Policy, procedures, work instructions, records: how to structure ISO 9001 quality documentation, decide what belongs at each tier, and keep it auditable.
By Konstantin Dolgan, Ph.D. · 11 min read · Topics: ISO 9001, Document Control, Quality Management, Audit Readiness
A QMS document hierarchy is the four-tier structure — policy and manual, procedures, work instructions and forms, records — that keeps every document in your quality system in its right place, with one owner and one current revision. Four tiers is a convention, not an ISO 9001 requirement: the standard only asks that documented information be identified, reviewed, approved and controlled. The hierarchy is how you make that controllable in practice.
Key takeaways
Tier 1 states intent, Tier 2 says who does what and when, Tier 3 says exactly how, Tier 4 proves it happened.
ISO 9001:2015 dropped the mandatory quality manual and the six mandatory procedures. Most companies still keep a manual — by choice, not by rule.
If a document names a hand-off between two functions, it is a procedure. If it names a single task at a single station, it is a work instruction.
Every controlled document needs four identity fields: number, title, revision and owner. Missing owners are what turn a document set into a graveyard.
A 15-person shop needs roughly 8–12 procedures, not 40. Depth costs money to maintain and buys nothing at audit.
The evidence trail auditors follow runs downwards: policy → procedure → work instruction → record. A break at any tier is a finding.
What are the four levels of quality documentation?
The hierarchy exists because quality documents answer four different questions, at four different levels of detail, for four different audiences. Collapse them and you get 40-page procedures nobody reads; separate them and each document has a job.
The four tiers, with the purpose and the audience each one serves.
Tier 1 — quality policy, scope and manual
Intent and boundaries. The quality policy, the scope of the management system, the process map showing how your processes interact, and the assignment of top-level responsibility. Owner: top management. Typical count: one to four documents. Audience: everybody, plus your certification body and your customers.
This tier answers what we commit to and where the system applies . It should not contain steps.
Tier 2 — procedures
Who does what, when, and what triggers it. A procedure crosses functions: it describes a flow that starts in one place and ends in another — purchasing raises a PO, receiving inspects the goods, quality dispositions the nonconformance. Owner: the process owner. Typical count: 8 to 25 depending on size and sector. Audience: supervisors, process owners, auditors.
This tier answers how the business runs the process . It names roles, not people.
Tier 3 — work instructions, forms and templates
Exactly how a single task is performed at a single station, by the person performing it. Setup sheets, inspection instructions, machine programs, packing instructions, the blank forms and checklists the task uses. Owner: the supervisor or engineer responsible for that operation. Typical count: the largest tier, often hundreds. Audience: the operator, at the point of work.
This tier answers how do I do this, right now, correctly . It should be short, visual, and revision-controlled tightly, because it is the tier that changes most often.
Tier 4 — records
Evidence that the work happened as planned. Completed inspection reports, calibration certificates, heat and material certificates, training records, internal audit reports, management review minutes, corrective action files. Owner: whoever performs the activity. Typical count: unbounded and growing. Audience: auditors and anyone investigating a problem after the fact.
Records differ from the other three tiers in one important way: you do not revise a record. You retain it, protect it, and eventually dispose of it according to a defined retention period.
Does ISO 9001:2015 still require a quality manual?
No. ISO 9001:2015 removed the explicit requirement for a quality manual and for the six mandatory documented procedures that the 1994 and 2000-era editions demanded. What replaced them is a single, broader requirement. Clause 7.5.1 states that the quality management system shall include:
a) documented information required by this International Standard;
b) documented information determined by the organization as being necessary for the effectiveness of the quality management system.
ISO 9001:2015, clause 7.5.1
Point (b) is the one that decides your hierarchy. You choose the depth. The trade-off is real: too little documented information and process knowledge walks out of the door with the person who holds it; too much and you own a maintenance liability that ages badly and generates findings for being out of date.
Most certified companies still keep a manual, for three practical reasons: customers and prospects ask for one, it is the cleanest place to hold the scope and the process map, and it gives an auditor a map on day one. Keep it if it earns its keep — just keep it thin, and stop copying clause text into it.
Which documents does ISO 9001 actually require?
The standard names specific documented information across its clauses. This is the floor, not the ceiling. Every item below is either a document you maintain or a record you retain.
Documented information Clause Tier
Scope of the quality management system 4.3 1
Quality policy 5.2.2 1
Quality objectives 6.2.1 1
Evidence of fitness for purpose of monitoring and measuring resources 7.1.5.1 4
Calibration and verification records for measuring equipment 7.1.5.2 4
Evidence of competence 7.2 4
Information necessary for the operation of processes 8.1 2, 3
Evidence that products and services meet requirements 8.1 4
Results of the review of requirements for products and services 8.2.3.2 4
Design and development inputs, controls, outputs and changes 8.3.3–8.3.6 4
Evaluation, selection and monitoring of external providers 8.4.1 4
Characteristics of products and services, and activities performed 8.5.1 2, 3, 4
Traceability of outputs, where required 8.5.2 4
Customer or external provider property that is lost, damaged or unsuitable 8.5.3 4
Results of the review of changes to production or service provision 8.5.6 4
Evidence of conformity to acceptance criteria and release authority 8.6 4
Nonconformity and the actions taken on it 8.7.2 4
Results of monitoring, measurement, analysis and evaluation 9.1.1 4
Internal audit programme and audit results 9.2.2 4
Management review results 9.3.3 4
Nature of nonconformities, actions taken, and results of corrective action 10.2.2 4
Notice the weighting: the standard mandates far more records than documents. That is the correct instinct for your own hierarchy too — evidence over prose.
How do I decide whether something is a procedure or a work instruction?
Use one test: does the document cross a hand-off?
It crosses a hand-off → procedure (Tier 2). Two or more roles are involved, and the document has to say who picks the work up next and on what trigger.
It stays at one station with one role → work instruction (Tier 3). The document tells one competent person how to perform one task correctly.
Three worked examples from a machine shop:
Receiving inspection
The procedure covers goods arriving, the inspection decision, what happens to a rejected lot, who is notified, and how the purchase order and supplier record are updated — purchasing, receiving and quality all appear. The work instruction covers how to inspect a specific part family: which dimensions, which gauge, sample size, what to record.
Heat-number traceability
The procedure defines where the heat number is captured, how it is carried forward through cutting, machining and shipping, and how it appears on the certificate of conformance — this is the traceability requirement of clause 8.5.2 and it necessarily crosses functions. The work instruction tells the operator how to transfer and re-stamp the heat number when a bar is cut into pieces.
Calibration recall
The procedure defines calibration intervals, who schedules recall, what happens to overdue equipment, and the out-of-tolerance impact assessment required by clause 7.1.5.2. The work instruction tells a technician how to verify a specific micrometer against a gauge block set.
When in doubt, write the flow as a procedure and pull the fiddly detail down into instructions. Procedures should be stable for years; instructions change whenever the process improves.
How should documents be numbered and identified?
Clause 7.5.2 requires that documented information carry, when created or updated:
a) identification and description (e.g. a title, date, author, or reference number);
b) format (e.g. language, software version, graphics) and media (e.g. paper, electronic);
c) review and approval for suitability and adequacy.
ISO 9001:2015, clause 7.5.2
In practice that becomes four fields you should be able to see on any document without opening it: number, title, revision, owner . Add the approval date and approver, and you have satisfied 7.5.2 in full.
A numbering scheme that survives growth is boring and flat:
QM-01 — quality manual (Tier 1)
QP-08 — quality procedure, sequential (Tier 2)
WI-08-03 — work instruction, third one under procedure 08 (Tier 3)
F-08-01 — form belonging to procedure 08 (Tier 3 blank, Tier 4 once completed)
Two rules matter more than the scheme itself. First, never encode the department or the machine into the number — reorganisations and equipment changes will strand it. Second, keep a master list that shows every controlled document with its current revision, owner, approval date and next review date. The master list is the first thing most auditors ask for, and comparing it against reality is the fastest self-audit you can run.
What does the hierarchy look like for a 15-person shop?
Smaller and flatter than the templates you will be sold. A realistic set:
Tier 1: one combined document holding the scope, quality policy, objectives and process map.
Tier 2: eight to twelve procedures — order review and quoting, purchasing and supplier control, receiving inspection, production control, in-process and final inspection, nonconforming output, corrective action, calibration, competence and training, document and record control, internal audit, management review.
Tier 3: instructions only where the work is genuinely error-prone or where a new hire cannot get it right unaided. Photographs beat paragraphs.
Tier 4: the full record set, because records are what prove conformity regardless of company size.
One person can hold several roles — the same person can be the process owner and the approver for different documents — as long as the authority is defined in advance and the approval evidence exists afterwards. What a small shop should not do is buy a 60-procedure template set: every document you adopt is a document you must keep current, and stale documents are findings.
How does the hierarchy connect to processes and records?
The hierarchy is not a filing convention, it is a traceability chain. For any process an auditor picks, they should be able to walk it in one direction and never fall through a gap:
Process (4.4) → Procedure that governs it (Tier 2) → Work instruction at the point of work (Tier 3) → Record proving it was done to the acceptance criteria (Tier 4, 8.6) → Nonconformance and corrective action when it was not (8.7, 10.2)
Practical consequences worth designing for:
Every process on your process map should name its governing procedure. An unlinked process is either undocumented or unnecessary — decide which.
Every procedure should name the records it produces, and every record type should have a defined retention period. Clause 7.5.3.2 requires control over retention and disposition ; a retention schedule is how you show it.
Forms belong to procedures. When a procedure is revised, the forms it references are the first thing to check.
Acceptance criteria live in Tier 3 and get proven in Tier 4. If a record has no criterion to compare against, it is data, not evidence.
What auditors find when the hierarchy is wrong
Five patterns, and the clause each is written against:
Obsolete revision in use at the point of work. The controlled copy in the binder at the machine is two revisions behind the master. Written against 7.5.3.1(a) — documented information must be available and suitable for use where and when it is needed.
No approval evidence for the current revision. The document exists and looks fine, but nothing shows who approved it or when. Written against 7.5.2(c).
Everything is a procedure. Thirty documents at Tier 2, half of them describing single-station tasks, none of them followed as written. Usually surfaces as a conformity finding against 8.5.1 when the observed practice differs from the text.
External documents outside the system. Customer drawings, specifications and standards sitting in an email folder with no revision control. Written against 7.5.3.2(a) — control of distribution, access, retrieval and use.
Records with no retention rule. Nobody can say how long inspection records are kept, and the oldest ones have already been deleted. Written against 7.5.3.2(d).
All five are structural, not clerical. They come from a hierarchy where ownership and revision identity were never designed in — which is exactly what the four tiers, a master list and four identity fields prevent.
Where to go next
This post covers structure. For the lifecycle that runs on top of it — create, review, approve, issue, change, retain, obsolete — and the 12-point checklist for evaluating a document control system, start from the document control hub . For the long-form implementation walkthrough with the audit evidence pack, read the ISO 9001 document control system guide .
If you would rather the hierarchy be enforced by the system than policed by a spreadsheet, QMS2GO holds procedures, work instructions and records against the processes they govern, with revision control and approval evidence built in.
Frequently Asked Questions
What is the QMS document hierarchy?
It is the tiered structure of a quality management system's documentation: Tier 1 quality policy, scope and manual; Tier 2 procedures; Tier 3 work instructions, forms and templates; Tier 4 records. Each tier answers a different question, at a different level of detail, for a different audience.
What are the four levels of quality documents in ISO 9001?
Policy and manual, procedures, work instructions and forms, and records. ISO 9001:2015 does not mandate four levels — it is a widely used convention that makes clause 7.5 controllable in practice.
How do I structure quality management system documentation?
Start from your process map. Give every process one governing procedure, pull single-station detail down into work instructions, define the records each procedure produces and how long they are retained, and keep a master list showing number, title, revision, owner and approval date for every controlled document.
Is a quality manual mandatory under ISO 9001:2015?
No. The 2015 edition removed the explicit requirement for a quality manual and for the six mandatory procedures. Clause 7.5.1 instead requires the documented information the standard demands plus whatever the organization determines is necessary for the effectiveness of the system.
What is the difference between a procedure and a work instruction?
A procedure describes a flow that crosses roles or functions and names the hand-offs and triggers. A work instruction tells one person how to perform one task correctly at one station. If two roles appear, it is a procedure.
How many procedures does a small manufacturer need?
Typically eight to twelve, covering order review, purchasing and supplier control, receiving and final inspection, production control, nonconforming output, corrective action, calibration, competence, document and record control, internal audit and management review. Every extra procedure is maintenance you have to fund.
How should quality documents be numbered?
Use a flat, sequential scheme that ties instructions and forms to their parent procedure — for example QP-08, WI-08-03, F-08-01. Avoid encoding departments, machines or people into the number, because those change. Always carry number, title, revision and owner on the document itself.
Where do records fit in the document hierarchy?
At the bottom tier, and they behave differently from the tiers above: records are not revised, they are retained. Define a retention period per record type and control storage, protection and disposition as clause 7.5.3.2 requires.
Sources
ISO 9001:2015, Quality management systems — Requirements — clauses 4.3, 4.4, 5.2.2, 6.2.1, 7.1.5, 7.2, 7.5, 8.1–8.7, 9.1–9.3, 10.2. Clause text quoted verbatim. iso.org
ISO/TC 176/SC 2, Guidance on the requirements for documented information of ISO 9001:2015 . committee.iso.org
ISO, The ISO Survey of certifications — certification population data. iso.org
ASQ, Quality Management System (QMS) resources . asq.org
QMS2GO is the audit-ready operating system for ISO 9001 manufacturers — documentation, registers, internal audits, CAPA, suppliers, production, and QuickBooks data in one connected quality management system. Manufacturing teams use it to build, run, and prove their ISO 9001 system without spreadsheets or scattered SharePoint folders.
Browse all articles · See the QMS software · Book a demo · Get a free ISO 9001 roadmap