Skip to content
TB
TeamBenchResources

ISO 9001 Documentation: Quality Management System Document Review

ISO 9001 certification requires documented information that auditors can verify. Here's what documentation you need, common audit findings, and how to review QMS documents for completeness.

TeamBench· Content Quality PlatformFebruary 9, 20269 min read

ISO 9001 is the world's most widely adopted quality management standard. Over one million organisations across 170 countries hold certification. Every one of them maintains documentation that must satisfy external auditors — and every audit cycle, documentation gaps are among the most common findings.

The 2015 revision of ISO 9001 moved away from prescriptive documentation requirements ("you must have a quality manual") toward a more flexible approach ("you must maintain documented information as determined necessary for QMS effectiveness"). This flexibility is both a benefit and a trap: organisations have more freedom in how they document, but less clarity on what's sufficient.

What ISO 9001:2015 Requires You to Document

Mandatory Documented Information

The standard explicitly requires these documents:

ClauseRequired DocumentPurpose
4.3Scope of the QMSDefines boundaries — what's covered and what's excluded
5.2Quality policyTop management's commitment to quality
6.2Quality objectivesMeasurable targets at relevant functions and levels
7.1.5Monitoring and measuring resourcesEvidence of measurement system adequacy
7.2Competence recordsEvidence of personnel competence (training, education, experience)
8.1Operational planning and controlDocuments needed to have confidence processes are carried out as planned
8.2.3Review of requirements for products/servicesRecords of review outcomes
8.3.2Design and development planningDocumentation of the design process
8.3.3Design and development inputsRecords of input requirements
8.3.4Design and development controlsReview, verification, and validation records
8.3.5Design and development outputsRecords that outputs meet input requirements
8.3.6Design and development changesChange records including authorisation
8.4Control of externally provided processesCriteria for evaluation, selection, monitoring of external providers
8.5.2Identification and traceabilityRecords to enable traceability (where required)
8.5.3Property belonging to customers/external providersRecords of property and any issues
8.5.6Control of changesRecords of change review results and authorisation
8.6Release of products/servicesEvidence of conformity, traceability to authorising person
8.7Control of nonconforming outputsRecords of nonconformity, actions taken, concessions obtained
9.1.1Monitoring, measurement, analysis, evaluationEvidence of results
9.2Internal auditAudit programme and audit results
9.3Management reviewRecords of management review outputs
10.2Nonconformity and corrective actionNature of nonconformities, actions taken, results

Documents You'll Typically Need (Not Explicitly Required but Expected)

DocumentWhy Auditors Expect It
Process maps/flowchartsDemonstrate the process approach (Clause 4.4)
Procedures for key processesShow how processes are controlled
Work instructionsDetailed operational guidance where needed
Risk registerEvidence of risk-based thinking (Clause 6.1)
Document control procedureHow documented information is managed
Record retention scheduleHow long records are kept
Organisational chartRoles, responsibilities, and authorities (Clause 5.3)

Document Control Requirements (Clause 7.5)

ISO 9001:2015 Clause 7.5 requires documented information to be controlled:

RequirementWhat It MeansCommon Failure
IdentificationEach document has a unique identifierDocuments without version numbers or IDs
FormatConsistent format appropriate to the contentRandom formats across the organisation
Review and approvalDocuments reviewed and approved before useDocuments in use that were never formally approved
DistributionRelevant documents available where neededObsolete versions still accessible
Storage and preservationDocuments protected from loss, damage, deteriorationNo backup, no access controls
Control of changesChanges identified, reviewed, and approvedUndocumented changes — "someone updated the procedure but didn't change the version"
Retention and dispositionRecords retained for defined periods, then disposedNo retention schedule, or records disposed too early

Common Audit Findings Related to Documentation

Finding 1: Procedures Don't Match Practice

The documented procedure says one thing; the team does another. This is either a documentation gap (procedure not updated) or a compliance gap (team not following procedure). Either way, it's a nonconformity.

Prevention: Review procedures annually against actual practice. When practice changes, update the documentation within 30 days.

Finding 2: Missing Records

The standard requires records of training, internal audits, management reviews, corrective actions, and more. Missing records = missing evidence = audit finding.

Prevention: Create a records matrix listing every required record, who creates it, where it's stored, and how long it's retained.

Finding 3: Incomplete Management Reviews

Management review must address specific inputs (Clause 9.3.2) and produce specific outputs (Clause 9.3.3). Auditors check that meeting minutes cover all required topics. A management review that discusses quality policy but skips customer satisfaction data is incomplete.

Required inputs:

  • Status of actions from previous reviews
  • Changes in external/internal issues
  • QMS performance and effectiveness (customer satisfaction, objectives, process performance, nonconformities, audit results, external provider performance)
  • Adequacy of resources
  • Risk and opportunity actions effectiveness
  • Improvement opportunities

Finding 4: Quality Objectives Not Measurable

"Improve customer satisfaction" is not a measurable objective. "Increase customer satisfaction score from 7.2 to 8.0 by December 2026" is. Auditors check that objectives are measurable, have timeframes, and are monitored.

Finding 5: Outdated Documents Still in Circulation

An outdated procedure available on the shared drive — even if the current version exists — is a document control failure. All obsolete documents must be clearly identified or removed from access points.

Reviewing QMS Documentation

Quality Policy Review Criteria

CriterionWeightWhat to Check
Relevance3Appropriate to the organisation's purpose and context
Commitment3Includes commitment to satisfy requirements and continual improvement
Framework for objectives2Provides a framework for setting quality objectives
Communication2Available to relevant interested parties, understood within the organisation
Currency1Reviewed at defined intervals, reflects current strategic direction

Procedure Review Criteria

CriterionWeightWhat to Check
Accuracy3Matches current practice — steps are correct and current
Completeness3All steps documented, inputs/outputs defined, responsibilities assigned
Clarity2Understandable by the intended user without additional explanation
Document control2Version controlled, approved, review date set
Consistency1Terminology consistent with other QMS documents

Internal Audit Report Review Criteria

CriterionWeightWhat to Check
Coverage3All QMS processes audited over the programme cycle
Finding classification3Nonconformities clearly distinguished from observations
Evidence2Findings supported by objective evidence
Corrective actions2Each nonconformity has a corrective action with owner and deadline
Follow-up2Verification that corrective actions were effective

The ISO 9001 Documentation Review Cycle

FrequencyWhat to ReviewWho
Before external auditAll mandatory documented information, recent management review minutes, corrective action close-out evidenceQuality manager + internal audit team
AnnuallyAll procedures against current practice, quality objectives progress, document control complianceProcess owners + quality manager
After significant changesAffected procedures, risk register, process mapsRelevant process owners
QuarterlyCorrective action status, quality objectives tracking, customer satisfaction dataQuality manager

Frequently Asked Questions

Do I still need a quality manual under ISO 9001:2015?

No — the 2015 revision removed the explicit requirement for a quality manual. However, many organisations still maintain one as a convenient reference document. If you have one, keep it current; if you don't, you don't need to create one.

How many procedures do I need?

Only as many as your organisation needs to ensure effective process control. The standard doesn't specify a number. A small organisation with simple processes might need 10-15 procedures. A large manufacturer might need 50+. The test: can you demonstrate to an auditor that your processes are controlled?

Can I use electronic documents?

Yes — ISO 9001:2015 explicitly references "documented information" rather than "documents and records," accommodating electronic systems. Ensure your electronic system meets document control requirements (version control, access control, backup, approval workflows).

How do I handle documentation for multiple sites?

Maintain a core QMS with site-specific supplements where processes differ. Ensure document control is consistent across all sites — this is a common audit focus for multi-site certifications.

What happens if an auditor finds a documentation nonconformity?

Minor nonconformity: you must submit a corrective action plan within a defined timeframe (usually 30-90 days) and provide evidence of implementation. Major nonconformity: may require a follow-up audit before certification is granted or renewed. Both require root cause analysis, not just a fix.

Can AI review help with ISO 9001 documentation?

AI review can check for completeness (are all required elements present?), consistency (does the procedure match other referenced documents?), clarity (is it understandable by the intended user?), and document control compliance (version numbers, review dates, approval). It cannot verify technical accuracy of process descriptions — that requires process owner review.

Key Takeaways

  • ISO 9001:2015 requires specific documented information — 20+ document types across the standard's clauses.
  • Document control (Clause 7.5) is non-negotiable — version control, approval, distribution, and retention must be managed.
  • The most common audit findings are documentation-related — procedures not matching practice, missing records, incomplete management reviews.
  • Quality objectives must be measurable with specific targets, timeframes, and monitoring.
  • Review documentation before every external audit and annually against actual practice.
  • AI review checks completeness, consistency, and clarity — process accuracy requires human verification.
  • Flexibility in the 2015 standard is a benefit — document what you need for effective QMS operation, not what you think auditors want to see.

This article is for informational purposes only. ISO 9001 requirements are interpreted and assessed by accredited certification bodies. Consult your certification body or a qualified ISO consultant for guidance specific to your organisation and scope.

iso-9001quality-managementqms-documentationiso-certificationdocument-controlquality-audit

Need consistent content quality across your team?

TeamBench lets you create custom AI reviewers that score content against your specific criteria. Submit content, get instant scored feedback, and improve with one click.

  • Create custom AI reviewers for your brand
  • Score content against your specific criteria
  • Instant feedback, one-click improvement
  • Free to start — no credit card required