Quality Management · ISO Standards
ISO 9001:2015 for product organizations: process, risk, and audit sampling
How to stand up a quality management system that matches how work actually happens — not a shelf manual — before an ISO 9001 Stage 2 audit.
6 min read
ISO 9001 is still the language of supplier qualification in manufacturing and increasingly in software services. Registrars sample processes, not slogans. A quality manual that does not match Jira, support, and release practice is the fastest path to nonconformities.
The paired checklist is the clause walk. This note is about risk-based thinking that is not a poster, objectives you can measure, and when 9001 is the wrong certificate next to 13485 or IATF.
If your only “quality” file is information security, the QMS looks borrowed. 9001 is about conformity of the product or service you sell — defects, delivery, complaints — not about your SOC 2.
A QMS is how work happens
Clause 4 context and interested parties should name actual customers, regulators, and suppliers. Clause 8 is the product realization path: requirements, design if you design, production or service delivery, and release. If those steps live in tools the manual never mentions, Stage 2 will follow the tools.
Documented information is whatever you need for the QMS to work. ISO 9001:2015 does not require a six-level procedure library. It does require that people can find the current way of working.
Outsourced design, cloud hosting, and contract manufacturers still need control if they affect conformity. “The vendor is certified” is a starting point, not the control.
For a product organization, clause 8 often maps to discovery, design, release, and support. If those names only exist in a RACI from 2019 while the team actually ships from GitHub and Intercom, rewrite the process around the tools — then control the tools. Registrars would rather see a short current process than a beautiful obsolete one.
Decisions the checklist will not make for you
Is 9001 the right standard? Medical devices want 13485. Automotive production wants IATF 16949. 9001 can be the base, but buyers in those sectors will not treat it as enough.
Scope of the QMS (which products, which sites) is a commercial decision. Certifying a side project while the revenue product sits outside scope will look odd in a tender.
Quality objectives without metrics fail management review. Pick a few: escape defects, on-time delivery, support reopen rate — then review them. Do not invent twenty KPIs for the audit week.
Decide whether design is in scope. Many SaaS firms exclude design and wonder why the registrar still samples how requirements become releases. If you change the product weekly, design-and-development thinking applies even when you do not call it “R&D.”
Where 9001 audits actually sting
Internal audits that only check documents, not process effectiveness, teach the organization the wrong lesson and fail the registrar’s sample of clause 9.2.
Skipping risk-based thinking (clause 6) and treating 9001 as a documentation exercise produces a binder. Registrars will ask what changed when a customer complaint spiked.
Change control that exists for software releases but not for the QMS itself — uncontrolled templates, two “official” processes — is a frequent nonconformity in product companies.
Complaints that never become corrective action are the registrar’s favorite sample. If support closes tickets as “user error” with no trend review, clause 10 is theatre. Tie escape defects and complaint themes into management review with owners and due dates.
How to use the paired checklist
Walk it with operations and quality together, using live tickets as evidence, not the manual. Tick an item only when the process matches the floor or the sprint board.
If you already have ISO 27001, share leadership and improvement machinery where it is honest, but do not pretend information-security objectives are quality objectives.
Use a live complaint and a live release as the two samples while you work the checklist. If those stories cannot be told with the QMS vocabulary — requirement, nonconformity, corrective action — you are not ready for Stage 2, no matter how complete the document list looks.
What teams get wrong
- ISO 9001 is only for factories.
- It is a generic QMS. Software, professional services, and SaaS use it when customers ask for a quality certificate. The processes look different; the clauses do not vanish. You still need measurable objectives, competent people, and control of nonconforming output — even if the output is a software release.
- A quality manual on the shelf is the QMS.
- The QMS is the work. Documented information supports it. Auditors follow a complaint or a release, not the table of contents. If the manual and the sprint board disagree, the board wins and the manual becomes a finding.
- ISO 27001 already covers quality.
- 27001 covers information security. Overlap exists in documented information and improvement. Product conformity and customer satisfaction are 9001’s job. A secure outage is still a quality failure if you promised availability in the SLA.
When the checklist is enough — and when it is not
- Use the checklist to align processes, objectives, and internal audit before you book Stage 1.
- Use a registrar (and a consultant only if the team has never run a QMS) for multi-site sampling and integrated audits with 14001/45001.
- Use sector specialists when the product is a medical device, automotive part, or otherwise sits under a scheme that 9001 does not satisfy.
- This guide is not a substitute for ISO 9001:2015 or for certification-body findings.
Related checklists
MedTech QMS
ISO 13485:2016 Medical Device QMS Checklist
Guide: ISO 13485: medical device QMS, design controls, and why 9001 is not enough
Automotive
IATF 16949:2016 Automotive QMS Readiness Checklist
Guide: IATF 16949: automotive QMS beyond ISO 9001 — APQP, PPAP, and customer specifics
Information Security
ISO 27001:2022 Implementation & Audit Readiness Checklist
Guide: ISO 27001:2022 audit readiness: what Stage 1 and Stage 2 actually test
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer