How to Implement ISO 9001
A step by step account of implementing a quality management system that meets ISO 9001:2015, from determining context through to Stage 2 certification and the surveillance cycle that follows.
Before you start
ISO 9001 implementation goes wrong in a predictable way: an organisation buys a set of template documents, fills in the company name, and then discovers at Stage 2 that the auditor is testing whether the described processes are the ones the business actually runs. The sequence below is written the other way round, starting from what the organisation does and ending at the certificate.
Two decisions have to be made by top management before anything else happens: what the scope of the quality management system will be, and who owns it. Clause 5 makes leadership commitment an auditable requirement, not a courtesy.
Which edition applies
The current edition is ISO 9001:2015, the fifth edition. It was amended by ISO 9001:2015/Amd 1:2024, Climate action changes, which requires an organisation to consider whether climate change is a relevant issue when determining its context and the needs and expectations of interested parties. The amendment did not change anything else in the standard.
ISO currently lists ISO 9001:2015 as a standard to be revised and has indicated that a revised edition is expected. Until that revision is published, ISO 9001:2015 with Amendment 1:2024 is the version you implement and are audited against. Check the ISO catalogue entry for ISO 9001 before planning any transition, and expect a transition period to be announced once a new edition appears.
The implementation sequence
- Confirm the edition and secure leadership commitment. Agree the scope, the resources and the accountable owner with top management, and confirm you are working to ISO 9001:2015 with Amendment 1:2024.
- Determine the context of the organisation. Identify the external and internal issues relevant to your purpose and strategic direction, identify the interested parties whose requirements matter, and record whether climate change is a relevant issue.
- Define and document the scope. State the products and services, sites and boundaries covered. If you determine that a requirement is not applicable, state which one and justify it. Design and development is the usual case.
- Map the processes and their interactions. Determine the processes needed, their sequence and interaction, their inputs and outputs, the criteria and methods for control, the resources, the responsibilities and the indicators you will use to judge performance.
- Set the quality policy and quality objectives. The policy has to be appropriate to the organisation and available as documented information. Objectives have to be measurable, monitored and supported by a plan stating what will be done, with what resources, by whom, by when, and how results will be evaluated.
- Address risks and opportunities. Determine what could stop the system achieving its intended results, plan proportionate actions, and integrate those actions into the processes rather than into a separate risk register nobody reads.
- Put support in place. People, infrastructure, working environment, monitoring and measuring resources including calibration where measurement traceability is required, and organisational knowledge. Establish competence, deliver awareness, define internal and external communication, and control your documented information.
- Implement operational planning and control. Cover requirements for products and services and their review, design and development where applicable, control of externally provided processes products and services, production and service provision including identification and traceability and preservation, post delivery activities, control of changes, release, and control of nonconforming outputs.
- Monitor, measure, analyse and evaluate. Decide what to measure, when to measure it and when to evaluate the results. Monitor customer perception. Analyse the data and use it.
- Run the internal audit programme. Audit against the requirements of the standard and against your own requirements, covering every process and site in scope before the certification audit. Use auditors who are competent and objective with respect to what they audit.
- Hold the management review. Cover the required inputs, including the status of actions from previous reviews, changes in external and internal issues, performance and effectiveness information, adequacy of resources, effectiveness of actions on risks and opportunities, and improvement opportunities. Record the decisions taken.
- Correct what the internal audit and review exposed. React to nonconformities, evaluate the need for action to eliminate causes, implement it, review effectiveness and retain the records.
- Select a certification body and complete Stage 1. Appoint an independent body, ideally accredited against ISO/IEC 17021-1. Stage 1 is a readiness and documentation review that tells you whether Stage 2 will succeed.
- Complete Stage 2 and close findings. Stage 2 tests implementation and effectiveness across the scope. Major nonconformities must be corrected and verified before the certificate is issued.
- Maintain the cycle. The certificate is valid for three years, with surveillance audits during that period and a recertification audit before expiry.
Mistakes that cost the most time
- Writing the system before mapping the processes. Template documents describe a generic organisation, and the auditor will sample against what your people actually do.
- A scope that does not match reality. Scopes that quietly exclude a busy site or a whole product line are found at Stage 1 and force a re-scope.
- Objectives that cannot be measured. Improve customer satisfaction is not an objective. An objective states a measure, a target and a review point.
- An internal audit programme that only covers the easy processes. The programme has to cover the requirements of the standard and all processes in scope, and evidence of that coverage is checked.
- Management review treated as a formality. The required inputs and outputs are specified, and a review with no recorded decisions is a finding.
- Leaving corrective action as a paperwork exercise. The standard asks for the cause to be evaluated and for the effectiveness of the action to be reviewed, not just for a form to be completed.
How Univate runs an ISO 9001 implementation
Univate works alongside the process owners rather than around them. That means a gap assessment against the current way of working, process mapping sessions with the people doing the work, a documented information set sized to the organisation, objectives and measurement your management team would use anyway, internal auditor training so the programme continues after we leave, a full internal audit and management review cycle, and support through Stage 1 and Stage 2 with the certification body you appoint.
We do not issue certificates and no consultancy can. Certification bodies operate under accreditation rules that keep consultancy and certification separate.
Implementation questions we are asked most often
Where should we start when implementing ISO 9001?
Start with context and scope, not with documents. Determine the external and internal issues that affect your ability to deliver, identify who your interested parties are and what they actually require, then write a scope statement that reflects the work you really do. Almost every failed implementation we see began by downloading a template manual and working backwards from it.
Do we need a quality manual?
ISO 9001:2015 does not require a quality manual. It requires documented information, some of which is specified in the standard and some of which the organisation determines is necessary for the effectiveness of the system. Many organisations still keep a manual because it is a convenient index for auditors and new staff, but it is a choice rather than a requirement.
What documented information does ISO 9001 actually require?
The scope of the quality management system, the quality policy, the quality objectives, and records covering monitoring and measuring resources, competence, product and service requirements review, design and development where applicable, external provider evaluation, characteristics of products and services, traceability where required, customer property that is lost or damaged, changes to production and service provision, release evidence, nonconforming outputs, monitoring and measurement results, the internal audit programme and results, management review results, and nonconformity and corrective action.
Does the climate change amendment mean we need an environmental programme?
No. ISO 9001:2015/Amd 1:2024 adds a requirement to consider whether climate change is a relevant issue when determining the context of the organisation and the needs and expectations of interested parties. It does not introduce environmental performance requirements. In practice you record the determination you reached and the reasoning behind it.
Can we implement ISO 9001 without a consultant?
Yes. Nothing in the standard requires external help, and organisations with in house quality expertise regularly do it themselves. Consultancy is usually bought to save calendar time, to avoid building a system that is heavier than the business needs, and to have someone who has seen how certification body auditors test each requirement.
What happens if the Stage 2 audit raises nonconformities?
Minor nonconformities are normally handled by submitting a corrective action plan that the certification body accepts, and the certificate can still be issued. Major nonconformities have to be corrected and the correction verified before certification, which in some cases means a follow up visit. The certification decision is taken by someone at the certification body who was not part of the audit team.
Univate Global delivers this certification in 9 markets. Get a free scoping consultation and a fixed-fee implementation quote today.
Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.








