One of the most common surprises when opening up the ISO 9001:2015 text is discovering how much less documentation it requires than most people expect. The 2015 revision replaced the rigid requirement for "documented procedures" with a more flexible concept: documented information, defined in clause 7.5.
The real change: from "mandatory procedure" to "whatever your company needs"
Earlier versions of the standard required several documented procedures by name. The 2015 version scrapped that fixed list and instead requires the organization to maintain whatever documentation it needs to ensure its own system's effectiveness — which gives a lot more freedom, but also raises questions about what's actually mandatory.
What the standard does require by name
- The scope of the management system.
- The quality policy.
- The quality objectives and the plan to achieve them.
- Evidence of the competence of staff relevant to their role.
- The results of the management review.
- Evidence of the results of monitoring and measurement (indicators, equipment calibration).
- The internal audit program and its results.
- Evidence of non-conformities found and the corrective actions taken.
- Criteria for evaluating external suppliers and evidence of that evaluation.
What's up to each company
Beyond that list, the standard leaves it to each organization to decide what additional procedures, work instructions, or records it needs for its system to work well — depending on company size, process complexity, staff competence, and the risk associated with what it does. A factory with complex technical processes will need more documented work instructions than a professional services firm with simple processes.
How to decide what to document, without overdoing it or falling short
- Ask yourself whether, without that document, someone new to the role could do the job right the first time. If the answer is no, you probably need to document it.
- Avoid documenting processes that already work fine informally just "because it looks good" for the audit — unnecessary red tape is one of the main reasons people end up rejecting the system.
- Prioritize records that prove the system works over time (training, indicators, non-conformities) over procedures that describe how it should work in theory.
A common mistake: confusing "less documentation" with "no control"
The fact that the standard has relaxed the documentation requirement doesn't mean it's less demanding about actual control. Quite the opposite: by not giving you a fixed template to fill in, it forces you to genuinely think through what your company needs to work well — which, done properly, tends to produce systems that are more useful and less "for show" than under the previous version of the standard.
The minimum structure, already set up for your company
EcoNiora comes with all the mandatory ISO 9001 and ISO 14001 documentation already structured into modules — you just need to fill it in with your company's reality, by hand or with the AI's help.
Request access →