ISO 9001 Requirements Checklist
A clause by clause checklist of what ISO 9001:2015 requires, the documented information you have to be able to produce, and the questions a certification body auditor will ask at Stage 1 and Stage 2.
How to use this checklist
This checklist follows the order of ISO 9001:2015. Each clause is listed with what you need to be able to show. It is not a substitute for the standard itself, which you should buy from ISO or your national standards body, and it does not reproduce the wording of the standard. Use it to work out where the gaps are before an auditor does.
One rule applies throughout: if you cannot produce evidence, the requirement is not met. Documented information is either maintained, meaning it is kept current, or retained, meaning it is kept as a record of what happened.
Which edition applies
The current edition is ISO 9001:2015, the fifth edition. It was amended by ISO 9001:2015/Amd 1:2024, Climate action changes, which requires an organisation to consider whether climate change is a relevant issue when determining its context and the needs and expectations of interested parties. The amendment did not change anything else in the standard.
ISO currently lists ISO 9001:2015 as a standard to be revised and has indicated that a revised edition is expected. Until that revision is published, ISO 9001:2015 with Amendment 1:2024 is the version you implement and are audited against. Check the ISO catalogue entry for ISO 9001 before planning any transition, and expect a transition period to be announced once a new edition appears.
Clause 4, Context of the organisation
- External and internal issues relevant to your purpose and strategic direction have been determined, and climate change has been considered as a possible relevant issue.
- Interested parties relevant to the quality management system have been identified, together with their relevant requirements.
- Both are monitored and reviewed rather than determined once and filed.
- The scope of the quality management system is available and maintained as documented information, stating the products and services covered and the boundaries.
- Any requirement determined not to be applicable is stated in the scope with its justification.
- The processes needed for the quality management system have been determined, along with their inputs, outputs, sequence and interaction, criteria and methods, resources, responsibilities and authorities, risks and opportunities, and performance indicators.
Clause 5, Leadership
- Top management can demonstrate accountability for the effectiveness of the quality management system, not just sponsorship of it.
- The quality policy is established, appropriate to the organisation, communicated, understood, applied, and available as documented information.
- Customer focus is demonstrated: customer and applicable statutory and regulatory requirements are determined and met, and risks and opportunities affecting conformity are addressed.
- Roles, responsibilities and authorities relevant to the quality management system are assigned and communicated.
Clause 6, Planning
- Risks and opportunities arising from context and interested parties have been determined, and actions to address them are planned and integrated into the processes.
- The effectiveness of those actions is evaluated.
- Quality objectives are established at relevant functions, levels and processes, are measurable, consistent with the policy, monitored, communicated and updated, and maintained as documented information.
- For each objective there is a plan covering what will be done, what resources are required, who is responsible, when it will be completed and how the results will be evaluated.
- Changes to the quality management system are planned rather than made ad hoc, considering purpose and consequences, system integrity, resource availability and reallocation of responsibilities.
Clause 7, Support
- Resources are determined and provided: people, infrastructure, environment for the operation of processes, monitoring and measuring resources, and organisational knowledge.
- Where measurement traceability is a requirement, measuring equipment is calibrated or verified against traceable standards, identified, and safeguarded, with records retained.
- Competence is determined for people whose work affects performance, and evidence of competence is retained.
- People are aware of the quality policy, relevant objectives, their contribution and the implications of not conforming.
- Internal and external communications relevant to the quality management system are determined: what, when, with whom, how and who communicates.
- Documented information is controlled: identification and description, format, review and approval, availability, protection, distribution, storage, version control, retention and disposition. External documented information is identified and controlled.
Clause 8, Operation
- Operational processes are planned, implemented and controlled, with criteria, resources and the documented information needed to give confidence that processes have been carried out as planned.
- Communication with customers covers product and service information, enquiries and orders including changes, customer feedback and complaints, handling of customer property and requirements for contingency actions.
- Requirements for products and services are determined and reviewed before commitment, and records of the review and of new requirements are retained. Changed requirements are communicated and documents amended.
- Where design and development applies, the process is planned and controlled, with inputs, controls, outputs and changes all recorded.
- Externally provided processes, products and services are controlled. External providers are evaluated, selected, monitored and re-evaluated against defined criteria, with records retained.
- Production and service provision is carried out under controlled conditions, covering documented characteristics and results, suitable monitoring and measuring resources, infrastructure and environment, competent people, validation of processes where output cannot be verified, and actions to prevent human error.
- Outputs are identified and, where traceability is a requirement, uniquely identified with records retained. Property belonging to customers or external providers is identified, verified, protected and safeguarded, with any loss or damage reported and recorded.
- Outputs are preserved, post delivery activities are determined, and changes to production and service provision are reviewed and controlled with records retained.
- Release does not proceed until planned arrangements are satisfactorily completed, with evidence of conformity and the identity of the releasing authority retained.
- Nonconforming outputs are identified and controlled, action taken is recorded, and the records describe the nonconformity, the actions taken, any concessions obtained and who decided.
Clause 9, Performance evaluation
- What needs to be monitored and measured has been determined, along with the methods, when it is done and when results are analysed and evaluated. Records are retained.
- Customer perception of the degree to which requirements have been met is monitored, and the methods for obtaining and using that information are defined.
- Data is analysed and evaluated to assess conformity, customer satisfaction, performance and effectiveness of the system and of planning, external provider performance and the need for improvement.
- An internal audit programme exists covering frequency, methods, responsibilities, planning and reporting. Audit criteria and scope are defined, auditors are objective and impartial, results are reported to relevant management, correction and corrective action follow without undue delay, and the programme and results are retained as documented information.
- Management review is held at planned intervals and covers all the required inputs, and the outputs record decisions and actions on improvement opportunities, changes needed to the system and resource needs.
Clause 10, Improvement
- Opportunities for improvement are determined and acted upon, including improving products and services, correcting and preventing undesired effects, and improving performance and effectiveness.
- When a nonconformity occurs it is reacted to, its consequences are dealt with, and the need for action to eliminate the cause is evaluated, including whether similar nonconformities exist or could occur.
- Corrective action is implemented, its effectiveness reviewed, and risks and opportunities updated if necessary.
- Documented information is retained on the nature of nonconformities, actions taken and the results of corrective action.
- The suitability, adequacy and effectiveness of the quality management system are continually improved, using the results of analysis and evaluation and the outputs of management review.
Readiness checks before the certification audit
- At least one complete internal audit cycle has covered every process and site in the scope.
- At least one management review has been held with all required inputs and recorded outputs.
- Corrective actions raised by internal audit have been closed with evidence of effectiveness, not just closed on paper.
- The scope statement matches the sites and activities the auditor will actually see.
- Objectives have current measurements and a recorded review, not targets set at the start of the project and never revisited.
- Documented information is version controlled and the current versions are the ones in use at the point of work.
- Someone can explain, without reading from a script, how a customer requirement travels through the process to release.
How Univate uses this checklist
Univate runs this as a gap assessment first, working through each clause with the process owners, recording what exists, what exists but is not evidenced, and what does not exist. That produces a prioritised plan rather than a list of missing documents. From there we support process mapping, the documented information set, internal auditor training, the first full audit cycle and management review, and the Stage 1 and Stage 2 audits with the certification body you appoint.
Checklist questions we are asked most often
What are the main requirement areas of ISO 9001?
The auditable requirements sit in clauses 4 to 10: context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. Clauses 1 to 3 cover scope, normative references and terms and definitions and contain no requirements to audit against.
Which documents are mandatory under ISO 9001:2015?
The standard requires the scope of the quality management system, the quality policy and the quality objectives to be maintained as documented information, plus retained records covering monitoring and measuring resources, competence, review of requirements for products and services, design and development where applicable, evaluation of external providers, characteristics of products and services, traceability where required, customer or external provider property that is lost or damaged, changes to production and service provision, release evidence, nonconforming outputs, monitoring and measurement results, the internal audit programme and results, management review results, and nonconformity and corrective action.
Is a quality manual still required?
No. The 2015 edition removed the requirement for a quality manual and for six specific documented procedures that earlier editions mandated. You determine what documented information is necessary for the effectiveness of your quality management system, in addition to what the standard specifically requires.
How does the climate change amendment affect the checklist?
ISO 9001:2015/Amd 1:2024 adds two things: the organisation shall determine whether climate change is a relevant issue when determining external and internal issues, and a note that relevant interested parties can have requirements related to climate change. It sits inside clause 4 and does not add environmental performance requirements anywhere else in the standard.
What will the auditor look at first?
At Stage 1 the auditor typically starts with the documented scope, the process map, the quality policy and objectives, the internal audit programme and its results, and the management review records. These show whether the system has completed at least one full cycle and is ready to be tested for effectiveness at Stage 2.
Can requirements be excluded?
A requirement can be determined to be not applicable only where it cannot affect the organisation ability to provide conforming products and services or to enhance customer satisfaction. The determination must be recorded in the documented scope with its justification. Design and development is the most common case, for example where an organisation manufactures entirely to customer specifications.
Need help achieving this certification? Univate Global delivers end-to-end implementation in 9 markets. Book a free consultation today.
Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.








