ISO 9001

ISO 9001 SOPs: what the standard actually requires

ISO 9001:2015 does not tell you to write SOPs, and it does not give you a template. Here is what clause 7.5 genuinely obliges you to do, and what an auditor asks to see.

Want the section structure and a blank Word template? That lives on the SOP format page.

On this page

  1. ISO 9001 does not require SOPs
  2. What clause 7.5 does require
  3. The documented information named explicitly
  4. What an auditor actually asks for
  5. Five findings that come up repeatedly
  6. How many procedures do you need?
  7. Common questions

ISO 9001 does not require SOPs

This surprises people, and it changes how you should approach the whole exercise.

ISO 9001:2008 required six documented procedures by name: document control, control of records, internal audit, control of nonconforming product, corrective action and preventive action. Organizations wrote those six, filed them, and treated the job as done.

The 2015 revision dropped that prescriptive list. It replaced "documents and records" with the single term documented information, and it moved the decision to you: maintain the documented information the standard specifically calls for, plus whatever you determine is necessary for your quality management system to be effective.

That second half is the part people miss. It is not permission to document nothing. It is an obligation to decide, and to be able to defend the decision. If a process depends on someone's memory and produces inconsistent output, the absence of a procedure is a finding even though no clause names that procedure.

So the honest answer to "does ISO 9001 require an SOP for this process" is: the standard requires you to determine whether it does, and to be able to explain your reasoning.

What clause 7.5 does require

Clause 7.5 has three parts. Paraphrasing rather than quoting, since the standard text is copyrighted:

7.5.1 General

Your quality management system includes the documented information the standard requires, plus the documented information you have determined is necessary for effectiveness. Scale is explicitly acknowledged: the extent of documentation varies with the size of the organization, the complexity of its processes, and the competence of its people.

7.5.2 Creating and updating

When you create or update documented information, you ensure appropriate:

7.5.3 Control of documented information

Controlled documented information must be available and suitable for use where and when it is needed, and adequately protected from loss of integrity, improper use, or loss of confidentiality. Control addresses:

Documented information of external origin that you rely on has to be identified and controlled too, which catches customer prints and supplier specifications more often than people expect.

Notice what is not there: no required section headings, no mandated layout, no page count, no numbering convention. Any format that satisfies the above is compliant. The structure on the SOP format page is one that does, not one the standard imposes.

The documented information named explicitly

While the six mandatory procedures are gone, the standard still calls out documented information in specific places. Common examples include the scope of the QMS, the quality policy, quality objectives, evidence of fitness for purpose of monitoring and measuring resources, evidence of competence, records of design and development, records of the review of customer requirements, evidence of conformity of product and service release, records of nonconforming output and its disposition, internal audit results, and management review outputs.

Those are records of things happening, not procedures describing how. Which is the whole shift in the 2015 revision: less emphasis on documents describing intent, more on evidence that the thing was done.

Worth checking against your own certificate. If you are certified to AS9100, IATF 16949 or ISO 13485 rather than plain ISO 9001, those standards add their own documentation requirements on top, and several of them are prescriptive in ways ISO 9001 is not.

What an auditor actually asks for

In practice an audit of your documented information tends to run the same way, and knowing the sequence lets you prepare for it:

  1. "Show me the current revision." They are testing version control. If two copies of the same procedure exist at different revisions and both are in use, that is the finding.
  2. "Who approved this, and when?" They are testing 7.5.2. An unsigned or undated approval block is an easy finding, and it is the most common one.
  3. "Show me a completed record from this procedure." They are testing whether the procedure connects to reality. If the SOP references FORM-014 and nobody can produce a filled-in FORM-014, the procedure is a description of something that does not happen.
  4. "Show me that the people doing this were trained on it." They are connecting the document to competence requirements. A procedure nobody was trained against is a document, not a control.
  5. "What changed at the last revision, and why?" They are testing whether the document is maintained. A revision history reading "updated section 5" four times over is not evidence of review.

Five findings that come up repeatedly

  1. The referenced form does not exist. The procedure cites a record by number, the record was never created, and nobody noticed because nobody followed the reference.
  2. Obsolete copies still in use. A printed procedure taped to a machine at revision 1 while the system holds revision 3. This is why printed copies get marked uncontrolled.
  3. Approval by the author. The person who wrote it is the only signature on it. Review and approval is meant to be an independent check on suitability.
  4. External documents uncontrolled. Customer drawings and supplier specs sitting in an email folder, with no way to tell whether the version in use is current.
  5. Documented information that describes an aspiration. The procedure describes a better process than the one being run. Auditors find this by watching the task and reading along, and it is the most awkward finding to close because the fix is either changing the process or admitting the document was wishful.

How many procedures do you need?

There is no number, and any consultant who gives you one is selling a package. The workable test is process by process: if the output would vary depending on who performed the task, or if getting it wrong has consequences you care about, document it. If a competent person will reliably get the same result without a document, do not.

Two failure modes sit either side of that line. Over-documentation produces a library nobody reads, which is worse than no library because it creates a body of evidence you are not following your own system. Under-documentation shows up as inconsistent output and as training that takes months instead of days.

The standard's own language about size, complexity and competence is the permission to sit in the middle. A ten-person shop with two experienced machinists genuinely needs less documented information than a two-hundred-person plant with high turnover, and the standard says so.

Generate a controlled SOP

Pick your standard, describe the process, and get a complete procedure with the document control block already in place. Free, no account needed.

Generate an SOP free

Common questions

Does ISO 9001:2015 require a quality manual?

No. The explicit requirement for a quality manual was removed in the 2015 revision. Many organizations keep one anyway because it is a useful map of the system, and there is nothing wrong with that. It is a choice, not an obligation.

Do I have to cite clause numbers inside my procedures?

No, and it usually makes the document worse. Clause references date quickly when the standard is revised, and they mean nothing to the operator following the procedure. Align to the intent and let your internal audit programme handle the mapping.

Can our SOPs be electronic only?

Yes. The standard is deliberately media-neutral and names electronic media explicitly. What matters is that the information is available and suitable for use where it is needed, which for a shop floor process means somebody has thought about whether there is a screen at the point of use.

How long do we have to keep records?

ISO 9001 does not set retention periods. You do, based on customer requirements, statutory and regulatory requirements, and your own needs. What the standard requires is that you define retention and disposition and then follow what you defined.

What is the difference between a document and a record?

The 2015 revision folded both into documented information, but the practical distinction survives: a document tells you what to do and gets revised, a record shows what happened and does not. Your SOP is a document. The completed inspection form it produces is a record.

Back to Dropfeed