ISO 9001 Process Documentation Requirements
Last updated: January 2026
ISO 9001:2015 requires far less documentation than most teams assume: just four documents you must maintain (scope, quality policy, quality objectives, supplier criteria) plus about fifteen kinds of record you must retain, with no quality manual and no mandated SOPs. Everything else is documented “to the extent necessary” to run your processes (clause 4.4).
The single most common misconception about ISO 9001 is that certification means producing binders of standard operating procedures. It does not. The 2015 revision deliberately cut the documentation burden: it removed the mandatory quality manual and the six required procedures that the 2008 version demanded, and replaced the split between “documents” and “records” with a single term, documented information. The mandatory core is a short, specific list, and this page sets out exactly what is on it.
Below: what ISO 9001:2015 actually mandates versus what is discretionary, clause 7.5 (documented information) in plain English, what auditors really look for, a worked minimal-but-compliant structure, and a copyable, ISO-aligned document-control header you can paste into any procedure. If you also need the procedures themselves, our SOP template library includes an ISO 9001-aligned format, and the broader process documentation software category page sits on our comparison hub.
This is a practical explainer, not certification advice. Where accuracy matters, the authoritative source is the standard itself and your certification body, both cited in the references at the end.
What ISO 9001:2015 actually requires
ISO 9001:2015 makes only four documents mandatory to maintain and roughly fifteen kinds of record mandatory to retain. The rest is left to your judgement under clause 4.4.2.
The standard draws a working distinction between information you maintain (living documents kept current, the old “documents”) and information you retain (evidence of what happened, kept unchanged, the old “records”). Both are “documented information” now, but the distinction still drives how you handle each. Here is the mandatory set.
Documents you must maintain
| Mandatory document | Clause |
|---|---|
| Scope of the quality management system | 4.3 |
| Quality policy | 5.2.2 |
| Quality objectives | 6.2.1 |
| Information needed to support the operation of your processes (to the extent you decide is necessary) | 4.4.2 |
| Criteria for the evaluation and selection of external suppliers | 8.4.1 |
Records you must retain
These are the evidence an auditor asks to see. Some apply only if you perform the activity: design records (8.3) or calibration (7.1.5.1) do not apply if you neither design nor use measuring equipment, so your exact list depends on your scope.
| Mandatory record | Clause |
|---|---|
| Monitoring and measuring equipment calibration / verification (where used) | 7.1.5.1 |
| Evidence of competence of people doing quality-affecting work | 7.2 |
| Evidence that processes ran as planned and that outputs conform | 8.1 |
| Results of the review of requirements for products and services | 8.2.3.2 |
| Design and development records (inputs, controls, outputs, changes) | 8.3 |
| Results of supplier evaluations and any actions arising | 8.4.1 |
| Records of unique identification / traceability, where required | 8.5.2 |
| Records of customer or supplier property that is lost or damaged | 8.5.3 |
| Results of change control for production / service provision | 8.5.6 |
| Evidence of product / service release and who authorised it | 8.6 |
| Records of nonconforming outputs and the actions taken | 8.7.2 |
| Monitoring and measurement results | 9.1.1 |
| The internal audit programme and audit results | 9.2.2 |
| Results of management reviews | 9.3.3 |
| Nature of nonconformities, actions taken, and results of corrective action | 10.2.2 |
What is NOT mandatory
A quality manual, documented procedures for individual processes, work instructions, org charts, and a process map are all discretionary in ISO 9001:2015. You create them only where clause 4.4.2 says you need them “to have confidence that the processes are being carried out as planned.” Plenty of small, certified organisations keep this layer deliberately thin.
Documented information explained (clause 7.5)
Clause 7.5 sets three requirements for any documented information: it must be created and identified properly, approved before use, and kept under control once it exists.
7.5.1 — General: what your system has to include
Your QMS must include the documented information ISO 9001 explicitly requires (the lists above) plus whatever you determine is necessary for the system to be effective. The size of that second part depends on your organisation’s size, the complexity of its processes, and the competence of its people, a point the standard makes directly. Small, simple, well-trained operations need less; that is by design.
7.5.2 — Creating and updating: identify, format, approve
When you create or change a document, clause 7.5.2 requires appropriate identification and description (a title, date, author, reference number), an appropriate format and media (explicitly “any format and media,” including electronic, photographs, and samples), and review and approval for suitability and adequacy before use. In plain English: name it, give it a version, and have the right person approve it before anyone follows it.
7.5.3 — Control: available, protected, versioned
Once a document exists it must be available and suitable for use where and when it is needed, and adequately protected from loss of confidentiality, improper use, or loss of integrity. The standard also names the control activities to address as applicable: distribution and access, storage and preservation (including keeping it legible), control of changes (version control), and retention and disposition. This is the clause behind “which revision was current on this date, and can the person doing the job actually reach it?”
What auditors actually look for
An ISO 9001 auditor tests control and truthfulness, not polish: is this the approved current version, can the operator reach it, and does the work match what it says?
In practice, a documented-information finding almost always traces to one of these. Pass these and your documentation is compliant regardless of how it was produced.
- Currency. The version in use is the current approved revision, not a printout from two years ago pinned to a wall. Uncontrolled copies are the classic nonconformity.
- Approval trail. Each document shows who prepared and approved it, and when. An auditor should be able to see it was reviewed for suitability before release (7.5.2).
- Availability. The person doing the work can actually get to the current document at the point of use, not “it’s somewhere on the shared drive.”
- Traceability of change. A revision history shows what changed, when, and by whom, so the auditor can establish which revision was current on any given date.
- Say-do match. The single biggest signal: the documented process matches what people actually do. A beautiful SOP nobody follows is worse than a plain one everybody follows.
- Retained evidence. The mandatory records exist and are retrievable: audits, management reviews, corrective actions, competence, and the rest of the retain list above.
A minimal compliant documentation system
A compliant ISO 9001 documentation set can be small: the four mandatory documents, a controlled place for your records, and only the procedures your processes genuinely need to run consistently.
Here is a lean structure that satisfies the standard without over-documenting. Add procedures where variation causes problems; leave them out where competent people already get consistent results.
- The four mandatory documents. A one-page scope, a quality policy, measurable quality objectives, and your supplier-selection criteria. This is the non-negotiable core (clauses 4.3, 5.2.2, 6.2.1, 8.4.1).
- A short process overview. Optional under 4.4, but a single diagram or table mapping your key processes and how they connect earns its keep and answers most of clause 4.4 in one page.
- Procedures only where needed. Write a controlled SOP for each process where inconsistency causes defects, safety risk, or rework, and skip the rest. Use one document-control header (below) across all of them so control is uniform.
- A controlled home for records. One structured location (folder tree or QMS tool) where the mandatory records are captured, named, and retained per your retention rules. This is your “retain” half.
- A document-control method. How you identify, approve, version, and review documents; even a simple register with revision numbers and review dates satisfies 7.5.2 and 7.5.3.
Where dubble fits (and where it does not)
Dubble produces the procedure content (accurate step-by-step guides with real screenshots captured from the process as it is actually performed) which you then place inside your own controlled document system. Dubble is not a QMS and does not replace one.
The hardest part of an ISO-aligned procedure is not the header fields; it is producing accurate step-by-step content and keeping it current. Dubble watches you perform a process once and turns it into numbered steps with auto-captured screenshots and written descriptions. Because the screenshots come from the real workflow, the procedure is evidence of the process as performed rather than an idealised description someone typed from memory, which is exactly the say-do match an auditor tests for.
When the process changes, you re-capture instead of re-screenshotting by hand. The reason procedures fall out of date is almost always the effort of updating images, and removing that effort is what keeps a controlled document current between reviews. You then export the guide as markdown, HTML, or PDF and paste it into your controlled-document system (a QMS platform, Confluence, a SharePoint library, wherever your master copies live) under the ISO-aligned header below.
Honest scope
Dubble is a capture-and-authoring tool, not a quality management system. It does not enforce approval workflows, retention schedules, or the record-keeping side of ISO 9001 on its own. It produces the documented content; the control (approval, versioning, availability, retention) lives in whatever repository you designate as the system of record. Treat dubble as the fastest way to generate and refresh the procedure content, then control it where your other documented information lives.
If procedures are your main need, our ISO 9001-aligned SOP template pairs with the header block below, and the process documentation software comparison covers tools with heavier document-control features if you need them built in.
Copyable ISO-aligned SOP header block
This header turns any procedure into a controlled document: it carries the identification, approval, and revision fields clauses 7.5.2 and 7.5.3 ask for. Copy it, paste it above your steps, and fill in the brackets.
CONTROLLED DOCUMENT — HEADER BLOCK (ISO 9001:2015 aligned) Document title: [e.g. Customer Complaint Handling Procedure] Document number: [QMS-SOP-014] Revision: [Rev. 03] Process / area: [Which QMS process this supports — clause 4.4] Effective date: [YYYY-MM-DD] Supersedes: [Rev. 02 / none] Prepared by: [Name / role] Date: [YYYY-MM-DD] Reviewed by: [Name / role] Date: [YYYY-MM-DD] Approved by: [Name / role — authority to release] Date: [YYYY-MM-DD] Next review due: [YYYY-MM-DD] Classification: [Internal / Controlled copy — uncontrolled if printed] Location of master: [Where the current approved version lives] REVISION HISTORY (control record — clause 7.5.2 / 7.5.3) | Rev | Date | Description of change | Author | Approved | |-----|------------|-----------------------------|---------|----------| | 01 | YYYY-MM-DD | Initial release | [Name] | [Name] | | 02 | YYYY-MM-DD | [What changed and why] | [Name] | [Name] | | 03 | YYYY-MM-DD | [What changed and why] | [Name] | [Name] | --- Procedure content below this line --- 1. PURPOSE 2. SCOPE 3. RESPONSIBILITIES 4. PROCEDURE (numbered steps + screenshots) 5. RECORDS (what this procedure generates and where it is kept) 6. REFERENCES (ISO 9001:2015 clause 7.5; related SOPs)
Frequently asked questions
Keep reading
- SOP templates: including an ISO 9001-aligned format that uses the header block above.
- Process documentation software: the broader category, with document-control features compared.
- How to choose process documentation software: the evaluation framework, including what a regulated team needs.
- The comparison hub: every tool head-to-head.
References
- ISO 9001:2015 — Quality management systems — Requirements — ISO
- ISO 9000:2015 — Fundamentals and vocabulary (defines 'documented information') — ISO
- Guidance on the requirements for documented information of ISO 9001:2015 — ISO/TC 176/SC 2
- ISO 9001:2015 documentation requirements — ASQ (American Society for Quality)
Produce audit-ready procedures without the busywork
Dubble captures a process as you perform it (real screenshots, numbered steps), then exports to markdown, PDF, or your document system. Pair it with the ISO-aligned header and re-capture when things change. Free to start.