An ISO 9001 Quality Policy should explain what quality means to an organisation, the commitments its management has made and the direction it intends its Quality Management System to follow.
Unfortunately, many Quality Policies do none of those things.
They are often generic statements copied from another company, filled with impressive words and signed by a Managing Director who may never look at them again. The policy is framed in reception, uploaded to the company website and shown to the certification auditor once per year.
That may create a document, but it does not create leadership or direction.
In my experience, the best Quality Policies are relatively short, specific enough to mean something and closely connected to the way the organisation actually operates. Employees do not need to memorise every sentence. They should, however, understand the commitments that affect their work.
This guide explains the ISO 9001 Quality Policy requirements, how to write a useful policy, what auditors look for and how to adapt the included template and examples for a real business.
If you are developing the complete system rather than reviewing the policy alone, my guide to implementing ISO 9001 step by step shows where policy development fits within the wider implementation process.
Building or reviewing an ISO 9001 Quality Management System? Visit the ISO 9001 resource hub or use the free ISO 9001 Starter Checklist to review Clauses 4 to 10 and identify gaps in your current system.
What is an ISO 9001 Quality Policy?
An ISO 9001 Quality Policy is a formal statement established by top management that defines the organisation’s overall intentions and commitments relating to quality.
It provides direction for the Quality Management System, commonly called the QMS, and creates a framework from which measurable quality objectives can be developed.
In practical terms, the policy should answer questions such as:
- What does the organisation provide?
- Who are its customers and other relevant interested parties?
- What requirements is it committed to meeting?
- What aspects of quality are important to its success?
- How will it use the QMS to improve?
- What direction does top management expect employees to follow?
The Quality Policy is part of the wider management framework explained in my practical guide to ISO 9001. It should not operate as an isolated statement. Its commitments need to appear in objectives, processes, responsibilities, performance measures and management decisions.
Is a Quality Policy mandatory under ISO 9001?
Yes. ISO 9001:2015 Clause 5.2 requires top management to establish, implement and maintain a Quality Policy.
The policy must also be maintained as documented information. In other words, it cannot exist only as an informal belief or verbal promise. It needs to be controlled and available in an appropriate form.
ISO 9001 does not prescribe a standard layout, fixed length or exact wording. A small consultancy may have a concise one-page policy. A multinational organisation may use a group-level policy supported by more specific business-unit commitments.
The format can vary. The required purpose and commitments cannot.
For a plain-English explanation of how the policy fits within the rest of the Standard, see my guide to ISO 9001 requirements and Clauses 4 to 10.
ISO 9001 Quality Policy requirements

Clause 5.2 contains two connected parts. The first deals with establishing the policy. The second deals with communicating and making it available.
The explanation below paraphrases the requirements in practical language. It does not reproduce the copyrighted text of the Standard.
1. The policy must suit the organisation’s purpose and context
A policy should sound as though it belongs to the organisation that issued it.
A construction contractor, engineering consultancy, software developer and medical-device manufacturer face different customers, risks, regulatory environments and operational challenges. Their policies should not be interchangeable.
Before drafting the policy, management should understand:
- What the organisation does
- The products and services it provides
- The needs of customers and relevant interested parties
- Applicable statutory, regulatory and contractual requirements
- Important internal and external issues
- The organisation’s strategic priorities
- The scope of the QMS
If the organisation’s context changes significantly, its policy may need to change as well. The same understanding should inform how the organisation identifies and addresses ISO 9001 risks and opportunities.
2. The policy must support the organisation’s strategic direction
The Quality Policy should align with the direction in which management is taking the business.
If the company intends to enter a highly regulated market, improve the reliability of its service or become the preferred contractor for technically complex projects, its quality commitments should support that direction.
A policy promising “the cheapest possible service” would conflict with a strategy based on specialist expertise and technical excellence. Similarly, a policy that promises exceptional delivery performance is not credible if management refuses to invest in planning, competence or resources.
The policy and the business strategy do not need to use identical words. They should not contradict one another.
3. The policy must provide a framework for quality objectives
The policy provides direction; quality objectives turn that direction into measurable priorities.
For example, a policy may commit the organisation to reliable delivery, reduced defects, competent personnel and improved customer satisfaction. Related objectives could then include:
- Achieve at least 95% on-time delivery each quarter
- Reduce repeat defects by 20% within 12 months
- Close 90% of corrective actions within 30 days
- Maintain a customer-satisfaction score above 85%
- Complete 100% of planned competence assessments
The Quality Policy should not contain a long list of targets that will quickly become outdated. Instead, it should establish the themes from which suitable objectives can be set and reviewed.
4. The policy must include a commitment to satisfy applicable requirements
The organisation needs to commit to satisfying the requirements that apply to its products, services and QMS.
Depending on the business, these may include:
- Customer requirements
- Contractual requirements
- Statutory and regulatory requirements
- Technical specifications
- Industry codes and standards
- Internal process requirements
- ISO 9001 requirements
This commitment should be reflected in how the organisation reviews contracts, controls operations, evaluates suppliers, verifies outputs and deals with nonconformities.
5. The policy must include a commitment to continual improvement
The organisation must commit to continually improving the suitability, adequacy and effectiveness of its QMS.
That does not mean every process must improve every month or every KPI must always move upwards. It means the organisation uses evidence to identify appropriate improvements over time.
Useful evidence may come from:
- Customer feedback and complaints
- Process and product performance
- Internal and external audits
- Nonconformities and corrective actions
- Supplier performance
- Risks and opportunities
- Management review
- Lessons learned
A promise of continual improvement has little value if recurring problems are tolerated, corrective actions are repeatedly overdue and management never reviews performance.
6. The policy must be controlled as documented information
The policy should be identified, approved, current, protected and available to the people who need it.
At a minimum, I would normally expect it to have:
- A clear title
- The organisation’s name
- An approval or authorisation
- An issue or revision status
- An effective or approval date
- A responsible owner
- A planned review arrangement
These controls should follow the organisation’s wider approach to ISO 9001 document control. If several uncontrolled versions of the policy are displayed in different offices, the organisation has created exactly the type of confusion its document-control process should prevent.
7. The policy must be communicated, understood and applied
Uploading the policy to the intranet does not prove that it has been communicated or understood.
People whose work affects quality should understand the commitments relevant to their roles. A buyer may need to understand supplier-control expectations. A supervisor may need to understand the importance of following approved information. A customer-service employee may need to understand how complaints are recorded and escalated.
Employees do not need to recite the policy word for word.
I have seen organisations train people to memorise a paragraph for an audit. An auditor asks, “What is the Quality Policy?” and the employee repeats a rehearsed statement that has no connection with their work.
A much better response is:
“Our policy commits us to meeting the client’s requirements and improving how we deliver our work. In my role, that means checking I am using the latest approved drawing, completing the required inspection records and reporting problems rather than covering them up.”
That demonstrates understanding and application.
8. The policy must be available to relevant interested parties where appropriate
The organisation should decide which interested parties need access to the Quality Policy and how it will be made available.
It may be:
- Published on the company website
- Included in tender or prequalification submissions
- Displayed in offices or workplaces
- Shared with customers, regulators or certification bodies
- Provided to suppliers and subcontractors where relevant
This does not mean the policy must be sent automatically to everybody. Availability should be appropriate to the organisation and its interested parties.
Who is responsible for the Quality Policy?
Top management is responsible for establishing, implementing and maintaining the Quality Policy.
A Quality Manager or consultant can facilitate the drafting process, explain the ISO 9001 requirements and prepare a proposed structure. However, the policy should not be written in isolation by the Quality Department and then handed to the Managing Director for a quick signature.
Top management needs to:
- Agree the direction and commitments
- Ensure the policy aligns with the business
- Approve and support its implementation
- Provide the resources needed to deliver it
- Promote it through leadership and decisions
- Review whether it remains suitable
This is why the Quality Policy sits within ISO 9001 Clause 5 on leadership.
Quality Policy versus Quality Objectives
The Quality Policy and quality objectives are connected, but they are not the same thing.
| Quality Policy | Quality Objectives |
|---|---|
| Provides overall direction and commitments | Translate that direction into measurable results |
| Usually remains relatively stable | May change as priorities and performance change |
| Established by top management | Set at relevant functions, levels and processes |
| May refer broadly to customers, conformity and improvement | Include defined measures, targets, responsibilities and timeframes |
| Explains the organisation’s intentions | Show what the organisation plans to achieve |
For example:
Policy commitment: We are committed to delivering projects that meet agreed customer, contractual and regulatory requirements.
Related objective: Achieve an average client-satisfaction score of at least 85% during the current financial year.
Policy commitment: We are committed to improving the effectiveness of our Quality Management System.
Related objective: Reduce repeat NCRs across active projects by 20% by 31 December.
Quality Policy versus Quality Manual
The Quality Policy should not be confused with a Quality Manual.
The policy is a concise statement of direction and commitment. A Quality Manual, where an organisation chooses to maintain one, normally provides a broader description of the QMS, its scope, processes and interactions.
ISO 9001:2015 requires a Quality Policy but does not specifically require a document called a Quality Manual.
An organisation may still find a short manual useful, particularly when it needs to explain its system to employees, customers, project teams or auditors. The decision should be based on usefulness rather than tradition.
Quality Policy versus Quality Assurance Policy
The terms are sometimes used interchangeably, but they can create confusion.
An ISO 9001 Quality Policy provides direction for the entire Quality Management System. A document described as a quality assurance policy may focus more narrowly on the processes used to prevent problems and provide confidence that requirements will be met.
ISO 9001 does not require separate Quality Assurance and Quality Control policies. It establishes one connected management system containing preventive controls, operational controls, verification activities and improvement processes.
My guide to quality assurance versus quality control explains the practical difference in more detail.
How to write an ISO 9001 Quality Policy

I recommend treating policy development as a management exercise rather than a writing exercise.
The objective is not to find the most impressive wording. It is to agree commitments that genuinely describe how the organisation intends to operate.
Step 1: Understand the organization before writing
Review the organization’s purpose, activities, context, interested parties, strategic direction and QMS scope.
Ask:
- Why does the organization exist?
- What does it promise its customers?
- What requirements are critical?
- What could seriously affect conformity or customer satisfaction?
- What capabilities distinguish the business?
- What needs to improve?
Do not begin by downloading five policies and joining their sentences together.
Step 2: Identify the essential commitments
Start with the commitments required by ISO 9001:
- Satisfying applicable requirements
- Continually improving the QMS
Then add a small number of commitments that matter to the organisation, such as:
- Customer satisfaction
- Reliable delivery
- Technical competence
- Defect prevention
- Supplier performance
- Employee involvement
- Evidence-based decisions
- Safe and compliant project delivery
Do not promise everything. Every commitment should be supported by processes, resources and evidence.
Step 3: Connect commitments to objectives
For every important policy statement, ask how the organisation will know whether it is being achieved.
If the policy promises reliable service, which measures demonstrate reliability? If it promises customer satisfaction, how is satisfaction evaluated? If it promises improvement, what evidence shows that lessons and corrective actions produce change?
This does not mean every sentence needs its own KPI. It means the policy should provide a meaningful framework for objectives rather than a collection of vague ambitions.
Step 4: Write in clear language
Use language that employees, customers and suppliers can understand.
Avoid unnecessary phrases such as:
- “World-class excellence in everything we do”
- “Unparalleled quality without compromise”
- “Exceeding every customer expectation at all times”
- “Zero defects under all circumstances”
These statements may sound ambitious, but they are difficult to define, measure and deliver.
It is usually better to say exactly what the organisation will do: understand requirements, provide competent resources, control processes, evaluate performance, correct problems and improve the QMS.
Step 5: Check the policy against ISO 9001
Before approval, confirm that the policy:
- Fits the organization’s purpose and context
- Supports its strategic direction
- Provides a framework for objectives
- Commits to satisfying applicable requirements
- Commits to continual improvement of the QMS
- Can be maintained as controlled documented information
- Can be communicated, understood and applied
- Can be made available to relevant interested parties
Step 6: Obtain genuine management approval
Top management should review the proposed policy, challenge it where necessary and confirm that the organisation can support the commitments being made.
A signature demonstrates approval, but leadership is shown by subsequent decisions and actions.
Step 7: Communicate and implement it
Choose communication methods appropriate to the workforce.
These may include:
- Employee induction
- Team briefings
- Toolbox talks
- Management presentations
- Posters and noticeboards
- The company intranet
- The public website
- Supplier or subcontractor onboarding
Communication should explain what the policy means in practice. Reading it aloud during induction and asking employees to sign an attendance sheet is rarely enough.
Step 8: Review the policy periodically
ISO 9001 does not prescribe a fixed review frequency for the Quality Policy.
Many organisations review it annually as part of ISO 9001 management review. It should also be reconsidered when significant changes occur, including:
- A change in strategic direction
- New products, services or markets
- Changes to the QMS scope
- Major regulatory or contractual changes
- Business acquisition or restructuring
- Persistent performance problems
- Changes to relevant management-system standards
The policy does not need a new revision every year if it remains suitable. The organisation should retain evidence that its continuing suitability was considered.
A practical ISO 9001 Quality Policy formula
A useful policy can normally be built using five elements:
- Who we are: State the organisation’s purpose and main activities.
- What we aim to deliver: Describe the value or outcome provided to customers.
- What we commit to: Address applicable requirements, customer needs and continual improvement.
- How we support delivery: Refer to people, processes, resources, suppliers, risk or evidence where relevant.
- How the policy is governed: Confirm that it provides a framework for objectives and is communicated and reviewed.
This formula is not mandatory. It is simply a practical way to avoid both a one-sentence policy that says very little and a three-page policy that nobody will read.
ISO 9001 Quality Policy template

The following template can be adapted for most organisations. Replace the bracketed text with information that genuinely reflects your business.
[ORGANISATION NAME] — QUALITY POLICY
[Organisation name] provides [products/services] to [main customer groups or markets]. Our purpose is to [briefly describe the value delivered by the organisation].
We are committed to:
- Understanding and satisfying applicable customer, contractual, statutory, regulatory and other relevant requirements.
- Providing competent people, appropriate resources and controlled processes needed to deliver conforming products and services.
- Establishing measurable quality objectives that support our strategic direction and reviewing progress against them.
- Working with employees, suppliers and other relevant interested parties to prevent problems and improve performance.
- Using performance information, feedback, audits, nonconformities and lessons learned to continually improve the suitability, adequacy and effectiveness of our Quality Management System.
This policy provides the framework for establishing and reviewing our quality objectives. It will be communicated within the organisation, made available to relevant interested parties and reviewed periodically to ensure that it remains appropriate to our purpose, context and strategic direction.
Approved by: [Name and position]
Approval date: [Date]
Document reference: [Reference]
Revision: [Revision]
Do not use the template without adapting it. A policy should reflect the actual organisation, not merely contain every expected phrase.
ISO 9001 Quality Policy example for a general business
NORTHSTAR TECHNICAL SERVICES LTD — QUALITY POLICY
Northstar Technical Services provides inspection, maintenance and technical-support services to industrial customers throughout the United Kingdom.
We aim to deliver reliable services that meet agreed requirements, protect our customers’ operations and build long-term working relationships.
We are committed to understanding customer needs; satisfying applicable contractual, statutory and regulatory requirements; providing competent personnel and suitable resources; controlling the processes that affect service quality; and monitoring our performance against measurable quality objectives.
We encourage employees to report problems and improvement opportunities. We use customer feedback, service data, audits, supplier performance and corrective actions to continually improve the effectiveness of our Quality Management System.
This policy is communicated across the business, made available to relevant interested parties and reviewed by top management to ensure that it remains appropriate to our purpose, context and strategic direction.
Managing Director
20 July 2026
ISO 9001 Quality Policy example for a construction company
EXAMPLE CONSTRUCTION LTD — QUALITY POLICY
Example Construction Ltd delivers building and civil-engineering projects for public- and private-sector clients.
Our aim is to deliver safe, compliant and reliable construction work that meets agreed drawings, specifications, contractual requirements and programme commitments.
We are committed to:
- Understanding client, statutory, regulatory and project-specific requirements before and during delivery.
- Providing competent people, suitable resources and clear responsibilities.
- Planning and controlling design, procurement, construction, inspection, testing and handover activities.
- Working with suppliers and subcontractors to achieve the required standards.
- Preventing defects where possible and reporting nonconforming work openly when problems occur.
- Establishing measurable quality objectives and reviewing project and company performance.
- Using audits, inspection results, customer feedback, NCRs and lessons learned to continually improve our Quality Management System.
This policy provides the framework for our quality objectives. It is communicated to employees, made available to relevant interested parties and reviewed regularly by top management to ensure that it remains suitable for our business.
Managing Director
20 July 2026
The construction example is intentionally connected to real project controls. My guide to ISO 9001 for construction companies explains how company-level commitments should flow into Project Quality Plans, document control, procurement, inspections, NCRs and handover records.
ISO 9001 Quality Policy example for a small business
BRIGHTPATH CONSULTING — QUALITY POLICY
BrightPath Consulting provides management and technical advice to small and medium-sized businesses.
We are committed to understanding each client’s requirements, agreeing clear deliverables, providing competent consultants, protecting client information and delivering work within agreed timescales.
We establish measurable quality objectives and use project reviews, client feedback, complaints and lessons learned to improve our services and the effectiveness of our Quality Management System.
This policy is communicated to everyone working on our behalf and reviewed by the Managing Director to ensure that it remains suitable for the business and its strategic direction.
Managing Director
20 July 2026
A small business does not need a complicated policy. It needs a truthful one supported by working processes.
ISO 9001 Quality Policy example for manufacturing
PRECISION COMPONENTS LTD — QUALITY POLICY
Precision Components Ltd manufactures machined components for engineering and industrial customers.
We are committed to consistently supplying products that meet approved drawings, specifications, delivery requirements and applicable statutory and regulatory obligations.
We support this commitment through competent employees, controlled production processes, maintained equipment, risk-based planning, reliable suppliers, inspection and testing, traceable records and prompt control of nonconforming outputs.
We establish and review measurable objectives for product conformity, on-time delivery, customer satisfaction and operational performance. We use data, audits, feedback and corrective action to continually improve the effectiveness of our Quality Management System.
This policy is communicated throughout the organisation, available to relevant interested parties and reviewed by top management for continuing suitability.
Managing Director
20 July 2026
What makes a weak Quality Policy?
A policy may contain the expected ISO language and still be weak.
It could belong to any company
If the company name can be replaced without changing anything else, the policy probably says too little about the organisation’s purpose, context or direction.
It makes promises the organisation cannot demonstrate
Statements such as “we exceed every expectation” or “we deliver zero defects” create commitments that may be impossible to support.
Ambition is welcome. Unsupported claims are not.
It is too long
A policy does not need to explain the entire QMS. Excessive detail makes it harder to communicate and more likely to become outdated.
It is written only for the auditor
If the policy uses formal language that employees cannot understand, it will be difficult to apply.
It is disconnected from objectives
A policy may promise customer focus, reliable delivery and improvement while the organisation measures none of them.
Management does not support it
The strongest wording cannot compensate for leadership decisions that contradict the policy.
If management instructs employees to use an unapproved supplier, ignore an inspection or close a complaint without investigation, the real policy is being demonstrated by behaviour rather than the framed statement.
How should the Quality Policy be communicated?
Communication should be proportionate to the organisation’s size, structure and workforce.
A practical communication plan might include:
| Audience | Communication method | Evidence |
|---|---|---|
| New employees | Induction with role-specific examples | Induction record and employee discussion |
| Existing employees | Team briefing, toolbox talk or refresher training | Attendance record and understanding demonstrated during work |
| Remote workers | Intranet, online induction and team meetings | Current policy available and discussed |
| Suppliers and subcontractors | Prequalification, onboarding or contract documentation where relevant | Approved supplier records and agreed requirements |
| Customers and interested parties | Website, tender submission or issue on request | Published or controlled copy |
Understanding is best tested through conversation and observation.
Ask employees:
- What does quality mean in your role?
- Which requirements must you follow?
- What should you do when something goes wrong?
- How does your work affect the customer?
- Which quality objectives are relevant to your team?
The answers are more valuable than perfect recitation.
What do ISO 9001 auditors look for?
An auditor is unlikely to assess the Quality Policy only by reading it.
They may look for evidence that:
- The policy has been approved by top management
- It reflects the organisation’s purpose, context and strategic direction
- It contains the necessary commitments
- Related quality objectives have been established
- The current version is controlled and available
- Employees understand the aspects relevant to their work
- It is applied through real processes and decisions
- It is available to relevant interested parties
- Management reviews its continuing suitability
The auditor may interview top management about why the policy was established and how it supports the business. They may ask employees how their work contributes to quality. They may compare policy commitments with objectives, customer feedback, operational performance and management-review records.
A properly planned ISO 9001 internal audit should test these connections before the certification auditor arrives.
Common Quality Policy audit findings
Potential weaknesses include:
- The policy does not reflect the organisation’s current activities or QMS scope
- Required commitments are missing
- The policy has not been approved or controlled
- Obsolete versions are displayed
- No meaningful objectives relate to the policy
- Employees are unaware of its relevant commitments
- The policy is not available to relevant interested parties
- Management cannot explain how it supports the business strategy
- The policy has not been reviewed following significant organisational change
- Actual practices contradict the policy
The classification of a finding will depend on the evidence, extent and certification body’s audit process. A minor wording issue is not the same as a complete failure of leadership and implementation.
Should the Quality Policy mention ISO 9001?
It may mention ISO 9001, but it does not have to.
The important issue is whether the policy meets the applicable requirements and reflects the organisation. A statement such as “we maintain a Quality Management System aligned with ISO 9001” may be useful, particularly for a certified organisation.
However, the organisation should not make misleading claims about certification. A business implementing the Standard should not describe itself as ISO 9001 certified until certification has been granted for the applicable scope by the certification body.
My guide to ISO 9001 certification, costs and audit stages explains the distinction between implementing a QMS and achieving certification.
Can ISO 9001, ISO 14001 and ISO 45001 share one policy?
Yes. An organisation operating an Integrated Management System may use one combined Quality, Environmental and Health and Safety Policy.
The combined policy must address the commitments required by each applicable Standard and remain clear enough for employees and interested parties to understand.
A poorly written integrated policy can become a long list of formal promises. A good one explains the organisation’s combined direction without losing the distinct purpose of quality, environmental and occupational health and safety management.
See my guide to integrating ISO 9001, ISO 14001 and ISO 45001 for the processes that can be shared and the requirements that need separate attention.
Quality Policy checklist
Before approving or revising your policy, check the following:
- Does it accurately describe the organisation?
- Is it appropriate to its purpose and context?
- Does it support the strategic direction?
- Does it provide a framework for quality objectives?
- Does it commit to satisfying applicable requirements?
- Does it commit to continually improving the QMS?
- Has top management genuinely reviewed and approved it?
- Is it controlled as documented information?
- Is the current revision available where needed?
- Has it been communicated in an understandable way?
- Can employees explain how it relates to their work?
- Is it applied through actual processes and decisions?
- Is it available to relevant interested parties?
- Are related objectives measured and reviewed?
- Is its continuing suitability considered during management review?
Need an editable construction Quality Policy?
The 12 Essential Construction Quality Documents Pack includes an editable Quality Policy together with an ITP, NCR form and register, corrective-action report, audit documents, RFI template, Quality Dashboard and other practical project-quality tools.
Final thoughts
An ISO 9001 Quality Policy does not need to be complicated.
It needs to belong to the organisation, contain meaningful commitments, guide measurable objectives and be supported by management behaviour.
The most polished policy in the world is useless when customers’ requirements are not understood, employees lack resources, problems are hidden and management ignores the results.
A simple policy can be effective when its commitments are visible in:
- How contracts and requirements are reviewed
- How people are trained and supported
- How suppliers and operations are controlled
- How quality performance is measured
- How nonconformities are investigated
- How management reviews evidence and makes decisions
- How the organisation learns and improves
That is the real test of a Quality Policy.
Frequently asked questions
What is the ISO 9001 Quality Policy?
It is a formal statement established by top management that defines the organisation’s overall quality direction and commitments. It should support the organisation’s purpose and strategic direction, provide a framework for quality objectives and commit to satisfying applicable requirements and continually improving the QMS.
Which ISO 9001 clause covers the Quality Policy?
The Quality Policy is covered by ISO 9001:2015 Clause 5.2. Clause 5.2.1 addresses establishing the policy, while Clause 5.2.2 addresses communicating it and making it available.
How long should a Quality Policy be?
ISO 9001 does not specify a length. For many organisations, one clearly written page is enough. It should be long enough to provide meaningful direction but short enough to communicate and understand.
Does the Quality Policy need to be signed?
ISO 9001 requires the policy to be established by top management and maintained as documented information, but it does not explicitly prescribe a handwritten signature. A signature or controlled electronic approval is a practical way to demonstrate management authorisation.
Does the Quality Policy need a revision number?
The Standard does not specifically demand a revision number on the policy. However, the organisation must control documented information. A reference, revision status, approval date or equivalent system helps identify the current approved version.
How often should a Quality Policy be reviewed?
ISO 9001 does not set a fixed frequency. Many organisations review it annually during management review and whenever significant changes affect the business, its context, strategy, scope or requirements.
Do employees have to memorise the Quality Policy?
No. Employees should be aware of the policy and understand how relevant commitments apply to their work. Being able to explain that connection is more important than repeating the document word for word.
Does the Quality Policy have to be displayed?
It must be communicated within the organisation and available to relevant interested parties where appropriate. Displaying it may help, but a poster alone does not demonstrate understanding or application.
Can a company copy an ISO 9001 Quality Policy template?
A template can provide a useful starting structure, but it should be adapted to the organisation’s purpose, context, strategic direction, customers and applicable requirements. A generic copied policy may fail to provide meaningful direction.
Can a small company have a simple Quality Policy?
Yes. A small company can use a concise policy provided that it addresses the ISO 9001 requirements and is implemented in practice. Complexity should reflect the needs of the organisation, not the size of the certification audit.