Guide

ISO 9001 Design and Development: Clause 8.3 Practical Guide

ISO 9001 design and development guide: use a practical Clause 8.3 evidence chain for design inputs, reviews, verification, validation, and controlled changes.

Konstantin Dolgan, Ph.D.
Konstantin Dolgan, Ph.D.

Quality Systems Engineer & Product Development Expert

September 2, 2026 12 min read
ISO 9001 Design and Development: Clause 8.3 Practical Guide

At a glance

ISO 9001 design and development guide: use a practical Clause 8.3 evidence chain for design inputs, reviews, verification, validation, and controlled changes.

  • Focus: ISO 9001 design and development · ISO 9001 Clause 8.3
  • Read time: 12 minutes
  • Updated: September 2, 2026

The Short Answer: Make the Development Story Traceable

An effective ISO 9001 design and development process connects a product or service to the need it must meet. It also preserves evidence that the result works as intended. Under the current published edition, ISO 9001 Clause 8.3 concerns design and development of products and services. A useful design and development process ISO 9001 approach is not a generic stage-gate chart. It is a clear, proportionate evidence chain. Decide whether design applies, understand the intended outcome, retain usable inputs, review the work, distinguish verification from validation, and control changes.

ISO identifies ISO 9001:2015 as the current published edition. Its public explanation describes ISO 9001 as a QMS framework for establishing, implementing, maintaining, and improving controlled processes. The next ISO 9001 edition is under development and is expected in September 2026. Until its final text is published, use the current edition for Clause 8.3 decisions. Base those decisions on actual customer, regulatory, and operational commitments, not predictions about draft wording. ISO’s current ISO 9001 overviewISO’s current ISO 9001 overviewhttps://www.iso.org/standard/62085.html is the public starting point.

Reader snapshot: A defensible design-and-development record answers six linked questions: what are we creating, what constraints apply, how did we test our assumptions, what evidence shows the output works in its real use, what changed, and who accepted the handoff?

First Decide Whether Design and Development Applies

Do not begin by asking whether the organization has a document called “design.” Start with the output and the decisions that shape it. Designing a manufactured product, configuring a customer-specific service, developing software, creating a new delivery method, or materially changing an existing offer can all involve a design-and-development decision. Routine repeat production, simple purchasing, or following a customer-controlled specification may call for a different control path.

SituationDecision questionEvidence path that may help
New product or serviceDoes the organization choose characteristics that affect the delivered outcome?Customer need, business case, concept record, design brief.
Customer-specific configurationIs the team making decisions that go beyond applying a fixed, approved specification?Contract review, configuration record, customer approval.
Process or delivery redesignCould the change affect conformity, customer experience, safety, performance, or applicable obligations?Change impact assessment, pilot plan, operational risk review.
Repeat work to an approved specificationIs the work already controlled through a stable production or service-delivery process?Approved specification, work instruction, order review, process evidence.
Externally developed outputWhat does the organization still need to define, accept, verify, validate, or control at the interface?Supplier requirements, acceptance criteria, handoff and approval records.

This table is a practical decision aid, not a prescribed ISO template. The ISO 9001 Auditing Practices Group (APG) publishes educational papers that emphasize process-based and risk-based thinking, while expressly noting that its guidance is not definitive requirements or a universal audit benchmark. Use the APG design-and-development paperAPG design-and-development paperhttps://committee.iso.org/files/live/sites/tc176/files/PDF%20APG%20New%20Disclaimer%2012-2023/ISO-TC%20176-TF_APG-Design%26Development.pdf as contextual reading, then tailor the control path to the organization’s outputs and commitments.

Build a Six-Part Evidence Chain

Stay Current

ISO expects the next edition in September 2026. Get source-checked weekly briefings.

The aim is not to create records for their own sake. Each part of the chain should help the team make a better decision, explain it later, or demonstrate that the delivered outcome matches its intended use.

1. Describe the intended outcome and constraints

Begin with the intended user, the promised outcome, relevant acceptance criteria, known risks, applicable obligations, and interfaces. Good design inputs and outputs are connected: a reader should be able to see how a stated need becomes a feature, service element, specification, method, or controlled delivery step.

Inputs can come from customer requirements, earlier lessons learned, statutory or regulatory obligations, performance data, usability needs, technical constraints, and interfaces with suppliers or internal teams. The important point is usability. A long list that no one can trace into a decision is less valuable than a short, current set of constraints linked to named decisions.

2. Plan reviews around decisions, not calendar rituals

An ISO 9001 design controls approach should make review points meaningful. A review before expensive tooling, customer commitment, pilot launch, regulatory submission, or large-scale rollout may be more valuable than a routine meeting with no decision to make. Identify who needs to participate, what information they need, the decision being requested, and the actions or unresolved risks that follow.

For a material change, connect the review to the organization’s ISO 9001 planning-of-changes guideISO 9001 planning-of-changes guide/article/iso-9001-planning-of-changes-guide. That helps a team consider purpose, consequences, resources, responsibilities, and QMS integrity rather than treating a design change as an isolated engineering event.

3. Keep outputs usable at the handoff

Outputs should give the next person enough reliable information to produce, deliver, buy, inspect, support, or maintain the intended result. Depending on the organization, that may be a released drawing, approved specification, configuration baseline, service workflow, acceptance criteria, test method, training material, or supplier requirement.

Do not assume that a polished presentation is an adequate output. Test whether a person who did not attend the original discussion can apply the released information without guessing at a critical requirement. When external providers affect the result, align the handoff with the organization’s supplier evaluation and risk-based management approachsupplier evaluation and risk-based management approach/article/iso-9001-supplier-evaluation-guide.

4. Separate verification from validation

Design verification and validation answer different questions. Verification asks whether the output meets the specified inputs or acceptance criteria. Validation asks whether the result is suitable for its intended use or user context. The methods should fit the risk and the output: review, calculation, inspection, test, pilot, simulated use, customer trial, or performance monitoring can each be useful when their purpose is clear.

Evidence questionExample methodCaution
Did the output meet the stated requirement?Inspection, peer review, calculation, controlled test against defined criteria.Do not confuse completing a test with showing that the right criterion was tested.
Does the output work in its intended setting?Pilot, controlled trial, user evaluation, service simulation, early performance review.Intended use may reveal constraints that were invisible in a desk review.
Is the measurement result credible?Calibrated or verified resource, defined method, traceable result, competent reviewer.The evidence should be appropriate to the decision and risk.

The measurement traceability guidemeasurement traceability guide/article/iso-9001-calibration-measurement-traceability-guide can help teams ask whether measuring resources support a credible decision. It does not prescribe a universal test protocol; the evidence must match the outcome, risk, and relevant commitments.

5. Control changes without losing the design story

An ISO 9001 design changes record should explain what changed, why it changed, what could be affected, and how the change was checked before release. Preserve the connection to earlier inputs, reviews, verification, validation, suppliers, customer approvals, and production or service handoff where relevant.

A useful change decision avoids two extremes: freezing a harmless correction behind excessive administration, and allowing a significant change to enter use with no review of its consequences. The right level of control follows the potential effect on conformity, intended use, customer commitments, applicable obligations, and process performance.

6. Use audit questions to test the whole chain

The strongest review traces one real output through the process. Rather than auditing a folder in isolation, start with a delivered product or service and work backward: what need was understood, what decisions were made, what criteria applied, what evidence supported release, and what happened after change or handoff?

Audit focusAdaptable questionEvidence to follow
Applicability“How did you determine whether this work needed design and development controls?”Output definition, contract, product/service change decision.
Inputs“Which customer, operational, technical, and applicable requirements informed this decision?”Design brief, requirement record, lessons learned, interface map.
Reviews“What decision was made at this review, and what remained open?”Agenda, participants, decision record, action closure.
Verification“How do you know the released output meets its stated criteria?”Test or inspection evidence, reviewer decision, acceptance criteria.
Validation“How do you know the output works for its intended use?”Pilot, user feedback, launch evidence, performance information.
Changes“What did this change affect and how was the revised output checked?”Change request, risk review, revised evidence, release approval.

For broader process-based prompts, see the ISO 9001 internal audit questions guideISO 9001 internal audit questions guide/article/iso-9001-internal-audit-questions-guide. The email-gated ISO 9001 Gap Analysis TemplateISO 9001 Gap Analysis Template/resources/gap-analysis-template can help a team organize its current evidence before deciding where a deeper review is needed.

An Original Practical Takeaway: Design Control Is a Decision-Quality System

The most useful way to view Clause 8.3 is as a decision-quality system. The record should show that the team made the right decision with the information available, tested the assumptions that mattered, and retained enough evidence for the next decision. That perspective discourages both document-heavy rituals and undocumented improvisation.

Warning

Keep present and future requirements separate:: ISO lists ISO 9001:2015 as the current published edition and the next ISO 9001 revision as under development. Do not claim that an existing development process conforms to final ISO 9001:2026 requirements, or rely on unverified draft summaries, until the final edition and applicable guidance are available.

Frequently Asked Questions

What is ISO 9001 Clause 8.3?

Under the current published ISO 9001:2015 edition, Clause 8.3 concerns the design and development of products and services. Apply the controlled edition and the organization’s real output, customer, and applicable-requirement context rather than assuming one generic lifecycle fits every organization.

Does every organization need a design-and-development procedure?

Do not assume that a named procedure or stage-gate template is universally required. First determine whether the organization makes design decisions that affect its products or services, then establish controls appropriate to those decisions and their risks.

What is the difference between design verification and validation?

Verification checks whether the output meets stated input requirements or acceptance criteria. Validation checks whether the output is suitable for its intended use. A single activity can contribute evidence to both, but the purpose and criteria should be clear.

What are examples of design inputs and outputs?

Inputs may include customer needs, contractual requirements, technical constraints, previous lessons, risks, and applicable obligations. Outputs may include released specifications, service workflows, acceptance criteria, test methods, training materials, or supplier requirements. The appropriate records depend on the output and the organization’s context.

How should ISO 9001 design changes be controlled?

Record the reason for the change, its potential effect, the information or approvals that need revision, and the evidence used to check the changed result before release. The depth of review should be proportionate to risk and commitments.

Will ISO 9001:2026 change Clause 8.3 requirements?

The final published wording is not yet available. ISO lists the revision as under development with publication planned for September 2026. Continue to use ISO 9001:2015 as the current baseline and assess changes after the final text is available.

ISO 9001 design and developmentISO 9001 Clause 8.3design and development process ISO 9001ISO 9001 design controlsdesign review ISO 9001design verification and validationdesign inputs and outputsISO 9001 design changesproduct and service design ISO 9001ISO 9001 design recordsdesign and development audit questions

Share this article

Editorial Disclaimer

This article is provided for informational and educational purposes only. It does not constitute legal, regulatory, certification, or professional advice. ISO 9001:2026 is an evolving standard and information may change as it is interpreted and implemented. Author attribution reflects the primary writer; it does not imply personal liability for any consequences arising from reliance on this content. Always consult your certification body and qualified professionals for advice specific to your organisation. See our Terms of Use for full details.

Was this article helpful?

Konstantin Dolgan, Ph.D.
Konstantin Dolgan, Ph.D.Quality Systems Engineer & Product Development Expert
Ph.D. Materials & Infrastructure Systems EngineeringCertified New Product Development Professional (NPDP)Forbes The Next 1000 (2021)7 Granted US Patents

Konstantin Dolgan, Ph.D., is a product development engineer and quality systems architect who first encountered ISO 9001 from the inside — as an R&D engineer designing API 610 centrifugal pumps inside a certified manufacturer. He has since led the development of over 1,000 physical products and holds a Ph.D. in Materials and Infrastructure Systems Engineering from Louisiana Tech University.

Expertise:Quality data architecture and traceabilityNew product development under ISO 9001 clause 8.3Design control and documented informationRoot cause analysis and risk-based thinkingISO 9001 for manufacturing and engineeringAI applied to quality managementERP integration and records management