iso-9001-design-development

By July 25th, 2026ISO Audit And Certificate9 min read

ISO 9001 Design and Development: Requirements and Process

Organisations that design and develop products or services must comply with clause 8.3 of ISO 9001:2015. This clause sets out the requirements for a controlled design and development process, from initial planning through to final verification and validation. Whether you manufacture physical products, develop software, or design services, clause 8.3 applies whenever your organisation creates new or modified offerings. This guide walks you through each requirement and shows you how to build a compliant design process within your Quality Management System (QMS).

What Is Clause 8.3 Design and Development?

Clause 8.3 of ISO 9001:2015 is titled “Design and development of products and services.” It applies when your organisation is responsible for designing something new or modifying an existing design. The clause does not apply if you simply produce products to an existing design provided by a customer or if you deliver services exactly as specified without any design input from your side.

The clause is structured into seven sub-clauses that represent the design lifecycle:

  1. 8.3.1 General
  2. 8.3.2 Design and development planning
  3. 8.3.3 Design and development inputs
  4. 8.3.4 Design and development controls
  5. 8.3.5 Design and development outputs
  6. 8.3.6 Design and development changes

Design and Development Planning (8.3.2)

Planning is the foundation of an effective design process. Your organisation must determine:

  • The stages of design and development: Define the phases your project will follow, from concept to launch.
  • Review, verification, and validation activities: Specify what checks will occur at each stage and who is responsible.
  • Authorities and responsibilities: Assign clear ownership for each design activity and decision point.
  • Internal and external resources: Identify the people, equipment, and information needed to complete the design.
  • Control of interfaces: Define how different teams, departments, or external parties will co-ordinate during the design process.
  • Customer and user involvement: Plan how and when customers or end users will contribute to the design.
  • Level of control: Determine the degree of control needed for each design stage based on risk.

The output of the planning stage is a design and development plan. This can be a standalone document or part of a project plan, but it must be maintained and updated as the design progresses.

Design Inputs (8.3.3)

Design inputs define what the design must achieve. You must determine the requirements that are essential for the specific type of product or service being designed. Complete and unambiguous inputs prevent costly rework later.

Input CategoryExamplesSource
Functional requirementsPerformance specifications, capacity limits, speed targetsCustomer brief, market research
Regulatory and legal requirementsIndustry standards, safety regulations, environmental complianceRegulatory bodies, legal team
Customer requirementsSpecific features, delivery expectations, usability criteriaCustomer contract, specifications
Organisational requirementsInternal standards, branding guidelines, cost targetsQMS, management review
Resource constraintsBudget limits, available technology, timeline restrictionsProject charter, feasibility study
Previous design knowledgeLessons learned from past projects, known failure modesDesign history, corrective actions

All design inputs must be documented, reviewed for adequacy, and approved. Contradictory or ambiguous inputs must be resolved before the design proceeds.

Design Controls (8.3.4)

Clause 8.3.4 requires you to apply controls to the design and development process to ensure that:

  • The results to be achieved are defined.
  • Reviews are conducted to evaluate the design’s ability to meet requirements.
  • Verification activities confirm that design outputs meet design inputs.
  • Validation activities confirm that the resulting product or service meets the intended use or application.
  • Any necessary actions are taken on problems identified during reviews, verification, or validation.

Design Review

Design reviews are formal evaluations at appropriate stages. Their purpose is to assess whether the design is on track to meet requirements and to identify any problems. Reviews should involve relevant stakeholders, including representatives from different functions and, where appropriate, customers or suppliers. Outcomes and actions must be documented.

Design Verification

Verification answers the question: “Did we design it correctly?” It ensures that the design outputs match the design inputs. Methods include design reviews, calculations, simulations, prototypes, and comparison with similar proven designs.

Design Validation

Validation answers the question: “Does the design meet the user’s needs?” It is typically performed under defined operating conditions on the final product or service. Validation should be completed before delivery wherever possible. If full validation cannot be completed before delivery, the scope of validation must be justified and documented.

VerificationValidation
Question answeredDid we build it right?Did we build the right thing?
FocusCompliance with specificationsSuitability for intended use
When performedThroughout design stagesTypically at or near completion
MethodsCalculations, simulations, inspectionsUser testing, pilot runs, field trials
ExampleA bridge design calculation matches the load specificationThe bridge carries actual traffic safely

Design Outputs (8.3.5)

Design outputs are the results of the design process. They must:

  • Meet the design input requirements.
  • Be adequate for subsequent processes (production, service delivery, monitoring, etc.).
  • Include or reference acceptance criteria.
  • Specify the characteristics of the product or service that are essential for its safe and proper use.
  • Be documented and approved before release.

Examples of design outputs include drawings, specifications, bill of materials, software architecture documents, service scripts, recipes, and user manuals.

Design Changes (8.3.6)

Changes to designs are inevitable. Clause 8.3.6 requires that:

  • Design changes are identified and documented.
  • Changes are reviewed, verified, and validated as appropriate.
  • The review includes evaluation of the impact of changes on already-delivered components and on the overall product or service.
  • Records of design changes, reviews, and authorisations are maintained.

The level of control for changes should be proportionate to the risk. A minor cosmetic change may require only a documented approval, while a change to a safety-critical feature demands full re-verification and re-validation.

Documenting Your Design Process

Your QMS must retain documented information to demonstrate that the design and development process has been followed. Key records include:

RecordRequired by ClausePurpose
Design and development plan8.3.2Documents stages, responsibilities, and control activities
Design inputs8.3.3Records requirements that the design must satisfy
Design review records8.3.4Evidence of evaluation and action on problems
Verification records8.3.4Evidence that outputs meet inputs
Validation records8.3.4Evidence that the product or service meets user needs
Design outputs8.3.5Approved specifications for production or delivery
Change records8.3.6Documentation of changes, reviews, and approvals

Common Nonconformities in Design and Development

Auditors frequently flag the following issues during certification audits:

  • No design plan: Organisations skip planning and jump straight into development, leaving no documented evidence that stages, reviews, and responsibilities were defined.
  • Incomplete design inputs: Regulatory or legal requirements are missed, or customer requirements are captured informally via email without formal review and approval.
  • No distinction between verification and validation: Organisations treat them as the same activity. Remember: verification checks against specifications; validation checks against user needs.
  • Uncontrolled design changes: Engineers modify designs without documented review, approval, or impact assessment.
  • Poor records: Design reviews take place but are not documented, or the minutes do not note decisions and follow-up actions.

Frequently Asked Questions

Does ISO 9001 clause 8.3 apply to service design?

Yes. Clause 8.3 applies to both products and services. If your organisation designs new services (e.g. a consulting package, a training programme, a logistics solution) or modifies existing ones, you must apply the requirements of 8.3. Service design outputs might include scripts, workflows, service level definitions, or customer journey maps.

Can I skip design and development if I use an existing design?

If you produce a product or service exactly to a design provided by a customer or a third party, and you have no design responsibility, clause 8.3 may not apply. However, if you make any modifications to the design, or if you are responsible for designing any part of the product or service, the clause applies to that scope of design activity.

How detailed should my design plan be?

Your design plan should be proportionate to the complexity and risk of the project. A simple design might have a one-page plan with three stages and a single review. A complex, multi-year product development project requires a detailed plan with stage gates, verification milestones, and clearly assigned authorities. The key is that the plan is sufficient to control the process effectively.

What is the difference between design review, verification, and validation?

A design review is a formal evaluation at a stage of the design process to assess results and identify problems. Verification checks that design outputs meet the design inputs (e.g. a specification matches a calculation). Validation checks that the final product or service meets the needs of the intended user (e.g. the customer confirms the product works in their environment). All three are required but serve different purposes and occur at different points in the process.

How do I handle design changes after production has started?

Post-production design changes must still follow the control process in clause 8.3.6. The change must be identified, reviewed, verified, validated as appropriate, and approved. The review must consider the impact on the already-produced items and on the production process itself. Document all changes and maintain records of authorisation.

Can design verification be done by the same person who created the design?

ISO 9001 does not explicitly prohibit this, but best practice is to have verification performed by someone independent of the design activity. Independence reduces the risk of overlooking errors. For small organisations where independence is difficult, you can use alternative methods such as peer reviews, structured walkthroughs, or automated verification tools.

How Bitrixme Can Help

Implementing a compliant design and development process within your QMS can be challenging, especially if you are new to ISO 9001 or your organisation handles complex design projects. Bitrixme provides ISO 9001 consulting services across Bahrain and the Middle East, helping organisations design processes that satisfy auditors and improve business outcomes.

We can assist with gap analysis, process documentation, internal auditing, and certification support. Our consultants understand both the standard and the practical realities of product and service design.

Contact Bitrixme today to discuss your ISO 9001 design and development needs. You can also message us directly on WhatsApp for a prompt response.