ISO 9001 Documented Information: What You Must Keep
ISO 9001:2022 requires specific documented information to demonstrate that your Quality Management System (QMS) conforms to the standard and operates effectively. Many organisations struggle with two questions: what must I keep, and how much is enough? This guide answers both, with a clear breakdown of mandatory documents, mandatory records, document control requirements, and practical tips to avoid unnecessary paperwork.
One of the most common misconceptions about ISO 9001 is that every process must be documented in excessive detail. In reality, ISO 9001:2022 is designed to be flexible. It gives organisations the freedom to determine the level of documentation needed based on their size, complexity, and risk profile. The key is understanding the difference between maintained documented information (documents) and retained documented information (records).
What ISO 9001:2022 Says About Documented Information
ISO 9001:2022 uses the term ‘documented information’ to cover both documents (procedures, policies, plans) and records (evidence of activities). The standard distinguishes between two types:
- Maintained documented information – Documents that must be kept current, such as the quality policy, quality objectives, and scope of the QMS. These define what the organisation intends to do.
- Retained documented information – Records that must be preserved as evidence, such as training records, audit reports, and management review minutes. These prove that the organisation did what it said it would do.
Every time the standard says ‘maintain documented information’ you need a current document. Every time it says ‘retain documented information’ you need a record. Understanding this distinction is the foundation of ISO 9001 documentation.
Mandatory Documented Information for ISO 9001:2022
The following table lists every clause that explicitly requires documented information. If your QMS misses any of these, you will face a nonconformity during certification. These are not optional. They are the minimum documentation requirements of the standard.
| Clause | Requirement | Type | What It Should Contain |
|---|---|---|---|
| 4.3 | Scope of the QMS | Document | Boundaries of the QMS, exclusions and justification for each exclusion |
| 5.2 | Quality policy | Document | Appropriate to purpose, commitment to improvement, available to interested parties |
| 6.2 | Quality objectives | Document | Measurable objectives at relevant functions, what will be done, resources, responsible persons, deadlines |
| 7.1.6 | Organisational knowledge | Document | Knowledge necessary for process operation, how it is acquired, maintained and made available |
| 7.5 | Documented information control | Document | Process for identification, format, review, approval, storage, protection, distribution, and control of changes |
Mandatory Records for ISO 9001:2022
These records are explicitly required as retained documented information. They form the evidence base for your QMS and will be the primary focus of external certification audits. Each record must be identifiable, legible, stored, protected, retrievable, and retained for a defined period.
| Clause | Requirement | What It Provides Evidence Of | Suggested Retention Period |
|---|---|---|---|
| 7.1.5.1 | Calibration records (monitoring and measurement resources) | Equipment is fit for purpose, calibration traceable to international or national standards | Life of equipment + one audit cycle |
| 7.2 | Competence records | Personnel are competent; training, qualifications, and experience documented | Employment duration + one audit cycle |
| 8.2.3.2 | Contract review records | Customer requirements reviewed before acceptance; changes managed and communicated | Contract duration + one audit cycle |
| 8.3.2 | Design and development planning records | Design stages, reviews, responsibilities, and authorities planned | Product lifecycle |
| 8.3.3 | Design and development input records | Functional, performance, regulatory, and other design inputs documented | Product lifecycle |
| 8.3.4 | Design and development control records | Design reviews, verification, and validation activities conducted | Product lifecycle |
| 8.3.5 | Design and development output records | Outputs meet input requirements; approved before release | Product lifecycle |
| 8.3.6 | Design and development change records | Changes reviewed, verified, validated, and approved | Product lifecycle |
| 8.4.1 | External provider evaluation records | Suppliers evaluated, monitored, and re-evaluated based on their ability to provide conforming products | Supplier relationship + one audit cycle |
| 8.5.2 | Product/service identification and traceability records | Unique identification maintained when traceability is a requirement | As required by contract or regulation |
| 8.5.3 | Customer property records | Customer property identified, verified, protected; loss or damage reported | Contract duration + one audit cycle |
| 8.5.6 | Change control records | Changes to production or service provision reviewed and controlled | One audit cycle |
| 8.6 | Product/service release records | Acceptance criteria met; authorised release of product or service | Contract duration + regulatory requirements |
| 8.7 | Nonconforming output records | Nonconformities identified, controlled, and disposition actions taken | One audit cycle |
| 9.1.1 | Monitoring and measurement results records | QMS performance evidence; customer satisfaction data; process KPIs | One audit cycle |
| 9.2.2 | Internal audit programme and results records | Audit schedule, audit reports, nonconformities, corrective actions, closure evidence | One audit cycle |
| 9.3.3 | Management review records | Management review minutes, decisions, action items, resource allocations | One audit cycle |
| 10.2.2 | Nonconformity and corrective action records | Root cause analysis, corrective actions taken, effectiveness verification | One audit cycle |
Document Control Requirements
ISO 9001:2022 Clause 7.5.3 requires that documented information is controlled to ensure its availability, protection, and integrity. Document control is often a source of nonconformities for organisations new to ISO 9001. The following elements must be addressed in your document control procedure:
- Availability – Documents are available and suitable for use where and when they are needed
- Protection – Documents are protected from loss of confidentiality, improper use, or loss of integrity
- Review and approval – Documents are reviewed and approved for adequacy before issue
- Change and revision status – Changes and current revision status are identified
- Relevant versions – Relevant versions of applicable documents are available at points of use
- Legibility and identification – Documents remain legible and readily identifiable
- External documents – External documents (standards, customer specifications, regulations) are identified and controlled
- Obsolete documents – Obsolete documents are removed or otherwise identified to prevent unintended use
Record Control Requirements
Records are retained documented information that provides evidence of conformity. While document control focuses on keeping documents current, record control focuses on preserving evidence. Your QMS must define how records are managed across their entire lifecycle.
| Control Element | Requirement | Typical Implementation |
|---|---|---|
| Identification | Each record uniquely identified and traceable to its source process | Record numbering system, document code, date stamp, barcode or QR code |
| Storage | Records stored in a safe, accessible location | Secure filing cabinets, document management system (DMS), cloud storage with access controls |
| Protection | Records protected from damage, deterioration, or loss | Fireproof cabinets, offsite or cloud backups, antivirus protection, access restrictions |
| Retrieval | Records easily found when needed for audits or operations | Indexed filing system, searchable database, consistent folder structure, metadata tagging |
| Retention | Retention periods defined and applied consistently across the organisation | Retention schedule, automated archiving, disposal authorisation process |
| Disposition | Records disposed of securely at end of retention period | Shredding (paper), secure deletion (electronic), disposal log with approval |
Difference Between Mandatory Documentation and Optional Documentation
One of the most common mistakes in ISO 9001 implementation is creating excessive documentation that the standard does not actually require. The table above lists everything the standard explicitly mandates. Everything else is optional. Many organisations voluntarily document additional processes because it adds value. For example:
- Quality manual – Optional in ISO 9001:2022, but many organisations keep one for auditor and customer convenience
- Procedure for internal audit – Not explicitly required, but necessary to ensure consistent auditing
- Procedure for management review – Not explicitly required, but recommended for consistency
- Work instructions – Optional unless the absence of instruction would affect product or service conformity
- Process maps and flowcharts – Optional but valuable for training and process improvement
Tips for Minimising Documentation
One of the biggest myths about ISO 9001 is that you need hundreds of documents. The standard is designed to be flexible and risk-based. Use these strategies to keep your QMS documentation lean, practical, and value-adding:
- Combine documents – Use a single integrated manual instead of separate quality manual, procedure manual, and work instruction sets. An integrated management system (IMS) manual combining ISO 9001, ISO 14001, and ISO 45001 is even more efficient
- Use process maps – A well-designed flowchart replaces pages of text describing process steps, decision points, and responsibilities
- Adopt QMS software – A purpose-built platform handles document control, versioning, approval workflows, and access permissions automatically
- Only document what adds value – If a process is simple, consistently performed correctly, and the risk of failure is low, a documented procedure may not be needed
- Use existing records – Customer emails, system logs, meeting minutes, and project management tools often satisfy record requirements without creating new forms
- Review and simplify annually – Schedule an annual document review to remove redundant, outdated, or duplicated paperwork. Keep the system as lean as possible
- Train people, not paper – Invest in training so people understand processes. Documentation should support competence, not replace it
Frequently Asked Questions
Do I need an ISO 9001 quality manual?
ISO 9001:2022 no longer explicitly requires a quality manual. However, you must maintain documented information that defines the scope of the QMS and supports the operation of your processes. Many organisations keep a quality manual because it provides a convenient reference for auditors, customers, and employees, but it is not mandatory.
How long must ISO 9001 records be retained?
The standard does not specify minimum retention periods. Your organisation must determine retention based on product lifecycle, contractual requirements, regulatory obligations, and customer expectations. A common practice is to retain records for the current audit cycle plus one additional year.
Can documented information be electronic?
Yes. ISO 9001 does not require paper in any clause. Electronic documented information is fully acceptable as long as it is controlled, protected, retrievable, and legible. A cloud-based QMS with version control, access permissions, and backup satisfies all ISO 9001 requirements.
What is the difference between a procedure and a work instruction?
A procedure describes who does what, when, and the sequence of activities for a process. A work instruction provides detailed step-by-step guidance for a specific task or operation. ISO 9001 does not mandate either format; use what works for your organisation and your risk profile.
How often should documented information be reviewed?
At least annually. Review dates should be tracked, and documented information should be updated whenever processes, technology, regulations, or organisational structures change. A master document register with review dates helps manage this systematically.
Do I need to document every process in my QMS?
No. ISO 9001 requires documented information only where explicitly specified in the standard and where the absence of documentation could lead to nonconformities. Many processes can be managed through training, on-the-job guidance, checklists, or simple verbal instructions without formal documentation.
What happens if I do not maintain the required documented information?
Missing mandatory documented information is a nonconformity that will be raised during your certification audit. Depending on the severity, it can be classified as a major nonconformity (if the system cannot function without it) or a minor nonconformity (if it is an isolated gap).
Can I use templates for ISO 9001 documentation?
Yes, but you must customise them to your organisation. Generic templates that do not reflect your actual processes, products, and risks will result in nonconformities during audit. Templates are a starting point; tailoring is essential.
Get ISO 9001 Documentation Support
Building the right documented information for ISO 9001 certification does not have to be overwhelming. Bitrixme helps organisations across the Middle East create lean, audit-ready QMS documentation that meets the standard without unnecessary bureaucracy.
Our team provides complete documentation services including gap analysis, documentation development, document control system setup, and auditor training. We work with organisations in manufacturing, construction, healthcare, professional services, and logistics sectors.
Contact Bitrixme for ISO 9001 documentation services or message us on WhatsApp for a free consultation.