Quick Answer: ISO 9001:2015 requires a specific set of documented information — covering your quality policy, objectives, scope, and a range of operational records — to demonstrate your quality management system actually works. The standard doesn't demand a mountain of paperwork by name, but auditors will look for evidence across roughly 10 documented areas. Miss any of them and you won't pass.
Key Takeaways
- ISO 9001:2015 requires documented information, not a fixed list of named procedures — but certain documents are non-negotiable in practice
- The quality policy, scope, and quality objectives are the three core documents every certified business must have
- You also need records — evidence that your system is running, not just written down
- Auditors check both documents (what you plan) and records (what you did)
- The standard gives you flexibility in format — digital, paper, or a mix all work
- Missing records are one of the most common reasons businesses fail their Stage 2 audit
- You don't need a 200-page quality manual — but you do need the right evidence in the right places
- Getting expert help to identify gaps early saves significant time and money
What Does ISO 9001 Actually Require You to Document?
ISO 9001:2015 requires documented information that supports the operation of your quality management system and provides confidence that processes are being carried out as planned. The standard deliberately avoids prescribing exact document names — it focuses on evidence of conformity instead.
That said, certain documents are clearly required when you read the standard carefully. Here's the honest breakdown.
ISO 9001 Mandatory Documents: What You Must Have (The Core List)
These are the documents and records the standard explicitly requires. Think of them in two categories: documents (what you plan and how you operate) and records (proof that you actually did it).
The Mandatory Documents
| Document | ISO 9001:2015 Clause |
|---|---|
| Scope of the QMS | 4.3 |
| Quality Policy | 5.2 |
| Quality Objectives | 6.2 |
| Criteria for evaluation of suppliers | 8.4 |
| Any other documents the organisation determines are necessary | Various |
Scope of the QMS — This defines what your quality management system covers. Which sites, which products, which services. If it's not in scope, auditors won't check it — but you can't cherry-pick just to avoid scrutiny.
Quality Policy — A short, genuine statement of your commitment to quality. It needs to be appropriate to your business, include a commitment to continual improvement, and actually be communicated to your people. A laminated poster nobody reads doesn't count.
Quality Objectives — Measurable targets that show you're actively improving. "We aim to be good" isn't an objective. "Reduce customer complaints by 15% by Q4 2026" is.
Supplier evaluation criteria — You need documented evidence of how you assess and select external suppliers. This matters particularly if you're in manufacturing, construction, or any sector where supply chain quality affects your output.
The Mandatory Records
Records are where many businesses fall short. You need documented evidence that your system is operating — not just that it exists on paper.
- ✅ Monitoring and measuring equipment calibration records
- ✅ Records of staff training, skills, experience, and qualifications
- ✅ Product and service requirements review records
- ✅ Internal audit programme and results
- ✅ Management review results
- ✅ Nonconformity records
- ✅ Corrective action records
- ✅ Results of design and development (if applicable to your business)
- ✅ Customer communication records (complaints, feedback, requirements)
Common mistake: Businesses write excellent procedures but keep no records of actually following them. An auditor will ask to see evidence. "We do it, we just don't write it down" is a nonconformity every time.
ISO 9001 Mandatory Documents: What You Must Know About the Quality Manual
Here's something that surprises a lot of people: ISO 9001:2015 does not require a quality manual.
The 2008 version did. The 2015 revision dropped that requirement deliberately. You can still create one — and many businesses find it useful as an overview document — but it's not mandatory. Don't let anyone tell you otherwise.
What the standard does require is that you can demonstrate your system through documented information, however that's organised. A well-structured set of procedures, policies, and records works just as well as a traditional quality manual.
Do You Need Documented Procedures?
Not as many as you might think. ISO 9001:2015 doesn't mandate specific named procedures the way older versions did.
You need documented procedures where their absence would lead to inconsistency. In practice, that usually means:
- Internal audit procedure
- Nonconformity and corrective action procedure
- Control of documented information
- Any process where variation creates risk
For other processes, a trained and competent person following a clear process may be sufficient — as long as you can demonstrate consistency. This is where a proper gap analysis is genuinely useful. It tells you exactly where your documentation is thin before an auditor finds out.
What Happens During the Audit If Documents Are Missing?
Short answer: you get a nonconformity, and certification is delayed.
During your Stage 2 certification audit, the auditor will systematically check for documented evidence across every clause they're sampling. If a required record doesn't exist — say, no calibration records for your measuring equipment — that's a finding.
Minor nonconformities can sometimes be resolved within a set timeframe post-audit. Major nonconformities mean you can't be certified until they're addressed and re-audited. That costs time and money.
The best way to avoid this? Know exactly what's required before you walk into the audit room. Our guide on how to prepare for your ISO certification audit walks through the full 90-day preparation process.
How Much Documentation Is Actually Enough?
The standard says: enough to give confidence that processes are carried out as planned, and enough to demonstrate conformity.
In practice, that means:
- Small businesses often need less documentation because processes are simpler and people wear multiple hats
- Larger businesses need more because consistency across teams and sites requires clearer written guidance
- Regulated industries (healthcare, medical devices, construction) typically need more rigorous records regardless of size
The goal isn't volume — it's evidence. Ten well-maintained, accurate records beat a hundred documents that nobody uses.
If you're unsure where your business sits, ISO Adviser's implementation support service helps you build exactly what you need — nothing more, nothing less.
Frequently Asked Questions
Q: Is a quality manual mandatory for ISO 9001:2015?
No. ISO 9001:2015 removed the quality manual requirement. You can create one if it helps, but it's not needed for certification.
Q: How many documented procedures does ISO 9001 require?
The standard doesn't specify a number. You need documented procedures wherever their absence would create inconsistency or risk. In practice, most businesses need at least 4–6 core procedures.
Q: Can documents be stored digitally?
Yes. ISO 9001:2015 accepts any format — digital, paper, or a combination. What matters is that documents are controlled, accessible, and protected from unintended changes.
Q: What's the difference between a document and a record in ISO 9001?
A document describes how something should be done (policy, procedure, work instruction). A record proves that it was done (audit results, calibration logs, training records).
Q: Do I need to document every single process?
No. You document processes where consistency matters and where undocumented variation creates risk. Routine, simple tasks performed by trained staff may not need formal written procedures.
Q: What happens if I'm missing a mandatory record during my audit?
The auditor will raise a nonconformity. Minor ones can be resolved post-audit within an agreed timeframe. Major ones prevent certification until they're fully addressed.
Q: How long do I need to keep ISO 9001 records?
The standard doesn't specify a retention period — you decide based on legal requirements, customer contracts, and operational need. Most businesses keep records for a minimum of three years.
Q: Can I use templates for my ISO 9001 documents?
Yes, templates are a practical starting point. But they must be adapted to reflect your actual business — auditors can spot generic, unadapted templates immediately, and they raise questions about whether your system is real.
Conclusion: Get Your Documents Right Before the Auditor Does
The ISO 9001 mandatory documents list isn't as long as most people fear. But what's required must be done properly — accurate, maintained, and actually used by your people.
Here's your action plan:
- Map your current documentation against the mandatory list above
- Identify gaps — especially in records (calibration, training, audits, corrective actions)
- Build or adapt documents to reflect how your business actually operates
- Run an internal audit before your certification audit to catch issues first
- Get expert eyes on it — a consultant who knows what auditors look for is worth the investment
If you're not sure where to start, a gap analysis is the most efficient first step. It shows you exactly what you have, what you're missing, and what needs to change — before you commit to a full implementation programme.
For a fuller picture of the certification journey, the ISO 9001 quality management overview and our guide on how long ISO 9001 certification takes are worth reading alongside this one.
The paperwork isn't the point. The point is a quality system that works — and documents are how you prove it does.
ISO 9001 Mandatory Documents Checker
Tick each item you already have in place. See how audit-ready you are.
