Key takeaways
  • The requirements live in clauses 4 to 10. Clauses 1 to 3 are scope, references and terms.
  • The standard requires far less documentation than most implementations produce. Only a handful of items are explicitly required as documented information.
  • Clause 6.1, actions to address risks and opportunities, is where most systems are thin and where auditors probe.
The clause most systems get wrong
6.1 risks and opportunities

Many organisations produce a risk register once and never connect it to anything. The clause expects risk thinking to influence the planning of the quality system and to be reviewed when things change, which is a behaviour rather than a document.

Clause 4: Context of the organisation

Determine the external and internal issues relevant to your purpose, identify interested parties and their relevant requirements, define the scope of the quality system, and establish the processes and how they interact. In practice: know what affects you, who cares, what you are claiming coverage of, and how your processes connect.

Clause 5: Leadership

Top management must demonstrate commitment, establish a quality policy, and assign responsibilities and authorities. Auditors test this by talking to management about the system rather than by reading the policy. A policy nobody in leadership can discuss is a finding waiting to happen.

Clause 6: Planning

  • 6.1 Actions to address risks and opportunities.
  • 6.2 Quality objectives and planning to achieve them: objectives must be measurable, monitored and have a plan with resources, responsibility and a timeframe.
  • 6.3 Planning of changes, so that changes to the system happen deliberately rather than by drift.

Clause 7: Support

Resources including people, infrastructure, environment, monitoring and measuring resources, and organisational knowledge. Then competence, awareness, communication, and documented information. Note that 7.1.5 requires measuring equipment to be calibrated or verified with records, one of the few explicit record requirements.

Clause 8: Operation

The largest clause: operational planning and control, requirements for products and services, design and development where applicable, control of external providers, production and service provision, release, and control of nonconforming outputs. Most of your day-to-day evidence lives here.

Clause 9: Performance evaluation

  • 9.1 Monitoring, measurement, analysis and evaluation, including customer satisfaction.
  • 9.2 Internal audit, on a programme reflecting importance and previous results.
  • 9.3 Management review, with defined inputs and outputs including decisions on improvement and resource needs.

Clause 10: Improvement

Nonconformity and corrective action, and continual improvement. The corrective action requirement includes evaluating whether similar nonconformities exist or could occur elsewhere, which is the clause equivalent of the discipline most teams skip.

What must actually be documented

The standard names a limited set of documented information: the scope, the quality policy, quality objectives, and specific records such as calibration, competence, audit results, management review, nonconformities and corrective actions, and evidence of conformity of products. Everything else is documented only to the extent needed for your processes to work, which is a judgement you are entitled to make.