Quality Management Systems — Requirements
Specifies requirements for a quality management system for organisations that need to demonstrate the ability to consistently provide products and services that meet customer and applicable statutory/regulatory requirements.
What this does not cover
stated in the document's own scope- Is a general QMS standard; it does not carry the medical-device regulatory requirements of ISO 13485 or the food-safety requirements of ISO 22000.
- Certifies the management system, not a product — it does not verify that any specific product meets a technical standard.
- Emphasises customer satisfaction and continual improvement rather than regulatory compliance, which is the focus of the sector QMS standards derived from it.
- Confers no market authorisation or legal approval; certification is a voluntary conformity assessment by an accredited body.
Always verify against the current published text before relying on it for a submission or inspection.
Overview
ISO 9001:2015 specifies the requirements for a quality management system for any organisation that needs to demonstrate its ability to consistently provide products and services meeting customer and applicable statutory and regulatory requirements, and that aims to enhance customer satisfaction. It is built on the ISO high-level structure and on seven quality-management principles — customer focus, leadership, engagement of people, process approach, improvement, evidence-based decision-making, and relationship management. The 2015 edition introduced risk-based thinking, greater emphasis on organisational context and interested parties, and leadership accountability, while relaxing the former prescriptive requirement for a quality manual and documented procedures.
Scope & applicability
Any organisation regardless of size, type, or product. In pharmaceutical context, ISO 9001 is the baseline QMS framework upon which ICH Q10 pharmaceutical-specific requirements are built.
Legal basis & how it acquires force
ISO 9001 is a voluntary international consensus standard; it is not law and confers no regulatory approval. Its force comes from adoption — by organisations that choose to certify, and by customers or authorities who require it contractually or in procurement. It underpins many sector-specific QMS standards that are themselves adopted into regulation (ISO 13485 for medical devices, IATF 16949 for automotive, AS9100 for aerospace), which is where ISO 9001’s architecture acquires regulatory weight. Certification is issued by accredited certification bodies, not by ISO itself.
Document structure
| Part | Covers |
|---|---|
| Clause 4 — Context of the organization | Understanding the organisation and its interested parties, and determining the scope and processes of the QMS |
| Clause 5 — Leadership | Leadership and commitment, the quality policy, and organisational roles, responsibilities, and authorities |
| Clause 6 — Planning | Actions to address risks and opportunities, quality objectives, and planning of changes |
| Clause 7 — Support | Resources, competence, awareness, communication, and documented information |
| Clause 8 — Operation | Operational planning, requirements for products and services, design and development, control of external providers, production, and control of nonconforming outputs |
| Clauses 9–10 — Performance evaluation and improvement | Monitoring, analysis, internal audit, management review, nonconformity and corrective action, and continual improvement |
Key requirements
- Context of the organisation — internal and external issues, interested parties
- Risk-based thinking — identification and treatment of risks throughout QMS
- Process approach — understanding and management of interrelated processes
- PDCA cycle — continual improvement through plan-do-check-act
- Performance evaluation — internal audit, management review, KPIs
Revision notes
2015 revision was last major update. Introduced risk-based thinking and context of the organisation. Replaces ISO 9001:2008.
Where this control fails
live FDA enforcementLive FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
International alignment
ISO 9001 uses the ISO high-level structure (Annex SL) shared with ISO 14001, ISO 45001, and ISO 22000, so those systems integrate cleanly. It is the parent framework for sector QMS standards — ISO 13485 (medical devices), IATF 16949 (automotive), and AS9100 (aerospace) — each of which adapts the ISO 9001 architecture to regulated or high-reliability sectors, some of which are then referenced by regulators.
ISO 9001:2015: frequently asked questions
Quick answers to common questions about ISO 9001:2015.
What changed in ISO 9001:2015?
The 2015 edition adopted the ISO high-level structure, introduced risk-based thinking, and added emphasis on organisational context, interested parties, and leadership. It removed the mandatory quality manual and prescriptive documented procedures, replacing them with "documented information" the organisation determines it needs.
Is ISO 9001 mandatory?
No. It is a voluntary standard. Organisations adopt it by choice or because a customer, contract, or procurement process requires it. Its architecture does gain regulatory weight indirectly through sector standards derived from it, such as ISO 13485.
What is the relationship between ISO 9001 and ISO 13485?
ISO 13485 is a medical-device QMS standard built on the ISO 9001 architecture but focused on regulatory compliance and device safety rather than continual improvement and customer satisfaction. They share structure but are separate, separately certified standards.
This standard in practice
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.