What Does a Company Need for ISO 9001 Certification?
ISO 9001:2015 is organized around ten clauses, but Clauses 4 through 10 are where the actual management-system requirements live. Below is a practical summary of what each area asks an organization to do — in plain language, not clause text.
1. Define the QMS Scope
Decide which products, services, sites, and processes the certificate will cover, and document that scope clearly.
2. Understand Interested Parties and Context
Identify the internal and external issues, and the relevant interested parties (customers, regulators, etc.), that affect your ability to consistently deliver conforming products or services.
3. Leadership Responsibilities
Top management must demonstrate visible commitment to the QMS — not delegate it entirely to a "quality manager" and step away.
4. Quality Policy
A documented commitment, appropriate to your organization, that is communicated and understood internally.
5. Quality Objectives
Measurable goals aligned with the quality policy, tracked and reviewed — not vague aspirations.
6. Risk-Based Thinking
Identify risks and opportunities that could affect your ability to meet objectives, and address them through your existing planning process.
7. Resources and Competence
Ensure people, infrastructure, and work environment are adequate, and that staff performing quality-affecting work are competent (by training, experience, or qualification).
8. Operational Controls
Plan and control the processes needed to deliver products or services — from customer requirements through to delivery.
9. Documented Information
Keep the documents and records genuinely needed to run and prove your processes — sized to your organization's actual complexity.
10. Internal Audit
Periodically check that the QMS conforms to your own requirements and the standard, and is effectively implemented.
11. Management Review
Top management formally reviews QMS performance at planned intervals and drives improvement decisions from it.
12. Corrective Action
When something goes wrong, correct it and address the root cause so it doesn't recur.
13. Certification Audit
An accredited certification body independently audits the QMS against all of the above (see our certification process guide for how this stage works).
What Documents Are Actually Required?
This is where many companies over-build. ISO 9001:2015 does not require a separate written procedure for every clause. It requires a documented scope, quality policy, and quality objectives, a defined set of records (such as evidence of competence, monitoring results, and audit results), and whatever additional documented information your organization determines it needs to operate effectively. A five-person company and a five-hundred-person company can both be fully compliant with very different amounts of paperwork.
Common Mistakes
- Creating too many procedures — documenting processes nobody will actually follow, just to "be safe."
- Copying templates without implementation — a downloaded quality manual that doesn't reflect how the business actually operates.
- Poor scope definition — a scope that's vague, or doesn't match what customers are actually told is certified.
- Weak internal audit — treating internal audits as a formality instead of a genuine check for gaps.
- No management evidence — leadership commitment exists in principle but leaves no trace in meeting minutes or decisions.
From Our ISO 9001 Consulting Experience
The gap we see most often isn't missing documentation — it's documentation that doesn't match reality. A quality manual describing a process nobody follows is a bigger audit risk than having fewer, but accurate, documents.
Unsure Whether Your Current QMS Meets ISO 9001 Requirements?
Send us one specific requirements question and get a focused professional read — US$19, one-time.
Start a $19 Quick CheckFrequently Asked Questions
Does every clause of ISO 9001 require a written procedure?
A: No. The 2015 version of ISO 9001 moved away from mandating a fixed list of procedures. Documentation should be whatever is genuinely needed for your organization to plan, run, and control its processes effectively — not a fixed checklist of documents.
What documents are actually required for ISO 9001?
A: A small number of records and a documented scope, quality policy, and quality objectives are effectively required. Beyond that, most documentation exists because the organization decided it was needed to control a process reliably, not because a clause explicitly demands that specific document.
Can a small company meet ISO 9001 requirements without a full-time quality team?
A: Yes. ISO 9001 is scalable by design. Small organizations typically assign quality responsibilities across existing roles rather than hiring a dedicated department.
Is risk-based thinking a separate program you need to build?
A: No. Risk-based thinking is meant to be built into existing processes — planning, decision-making, and reviews — rather than run as a standalone risk-management project.