
Implementing ISO 9001 is mostly writing down what you already do, finding the gaps, and putting numbers on things. The businesses that struggle are the ones that start with a template instead of their own processes.
Start with your processes, not the standard
The common mistake is opening the standard at clause 4 and working through to clause 10, producing a document for each. You end up with a system that satisfies the standard and describes nobody's business.
Map how work actually moves through your company first. Enquiry to quote to order to delivery to invoice, or whatever the equivalent is for you. Then check that map against the standard and see what is missing. It is the same destination and a much better system at the end of it.
The documents you actually need
Fewer than most people think. ISO 9001 requires far less documentation than it did in older versions, and nothing says a procedure has to be long.
- Scope of the management system
- Quality policy
- Quality objectives, with measurements against them
- Evidence of competence for people doing work that affects quality
- Records of the operational processes you have decided you need
- Internal audit programme and results
- Management review records
- Non-conformities and the corrective actions taken
Everything else is optional and should earn its place. Every procedure you write is something an assessor can hold you to.
The parts that catch people out
Context and interested parties. Clause 4 asks who matters to your business and what they need. Most businesses answer it in a paragraph of generalities. Keep it specific: name the customer types, the regulators, the key suppliers, and what each of them actually expects.
Risks and opportunities. This is not a risk register with fifty rows. It is a documented consideration of what could go wrong with your ability to deliver, and what you are doing about it. Half a dozen real risks beats fifty generic ones.
Objectives. They have to be measurable and they have to be measured. "Improve customer satisfaction" is not an objective. "Reduce late deliveries from 12% to under 5% by December, measured monthly" is. This is the clause that most often produces a finding, because businesses set objectives and then never report against them.
Internal audit. Cover the whole standard and the whole business across the cycle, spread through the year, and let it find things. An audit programme with no findings tells an assessor the programme is not working.
Management review. It has required inputs and they need to be evidenced. Your team completes and contributes to it, and the decisions get recorded. "We discussed it" is not a decision.
A realistic timeline
For a business under fifty people on one site:
- Weeks 1 to 2: gap analysis and process mapping
- Weeks 3 to 6: build the documented system
- Weeks 6 to 10: implement it, train people, start generating records
- Weeks 10 to 12: internal audit and management review
- Then: stage 1 and stage 2 with your certification body
The operating period in the middle is the bit you cannot compress. An assessor needs to see the system running, and a system with two weeks of records does not demonstrate a cycle.
Who should own it internally
One person, with enough authority to change how things are done and enough time to actually do it. The most common cause of a stalled implementation is giving it to someone who already has a full-time job and no mandate.
It does not need to be a quality specialist. Someone organised who understands the business is usually better than someone who knows the standard but not the company.
If you want help
We build the system around how you already work, support you through the internal audit and management review so your team owns them, and get you to certification at a fixed price. See our ISO 9001 consultancy or system implementation service. If you plan to add ISO 14001 or ISO 45001 later, say so now, because building one integrated system from the start costs very little extra.
‹ Back to all articles