ISO 9001 Procedures List – What You Actually Need
When people search for an ISO 9001 procedures list, they are usually looking for a simple answer. They want to know what procedures are actually needed, what an auditor will expect to see, and whether they need to create a huge pile of documents just to meet the standard.
That is understandable, because a lot of the advice online either makes ISO 9001 look far more complicated than it needs to be or oversimplifies it so much that it becomes misleading.
The reality sits somewhere in the middle.
ISO 9001 does not require every company to have the same set of procedures written in the same way. What it does require is that your quality management system is controlled, consistent, and capable of delivering products or services in a reliable way. For most organisations, that means having a number of key procedures in place, whether they are called procedures, processes, workflows, or work instructions.
What procedures are actually required under ISO 9001?
ISO 9001:2015 is less prescriptive than older versions of the standard when it comes to documented procedures. It does not give you a fixed master list and say you must have a separate procedure for each one.
Instead, it expects you to maintain documented information where necessary for the effectiveness of the quality management system and to retain records that show things are being carried out as planned.
In practice, most organisations operating a workable ISO 9001 system end up with procedures covering areas such as document control, control of records, internal audits, nonconformity and corrective action, management review, training or competence, operational control, and handling customer issues or complaints.



Depending on the business, there may also be procedures for design and development, purchasing or supplier control, production or service provision, calibration, inspection and testing, and control of externally provided processes.
So although the standard may not force every one of these into a separate formal procedure, most businesses still need them in some form if they want the system to function properly.
The procedures most companies usually need
A practical ISO 9001 procedures list often includes document control, so people know how documents are approved, updated and removed when obsolete. It usually includes control of records, so evidence is retained properly and can be found when needed.
Internal audit is another core area, because the organisation needs a defined way of checking whether the system is working. Management review also needs structure, even if it is carried out in a straightforward way, because leadership is expected to review performance, risks, opportunities and improvement needs.
Nonconformity and corrective action is one of the most important procedures in the system, because this is how issues are identified, investigated and prevented from recurring. Competence and training are also commonly documented, particularly where roles affect quality outcomes. Supplier control is another frequent area, especially where poor supplier performance could affect the final product or service.
Then there are the operational procedures that are specific to the business itself. A construction firm will need different process controls from a training provider, manufacturer, software company or professional services business. This is where generic template packs often start to fall down, because they treat every organisation as though it operates in the same way.
What auditors usually expect to see
Auditors are not normally looking for a document with a specific title just for the sake of it. They are looking for evidence that key activities are defined and controlled.
For example, if you tell an auditor that nonconformities are investigated and corrective action is taken, they will want to see how that happens in practice. That may be through a written procedure, a workflow, a form, a ticketing system, meeting records, or a combination of these. The important point is that the process is clear, followed, and capable of producing consistent results.
The same applies to areas like internal audits, supplier reviews, training, customer feedback and operational controls. If the business says it does these things, there should be a clear and repeatable method behind them.
This is why a simple list of procedure names is never enough on its own. The real question is whether those procedures fit together and reflect how the organisation actually works.
Where businesses often go wrong
One common mistake is assuming that fewer procedures always means a simpler system. In reality, this often just means the organisation has gaps that people are expected to fill from memory. That tends to work until staff change, work pressure increases, or an audit starts asking for consistency and evidence.
Another mistake is downloading a generic pack full of procedures that sound impressive but do not match the business. That creates a different problem, because now the company has documents that say one thing while the business does something else. Once that gap appears, it usually spreads across audits, training, records and day-to-day operations.
A third mistake is treating procedures as isolated documents. In a functioning quality management system, procedures connect to objectives, risks, audit findings, complaints, corrective actions, supplier performance and management review. If they sit separately with no clear links, the system becomes much harder to maintain.
A simple example of how this fits together
Take something straightforward like handling a customer complaint.
At first glance, this might just look like one procedure. But in practice it links to several parts of the quality management system. The complaint needs to be recorded. The issue may trigger a nonconformity.

A corrective action may be needed. Trends may need reviewing in management review. Staff may need further training. Internal audits may later test whether the revised process is working.
So even a single process often has several connections around it. That is why building an ISO 9001 system from disconnected templates can become frustrating quite quickly.
What a usable ISO 9001 procedure set should look like
A usable procedure set should be clear enough for people to follow, practical enough to reflect the real business, and structured enough that it supports audit and improvement. It should not read like a textbook. It should explain who does what, when they do it, what records are produced, and what happens when something goes wrong.
It should also be proportionate. A small service business does not need the same level of procedural detail as a complex manufacturer with multiple stages of inspection, external providers and tightly controlled production conditions. The system should fit the organisation, not the other way around.
If you want a complete, working system rather than a disconnected list of procedures
This is exactly where many businesses get stuck. They start by searching for an ISO 9001 procedures list, but what they really need is not just a list. They need a coherent set of procedures that works together as part of a wider quality management system.
That is what The Compliance Companion is designed to help with. Instead of giving you isolated documents to piece together yourself, it provides a structured system that helps align procedures, records and supporting documents in a way that is practical to implement and maintain.
If you are at the stage where you are trying to work out what procedures you actually need and how they should fit together, that is usually the point at which a proper framework becomes far more useful than another generic template.
This is exactly the gap The Compliance Companion is designed to fill. Instead of providing isolated documents, it gives you a structured, interlinked system designed to be implemented in a practical way (not just sit on a shelf).