ISO 9001:2015 does not tell you to write SOPs, and it does not give you a template. Here is what clause 7.5 genuinely obliges you to do, and what an auditor asks to see.
This surprises people, and it changes how you should approach the whole exercise.
ISO 9001:2008 required six documented procedures by name: document control, control of records, internal audit, control of nonconforming product, corrective action and preventive action. Organizations wrote those six, filed them, and treated the job as done.
The 2015 revision dropped that prescriptive list. It replaced "documents and records" with the single term documented information, and it moved the decision to you: maintain the documented information the standard specifically calls for, plus whatever you determine is necessary for your quality management system to be effective.
That second half is the part people miss. It is not permission to document nothing. It is an obligation to decide, and to be able to defend the decision. If a process depends on someone's memory and produces inconsistent output, the absence of a procedure is a finding even though no clause names that procedure.
So the honest answer to "does ISO 9001 require an SOP for this process" is: the standard requires you to determine whether it does, and to be able to explain your reasoning.
Clause 7.5 has three parts. Paraphrasing rather than quoting, since the standard text is copyrighted:
Your quality management system includes the documented information the standard requires, plus the documented information you have determined is necessary for effectiveness. Scale is explicitly acknowledged: the extent of documentation varies with the size of the organization, the complexity of its processes, and the competence of its people.
When you create or update documented information, you ensure appropriate:
Controlled documented information must be available and suitable for use where and when it is needed, and adequately protected from loss of integrity, improper use, or loss of confidentiality. Control addresses:
Documented information of external origin that you rely on has to be identified and controlled too, which catches customer prints and supplier specifications more often than people expect.
Notice what is not there: no required section headings, no mandated layout, no page count, no numbering convention. Any format that satisfies the above is compliant. The structure on the SOP format page is one that does, not one the standard imposes.
While the six mandatory procedures are gone, the standard still calls out documented information in specific places. Common examples include the scope of the QMS, the quality policy, quality objectives, evidence of fitness for purpose of monitoring and measuring resources, evidence of competence, records of design and development, records of the review of customer requirements, evidence of conformity of product and service release, records of nonconforming output and its disposition, internal audit results, and management review outputs.
Those are records of things happening, not procedures describing how. Which is the whole shift in the 2015 revision: less emphasis on documents describing intent, more on evidence that the thing was done.
In practice an audit of your documented information tends to run the same way, and knowing the sequence lets you prepare for it:
There is no number, and any consultant who gives you one is selling a package. The workable test is process by process: if the output would vary depending on who performed the task, or if getting it wrong has consequences you care about, document it. If a competent person will reliably get the same result without a document, do not.
Two failure modes sit either side of that line. Over-documentation produces a library nobody reads, which is worse than no library because it creates a body of evidence you are not following your own system. Under-documentation shows up as inconsistent output and as training that takes months instead of days.
The standard's own language about size, complexity and competence is the permission to sit in the middle. A ten-person shop with two experienced machinists genuinely needs less documented information than a two-hundred-person plant with high turnover, and the standard says so.
Pick your standard, describe the process, and get a complete procedure with the document control block already in place. Free, no account needed.
Generate an SOP freeNo. The explicit requirement for a quality manual was removed in the 2015 revision. Many organizations keep one anyway because it is a useful map of the system, and there is nothing wrong with that. It is a choice, not an obligation.
No, and it usually makes the document worse. Clause references date quickly when the standard is revised, and they mean nothing to the operator following the procedure. Align to the intent and let your internal audit programme handle the mapping.
Yes. The standard is deliberately media-neutral and names electronic media explicitly. What matters is that the information is available and suitable for use where it is needed, which for a shop floor process means somebody has thought about whether there is a screen at the point of use.
ISO 9001 does not set retention periods. You do, based on customer requirements, statutory and regulatory requirements, and your own needs. What the standard requires is that you define retention and disposition and then follow what you defined.
The 2015 revision folded both into documented information, but the practical distinction survives: a document tells you what to do and gets revised, a record shows what happened and does not. Your SOP is a document. The completed inspection form it produces is a record.