise found unsuitable.

• Results of reviewing changes.

• Records showing the release of products and services.

• Records of nonconformities and actions taken.

• Monitoring and measurement results.

• Internal audit programme and audit results.

• Management review results.

• Evidence showing the nature of nonconformities and actions taken.

• Results of corrective actions.

3. What ISO 9001 Does NOT Require

Since the 2015 revision, ISO 9001 no longer specifically requires:

• A Quality Manual

• A Management Representative

• Six specific documented procedures

Many organisations still use a Quality Manual or documented procedures because they find them useful. That's perfectly acceptable.

The important point is that these are choices, not mandatory requirements.

4. What Auditors Look for in Your Documents

Document Control

Documents should be:

• Clearly identified

• Approved before use

• Available where they are needed

• At the correct revision/version

For example, if the latest procedure is stored on a computer but employees are using an old printed copy on the shop floor, there is a document-control problem.

Current Information

Documents should reflect how work is actually being performed.

If a process changed 18 months ago but the procedure was never updated, an auditor may raise a finding.

Legibility and Protection

Records must remain:

• Readable

• Protected from damage or loss

• Protected from unauthorised changes

• Available for the required retention period

This applies to both paper and electronic records, including backups.

Retention

Your organisation should decide how long records need to be kept and ensure that the defined retention periods are followed.

5. Practical Tips for ISO 9001 Documentation

Write for the People Who Do the Work

A procedure should be easy for employees to understand and follow.

If employees cannot practically use the procedure, they are unlikely to follow it consistently.

Choose the Right Format

Documented information does not have to be a lengthy written procedure.

Depending on the process, you could use:

• Flowcharts

• Checklists

• Photographs

• One-page work instructions

• Tables

• Videos

Choose the format that makes the process easiest to understand and follow.

Don't Create Unnecessary Documents

Every document you create needs to be reviewed and kept up to date.

Fewer documents that are accurate and useful are better than many documents that are outdated or rarely used.

Keep Documents and Records Separate

A simple way to remember the difference is:

Documents = What should happen

Records = What actually happened

For example, a work instruction explains how an inspection should be performed. The completed inspection checklist provides evidence that the inspection was actually performed.

6. Common ISO 9001 Documentation Findings

Some common issues auditors identify include:

1. Outdated Procedures

The actual process has changed, but the documented procedure has not been updated.

2. Records That Do Not Provide Enough Evidence

A record may exist but may not prove that the ISO 9001 requirement was met.

For example, a training attendance sheet shows that someone attended training, but it does not necessarily prove that the person became competent.

3. Document Control Problems on the Shop Floor

The quality team may have the latest procedure in the document-management system, while employees are still using an old printed version.

Key Takeaway

ISO 9001 is not about creating paperwork for the sake of paperwork.

The objective is to maintain enough documented information to:

Define what needs to happen → Ensure people know how to do it → Provide evidence that it happened → Continually improve the process.

The best documentation is simple, useful, current and relevant to the way your organisation actually works.



What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 9001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles