A quality policy is the shortest document in a quality management system and the one most companies get wrong in the same way: a paragraph of good intentions that would fit any company in any industry. ISO 9001:2015 does not ask for intentions. Clause 5.2 asks for four specific contents and three specific things to happen to the document, and an auditor checks all seven. This article is the seven, what each means for a page of text, and a one-page example; the clause is paraphrased in our reading and ISO's wording is not reproduced.

Who writes it, and why that matters (5.1 and 5.2.1)

The policy is top management's. Clause 5.1.1 lists what top management does to demonstrate leadership, and among the items is ensuring the quality policy and the quality objectives are established and compatible with the organisation's context and strategic direction. Clause 5.2.1 then says top management establishes, implements and maintains the policy. A quality manager may draft it; the people who set the company's direction sign it, because the first thing the policy has to do is fit that direction. A policy the managing director has never read fails 5.2.1 before its first sentence.

The four contents (5.2.1)

5.2.1 requires the policy to do four things.

5.2.1 The policy must What it means for the text
(a) Be appropriate to the purpose and context of the organisation and support its strategic direction It names what the company does and for whom, and what quality means for that, in words that would not fit a different company. The context analysis of 4.1 and 4.2 is where "purpose and context" is written down; the policy reads from it.
(b) Provide a framework for setting quality objectives It says what the company will be measured on, so that the objectives of 6.2 can be derived from it: on-time delivery, defect rates, response times, customer satisfaction, whatever the company chose. The objectives themselves are set elsewhere and are measurable; the policy gives them their headings.
(c) Include a commitment to satisfy applicable requirements A sentence committing to meet customer requirements and the statutory and regulatory requirements that apply to what the company sells. "Applicable" is the company's determination under 4.2 and 8.2.2; the policy commits to it.
(d) Include a commitment to continual improvement of the quality management system A sentence committing to improve the system, which clause 10.3 then turns into a duty.

A policy can contain more. It cannot contain less, and the two commitments in (c) and (d) have to be there in substance, not implied.

The three things that must happen to it (5.2.2)

5.2.2 requires the policy to be, first, available and maintained as documented information: it is a controlled document under 7.5, with an identifier, a version, an approval and a review, one of the five documents the standard requires to be maintained. Second, communicated, understood and applied within the organisation: three verbs, and an auditor tests the middle one by asking people on the floor what the policy means for their work, not whether they can recite it. Third, available to relevant interested parties, as appropriate: on the website, in a tender response, on request, as the company decides.

The second of the three is where a policy of good intentions fails. "Understood and applied" requires the policy to say something a person can apply: a commitment to answer every customer complaint within two working days can be applied; a commitment to excellence cannot.

What auditors write up

From the clause, the findings are predictable. A policy with no link to the objectives (the objectives of 6.2 exist but nothing in the policy frames them). A policy without one of the two commitments, usually the one to applicable requirements. A policy that was written once and never reviewed, so that it describes a company that has since changed its products, its markets or its owners, and no longer fits the context of 4.1. A policy that management cannot explain. And a policy that nobody outside management has seen, which fails "communicated" on the evidence.

The review is the fix for the third: the management review of clause 9.3 considers changes in the external and internal issues relevant to the system, and a policy re-read against that input each year stays appropriate to the context.

One policy for ISO 9001 and ISO 27001

Clause 5.2 belongs to the Harmonized Structure, and ISO/IEC 27001:2022 has a clause 5.2 of the same shape: appropriate to the purpose, a framework for objectives, a commitment to applicable requirements, a commitment to continual improvement, documented, communicated, available. A company certified to both may hold one integrated policy or two; an integrated one is audited against both clauses, so the quality commitments and the information security commitments each have to be present, and the objectives of each standard need their framework. StandardOS drafts the quality policy as its own controlled document, in the policy pack for ISO 9001, next to the information security policy for ISO 27001, each with the four contents and each versioned and approved as 7.5 asks; which clauses of ISO 9001 the product covers, clause by clause, is published.

A one-page example

Our example, for a fictional software company, in our own words. It is a model of the structure, not a text to copy: the sentences that make it fit 5.2.1(a) are the ones that would have to change for another company.

Quality policy, Example Software GmbH, Berlin. Version 3, approved by the managing directors on 1 March 2026.

Example Software builds and operates accounting software for small companies in the European Union. Quality, for us, means that the software does what its documentation says, that a release does not break what the previous one did, and that a customer who reports a problem knows within two working days what will happen and when.

We commit to meeting the requirements we agree with our customers, the requirements of the laws and regulations that apply to accounting software in the markets we sell in, and the requirements of this management system. We commit to improving the management system continually, using what our audits, our customer feedback and our nonconformities tell us.

Our quality objectives are set each year within this framework and are measurable: the share of releases withdrawn after release, the time to first response and to resolution on customer reports, and customer satisfaction as we measure it. The objectives, their targets and their results are reviewed at the management review.

This policy is available to everyone who works for us and is explained to new colleagues in their first week. It is available to customers and other interested parties on our website. It is reviewed at the management review and whenever what we sell or where we sell it changes.

Signed for Example Software GmbH, the managing directors.

Sources

  • ISO 9001:2015, clauses 4.1, 4.2, 5.1.1, 5.2.1, 5.2.2, 6.2, 7.5, 8.2.2, 9.3 and 10.3, cited by number; the text is ISO's and is not reproduced.
  • ISO/IEC 27001:2022, clause 5.2, for the shape the two policies share.

The free page writes the policy from ten answers, in the company's own words. This is not certification advice. Whether a policy meets the clause is the certification body's judgement at audit; the seven requirements above are what it reads the page against.