Skip to content

ISO 9001 Requirements Checklist: What Every UK Manufacturer Needs to Know

What ISO 9001:2015 Requires

ISO 9001:2015 is the international standard for quality management systems. Its requirements are structured across ten clauses. Clauses 1-3 cover scope, normative references, and terms. Clauses 4-10 contain the auditable requirements that a UKAS-accredited certification body will assess when certifying or conducting surveillance audits of your quality management system.

This checklist covers clauses 4-10 — the requirements your QMS must meet. Each section identifies what the standard requires, what auditors look for, and where documentation is expected.

ISO 9001:2015 uses the Plan-Do-Check-Act (PDCA) cycle as its structural framework. Clauses 4-6 map to Plan (establishing the system), clause 7-8 to Do (implementing it), clause 9 to Check (monitoring results), and clause 10 to Act (improving the system).

Clause 4 — Context of the Organisation

4.1 Understanding the organisation and its context

The organisation must determine external and internal issues relevant to its purpose that affect its ability to achieve intended outcomes. External issues include market conditions, regulatory requirements, supplier environment, and technology. Internal issues include culture, capability, resources, and knowledge.

This is not a one-time activity — the standard requires the organisation to monitor and review this information. Most auditors check for evidence of a regular review, typically aligned with management review (clause 9.3).

What auditors check:

  • Is there a documented analysis of external and internal issues?
  • Does the QMS scope address the context identified?
  • Is the context reviewed periodically (not set once and forgotten)?

4.2 Understanding the needs and expectations of interested parties

The organisation must identify interested parties (customers, regulators, suppliers, employees) and their relevant requirements. Not all requirements of interested parties become QMS requirements — only those that the organisation has determined are relevant to its QMS.

What auditors check:

  • Is there a documented list of interested parties?
  • Are requirements of interested parties identified?
  • Is the list reviewed as part of management review?

4.3 Determining the scope of the QMS

The scope defines which products, services, and locations the QMS covers. The scope must be documented and available to interested parties. Where clauses are excluded, the exclusion must be justified — and exclusions are only permitted from clause 8 (Operations), not from other clauses.

What auditors check:

  • Is the scope documented and stated clearly?
  • If any clause 8 requirements are excluded, is the justification valid?
  • Does the scope reflect what the organisation actually does?

4.4 Quality management system and its processes

The organisation must establish, implement, maintain, and continually improve a QMS, including the processes needed and their interactions. For each process: determine inputs and outputs, sequence and interactions, criteria and methods, resources, responsibilities, risks and opportunities, and opportunities for improvement.

What auditors check:

  • Can the organisation explain its QMS processes and how they interact?
  • Is there a process approach (not just a procedures library)?
  • Is documented information retained to demonstrate processes operate as planned?

Clause 5 — Leadership

5.1 Leadership and commitment

Top management must demonstrate personal commitment to the QMS — not delegate quality management entirely to a quality function. Evidence of leadership commitment includes: establishing quality policy and objectives, ensuring the QMS is integrated with the business, promoting process approach and risk-based thinking, and ensuring resources are available.

What auditors check:

  • Does top management understand the QMS (not just know it exists)?
  • Is the quality policy appropriate to the organisation?
  • Can top management describe how they ensure the QMS supports business objectives?

5.2 Quality policy

The quality policy must be appropriate to the organisation's purpose and context, provide a framework for quality objectives, include a commitment to satisfy applicable requirements and continual improvement, and be communicated, understood, and applied within the organisation.

What auditors check:

  • Is the quality policy documented?
  • Is it visible and communicated to staff?
  • Can employees explain how the quality policy relates to their work?

5.3 Organisational roles, responsibilities and authorities

Top management must assign, communicate, and ensure responsibilities and authorities for ISO 9001-relevant roles. This includes the responsibility for ensuring the QMS conforms to requirements and for reporting QMS performance to top management.

What auditors check:

  • Are quality-related roles and responsibilities documented (typically an organisation chart and role descriptions)?
  • Is there a named person responsible for QMS conformity reporting?

Clause 6 — Planning

6.1 Actions to address risks and opportunities

The organisation must determine risks and opportunities related to context (clause 4.1) and interested party requirements (clause 4.2), and plan actions to address them. ISO 9001:2015 does not require a formal risk register — proportionate and documented thinking on risks is sufficient.

What auditors check:

  • Is there evidence of risk assessment related to quality objectives?
  • Are risks and opportunities considered when planning changes (clause 6.3)?
  • Are actions taken to address risks tracked?

6.2 Quality objectives and planning to achieve them

Quality objectives must be consistent with the quality policy, measurable (where practicable), monitored, communicated, and updated as required. For each objective, the organisation must document: what will be done, what resources are required, who is responsible, when it will be completed, how results will be evaluated.

What auditors check:

  • Are quality objectives documented?
  • Are they measurable (KPIs, targets, thresholds)?
  • Is there a plan showing how each objective will be achieved?

6.3 Planning of changes

When the organisation determines a need to change the QMS, the change must be planned — purpose and consequences, integrity of the QMS, availability of resources, responsibility and authority allocation. This clause covers changes to the QMS structure itself (not product changes, which are clause 8.3.6 and 8.5.6).

What auditors check:

  • Are changes to the QMS documented and reviewed before implementation?
  • Does the change process consider risks to QMS integrity?

Clause 7 — Support

7.1 Resources

The organisation must provide necessary resources for the QMS: people (7.1.2), infrastructure (7.1.3), process environment (7.1.4), monitoring and measurement resources (7.1.5), and organisational knowledge (7.1.6).

On monitoring and measurement (7.1.5): where measurement equipment is used to verify product conformity, the organisation must ensure equipment is fit for purpose and protected from damage. Calibration is required where traceability to national measurement standards is necessary (typically for customer or regulatory requirements). Calibration records must be retained.

What auditors check:

  • Are calibration records available for measurement equipment?
  • Is infrastructure maintained (maintenance records)?
  • Is organisational knowledge documented and controlled (e.g. work instructions, procedures)?

7.2 Competence

The organisation must determine competency requirements for people doing QMS-affecting work, ensure those people are competent (through education, training, or experience), take actions where competence gaps exist, and retain evidence of competence.

What auditors check:

  • Are competency requirements documented for key roles?
  • Is training recorded and retained?
  • Can the organisation demonstrate that people doing quality-critical work are qualified to do it?

7.3 Awareness

Persons doing work under the QMS must be aware of the quality policy, relevant quality objectives, their contribution to QMS effectiveness, and the implications of not conforming.

What auditors check:

  • Do employees know the quality policy (not just know it exists)?
  • Do employees understand their quality objectives?
  • Is awareness documented (induction records, toolbox talks, training)?

7.4 Communication

The organisation must determine internal and external communications relevant to the QMS: what will be communicated, when, to whom, and how. This is broader than a communications plan — it includes customer communication on orders, complaints, and feedback.

7.5 Documented information

ISO 9001:2015 uses "documented information" to cover what earlier versions called "documents" and "records." The standard requires documented information to be:

  • Created and updated with appropriate format, media, and review/approval
  • Controlled — available when needed, protected from unintended changes

The standard specifies specific items that must be documented information (e.g. scope, quality policy, quality objectives, calibration records, internal audit results, nonconformance records, management review outputs). Organisations may also choose to document additional items.

What auditors check:

  • Is there a document control procedure (or equivalent)?
  • Are documents reviewed and approved before issue?
  • Are records retained for appropriate periods and protected from deterioration or loss?

Clause 8 — Operation

8.1 Operational planning and control

The organisation must plan, implement, control, and review processes needed to meet product and service requirements. This requires establishing criteria for processes and acceptance of products and services, determining resources, controlling to criteria, retaining documented information to demonstrate products/services meet requirements.

What auditors check:

  • Is there evidence of operational planning (production plans, travellers, route cards)?
  • Are acceptance criteria defined?
  • Are process parameters documented and controlled?

8.2 Requirements for products and services

The organisation must have a defined process for: determining customer requirements (including delivery, applicable statutory/regulatory requirements, and any additional requirements), reviewing requirements before accepting an order, and communicating changes to customers.

What auditors check:

  • Is there a documented process for reviewing customer requirements before acceptance?
  • Are customer requirements and order review records retained?
  • Is there a process for handling customer amendments?

8.3 Design and development

This clause applies when the organisation designs products or services, not when it manufactures to customer designs. Clause 8.3 covers design planning, inputs, controls (reviews, verification, validation), outputs, and changes (8.3.6).

If your organisation manufactures exclusively to customer designs and specifications, you can exclude clause 8.3 from the QMS scope (with justification in your scope statement).

What auditors check (if applicable):

  • Is design input documented?
  • Are design reviews, verification, and validation recorded?
  • Are design changes controlled under clause 8.3.6?

8.4 Control of externally provided processes, products and services

The organisation must determine what controls to apply to external providers, including what will be communicated (specifications, delivery requirements, quality requirements) and how external providers will be evaluated, monitored, and re-evaluated.

What auditors check:

  • Is there an approved supplier list?
  • Are suppliers evaluated and re-evaluated (supplier performance records)?
  • Are purchase order specifications adequate?

8.5 Production and service provision

This is the core operations clause. Key requirements include:

  • 8.5.1 — controlled conditions for production (work instructions, equipment, monitoring, release criteria)
  • 8.5.2 — identification and traceability (product identified throughout; if traceability required, the unique identification is retained)
  • 8.5.3 — customer property (property on loan from customers must be identified, protected, reported if lost/damaged)
  • 8.5.4 — preservation (product integrity maintained during internal processing and delivery)
  • 8.5.5 — post-delivery activities
  • 8.5.6 — control of changes (planned, reviewed, authorised before implementation; retained as documented information)

The change control procedure is the primary mechanism for satisfying clause 8.5.6.

What auditors check:

  • Are work instructions available at point of use?
  • Is product identified and, where required, traceable to batch or serial number?
  • Are changes to production processes controlled and documented?

8.6 Release of products and services

The organisation must implement planned arrangements to verify product and service requirements are met before release. Evidence of conformity must be retained, including who authorised release. Products must not be released until arrangements are satisfactorily completed (unless approved by an authorised person).

First article inspection is the primary mechanism for satisfying clause 8.6 for new or changed products. See the first article inspection guide for what FAI records must contain.

What auditors check:

  • Are inspection records available for released batches?
  • Is there evidence that product was not released before acceptance criteria were met?
  • Is the person authorising release identified in the records?

8.7 Control of nonconforming outputs

When a product or service does not meet requirements, the organisation must identify and control it to prevent unintended use. Options for disposition: correction, segregation, quarantine, return to supplier, suspension of service, informing the customer, obtaining authorisation for use-as-is (concession).

The non-conformance report guide covers clause 8.7 in detail, including what the NCR form must contain.

What auditors check:

  • Is there a documented nonconformance process?
  • Are nonconforming products quarantined and labelled?
  • Are NCR records retained?
  • Are disposition decisions authorised?

Clause 9 — Performance Evaluation

9.1 Monitoring, measurement, analysis and evaluation

The organisation must determine what to monitor and measure, the methods for analysis and evaluation, and when results will be analysed. Customer satisfaction must be monitored (clause 9.1.2). Analysis of data must include: conformity of products/services, customer satisfaction, QMS performance and effectiveness, supplier performance, risk and opportunity actions.

What auditors check:

  • Are KPIs defined and monitored?
  • Is customer satisfaction measured (survey, feedback, complaint analysis)?
  • Is data analysed to identify trends?

9.2 Internal audit

The organisation must conduct internal audits at planned intervals to determine whether the QMS conforms to its own requirements and to ISO 9001:2015, and whether it is effectively implemented. Internal audits must:

  • Follow a planned programme (frequency, scope, methods, responsibilities, criteria)
  • Be conducted by people who cannot audit their own work
  • Report results to management
  • Produce corrective actions for nonconformities found

The internal audit checklist is the primary tool for conducting clause 9.2 audits. Internal auditors must not audit their own work — auditor independence is a specific requirement.

What auditors check:

  • Is there an audit programme (not just ad hoc audits)?
  • Are audit records available (audit plans, checklists, reports, corrective actions)?
  • Have all QMS processes been audited within the period?
  • Were findings followed up and corrective actions closed?

9.3 Management review

Top management must review the QMS at planned intervals to ensure its continuing suitability, adequacy, effectiveness, and alignment with the strategic direction. Management review inputs must include: internal/external issues changes, quality objectives achievement, process performance, NCRs and corrective actions, audit results, customer satisfaction, supplier performance, resource adequacy, risks and opportunities.

Management review outputs must include decisions on improvement opportunities and resource needs.

What auditors check:

  • Are management review records available?
  • Do they contain the required inputs (clause 9.3.2)?
  • Do they contain decisions/actions on improvement?
  • Is management review conducted by top management (not delegated)?

Clause 10 — Improvement

10.1 General

The organisation must determine and select opportunities for improvement, including improving products and services, preventing adverse effects, and improving QMS performance.

10.2 Nonconformity and corrective action

When a nonconformance occurs (whether in product, process, or the QMS itself), the organisation must react, evaluate the need for root cause investigation, implement corrective actions, review effectiveness, update risks and opportunities if needed, and make changes to the QMS if required. Documented information must be retained on: the nonconformance and actions taken, the results of corrective actions.

The CAPA process guide covers clause 10.2 requirements in detail.

What auditors check:

  • Is there a formal corrective action process?
  • Are nonconformances investigated to root cause?
  • Are corrective actions tracked to completion?
  • Is effectiveness verified?
  • Do repeat nonconformances get escalated?

10.3 Continual improvement

The organisation must continually improve the suitability, adequacy, and effectiveness of the QMS — using outputs of analysis, management review, and other sources.

What auditors check:

  • Is there evidence of improvement actions over time?
  • Does management review include improvement decisions?
  • Are quality objectives updated as targets are met?

Using This Checklist for Certification and Surveillance Audits

This checklist maps the structure of ISO 9001:2015 clauses 4-10. For certification audits, UKAS-accredited certification bodies assess all clauses. For surveillance audits (typically annual between 3-year recertification cycles), auditors typically focus on a subset of clauses, including areas with previous nonconformances and clause 9.2 (internal audit programme) in full.

Practical preparation steps:

  1. Map your documented information to clauses. For each mandatory documented information requirement in the standard, confirm you have a current, controlled document and that records exist.

  2. Review open corrective actions. Auditors will ask about all open nonconformances from previous audits. Ensure each has a root cause, a corrective action in progress or closed, and an effectiveness verification record.

  3. Check your internal audit programme. Confirm that all clauses have been audited within the programme period, that findings have been actioned, and that auditor independence was maintained.

  4. Prepare your management review records. Management review must have occurred since the last external audit. Check that it included all required inputs (clause 9.3.2) and produced documented outputs with decisions on improvement.

  5. Verify calibration records. Measurement equipment calibration is a common audit finding. Confirm that all measurement equipment used to verify product conformity is calibrated and records are current.


This guide summarises the requirements structure of ISO 9001:2015. The full standard text is available from ISO. This guide is a practical reference — verify requirements with the standard and your UKAS-accredited certification body.


Sources


ChangeRoute is a quality management tool for ISO 9001-certified UK manufacturing SMEs. Join the waitlist to be notified when it launches.

Ready to automate your change management workflow?

ChangeRoute replaces paper ECRs with a structured digital workflow. Join the waitlist for early access.

No spam. Unsubscribe any time. Privacy policy.