Skip to content

explainer

ISO 9001 Clause 8 (Operation) Explained

Clause 8 is the largest clause in ISO 9001:2015 and the one that generates the most audit findings. It is also the clause most often implemented backwards — written as a set of procedures to satisfy an auditor rather than a description of how the business actually delivers work.

This is a working reference for the whole of Clause 8: what each section requires, what auditors look for, and where the findings cluster. If you are preparing for a certification audit or trying to close a nonconformity, jump to the section you need.

What Clause 8 is for

Clauses 4 through 7 build the conditions: context, leadership, planning, resources. Clause 9 measures. Clause 10 improves. Clause 8 is where the work happens — the controls over how you plan production or service delivery, agree what the customer wants, design it if design is yours, control your suppliers, do the work, check it, and handle it when something goes wrong.

That framing matters practically. A Clause 8 system that does not describe your real operations is not a lean system, it is a fictional one, and auditors are experienced at spotting the gap between the procedure and the shop floor.

One structural point before the detail: if you have no design and development responsibility, Clause 8.3 can be excluded from your scope — and excluding it is one of the recognised factors that can reduce your certification audit days under IAF MD 5. Exclusions must be justified and must not affect your ability to deliver conforming product. Do not exclude 8.3 because it is inconvenient; do exclude it if you genuinely manufacture to customer drawings.


8.1 Operational planning and control

The requirement is to plan, implement and control the processes needed to meet requirements — determining requirements, establishing acceptance criteria, determining the resources needed, implementing process control, and keeping documented information sufficient to have confidence the processes were carried out as planned.

It also requires you to control planned changes and review the consequences of unintended changes, taking action to mitigate adverse effects. And it requires you to ensure that outsourced processes are controlled — a hook that points forward to 8.4.

Where findings come from. Two patterns dominate. The first is acceptance criteria that exist in someone’s head rather than in a record — the inspector knows what good looks like, but nothing defines it, so nothing can be verified or handed over. The second is change: production changes get made for sound operational reasons and nobody documents the review. When an auditor asks how you knew a change was safe, “we discussed it” is not an answer that survives.

What to do about it. Make the documented information proportionate. You do not need a procedure for everything; you need enough record that a competent person could confirm the process ran as planned. And put a lightweight change review in place before you need it — a short form, a signature, a note of what was considered.


8.2 Requirements for products and services

Four sub-clauses that together cover the customer-facing edge of the system.

8.2.1 Customer communication

Covers providing information about products and services, handling enquiries, contracts and orders including changes, obtaining customer feedback including complaints, handling or controlling customer property, and establishing requirements for contingency actions where relevant.

The contingency requirement is frequently missed. It does not demand a full business continuity plan, but where a disruption would materially affect your ability to deliver, an auditor will expect to see that you have thought about it.

8.2.2 Determining requirements

Before committing to supply, you must ensure requirements are defined — including applicable statutory and regulatory requirements and anything you consider necessary yourself — and that you can meet the claims you make.

The statutory and regulatory element is where findings cluster. Many organisations document customer requirements thoroughly and record nothing about the regulatory requirements applying to their product. If your product is subject to CE marking, FDA regulation, FCC rules, RoHS, or industry-specific safety standards, that determination needs to be visible.

8.2.3 Review of requirements

You must review requirements before committing — covering customer-specified requirements including delivery and post-delivery activities, requirements not stated but necessary for the known intended use, your own requirements, statutory and regulatory requirements, and any contract or order requirements differing from those previously expressed. Where the customer gives no documented statement, you must confirm requirements before acceptance. Documented information on the review and on any new requirements must be retained.

Where findings come from. Verbal orders accepted without confirmation, and requirements changing during a job without a re-review. The second is more common and more damaging — the original review is immaculate, then three change requests arrive by email and none is reviewed against capability.

8.2.4 Changes to requirements

Where requirements change, you must amend the relevant documented information and make relevant people aware. Short clause, frequent finding: the change gets made, production is told, and the drawing, the work instruction or the inspection criteria still says the old thing.


8.3 Design and development

Excludable if you have no design responsibility. If you do, this is the most procedurally demanding part of the standard, running across seven sub-clauses.

8.3.1 and 8.3.2 — General and planning

You must establish, implement and maintain a design and development process. In planning it, you consider the nature, duration and complexity of the activities; required process stages including reviews; verification and validation activities; responsibilities and authorities; internal and external resource needs; interfaces between people involved; the need for customer and user involvement; requirements for subsequent provision; the level of control expected by customers and other interested parties; and the documented information needed to demonstrate requirements were met.

Note the distinction between verification and validation, because it is regularly conflated and regularly found. Verification asks whether outputs met the input requirements — did we build it to spec. Validation asks whether the resulting product meets the requirements for its specified application or intended use — does it work for the customer’s actual purpose. Both are required, and evidence of one does not discharge the other.

8.3.3 Design inputs

Requirements essential for the specific type of product, including functional and performance requirements, information from previous similar activities, statutory and regulatory requirements, standards or codes of practice you have committed to implement, and the potential consequences of failure. Inputs must be adequate, complete and unambiguous, and conflicting inputs must be resolved.

“Potential consequences of failure” is the most commonly omitted input. It is the standard’s hook for risk-based thinking inside design. A design FMEA or an equivalent hazard analysis discharges it cleanly.

8.3.4 Design controls

Results to be achieved must be defined; reviews conducted to evaluate ability to meet requirements; verification conducted to ensure outputs meet inputs; validation conducted to ensure resulting products meet requirements for the specified application or intended use; and any necessary actions taken on problems determined. Documented information of these activities must be retained.

The classic finding here is a review with no record of the problems raised. A design review minute that says only “design approved” is weak evidence. Auditors read reviews looking for evidence that someone challenged something.

8.3.5 Design outputs

Outputs must meet input requirements, be adequate for subsequent processes, include or reference monitoring and measuring requirements and acceptance criteria, and specify the characteristics essential for the intended purpose and for safe and proper provision.

8.3.6 Design changes

Changes made during or after design must be identified, reviewed and controlled to the extent necessary to ensure no adverse impact on conformity. Documented information must be retained on the changes, the results of reviews, the authorisation of the changes, and the actions taken to prevent adverse impacts.

Change control is where design systems fail in practice. The original design file is exemplary; the eighteen changes since are an email thread.


8.4 Control of externally provided processes, products and services

This is Clause 8’s second-largest source of findings, and the one most likely to be under-built in small organisations.

8.4.1 General

You must ensure externally provided processes, products and services conform to requirements — where they are intended for incorporation into your own product, where they are provided directly to the customer on your behalf, or where a process is provided by an external provider as a result of your decision to outsource.

You must determine and apply criteria for the evaluation, selection, monitoring of performance, and re-evaluation of external providers, and retain documented information of these activities and any necessary actions arising.

The most common finding in the entire clause is an approved supplier list that has not been re-evaluated. Suppliers get approved once, then stay approved indefinitely with no performance monitoring. The standard explicitly requires monitoring and re-evaluation — and the evidence has to show it happened, not that a procedure says it should.

8.4.2 Type and extent of control

Controls must be proportionate to the potential impact on your ability to consistently meet requirements. You must ensure externally provided processes remain within the control of your quality management system, define both the controls you intend to apply to the provider and those you intend to apply to the resulting output, and consider the potential impact of the externally provided item on your ability to meet requirements and on customer satisfaction — determining verification activities necessary to ensure conformity.

Outsourced processes are where organisations most often lose the thread. If you outsource heat treatment, plating, calibration or sterilisation, that process is still inside your QMS. “Our supplier is certified” is a control, but it is rarely a sufficient one on its own.

8.4.3 Information for external providers

You must communicate requirements to providers covering the processes, products and services to be provided; approval of products and services, methods, processes and equipment, and release; competence including required qualification of persons; the provider’s interactions with you; the control and monitoring you will apply; and any verification or validation activities you or your customer intend to perform at the provider’s premises.

Findings here are usually purchase orders that specify a part number and a quantity and nothing else — no revision level, no applicable specification, no inspection requirement.


8.5 Production and service provision

8.5.1 Control of production and service provision

You must implement production and service provision under controlled conditions, which include: documented information defining the characteristics of the products and services and the results to be achieved; availability and use of suitable monitoring and measuring resources; monitoring and measurement activities at appropriate stages to verify criteria for control of processes or outputs and acceptance criteria have been met; use of suitable infrastructure and environment; appointment of competent persons including any required qualification; validation and periodic revalidation of any process where the resulting output cannot be verified by subsequent monitoring or measurement; implementation of actions to prevent human error; and implementation of release, delivery and post-delivery activities.

Special processes — the validation requirement for processes whose output cannot be verified afterwards — catch people out. Welding, heat treatment, plating, adhesive bonding and sterilisation typically qualify: you cannot inspect the result without destroying it, so the process itself must be validated and the operators qualified.

“Actions to prevent human error” is new relative to older revisions and frequently unaddressed. Poka-yoke, checklists, verification steps, system constraints — something visible that shows you designed against mistakes rather than relying on care.

8.5.2 Identification and traceability

You must use suitable means to identify outputs where necessary to ensure conformity, identify the status of outputs with respect to monitoring and measurement requirements throughout production, and — where traceability is a requirement — control the unique identification of outputs and retain documented information to enable traceability.

Inspection status is the recurring gap: material that has been inspected and material that has not, sitting in the same area, distinguishable only by asking someone.

8.5.3 Property belonging to customers or external providers

Care must be exercised over property belonging to customers or external providers while it is under your control. You must identify, verify, protect and safeguard it — and when it is lost, damaged or otherwise found unsuitable, report this to the owner and retain documented information.

Often read as covering only physical goods. It covers customer data and intellectual property too, which is where it intersects with ISO 27001 for organisations holding both.

8.5.4 Preservation

Outputs must be preserved during production and service provision to the extent necessary to ensure conformity — covering identification, handling, contamination control, packaging, storage, transmission or transportation, and protection.

8.5.5 Post-delivery activities

You must meet requirements for post-delivery activities, and in determining their extent consider statutory and regulatory requirements, the potential undesired consequences associated with the products and services, the nature, use and intended lifetime of the products and services, customer requirements, and customer feedback.

Warranty, field service, recycling, final disposal — the further your product goes after it leaves, the more this clause expects of you.

8.5.6 Control of changes

Changes for production or service provision must be reviewed and controlled to the extent necessary to ensure continuing conformity. Documented information must be retained describing the results of the review, the persons authorising the change, and any necessary actions arising.

Note this is distinct from 8.3.6, which covers design changes. Production changes need their own review and their own record, and organisations with strong design change control frequently have none for production.


8.6 Release of products and services

You must implement planned arrangements at appropriate stages to verify that requirements have been met. Release must not proceed until planned arrangements have been satisfactorily completed, unless otherwise approved by a relevant authority and, where applicable, by the customer. Documented information on release must be retained, including evidence of conformity with acceptance criteria and traceability to the persons authorising release.

Traceability to the authorising person is the detail most often missing. A signed-off inspection record with an illegible initial and no way to identify who it belongs to does not meet this. Auditors check.


8.7 Control of nonconforming outputs

8.7.1

Outputs that do not conform must be identified and controlled to prevent unintended use or delivery. Action must be appropriate to the nature of the nonconformity and its effect on conformity — and this applies also to nonconforming products and services detected after delivery, and during or after the provision of services.

The standard names the options: correction; segregation, containment, return or suspension of provision; informing the customer; and obtaining authorisation for acceptance under concession.

Conformity must be verified when nonconforming outputs are corrected.

8.7.2

Documented information must be retained that describes the nonconformity, describes the actions taken, describes any concessions obtained, and identifies the authority deciding the action.

Two findings recur. First, a nonconformity log that records what happened but not who decided the disposition. Second — and more serious — nonconformities identified after delivery being handled informally as customer service and never entering the system at all. If a customer returns a part and you replace it without logging it, the standard’s requirement has not been met and, more importantly, your corrective action process has been starved of its most valuable input.


Where Clause 8 findings actually cluster

Across certification and surveillance audits, the concentrations are consistent:

  1. 8.4.1 — supplier re-evaluation not performed, or performed with no record
  2. 8.5.6 — production changes made without documented review
  3. 8.7.2 — post-delivery nonconformities handled outside the system
  4. 8.2.3 — requirements changing after the initial review with no re-review
  5. 8.3.6 — design changes controlled less rigorously than the original design
  6. 8.6 — release records that do not identify the authorising person

The pattern underneath all six is the same: the system is built for the first pass and not for the second. Initial supplier approval, initial requirement review, initial design, initial release — all documented well. What happens afterwards, when things change, is where the evidence thins out.

If you are preparing for an audit and want to spend your remaining time efficiently, look at change and look at what happens after delivery. That is where the findings are.


This article summarises requirements of ISO 9001:2015 for practitioners. It is not a substitute for the standard itself, which is copyright ISO and available for purchase from ISO or your national standards body. Where this article and the standard differ, the standard governs.