"What documents do I need for ISO 9001?" is one of the most common questions from businesses starting their certification journey. It is also one of the most poorly answered. Generic checklists circulating online are often either outdated, copied from the 2008 version of the standard, or so long they suggest you need a dedicated document management team to get certified.
The honest answer is that ISO 9001:2015 is more flexible about documentation than its predecessor. The standard does not prescribe a fixed list of documents you must produce. Instead, it requires documented information to the extent necessary to support the operation of your processes and to retain evidence that those processes are being carried out as planned. What that means in practice depends on the size and complexity of your organization.
This guide separates what the standard explicitly requires from what is commonly expected by auditors, and gives you a complete reference you can use to plan your documentation.
Documents Versus Records: Understanding the Difference
ISO 9001:2015 uses the term "documented information" to cover two distinct types of material that require different handling.
A document describes how something should be done: a procedure, a policy, a work instruction, a process map. Documents must be controlled, version-numbered, approved before use, and kept current. When a document is updated, the old version must be clearly superseded.
A record provides evidence that something was done: a completed inspection report, a signed delivery note, a management review meeting minute. Records must be retained for a defined period and protected from alteration. Unlike documents, records are not revised; they stand as permanent evidence of what happened.
Your document control procedure must address both types. Most nonconformities at ISO 9001 audits involve one of two failures: a document that has not been updated to reflect current practice, or a record that does not exist because nobody captured it at the time.
The Complete ISO 9001:2015 Mandatory Documents Reference
The table below lists every document and record explicitly required by ISO 9001:2015, along with commonly required additions. The "Required?" column distinguishes between what the standard explicitly mandates and what is strongly recommended in practice.
| Document or record | Required? | Notes |
|---|---|---|
| CLAUSE 4 | ||
| Scope of the QMS (Clause 4.3) | Yes | Defines which products, services, locations, and activities are covered. Must justify any exclusions to Clause 8 requirements. |
| CLAUSE 5 | ||
| Quality policy (Clause 5.2) | Yes | Must be appropriate to the organization, include a commitment to continual improvement, and be communicated internally. |
| CLAUSE 6 | ||
| Quality objectives (Clause 6.2) | Yes | Must be measurable, monitored, communicated, and updated as needed. Should include the metric, target, measurement method, responsible person, and review frequency. |
| CLAUSE 7 | ||
| Documented information control procedure (Clause 7.5) | Yes | Describes how QMS documents are created, approved, updated, distributed, and disposed of. |
| Competence records (Clause 7.2) | Yes | Evidence that staff performing work affecting quality conformance are competent: qualifications, training records, skill matrices, and results of competence assessments. |
| Awareness records (Clause 7.3) | Yes | Evidence that staff are aware of the quality policy, their contribution to QMS effectiveness, and the implications of non-conformity. |
| Communication records (Clause 7.4) | Yes | Records demonstrating that relevant internal and external communications related to the QMS have taken place. |
| CLAUSE 8 | ||
| Operational planning and control information (Clause 8.1) | Yes | Documents and records showing that production or service delivery processes are planned and carried out as intended. |
| Customer requirements review records (Clause 8.2.3) | Yes | Evidence that customer requirements and the organization's ability to meet them were reviewed before accepting an order. |
| Design and development records (Clause 8.3), if applicable | Yes | Required only if the organization carries out design and development. Includes inputs, outputs, reviews, verification, validation, and change records. |
| External provider information (Clause 8.4) | Yes | Approved supplier list, supplier evaluation records, purchase orders with quality requirements specified, incoming inspection records. |
| Traceability records (Clause 8.5.2), if required | Yes | Required when traceability is a contractual or regulatory requirement. Lot/batch records, serialization records. |
| Customer property records (Clause 8.5.3), if applicable | Yes | Records of customer-supplied materials, tooling, or data. Required only where customer property is part of the operation. |
| Change control records (Clause 8.5.6) | Yes | Records of planned and unplanned changes to processes or products, including reviews, approvals, and actions taken. |
| Product/service release records (Clause 8.6) | Yes | Evidence that release criteria were met before delivery. Inspection records, test results, certificates of conformance, delivery sign-off. |
| Nonconforming output records (Clause 8.7) | Yes | Records of nonconformities identified, actions taken (rework, scrap, concession), and the authorizing person. |
| CLAUSE 9 | ||
| Monitoring and measurement results (Clause 9.1) | Yes | Data showing performance against quality objectives and process metrics. KPI dashboards, defect rate logs, customer satisfaction results. |
| Calibration records (Clause 9.1.1), if applicable | Yes | Records for monitoring and measuring equipment used to provide evidence of product conformity. Calibration certificates, schedules. |
| Internal audit programme and reports (Clause 9.2) | Yes | An audit schedule covering all QMS areas, plus records of each audit: scope, findings, nonconformities raised, and auditor details. |
| Management review records (Clause 9.3) | Yes | Minutes of management review meetings covering all required inputs and any decisions and actions arising. |
| CLAUSE 10 | ||
| Nonconformity and corrective action records (Clause 10.2) | Yes | Records of nonconformities, causes, corrective actions taken, and verification that actions were effective. |
| RECOMMENDED (not explicitly mandated but expected) | ||
| Quality manual | Recommended | Not required by ISO 9001:2015 but widely expected by auditors and customers. Provides a navigable overview of the QMS. |
| Document register / master list | Recommended | Not explicitly required but essential in practice for maintaining version control across all controlled documents. |
| Risk register (Clause 6.1) | Recommended | The standard requires risks and opportunities to be identified and addressed but does not mandate a documented register. Auditors expect one. |
| Organizational chart or responsibility matrix | Recommended | Clause 5.3 requires roles and responsibilities to be assigned and communicated. An org chart or RACI matrix demonstrates this. |
| Supplier assessment questionnaire or evaluation form | Recommended | Clause 8.4 requires criteria for evaluating suppliers. A standard form documents how that criteria is applied consistently. |
| Customer satisfaction process records | Recommended | Clause 9.1.2 requires monitoring customer perception. Survey forms, complaint logs, and review records demonstrate compliance. |
| Internal audit procedure | Recommended | Clause 9.2 does not explicitly require a documented procedure, but most auditors expect one. |
| Corrective action procedure | Recommended | Clause 10.2 does not require a documented procedure, but a defined process for raising, investigating, and closing corrective actions is expected. |
How Much Documentation Does a Small Business Actually Need?
ISO 9001:2015 is explicit on this point. Clause 7.5.1 states that the extent of documented information required depends on the size of the organization and its type of activities, processes, products, and services; the complexity of processes and their interactions; and the competence of persons.
A professional services firm with ten employees and a straightforward service delivery model needs significantly less documentation than a 200-person manufacturer with complex production processes, multiple sites, and a regulated customer base. Both can achieve ISO 9001 certification; their documented systems will look very different. If you want a ballpark on overall effort and cost, our ISO 9001 cost calculator gives an instant estimate based on your size and number of sites.
The common mistake is over-documentation: producing lengthy, generic procedures in the belief that more documentation equals stronger compliance. Auditors are not impressed by volume. They look for accuracy, currency, and evidence that the documented system reflects what the organization actually does. A five-page procedure that is accurate and actively used will always outperform a fifty-page generic document that nobody has read.
The Documents Most Commonly Missing at First Audits
Based on the pattern of nonconformities raised at ISO 9001 certification audits, these are the documented information gaps that appear most frequently in first-time certification businesses.
- Calibration records with no out-of-tolerance procedure: organizations have calibration schedules but no documented process for what happens when an instrument fails calibration.
- Quality objectives with no measurement records: the objectives are documented but there is no evidence they are being tracked or reviewed.
- Internal audit reports with no audit programme: a single audit has been conducted but there is no documented schedule demonstrating that all areas of the QMS are covered in the audit cycle. A ready-made ISO 9001 internal audit checklist closes this gap quickly.
- Management review minutes that do not cover all required inputs: the meeting happened and was minuted, but the minutes do not address all the inputs that Clause 9.3 requires.
- Corrective action records with no effectiveness verification: a corrective action was raised and the fix was implemented, but there is no record confirming the fix worked.
- Supplier evaluation records that cannot be found: an approved supplier list exists but there are no evaluation records to show how suppliers were assessed before being added to it.
Document Control: The Foundation Everything Else Depends On
Every document in your QMS must itself be subject to document control. This means each document needs a unique identifier, a version number or issue date, an approval signature, and a defined review frequency. Your document control procedure must specify how documents are created, approved, updated, distributed, and retired.
The most common document control failures at audit are working from an outdated version of a procedure, having the same procedure in multiple versions across different departments, and failing to identify and remove superseded documents from circulation. Cloud-based document management, even something as simple as a shared folder with version history enabled, eliminates most of these failures. If you are evaluating purpose-built tools, you can browse ISO 9001 compliance software in our directory.
