ISO 9001:2015 names surprisingly few mandatory documents. The standard requires a defined scope, a quality policy, quality objectives, and the records that prove your processes ran. Everything else falls under one phrase — "documented information" — that the standard leaves you to interpret.
That gap between what the standard names and what an auditor expects is where most first certifications go wrong. This article lists the documents the standard explicitly requires, the records auditors ask for by name, and the working document set a small manufacturer needs to pass a Stage 2 audit.
Documents ISO 9001:2015 explicitly requires
The 2015 revision dropped the old mandatory "quality manual" and six required procedures from ISO 9001:2008. What remains as explicitly required documented information is short:
| Document | Clause | What the auditor checks |
|---|---|---|
| Scope of the QMS | 4.3 | Boundaries and justification for any requirement you claim does not apply |
| Quality policy | 5.2 | Signed, communicated, and understood on the floor — auditors ask operators about it |
| Quality objectives | 6.2 | Measurable, tracked, and tied to a plan for reaching them |
| Operational process criteria | 8.1 | Evidence your production processes run to defined criteria |
If that short list were the whole story, nobody would fail an audit on documentation. The rest of the standard requires retaining documented information as evidence — records — in more than twenty places.
Records the standard requires you to retain
These are records, not procedures: proof that something happened. An auditor samples them. Missing records in any of these areas is a finding, and missing records in management review (9.3) or corrective action (10.2) at Stage 1 is routinely treated as a major nonconformity trigger.
- Monitoring and measuring equipment calibration records — clause 7.1.5.1
- Competence records: training, education, experience — clause 7.2
- Process operation criteria evidence — clause 8.1
- Review of requirements for products and services — clause 8.2.3.2
- Design and development records: inputs, controls, outputs, changes — clauses 8.3.3 to 8.3.6
- External provider (supplier) evaluation records — clause 8.4.1
- Traceability records where required — clause 8.5.2
- Customer property records — clause 8.5.3
- Change control records for production — clause 8.5.6
- Product release records, including who released — clause 8.6
- Nonconforming output records and actions taken — clause 8.7.2
- Monitoring and measurement results — clause 9.1.1
- Internal audit programme and results — clause 9.2.2
- Management review inputs and outputs — clause 9.3.3
- Nonconformity and corrective action records — clause 10.2.2
Documents auditors expect even though the standard does not name them
A registrar can audit you against exactly what the standard says. In practice, Stage 1 auditors ask for a documented system they can navigate. A pile of records with no procedures behind them makes every audit question slower and every answer harder to defend.
- A quality manual or equivalent top-level document — no longer mandatory, still the map auditors navigate by
- Documented procedures for the processes where an undocumented mistake costs you: control of documents and records, internal audit, corrective action, nonconforming output, supplier management
- Work instructions where operator judgment alone cannot guarantee the outcome
- Forms that make the required records happen: audit checklists, NCR forms, management review agendas, training matrices
The working set: what a complete small-manufacturer QMS looks like
A documentation set that passes audit without drowning a 10-50 person shop is built in four tiers — how many documents depends on the company, from a couple of dozen to well over a thousand:
| Tier | What it holds | Examples |
|---|---|---|
| Manuals and policies | The few documents that frame the system | Quality manual, quality policy, objectives framework, context and scope document |
| Procedures | One per process that must run the same way every time | Document control, internal audit, corrective action, nonconforming output, supplier management, calibration, training, design control |
| Work instructions | Only where step-level wording matters | Step-level instructions for the operations where wording matters: inspection, release, equipment setup, handling |
| Forms and records templates | What people fill in; completed forms become records | NCR form, audit checklist, management review minutes template, training matrix, supplier evaluation form |
The counts flex with your scope — a design-exempt shop drops the design control tier, a distributor drops most work instructions. What does not flex is the structure: policies say what you commit to, procedures say who does what and when, work instructions say exactly how, and forms capture the proof.
Three ways to produce the set
- Write it yourself. Free, and the deepest way to learn the standard. Budget 150-300 hours of someone senior, spread over months, and expect the auditor to find the sections written at 11 pm.
- Buy a template pack. $300-$2,000. Fast to acquire, slow to make true: every generic sentence that does not match how your shop runs is a finding waiting for a Stage 2 auditor to read it aloud.
- Generate it from your operations. This is what ISO Delivered does: a structured questionnaire about how your shop runs day to day, then the full document set written from those answers — $8,000 flat, typically 2–4 weeks after a complete intake.
Whichever route you take, the test is the same: hand any procedure to the person named in it and ask whether it describes what they really do. If it does not, an auditor will discover that faster than you can.
Sources
- ISO 9001:2015 — Quality management systems — Requirements, International Organization for Standardization.
Frequently asked questions
Is a quality manual mandatory for ISO 9001:2015?
No. The 2015 revision removed the mandatory quality manual. Most certified companies keep one anyway because it gives auditors and customers a single navigable summary of the QMS, and many registrars still ask for one at Stage 1.
Does ISO 9001:2015 name a long mandatory document list?
No. The 2015 revision names a short set of documented information — scope, quality policy, quality objectives, and process criteria — plus records in many clauses. A working system still needs procedures and forms because records only exist when processes produce them. The size of that working set depends on the operation.
Can I get certified with just the mandatory documents?
In theory the standard allows it. In practice a Stage 2 audit samples your records, and records only exist when working procedures produce them. Companies that skip procedures fail on evidence, not paperwork.
How long does it take to create ISO 9001 documentation?
Writing from scratch typically takes 150-300 senior hours over 3-6 months. Template packs are faster to buy but need heavy editing to match your operations. Generated documentation built from a structured questionnaire is typically 2–4 weeks after a complete intake. Certification itself then needs about 3 months of operating records.