Article
ISO 9001 Documented Information: What the 2015 Guidance Says, and What to Check for 2026
What ISO/TC 176/SC 2's guidance says about documented information in ISO 9001:2015, the difference between maintained documents and retained records, and what to check for the 2026 edition.
Last reviewed October 1, 2026
"What documents do we actually have to have?" is a fair question, and ISO's own guidance points to a fairly short list.
ISO/TC 176/SC 2's guidance says ISO 9001:2015 did not require a quality manual or a fixed set of procedures. It asks for specific documented information, plus whatever your organization decides it needs for its system to work. This article summarizes that guidance in our own words, and flags what to check for the 2026 edition, published on September 16, 2026.
We have not checked these lists against ISO 9001:2026. Check your own licensed copy. This is our summary of the guidance, not ISO text.
Two kinds of documented information
Since 2015 the standard has used "documented information" instead of "documents" and "records". In practice there are two kinds:
Maintained documented information describes how things work and is kept up to date. This is what people used to call documents.
Retained documented information is evidence that something happened. This is what people used to call records.
The guidance says the amount you need depends on the size and type of the organization, the complexity of its processes, and the competence of its people. It can be on any medium: paper, electronic files, photographs, even a master sample. It also says that an organization with an existing system should not need to rewrite all of its documented information, and that analysis of processes, not documents, should drive how much you keep.
Maintained: as listed in the 2015 guidance
The scope of the quality management system
Documented information to the extent needed to support the operation of your processes
The quality policy
Quality objectives
Retained: some examples
Examples of retained documented information in the guidance include: evidence of competence; the audit program and internal audit results; management review results; nonconformities and corrective action results; monitoring and measurement results; evidence of how monitoring equipment was calibrated where no standard exists; evaluation of external providers; and, only if you design products or services, design and development records. This is a selection, not a full list. See ISO's guidance for the full list: https://www.iso.org/files/live/sites/isoorg/files/archive/pdf/en/documented_information.pdf
Not required, but can add value
The same guidance lists documents that are not specifically required but "can add value", including organization charts, process maps, procedures, work instructions, specifications, quality plans, quality manuals and forms. You may keep some of these. If you keep a quality manual, update its clause references for the 2026 edition. Keep only what helps people do their work.
What the 2026 edition changes
Global ACI, which sets transition rules for accredited certification, reports that ISO 9001:2026 includes a "new phrase for documented information" and clarifies that "documented information shall be available" (TECH-3-TR, version 1.0, section 3.1). That is a wording change. It is not a reason to stop keeping evidence.
Global ACI's summary of the 2026 changes doesn't list new documented-information requirements apart from the wording change above. We haven't checked that against the standard itself, so check your copy.
Areas Global ACI and UKAS highlight, where you will want to be able to show how you have covered them:
Risks and opportunities, now handled separately (clause 6.1)
Planning of changes (clause 6.3)
Management review inputs, including changes in interested parties' needs and expectations (clause 9.3.2)
Quality culture and ethical behavior (clauses 5.1.1 and 7.3)
The guidance's lists don't include a risk register, but you still need to be able to show how you dealt with risks and opportunities. A register is one simple way to do that.
Common mistakes
Writing procedures nobody uses. A short system that people follow is easier to keep current than a large one nobody reads.
Throwing away records because of the new "available" wording.
Copying ISO text into your documents. It is copyrighted. Describe how you work in your own words.
Forgetting clause references in existing documents.
Starting from a template without checking what the standard asks for and what your processes need.
A quick way to see what you already have
Our free Gap Analysis Checklist for ISO 9001:2026 lists typical evidence next to each of its 111 plain-English questions, so you can see which documents and records you already keep and where the gaps are. It is available as an Excel workbook and a printable Word version.
The checklist paraphrases requirements in our own words. It is not ISO text, you will still need your own copy of the standard, and using it does not promise a pass or certification.
Sources
ISO/TC 176/SC 2, "Guidance on the requirements for Documented Information of ISO 9001:2015": https://www.iso.org/files/live/sites/isoorg/files/archive/pdf/en/documented_information.pdf
Global ACI, TECH-3-TR, Transition Requirements for ISO 9001:2026, section 3.1 (issued September 4, 2026, version 1.0): https://global-aci.org/en/news/global-aci-publishes-transition-requirements-for-iso-90012026/
UKAS technical bulletin, "QMS ISO 9001:2026 transition": https://www.ukas.com/resources/technical-bulletins/qms-iso-9001-2026-transition/
ISO, ISO 9001 page: https://www.iso.org/standard/9001
All sources checked September 30, 2026. Clearline Systems is not affiliated with or endorsed by ISO.