"Quality manual" is still the phrase people search for, in every language, when they start ISO 9001. The standard stopped requiring one a decade ago. ISO 9001:2008, clause 4.2.2, required a quality manual containing the scope of the system with the justification for any exclusion, the documented procedures or references to them, and a description of the interaction between the processes. ISO 9001:2015 has no such clause. Its Annex A, the informative note on the changes, says in A.6 that the specific terms of the 2008 edition, "quality manual" among them, were replaced by a single requirement to maintain documented information, and clause 7.5 is that requirement. This article is what 7.5 asks for, the 21 places where the 2015 text names documented information, and what a manual is still good for.
What clause 7.5 asks of every document
Clause 7.5 has three parts, and none of them names a document by title.
7.5.1 says the quality management system includes the documented information the standard requires, and the documented information the organisation itself determines to be necessary for the system's effectiveness. The second half is the freedom: the organisation decides how much, and the standard notes that the extent differs with the size of the organisation, the complexity of its processes and the competence of its people.
7.5.2 is about creating and updating: each document is identified and described (a title, a date, an author or a reference number), in a suitable format and medium, and reviewed and approved for suitability and adequacy.
7.5.3 is about control: the document is available where and when it is needed, and adequately protected; and the organisation addresses distribution, access, retrieval and use, storage and preservation, control of changes, and retention and disposition. Documented information of external origin that the organisation needs is identified and controlled, and records are protected from unintended alteration.
That last sentence is the one that separates "maintain" from "retain" throughout the standard. Documented information that is maintained is a document: kept current, versioned, approved. Documented information that is retained is a record: evidence that something happened, protected from being changed afterwards. The 2015 text uses the two verbs deliberately, and the list below follows them.
The 21 places the standard names documented information
Our reading of the 2015 text, by clause number; the wording is ISO's and is not reproduced here. Five are documents to maintain, sixteen are records to retain.
| Clause | Maintain or retain | What it is |
|---|---|---|
| 4.3 | Maintain | The scope of the quality management system, with the justification for any requirement judged not applicable |
| 4.4.2(a) | Maintain | The documented information needed to support the operation of the processes |
| 5.2.2(a) | Maintain | The quality policy, the four contents clause 5.2 requires and a one-page example |
| 6.2.1 | Maintain | The quality objectives |
| 8.1(e) | Maintain and retain | Planning information to have confidence the processes are carried out as planned, and the records that show they were |
| 4.4.2(b) | Retain | Evidence that the processes are carried out as planned |
| 7.1.5.1 and 7.1.5.2 | Retain | Evidence that monitoring and measuring resources are fit for purpose, and the basis of calibration or verification |
| 7.2(d) | Retain | Evidence of competence |
| 8.2.3.2 | Retain | The results of the review of requirements for products and services, and any new requirements |
| 8.3.2 to 8.3.6 | Retain | Design and development: planning, inputs, controls, outputs and changes |
| 8.4.1 | Retain | The evaluation, selection, monitoring of performance and re-evaluation of external providers |
| 8.5.2 | Retain | Traceability of outputs, where traceability is a requirement |
| 8.5.3 | Retain | What happened to customer or external provider property that was lost, damaged or found unsuitable |
| 8.5.6 | Retain | The results of the review of changes to production or service provision |
| 8.6 | Retain | Evidence of conformity with the acceptance criteria at release, and who authorised it |
| 8.7.2 | Retain | Nonconforming outputs: the nonconformity, the action taken, any concession, and who decided |
| 9.1.1 | Retain | The results of monitoring, measurement, analysis and evaluation |
| 9.2.2(f) | Retain | Evidence of the implementation of the audit programme and the audit results |
| 9.3.3 | Retain | The results of management reviews, the one meeting the standard writes the agenda for |
| 10.2.2 | Retain | The nature of nonconformities, the actions taken, and the results of corrective action |
Twenty-one requirements in twenty rows, 8.1(e) counted on both sides, and not one of them is a manual, a procedure or a form by name. A company that has the five documents and the sixteen records, each created, approved and controlled the way 7.5.2 and 7.5.3 say, has what an auditor asks to see under 7.5. Everything else it writes is the documented information it "determines as being necessary", which is a judgement the standard hands to the organisation.
What a manual is for today
Nothing in the 2015 text forbids a quality manual, and there are three reasons to keep one, as long as it is thin.
The first is the map. The 2008 manual's third element, the description of how the processes interact, is still required in substance: clause 4.4.1 asks the organisation to determine its processes, their inputs and outputs, their sequence and interaction, the criteria and methods that make them effective, the resources, the responsibilities and the risks. That determination has to live somewhere, and a short manual with a process map is the conventional place. In our own clause register, 4.4 is the clause marked partly covered for exactly this reason: processes can be recorded, and the interaction between them, one feeding another, is the part a record structure does not yet express.
The second is the scope. Clause 4.3 requires the scope to be maintained as documented information and to state the products and services covered and the justification for any requirement the organisation judges not applicable. A certification body prints the scope on the certificate; a manual that opens with it, the policy and the process map is the document a new employee, a customer's auditor and the certification auditor all read first.
The third is procurement. In the last 365 days, 17,076 notices on TED, the EU's procurement portal, mention ISO 9001, five times the 3,405 that mention ISO 27001, and 1,499 mention both in the same notice (full-text search, spellings "ISO 9001" and "ISO9001", run on 12 September 2026; the query is reproducible on TED's public API). A buyer who asks for ISO 9001 in a tender expects a certificate, and often asks for the manual or the policy as evidence of the system behind it. A two-page manual answers that question; a hundred-page one is not read.
What not to put in it: the procedures themselves, which change more often than the map and belong in their own controlled documents; the records, which are retained, not maintained; and copies of the standard's text, which is ISO's and which the auditor already has.
The four documents to write first
For a company starting from nothing, the order that follows from the list is: the scope (4.3), the quality policy (5.2), the quality objectives (6.2) and the control of documented information itself (7.5), because the fourth is what makes the first three controlled. The policy pack StandardOS drafts for ISO 9001 begins with the quality policy and the control of documented information, then the internal audit procedure and the nonconformity and corrective action procedure, and the documents module gives every document the 7.5.2 and 7.5.3 properties by construction: an identifier, a version, a review and an approval, controlled access, a retention setting, and a hash of the approved text so that a retained record cannot be altered without it showing. Which clauses the product covers in full, in part or not at all is published clause by clause, the four of clause 8 it does not hold included.
Sources
- ISO 9001:2015, clauses 4.3, 4.4, 5.2.2, 6.2.1, 7.1.5, 7.2, 7.5, 8.1, 8.2.3.2, 8.3, 8.4.1, 8.5.2, 8.5.3, 8.5.6, 8.6, 8.7.2, 9.1.1, 9.2.2, 9.3.3, 10.2.2 and Annex A.6, cited by number; the text is ISO's and is not reproduced.
- ISO 9001:2008, clause 4.2.2, for what the quality manual once had to contain.
- TED, the EU's procurement portal, full-text search over the last 365 days, run on 12 September 2026: 17,076 notices mentioning ISO 9001, 3,405 mentioning ISO 27001, 1,499 mentioning both.
This is not certification advice. Whether a document is adequate is the certification body's judgement at audit; the clauses above are where it looks.