ISO 9001 Process Documentation Requirements

Last updated: January 2026

TL;DR

ISO 9001:2015 requires far less documentation than most teams assume: just four documents you must maintain (scope, quality policy, quality objectives, supplier criteria) plus about fifteen kinds of record you must retain, with no quality manual and no mandated SOPs. Everything else is documented “to the extent necessary” to run your processes (clause 4.4).

The single most common misconception about ISO 9001 is that certification means producing binders of standard operating procedures. It does not. The 2015 revision deliberately cut the documentation burden: it removed the mandatory quality manual and the six required procedures that the 2008 version demanded, and replaced the split between “documents” and “records” with a single term, documented information. The mandatory core is a short, specific list, and this page sets out exactly what is on it.

Below: what ISO 9001:2015 actually mandates versus what is discretionary, clause 7.5 (documented information) in plain English, what auditors really look for, a worked minimal-but-compliant structure, and a copyable, ISO-aligned document-control header you can paste into any procedure. If you also need the procedures themselves, our SOP template library includes an ISO 9001-aligned format, and the broader process documentation software category page sits on our comparison hub.

This is a practical explainer, not certification advice. Where accuracy matters, the authoritative source is the standard itself and your certification body, both cited in the references at the end.

What ISO 9001:2015 actually requires

ISO 9001:2015 makes only four documents mandatory to maintain and roughly fifteen kinds of record mandatory to retain. The rest is left to your judgement under clause 4.4.2.

The standard draws a working distinction between information you maintain (living documents kept current, the old “documents”) and information you retain (evidence of what happened, kept unchanged, the old “records”). Both are “documented information” now, but the distinction still drives how you handle each. Here is the mandatory set.

Documents you must maintain

Mandatory documentClause
Scope of the quality management system4.3
Quality policy5.2.2
Quality objectives6.2.1
Information needed to support the operation of your processes (to the extent you decide is necessary)4.4.2
Criteria for the evaluation and selection of external suppliers8.4.1

Records you must retain

These are the evidence an auditor asks to see. Some apply only if you perform the activity: design records (8.3) or calibration (7.1.5.1) do not apply if you neither design nor use measuring equipment, so your exact list depends on your scope.

Mandatory recordClause
Monitoring and measuring equipment calibration / verification (where used)7.1.5.1
Evidence of competence of people doing quality-affecting work7.2
Evidence that processes ran as planned and that outputs conform8.1
Results of the review of requirements for products and services8.2.3.2
Design and development records (inputs, controls, outputs, changes)8.3
Results of supplier evaluations and any actions arising8.4.1
Records of unique identification / traceability, where required8.5.2
Records of customer or supplier property that is lost or damaged8.5.3
Results of change control for production / service provision8.5.6
Evidence of product / service release and who authorised it8.6
Records of nonconforming outputs and the actions taken8.7.2
Monitoring and measurement results9.1.1
The internal audit programme and audit results9.2.2
Results of management reviews9.3.3
Nature of nonconformities, actions taken, and results of corrective action10.2.2

What is NOT mandatory

A quality manual, documented procedures for individual processes, work instructions, org charts, and a process map are all discretionary in ISO 9001:2015. You create them only where clause 4.4.2 says you need them “to have confidence that the processes are being carried out as planned.” Plenty of small, certified organisations keep this layer deliberately thin.

Documented information explained (clause 7.5)

Clause 7.5 sets three requirements for any documented information: it must be created and identified properly, approved before use, and kept under control once it exists.

7.5.1 — General: what your system has to include

Your QMS must include the documented information ISO 9001 explicitly requires (the lists above) plus whatever you determine is necessary for the system to be effective. The size of that second part depends on your organisation’s size, the complexity of its processes, and the competence of its people, a point the standard makes directly. Small, simple, well-trained operations need less; that is by design.

7.5.2 — Creating and updating: identify, format, approve

When you create or change a document, clause 7.5.2 requires appropriate identification and description (a title, date, author, reference number), an appropriate format and media (explicitly “any format and media,” including electronic, photographs, and samples), and review and approval for suitability and adequacy before use. In plain English: name it, give it a version, and have the right person approve it before anyone follows it.

7.5.3 — Control: available, protected, versioned

Once a document exists it must be available and suitable for use where and when it is needed, and adequately protected from loss of confidentiality, improper use, or loss of integrity. The standard also names the control activities to address as applicable: distribution and access, storage and preservation (including keeping it legible), control of changes (version control), and retention and disposition. This is the clause behind “which revision was current on this date, and can the person doing the job actually reach it?”

What auditors actually look for

An ISO 9001 auditor tests control and truthfulness, not polish: is this the approved current version, can the operator reach it, and does the work match what it says?

In practice, a documented-information finding almost always traces to one of these. Pass these and your documentation is compliant regardless of how it was produced.

  • Currency. The version in use is the current approved revision, not a printout from two years ago pinned to a wall. Uncontrolled copies are the classic nonconformity.
  • Approval trail. Each document shows who prepared and approved it, and when. An auditor should be able to see it was reviewed for suitability before release (7.5.2).
  • Availability. The person doing the work can actually get to the current document at the point of use, not “it’s somewhere on the shared drive.”
  • Traceability of change. A revision history shows what changed, when, and by whom, so the auditor can establish which revision was current on any given date.
  • Say-do match. The single biggest signal: the documented process matches what people actually do. A beautiful SOP nobody follows is worse than a plain one everybody follows.
  • Retained evidence. The mandatory records exist and are retrievable: audits, management reviews, corrective actions, competence, and the rest of the retain list above.

A minimal compliant documentation system

A compliant ISO 9001 documentation set can be small: the four mandatory documents, a controlled place for your records, and only the procedures your processes genuinely need to run consistently.

Here is a lean structure that satisfies the standard without over-documenting. Add procedures where variation causes problems; leave them out where competent people already get consistent results.

  1. The four mandatory documents. A one-page scope, a quality policy, measurable quality objectives, and your supplier-selection criteria. This is the non-negotiable core (clauses 4.3, 5.2.2, 6.2.1, 8.4.1).
  2. A short process overview. Optional under 4.4, but a single diagram or table mapping your key processes and how they connect earns its keep and answers most of clause 4.4 in one page.
  3. Procedures only where needed. Write a controlled SOP for each process where inconsistency causes defects, safety risk, or rework, and skip the rest. Use one document-control header (below) across all of them so control is uniform.
  4. A controlled home for records. One structured location (folder tree or QMS tool) where the mandatory records are captured, named, and retained per your retention rules. This is your “retain” half.
  5. A document-control method. How you identify, approve, version, and review documents; even a simple register with revision numbers and review dates satisfies 7.5.2 and 7.5.3.

Where dubble fits (and where it does not)

Dubble produces the procedure content (accurate step-by-step guides with real screenshots captured from the process as it is actually performed) which you then place inside your own controlled document system. Dubble is not a QMS and does not replace one.

The hardest part of an ISO-aligned procedure is not the header fields; it is producing accurate step-by-step content and keeping it current. Dubble watches you perform a process once and turns it into numbered steps with auto-captured screenshots and written descriptions. Because the screenshots come from the real workflow, the procedure is evidence of the process as performed rather than an idealised description someone typed from memory, which is exactly the say-do match an auditor tests for.

When the process changes, you re-capture instead of re-screenshotting by hand. The reason procedures fall out of date is almost always the effort of updating images, and removing that effort is what keeps a controlled document current between reviews. You then export the guide as markdown, HTML, or PDF and paste it into your controlled-document system (a QMS platform, Confluence, a SharePoint library, wherever your master copies live) under the ISO-aligned header below.

Honest scope

Dubble is a capture-and-authoring tool, not a quality management system. It does not enforce approval workflows, retention schedules, or the record-keeping side of ISO 9001 on its own. It produces the documented content; the control (approval, versioning, availability, retention) lives in whatever repository you designate as the system of record. Treat dubble as the fastest way to generate and refresh the procedure content, then control it where your other documented information lives.

If procedures are your main need, our ISO 9001-aligned SOP template pairs with the header block below, and the process documentation software comparison covers tools with heavier document-control features if you need them built in.

Copyable ISO-aligned SOP header block

This header turns any procedure into a controlled document: it carries the identification, approval, and revision fields clauses 7.5.2 and 7.5.3 ask for. Copy it, paste it above your steps, and fill in the brackets.

ISO 9001-aligned document-control header
CONTROLLED DOCUMENT — HEADER BLOCK (ISO 9001:2015 aligned)

Document title:      [e.g. Customer Complaint Handling Procedure]
Document number:     [QMS-SOP-014]              Revision: [Rev. 03]
Process / area:      [Which QMS process this supports — clause 4.4]
Effective date:      [YYYY-MM-DD]               Supersedes: [Rev. 02 / none]
Prepared by:         [Name / role]              Date: [YYYY-MM-DD]
Reviewed by:         [Name / role]              Date: [YYYY-MM-DD]
Approved by:         [Name / role — authority to release]   Date: [YYYY-MM-DD]
Next review due:     [YYYY-MM-DD]
Classification:      [Internal / Controlled copy — uncontrolled if printed]
Location of master:  [Where the current approved version lives]

REVISION HISTORY (control record — clause 7.5.2 / 7.5.3)
| Rev | Date       | Description of change        | Author  | Approved |
|-----|------------|-----------------------------|---------|----------|
| 01  | YYYY-MM-DD | Initial release             | [Name]  | [Name]   |
| 02  | YYYY-MM-DD | [What changed and why]      | [Name]  | [Name]   |
| 03  | YYYY-MM-DD | [What changed and why]      | [Name]  | [Name]   |

--- Procedure content below this line ---
1. PURPOSE
2. SCOPE
3. RESPONSIBILITIES
4. PROCEDURE (numbered steps + screenshots)
5. RECORDS (what this procedure generates and where it is kept)
6. REFERENCES (ISO 9001:2015 clause 7.5; related SOPs)

Frequently asked questions

No. ISO 9001:2015 does not require standard operating procedures, a quality manual, or the six documented procedures the 2008 version demanded. It requires 'documented information', and only a short list of it is explicitly mandatory. Beyond that list, clause 4.4.2 leaves the amount of procedure to your judgement: you maintain documentation 'to the extent necessary' to run your processes reliably. Many organisations still write SOPs because they genuinely help consistency, not because a clause forces them to.

Only four documents must be maintained: the scope of the QMS (clause 4.3), the quality policy (5.2.2), the quality objectives (6.2.1), and the criteria for evaluating suppliers (8.4.1). Clause 4.4.2 adds process information 'to the extent necessary.' Separately, roughly fifteen kinds of record must be retained as evidence: audit results, management reviews, corrective actions, competence, calibration, and so on. That is the entire mandatory set; everything else is your discretion.

Yes. ISO 9001 is deliberately format-agnostic. Clause 7.5.2 accepts 'any format and media,' explicitly naming paper, electronic, photographs, and samples. A screenshot-based, step-by-step guide is perfectly valid documented information. What matters to an auditor is control, not medium: the document must be identified, reviewed and approved before use, available where the work happens, and traceable through a revision history. A well-controlled set of annotated screenshots meets the requirement as fully as a text procedure.

No. The requirement for a quality manual was removed in the 2015 revision. You may still keep one if it helps people navigate your system, but nothing in the standard mandates it. This is one of the biggest sources of the 'ISO means piles of paperwork' myth. The manual, and the six mandatory procedures, both disappeared. The 2015 standard cares about controlled information and evidence, not a specific document you have to produce.

'Maintain' means a living document you keep current: your policy, objectives, scope, and procedures. These get updated as things change. 'Retain' means a record: evidence that something happened at a point in time, which you keep and do not alter, such as an audit result, a calibration certificate, or a signed release. The old terms were 'documents' (maintain) and 'records' (retain). ISO 9001:2015 folds both into 'documented information' but the distinction still drives how you control each.

Clause 7.5 has three parts. 7.5.1 (general) says your QMS includes the documented information ISO requires plus whatever you decide is necessary. 7.5.2 (creating and updating) requires appropriate identification, format, and review/approval for suitability before use. 7.5.3 (control) requires that documents are available where needed, protected from loss or misuse, and managed for distribution, versioning, retention, and disposal. In plain terms: name it, approve it, make it findable, and control its versions.

Around fifteen distinct types, though the exact count varies with your scope: some, like design and development records (clause 8.3) or calibration records (7.1.5.1), only apply if you do those activities. The consistently required ones include competence evidence (7.2), evidence of conforming outputs (8.1), monitoring results (9.1.1), internal audit results (9.2.2), management review outputs (9.3.3), and corrective action records (10.2.2). These are the evidence an auditor asks to see.

No. Auditors care that it is controlled, current, and followed. An ISO 9001 auditor will pull a procedure, check it is the approved current revision, ask the person doing the work to show they can access it, and look for evidence the process runs as documented. They do not award points for how the screenshots were captured or how polished the layout is. The failure mode auditors flag is a document that is out of date, uncontrolled, or contradicted by what people actually do.

Produce audit-ready procedures without the busywork

Dubble captures a process as you perform it (real screenshots, numbered steps), then exports to markdown, PDF, or your document system. Pair it with the ISO-aligned header and re-capture when things change. Free to start.