The Shift That Changes Everything: "Available" vs. "Retained"
Before diving into the full list of what ISO 9001:2026 requires, there is one change in Clause 7.5 that practitioners need to understand immediately: the word "available" has been added alongside "retained" for documented information requirements.
In ISO 9001:2015, the standard required that certain documented information be "retained" — meaning you must keep it as evidence that something happened. ISO 9001:2026 strengthens this by requiring that documented information also be "available" — meaning it must be accessible to the people who need it, at the time they need it, in the format they can use.
This distinction is not semantic. An organization that stores corrective action records in a filing cabinet that only the quality manager can access has "retained" the information. Under ISO 9001:2026, that same organization may not have made it "available" to the production supervisors who need to reference it during process changes. The practical implication is that document management systems, access controls, and retrieval processes are now more directly in scope for transition audits.
What ISO 9001:2026 Actually Requires: The Complete List
The standard distinguishes between two categories of documented information. The first is information that must be "maintained" — the equivalent of what the previous version called documents. These describe how things are done and are updated when processes change. The second is information that must be "retained" — the equivalent of records. These are evidence that something happened and are preserved unchanged.
The 4 Mandatory Maintained Documents
ISO 9001:2026 requires organizations to maintain documented information in four areas:
| Document | What It Must Include | ISO 9001:2026 Requirement |
|---|---|---|
| Scope of the QMS | Boundaries, applicable products/services, any exclusions with justification | Clause 4.3 |
| Quality Policy | Commitment to quality, framework for objectives, commitment to continual improvement | Clause 5.2 |
| Quality Objectives | Measurable targets at relevant functions, with resources, responsibility, timeline, evaluation method | Clause 6.2 |
| Determined necessary information | Whatever the organization determines is needed for QMS effectiveness | Clause 7.5.1 |
The fourth item is the one that trips organizations up. The standard does not prescribe a fixed list of procedures. Instead, it requires organizations to determine what documented information their specific system needs to operate effectively. For a 10-person professional services firm, this might be three procedures. For a 500-person manufacturer with complex production processes, it might be thirty. The auditor's job is to assess whether your determination was reasonable, not to check boxes against a fixed list.
Key Insight
The Quality Manual is not required.: ISO 9001 removed the Quality Manual requirement in 2015 and ISO 9001:2026 does not restore it. Organizations that still maintain a Quality Manual are doing so for marketing purposes (customer supplier audits often expect to see one) or organizational convenience — not for compliance. The standard does not care.
The 20 Mandatory Retained Records
These are the pieces of evidence the standard explicitly requires organizations to keep. Unlike the maintained documents, these cannot be substituted with judgment — if the record does not exist, it is a nonconformity.
Resources and People
- Evidence that monitoring and measurement equipment is fit for purpose (calibration certificates, verification records)
- The basis used for calibration when no internationally traceable standard exists
- Evidence of competence for staff whose work affects QMS performance (training records, qualifications, experience evidence)
Operations, Products and Services
- Evidence that products and services conform to requirements (inspection records, test results)
- Results of customer requirement reviews (contract reviews, order acceptance records)
- Records of any new or changed customer requirements
Design and Development (only if the organization performs design and development)
- Records of design and development inputs
- Records of design and development controls (review, verification, validation)
- Records of design and development outputs
- Records of design and development changes
Supply Chain and Customer Property
- Records of evaluation, selection, monitoring, and re-evaluation of external providers (approved supplier list, performance reviews)
- Records of customer property that is lost, damaged, or otherwise unsuitable
Production and Service Provision
- Records of changes in production or service provision
- Records of conformity with acceptance criteria for product or service release
- Records of nonconforming outputs and actions taken
Performance Evaluation
- Results of monitoring and measurement of QMS performance
- Internal audit programme and audit results
- Results of management reviews (meeting minutes capturing all required inputs and outputs)
Improvement
- Records of nonconformities and subsequent actions taken
- Results of corrective actions (verification of effectiveness, closure records)
What ISO 9001:2026 Adds: Digital and AI-Generated Documented Information
Stay Current
ISO 9001:2026 publishes September 16, 2026. Get weekly briefings.
ISO 9001:2026 explicitly acknowledges that documented information may be digital, automated, or AI-generated. This is a significant clarification that addresses the reality of how modern organizations actually operate. Electronic signatures, automated inspection records, AI-generated quality reports, and digital calibration certificates are all acceptable forms of documented information — provided they meet the control requirements of Clause 7.5.2 and 7.5.3.
The control requirements have not changed: documented information must be identified (title, reference, version), reviewed and approved, available where needed, protected from loss or unauthorized changes, and controlled for distribution and access. What has changed is that the standard now explicitly recognizes that these controls can be implemented digitally rather than through paper-based systems.
Warning
AI-generated documented information requires the same controls as any other documented information.: An AI-generated inspection report must still be identified, approved, and protected. Organizations that implement AI-assisted quality management tools will need to ensure their document control procedures cover AI-generated outputs explicitly — this is likely to be an area of focus in transition audits.
The Two Most Common Documented Information Failures in Audits
Understanding what auditors actually find helps organizations prioritize their preparation. Based on patterns reported by certification bodies, two categories of finding appear consistently.
The orphan document. A procedure or work instruction that is being used in practice but is not in the document register, has no version number, and has no review record. The auditor finds it during a process walk-through — someone is following it, but it has never been formally controlled. This is typically a major nonconformity because it means the organization cannot demonstrate that the document has been reviewed, approved, or kept current.
The ghost record. A record that should exist but does not. Equipment was used before calibration was verified. A change was made to a process without a documented review. A supplier was added to the approved list without an evaluation record. These are the most common corrective action findings because they represent gaps in the evidence trail that auditors use to verify that the system is actually operating as described.
Both failures have the same root cause: document control is treated as a compliance exercise rather than an operational discipline. Organizations that integrate document control into their daily workflows — where creating and updating records is part of how work gets done, not an additional step — consistently perform better in audits than organizations that maintain a separate "QMS layer" that gets dusted off before certification visits.
How to Structure Your Documented Information for ISO 9001:2026
The standard prescribes no required structure, but practitioners who have implemented multiple QMS certifications consistently recommend a four-tier model that scales from small professional services firms to large manufacturers.
Tier 1 — Strategic documents: Quality policy, scope, organizational context, interested parties register, risks and opportunities register, quality objectives. These are the "what" of the system. Five to ten documents for most organizations.
Tier 2 — Process maps and procedures: Documents that describe how key processes work. Sales, production, service delivery, purchasing, internal audit, document control, management review. The "how" at the business level. Ten to twenty documents for a typical mid-size organization.
Tier 3 — Work instructions and forms: Detailed how-to documents and controlled forms. Lives alongside the work, used by the people doing it. Quantity varies significantly based on process complexity and workforce competence.
Tier 4 — Records: Completed forms, reports, certificates, evidence. Generated by operating the system. Stored according to the organization's retention schedule.
The most common implementation mistake is starting with templates from a previous organization or a consultant's standard package and trying to retrofit them to the current context. The result is documentation that describes how someone else's organization works, not yours — and auditors can tell the difference.
Retention Periods: What ISO 9001:2026 Requires
ISO 9001:2026 does not specify minimum retention periods. The standard requires organizations to determine appropriate retention periods based on customer requirements, regulatory requirements, statutory requirements, and contractual requirements. This is the organization's responsibility, not the standard's.
A practical default for most quality records is five to seven years from the end of the relevant audit cycle. Records related to product safety, regulated industries, or long-life capital goods typically require longer retention. Records for design and development of medical devices, defense equipment, or aerospace components are governed by separate, often much longer, regulatory requirements.
The key requirement is that the retention policy be documented and consistently applied. Auditors will ask to see it.
Preparing Your Documented Information for Transition Audits
Transition audits under IAF MD 26 will assess whether the organization has addressed the documented information changes in ISO 9001:2026. Based on the standard's requirements and early guidance from certification bodies, the highest-priority preparation areas are:
- Availability review: Audit your current document management system against the new "available" requirement. Who needs access to what documented information? Can they get it when they need it? Are there bottlenecks or access restrictions that would prevent this?
- Digital documentation controls: If your organization uses electronic QMS software, ensure it meets the control requirements of Clause 7.5.2 and 7.5.3. Version control, approval workflows, access controls, and audit trails should all be demonstrable.
- AI-generated content policy: If any documented information is AI-generated or AI-assisted, establish a policy for how it is reviewed, approved, and controlled. This is a new area that auditors are beginning to probe.
- Document register audit: Walk through your complete document register and verify that every controlled document has a current version, an approval record, and a review date. Identify and remediate any orphan documents.
- Records gap analysis: Map every mandatory retained record against your current evidence. Identify any ghost records — areas where the record should exist but does not — and implement the processes to generate them consistently.
Key Insight
The transition audit is not just a document review.: Auditors will verify that documented information is being used in practice, not just maintained in a system. Process walk-throughs, interviews with staff, and sampling of records are all part of how transition auditors assess whether the organization's documented information is genuinely supporting QMS operation.
Key Resources
- ISO 9001:2026 Complete Transition GuideISO 9001:2026 Complete Transition Guide/article/how-to-transition-iso-9001-2015-to-2026 — Full step-by-step transition methodology
- ISO 9001:2026 Gap Analysis TemplateISO 9001:2026 Gap Analysis Template/resources/gap-analysis-template — Free PDF covering all documented information requirements
- ISO 9001:2026 Transition ChecklistISO 9001:2026 Transition Checklist/resources/transition-checklist — 30-item checklist including documentation review steps
- ISO 9001:2026 GlossaryISO 9001:2026 Glossary/glossary — Definitions of documented information, records, and related terms
- IAF MD 26 Transition GuidanceIAF MD 26 Transition Guidance/article/iaf-mandatory-document-iso-9001-2026-transition-guidance — What certification bodies are required to assess
- ISO 9001:2026 Internal Audit GuideISO 9001:2026 Internal Audit Guide/article/iso-9001-2026-internal-audit-complete-guide — How to audit documented information in practice
- ISO.org — ISO 9001 FamilyISO.org — ISO 9001 Familyhttps://www.iso.org/iso-9001-quality-management.html — Official standard information
- IAF MD 26IAF MD 26https://www.iaf.nu/articles/Mandatory_Documents_/38 — IAF transition requirements for certification bodies
Frequently Asked Questions
Does ISO 9001:2026 require a Quality Manual?
No. The Quality Manual requirement was removed in ISO 9001:2015 and is not restored in ISO 9001:2026. Organizations may maintain a Quality Manual for marketing or organizational convenience, but it is not required for certification.
How many mandatory procedures does ISO 9001:2026 require?
Zero explicitly mandatory procedures. The previous version (ISO 9001:2008) required six mandatory procedures. ISO 9001:2015 and ISO 9001:2026 replaced this with a requirement to maintain documented information that the organization determines is necessary for QMS effectiveness.
Can documented information be stored in cloud software like Google Drive or Confluence?
Yes, provided the tool meets the document control requirements: version control, approval workflows, access controls, retrieval capability, and retention management. Most modern collaboration platforms can be configured to meet these requirements.
What is the difference between "maintained" and "retained" documented information?
Maintained documented information describes how things are done and is updated when processes change (equivalent to the old concept of "documents"). Retained documented information is evidence that something happened and is preserved unchanged (equivalent to the old concept of "records").
What does the new "available" requirement mean in practice?
ISO 9001:2026 requires documented information to be available (accessible to those who need it) in addition to retained (kept as evidence). This means organizations must ensure that the right people can access the right information at the right time — not just that the information exists somewhere in a system.
