← Back to Blog

Compliance

ISO 9001 SOP Requirements: Documented Information, Procedures & Records

| 10 min read

ISO 9001 is the world's most widely used quality management standard, and teams often assume it demands a mountain of policies and procedures. The 2015 revision went the opposite direction: it removed the requirement for a formal quality manual and a mandated set of six documented procedures, replacing them with a flexible concept called "documented information." That flexibility is good news — but it also confuses teams about what they actually have to write down.

Here's the practical answer. ISO 9001 requires some documented information explicitly, requires you to keep certain records, and expects you to decide what additional procedures and SOPs your operations genuinely need. This guide walks through exactly which documents are mandatory, which procedures most teams still write, and how to keep the whole system from going stale.

The Shift: From Six Procedures to "Documented Information"

Earlier versions of ISO 9001 listed six procedures you had to document: control of documents, control of records, internal audit, control of nonconforming product, corrective action, and preventive action. The 2015 revision scrapped that prescriptive list. Instead, clause 7.5 says the organization shall maintain the documented information required by the standard and the documented information it determines is necessary for the effectiveness of its quality management system (QMS).

In plain terms: the standard tells you what must exist, and it trusts you to decide how much procedure you need to run your processes consistently. Many teams still find it useful to document roughly the same six areas, but now you can size the documentation to your operation rather than writing boilerplate to check a box.

Documented Information ISO 9001 Explicitly Requires

Even under the flexible model, the standard names specific documented information you must maintain or retain. You're not free to skip these:

Notice the pattern: the mandatory items are mostly records — evidence that you ran the system. The procedures, on the other hand, are largely up to you, which is exactly why smart teams document the actual workflows they run.

The Procedures Most Teams Still Document

Even without the old mandated list, a workable QMS needs operating procedures for the core things the standard keeps pointing at. In practice these are your SOPs — step-by-step instructions for the processes that keep quality intact:

These five are rarely optional in practice — auditors consistently probe them — and they map cleanly to documented procedures most teams can produce quickly.

How to Document Your ISO 9001 Procedures Without Writing Them by Hand

The painful part of an ISO 9001 implementation is not the policy documents — it's the operational procedures, which describe how people actually do the work: how an order gets processed, how a defect gets logged, how a document gets through review. These are the SOPs that go stale the fastest because they describe live processes that change.

Recording the workflow while you do it is far more reliable than reconstructing it from memory. For any browser-based process — quality checks in a portal, order entry, complaint handling, audit evidence — a click-by-click recording captures the exact steps, the exact screens, and the exact navigation. It produces a step-accurate procedure in the time it takes to actually run the task, instead of an hour of writing and screenshotting.

Keep Records and Procedures Local and Current

ISO 9001 records can be sensitive — inspection results, nonconformity reports, audit findings, corrective actions. When you document these processes, where the records live matters. A privacy-first, local-first tool keeps your quality procedures and their evidence on your own devices rather than uploading sensitive QMS material to a third-party server. For a quality team handling inspection and customer data under a certification scope, that control is a real advantage.

Currency is the other half. A QMS full of stale SOPs is an audit finding waiting to happen. Assign an owner to each procedure, review on a regular cadence, and fold process capture into the work so procedures reflect what you actually do — not what you wrote a year ago.

Build your QMS procedures from real workflows

Claudia records your browser workflows locally and exports AI-readable SOPs your team and auditors can follow — nothing leaves your machine.

Add to Chrome

FAQ: ISO 9001 SOP Requirements

Does ISO 9001 still require a quality manual?

No. The 2015 revision removed the requirement for a formal quality manual. You must maintain documented information defining the scope of the QMS and supporting other clauses, but you are free to structure it as policies, procedures, and records rather than a single manual.

Are the six documented procedures still mandatory?

No — the 2015 standard dropped the mandated list of six procedures. In practice most teams still document document control, records control, internal audit, nonconforming output, and corrective action because auditors consistently review them. But the scope is sized to your operation.

What is the difference between a document and a record in ISO 9001?

A document tells you how to do something (a procedure, an SOP, a policy). A record is evidence that it was done (an audit report, an inspection log, a corrective action entry). Both are "documented information," but records are what auditors use to prove your QMS actually ran.

How long must ISO 9001 records be kept?

ISO 9001 does not set a fixed retention period; it requires you to determine retention yourself based on the record's purpose and any legal or customer requirements. Document your retention decisions and apply them consistently.

Can I record ISO 9001 procedures instead of writing them?

Yes. Recording the real workflow produces a step-accurate procedure faster and it stays current because re-recording is trivial when a process changes. A local recorder keeps sensitive QMS material from being exposed to a third-party server. See how this fits automated compliance documentation.

Related Articles

Build a QMS that stays current

Claudia records your browser workflows locally and exports SKILL.md files automatically. No writing, no AI subscription, no cloud upload.

Add to Chrome