ISO 9001 Process Documentation: What's Required and How to Show It
By Nikhil Gupta
ISO 9001 Process Documentation: What's Required
Short answer: ISO 9001:2015 requires organizations to determine the processes their quality management system (QMS) needs, and how those processes interact (clause 4.4). Documentation is required "to the extent necessary": the standard calls it documented information (clause 7.5).
You maintain documented information to support how processes operate, such as procedures and process maps. You retain it as evidence that they ran as planned, such as records.
Process maps are not mandatory, but they're one of the clearest ways to show the process approach to an auditor.
This is general guidance, not certification advice. Confirm requirements with your certification body or quality adviser. Vevos helps document processes; it does not certify ISO compliance.
Part of Process Governance and Compliance.
The process approach in plain English
ISO 9001 asks you to manage your organization as a set of connected processes. For each process, be clear about:
its inputs and outputs;
its sequence and interactions with other processes;
criteria and methods for running and controlling it;
the resources it needs;
responsibilities and authorities;
risks and opportunities;
how it's monitored, measured, and improved.
"Maintain" vs "retain"
Maintain (describe how) | Retain (prove it happened) | |
|---|---|---|
Purpose | Support operation of processes | Evidence of conformity and results |
Examples | Quality policy and objectives, scope, process descriptions, procedures, process maps | Training records, inspection results, audit results, management review outputs, nonconformity records |
Changes | Version-controlled updates | Kept as records, not edited |
What auditors typically look for
A clear picture of your core processes and how they connect, often an interaction map.
For each key process: owner, inputs and outputs, steps, controls, and measures.
Documentation that matches what people actually do.
Control of documented information: current versions available, changes reviewed and approved, obsolete versions handled.
Evidence of monitoring and improvement.
How process maps help
The interaction map: one high-level map showing how sales, design, purchasing, production, delivery, and support connect.
Process-level maps: a BPMN or swimlane map per key process, with roles, decisions, and control points.
Auditor walkthroughs: an auditor can follow a map and then check that the floor matches it.
Faster updates: when processes change, a map is quicker to update than a long procedure.
Using Vevos for ISO 9001 documentation
Capture processes quickly from existing procedures, work instructions, or walkthroughs.
Model in BPMN 2.0, with owners, inputs and outputs, and control points.
Generate process documentation and publish it where teams work.
Control changes with version history, restore points, and role-based access.
Keep processes findable with natural-language search across Playbooks.
Retained records (inspection results, training records, and so on) usually live in your QMS or operational systems. Vevos documents the processes that produce them.
ISO 9001 process documentation checklist
Define QMS scope and list your processes
Create a process interaction map
Map each key process: owner, inputs and outputs, steps, controls, KPIs
Write or generate procedures where they're needed
Set up document control: versions, approvals, access
Define records to retain, and where they live
Schedule reviews and link them to internal audits and management review
FAQ
Does ISO 9001 require process maps?
No. ISO 9001:2015 doesn't require any specific format. Process maps are a common, effective way to show processes and how they interact.
How much documentation does ISO 9001:2015 require?
Less than older versions. It requires certain documented information (such as scope, quality policy, and objectives) plus whatever you determine is necessary for your QMS to be effective.
What is "documented information"?
The term ISO 9001:2015 uses for documents and records the organization must control: maintained (procedures, maps) or retained (records, evidence).
Map your QMS processes: try Vevos free.
Related blog posts
- BPM Software Pricing Explained: Models, Hidden Costs, and What to Budget (2026) — How BPM software is priced: per user, per process, usage-based, or enterprise quote. The hidden costs to budget for, how to compare total cost of ownership, and Vevos's public pricing.
- BPM Software Selection Checklist and RFP Template — How to choose BPM software: a step-by-step selection process, a weighted evaluation checklist, RFP questions to ask vendors, and a proof-of-concept scorecard. Free template.
- How to Review an AI-Generated Process Model — AI can draft a BPMN process map in seconds, but someone still has to check it. Use this 10-point checklist to review AI-generated process models for accuracy, completeness, and correct BPMN.