What Clause 4.2 Actually Says
ISO 9001 Clause 4.2 requires your organisation to determine two things: who the relevant interested parties are, and what their relevant requirements are. That is it. The clause is short, but the thinking behind it is not.
On this page
The full clause reads something like this: the organisation shall determine the interested parties that are relevant to the quality management system, and the requirements of those interested parties that are relevant to the quality management system. You then need to monitor and review information about these interested parties and their relevant requirements.
What the clause does not say is that you need to satisfy every requirement of every interested party. The word “relevant” appears twice, and that is deliberate. Not every stakeholder's expectation needs to land inside your QMS. Your job is to make a considered judgement about which ones do.
Why This Clause Exists
Before ISO 9001:2015, earlier versions of the standard were criticised for being too internally focused. Organisations could build a quality management system that looked good on paper but failed to account for the broader environment in which they operated. The 2015 revision introduced Clause 4 as a whole to fix that. Clause 4.1 asks you to understand your context. Clause 4.2 asks you to understand the people and groups that exist within and around that context.
The logic is straightforward. A quality management system that ignores the expectations of regulators, customers, suppliers, or employees is fragile. It might produce conforming product today and collapse under external pressure tomorrow. Clause 4.2 forces organisations to look outward and factor those external and internal forces into how the QMS is designed and operated.
This connects directly to ISO 9001 Clause 4.1, which covers the broader context of the organisation. The two clauses work together. Context without stakeholders is incomplete, and stakeholders without context lack grounding.
Exemplar Global Recognised Training ProviderRTP No. 310970Who Counts as an Interested Party?
ISO 9001 defines an interested party as a person or organisation that can affect, be affected by, or perceive themselves to be affected by a decision or activity. That is a broad definition, and intentionally so.
In practice, most organisations will identify some combination of the following:
- Customers: The most obvious group. Their product and service requirements feed directly into the QMS.
- Regulatory and government bodies: Licensing authorities, work health and safety regulators, environmental agencies, and similar bodies set requirements that the organisation must meet regardless of whether a customer asks for them.
- Employees and workers: Their expectations around fair treatment, safe conditions, and clear communication affect how the QMS functions day to day.
- Suppliers and subcontractors: Their performance directly affects your ability to deliver conforming product or service. Their requirements, such as payment terms or access arrangements, may also be relevant.
- Owners and shareholders: Financial performance expectations, ethical conduct, and governance requirements often flow from this group.
- Industry bodies and standards organisations: Membership obligations or sector codes of practice can impose requirements on the QMS.
- Local communities: Particularly relevant for manufacturers or construction companies where noise, traffic, or environmental impact affects neighbours.
- Certification bodies: If you hold or are seeking ISO 9001 certification, the requirements of your certification body are relevant.
The list above is a starting point, not a checklist you must tick off. Every organisation is different. A small professional services firm may have a short list dominated by clients and a couple of regulators. A large manufacturer might have dozens of relevant parties across multiple jurisdictions.
What Makes an Interested Party Relevant?
This is where most organisations struggle. Listing every conceivable stakeholder is easy. Determining which ones are actually relevant to the QMS takes judgement.
Ask yourself two questions for each potential interested party. First, can they affect the organisation's ability to consistently provide products and services that meet customer and applicable statutory and regulatory requirements? Second, can they affect the organisation's ability to enhance customer satisfaction?
If the answer to either question is yes, that party is likely relevant. If the answer is no, you may not need to include them in your QMS analysis, even if they matter to the business in other ways.
A practical example: a company that manufactures food packaging has a customer base of food manufacturers who must comply with food safety legislation. The relevant interested parties would include those customers, the food safety regulator, the raw material suppliers, and the workers who operate the production lines. The local council that manages the car park lease is probably not relevant to the QMS, even though they are a party the organisation interacts with.
What Are Relevant Requirements?
Once you have identified your relevant interested parties, Clause 4.2 asks you to determine their relevant requirements. Requirements can take many forms:
- Contractual obligations set out in customer agreements
- Legislative and regulatory requirements imposed by government
- Industry codes or standards that apply to your sector
- Internal policies or commitments made by the organisation
- Expectations communicated informally by suppliers or workers
Not every expectation is a requirement. A customer might prefer that you use a particular courier, but if it is not written into the contract and non compliance does not affect product conformity or satisfaction, it may not be a QMS requirement. Use your judgement and document your reasoning.
One area that catches organisations out is the distinction between statutory requirements and regulatory requirements. Statutory requirements come from legislation passed by parliament. Regulatory requirements come from regulations, codes, and standards issued under that legislation. Both are relevant. If your organisation operates in a licensed industry, the conditions attached to that licence are also requirements you need to account for.
How to Document Clause 4.2
ISO 9001 does not require a specific document format for Clause 4.2. There is no mandatory “interested parties register” prescribed by the standard. However, most organisations find it useful to maintain one, because it makes the analysis visible, auditable, and easier to review over time.
A practical register typically includes:
- The name or category of the interested party
- Why they are relevant to the QMS
- Their relevant requirements or expectations
- How those requirements are monitored or addressed within the QMS
- When the register was last reviewed
Keep it simple. A one page table is often enough for a small to medium organisation. Larger or more complex organisations may need more detail, particularly where regulatory requirements vary by site, product type, or jurisdiction.
The key is that when an auditor asks how you determined your interested parties and their requirements, you can show them a clear, logical record of that thinking. Vague answers like “we know our stakeholders” will not satisfy a competent auditor.
How Clause 4.2 Connects to the Rest of the QMS
Clause 4.2 is not a standalone exercise. The outputs of your interested party analysis feed into multiple other parts of the quality management system.
Clause 4.3 (Scope): The scope of your QMS must reflect the needs and expectations of relevant interested parties. If a major customer requires you to include a specific process in your QMS, that affects scope.
Clause 6.1 (Risks and opportunities): Interested party requirements are a primary input to your risk assessment. A regulatory change is a risk. A new customer requirement is both an opportunity and a potential risk if you cannot meet it.
Clause 8.2 (Requirements for products and services): Customer requirements, which come directly from Clause 4.2 analysis, drive the determination of product and service requirements.
Clause 9.1.2 (Customer satisfaction): Understanding what customers expect, which is a Clause 4.2 activity, is a prerequisite for measuring whether you are meeting those expectations. You can read more about this in our article on understanding ISO 9001 customer satisfaction requirements.
Clause 9.3 (Management review): The needs and expectations of relevant interested parties must be considered as part of management review inputs.
When you understand these connections, you realise that Clause 4.2 is not a box to tick during implementation. It is the foundation on which much of the QMS logic rests.
Common Mistakes Organisations Make With Clause 4.2
After conducting hundreds of audits across Australia and internationally, certain patterns come up repeatedly when Clause 4.2 is not implemented well.
Listing interested parties without identifying requirements
Many organisations produce a list of stakeholders and stop there. The clause requires you to go further and determine what those parties actually require from you in relation to the QMS. A list of names without requirements attached is only half the work.
Including every conceivable party regardless of relevance
The opposite problem is equally common. Some organisations try to demonstrate thoroughness by listing every party they can think of, including ones that have no bearing on the QMS. This makes the register unwieldy and harder to maintain. Relevance is the filter. Apply it.
Treating the register as a one off document
Clause 4.2 requires you to monitor and review information about interested parties and their requirements. That means the register needs to be a living document, not something created during implementation and never touched again. Regulatory changes, new customers, supply chain changes, and shifts in community expectations all require the register to be updated.
Failing to link requirements to QMS processes
Identifying a requirement is only useful if the QMS actually addresses it. If your register notes that a regulator requires product traceability but your QMS has no traceability process, you have identified a gap and left it open. The register should prompt action, not just record information.
Not involving the right people
Clause 4.2 analysis is often done by the quality manager alone. In practice, the best results come from involving people who actually interact with interested parties. Sales staff know what customers expect. Procurement staff know supplier requirements. Operations managers know what regulators inspect. Pull that knowledge into the process.
What Auditors Look for in Clause 4.2
When an internal or external auditor reviews Clause 4.2, they are looking for evidence that the organisation has genuinely thought about who matters to the QMS and why. They are not just checking that a document exists.
Expect auditors to ask questions like:
- How did you determine which interested parties are relevant to your QMS?
- Can you walk me through the requirements you identified for your key customers and regulators?
- When was this last reviewed, and what triggered the review?
- How do the requirements identified here flow into your risk assessment or quality objectives?
- Have there been any changes to regulations or customer requirements recently? How did you capture those?
If you can answer these questions with reference to actual evidence, such as a reviewed register, meeting minutes, or a documented process for monitoring regulatory changes, you are in good shape. If you cannot, expect a nonconformity or at minimum an observation.
For a deeper look at what auditors commonly raise against Clause 4 as a whole, see our article on common ISO 9001 Clause 4 nonconformities and how to avoid them.
A Practical Approach for Quality Managers
If you are setting up or reviewing your Clause 4.2 compliance, here is a straightforward approach that works in practice.
Start by gathering a small group of people who deal with different stakeholder groups. Run a short workshop, maybe an hour, and brainstorm who could affect or be affected by your QMS. Do not filter yet, just list.
Then apply the relevance test. For each party on the list, ask whether they can affect your ability to deliver conforming product or service, or affect customer satisfaction. If yes, they are in. If no, explain why and move on.
For those that are in, identify their requirements. Be specific. “Customers want good quality” is not a requirement. “Customer X requires products to meet AS 1234 and delivery within 5 business days of order confirmation” is a requirement.
Record the analysis in a format that works for your organisation. Link each requirement to the QMS process or control that addresses it. Set a review frequency, at minimum annually, and connect it to your management review cycle.
Finally, make sure someone owns it. The quality manager is the obvious choice, but the analysis should be informed by input from across the business.
Exemplar Global Recognised Training ProviderRTP No. 310970Clause 4.2 and the Upcoming ISO 9001:2026 Revision
The ISO 9001 standard is currently under revision, with the 2026 edition expected to bring some changes to how context and interested parties are addressed. Early indications suggest the new edition will place greater emphasis on the needs of workers as interested parties, and may strengthen the connection between interested party analysis and risk based thinking.
If you want to understand what is coming and how it may affect your QMS, our article on ISO 9001:2026: What Is Changing in the New Edition provides a useful overview.
For now, organisations that have a robust, regularly reviewed Clause 4.2 process will be well placed to transition, because the fundamentals of the clause are unlikely to change significantly.
Building Auditor Competence Around Clause 4
If you are an internal auditor or aspiring lead auditor, understanding Clause 4.2 deeply is important not just for auditing quality management systems, but because the same clause structure appears in ISO 14001 and ISO 45001 under the Harmonised Structure. The skills you develop in auditing interested parties under ISO 9001 transfer directly to environmental and safety management system audits.
At Audit Workshop, our ISO 9001 Internal Auditor and Lead Auditor courses cover Clause 4 in detail, including how to audit interested party analysis in a way that goes beyond document review. You will learn how to ask the right questions, assess whether the analysis is genuine, and identify gaps that a checklist alone would miss. Whether you are building skills for internal auditing or working toward certification body work, understanding clauses like 4.2 at a practical level is what separates a competent auditor from someone who just reads the standard.













