ISO 9001 QM manual template: sample structure, obligations and audit practice
ISO 9001:2015 no longer requires a classic QM manual, but in practice auditors still require a resilient structure. This template shows the structure, mandatory chapters and documentation.
DIN EN ISO 9001:2015 has formally abolished the classic QM manual, but in Chapter 7.5 it requires documented information that proves the scope, the processes and their interaction. In audit practice, almost every certifier continues to require a structured manual because it forms the only bracket around processes, procedural instructions and evidence.
This article provides a complete model structure, explains the ten chapters of the standard and shows which templates you need as a quality management representative. You will learn how the manual is interlinked with the reporting line, appointment certificate and audit templates so that the auditor does not have to wait on audit day.
Key Takeaways
- ISO 9001:2015 does not require a QM manual, but does require documented information according to Chapter 7.5 with a clear scope and process map.
- A model structure along the ten standard chapters makes the manual navigable for auditors and reduces findings in the certification audit.
- With 37 ready-to-use audit templates, appointment certificate and reporting line, the manual becomes a living system instead of a filing cabinet document.
What ISO 9001:2015 really requires: compulsory or free?
The 2015 revision deleted the term QM manual from the standard text. What remains is Chapter 7.5 Documented Information, which stipulates the scope, policy, goals and all process-relevant records. The form is free, the evidence is not.
In practice, auditors continue to expect a document that addresses the standard chapter by chapter. Without this bracket, procedural instructions, work instructions and records quickly become lost in individual files. A QM manual is therefore not an end in itself, but the map of the entire management system.
In the narrower sense, the policy (chapter 5.2), the goals (6.2), the scope (4.3) and all process descriptions that are necessary for the conformity of the products are mandatory. These four elements form the hard, mandatory framework of every QM template.
In addition, there are records from internal audits (9.2), management assessment (9.3), corrective measures (10.2) and risk assessment (6.1). These must be accessible at any time, classically on paper, modernly in a structured QMB workspace.
Anyone who sees the manual as purely a standard fulfilment is creating dead paper. Anyone who creates it as an operational control document shortens audit preparation from weeks to days and makes the handover between QMB generations easier.
The CIVAC platform bundles the required mandatory documents in 490 ready-to-use audit templates and links them to management via the reporting line so that responsibility remains visible.
Sample structure: The ten chapters as a manual structure
A proven structure follows standard chapters 4 to 10 directly. This order saves the auditor from having to search because each chapter in the manual corresponds to the same numbered standard chapter. Anyone who invents their own logic creates friction.
Chapter 4 describes the context of the organisation, i.e. stakeholders, scope and process map. Chapter 5 is dedicated to leadership, politics and roles, especially the appointment document of the quality management representative. Chapter 6 covers planning, risks and opportunities.
Chapter 7 is the cross-sectional chapter: resources, personnel, infrastructure, knowledge, communication and the famous documented information. Chapter 8 is the operational core with product realization, supplier approval, development and control of defective results.
Chapter 9 covers performance assessment, customer satisfaction, internal audit and management review. Chapter 10 concludes with continuous improvement, corrective actions, and follow-up. This sequence is standard logic and audit practice at the same time.
There are three preamble elements in front of these seven main chapters: cover sheet with versioning and approval, table of contents with cross-references and a list of abbreviations and terms according to ISO 9000:2015.
A pure text template is not enough; each chapter needs linked procedural instructions, forms and records. In a compliance platform and officer-as-a-service environment like CIVAC, this integration is created automatically via tags and reporting lines.
Mandatory documents in detail: What really has to be present
The standard names around 20 pieces of documented information that must be explicitly available. This includes scope (4.3), quality policy (5.2.2), quality goals (6.2.1) and planning to achieve goals. These four are the basis of every manual.
At the operational level, the standard requires evidence of the competence of the employees (7.2), the suitability of the infrastructure (7.1.3) and the control of the monitoring and measuring equipment (7.1.5). Anyone who uses testing equipment must keep calibration certificates and traceability certificates.
In the value creation process, records for product realization (8.1), requirements testing (8.2.3.2), development inputs and outputs (8.3), supplier evaluation (8.4.1) and the release of products and services (8.6) are mandatory.
In addition, there are records of non-conformities (8.7.2), internal audits (9.2.2), management review (9.3.3) and corrective actions (10.2.2). These are the classics that are almost always checked in the audit.
Requirement of templates does not mean requirement of forms. A structured Excel list, a ticket system or a CIVAC workspace entry provides proof as long as the date, person responsible and content are traceable. The appointment certificate, signed, filed, verifiable.
Consolidation is worthwhile for companies with multiple locations or multiple agent roles. The Overview of the 25 officer roles shows where QMB, ESG and compliance officers can use the same evidence.
Procedural instructions: The bridge between norm and everyday life
The QM manual describes the What, the procedural instructions describe the How. Classic mandatory procedures concern document control, internal audit, corrective measures, control of defective products and training planning. These five form the minimum inventory.
A procedural instruction has a fixed structure: purpose, scope, terms, responsibilities, process with flowchart, applicable documents and records. Anyone who uses this structure consistently makes training and audit discussions easier.
The instructions must be process-specific and not overloaded. 80 percent of findings arise because real processes deviate from the instructions or because instructions are out of date. Version status, release date and revision history belong in every header area.
Versioning has a life of its own. Without clear guidance, several stands circulate, employees work according to outdated specifications, the auditor recognises this immediately. A workspace with central release logic prevents this classic.
Cross-references build a bridge to the manual: Each procedural instruction refers to the higher-level standard chapter, the manual refers to the subordinate instruction. This creates a navigable system instead of a stack.
Licence the workspace for your internal representatives or have our representatives order it. In both models, CIVAC delivers the procedural instructions as changeable templates with example texts and flowcharts.
Scope and Exclusions: Common Audit Findings
The scope according to Chapter 4.3 is one of the most common sources of error. He mustprecisely name products, services, locations and processes. General formulations such asall activities at the Musterstadt locationare not enough for auditors.
According to ISO 9001:2015, exclusions are only permitted for requirements in Chapter 8. For example, if you do not do any development, you can exclude Chapter 8.3, but you must justify and document this in the manual. An exclusion without justification leads to the main deviation.
Interested parties according to 4.2 are also often treated superficially. Customers, authorities, owners, employees and suppliers must be identified with their requirements. A table with stakeholder, requirement and measure columns serves this purpose.
The process map according to 4.4 requires interactions, inputs, outputs and those responsible. A mere org chart is not enough. It is common to divide them into management processes, core processes and support processes, each with key figures.
A realistic scope avoids excessive demands. If you certify all locations at the same time without ensuring that they all have the same level of maturity, you risk findings across the entire organisation. Phased expansion is legitimate and permissible in the norm.
The CIVAC audit templates contain tested formulations for scope, stakeholder analysis and process map, tailored to typical SME structures. The auditor calls, the evidence is ready.
Risks and opportunities: Chapter 6.1 without formal risk management
Chapter 6.1 calls for the consideration of risks and opportunities, but does not prescribe a specific method. ISO 31000 or a lean SWOT analysis are both acceptable. What is important is the link with the quality goals and with concrete measures.
The most common weakness in the audit: risks are described generically without measures being derived or effectiveness assessed. A risk without a documented effectiveness control is an entry, not a risk management.
A risk matrix with probability of occurrence, impact and risk class has proven successful. Measures, responsible persons and dates are determined for each risk. In the follow-up audit, the auditor checks whether these measures were implemented and effective.
Opportunities often fall by the wayside. The standard requires symmetrical treatment: ideas for improvement, market entry or new customer groups must be documented if they are pursued strategically. The same applies here: measure plus effectiveness.
Dovetailing with other standards is worthwhile. Anyone who operates an ISO/IEC 27001:2022 in parallel can map information security risks with quality risks in a common methodology instead of running two parallel systems.
CIVAC provides an integrated risk matrix as an audit template that maps ISO 9001, ISO 27001 and LkSG requirements in a table, with filters according to standard and responsible person.
Internal audit and management review: Mandatory appointments throughout the year
Chapter 9.2 requires at least one internal audit per year that covers all processes within a defined cycle. The usual maximum is three years; in practice, an annual run-through of all core processes is recommended.
Planning is risk-based: processes with a high risk class or many findings are checked more frequently. The internal audit may not be checked by those who are responsible for the process themselves. Independence is mandatory, not recommendation.
The audit report contains scope, audit criteria, findings, deviations and recommendations. A major deviation indicates a systemic deficiency, a minor deviation indicates an individual case. This separation makes it easier to prioritise the corrective measures.
The management review according to 9.3 is the bracket around the entire system. It evaluates inputs such as customer satisfaction, process performance, supplier evaluation, audit results and risks, and produces outputs in the form of decisions and resource releases.
A common mistake is the superficial protocol. Auditors expect comprehensible decisions with measures, responsible persons and deadlines. Blanket statements such as the system is effective are not enough.
The CIVAC reporting line connects internal audits, management review and corrective actions in a timeline so that all three obligations are visible as a coherent annual cycle.
Versioning, release and document control
Chapter 7.5.3 requires the governance of documented information: availability, protection, distribution, access, storage, version control and retention. Seven requirements that are bundled in the manual in a document control procedure instruction.
Each document has a cover page or a header with title, document ID, version status, release date and person responsible. The revision history lists the date, change and editor. Without this data, versioning cannot be checked.
Retention periods result from legal requirements: 10 years for commercial books (§ 257 HGB), 6 years for business letters, longer periods for product liability. The retention periods belong in a table within the manual.
The management of external documents, such as customer specifications or supplier standards, is often forgotten. These must also be identified, marked and directed. An input list with a version is sufficient.
The following applies to digital control: separate read and write rights, set up a release workflow, activate automatic versioning. A file share without authorisation logic does not meet the standard because version chaos is foreseeable.
CIVAC offers document control as an integrated workspace service with EU data residency, automatic versioning and a release logic that meets ISO 9001 and ISO/IEC 27001:2022 at the same time.
From manual to living system: your next step
A QM manual based on a template is the beginning, not the result. Only the integration with procedural instructions, records, audits and management evaluation creates a system that is convincing in audits and relieves the burden in everyday life.
Others run compliance like a filing cabinet. We run it like software. The CIVAC platform provides 490 ready-to-use audit templates, a reporting line to management and an appointment document for the quality management representative in one workspace.
Licence the workspace for your internal representatives or have our representatives appointed. Both models deliver the same audit status: documented, versioned, with a clear chain of responsibility. The SLA for external orders is two working days.
Anyone who operates other standards in parallel, such as ISO/IEC 27001:2022 or ISO 14001, benefits from the common database. Risks, key figures and audit findings are maintained once and used multiple times instead of being lost in parallel systems.
Concrete next steps: specify the scope, update the process map, fill in missing procedural instructions with templates, plan internal audits, schedule management reviews. With a structured template, this path can be followed in four to six weeks.
Turn reading into an assignment. Write to info@civac.de or use the contact form on civac.de. We check your initial situation, suggest a course of action and name the appropriate quality management representative for your audit cycle.
FAQ
Is a QM manual still mandatory according to ISO 9001:2015?
Formally no, factually yes. The standard requires documented information in Chapter 7.5 with scope, policy, objectives and process descriptions. In audit practice, certifiers expect a structured document that addresses the ten chapters of the standard.
How many procedural instructions must a manual contain?
The standard does not specify a number but requires procedures for document control, internal audit, corrective action, defective product control and training. These five form the minimum stock, with 5 to 15 more added depending on the industry.
What exclusions are allowed in ISO 9001:2015?
Only requirements from Chapter 8 may be excluded, such as development (8.3), if the company does not engage in development. The exclusion must be justified in the manual, otherwise there is a risk of a major deviation in the certification audit.
How is the manual structured for multiple locations?
A group manual with cross-location specifications and location-specific appendices is common. Scope and process differences are documented for each location. Phased certification of locations is permitted according to the standard and reduces risks.
Who is responsible for releasing the QM manual?
The top management bears responsibility according to Chapter 5.1 and approves the manual. The operational creation typically lies with the quality management representative. The appointment certificate documents this delegation and belongs in the manual or its appendices.
How does CIVAC support the creation of a QM manual?
CIVAC provides 37 audit templates, an appointment certificate and a reporting line as a workspace. You can either licence the system for your internal QMB or order an Officer-as-a-Service, both models with a two-working day SLA.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.