Resources · Quality management

ISO 9001 explained

ISO 9001 is the international standard for quality management systems, and it is about consistency rather than excellence.

ISO 9001:2015 is the international standard for quality management systems. It is built on seven quality management principles and structured in ten clauses, of which four to ten carry the requirements. It does not define what a good product is. It requires that you define it, deliver it consistently, and improve when you do not.

What ISO 9001 actually asks of you

The most common misunderstanding is that certification means high quality. It does not. It means you have defined what your customers require, built a system to meet those requirements consistently, and can demonstrate the system works.

A company making deliberately basic products can be certified, provided it makes them to a defined specification, reliably, and handles it properly when it does not. That sounds like a criticism and it is not. Consistency is the harder problem for most organisations, and it is the one customers actually feel.

The 2015 revision shifted the emphasis in two ways worth knowing. It reduced the demand for documented procedures and increased the demand for demonstrated results. And it introduced risk-based thinking throughout, replacing the separate preventive action clause that used to sit at the end.

The seven quality management principles

These underpin the requirements and explain why the clauses are shaped as they are.

  1. Customer focus. Meeting and where possible exceeding customer requirements.
  2. Leadership. Direction and purpose set at the top, with alignment throughout.
  3. Engagement of people. Competent, empowered and involved people at every level.
  4. Process approach. Understanding activities as interrelated processes with inputs, outputs and owners.
  5. Improvement. A standing focus, not a project.
  6. Evidence-based decision making. Decisions from analysis of data rather than assertion.
  7. Relationship management. Managing suppliers and interested parties as part of performance.

How the ten clauses are structured

ISO 9001 uses the same harmonised structure as ISO 45001 and ISO 14001, which is why organisations increasingly run one integrated system rather than three parallel ones. Clauses 1 to 3 are scope, references and terms. The requirements are 4 to 10.

  • Clause 4, Context. Internal and external issues, interested parties, scope of the system, and the processes it covers.
  • Clause 5, Leadership. Top management accountability, the quality policy, and clear roles and authorities.
  • Clause 6, Planning. Risks and opportunities, quality objectives and how change is managed.
  • Clause 7, Support. Resources, competence, awareness, communication, documented information and the calibration of measuring equipment.
  • Clause 8, Operation. The largest clause. Planning and control, customer requirements, design and development, external providers, production and service provision, release, and control of non-conforming outputs.
  • Clause 9, Performance evaluation. Monitoring, customer satisfaction, analysis, internal audit and management review.
  • Clause 10, Improvement. Non-conformity, corrective action and continual improvement.

Non-conformity and corrective action under clause 10

Clause 10.2 is where most audit findings land, and its logic is worth reading carefully. When a non-conformity occurs you must react to it and deal with the consequences, evaluate whether action is needed to eliminate the cause so it does not recur, implement that action, review its effectiveness, and update risks and the system if needed.

The word “evaluate” carries weight. The standard does not require corrective action for every non-conformity. It requires you to consider whether it is needed and to be able to justify the answer. Raising a full corrective action for every minor defect is a common over-correction that buries the significant ones.

Note also that the 2015 version has no preventive action clause. Prevention is handled through risk-based thinking in clause 6 instead. Organisations still running a separate preventive action register are working to the 2008 structure. See CAPA explained and what a non-conformance is.

What certification involves

Certification is voluntary unless a customer or a tender requires it, and for many organisations that requirement is precisely why they pursue it.

The route is a stage one audit reviewing documentation and readiness, then a stage two audit some weeks later testing whether the system operates in practice. Certificates run three years with annual surveillance audits and a recertification at the end. You need enough operating history to produce records, typically at least three months, and a completed internal audit and management review before stage two.

Use a certification body accredited by a recognised national accreditation body, UKAS in the UK. Unaccredited certificates exist, cost less, and are routinely rejected by the customers who asked for certification in the first place, which defeats the purpose.

Important: this guide is a general explanation, not legal advice. the requirements of ISO 9001 are set by ISO and certification requirements vary by certification body. Always check the current source, and take professional advice where needed.

Frequently asked questions

Does ISO 9001 certification mean a product is high quality?

No. It means the organisation has defined its requirements and has a system for meeting them consistently. Consistency and quality are related but not the same thing, and the standard is explicit that it sets no product specification.

What is the current version of ISO 9001?

ISO 9001:2015. It replaced ISO 9001:2008, introducing the harmonised ten-clause structure, risk-based thinking, and a reduced emphasis on documented procedures.

Is preventive action still part of ISO 9001?

Not as a separate clause. The 2015 version removed it and handles prevention through risk-based thinking in clause 6. A separate preventive action register is a sign of a system still built to the 2008 structure.

How long does ISO 9001 certification take?

Typically six to twelve months from a standing start. You need enough operating history to generate records, plus a completed internal audit and management review before the stage two audit.

What is the difference between ISO 9001 and ISO 45001?

ISO 9001 covers quality management, ISO 45001 covers occupational health and safety. They share the same ten-clause structure, so running them as one integrated system is considerably easier than running two separate ones.

Do I need accredited certification?

If a customer or tender requires ISO 9001, they almost always mean accredited certification from a body overseen by a national accreditation body such as UKAS. Unaccredited certificates are cheaper and frequently rejected.

Does every non-conformity need a corrective action?

No. Clause 10.2 requires you to evaluate whether action is needed to eliminate the cause, and to be able to justify that decision. Raising corrective actions for every minor defect buries the significant ones.

Sources

  1. International Organization for Standardization, ISO 9001:2015 Quality management systems. https://www.iso.org/standard/62085.html
  2. International Organization for Standardization, quality management principles. https://www.iso.org/publication/PUB100080.html
  3. United Kingdom Accreditation Service, accredited certification bodies. https://www.ukas.com/
  4. International Organization for Standardization, ISO 45001:2018. https://www.iso.org/standard/63787.html

Non-conformances that close properly

Raise, assign, action and verify effectiveness in one place, with the audit trail already there when the certification body asks.

Book a demo