Exemplar Global Certified Courses from USD 99. Ending Soon!

A Plain English Guide to ISO 9001 Clause 4.2 Interested Parties

AW

Team @ Audit Workshop

12 min read
A Plain English Guide to ISO 9001 Clause 4.2 Interested Parties

What Clause 4.2 Actually Says

ISO 9001 Clause 4.2 requires your organisation to determine two things: who the relevant interested parties are, and what their relevant requirements are. That is it. The clause is short, but the thinking behind it is not.

The full clause reads something like this: the organisation shall determine the interested parties that are relevant to the quality management system, and the requirements of those interested parties that are relevant to the quality management system. You then need to monitor and review information about these interested parties and their relevant requirements.

What the clause does not say is that you need to satisfy every requirement of every interested party. The word “relevant” appears twice, and that is deliberate. Not every stakeholder's expectation needs to land inside your QMS. Your job is to make a considered judgement about which ones do.

Why This Clause Exists

Before ISO 9001:2015, earlier versions of the standard were criticised for being too internally focused. Organisations could build a quality management system that looked good on paper but failed to account for the broader environment in which they operated. The 2015 revision introduced Clause 4 as a whole to fix that. Clause 4.1 asks you to understand your context. Clause 4.2 asks you to understand the people and groups that exist within and around that context.

The logic is straightforward. A quality management system that ignores the expectations of regulators, customers, suppliers, or employees is fragile. It might produce conforming product today and collapse under external pressure tomorrow. Clause 4.2 forces organisations to look outward and factor those external and internal forces into how the QMS is designed and operated.

This connects directly to ISO 9001 Clause 4.1, which covers the broader context of the organisation. The two clauses work together. Context without stakeholders is incomplete, and stakeholders without context lack grounding.

Who Counts as an Interested Party?

ISO 9001 defines an interested party as a person or organisation that can affect, be affected by, or perceive themselves to be affected by a decision or activity. That is a broad definition, and intentionally so.

In practice, most organisations will identify some combination of the following:

  • Customers: The most obvious group. Their product and service requirements feed directly into the QMS.
  • Regulatory and government bodies: Licensing authorities, work health and safety regulators, environmental agencies, and similar bodies set requirements that the organisation must meet regardless of whether a customer asks for them.
  • Employees and workers: Their expectations around fair treatment, safe conditions, and clear communication affect how the QMS functions day to day.
  • Suppliers and subcontractors: Their performance directly affects your ability to deliver conforming product or service. Their requirements, such as payment terms or access arrangements, may also be relevant.
  • Owners and shareholders: Financial performance expectations, ethical conduct, and governance requirements often flow from this group.
  • Industry bodies and standards organisations: Membership obligations or sector codes of practice can impose requirements on the QMS.
  • Local communities: Particularly relevant for manufacturers or construction companies where noise, traffic, or environmental impact affects neighbours.
  • Certification bodies: If you hold or are seeking ISO 9001 certification, the requirements of your certification body are relevant.

The list above is a starting point, not a checklist you must tick off. Every organisation is different. A small professional services firm may have a short list dominated by clients and a couple of regulators. A large manufacturer might have dozens of relevant parties across multiple jurisdictions.

What Makes an Interested Party Relevant?

This is where most organisations struggle. Listing every conceivable stakeholder is easy. Determining which ones are actually relevant to the QMS takes judgement.

Ask yourself two questions for each potential interested party. First, can they affect the organisation's ability to consistently provide products and services that meet customer and applicable statutory and regulatory requirements? Second, can they affect the organisation's ability to enhance customer satisfaction?

If the answer to either question is yes, that party is likely relevant. If the answer is no, you may not need to include them in your QMS analysis, even if they matter to the business in other ways.

A practical example: a company that manufactures food packaging has a customer base of food manufacturers who must comply with food safety legislation. The relevant interested parties would include those customers, the food safety regulator, the raw material suppliers, and the workers who operate the production lines. The local council that manages the car park lease is probably not relevant to the QMS, even though they are a party the organisation interacts with.

What Are Relevant Requirements?

Once you have identified your relevant interested parties, Clause 4.2 asks you to determine their relevant requirements. Requirements can take many forms:

  • Contractual obligations set out in customer agreements
  • Legislative and regulatory requirements imposed by government
  • Industry codes or standards that apply to your sector
  • Internal policies or commitments made by the organisation
  • Expectations communicated informally by suppliers or workers

Not every expectation is a requirement. A customer might prefer that you use a particular courier, but if it is not written into the contract and non compliance does not affect product conformity or satisfaction, it may not be a QMS requirement. Use your judgement and document your reasoning.

One area that catches organisations out is the distinction between statutory requirements and regulatory requirements. Statutory requirements come from legislation passed by parliament. Regulatory requirements come from regulations, codes, and standards issued under that legislation. Both are relevant. If your organisation operates in a licensed industry, the conditions attached to that licence are also requirements you need to account for.

How to Document Clause 4.2

ISO 9001 does not require a specific document format for Clause 4.2. There is no mandatory “interested parties register” prescribed by the standard. However, most organisations find it useful to maintain one, because it makes the analysis visible, auditable, and easier to review over time.

A practical register typically includes:

  1. The name or category of the interested party
  2. Why they are relevant to the QMS
  3. Their relevant requirements or expectations
  4. How those requirements are monitored or addressed within the QMS
  5. When the register was last reviewed

Keep it simple. A one page table is often enough for a small to medium organisation. Larger or more complex organisations may need more detail, particularly where regulatory requirements vary by site, product type, or jurisdiction.

The key is that when an auditor asks how you determined your interested parties and their requirements, you can show them a clear, logical record of that thinking. Vague answers like “we know our stakeholders” will not satisfy a competent auditor.

How Clause 4.2 Connects to the Rest of the QMS

Clause 4.2 is not a standalone exercise. The outputs of your interested party analysis feed into multiple other parts of the quality management system.

Clause 4.3 (Scope): The scope of your QMS must reflect the needs and expectations of relevant interested parties. If a major customer requires you to include a specific process in your QMS, that affects scope.

Clause 6.1 (Risks and opportunities): Interested party requirements are a primary input to your risk assessment. A regulatory change is a risk. A new customer requirement is both an opportunity and a potential risk if you cannot meet it.

Clause 8.2 (Requirements for products and services): Customer requirements, which come directly from Clause 4.2 analysis, drive the determination of product and service requirements.

Clause 9.1.2 (Customer satisfaction): Understanding what customers expect, which is a Clause 4.2 activity, is a prerequisite for measuring whether you are meeting those expectations. You can read more about this in our article on understanding ISO 9001 customer satisfaction requirements.

Clause 9.3 (Management review): The needs and expectations of relevant interested parties must be considered as part of management review inputs.

When you understand these connections, you realise that Clause 4.2 is not a box to tick during implementation. It is the foundation on which much of the QMS logic rests.

Common Mistakes Organisations Make With Clause 4.2

After conducting hundreds of audits across Australia and internationally, certain patterns come up repeatedly when Clause 4.2 is not implemented well.

Listing interested parties without identifying requirements

Many organisations produce a list of stakeholders and stop there. The clause requires you to go further and determine what those parties actually require from you in relation to the QMS. A list of names without requirements attached is only half the work.

Including every conceivable party regardless of relevance

The opposite problem is equally common. Some organisations try to demonstrate thoroughness by listing every party they can think of, including ones that have no bearing on the QMS. This makes the register unwieldy and harder to maintain. Relevance is the filter. Apply it.

Treating the register as a one off document

Clause 4.2 requires you to monitor and review information about interested parties and their requirements. That means the register needs to be a living document, not something created during implementation and never touched again. Regulatory changes, new customers, supply chain changes, and shifts in community expectations all require the register to be updated.

Failing to link requirements to QMS processes

Identifying a requirement is only useful if the QMS actually addresses it. If your register notes that a regulator requires product traceability but your QMS has no traceability process, you have identified a gap and left it open. The register should prompt action, not just record information.

Not involving the right people

Clause 4.2 analysis is often done by the quality manager alone. In practice, the best results come from involving people who actually interact with interested parties. Sales staff know what customers expect. Procurement staff know supplier requirements. Operations managers know what regulators inspect. Pull that knowledge into the process.

What Auditors Look for in Clause 4.2

When an internal or external auditor reviews Clause 4.2, they are looking for evidence that the organisation has genuinely thought about who matters to the QMS and why. They are not just checking that a document exists.

Expect auditors to ask questions like:

  • How did you determine which interested parties are relevant to your QMS?
  • Can you walk me through the requirements you identified for your key customers and regulators?
  • When was this last reviewed, and what triggered the review?
  • How do the requirements identified here flow into your risk assessment or quality objectives?
  • Have there been any changes to regulations or customer requirements recently? How did you capture those?

If you can answer these questions with reference to actual evidence, such as a reviewed register, meeting minutes, or a documented process for monitoring regulatory changes, you are in good shape. If you cannot, expect a nonconformity or at minimum an observation.

For a deeper look at what auditors commonly raise against Clause 4 as a whole, see our article on common ISO 9001 Clause 4 nonconformities and how to avoid them.

A Practical Approach for Quality Managers

If you are setting up or reviewing your Clause 4.2 compliance, here is a straightforward approach that works in practice.

Start by gathering a small group of people who deal with different stakeholder groups. Run a short workshop, maybe an hour, and brainstorm who could affect or be affected by your QMS. Do not filter yet, just list.

Then apply the relevance test. For each party on the list, ask whether they can affect your ability to deliver conforming product or service, or affect customer satisfaction. If yes, they are in. If no, explain why and move on.

For those that are in, identify their requirements. Be specific. “Customers want good quality” is not a requirement. “Customer X requires products to meet AS 1234 and delivery within 5 business days of order confirmation” is a requirement.

Record the analysis in a format that works for your organisation. Link each requirement to the QMS process or control that addresses it. Set a review frequency, at minimum annually, and connect it to your management review cycle.

Finally, make sure someone owns it. The quality manager is the obvious choice, but the analysis should be informed by input from across the business.

Clause 4.2 and the Upcoming ISO 9001:2026 Revision

The ISO 9001 standard is currently under revision, with the 2026 edition expected to bring some changes to how context and interested parties are addressed. Early indications suggest the new edition will place greater emphasis on the needs of workers as interested parties, and may strengthen the connection between interested party analysis and risk based thinking.

If you want to understand what is coming and how it may affect your QMS, our article on ISO 9001:2026: What Is Changing in the New Edition provides a useful overview.

For now, organisations that have a robust, regularly reviewed Clause 4.2 process will be well placed to transition, because the fundamentals of the clause are unlikely to change significantly.

Building Auditor Competence Around Clause 4

If you are an internal auditor or aspiring lead auditor, understanding Clause 4.2 deeply is important not just for auditing quality management systems, but because the same clause structure appears in ISO 14001 and ISO 45001 under the Harmonised Structure. The skills you develop in auditing interested parties under ISO 9001 transfer directly to environmental and safety management system audits.

At Audit Workshop, our ISO 9001 Internal Auditor and Lead Auditor courses cover Clause 4 in detail, including how to audit interested party analysis in a way that goes beyond document review. You will learn how to ask the right questions, assess whether the analysis is genuine, and identify gaps that a checklist alone would miss. Whether you are building skills for internal auditing or working toward certification body work, understanding clauses like 4.2 at a practical level is what separates a competent auditor from someone who just reads the standard.

Frequently Asked Questions

ISO 9001 does not prescribe a specific document format for Clause 4.2. However, maintaining a register is strongly recommended because it makes the analysis visible, auditable, and easier to review. Without some form of documented record, it is very difficult to demonstrate to an auditor that the analysis has been done thoroughly and kept current.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.