ISO 9001 requirements span Clauses 4 through 10 — context, leadership, planning, support, operation, performance evaluation, and improvement — built on the process approach, customer focus, and risk-based thinking that run through every clause. Understanding what each clause requires, not just what it's titled, is what separates a QMS that exists on paper from one that actually functions.
ISO 9001 requirements can feel abstract stated in isolation — "the organization shall determine risks and opportunities" doesn't mean much without understanding what that determination actually needs to produce. This guide walks through each clause with specific attention to what it requires in practice, and is written by Maria Falbo, a Lead Auditor with decades of ISO 9001 experience.
ISO 9001 follows the Harmonized Structure shared across major ISO management system standards — the same clause numbering and overall logic used in ISO 14001, ISO 45001, and ISO 50001. Clauses 1 through 3 cover scope, normative references, and definitions, with no auditable requirements. Clauses 4 through 10 contain the actual requirements, and this shared structure is exactly what makes an integrated management system combining multiple standards practical to build and audit together.
Clause 4.1 requires organizations to determine internal and external issues relevant to their purpose and strategic direction — including whether climate change is a relevant issue, a requirement that applies under both the current and prior edition of the standard.
Clause 4.2 requires organizations to determine relevant interested parties and their requirements. Under ISO 9001:2026, this clause adds a new step: organizations must also determine which of those requirements will actually be addressed through the QMS — not just list every stakeholder and everything they might want.
Clause 4.3 requires defining the QMS's scope, documented and available, with conformity only claimed for what's within the defined boundary. Clause 4.4 requires the QMS itself, established as a set of interrelated processes, with the interactions between them understood well enough to manage the system as a whole rather than a collection of disconnected activities.
Clause 5.1 requires top management to demonstrate leadership and commitment — not delegate the QMS entirely and simply approve what others produce. This includes ensuring the quality policy and objectives align with strategic direction, resources are available, and process approach and risk-based thinking are promoted throughout the organization.
Clause 5.2 requires a documented quality policy, established and communicated.
Clause 5.3 requires organizational roles, responsibilities, and authorities to be assigned and communicated — including specifically ensuring the QMS conforms to requirements and that its performance is reported to top management.
Clause 6.1 requires organizations to determine risks and opportunities affecting the QMS's ability to achieve intended results. Under ISO 9001:2026, this clause is restructured — the 2015 edition treats risks and opportunities together in one combined clause, while 2026 splits this into three separate subclauses: determining risks and opportunities, addressing risks, and addressing opportunities, each with its own dedicated treatment.
A distinction I find genuinely useful when explaining Clause 6.1 to new auditors: a risk is something that could stop the QMS from delivering what it's supposed to; an opportunity is something that could make it deliver better than it currently does. Teams often lump both into one generic "risks and opportunities" brainstorm and end up with a list that's mostly just risks in disguise — "risk: losing a key supplier" becomes "opportunity: diversify suppliers," which is really just the same risk restated. A genuine opportunity is something the organization wasn't already planning to do.
Clause 6.2 requires quality objectives that are consistent with the quality policy, measurable where practicable, supported by action plans, monitored, and available as documented information.
Clause 6.3 requires planned changes to the QMS to be carried out in a controlled manner, considering their purpose and consequences. Under 2026, this clause expands to include three additional considerations: how the change's effectiveness will be monitored and evaluated, how it will be communicated, and how its results will be reviewed.
Clause 7.1 requires the resources needed for the QMS — people, infrastructure, a suitable operating environment, monitoring and measurement resources, and organizational knowledge — to be determined and provided.
Clause 7.2 requires competence to be determined, ensured, and evidenced for anyone whose work affects QMS performance.
Clause 7.3 requires awareness among relevant personnel of the quality policy, their contribution to the QMS, and the implications of nonconformity. Under 2026, this clause adds a new specific awareness item: organizational quality culture and ethical behavior.
Clause 7.4 requires internal and external communications relevant to the QMS to be determined.
Clause 7.5 requires documented information to be controlled, current, and available where and when needed.
Our ISO 9001 Internal Auditor course covers Clause 4 through Clause 10 in depth, built on ISO 9001 and ISO 19011.
Clause 8.1 requires operational planning and control — establishing criteria for processes, implementing controls, and keeping documented information sufficient to demonstrate the process was carried out as planned. Under 2026, the scope here broadens: where 2015 refers only to "outsourced processes," 2026 requires control over "externally provided processes, products or services" more broadly, aligning with the terminology used in Clause 8.4.
Clause 8.2 requires determining and reviewing requirements for products and services, including communication with customers.
Clause 8.3 requires a controlled design and development process, where applicable, covering planning, inputs, controls, outputs, and changes.
Clause 8.4 requires externally provided processes, products, and services to be controlled based on their potential impact on the organization's ability to consistently meet requirements.
Clause 8.5 requires production and service provision to be carried out under controlled conditions — including identification and traceability, protection of outputs, and control of changes.
Clause 8.6 requires verification that product and service requirements have been met before release.
Clause 8.7 requires nonconforming outputs to be identified and controlled to prevent unintended use or delivery.
Clause 9.1 requires monitoring, measurement, analysis, and evaluation of QMS performance and effectiveness — including customer satisfaction specifically, which the standard treats as a distinct, required measure, not an assumed byproduct of low complaint volume.
Clause 9.2 requires internal audits at planned intervals to determine whether the QMS conforms to requirements and is effectively implemented and maintained. Under 2026, audit programs must define audit objectives for each individual audit, not just scope and criteria, as covered in our full guide to conducting an ISO 9001 internal audit.
Clause 9.3 requires management review at planned intervals, addressing defined inputs and producing decisions related to improvement opportunities, QMS changes, and resource needs. Under 2026, one genuinely new input is added: changes in the needs and expectations of interested parties relevant to the QMS.
Clause 10 requires organizations to determine and select opportunities for improvement, and to address nonconformities through corrective action — investigating root cause, implementing corrective action, and reviewing its effectiveness. Under 2026, this clause is restructured rather than substantively changed: the general improvement principles previously split across a separate opening clause and a closing "Continual Improvement" clause are merged into a single Continual Improvement clause that now leads the section, with Nonconformity and Corrective Action following in the same position it held before.
For a full practical breakdown of how the risk and opportunity requirements in Clause 6.1 actually apply, see our ISO 9001 risk and opportunity management guide.
ISO 9001 has ten clauses total. Clauses 1 through 3 cover scope, normative references, and definitions with no auditable requirements. Clauses 4 through 10 contain the actual requirements organizations must meet.
Clause 6.1 saw the most significant structural change — risks and opportunities, treated together in a single clause under 2015, are split into three separate subclauses under 2026. Clause 10 is also restructured, though its underlying requirements remain largely the same.
Yes — organizations must determine whether climate change is a relevant issue to their context. This applies under the current 2015 edition, not just the 2026 revision; it was introduced via a 2024 amendment to ISO 9001:2015.
No — the clause requires internal audits at planned intervals covering defined criteria and scope, plus objectives under the 2026 revision, but doesn't mandate a specific checklist format. For what a well-structured checklist should cover, see our ISO 9001 internal audit checklist guide.
Yes — ISO 9001 shares the same Harmonized Structure as ISO 14001, ISO 45001, ISO 50001, and other relevant ISO standards, making clause numbering, terminology, and overall logic align closely across standards, which is what makes an integrated management system practical to build and audit as one coordinated system.

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.
Learn more about Maria →Self-paced · 365-day access · Training certificate included