Skip to main content
Contact Us

ISO 9001 Requirements: Every Clause (4 to 10), Explained

ISO 9001:2015 sets its auditable requirements across clauses 4 to 10. This page lists every sub-clause, grouped by clause, with what the requirement asks for and what an auditor looks for as evidence, plus a free ISO 9001 audit checklist you can tick off or download.

Last updated: 20 August 2026

ISO 9001 Lead Auditor: From A$849 + GST · exam voucher + 2 attempts included

Free ISO 9001 audit checklist (PDF): every requirement in clauses 4 to 10 as a printable, clause-by-clause checklist for building or auditing your QMS.

Download the audit checklist (PDF)

What Are the ISO 9001 Requirements?

ISO 9001:2015 is the international standard for a Quality Management System (QMS). Like every modern ISO management-system standard, it follows the Harmonized Structure: clauses 1 to 3 introduce the standard, and clauses 4 to 10 set the actual requirements your organisation must meet to be certified.

The requirements are deliberately generic so they fit any organisation, from a two-person workshop to a global manufacturer. They tell you what to achieve (a controlled, customer-focused, continually improving QMS) without dictating how to run your business. That is why the same seven clauses apply whether you make components, deliver services, or write software.

Each requirement in the standard is signalled by the word "shall". An auditor works through those "shall" statements and asks for evidence that you do what the clause requires. The tables below break clauses 4 to 10 into their sub-clauses, summarise what each one requires, and set out what an auditor typically looks for.

The 7 Requirement Clauses at a Glance

ISO 9001:2015 groups its requirements under seven clauses, each covering one area of the quality management system.

The seven ISO 9001:2015 requirement clauses (4 to 10) with a one-line summary of each.
Clause Title What it covers
4Context of the organisationUnderstanding your organisation, interested parties, and the scope and processes of the QMS.
5LeadershipTop-management commitment, the quality policy, and clear roles and responsibilities.
6PlanningAddressing risks and opportunities, setting quality objectives, and planning change.
7SupportPeople, infrastructure, competence, awareness, communication, and documented information.
8OperationRunning the operation, from customer requirements and design through to delivery and nonconformity control.
9Performance evaluationMonitoring, customer satisfaction, internal audit, and management review.
10ImprovementCorrective action for nonconformities and continual improvement of the QMS.

Clauses 4 to 7 build the system, clause 8 runs it, and clauses 9 and 10 check and improve it. This is the same Plan-Do-Check-Act cycle that underpins ISO 14001, ISO 45001, and ISO 27001, which is why organisations running more than one standard can share a single management-system backbone.

ISO 9001:2015 Requirements, Clause by Clause

Below is every requirement sub-clause in ISO 9001:2015 clauses 4 to 10, grouped by clause. For each one you get a plain-English summary of what the clause requires and a note on what an auditor typically asks to see. Use it to build your QMS, prepare for a certification audit, or run an internal audit.

Prefer to work in a spreadsheet? Download the fillable ISO 9001 requirements checklist (XLSX) and mark each clause conformant, with evidence and owner columns.

Download the checklist (XLSX)

Clause 4: Context of the organisation (4 sub-clauses)

ISO 9001:2015 clause 4: four sub-clauses covering organisational context, interested parties, QMS scope, and QMS processes.
Clause What it requires What an auditor looks for
4.1 Understanding the organisation and its context Determine the external and internal issues relevant to your purpose and strategic direction that affect the QMS, and monitor and review them. Evidence you have identified issues (market, regulatory, technology, culture, resourcing) and that they are reviewed, not written once and forgotten. A SWOT, context register, or business-plan input is common.
4.2 Understanding the needs and expectations of interested parties Identify the interested parties relevant to the QMS and their relevant requirements, and monitor and review that information. A list of interested parties (customers, regulators, owners, suppliers, staff) with their relevant requirements, and a way those requirements feed into planning.
4.3 Determining the scope of the QMS Define the boundaries and applicability of the QMS as documented information, considering the context, interested parties, and your products and services. Justify any requirement you determine is not applicable. A documented scope statement naming sites, products and services, and any justified exclusions (design and development, clause 8.3, is the usual one). Auditors check the scope matches what you actually do.
4.4 Quality management system and its processes Establish, implement, maintain and continually improve the QMS, including the processes needed and their interactions, inputs and outputs, sequence, criteria, resources, responsibilities, risks and improvement. Evidence you manage the QMS as a set of linked processes (a process map or turtle diagrams) with owners and measures, not just a folder of policies.

Clause 5: Leadership (3 sub-clauses)

ISO 9001:2015 clause 5: three sub-clauses covering leadership and commitment, the quality policy, and organisational roles and responsibilities.
Clause What it requires What an auditor looks for
5.1 Leadership and commitment Top management must demonstrate leadership and commitment to the QMS and to customer focus: taking accountability, setting policy and objectives, integrating the QMS into business processes, and ensuring resources. Evidence senior leaders are visibly engaged: chairing management reviews, approving objectives, resourcing the QMS. Auditors often interview top management directly to test this.
5.2 Quality policy Establish, implement and maintain a quality policy appropriate to the organisation, that commits to satisfying requirements and continual improvement, provides a framework for objectives, and is communicated and available as documented information. A documented quality policy that is more than a poster: it is understood by staff, references your actual context, and links to measurable objectives.
5.3 Organisational roles, responsibilities and authorities Assign and communicate responsibilities and authorities for QMS conformity, process performance, reporting to top management, and maintaining QMS integrity through change. Clear ownership of QMS roles (org chart, responsibility matrix, position descriptions) and staff who can say who is responsible for what.

Clause 6: Planning (3 sub-clauses)

ISO 9001:2015 clause 6: three sub-clauses covering actions to address risks and opportunities, quality objectives, and planning of changes.
Clause What it requires What an auditor looks for
6.1 Actions to address risks and opportunities Determine the risks and opportunities arising from your context and interested parties, plan actions to address them, integrate those actions into QMS processes, and evaluate their effectiveness. A risk-and-opportunity register linked to context (4.1) and interested parties (4.2), with actions that are actually implemented and reviewed. Formal risk methodology is not mandated, but risk-based thinking must be visible.
6.2 Quality objectives and planning to achieve them Set measurable quality objectives at relevant functions and levels, consistent with the quality policy, and plan what will be done, with what resources, by whom, by when, and how results are evaluated. Documented objectives that are measurable and monitored, with a plan behind each one. Auditors test whether objectives are tracked, not just declared.
6.3 Planning of changes When changes to the QMS are needed, carry them out in a planned manner, considering the purpose and consequences of the change, QMS integrity, resources, and responsibilities. Evidence that significant QMS changes (new processes, sites, systems) are planned and controlled, for example through change records or management-review actions.

Clause 7: Support (5 sub-clauses)

ISO 9001:2015 clause 7: five sub-clauses covering resources, competence, awareness, communication, and documented information.
Clause What it requires What an auditor looks for
7.1 Resources Provide the resources the QMS needs: people, infrastructure, a suitable process environment, monitoring and measuring resources (including calibration where measurement traceability matters), and organisational knowledge. Evidence resources are adequate and maintained: calibration records for measuring equipment, maintained infrastructure, and a way of capturing and retaining organisational knowledge.
7.2 Competence Determine the competence needed for people doing work that affects QMS performance, ensure they are competent on the basis of education, training or experience, take action to close gaps, and retain evidence. A competence or training matrix, records of qualifications and training, and evidence that gaps are actioned. This is one of the mandatory records.
7.3 Awareness Ensure people doing work under your control are aware of the quality policy, relevant quality objectives, their contribution to QMS effectiveness, and the implications of not conforming. Staff who can explain, in their own words, the policy and how their work affects quality. Auditors test this through shop-floor interviews, not documents.
7.4 Communication Determine the internal and external communications relevant to the QMS: on what, when, with whom, how, and who communicates. A simple communication plan or matrix, and evidence it happens (team briefings, notices, customer updates).
7.5 Documented information Maintain the documented information the standard and your QMS require, and control it: identification, format, review and approval, availability, protection, distribution, retention and disposition. Control external documents too. A controlled document and record system with version control, approval, and retention. Auditors check documents in use are current and that records are protected and retrievable.

Clause 8: Operation (7 sub-clauses)

ISO 9001:2015 clause 8: seven sub-clauses covering operational planning, product and service requirements, design and development, external providers, production and service provision, release, and control of nonconforming outputs.
Clause What it requires What an auditor looks for
8.1 Operational planning and control Plan, implement and control the processes needed to meet product and service requirements: set criteria, provide resources, control processes to those criteria, and keep documented information to show they were carried out. Evidence operations run to defined criteria (production plans, work instructions, acceptance criteria) and that outsourced processes are controlled.
8.2 Requirements for products and services Communicate with customers, determine the requirements for what you offer (including legal and your own), and review those requirements before committing so you can meet them. Retain records of the review and of changed requirements. Records of contract or order review, evidence customer and statutory requirements are captured, and a process for handling changes to requirements.
8.3 Design and development of products and services Where you design what you provide, control the design process: planning, inputs, controls (review, verification, validation), outputs, and changes, retaining documented information throughout. May be excluded if you do not design. If applicable: a controlled design process with staged reviews and records. If excluded: a justified exclusion in the QMS scope. This is the most common clause 4.3 exclusion.
8.4 Control of externally provided processes, products and services Ensure externally provided processes, products and services conform: evaluate and select providers on defined criteria, define the controls and information you apply to them, and monitor their performance. Retain records. An approved-supplier list with selection and evaluation criteria, records of supplier performance monitoring, and purchasing information that states your requirements.
8.5 Production and service provision Control production and service delivery under defined conditions: identification and traceability, care of customer and external-provider property, preservation, post-delivery activities, and control of changes. Controlled work environments, traceability where required, protection of customer property, and change control on the line. Records of anything that must be traced.
8.6 Release of products and services Verify that product and service requirements have been met before release, and do not release until planned arrangements are complete unless authorised. Retain evidence of conformity and of who authorised release. Inspection, test or sign-off records against acceptance criteria, and traceability to the person who authorised release. A mandatory record.
8.7 Control of nonconforming outputs Identify and control outputs that do not conform so they are not unintentionally used or delivered: correct, segregate, return, or obtain concession. Retain records of the nonconformity and action taken. A nonconforming-product process with records: what was found, what was done, who authorised any concession. Auditors sample these records.

Clause 9: Performance evaluation (3 sub-clauses)

ISO 9001:2015 clause 9: three sub-clauses covering monitoring and measurement, internal audit, and management review.
Clause What it requires What an auditor looks for
9.1 Monitoring, measurement, analysis and evaluation Determine what needs monitoring and measuring and how, including customer satisfaction, then analyse and evaluate the results to judge QMS performance and effectiveness. Retain the results. Evidence you measure the right things (quality KPIs, customer satisfaction data) and that the data is analysed and used, not just collected.
9.2 Internal audit Conduct internal audits at planned intervals to confirm the QMS conforms to ISO 9001 and to your own requirements and is effectively implemented. Plan a programme, define criteria and scope, keep auditors objective, report results, and act on findings. An internal audit programme, audit records covering all clauses over time, competent and impartial auditors, and corrective actions that close the loop. A mandatory record.
9.3 Management review Top management must review the QMS at planned intervals against a defined set of inputs (audit results, customer feedback, objectives, risks, improvement opportunities) and produce outputs: decisions on improvement, change, and resources. Retain records. Management review records showing the required inputs were considered and that decisions and actions came out of it. Auditors check leadership involvement. A mandatory record.

Clause 10: Improvement (3 sub-clauses)

ISO 9001:2015 clause 10: three sub-clauses covering general improvement, nonconformity and corrective action, and continual improvement.
Clause What it requires What an auditor looks for
10.1 General Determine and select opportunities for improvement and implement actions to meet customer requirements and enhance satisfaction, including improving products and services and the QMS itself. Evidence improvement is ongoing and outward-looking, not just reactive: improvement initiatives tied to customer needs and QMS performance.
10.2 Nonconformity and corrective action When a nonconformity occurs (including from complaints), react to it, evaluate the need to eliminate the cause so it does not recur, implement action, review effectiveness, and update risks if needed. Retain records of the nonconformity and the corrective action. A corrective-action process with root-cause analysis and effectiveness checks, and records that show causes are addressed rather than symptoms patched. A mandatory record.
10.3 Continual improvement Continually improve the suitability, adequacy and effectiveness of the QMS, using the results of analysis, evaluation, and management review to identify where improvement is needed. A trend of improvement over time driven by data and management review, closing the Plan-Do-Check-Act loop.

Which ISO 9001 Documents and Records Are Mandatory?

ISO 9001:2015 is far lighter on paperwork than older versions. It stopped requiring a quality manual and six documented procedures. What it still requires is a short list of documents you maintain and a set of records you retain as evidence.

Documents you must maintain

  • Scope of the QMS (clause 4.3), including any justified exclusions.
  • Quality policy (clause 5.2).
  • Quality objectives (clause 6.2).
  • Documented information to support the operation of processes (clause 4.4), sized to your organisation.

Records you must retain (as evidence)

  • Fitness of monitoring and measuring resources, and calibration where used (clause 7.1.5).
  • Competence of your people (clause 7.2).
  • Review of the requirements for products and services (clause 8.2.3).
  • Design and development records, where clause 8.3 applies.
  • Evaluation, selection and performance of external providers (clause 8.4).
  • Traceability and customer-property records where relevant (clause 8.5).
  • Conformity of outputs to acceptance criteria and release authority (clause 8.6).
  • Nonconforming outputs and the action taken (clause 8.7).
  • Monitoring and measurement results (clause 9.1).
  • The internal audit programme and its results (clause 9.2).
  • Management review results (clause 9.3).
  • Nonconformities and corrective actions (clause 10.2).

The exact documents that make sense for you depend on your size and complexity. The PECB ISO 9001 Lead Implementer course includes templates for each of these so you are not drafting them from a blank page.

Where to Start: A Practical Implementation Order

You do not build the clauses in numerical order. A practical sequence that maps to how a QMS actually comes together:

  1. Context and scope first (clause 4). You cannot scope anything until you understand your organisation, your interested parties, and what the QMS will cover.
  2. Leadership and policy (clause 5). Secure top-management commitment and set the quality policy. Without this, nothing downstream sticks.
  3. Planning (clause 6). Turn context into risks, opportunities, and measurable objectives.
  4. Support (clause 7). Put the people, competence, infrastructure, and documented information in place.
  5. Operation (clause 8). The heavy lifting: control the processes that actually deliver your products and services.
  6. Evaluation and improvement (clauses 9 and 10). Monitor, run an internal audit, hold a management review, and act on what you find, before you invite a certification body in.

For a structured path through every clause with templates and worked examples, the PECB ISO 9001 Lead Implementer course follows this sequence.

Resources

ISO 9001 Audit Checklist

Use this ISO 9001 checklist to work through every requirement in clauses 4 to 10. It condenses the clause tables above into a scannable ISO 9001 audit checklist you can track as you build or audit your quality management system. Tick items off below (your progress is saved in this browser), or download the printable and fillable versions.

Download the full checklist: the printable ISO 9001 audit checklist (PDF), or the fillable requirements checklist (XLSX) with conformity, evidence and owner columns.

Clause 4: Context of the organisation

  • 4.1 External and internal issues determined and reviewed
  • 4.2 Interested parties and their relevant requirements identified
  • 4.3 QMS scope documented, with any exclusions justified
  • 4.4 QMS processes and their interactions defined

Clause 5: Leadership

  • 5.1 Top management demonstrates leadership and customer focus
  • 5.2 Quality policy established, communicated and available
  • 5.3 Roles, responsibilities and authorities assigned and communicated

Clause 6: Planning

  • 6.1 Risks and opportunities addressed with planned actions
  • 6.2 Measurable quality objectives set with plans to achieve them
  • 6.3 Changes to the QMS planned and controlled

Clause 7: Support

  • 7.1 Resources provided: people, infrastructure, environment, measurement, knowledge
  • 7.2 Competence determined and evidence retained
  • 7.3 Awareness of policy, objectives and consequences ensured
  • 7.4 Internal and external communication determined
  • 7.5 Documented information maintained and controlled

Clause 8: Operation

  • 8.1 Operational processes planned and controlled to criteria
  • 8.2 Product and service requirements determined and reviewed
  • 8.3 Design and development controlled (or justifiably excluded)
  • 8.4 Externally provided processes, products and services controlled
  • 8.5 Production and service provision controlled
  • 8.6 Release of products and services verified before delivery
  • 8.7 Nonconforming outputs identified and controlled

Clause 9: Performance evaluation

  • 9.1 Monitoring, measurement and customer satisfaction analysed
  • 9.2 Internal audits planned, conducted and actioned
  • 9.3 Management review conducted with required inputs and outputs

Clause 10: Improvement

  • 10.1 Improvement opportunities determined and acted on
  • 10.2 Nonconformity and corrective action process operating
  • 10.3 Continual improvement of the QMS demonstrated

Frequently Asked Questions

Common questions about ISO 9001 requirements, clauses, and audits.

How many clauses are in ISO 9001?

ISO 9001:2015 has 10 clauses. Clauses 1 to 3 are introductory (scope, normative references, terms and definitions) and set no auditable requirements. The certifiable requirements sit in clauses 4 to 10: Context of the organisation, Leadership, Planning, Support, Operation, Performance evaluation, and Improvement. Those seven clauses are what a certification body audits your quality management system against.

What are the main requirements of ISO 9001?

At a high level: understand your organisation and interested parties and set the QMS scope (clause 4); demonstrate top-management leadership and set a quality policy (clause 5); plan for risks, opportunities and quality objectives (clause 6); provide the people, infrastructure and documented information the QMS needs (clause 7); control your operations from customer requirements through to delivery (clause 8); monitor, audit and review performance (clause 9); and correct nonconformities and continually improve (clause 10). Clause 8 (Operation) is usually the largest and most organisation-specific.

Which ISO 9001 clauses are mandatory?

All of clauses 4 to 10 apply. ISO 9001 lets you declare a requirement not applicable only where it genuinely cannot affect your ability to deliver conforming products and services (clause 4.3), and design and development (clause 8.3) is the most common exclusion for organisations that do not design what they sell. Every exclusion must be justified and documented in the QMS scope. You cannot simply skip a clause because it is inconvenient.

What documented information does ISO 9001 require?

ISO 9001:2015 requires far fewer documents than the 2008 version. The documents you must maintain are the QMS scope (4.3), the quality policy (5.2), quality objectives (6.2), and enough documented information to support the operation of your processes (4.4). On top of that you must retain records as evidence, including competence records (7.2), results of the review of product and service requirements (8.2.3), design and development records where applicable (8.3), external-provider evaluations (8.4), evidence of conformity to acceptance criteria (8.6), nonconforming output records (8.7), monitoring and measurement results (9.1), the internal audit programme and results (9.2), management review outputs (9.3), and corrective-action records (10.2).

What is the difference between a clause and a requirement?

A clause is a numbered section of the standard (for example 8.4, "Control of externally provided processes, products and services"). A requirement is a specific thing you must do inside that clause, usually signalled by the word "shall". A single clause often contains several requirements: clause 8.4 alone requires you to evaluate external providers, define the controls you apply to them, and communicate your requirements to them. Auditors trace each "shall" to evidence, so it helps to read requirements at the shall level, not just the clause level.

Is there an ISO 9001 internal audit checklist?

Yes. A practical ISO 9001 internal audit checklist walks clause by clause through 4 to 10, turning each requirement into a question you can evidence: is the QMS scope documented, is the quality policy communicated, are objectives measurable, is competence recorded, are nonconformities actioned. The tickable checklist further down this page covers every sub-clause, and you can download it as a printable PDF or a fillable spreadsheet.

Do I need a consultant to meet ISO 9001 requirements?

No. Many organisations meet the requirements in-house by training one person as a PECB ISO 9001 Lead Implementer, who then builds the QMS using the standard structure and templates rather than paying a consultant day rate. A consultant can accelerate the work, but the knowledge to interpret and evidence each clause is exactly what the Lead Implementer and Lead Auditor courses teach.

How do I get certified against ISO 9001?

Certification requires an accredited certification body to audit your quality management system against clauses 4 to 10 in a two-stage audit (documentation review, then implementation assessment). Before that, most organisations run a gap analysis, build the QMS, train their people, complete at least one internal audit, and hold a management review. Our ISO 9001 certification cost guide breaks down what each stage costs in Australia.

Ready to implement or audit ISO 9001?

The PECB ISO 9001 courses cover every clause with implementation templates, worked examples, and certification exam preparation, self-paced eLearning with the exam voucher included.