ISO 9001 Documents List: What You Actually Need

Home/ISO 9001/Documents list

ISO 9001 documents list: what you actually need

Four named documents, one catch all clause and eighteen records. No quality manual, no six procedures, no thousand page binder. Here is the full list with clause numbers, updated for the 2026 edition, and a checklist you can tick as you go.

Updated 25 September 20269 minute readAxora Global

Open the checklistAsk about your gaps

What the standard actually asks for

4
documents you write once and keep current
18
records you keep as evidence of what happened
1
catch all clause for process information, 4.4.2
0
procedures the standard forces you to write

Some items apply only if the activity applies to you, for example design and development or calibration.

In short

  • ISO 9001 names four documents you must maintain: the scope of your quality management system, the quality policy, the quality objectives, and your criteria for selecting suppliers.
  • It also expects eighteen kinds of record, which are simply evidence that the work was done: audits, reviews, training, calibration, releases, corrective actions and the rest.
  • Clause 4.4.2 is the catch all. It asks for whatever process information your people need to do the job properly, which is why two companies can both comply with very different folders.
  • There is no mandatory quality manual and no mandatory procedure. Those came from the 1994 and 2008 editions and have not been required since 2015.
  • The 2026 edition does not add a new list of mandatory documents. It changes what your existing records have to show, especially around risk, change and climate.

The first thing to get right

Document or record, and how to tell them apart

Since 2015 the standard stopped using the words “document” and “record”. Everything is now documented information, which is why so many teams overbuild. The distinction still exists, it just hides in the wording of each requirement, and the new Annex A in the 2026 edition finally spells the rule out.

Phrase one “shall be available as documented information”

This is a document. Something you write, approve and keep current, like your scope statement or your quality policy. It describes intent, and it lives in the present tense.

Phrase two “documented information shall be available as evidence of”

This is a record. Something produced by the work itself, like a calibration certificate, an audit report or a signed release note. It proves the past, so it is never edited, only filed.

Keep that split in your head and the whole standard becomes easier. Documents are few and you write them. Records are many and your processes create them for you. If you find yourself writing a record by hand at the end of the month, your process is not producing its own evidence, and that is the real problem to fix.

The full list

Every document and record ISO 9001 asks for

Tick what you already have. Nothing is saved or sent anywhere, so use it as a working list on screen or print it for a walkthrough. Clause numbers follow the current structure, which the 2026 edition keeps.

0 of 23 in place Start ticking to see where you stand.

Documents you maintain

five items

Records you keep

eighteen items

That is the whole mandatory set. If your folder structure has fifty controlled documents and you are a twenty person firm, the extra forty five are your choice, not the standard’s requirement, and every one of them has to be kept current. Fewer documents and better records is almost always the stronger system. Our 24 point self assessment is a quick way to see whether the rest of your system is carrying its weight.

Scope matters

The items that only apply if the activity applies

Several requirements above are conditional. If you do not do the activity, you do not need the record, but you should be able to say why in your scope statement rather than leaving a silent gap.

RequirementYou need it whenYou can leave it out when
Design and development, clause 8.3You define what the product or service is, from a brief or your own ideaYou build strictly to a customer drawing or a fixed recipe with no design input of your own
Calibration, clause 7.1.5.2Measurement is used to prove conformity, for example dimensions, weight, temperatureYou take no measurements that decide acceptance, which is rare in manufacturing and common in some services
Traceability, clause 8.5.2A customer, a regulator or your own recall plan requires itNothing external requires it and you do not rely on it internally
Customer property, clause 8.5.3You hold material, tooling, data or premises belonging to a customer or supplierNothing of theirs is ever in your control, including their data
Post delivery activities, clause 8.5.5You provide warranty, maintenance, installation or recycling obligationsYour responsibility genuinely ends at delivery, which is worth checking against your contracts

Exclusions are allowed, but only where the requirement does not affect your ability to deliver a conforming product or service. Write the reason into the scope, keep it to two lines, and expect the auditor to test it.

Stop building these

What ISO 9001 does not require

A quality manual

Not required since 2015. Many firms keep a short one because customers ask for it or because it helps new staff. That is a business decision, not a certification requirement.

The six documented procedures

Document control, records, internal audit, nonconforming product, corrective and preventive action. That was the 2008 edition. You still do these activities, you just do not have to write a procedure for each one.

A management representative

The role disappeared in 2015. Responsibilities must be assigned and understood, but no single title is imposed and top management cannot delegate its own accountability.

Special software

A shared drive with version control in the file name beats an expensive system nobody updates. The requirement is control, not a licence.

Paper copies

Electronic records are fine, including photographs, scans and system logs, as long as they are protected, legible and retrievable for as long as you say you keep them.

A fixed retention period

The standard sets no number of years. You set the period, based on contracts, law and how long the product or service stays in use, then you follow your own rule.

The new edition

What the 2026 edition changes for your documents

ISO 9001:2026 was published on 16 September 2026. It does not hand you a longer list of mandatory documents, and clause 7.5 on documented information is substantially the same. What changes is what your existing records have to show. Our full guide to the 2026 changes covers the transition itself.

Clause 4.1, 4.2
Climate change has to appear in your context review

You must decide whether climate change is a relevant issue for your organisation, and whether interested parties have climate related requirements. Deciding that it is not relevant is acceptable. Not having considered it is not. Add a line to your context record.

Clause 6.1
Risks and opportunities are handled separately

The clause splits them, so a single combined register now reads as a gap. Give opportunities their own columns, with their own actions and their own review of whether the action worked.

Clause 6.3
Change planning needs more evidence

Alongside purpose, integrity, resources and responsibilities, your change record should now show how the change was communicated, how it was monitored, and what the review of its effectiveness concluded.

Clause 5.1, 7.3
Quality culture and ethical behaviour become auditable

Top management has to promote them, and your people have to be aware of them. The practical effect is small: induction material, awareness sessions and management review discussion that goes past the numbers.

Clause 7.1.6
Organisational knowledge covers the whole system

It is no longer limited to the knowledge needed to make the product. Know how that keeps the management system itself running counts too, which matters when one person holds all of it.

Annex A
A guidance annex, for the first time

Annex A explains intent and terminology, including the document and record wording above. It is informative, so a certification body cannot raise a finding against it, but it will shape how auditors are trained.

Certificates issued against the 2015 edition stay valid through the transition, which the certification bodies describe as three years from publication. Confirm the exact date with your own body before you plan the work, because the accreditation rules are what fix it.

Clause 7.5

Controlling what you have

Having the documents is half of it. Clause 7.5.2 and 7.5.3 ask that they are created properly and controlled afterwards. Six practical tests cover almost every finding we see.

Identification

Title, date, author or owner, and a reference number. A file called final_v3_new is not identification.

Review and approval

Someone with authority approved it before use, and you can show who and when.

Availability

The current version is where the work happens, in a language and format the user can actually read.

Protection

Backed up, access controlled, and safe from accidental edits. Records in particular must not be changeable after the fact.

Version control

Superseded copies are removed or marked. Old forms circulating on the floor are a classic finding.

External documents

Standards, customer drawings and regulations that you rely on are identified and kept current, because they change without telling you.

The question everyone asks

How long do you keep records

ISO 9001 gives no number. You decide, you write the period into your own retention rule, and then the auditor holds you to your own rule rather than to a figure in the standard. Four things should drive the decision.

  1. Contract and customer requirementsMany buyers, especially in aerospace, automotive, pharmaceutical and export supply chains, state a retention period in the purchase agreement. That period wins.
  2. Law and regulationTax, employment, product safety and environmental rules in your country set minimums for certain records. Check these before choosing a shorter period.
  3. The life of the product or serviceIf your product is in use for ten years, records that could matter in a complaint or a recall should still exist in year ten.
  4. The certification cycleA certification cycle runs three years. Records of audits, management reviews and corrective actions from the current cycle should be retrievable at every visit, so treat three years as a practical floor for system records.

Write the periods into a single retention table, keep it on one page, and apply it. A table that says seven years while the server was cleared last spring is worse than a table that says three years and is true.

On the ground

What auditors in Pakistan ask for first

Stage one of a certification audit is largely a document review. Most of it happens before anyone looks at your floor, and the pattern is consistent across bodies operating here.

The scope, then the gaps

Your scope statement is read first, then the auditor looks for the processes it implies and asks for the records those processes should have produced.

Evidence with dates on it

Internal audit reports, management review outputs and corrective actions with a visible closing date. A system certified on paper but started last month shows up immediately here.

Documents that match reality

The fastest finding of all is a procedure that describes a process nobody follows. Where the two differ, change the document, not the answer.

If you are preparing for a first certification, our guide to ISO certification in Pakistan sets out the full path, and the ISO 9001 certification service page explains how we run a gap review before the documents are written. If you want your own people to read a system the way an auditor does, the ISO 9001 lead auditor course is the route most teams take.

If you are starting

The order to build them in

Writing documents in the order the standard lists them is the slowest way to do this. Build in the order that lets each piece feed the next.

  1. ScopeDecide what is in and what is out. Everything after this depends on it, and it takes an hour.
  2. Process mapList your processes and their sequence on one page. This is the backbone of clause 4.4 and the catch all document.
  3. Context, risks and opportunitiesTwo lists, kept separate under the 2026 wording, with climate change considered and an action against anything significant.
  4. Quality policyShort, signed, tied to your strategic direction and readable by the people who have to follow it.
  5. Quality objectivesThree to five that matter, each with an owner, a measure and a date.
  6. Operational documentsOnly the work instructions and forms your people actually need. Every form you create is a record you then have to keep.
  7. Supplier criteriaOne matrix, applied before approval, with a place to store the results.
  8. Run the systemLet it produce records for at least two or three months. Records cannot be backdated and auditors know what a system with no history looks like.
  9. Internal auditAudit every process once against the standard and against what your own documents claim.
  10. Management reviewTake the audit results, the quality data and the customer feedback into a review that ends in decisions, then fix what it finds before the certification body arrives.

Most small and medium firms in Pakistan can reach this point in a few months of steady work. The blocker is rarely the documents. It is finding someone who owns the system after the consultant leaves, which is the same point our post on why a growing business needs a QMS makes.

Questions

Common questions about ISO 9001 documents

How many documents does ISO 9001 require?

Four named documents, plus process information under clause 4.4.2, plus eighteen kinds of record. Twenty three items in total, and several of the records only apply if you carry out the activity, such as design or calibration.

Is a quality manual mandatory for ISO 9001?

No. The requirement for a quality manual was removed in the 2015 edition and the 2026 edition does not bring it back. You can keep one if customers ask for it or if it helps new staff, but no certification body can raise a finding for not having one.

What are the mandatory procedures in ISO 9001?

There are none. The six documented procedures belonged to the 2008 edition. You still have to control documents, run internal audits and handle nonconformities, but how you describe those activities is your choice.

What is the difference between a document and a record?

A document states intent and is kept current, such as your quality policy. A record proves something happened and is never edited afterwards, such as an audit report. In the 2026 wording, “shall be available as documented information” points to a document, while “documented information shall be available as evidence of” points to a record.

Does ISO 9001:2026 require new documents?

It does not add a new list. It changes what existing records must show: climate change considered in your context, risks and opportunities handled separately, more evidence around planned changes, and awareness of quality culture and ethical behaviour.

How long do we have to keep ISO 9001 records?

The standard sets no period. You define it yourself using contract requirements, the law, the life of the product and the three year certification cycle, then apply your own rule consistently.

Can our records be electronic only?

Yes. Electronic records, photographs, scans and system logs are all acceptable, provided they are protected from unauthorised change, backed up, legible and retrievable for the whole retention period.

What are documents of external origin?

Anything you rely on but did not write: the standard itself, customer drawings and specifications, regulations, supplier manuals. You must identify them and make sure the version in use is current, because they are updated without warning you.

Can we buy a template pack and be ready?

A template saves typing, not thinking. A purchased manual that describes a business other than yours is the single most common cause of findings at stage one, because the documents and the floor do not match. Use templates as a starting structure, then rewrite them around how your people actually work.

Sources

  • ISO, ISO 9001:2026 what businesses need to know, iso.org, September 2026
  • ISO 9001:2026, sixth edition, published 16 September 2026, iso.org catalogue
  • Advisera 9001Academy, list of mandatory documents required by ISO 9001
  • Oxebridge Quality Resources, ISO FDIS 9001:2026 full review, on the Annex A wording for documents and records
  • 9001Simplified, next ISO 9001 revision and required documents guide
  • Certification body transition notes from DNV, SGS and LRQA on the three year transition

Next step

Not sure which of these you are missing

Send us your current document list, or nothing at all if you are starting from zero. We will tell you what is genuinely required for your scope, what you can delete, and what has to change before an auditor sees it. The first conversation costs nothing.

Request a gap reviewSee our ISO training

We work with clients across Pakistan, including Lahore, Karachi and Islamabad.

Comments are closed.