Quality management
ISO 9001: quality management requirements and how to run it
In short
ISO 9001 is the international standard for a quality management system (QMS). It sets requirements for consistently providing products and services that meet customer and regulatory requirements, built around a process approach, risk-based thinking and continual improvement. It is the most widely adopted management-system standard in the world and is certified by an accredited body.
Last reviewed: August 2026
Who it is for
ISO 9001 applies to organizations of any size or sector that want to demonstrate consistent quality and continual improvement. It is common in manufacturing, construction, professional services and any supply chain where customers require a certified QMS as a condition of doing business.
Core structure
ISO 9001:2015 follows the same high-level structure as other ISO management standards (clauses 4–10), which makes it straightforward to integrate with ISO 27001 or ISO 14001.
- Context of the organization and interested parties
- Leadership and quality policy
- Planning, including risks and opportunities and quality objectives
- Support: resources, competence, documented information
- Operation: control of products, services and suppliers
- Performance evaluation: monitoring, internal audit, management review
- Improvement: nonconformity, corrective action, continual improvement
Typical compliance challenges
- Keeping documented information current across many sites or teams
- Running internal audits and management reviews on schedule
- Tracking nonconformities and corrective actions to closure
- Managing supplier quality across the chain
- Integrating the QMS with other standards without duplicating effort
What can reasonably be automated
- The annual calendar for audits, reviews and objectives
- Nonconformity and corrective-action tracking with owners
- Supplier questionnaires and quality records
- KPI and quality-objective monitoring
- Shared documentation and evidence with other management systems
Evidence auditors expect
- Quality policy, objectives and scope
- Documented processes and control of documented information
- Internal audit programme and results
- Management review records
- Nonconformity and corrective-action records
- Supplier evaluations and monitoring data
Continuous improvement in practice
ISO 9001 is built on the Plan–Do–Check–Act cycle. Running the QMS as a live operation — with KPIs, incidents and corrective actions tracked continuously rather than reconstructed before an audit — is what turns certification into genuine operational value.
How Isodora supports ISO 9001
Isodora runs the quality management system as a live operation, integrated with your other standards.
Integrated management system
KPIs, risks, incidents, suppliers and the annual calendar in one place — shareable with management and auditors.
Corrective actions
Nonconformities and corrective actions tracked to closure with clear ownership.
Supplier registry
Evaluate and monitor supplier quality across the chain with token-based questionnaires.
One-click reports
A management report for reviews and audits, generated from live data.
Isodora helps you build and maintain a QMS. Certification is issued by an independent accredited body after its own audit.
Frequently asked questions
- What is ISO 9001 used for?
- ISO 9001 gives organizations a structured quality management system so they consistently meet customer and regulatory requirements and continually improve. It is often required by customers as a condition of supply.
- Can ISO 9001 be integrated with ISO 27001?
- Yes. Both use the same high-level clause structure, so context, leadership, internal audit, management review and improvement can be run as one integrated management system, reusing shared evidence.
- How often is an ISO 9001 audit?
- After certification, an accredited body runs surveillance audits — typically annually — with a full recertification audit every three years. Internal audits run on your own schedule throughout.