Guides · Documents
The documents and records ISO 9001 requires
The most persistent myth about ISO 9001 is that it buries you in paperwork. The 2015 revision did the opposite: it removed the mandatory quality manual and the six required procedures, and left just four documents you must keep current and a set of records you must retain as evidence. The rest is your choice, sized to your operation, not to a template.
The short version
ISO 9001:2015 uses one term, documented information, for both documents and records, and the verb tells you which. Information you maintain is a document (four are mandatory). Information you retain is a record (evidence that something happened). No quality manual is required, and no procedures are mandatory.
Documents · at a glance
Maintained
The four documents you must keep
These are living documents that you keep current. Every ISO 9001 system has all four.
Scope of the QMS Clause 4.3
What your management system covers, meaning the products, services, and sites, plus a justification for any requirement of the standard you decide does not apply. The boundary everything else is measured against.
Quality policy Clause 5.2
Top management's stated commitment to quality and continual improvement, appropriate to your organization and communicated within it. Short, signed, and genuinely used, not framed on a wall and forgotten.
Quality objectives Clause 6.2
Measurable objectives consistent with the policy, at the relevant functions and levels, with plans to achieve them. "Improve quality" is not an objective; a target with a number and a date is.
Criteria for external providers Clause 8.4.1
How you select, evaluate, and monitor suppliers and other external providers whose work affects your product or service. The written basis for deciding who you trust with your inputs.
Retained
The records you must keep as evidence
Records prove the system operated. You retain them; you don't rewrite them. The standard requires these wherever the underlying clause applies to you.
Throughout clauses 7 through 10, the phrase to watch for is "documented information shall be retained." Each time it appears, it names a record you must be able to produce. The core set that nearly every organization keeps:
| Record | Clause | What it proves |
|---|---|---|
| Monitoring & measuring equipment calibration | 7.1.5.1 | Your measurements can be trusted |
| Competence, training & qualifications | 7.2 | People are able to do their work |
| Review of requirements for products/services | 8.2.3 | You agreed to what you could deliver |
| Design & development records | 8.3 | Where design applies to you |
| Characteristics of products & services | 8.5.1 | What you actually make or do |
| Customer or external-provider property | 8.5.3 | You safeguarded what wasn't yours |
| Conformity of outputs & release authority | 8.6 | What shipped met requirements |
| Nonconforming outputs | 8.7.2 | You caught and controlled defects |
| Monitoring & measurement results | 9.1.1 | The system is being measured |
| Internal audit programme & results | 9.2 | The system audits itself |
| Management review results | 9.3 | Leadership steered the system |
| Nonconformity & corrective action | 10.2 | Problems were fixed, not just found |
Some records apply only if the clause does. Design and development records matter only if you design. Right-sizing means keeping what your work actually generates, not manufacturing evidence for clauses you don't touch.
The freedom, and the trap
Everything else is your call
ISO 9001:2015 contains zero mandatory procedures. No document control procedure, no internal audit procedure, no corrective action procedure. The 2008 version required six of these, and 2015 deleted the list. You determine what documented information your system needs based on your size, your complexity, and your risk. A ten-person shop and a five-hundred-person manufacturer can both be fully compliant with very different amounts of paper.
That freedom is also the trap. "Not mandatory" is not "not useful." Most organizations still write procedures for their key processes, not because an auditor demands the document, but because a process that lives only in one person's head fails the moment that person is out. The discipline is to document what your operation actually needs to run consistently, and clause 7.5 governs how: every document controlled, identifiable, and current; every record legible, retrievable, and protected from unintended change.
This is exactly the line an engineered program is built to walk. The implementation guide shows where each document is produced in the build; JumpStart ISO ships the controlled document set already written and already right-sized, so you adapt working documents instead of authoring from a blank page.
Straight answers
Asked and answered
Do we need a quality manual?
No. The 2015 revision removed the required manual and the six required procedures. Keep a manual if it helps you, as many do, but it is a choice, not a requirement.
How many documents are actually required?
Four maintained documents (scope, quality policy, quality objectives, and external-provider criteria) plus the records you retain as evidence. No mandatory procedures beyond those.
Document or record: what's the difference?
The verb. Information you maintain is a document you keep current; information you retain is a record of something that happened, which you don't edit afterward.
Can a small business really keep it light?
Yes. The standard explicitly scales documentation to size, complexity, and risk. The skill is keeping what your work generates and skipping what it doesn't.
Sources
- ISO 9001:2015, Quality management systems — Requirements (clause 7.5 and the "shall be retained" record requirements throughout)
- ISO 9001 Auditing Practices Group (ISO/TC 176 & IAF)
- ASQ: ISO 9001 overview
Next up
JumpStart ISO ships this exact set, already written, controlled, and right-sized, so you adapt working documents instead of authoring from a blank page.
Request early access