ISO 9001, with risk-based thinking that shows up in the record
The 2015 revision put risk-based thinking into the standard and removed the preventive action clause, on the logic that a system built on risk is preventive throughout. Auditors test that directly. Dimeri holds the risks alongside the processes they threaten.
What ISO 9001 requires
ISO 9001 specifies requirements for a quality management system where an organisation needs to demonstrate its ability to consistently provide products and services that meet customer and applicable statutory and regulatory requirements. It is the most widely held management system certificate in the world and the one most often demanded in tenders and supply chains.
The 2015 revision made two changes that still catch organisations out. It formalised the process approach in clause 4.4, requiring the processes of the system, their inputs, outputs, sequence, interaction, criteria and measures to be determined. And it introduced risk-based thinking in clause 6.1, while deleting the separate preventive action requirement, on the reasoning that a system designed around risk is preventive by construction. An auditor will therefore ask where the risks to your processes are recorded and what you did about them.
The rest is familiar management system territory: leadership and customer focus, planning of changes, resources including people, infrastructure and monitoring equipment, operational planning, design and development where applicable, control of externally provided processes, release of products and services, control of nonconforming output, monitoring and measurement including customer satisfaction, internal audit, management review, and corrective action.
The clauses Dimeri tracks
Dimeri holds the process map, the risks against each process, and the evidence that controls operate, in one structure.
Process approach and leadership
The processes of the system determined with their inputs, outputs, sequence and measures, and top management accountable including for customer focus.
- Process register with owners and interactions
- Criteria and performance measures per process
- Quality policy with approval and review dates
- Customer requirements captured and tracked
Risk-based thinking
Risks and opportunities that affect conformity of products and services and the ability to enhance customer satisfaction, addressed and their effectiveness evaluated.
- Risks recorded against the processes they threaten
- Opportunities captured alongside risks
- Actions with owners and due dates
- Effectiveness of the action evaluated, as the clause asks
Resources and competence
People, infrastructure, environment and monitoring resources determined and provided, with competence established and evidenced.
- Competence requirements per role
- Training and qualification records by individual
- Calibration and maintenance schedules tracked
- Gaps raised as actions rather than noted
Externally provided processes and suppliers
Controls over externally provided processes, products and services, with criteria for evaluation, selection and re-evaluation of suppliers.
- Supplier register with evaluation criteria and scores
- Re-evaluation on a cycle, not only at onboarding
- Controls held against the supply contract
- Performance issues raised as nonconformities
Nonconforming output and corrective action
Nonconforming output identified and controlled, and nonconformities investigated with corrective action taken where the cause could recur.
- Nonconformity register with disposition recorded
- Root cause analysis against recurring issues
- Corrective actions carried until evidence closes them
- Trend view across processes and suppliers
Monitoring, audit and management review
Performance and customer satisfaction monitored, internal audit run across the system, and management review held with the inputs the clause lists.
- Process measures tracked with thresholds
- Customer satisfaction captured and trended
- Internal audit programme covering every clause
- Management review inputs assembled through the year
How Dimeri covers ISO 9001
Quality systems drift when the documented process and the performed process separate. Dimeri keeps the evidence attached to the process rather than to a binder.
Risk-based thinking with somewhere to live
The 2015 revision asks for risks to processes but gives no register to keep them in, so most organisations improvise a spreadsheet. Dimeri holds them in the same register as every other risk, scored the same way, which is what makes clause 6.1 auditable.
Nonconformities that trend
Individual corrective actions close. Patterns across processes and suppliers only become visible when nonconformities share a structure, which is where the improvement clause 10.3 actually earns its place.
Supplier evaluation on a cycle
Clause 8.4 requires re-evaluation, not just selection. Suppliers carry review dates and performance history, and the third party risk module uses the same records.
Shared clauses across the ISO set
Context, leadership, competence, documented information, internal audit and management review are common to ISO 9001, 14001, 45001 and 27001. One system, several scopes, one internal audit programme.
Getting ISO 9001 in place
- 1
Map the processes
Clause 4.4 wants the processes, their inputs and outputs, their sequence and interaction, and the criteria and measures that show they work. Everything else in the standard hangs off this map.
- 2
Put risks against the processes
Risks and opportunities are recorded against the processes they affect and scored on the organisation's own criteria, so clause 6.1 has an answer rather than a paragraph.
- 3
Set controls, competence and suppliers
Operational controls, competence requirements and supplier evaluation criteria are configured with owners and review cycles, and evidence is captured as they run.
- 4
Measure, audit and improve
Process measures, customer satisfaction, internal audit and management review run on schedule, and nonconformities carry root cause through to closure so the trend is usable.
ISO 9001 questions
What happened to preventive action in the 2015 revision?
It was removed as a separate clause and replaced by risk-based thinking in clause 6.1. The reasoning is that a management system built around risks and opportunities is preventive throughout, rather than having prevention bolted on as one procedure. Practically, auditors now ask where your process risks are recorded and what you did about them.
Do we need a quality manual?
The 2015 revision removed the explicit requirement for a quality manual and for six documented procedures, replacing them with documented information that the organisation determines is necessary. Many organisations keep a manual because customers expect it, but the standard does not require one.
Can ISO 9001 and ISO 14001 share one system?
Yes, and most organisations holding both do. The common management system structure means context, leadership, competence, documented information, internal audit and management review are shared clauses. Dimeri holds one system with separate scopes and one internal audit programme covering both.
Is certification worth it if no customer has asked?
That is a commercial judgement rather than a compliance one. The structure is useful on its own, and many organisations align without certifying. Certification matters when a tender, a customer or a supply chain requires independent assurance, which in South African public procurement is increasingly common.
Is this a substitute for the standard itself?
No. ISO 9001 is a copyrighted document published by ISO and should be obtained from ISO or a national standards body if you intend to certify against it.
Go further on ISO 9001
Put ISO 9001 on one register
Every requirement mapped to a control with a named owner, the evidence held against it, and one view of where you stand.