ISO 9001:2015 Clauses Explained ISO 9001:2015 has ten clauses. Only seven of them — Clauses 4 through 10 — actually contain requirements an auditor can score you against. The first three are scope, references, and definitions. No teeth, no findings, no evidence to produce.

That distinction matters because the Standard's language is deliberately generic. It has to work for a five-person job shop and a 3,000-person aerospace supplier using the same sentence. Which means quality managers and plant leads are left to translate abstract wording like "determine the interested parties relevant to the quality management system" into something a CNC operator or shipping clerk can actually do on a Tuesday.

This guide breaks down every clause in plain language, shows what it looks like on the floor, and flags where teams most commonly lose points during a certification or surveillance audit.

Key Takeaways

  • Clauses 1-3 are introductory; Clauses 4-10 hold every auditable requirement
  • Plan-Do-Check-Act drives Clauses 4-10, so the sequence isn't arbitrary
  • Clause 6 (Planning) generates more nonconformities than almost any other section
  • Documentation that looks complete on paper is the single biggest audit risk
  • Exclusions are limited and must be justified in the QMS scope — you can't skip clauses you don't like

The 10 Clauses of ISO 9001:2015 at a Glance

ISO 9001:2015 splits into two functional halves. Clauses 1 through 3 set the stage: they define what the Standard covers, point to related documents, and establish shared vocabulary. None of it gets audited.

Clauses 4 through 10 are where certification lives. This is the structure:

# Clause Title Contains Requirements?
1 Scope No
2 Normative References No
3 Terms and Definitions No
4 Context of the Organization Yes
5 Leadership Yes
6 Planning Yes
7 Support Yes
8 Operation Yes
9 Performance Evaluation Yes
10 Improvement Yes

Clauses 4–10 aren't just a checklist. They're built around the Plan-Do-Check-Act (PDCA) cycle:

  • Plan — Clauses 4, 5, and 6
  • Do — Clauses 7 and 8
  • Check — Clause 9
  • Act — Clause 10

That order isn't decorative. A company that jumps straight to Clause 8 (Operation) without the Clause 4 context work usually ends up with a QMS scope that doesn't match what the plant actually does. That mismatch shows up in almost every subsequent audit.

PDCA cycle mapped to ISO 9001 clauses 4 through 10

Clause 4: Context of the Organization and Clause 5: Leadership

These two clauses set the foundation. Skip them, and everything built afterward sits on soft ground.

Clause 4: Context of the Organization

Before you write a single procedure, Clause 4 requires you to figure out who has a stake in your QMS and what's happening around it. That means identifying:

  • Interested parties: customers, regulators, employees, suppliers, and anyone else whose requirements could affect quality outcomes
  • Internal and external issues: competitive pressure, workforce turnover, supplier concentration, regulatory shifts

From there, Clause 4.3 requires you to define your QMS scope: what's in, what's out, and why. A common exclusion for contract manufacturers is Clause 8.3 (Design and Development), claimed when the organization builds strictly to customer-supplied specs with zero design responsibility.

A vague scope statement here creates problems everywhere else. Auditors can't verify conformity against requirements you never clearly defined in the first place.

Clause 4.4 then asks you to map your key processes and how they interact. Turtle diagrams and flowcharts are popular tools for this, but they're optional formats. The requirement is understanding the interaction, not producing a specific diagram.

Clause 5: Leadership

Clause 5 puts direct accountability on top management, not a delegate or the quality manager alone. Auditors actively probe for engagement evidence:

  • Whether the plant manager can link the quality policy to a real decision made last quarter
  • Whether leadership can name a current quality objective without checking a binder

The Quality Policy (5.2) requirement trips up more companies than it should. A generic policy lifted from a template doesn't hold up. It needs to be specific enough to function as an actual reference point when priorities conflict, such as when a rush order threatens an inspection step.

Clause 5.3 covers roles, responsibilities, and authorities. This is where small manufacturers frequently stumble. When "everyone does everything," no one can clearly show during an audit who owns nonconforming material decisions or who's authorized to release a hold.

Clause 6: Planning and Clause 7: Support

If Clauses 4 and 5 are the foundation, Clauses 6 and 7 are where you decide what to build and make sure you have the tools to build it.

Clause 6: Planning

Clause 6.1 introduces risk-based thinking, and it scares people more than it should. There's no requirement for a formal risk matrix or software. What's required is identifying real threats (a key machinist nearing retirement, a single-source supplier for a critical component) and having a documented response.

This is also the clause where teams struggle most in practice. DNV's audit data from 2023-2025 shows that more than half of audited organizations had Clause 6 nonconformities, with 6.1 ranking as the second most common finding across all of ISO 9001.

The recurring pattern is familiar: risk registers built in a spreadsheet, disconnected from actual operations, with no clear owner tracking whether the response actually worked.

Clause 6.2 covers Quality Objectives. There's a real difference between:

  • ❌ "Maintain customer satisfaction" — vague, unmeasurable
  • ✅ "Reduce customer returns from 2.1% to under 1.5% by Q3, tracked monthly against existing shipping data" — specific, tied to numbers you already collect

Vague versus SMART ISO 9001 quality objective comparison example

Clause 6.3 rounds this out with planning of changes: thinking through consequences before swapping a supplier, altering a process, or bringing in new equipment.

Clause 7: Support

Clause 7.1 covers resources, including organizational knowledge: the requirement to protect expertise instead of letting it live in one veteran employee's head with no backup.

Competence (7.2) goes further than most companies treat it. A training certificate isn't proof of competence; it's proof of attendance. Real evidence looks at outcomes. Track scrap rates on a CNC line before and after operator training, for example, to confirm the training changed performance instead of just checking a box.

Awareness (7.3) and communication (7.4) matter too, but most audit pain shows up in competence and control of documents.

Clause 7.5, documented information, is the Standard's term for document and record control. Version confusion (outdated work instructions still floating on a shop floor) is still one of the findings teams report most often.

Clause 8: Operation — The Largest and Most Audited Clause

Clause 8 covers what your organization actually produces or delivers day to day. It's the biggest clause in the Standard, and it's usually where auditors spend the most time.

Operational planning and control (8.1) requires you to plan, implement, and control the processes needed to meet requirements — including process criteria, acceptance of outputs, resources, and control of planned changes.

Products and services (8.2) starts with contract review — confirming tolerances, specs, and customer requirements before committing to a job. Skipping this step is how companies end up building to an outdated print.

Design and development (8.3) is the most commonly excluded sub-clause for contract manufacturers. But the line isn't always clean.

According to ISO's Auditing Practices Group guidance, outsourcing design work to someone else doesn't automatically justify claiming 8.3 doesn't apply. Auditors are directed to verify who actually defines the product characteristics before accepting that exclusion.

External providers (8.4) covers supplier evaluation, approved supplier lists, and incoming inspection. An approved supplier list alone isn't sufficient evidence; auditors expect to see the selection criteria, ongoing performance monitoring, and risk-based controls behind it.

The remaining sub-clauses round out day-to-day operations:

  • 8.5 — Production and service provision (process controls, validation, identification and traceability, preservation)
  • 8.6 — Release of products and services (verify requirements are met before release to the customer)
  • 8.7 — Control of nonconforming outputs, including disposition decisions and retained records

Clause 8 Operation sub-clauses breakdown from 8.1 to 8.7

Clause 9: Performance Evaluation and Clause 10: Improvement

This is the "Check" and "Act" half of PDCA: where you find out if the system is actually working and fix what isn't.

Clause 9: Performance Evaluation

Customer satisfaction monitoring (9.1) doesn't require a formal survey program. Most companies already have legitimate evidence sitting in an ERP system:

  • Delivery performance
  • Complaint trends
  • Repeat business

Internal audit (9.2) and management review (9.3) catch drift before a registrar does. The most common gap is internal audits that check whether paperwork exists but never verify what's happening on the floor.

An auditor who checks a training record without watching the operator work the process is missing the point of the requirement entirely.

Clause 10: Improvement

Nonconformity and Corrective Action (10.2) is where root cause discipline matters most. According to NQA's guidance on managing nonconformities, ineffective corrective action is one of the most common reasons assessors raise major nonconformities.

Repeat findings almost always trace back to a correction that addressed the symptom (a bad part reworked) without ever fixing the process that produced it.

Continual Improvement (10.3) ties audit results, data analysis, and corrective actions together into a working loop rather than a stack of static documents nobody revisits between surveillance visits.

From Clause Knowledge to Audit-Ready Capability

Reading these clauses and understanding them isn't the same as applying them when an auditor asks a follow-up question you didn't prepare for. Most teams pass their training modules and still freeze the moment a real nonconformity or an unexpected finding lands on the table.

The highest-value habit is periodically walking each clause and asking one question: is this functioning, or just documented? Surveillance audit failures rarely stem from a missing procedure. They stem from a procedure that looks complete while daily practice has quietly drifted away from it.

This is the exact gap QMS Learning's General Manufacturing Quality pathway was built to close. It includes:

  • A 16-hour ISO 9001 Internal Auditor course on every clause, the process approach, risk-based thinking, and ISO 19011, built around 27 interactive scenarios
  • Root Cause Analysis & CAPA training on 5-Why, fishbone, and fault-tree methods through verification and closure
  • Internal Audit Program Management and Management Review courses that treat those functions as operating systems
  • An AI Workbench that diagnoses the problem behind a nonconformity and routes it to the right method

The platform was built by founder Will Trikha, who spent 20 years writing over 1,000 audit findings and closing roughly twice that number as a quality manager. That background shows up in how the Workbench handles real scenarios. A recurring supplier defect, for example, is treated as a systemic issue needing 5-Why analysis plus supplier CAPA, not a one-off fix.

QMS Learning AI Workbench interface diagnosing nonconformity root cause

Teams get evidence compiled into a single, indexed Audit-Evidence Package PDF, ready for registrar handoff instead of a last-minute scramble before surveillance.

Frequently Asked Questions

What are the 10 clauses of ISO 9001?

The 10 clauses are: Scope, Normative References, Terms and Definitions, Context of the Organization, Leadership, Planning, Support, Operation, Performance Evaluation, and Improvement. Only Clauses 4 through 10 contain requirements an auditor can score.

Which ISO 9001 clauses are mandatory for certification?

Clauses 4 through 10 are mandatory unless a specific requirement is formally justified as not applicable and documented in the QMS scope. The most common exclusion is Clause 8.3 for organizations with no design responsibility.

Can you exclude any ISO 9001 clauses?

Exclusions apply only to specific requirements within Clause 8 that genuinely don't fit your operations, not entire clauses. Every exclusion must be documented and justified in the QMS scope statement.

What is the difference between an ISO 9001 clause and a sub-clause?

A main clause, like Clause 8, represents a broad requirement category. Sub-clauses, like 8.3 or 8.4, break that category into specific, individually auditable requirements.

How is the ISO 9001 clause structure related to the PDCA cycle?

Plan maps to Clauses 4 through 6, Do maps to Clauses 7 and 8, Check maps to Clause 9, and Act maps to Clause 10. This is the exact grouping ISO uses in the Standard's own structure.

What's the biggest mistake companies make when implementing the ISO 9001 clauses?

Documenting a clause correctly but never operating it day to day. Auditors are trained to probe exactly that gap during surveillance audits, which is why paper compliance rarely survives a second or third visit.