ISO Documentation Requirements: What Documents Do You Need?

By July 25th, 2026ISO Audit And Certificate9 min read

ISO Documentation Requirements: What Documents Do You Need?

Every ISO management system standard requires specific documented information, but the amount and type vary by standard. The term “documented information” covers both documents (policies, procedures, plans) and records (evidence of activity). Understanding what is mandatory, what is optional and what your certification body auditor expects is the difference between manageable documentation and an over-engineered system.

Published: July 2026  |  Last updated: July 2026  |  Author: Bitrixme Compliance Team

Mandatory Documents by Standard

Each standard specifies the documented information it requires. The following table lists the mandatory documents and records for the most common certifiable ISO standards. Everything beyond this list is optional, though most organisations add documents that make their system practical to operate and audit.

Document or RecordISO 9001ISO 27001ISO 14001ISO 45001ISO 22000
Scope of the management systemYesYesYesYesYes
Quality / security / environmental / OH&S / food safety policyYesYesYesYesYes
Objectives and plans to achieve themYesYesYesYesYes
Criteria for evaluation and selection of suppliersYesN/AN/AN/AYes
Risk assessment and risk treatment methodologyN/AYesYesYesYes
Statement of Applicability (Annex A controls)N/AYesN/AN/AN/A
Information security risk treatment planN/AYesN/AN/AN/A
Legal and other requirements registerN/AYesYesYesYes
Competence records (training, skills, experience)YesYesYesYesYes
Documented information of external origin determined as necessaryYesYesYesYesYes
Evidence of communicationYesYesYesYesYes
Operational planning and control recordsYesYesYesYesYes
Monitoring and measurement recordsYesYesYesYesYes
Internal audit programme and resultsYesYesYesYesYes
Management review minutesYesYesYesYesYes
Nonconformity and corrective action recordsYesYesYesYesYes
HACCP plan and hazard analysisN/AN/AN/AN/AYes
Prerequisite programme documentationN/AN/AN/AN/AYes
Incident and emergency response recordsN/AN/AYesYesYes
Emergency drill and test recordsN/AN/AYesYesYes

The table shows that most mandatory documentation is common across standards, particularly in the management system clauses (4 to 10). The standard-specific additions appear in the operational clauses and the subject-specific requirements such as Annex A for ISO 27001 or HACCP for ISO 22000. When implementing multiple standards, the common documents can be shared, reducing the total documentation volume significantly.

Document Control Procedures

Document control is the process that ensures your documented information is current, approved and available where needed. Every standard requires the organisation to control its documented information, but the standard does not prescribe how. The level of formality should match the organisation’s size and complexity.

  • Approval. Documents are reviewed and approved before issue by a person authorised to do so. The approval authority depends on the document type: a work instruction may need only the process owner’s approval, while the quality policy requires top management approval.
  • Identification. Each document has a unique identifier, a version number, an effective date and a title. The identification system should be simple enough that any staff member can locate the correct version.
  • Review and update. Documents are reviewed periodically and updated when process changes occur. The review cycle should be defined in the document control procedure itself.
  • Change control. Changes to documents are approved and recorded. A change history log at the end of each document shows what changed, when and by whom.
  • Availability. Current versions of documents are available at points of use. Obsolete versions are removed or clearly marked as obsolete if retained for legal or knowledge purposes.
  • External documents. Documents of external origin, such as standards, regulations and customer specifications, are identified, controlled and checked for current revision status.
  1. Write only what the standard requires and what your organisation needs. The standards explicitly state where documented information is mandatory. If the standard says “the organisation shall retain documented information,” it is mandatory. If it says “the organisation may retain documented information,” it is optional. Do not add documents that serve no operational purpose.
  2. Use your existing documents where possible. Many organisations already have policies, procedures and records for business reasons. If they already exist and meet the standard’s requirements, adopt them. Creating entirely new documents duplicates effort and creates confusion about which version of a process description is current.
  3. Keep language simple. A procedure written in plain language that operators can follow is more effective than a procedure written in formal compliance language that only auditors can interpret. ISO standards themselves encourage the use of plain language in documentation.
  4. Integrate documentation across standards. If you are implementing multiple standards, integrate the documentation into a single set of policies and procedures where the requirements overlap. A single document control procedure, internal audit procedure and management review procedure can serve ISO 9001, ISO 14001 and ISO 45001 simultaneously.
  5. Review and prune documentation annually. Documentation should be reviewed at least annually to remove obsolete documents, consolidate overlapping ones and simplify those that have become over-complicated. A documentation review can be part of the management review process.
  6. Use templates and examples. Starting from a proven template reduces development time and ensures coverage of the required elements. Many certification bodies and industry associations provide document templates for common management system documents. Adapting a template is faster and more reliable than creating a document from scratch.
  7. Train document authors. The people who write procedures and work instructions need guidance on what good documentation looks like. A half-day training session on document writing, covering structure, language, version control and the distinction between documents and records, pays for itself many times by reducing review cycles and rework.
  • Writing a quality manual because “everyone does it.” ISO 9001:2015 does not require a quality manual. Neither do ISO 27001:2022, ISO 14001:2015 or ISO 45001:2018. The manual was mandatory in earlier versions of the standards but is now optional. Certify your system without one if you prefer.
  • Creating procedures that mirror the standard’s clause structure. A procedure titled “Context of the Organisation” that simply restates clause 4 adds no value. Write procedures that describe how your organisation operates, not how the standard is structured.
  • Documenting processes that do not exist. Creating documentation for an ideal future state rather than documenting current practice creates a gap between what the documents say and what people do. The auditor will find this during the Stage 1 audit.
  • Over-controlling documents in a small organisation. A two-person quality team does not need a formal document control committee and a five-step approval workflow. Document control should be proportionate to the organisation’s size and risk profile.
  • Treating records retention as an afterthought. Records must be retained for defined periods, protected from loss or alteration and disposed of appropriately. Failure to demonstrate systematic records management is a common finding in certification audits. A document retention schedule that specifies retention periods by record type, approved disposal methods and the responsible owner should be established before the certification audit.
  • Failing to identify external documents. Standards, regulations, customer specifications and industry codes are external documents that must be controlled. Many organisations overlook this category entirely.

How many documents does ISO 9001 actually require?

ISO 9001:2015 requires documented information for the scope, quality policy, quality objectives, evidence of competence, records of operational processes, monitoring and measurement records, internal audit records, management review minutes and nonconformity records. Beyond these mandatory items, the organisation decides what additional documentation is needed to operate effectively.

Do we need a quality manual for ISO 9001?

No. The 2015 revision removed the requirement for a quality manual. Many organisations continue to maintain one because it is a convenient reference document, but it is not mandatory. If you do create one, keep it brief and focused on describing the scope of the management system and the interaction between processes.

What is the difference between a procedure and a work instruction?

A procedure describes a process at the level of who does what, in what sequence and with what criteria. A work instruction provides step-by-step guidance for a specific task within that process. Not every procedure needs a corresponding work instruction; work instructions should be created only when the complexity of the task requires detailed guidance.

How long must ISO records be retained?

The standard requires records to be retained for documented retention periods defined by the organisation, regulatory requirements and contractual obligations. Common practice is to retain certification-related records for at least the current certification cycle (three years) plus the current year. Regulatory requirements may impose longer periods, such as six years for VAT records in Saudi Arabia.

Can documentation be electronic?

Yes. The standards are technology-neutral. Electronic documentation is acceptable and increasingly preferred over paper. The organisation must control electronic documents as effectively as paper ones, including access control, version control, backup and protection against unauthorised changes. Most certification bodies accept an electronic document management system as evidence of document control.

Do we need to rewrite all our documents for the new ISO standard version?

Not necessarily. When a standard is revised, the organisation must review its documented information for alignment with the new requirements. Some documents may need updates, but a complete rewrite is rarely necessary. The transition period provided by the certification body and accreditation framework typically allows 12 to 36 months for transition. The key is to review each document against the new clause requirements and update only those that contain gaps or outdated references, rather than assuming every document needs revision.

Need help building your ISO documentation? Our consultants can develop your documentation, set up your document control system and train your team. Contact us at bitrixme.com/contact or message us on WhatsApp.