ISO 9001:2015 is a short document that is widely misread. Most of the misreading comes from treating it as a documentation specification rather than as a set of outcomes the organisation must achieve. This article walks through clauses 4 to 10 and, for each, states what the clause actually requires, what an auditor will accept as evidence, and where organisations most commonly go wrong.
Clause 4 — Context of the organisation
Clause 4 asks four things: determine the external and internal issues relevant to your purpose, determine the interested parties and their relevant requirements, determine the scope of the quality management system, and establish the processes needed and their interactions.
The common failure is a context analysis produced once, at implementation, by the management representative alone, and never revisited. A SWOT grid in a folder is not an analysis of context; it is a document about one. What an auditor looks for is evidence that the identified issues actually influenced something — an objective, a risk, a resourcing decision. If your context analysis changed nothing, it was not used.
Clause 5 — Leadership
Clause 5 places accountability on top management personally and explicitly. It is not delegable to a management representative — the 2015 revision removed that role for exactly this reason. Top management must be accountable for the effectiveness of the QMS, ensure the policy and objectives are compatible with strategic direction, ensure the QMS is integrated into business processes, and promote the process approach and risk-based thinking.
Auditors test this by interviewing top management directly. The question is rarely "what does clause 5 require" — it is "what were the outputs of your last management review, and what did you decide?" A managing director who cannot describe their own quality objectives, or who describes the QMS as something the quality department handles, has produced the evidence.
Clause 6 — Planning
Clause 6.1 requires you to determine the risks and opportunities that need to be addressed to give assurance that the QMS can achieve its intended results. Note what it does not require: a formal risk methodology, a risk matrix, or a risk register in any particular format. It requires that risks are determined and that actions to address them are planned, integrated into processes, and evaluated for effectiveness.
Clause 6.2 requires quality objectives that are measurable, monitored, communicated and updated. "Improve customer satisfaction" is not an objective; it is an aspiration. "Reduce customer complaints relating to delivery accuracy from 14 per quarter to fewer than 6 by Q4, owned by the logistics manager, reviewed monthly" is an objective.
Clause 7 — Support
- Resources — people, infrastructure, environment, monitoring and measuring resources including calibration, and organisational knowledge
- Competence — determined, achieved and evidenced, with the effectiveness of actions evaluated rather than assumed
- Awareness — people must know the policy, the relevant objectives, their contribution, and the implications of not conforming
- Communication — what, when, with whom, how and who does it
- Documented information — created, updated and controlled, with only the specific items the standard names being mandatory
Organisational knowledge (7.1.6) is the clause most often missed entirely. It asks you to determine the knowledge necessary to operate your processes, maintain it, and consider how to acquire additional knowledge when needs change. In practice, auditors examine what happens when an experienced person leaves.
Clause 8 — Operation
Clause 8 is the largest clause and the one where audits spend most of their time, because it is where the work happens: operational planning and control, requirements for products and services, design and development, control of externally provided processes, production and service provision, release, and control of nonconforming outputs.
The most productive area for auditors is 8.4, control of externally provided processes, products and services. Organisations routinely apply rigorous control to their own processes and almost none to the outsourced ones — despite the standard applying identical expectations. If you outsource heat treatment, plating, calibration or a service delivery component, the control you apply to it is in scope.
Clause 9 — Performance evaluation
Monitoring, measurement, analysis and evaluation; customer satisfaction; internal audit; management review. The requirement that is most often met in form and missed in substance is 9.1.3, analysis and evaluation. Collecting data is not analysing it. The standard asks you to evaluate conformity, customer satisfaction, QMS performance, planning effectiveness, risk action effectiveness, external provider performance, and improvement needs — and to use the results.
Management review (9.3) has a mandatory input list and a mandatory output list. Minutes that record attendance and a presentation but no decisions do not satisfy 9.3.3, which requires outputs on improvement opportunities, changes needed to the QMS, and resource needs.
Clause 10 — Improvement
Nonconformity and corrective action, and continual improvement. The critical requirement in 10.2 is the evaluation of the need for action to eliminate the cause, so the nonconformity does not recur. Correction is not corrective action. Replacing the defective part is correction; determining why the process produced it and changing that is corrective action.
If your corrective actions consistently read "operator counselled" or "training provided", your root cause analysis is not reaching a cause. People are almost never the root cause; the system that let them fail usually is.
Where to focus first
- Get the scope statement right — it appears on the certificate and your customers read it
- Make top management genuinely engaged in management review, because auditors will interview them
- Write measurable objectives with owners and review frequencies
- Apply 8.4 controls to your outsourced processes with the same rigour as your internal ones
- Fix root cause analysis before anything else — it is the single highest-leverage improvement in most systems