ISO 9001:2008 Procedures—6 Mandatory Procedures

Updated on March 7, 2018
LeanMan profile image

I am a trainer and consultant in lean manufacturing, Six Sigma, quality management, and business management.

ISO 9001 Standard and Quality Procedures

ISO 9001:2008 is an international standard that defines the requirements for a quality management system, the system by which your company can ensure that all of your processes are controlled and repeatable to ensure the quality of your products and services.

Your processes are normally controlled through the presence of and the audit of written quality ISO9001 procedures which define what has to be done. ISO 9001:2008 defines best practice for each process within your organization to ensure control, however it only defines 6 mandatory procedures that you must have;

6 Mandatory procedures for ISO9001:2008

  1. Control of Documents (4.2.3)
  2. Control of Records (4.2.4)
  3. Internal Audits (8.2.2)
  4. Control of Non-Conforming Products (8.3)
  5. Corrective Action (8.5.2)
  6. Preventive Action (8.5.3)

ISO 9001 Procedure Flowchart

Procedures ISO 9001
Procedures ISO 9001 | Source
Flowchart Procedure ISO 9001
Flowchart Procedure ISO 9001 | Source

What is a Quality Procedure

A procedure is a statement of what will be done, when it will be done, and by whom. It is a set of instructions and intent that anyone in the company can follow (Not a top secret company document for management eyes only as one quality manager once told me!)  It is a specific way to carry out a process, a set of clear instructions that the staff can refer to help them understand and conduct their daily work in an efficient and repeatable manner.

ISO 9001 says that only certain requirements within your quality management system have to have a documented procedure, other procedure requirements depend on the size and complexity of the processes and the overall system as well as the competence of the staff.

Simple ISO 9001 Procedure

ISO 9001 Procedure
ISO 9001 Procedure | Source
Flow Chart ISO 9001 Procedures vs Word Documents
Flow Chart ISO 9001 Procedures vs Word Documents | Source

Writing an ISO 9001 Procedure

An ISO 9001 procedure does not have to be a hundred page document telling the individual how and when to pick up a pen, check that there is ink of the correct hue before forming letters in the specifically highlighted box on form no.XYZ. Too many people and organizations over-complicate their ISO 9001 procedures.

If you split your procedures and work instructions, then the procedures themselves can be very simple, remember that they only have to contain the right amount of information for the people doing the job to do it efficiently and in the best proscribed way. If your people are of high quality, well trained, experienced, or the process is very simple and obvious then there may be no need for a procedure at all.

I prefer to use simple flow charts to create procedures, use software such as Visio in the office suite of programs. They need to be just a simple step by step instructions saying what is to be done, then the next step in the sequence. They do not have to be overly complex.

For work instruction level, there is also the opportunity to clarify the process using things like photographs to highlight and clarify specific things.

Far too many organizations go over the top with regard to their ISO 9001 procedures, thinking that the weight of their procedure manual is a reflection of the effectiveness of their system. Too many, too complicated procedures just lead to confusion and the likely hood that the system will never be read and followed.

ISO 9001 Procedures Video

Mandatory ISO 9001 Procedures

Within ISO 9001 there are only six procedures that are mandatory, you must document these six. This does not mean that you can get away with just these six, the procedures you need will very much depend on the size and complexity of your organization, these six however are the ones that you must have.

The 6 mandatory ISO 9001 Procedures;

4.2.3 Control Of Documents

A written procedure to control the approval and re-approval of procedures prior to issue as well as ensuring that the current revision status is displayed. To ensure that documents are legible and that the current versions are available at point of use. Also ensure that obsolete documents are controlled and documents from external parties such as your customers.

4.2.4 Control of Records

A procedure to control the identification, storage, protection, retrieval, retention and disposal of records.

8.2.2 Internal Audits

A procedure to define a planned program of audits to ensure that your processes meet both ISO 9001 requirements and your own requirements. Also for the reporting, follow up and records of these audits.

8.3 Control of Non-conforming Product

A procedure to ensure that non-conforming product is not used and action is taken.

8.5.2 Corrective Action

A written procedure to ensure that the root causes of problems are identified and actions taken to correct them, actions must be verified to ensure effectiveness

8.5.3 Preventive Action

A written procedure similar to that for corrective action, but the organization should take steps to identify POTENTIAL problems and eliminate them before a problem occurs.

Implementing ISO 9001 Procedures

Quality procedure structure

A procedure can come in many different forms, it can be an overview of a process stating purely what is to be done, by whom and when or it can be specific detailed instructions. Most companies try to separate the two levels of documentation for the sake of clarity, having procedures and then standard operating instructions, work instructions, or other detailed documents at a lower “local” level in the system with the detailed “how to” instructions.

A procedure should detail out a few simple sections before the actual detail of what the procedure actually is, so that you can maintain control of the specific procedure;

Scope; What is the area covered by the procedure, i.e. Incoming delivery of consumable items, not including intercompany items.”

Responsibility; Who is the owner and responsible person for this procedure, after all, these are process specific documents so the quality manager is not responsible for approving and creating the purchasing procedures for example, that would be the place of the head of purchasing!

Control or Issue; What is the issue date, approval, etc. You have to maintain control of your procedures, they need to be approved, people must be able to be sure that this is the current revision etc.

References or Related Documents; List out the other documents and forms that may be related and relevant to this procedure.

After these sections would come the actual body of the procedure;

Generic off the shelf procedures

If you are going to develop your ISO 9001 quality management system procedures you might want to consider an alternative to producing everything from scratch. There are many systems that you can buy that have generic procedures and forms already designed and formatted. By entering your company name and other information they can create basic documents that meet the requirements of ISO 9001.

These systems are OK as a starting point to save you the effort of designing from nothing, they will also ensure that you cover all ISO 9001 procedural requirements including the mandatory procedures. Most consultants experienced in installing ISO 9001 systems will use something like this, either a purchased package or something home made.

Beware of companies that advertise to create all of your procedures and provide you with a certificate to say that you meet the requirements of ISO 9001, many of these companies are scams and the certificates are worthless. Unless they are registered with UKAS (link below) then they are not an accredited body that can issue an ISO 9001 certificate.

Additional Help With Your Procedures

The following are some useful links that will help you gain additional information regarding the ISO 9000 standards;

International Organization for Standardization; ISO website where you can find out about other international standards and monitor changes and developments in the standards.

Lloyds Register Quality Assurance; Lloyds Register Quality Assurance is about the oldest of the certification bodies in existence, they can audit your procedures as well as offer training and other services.

British Standards Institute; British Standards Institute is another well established certification body operating globally, they too can offer certification audits and training to help you implement your ISO 9001:2008 procedures.

The American Standards Organization; (ANSI) American Standards Organization can help you implement your ISO 9001 procedures in much the same way as Lloyds and BSI above.

International Register of Certified Auditors (IRCA); The International Register of Certified Auditors is where you go to check the qualifications of an individual trainer or auditor.

UKAS; The United Kingdom Accreditation Service is responsible for accrediting the certification bodies to be able to conduct ISO 9001 audits. They have a list of all accredited bodies that are able to provide valid ISO 9001 certification of your ISO 9001 procedures.

Chartered Quality Institute (CQI); The Chartered Quality Institute (Formerly the Institute of Quality Assurance.) They are able to provide much support in all quality related areas, if you are a quality professional I would recommend membership.

American Society for Quality (ASQ); The American society for quality can help you in the same way as the CQI can help you in the UK.

The above links can help with ISO 9000 Standards, ISO 9001, ISO 9004, Certification, auditing, Training, quality management systems, procedures, continuous quality improvement, etc.

Questions & Answers


      0 of 8192 characters used
      Post Comment

      • LeanMan profile image

        Tony 24 months ago from At the Gemba

        Hi Nani, if you really have no idea about what to do with your procedures you are best off getting help from someone local to you. Hire a consultant or visit another local company that already has ISO to see what they do and what they have.

      • profile image

        Nani 2 years ago

        Thank you for your reply. And one more doubt last auditor informed me to add mandatory procedures ( purchase, marketing,quality, production and two more totally 6 procedures ) how can i added this procedures. please reply soon.

      • profile image

        JOSH 2 years ago

        For the six elements described above, how would provide evidence for an auditor to demonstrate compliance?

        Could you let me know, Thanks

      • profile image

        Mastermind Bhavesh 2 years ago

        Thanks. Very informative

      • LeanMan profile image

        Tony 2 years ago from At the Gemba

        Hi Nani,

        Just write the procedure as you would any other procedure in your company according to your own procedures for writing and numbering procedures. As to what the procedure content should be that is down to what your company wants to include.

      • profile image

        Nani 2 years ago

        i want to include current welding procedure and special process validation welding procedure with ( qualification, personal qualification and katiria) how i do it? please help me.

      • LeanMan profile image

        Tony 2 years ago from At the Gemba

        Zil, it all depends in what your local procedure says you should do. It is the local procedure that is going to say what should be done with the list and when.

      • profile image

        zil 2 years ago

        i have one question to ask. You are a new clerk at faculty. every week you have to consolidate the attendance list. should the attendance list be filed as per standard procedure? or should be kept in the instructor's drawer?

      • LeanMan profile image

        Tony 2 years ago from At the Gemba

        Attendance lists for what Zil? There are no specific requirements for attendance lists for anything within ISO9001, I think you are talking about a company specific procedure and you will have to look at what the company is doing and why they are doing it. Often procedures are made purely for the sake of making procedures and are unnecessary.

      • profile image

        Zil 2 years ago

        Should the attendance lists be filled as per standard procedure? or should it kept in the instructor drawer? if yes why?

      • LeanMan profile image

        Tony 2 years ago from At the Gemba


        The answer is that it depends if they are needed to actually achieve the job. For most companies they have company wide procedures that cover every project that is run within the business. However if there are specifics about the project that need to be handled differently then there may be a need for project specific procedures - but only if actually required to ensure that the project runs smoothly.

      • profile image

        Prakash 2 years ago

        We are working on a project. Mandatory procedures are available in Company's corporate procedures. But not specific to the project. In this case, Please let me know "Whether Project specific Procedures are required?

      • LeanMan profile image

        Tony 3 years ago from At the Gemba

        Hi Kris, what you call a procedure is up to you - SOP or procedure - as long as you have fully documented your approach to the six mandatory clauses it is fine. However talk to your auditing body before your document review stage as some auditors can be a little "funny" about things!

      • profile image

        kris 3 years ago

        can we substitute quality procedures with SOP? ours is a pharma company and follows the GMP norms. From the ISO auditors point of view is QP mandatory! what i infer from net is that SOP if comprehensive can be Valid. please throw some light ,would appreciate

      • LeanMan profile image

        Tony 3 years ago from At the Gemba

        Thank you for Auditing and finding the error Ahmad Khan, slip of the finger I guess. Corrected in the list.

      • profile image

        Confused 3 years ago

        Control of Documents (4.2.3)

        Control of Records (8.2.4)

        Internal Audits (8.2.2)

        Control of Non-Conforming Products (8.3)

        Corrective Action (8.5.2)

        Preventive Action (8.5.3)

        In which have one wrong reference #....

        Control of Record correct reference is 4.2.4

        Ahmad Khan

      • LeanMan profile image

        Tony 4 years ago from At the Gemba

        Hi Davis,

        A procedure is very much what will be done and by whom, if the details of how it will be done are slightly different between companies this can be covered in a "lower level" work instruction specific to the individual company if written procedures are really necessary.

      • profile image

        Davis 4 years ago

        Hi LeanMan

        I'm just wondering, how to approach procedure/policy for departments (accounting, administration, finance, HR) that are shared by 2 or more companies?


      • profile image

        thirumaran 4 years ago

        Thanks for sharing the procedure of ISO 9001

      • LeanMan profile image

        Tony 4 years ago from At the Gemba

        Hi Ghana,

        Good luck on your procedures, let us know how you do with passing your ISO9001

      • profile image

        Zeesan 4 years ago

        thanks Sir Mr. LeanMan you sheared free information thanks again keep it up

      • LeanMan profile image

        Tony 4 years ago from At the Gemba

        Faraz, I think you need to have a read of the standard and the various hubs here so that you understand why what you have asked is of no use to you at all. Your procedures are specific to your processes not a different company. You can buy ready made procedures but you still have to work hard to adapt them to match your specific processes.

      • profile image

        Faraz 4 years ago

        I need ISO 9001:2008 Quality procedure sample for a Power Management Company at my email address at

      • LeanMan profile image

        Tony 5 years ago from At the Gemba

        Hi Harpal

        All procedures, instructions, manuals etc are specific to your own company and situation. Each has to be developed for your unique situation. Read the standards and bring in help in the form of a consultant if you need it.

      • profile image

        harpal 5 years ago

        Dear sir,

        i want the QUALITY MANUAL ,WORK INTRUCTIONS & SEFETY INSTRUCTION 9001&14000 so please send the detail regarding that,




        9215137313 __email

      • LeanMan profile image

        Tony 5 years ago from At the Gemba

        It would be difficult to advise without fully understanding the purpose and scope of what you require. I would suggest that you contact similar companies to yourself and see what they have or even speak to a consultant local to you.

      • profile image

        michael Mukopi 5 years ago

        Great information for better society. I have a question;

        I need to prepare a procedure on cascading responsibility and authority, kindly advise or share with me a sample to guide me.



      • LeanMan profile image

        Tony 5 years ago from At the Gemba

        Hi Gesso,

        This is one article in a whole series of articles, if you follow the various links within the text you will be able to find out much more about ISO 9001 in general and about writing procedures. If you need more information feel free to email using the "contact" button on my profile page (click the link beside my picture top right.)

      • profile image

        gesso 5 years ago

        documented procedures,quality objectives, please give ideas how prepare them. thank you in advance

      • profile image

        Meerambi 7 years ago

        Thank you so much LEanMAn.. You have explained about ISO (9001:2008) in a very simple and understandable way. Thanks for sharing it :)

      • LeanMan profile image

        Tony 7 years ago from At the Gemba

        Thank you for your kind comments about ISO 9001 procedures Jeddex.

      • jeddex profile image

        jeddex 7 years ago

        Great Hub LEanMAn! You've discussed things well. Your article is very informative especially regarding the six mandatory procedures. :)

      • LeanMan profile image

        Tony 7 years ago from At the Gemba

        Thanks for your comments and having read about ISO 9001:2008 Procedures Smart Rookie.

      • Smart Rookie profile image

        Smart Rookie 7 years ago

        Good info about ISO 9001 procedures.

      • LeanMan profile image

        Tony 7 years ago from At the Gemba

        Thanks for commenting PDH, Those companies who have correctly applied their ISO 9001:2008 procedures and policies will be certified and be able to use the ISO 9001 logo on their products to indicate the fact that they have a certified quality management system in place.

      • LeanMan profile image

        Tony 7 years ago from At the Gemba

        Hi Humagaia, thanks for your comments, I am happy to give away all of my very limited knowledge, the more companies that start to correctly implement their ISO 9001 Procedures and other improvement initiatives the better for all of us!

      • prettydarkhorse profile image

        prettydarkhorse 7 years ago from US

        Excelente! I understand it now, they always put it in theri logo -- companies, ISO certified, now I know, Maita

      • humagaia profile image

        Charles Fox 7 years ago from United Kingdom

        Be careful - don't give too much info away for free.

      • LeanMan profile image

        Tony 7 years ago from At the Gemba

        Nice to hear that you already have your ISO 9001 procedures in place and have been certified. Thanks for stopping by Mutiny.

      • Mutiny92 profile image

        Mutiny92 7 years ago from Arlington, VA

        Very nice! We got ISO 9001 designated at our engineering facilities.


      This website uses cookies

      As a user in the EEA, your approval is needed on a few things. To provide a better website experience, uses cookies (and other similar technologies) and may collect, process, and share personal data. Please choose which areas of our service you consent to our doing so.

      For more information on managing or withdrawing consents and how we handle data, visit our Privacy Policy at: ""

      Show Details
      HubPages Device IDThis is used to identify particular browsers or devices when the access the service, and is used for security reasons.
      LoginThis is necessary to sign in to the HubPages Service.
      Google RecaptchaThis is used to prevent bots and spam. (Privacy Policy)
      AkismetThis is used to detect comment spam. (Privacy Policy)
      HubPages Google AnalyticsThis is used to provide data on traffic to our website, all personally identifyable data is anonymized. (Privacy Policy)
      HubPages Traffic PixelThis is used to collect data on traffic to articles and other pages on our site. Unless you are signed in to a HubPages account, all personally identifiable information is anonymized.
      Amazon Web ServicesThis is a cloud services platform that we used to host our service. (Privacy Policy)
      CloudflareThis is a cloud CDN service that we use to efficiently deliver files required for our service to operate such as javascript, cascading style sheets, images, and videos. (Privacy Policy)
      Google Hosted LibrariesJavascript software libraries such as jQuery are loaded at endpoints on the or domains, for performance and efficiency reasons. (Privacy Policy)
      Google Custom SearchThis is feature allows you to search the site. (Privacy Policy)
      Google MapsSome articles have Google Maps embedded in them. (Privacy Policy)
      Google ChartsThis is used to display charts and graphs on articles and the author center. (Privacy Policy)
      Google AdSense Host APIThis service allows you to sign up for or associate a Google AdSense account with HubPages, so that you can earn money from ads on your articles. No data is shared unless you engage with this feature. (Privacy Policy)
      Google YouTubeSome articles have YouTube videos embedded in them. (Privacy Policy)
      VimeoSome articles have Vimeo videos embedded in them. (Privacy Policy)
      PaypalThis is used for a registered author who enrolls in the HubPages Earnings program and requests to be paid via PayPal. No data is shared with Paypal unless you engage with this feature. (Privacy Policy)
      Facebook LoginYou can use this to streamline signing up for, or signing in to your Hubpages account. No data is shared with Facebook unless you engage with this feature. (Privacy Policy)
      MavenThis supports the Maven widget and search functionality. (Privacy Policy)
      Google AdSenseThis is an ad network. (Privacy Policy)
      Google DoubleClickGoogle provides ad serving technology and runs an ad network. (Privacy Policy)
      Index ExchangeThis is an ad network. (Privacy Policy)
      SovrnThis is an ad network. (Privacy Policy)
      Facebook AdsThis is an ad network. (Privacy Policy)
      Amazon Unified Ad MarketplaceThis is an ad network. (Privacy Policy)
      AppNexusThis is an ad network. (Privacy Policy)
      OpenxThis is an ad network. (Privacy Policy)
      Rubicon ProjectThis is an ad network. (Privacy Policy)
      TripleLiftThis is an ad network. (Privacy Policy)
      Say MediaWe partner with Say Media to deliver ad campaigns on our sites. (Privacy Policy)
      Remarketing PixelsWe may use remarketing pixels from advertising networks such as Google AdWords, Bing Ads, and Facebook in order to advertise the HubPages Service to people that have visited our sites.
      Conversion Tracking PixelsWe may use conversion tracking pixels from advertising networks such as Google AdWords, Bing Ads, and Facebook in order to identify when an advertisement has successfully resulted in the desired action, such as signing up for the HubPages Service or publishing an article on the HubPages Service.
      Author Google AnalyticsThis is used to provide traffic data and reports to the authors of articles on the HubPages Service. (Privacy Policy)
      ComscoreComScore is a media measurement and analytics company providing marketing data and analytics to enterprises, media and advertising agencies, and publishers. Non-consent will result in ComScore only processing obfuscated personal data. (Privacy Policy)
      Amazon Tracking PixelSome articles display amazon products as part of the Amazon Affiliate program, this pixel provides traffic statistics for those products (Privacy Policy)