Documents Required for ISO Certification in India: Complete Checklist by Standard
Preparing the right documentation is the single most critical step in achieving ISO certification. The auditor will check your documented information — mandatory documents and records specified in the standard — before conducting an on-site audit. A missing or incomplete document can result in a major non-conformity, delaying your certification. This guide provides a complete checklist for ISO 9001, 14001, 22000, and 27001 certifications.
- ISO standards distinguish between documents (policies, procedures) and records (evidence of actions taken)
- ISO 9001:2015 has 10 mandatory documented information requirements
- Internal audit records and management review minutes are required by all major ISO standards
- Documents don’t need to be in any specific format — can be digital or paper
- Auditors check implementation evidence (records), not just the written documents
What Is the Difference Between ISO Documents and Records?
ISO 9001:2015 (and other standards) uses the term “documented information” for both documents (instructions, policies, procedures) and records (completed forms showing past actions). The distinction matters because:
- Documents (maintained documented information): Quality Policy, procedures, work instructions. These are living documents — they can be updated. Must be version-controlled.
- Records (retained documented information): Completed inspection checklists, audit reports, training attendance sheets, customer complaint logs. These are historical evidence — they are not updated, only retained.
Auditors will check both. A procedure without supporting records (evidence that it is being followed) will result in a non-conformity — “procedure exists but implementation not evidenced”.
What Documents Are Required for ISO 9001:2015 Certification?
ISO 9001:2015 specifies mandatory documented information at various clauses. The core list:
| Document / Record | ISO 9001 Clause | Type |
|---|---|---|
| Quality Policy | 5.2.2 | Document |
| Quality Objectives | 6.2.1 | Document |
| Scope of the QMS | 4.3 | Document |
| Risk and Opportunity Register | 6.1 | Document + Record |
| Competency Records (training, qualifications) | 7.2 | Record |
| Monitoring and Measurement Evidence | 9.1 | Record |
| Internal Audit Reports and Schedule | 9.2 | Record |
| Management Review Minutes | 9.3 | Record |
| Nonconformity and Corrective Action Records | 10.2 | Record |
| Customer Satisfaction Data | 9.1.2 | Record |
What Additional Documents Are Needed for Other ISO Standards?
| Standard | Additional Key Documents |
|---|---|
| ISO 14001:2015 | Environmental Policy, Environmental Aspects Register, Legal and Compliance Register, Emergency Response Plan, Environmental Objectives, Waste Management Records |
| ISO 22000:2018 | Food Safety Policy, HACCP Plan, PRPs (Prerequisite Programme) documentation, Hazard Analysis, CCP Monitoring Records, Traceability Records, Allergen Management Plan |
| ISO 27001:2022 | Information Security Policy, Asset Inventory, Risk Assessment & Treatment Plan (Statement of Applicability), Access Control Policy, Incident Management Records, Business Continuity Plan, Supplier Security Assessment |
| ISO 45001:2018 | OHS Policy, Hazard Identification Register, Incident Records, Emergency Response Plan, Legal Compliance Register, PPE Records, Contractor Safety Records |
What Documents Are Needed for the ISO Company Application (From the Business)?
Beyond QMS/EMS/ISMS documentation, the Certification Body also requires business documents to verify the applicant:
- Certificate of Incorporation (for company) or PAN card (for proprietorship/partnership)
- GST Registration Certificate
- List of locations/sites to be covered (scope of certification)
- Employee headcount (permanent and contract) for audit man-day calculation
- Brief description of products/services covered under the scope
- Previous ISO certificates (if any) for transfer applications
How Long Should ISO Records Be Retained?
ISO standards do not prescribe specific retention periods, but they require the organisation to determine and document appropriate retention periods based on:
- Legal/regulatory requirements (for example, FSSAI requires food safety records for 2+ years)
- Product/service warranty period (quality records should last at least as long)
- Customer contractual requirements
- Internal audit cycle (at least 2 full internal audit cycles worth of records for recertification)
Best practice: retain most ISO records for 3 years minimum — this covers one full certification cycle (initial + 2 annual surveillances) and supports the recertification audit.
What Are the Common Document Gaps Found During ISO Audits?
- No evidence of internal audits: The procedure exists but there is no completed audit report from the last 12 months
- Management review not held: Top management meeting minutes are missing or older than 12 months
- Competency records missing: Training certificates, qualifications, and skills assessments for key staff not maintained
- Risk register not updated: Created for initial certification but not reviewed annually
- Customer feedback not systematically collected: Informally done but no formal records or trend analysis
- No corrective action follow-up: Nonconformities raised but no closure records showing root cause and verification of fix
Frequently Asked Questions
Quality Policy, Quality Objectives, QMS Scope, Risk Register, Competency Records, Internal Audit Reports, Management Review Minutes, Nonconformity Records, and Customer Satisfaction data are the mandatory documented information requirements.
Documents are maintained instructions and policies (can be updated). Records are retained evidence of activities (completed forms, reports, logs). Both are called “documented information” in ISO standards.
ISO 9001:2015 does not require a quality manual (unlike the 2008 version). You still need documented procedures and policies, but they do not need to be compiled into a single “manual” document.
The organisation decides, based on legal requirements and business needs. Best practice: retain ISO records for at least 3 years to cover one full certification cycle and support the recertification audit.
Beyond ISO 9001 basics: Information Security Policy, Asset Inventory, Risk Assessment and Treatment Plan, Statement of Applicability (SoA), Access Control Policy, Incident Management Records, and Business Continuity Plan are mandatory for ISO 27001:2022.
Related: ISO Registration Fees in India