ISO Procedure Writing Guide: Templates and Examples

Quick Answer: An ISO procedure is a documented, step-by-step description of how a specific process should be carried out within your management system. A good ISO procedure writing guide covers four core elements: purpose and scope, roles and responsibilities, the procedure steps themselves, and a revision history. Get these right, and your documents will satisfy auditors and actually help your team do their jobs.


Key Takeaways

  • ISO procedures must be clear, consistent, and usable by the people doing the work — not just impressive on paper
  • Every procedure needs a purpose, scope, defined roles, numbered steps, and version control
  • Plain language beats technical jargon every time — if your team can't follow it, it won't pass an audit
  • Templates save significant time; adapt them to your business rather than copying them verbatim
  • Auditors look for evidence that your procedures are followed, not just written
  • Work instructions and procedures are different things — know which one you need
  • Overly complex procedures are one of the most common reasons businesses struggle at certification audits
  • You don't need hundreds of documents — quality beats quantity in ISO documentation

What Is an ISO Procedure and Why Does It Matter?

An ISO procedure is a controlled document that explains how a process works within your quality or management system. It answers three questions: what needs to happen, who does it, and in what order.

Here's why it matters. During a certification audit, auditors don't just check that your procedures exist — they check whether your team actually follows them. A procedure that nobody uses is worse than no procedure at all, because it creates a gap between what you've documented and what you're doing.

Common mistake: Writing procedures for auditors instead of for your team. If your staff can't pick up a document and follow it without a translator, rewrite it.


What Should Every ISO Procedure Include?

Every well-written ISO procedure contains the same core components, regardless of which standard you're working to — ISO 9001, ISO 14001, ISO 27001, or others.h

Here's the standard structure:

Document HeaderTitle, document number, version, date, author, approver
PurposeWhy this procedure exists — one or two sentences
ScopeWhat it applies to and what it doesn't
Roles and ResponsibilitiesWho owns each step — job titles, not names
Procedure StepsNumbered, sequential actions in plain language
Related DocumentsLinks to forms, work instructions, or other procedures
Revision HistoryVersion log showing what changed and when

Use job titles rather than individual names in the roles section. People leave; job titles don't. An auditor will flag a procedure that references "Sarah in accounts" as poorly controlled.


How to Use This ISO Procedure Writing Guide: Templates and Examples

This ISO procedure writing guide works best when you treat it as a framework, not a formula. Every business is different, and your procedures should reflect how your organisation actually operates.

Here's a practical approach:

  1. Start with your highest-risk processes — the ones where mistakes cost money, cause safety issues, or affect customers
  2. Interview the people who do the work — they know the real steps, not the theoretical ones
  3. Draft in plain English first — worry about formatting later
  4. Test it with someone unfamiliar with the process — if they can follow it, it works
  5. Get sign-off from the process owner — not just the quality manager

One thing this ISO procedure writing guide consistently highlights: the gap between what management thinks happens and what actually happens on the ground is often significant. Your procedures need to capture reality, then improve it — not describe a fantasy version of your process.

For businesses just starting out, our ISO implementation support service includes procedure templates tailored to your specific standard and industry.


What's the Difference Between a Procedure and a Work Instruction?

This trips up almost everyone. Here's the distinction in plain English.

  • A procedure describes a process at a higher level — what happens, who's responsible, and the general sequence of steps
  • A work instruction is more granular — it tells someone exactly how to perform a specific task, often with screenshots, diagrams, or very detailed steps

Think of a procedure as the recipe and a work instruction as the technique guide for a specific cooking method.

When to use which:

  • Use a procedure when multiple roles are involved or when the process spans departments
  • Use a work instruction when one person performs a single, specific task that requires detailed guidance

Not every process needs both. Over-documenting is a real problem — it creates maintenance burden without adding value.


ISO Procedure Template: A Practical Example

Below is a stripped-down example of what a completed procedure looks like in practice. This follows the structure recommended in this ISO procedure writing guide.


Document Title: Customer Complaint Handling Procedure
Document Number: QMS-007
Version: 1.2
Date: 01 March 2026
Owner: Quality Manager
Approved by: Operations Director

Purpose: To ensure all customer complaints are received, investigated, and resolved in a consistent and timely manner.

Scope: Applies to all complaints received via phone, email, or in person. Does not cover warranty claims handled under QMS-012.

Roles:

  • Customer Service Team: Receives and logs complaints
  • Quality Manager: Investigates root cause
  • Operations Director: Approves corrective actions over £500

Procedure:

  1. Log complaint in the CRM system within 24 hours of receipt
  2. Acknowledge complaint to customer within 48 hours
  3. Investigate root cause using the 5-Why method
  4. Document findings in the Complaint Investigation Form (F-007)
  5. Implement corrective action and record in the CAPA register
  6. Close complaint and notify customer within 10 working days

Related Documents: F-007 Complaint Investigation Form, QMS-012 Warranty Claims Procedure


This is the level of detail auditors expect. Not a novel — a clear, usable document.


How Do You Control and Maintain ISO Procedures?

Document control is non-negotiable for ISO certification. Without it, you'll have multiple versions of the same procedure floating around, and that's an immediate finding in any audit.

Your document control system needs to handle:

  • Version numbering — every change creates a new version
  • Approval workflow — who can authorise changes
  • Distribution control — ensuring people use the current version
  • Obsolete document management — removing old versions from circulation

You don't need expensive software for this. A shared drive with clear folder structure and a document register works fine for smaller businesses. What matters is consistency.

If you're working towards ISO 9001 certification, Clause 7.5 specifically covers documented information requirements — it's worth reading carefully before you build your document control system.

Our internal auditing service regularly identifies document control issues before they become audit findings. It's one of the most common gaps we see.


What Are the Most Common Mistakes in ISO Procedure Writing?

Here's the truth: most businesses make the same mistakes. Knowing them in advance saves you significant rework.

The top mistakes:

  • Writing for auditors, not users — procedures nobody reads are worthless
  • Using passive voice throughout — "the form shall be completed" by whom?
  • Including too much detail — procedures become unmanageable and outdated quickly
  • Skipping the scope section — ambiguity about what a procedure covers causes real problems
  • Not reviewing procedures regularly — outdated procedures fail audits and cause operational errors
  • Copying templates verbatim — generic templates need adapting to your actual processes

The reality is that a short, accurate, well-followed procedure beats a comprehensive document nobody opens. Auditors know the difference.


FAQ

How many procedures does an ISO 9001 system need?
There's no fixed number. ISO 9001 requires documented information to support your processes — the quantity depends on your business size and complexity. Most small to medium businesses need between 10 and 30 core procedures.

Do ISO procedures need to follow a specific format?
No. ISO standards don't mandate a particular format or template. What matters is that your procedures are controlled, accessible, and actually used.

Can procedures be stored electronically?
Yes. Electronic document management is perfectly acceptable and often preferable. Just ensure version control and access controls are in place.

How often should ISO procedures be reviewed?
At minimum annually, or whenever a significant process change occurs. Document your review dates in the revision history.

What's the difference between a mandatory procedure and an optional one?
Some ISO standards explicitly require certain documented procedures. Others leave it to your judgement. Check your specific standard's requirements — or get a gap analysis done to identify exactly what's needed.

Can one procedure cover multiple processes?
Sometimes, but be careful. Combining too much into one document makes it harder to maintain and harder to follow. When in doubt, keep procedures focused on a single process.

Do work instructions need the same level of document control as procedures?
Yes. All documents within your management system should be controlled, regardless of type.

How do I know if my procedures are good enough for an audit?
The practical test: hand the procedure to someone unfamiliar with the process and ask them to follow it. If they can, it's probably good enough. If they can't, rewrite it before your auditor sees it.


Conclusion: Where to Go From Here

Writing solid ISO procedures isn't complicated, but it does require discipline. Follow the structure in this ISO procedure writing guide — purpose, scope, roles, steps, revision history — and you'll produce documents that satisfy auditors and actually help your team.

Your next steps:

  1. Identify your top five highest-risk processes and prioritise those for documentation
  2. Download or adapt a procedure template that matches your standard's requirements
  3. Interview the people doing the work before you write a single word
  4. Build a simple document control register — even a spreadsheet works
  5. Test every procedure with a real user before finalising it

If you'd like expert support rather than doing this alone, ISO Adviser works with businesses across the UK to build management systems that pass first time. From gap analysis through to full implementation support, the team has done this hundreds of times. You don't need to figure it out from scratch.

And if you're still working out which standard you need, start with our complete guide to ISO certification — it'll save you a lot of time.


ISO Procedure Completeness Checker

Tick each element as you complete it. See instantly whether your procedure is audit-ready — or what's still missing.

📋 Procedure Completeness Checklist
Document header (title, number, version, date, author)
Every procedure needs a unique document number and version so you can control it properly.
Required
Purpose statement (1–2 sentences, plain English)
Explains why this procedure exists. Auditors read this first.
Required
Scope (what's included and what's not)
Ambiguity about scope causes audit findings. Be specific about boundaries.
Required
Roles and responsibilities (job titles, not names)
Use job titles so the procedure stays valid when staff change.
Required
Numbered procedure steps in sequential order
Each step should be a single, clear action. Avoid combining multiple actions in one step.
Required
Revision history / version log
Shows what changed, when, and who approved it. Essential for document control.
Required
Approval signature / sign-off recorded
Auditors check that procedures have been formally approved by an authorised person.
Required
Related documents listed (forms, work instructions)
Links your procedure to supporting documents so nothing gets missed.
Recommended
Plain language test passed (non-expert can follow it)
Ask someone unfamiliar with the process to read it. If they're confused, rewrite before your auditor sees it.
Recommended
Review date set (at least annually)
Procedures without a review date become outdated. Set a calendar reminder.
Recommended
Progress 0 of 10 complete