ISO 9001 Documentation: Quality Management System Document Review
ISO 9001 certification requires documented information that auditors can verify. Here's what documentation you need, common audit findings, and how to review QMS documents for completeness.
ISO 9001 is the world's most widely adopted quality management standard. Over one million organisations across 170 countries hold certification. Every one of them maintains documentation that must satisfy external auditors — and every audit cycle, documentation gaps are among the most common findings.
The 2015 revision of ISO 9001 moved away from prescriptive documentation requirements ("you must have a quality manual") toward a more flexible approach ("you must maintain documented information as determined necessary for QMS effectiveness"). This flexibility is both a benefit and a trap: organisations have more freedom in how they document, but less clarity on what's sufficient.
What ISO 9001:2015 Requires You to Document
Mandatory Documented Information
The standard explicitly requires these documents:
| Clause | Required Document | Purpose |
|---|---|---|
| 4.3 | Scope of the QMS | Defines boundaries — what's covered and what's excluded |
| 5.2 | Quality policy | Top management's commitment to quality |
| 6.2 | Quality objectives | Measurable targets at relevant functions and levels |
| 7.1.5 | Monitoring and measuring resources | Evidence of measurement system adequacy |
| 7.2 | Competence records | Evidence of personnel competence (training, education, experience) |
| 8.1 | Operational planning and control | Documents needed to have confidence processes are carried out as planned |
| 8.2.3 | Review of requirements for products/services | Records of review outcomes |
| 8.3.2 | Design and development planning | Documentation of the design process |
| 8.3.3 | Design and development inputs | Records of input requirements |
| 8.3.4 | Design and development controls | Review, verification, and validation records |
| 8.3.5 | Design and development outputs | Records that outputs meet input requirements |
| 8.3.6 | Design and development changes | Change records including authorisation |
| 8.4 | Control of externally provided processes | Criteria for evaluation, selection, monitoring of external providers |
| 8.5.2 | Identification and traceability | Records to enable traceability (where required) |
| 8.5.3 | Property belonging to customers/external providers | Records of property and any issues |
| 8.5.6 | Control of changes | Records of change review results and authorisation |
| 8.6 | Release of products/services | Evidence of conformity, traceability to authorising person |
| 8.7 | Control of nonconforming outputs | Records of nonconformity, actions taken, concessions obtained |
| 9.1.1 | Monitoring, measurement, analysis, evaluation | Evidence of results |
| 9.2 | Internal audit | Audit programme and audit results |
| 9.3 | Management review | Records of management review outputs |
| 10.2 | Nonconformity and corrective action | Nature of nonconformities, actions taken, results |
Documents You'll Typically Need (Not Explicitly Required but Expected)
| Document | Why Auditors Expect It |
|---|---|
| Process maps/flowcharts | Demonstrate the process approach (Clause 4.4) |
| Procedures for key processes | Show how processes are controlled |
| Work instructions | Detailed operational guidance where needed |
| Risk register | Evidence of risk-based thinking (Clause 6.1) |
| Document control procedure | How documented information is managed |
| Record retention schedule | How long records are kept |
| Organisational chart | Roles, responsibilities, and authorities (Clause 5.3) |
Document Control Requirements (Clause 7.5)
ISO 9001:2015 Clause 7.5 requires documented information to be controlled:
| Requirement | What It Means | Common Failure |
|---|---|---|
| Identification | Each document has a unique identifier | Documents without version numbers or IDs |
| Format | Consistent format appropriate to the content | Random formats across the organisation |
| Review and approval | Documents reviewed and approved before use | Documents in use that were never formally approved |
| Distribution | Relevant documents available where needed | Obsolete versions still accessible |
| Storage and preservation | Documents protected from loss, damage, deterioration | No backup, no access controls |
| Control of changes | Changes identified, reviewed, and approved | Undocumented changes — "someone updated the procedure but didn't change the version" |
| Retention and disposition | Records retained for defined periods, then disposed | No retention schedule, or records disposed too early |
Common Audit Findings Related to Documentation
Finding 1: Procedures Don't Match Practice
The documented procedure says one thing; the team does another. This is either a documentation gap (procedure not updated) or a compliance gap (team not following procedure). Either way, it's a nonconformity.
Prevention: Review procedures annually against actual practice. When practice changes, update the documentation within 30 days.
Finding 2: Missing Records
The standard requires records of training, internal audits, management reviews, corrective actions, and more. Missing records = missing evidence = audit finding.
Prevention: Create a records matrix listing every required record, who creates it, where it's stored, and how long it's retained.
Finding 3: Incomplete Management Reviews
Management review must address specific inputs (Clause 9.3.2) and produce specific outputs (Clause 9.3.3). Auditors check that meeting minutes cover all required topics. A management review that discusses quality policy but skips customer satisfaction data is incomplete.
Required inputs:
- Status of actions from previous reviews
- Changes in external/internal issues
- QMS performance and effectiveness (customer satisfaction, objectives, process performance, nonconformities, audit results, external provider performance)
- Adequacy of resources
- Risk and opportunity actions effectiveness
- Improvement opportunities
Finding 4: Quality Objectives Not Measurable
"Improve customer satisfaction" is not a measurable objective. "Increase customer satisfaction score from 7.2 to 8.0 by December 2026" is. Auditors check that objectives are measurable, have timeframes, and are monitored.
Finding 5: Outdated Documents Still in Circulation
An outdated procedure available on the shared drive — even if the current version exists — is a document control failure. All obsolete documents must be clearly identified or removed from access points.
Reviewing QMS Documentation
Quality Policy Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Relevance | 3 | Appropriate to the organisation's purpose and context |
| Commitment | 3 | Includes commitment to satisfy requirements and continual improvement |
| Framework for objectives | 2 | Provides a framework for setting quality objectives |
| Communication | 2 | Available to relevant interested parties, understood within the organisation |
| Currency | 1 | Reviewed at defined intervals, reflects current strategic direction |
Procedure Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Accuracy | 3 | Matches current practice — steps are correct and current |
| Completeness | 3 | All steps documented, inputs/outputs defined, responsibilities assigned |
| Clarity | 2 | Understandable by the intended user without additional explanation |
| Document control | 2 | Version controlled, approved, review date set |
| Consistency | 1 | Terminology consistent with other QMS documents |
Internal Audit Report Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Coverage | 3 | All QMS processes audited over the programme cycle |
| Finding classification | 3 | Nonconformities clearly distinguished from observations |
| Evidence | 2 | Findings supported by objective evidence |
| Corrective actions | 2 | Each nonconformity has a corrective action with owner and deadline |
| Follow-up | 2 | Verification that corrective actions were effective |
The ISO 9001 Documentation Review Cycle
| Frequency | What to Review | Who |
|---|---|---|
| Before external audit | All mandatory documented information, recent management review minutes, corrective action close-out evidence | Quality manager + internal audit team |
| Annually | All procedures against current practice, quality objectives progress, document control compliance | Process owners + quality manager |
| After significant changes | Affected procedures, risk register, process maps | Relevant process owners |
| Quarterly | Corrective action status, quality objectives tracking, customer satisfaction data | Quality manager |
Frequently Asked Questions
Do I still need a quality manual under ISO 9001:2015?
No — the 2015 revision removed the explicit requirement for a quality manual. However, many organisations still maintain one as a convenient reference document. If you have one, keep it current; if you don't, you don't need to create one.
How many procedures do I need?
Only as many as your organisation needs to ensure effective process control. The standard doesn't specify a number. A small organisation with simple processes might need 10-15 procedures. A large manufacturer might need 50+. The test: can you demonstrate to an auditor that your processes are controlled?
Can I use electronic documents?
Yes — ISO 9001:2015 explicitly references "documented information" rather than "documents and records," accommodating electronic systems. Ensure your electronic system meets document control requirements (version control, access control, backup, approval workflows).
How do I handle documentation for multiple sites?
Maintain a core QMS with site-specific supplements where processes differ. Ensure document control is consistent across all sites — this is a common audit focus for multi-site certifications.
What happens if an auditor finds a documentation nonconformity?
Minor nonconformity: you must submit a corrective action plan within a defined timeframe (usually 30-90 days) and provide evidence of implementation. Major nonconformity: may require a follow-up audit before certification is granted or renewed. Both require root cause analysis, not just a fix.
Can AI review help with ISO 9001 documentation?
AI review can check for completeness (are all required elements present?), consistency (does the procedure match other referenced documents?), clarity (is it understandable by the intended user?), and document control compliance (version numbers, review dates, approval). It cannot verify technical accuracy of process descriptions — that requires process owner review.
Key Takeaways
- ISO 9001:2015 requires specific documented information — 20+ document types across the standard's clauses.
- Document control (Clause 7.5) is non-negotiable — version control, approval, distribution, and retention must be managed.
- The most common audit findings are documentation-related — procedures not matching practice, missing records, incomplete management reviews.
- Quality objectives must be measurable with specific targets, timeframes, and monitoring.
- Review documentation before every external audit and annually against actual practice.
- AI review checks completeness, consistency, and clarity — process accuracy requires human verification.
- Flexibility in the 2015 standard is a benefit — document what you need for effective QMS operation, not what you think auditors want to see.
This article is for informational purposes only. ISO 9001 requirements are interpreted and assessed by accredited certification bodies. Consult your certification body or a qualified ISO consultant for guidance specific to your organisation and scope.