← All postsHow-to

ISO 9001: what the standard requires that a competent company is not already doing

Most of ISO 9001 describes how a well-run company already works. The gap is usually in evidence, ownership and the parts that repeat on a schedule.

How-toI

ISO 9001 is the international standard for quality management systems. It does not say how to make your product; it says that you should understand what your customers require, plan how to deliver it, control the processes that do, measure whether they worked, and improve where they did not — and that you should be able to show all of this.

For a company that already works competently, the standard rarely demands new activity. It demands that existing activity be assigned, recorded and repeated on a schedule. That is why the gap between "we do this" and "we can show we do this" is where certification projects actually spend their time.

The ISO 9001 requirements that most often need building

  • Context and interested parties: who your requirements come from, written down rather than assumed.
  • Process ownership: a named person for each significant process, with authority to change it.
  • Documented information under control: current versions, approvals, and review dates that have not passed.
  • Risk-based thinking: risks and opportunities identified and acted on — no separate risk register is required, but the thinking has to be visible.
  • Internal audits: a programme covering the system over time, performed by people independent of the area.
  • Management review: a meeting with the inputs the standard lists and minutes that record decisions.
  • Nonconformity and corrective action with evidence of effectiveness.

Internal audit and management review are the two that get scheduled and then quietly skipped, and they are also the two an auditor checks first — because both leave an unmistakable record when they happen and an equally unmistakable gap when they do not.

Documented information: less than people expect

The 2015 revision removed the requirement for a quality manual and for six mandatory procedures. What remains is the requirement to keep the documented information necessary for the effectiveness of the system, plus the specific records the standard names. Companies that build a large document set are usually re-creating an older version of the standard, or copying a template from a much larger organisation.

A procedure nobody follows is worse than none. If the written process and the real process differ, an auditor has evidence that the system is not being operated — and the honest fix is usually to rewrite the document to match what the competent version of the work actually looks like.

A realistic route to certification

  1. Define the scope, and be precise about what is excluded and why.
  2. Map the processes that deliver the product or service, with owners.
  3. Fill the gaps in documented information — current versions, approvals, records that the standard names.
  4. Run at least one full cycle of internal audits, and act on what they find.
  5. Hold a management review with the required inputs, and minute the decisions.
  6. Fix the findings, then invite the certification body for stage 1.

Because the standard is largely about documented information being current, approved and findable, the document layer is where most of the practical work lives. Ettex Docs keeps procedures with their approvals, revision history and review dates, so an auditor’s question about which version was in force in April is a property of the document. Everything the documents describe — the processes, the audits, the corrective action — still has to be done by the organisation, and no tool substitutes for that.

Whether it is worth it

The honest answer depends on why you are doing it. If customers or tenders require the certificate, the decision is made. If the motivation is internal improvement, the standard is a reasonable checklist but an expensive one, and much of the benefit is available by adopting the parts that matter — process ownership, internal audit, management review — without the certificate.

Frequently asked

Is a quality manual still required by ISO 9001?

No. The 2015 revision removed that requirement, along with the six mandatory documented procedures. Many organisations keep a short manual anyway because it is a convenient index.

How long does ISO 9001 certification take?

Typically three to nine months for a small organisation, driven mostly by the need to complete a cycle of internal audits and at least one management review before the stage 2 audit.

What is the difference between ISO 9000 and ISO 9001?

ISO 9000 sets out the vocabulary and principles; ISO 9001 contains the requirements you can be certified against. ISO 9004 gives guidance on going further than the requirements.

Can a service company be certified?

Yes. The standard is deliberately sector-neutral; the requirements apply to the processes that deliver whatever you provide, product or service.

IP
Written by Ivan P.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.