Quick Answer: The ISO 9001 requirements checklist covers 305 individual requirements organised across Clauses 4 to 10 of the ISO 9001:2015 standard (updated with a mandatory 2024 climate change amendment). To get certified, your quality management system must satisfy every clause — from documenting your organisational context right through to demonstrating continuous improvement. This guide breaks down exactly what you need, clause by clause.
Key Takeaways
- ISO 9001:2015 has 10 clauses total — Clauses 4 through 10 contain the operational requirements you must meet
- A 2024 amendment added mandatory climate change risk assessment to Clause 4 — you can't ignore it
- You'll need a live risk and opportunity register, not a document you create once and forget
- Competence records — job descriptions, training logs, skills matrices — are audited closely
- A gap analysis is the smartest starting point before you touch a single document
- Internal audits must happen before your external certification audit
- Nonconformities need documented corrective actions with evidence of root cause resolution
- Certification bodies must be accredited — not every auditor qualifies
- ISO 9001 requires ongoing improvement, not just a one-time compliance exercise
- Getting expert support significantly reduces the risk of failing your Stage 2 audit
What Is the ISO 9001 Requirements Checklist and Why Does It Matter?
The ISO 9001 requirements checklist is a structured tool that maps every mandatory requirement of the ISO 9001:2015 standard so you can verify whether your quality management system (QMS) meets them. Think of it as your pre-flight checklist before the certification audit.
Here's why it matters: auditors don't give partial credit. If a requirement isn't met, it's a nonconformity — and enough of those will delay or block your certificate. Having a clear checklist means no nasty surprises.
If you're new to all this, our complete guide to ISO 9001 certification gives you the full picture before you dig into the detail here.
What Are the 10 Clauses of ISO 9001:2015?
ISO 9001:2015 is built around 10 clauses. Clauses 1 to 3 are introductory — definitions, scope, and references. The real work starts at Clause 4.
| Clause | Title | Key Focus |
|---|---|---|
| 4 | Context of the Organisation | Internal/external issues, interested parties, QMS scope |
| 5 | Leadership | Management commitment, quality policy, roles |
| 6 | Planning | Risks, opportunities, quality objectives |
| 7 | Support | Resources, competence, communication, documentation |
| 8 | Operation | Process planning, customer requirements, production |
| 9 | Performance Evaluation | Monitoring, internal audits, management review |
| 10 | Improvement | Nonconformities, corrective actions, continual improvement |
Each clause builds on the last. You can't bolt them on independently — they're designed to work as a system.
The Full ISO 9001 Requirements Checklist: Everything You Need by Clause
Here's the practical breakdown. Use this as your working checklist.
Clause 4 — Context of the Organisation
- Document the internal and external issues that affect your QMS
- Identify all interested parties (customers, regulators, suppliers) and their requirements
- Define the scope of your QMS in writing
- Critical 2024 update: You must now formally assess how climate change could affect your operations. This isn't a policy statement — it requires genuine analysis. Auditors will probe it.
Clause 5 — Leadership
- Top management must demonstrate active commitment (not just sign a policy)
- A documented quality policy that's communicated across the business
- Defined roles, responsibilities, and authorities — in writing
Clause 6 — Planning
- A documented, actively maintained risk and opportunity register
- Quality objectives that are measurable and linked to business goals
- A formal change management process for QMS updates
Common mistake: Many businesses create a risk register for the audit and never touch it again. Auditors check dates. Keep it live.
Clause 7 — Support
- Evidence of adequate resources (people, infrastructure, environment)
- Competence records: job descriptions, training logs, skills matrices for key roles
- Documented information and communication processes
Clause 8 — Operation
- Planned and controlled processes for delivering your product or service
- Customer communication and requirements review processes
- Control of externally provided processes (your supply chain)
- Documented design and development processes (if applicable)
Clause 9 — Performance Evaluation
- Monitoring and measurement processes with defined methods
- Internal audits conducted at planned intervals before your external audit
- Management review meetings with documented outputs
Clause 10 — Improvement
- A documented procedure for identifying and recording nonconformities
- Corrective action processes with root cause analysis and evidence of resolution
- Ongoing improvement as a system element — not just reactive fixes
For a deeper look at what happens when auditors actually review all this, see our guide on what happens during an ISO certification audit.
Where Should You Start With the ISO 9001 Requirements Checklist?
Start with a gap analysis. Full stop.
A gap analysis compares your current processes against every ISO 9001 requirement and tells you exactly where you're compliant, where you're partially there, and where you have nothing. It stops you wasting time documenting things that are already fine and focuses your energy where it's actually needed.
Our gap analysis service does exactly this — and most clients are genuinely surprised by how much they already have in place.
After your gap analysis, the typical sequence looks like this:
- Address gaps in documentation and processes (Clauses 4–8)
- Run your first internal audit (Clause 9)
- Hold a management review meeting (Clause 9)
- Conduct your Stage 1 audit with your certification body
- Fix any issues raised at Stage 1
- Pass your Stage 2 audit and receive your certificate
Curious how long this realistically takes? Our ISO 9001 certification timeline guide gives you honest timescales.
What Documentation Does ISO 9001 Actually Require?
Here's what nobody tells you: ISO 9001:2015 doesn't prescribe a mountain of paperwork. It requires documented information — which means whatever format works for your business, as long as it's controlled and accessible.
Mandatory documented information includes:
- QMS scope
- Quality policy
- Quality objectives
- Risk and opportunity register
- Competence records
- Internal audit results
- Management review outputs
- Nonconformity and corrective action records
You do NOT need a separate procedure for every process — unless your auditor asks for one to demonstrate control. Keep it proportionate to your business size and complexity.
FAQ
Q: How many requirements does ISO 9001 have?
ISO 9001:2015 contains 305 individual requirements across Clauses 4 to 10. Your QMS must address all of them to achieve certification.
Q: Is the 2024 climate change amendment mandatory?
Yes. Since the 2024 amendment, every organisation must formally assess climate change as an external factor affecting their QMS. A brief policy mention won't satisfy auditors — it needs genuine analysis.
Q: Do I need a quality manual?
No. ISO 9001:2015 removed the mandatory quality manual requirement. You still need documented information, but the format is up to you.
Q: Can a small business get ISO 9001 certified?
Absolutely. The standard scales to any organisation size. Smaller businesses often have simpler QMS documentation and shorter certification timelines.
Q: What's the difference between a Stage 1 and Stage 2 audit?
Stage 1 reviews your documentation and readiness. Stage 2 is the full assessment of whether your QMS works in practice. Our Stage 1 vs Stage 2 audit guide explains both in detail.
Q: How often do internal audits need to happen?
At least once per year at a minimum, but the standard says "at planned intervals" — meaning often enough to cover all processes within your audit cycle.
Q: What happens if I fail the certification audit?
You'll receive a list of nonconformities. Minor ones can be closed with evidence. Major ones require a follow-up visit. Failing isn't the end — but it delays your certificate and costs more.
Q: How much does ISO 9001 certification cost?
Costs vary by business size and certification body. Our ISO 9001 certification cost guide breaks down what you'll actually pay in the UK.
Conclusion: Your Next Steps
The ISO 9001 requirements checklist isn't just a compliance exercise — it's a structured path to a quality management system that genuinely improves how your business operates.
Here's what to do next:
- Run a gap analysis — find out where you actually stand before spending time on documentation
- Build your risk register — and keep it live, not static
- Sort your competence records — auditors check these carefully
- Plan your internal audit — don't leave it to the last minute
- Choose an accredited certification body — not every auditor qualifies
If you want expert guidance through every step, ISO Adviser's implementation support is built for exactly this. We've guided hundreds of businesses through certification — we know what auditors look for and what trips people up.
Ready to get started? Get in touch with the team and we'll tell you honestly where you stand and what it'll take to get certified.
ISO 9001 Clause Readiness Checker
Tick each requirement your QMS currently satisfies. Track your readiness before the audit.
