Why Clause 4.4 Is the Heart of ISO 9001
If you had to pick one clause that makes ISO 9001 a genuine management tool rather than a documentation exercise, it would be Clause 4.4. This is where the standard requires you to establish, implement, maintain, and continually improve a quality management system, and to do so by understanding and managing your processes as an interconnected system. Every other clause in ISO 9001 either feeds into or flows out of what Clause 4.4 demands.
On this page
The clause is short in word count but enormous in implication. It sits at the end of Clause 4, which deals with organisational context, interested parties, and scope. By the time you reach 4.4, the standard is essentially saying: now that you understand your organisation and what it needs to achieve, here is how you build the system that delivers it.
This article walks through every requirement in Clause 4.4, explains what it means in practice, and shows you what auditors look for when they assess it. Whether you are implementing a QMS for the first time, preparing for a certification audit, or auditing someone else's system, this is the clause you need to understand deeply.
The Process Approach: What It Actually Means
Clause 4.4 is built on the process approach, one of the seven quality management principles that underpin ISO 9001. The idea is straightforward: organisations achieve consistent results more effectively when they understand and manage their activities as interrelated processes rather than as isolated tasks or departments.
In practice, this means identifying what your key processes are, understanding how they connect, and managing them as a system. A process takes inputs, applies resources and controls, and produces outputs. Those outputs often become inputs to the next process. When you map this out across your organisation, you see the system as a whole rather than a collection of silos.
For a construction company, the processes might include tendering, project planning, procurement, construction, inspection, and handover. Each one depends on the one before it. A failure in procurement affects construction quality. A weakness in inspection affects handover. Managing these as a system means the connections between processes are just as important as the processes themselves.
This is very different from the old approach of writing a procedure for every activity and calling it a quality system. The process approach asks you to think about what each process is trying to achieve, what it needs to work properly, and how you know it is working.
For a deeper look at the process approach and how it applies in practice, see our article on the process approach explained with examples.
Exemplar Global Recognised Training ProviderRTP No. 310970The Eight Requirements of Clause 4.4.1
Clause 4.4.1 contains eight specific things the organisation must determine for each process in the QMS. These are not optional. They are the minimum information you need to understand and manage a process properly.
Inputs and Outputs
For every process, you need to know what goes in and what comes out. Inputs might be customer requirements, raw materials, data from a previous process, or regulatory specifications. Outputs might be a finished product, a service delivered, a report, or an approved design.
This sounds obvious, but many organisations struggle to articulate process outputs clearly. If you cannot state what a process produces, you cannot measure whether it is working. An auditor will ask about this directly, and vague answers like we just do the work are not sufficient.
Sequence and Interaction
The standard requires you to determine the sequence and interaction of your processes. This is where process maps and turtle diagrams become genuinely useful. You need to show how your processes connect, what triggers each one, and what passes between them.
Auditors look for evidence that the organisation understands these connections, not just that a flowchart exists on a wall somewhere. They will follow a thread through the system, from a customer order through design, procurement, production, and delivery, and check whether the interfaces between processes are managed.
Criteria and Methods
You need to determine the criteria and methods needed to ensure that both the operation and control of these processes are effective. This means defining how you know a process is running correctly and how you measure whether it is achieving its intended result.
For a procurement process, criteria might include supplier approval requirements, lead time targets, and acceptable quality levels for incoming goods. Methods might include supplier evaluations, goods inwards inspections, and purchase order review procedures.
The key word here is effective. The standard is not asking you to document everything that happens. It is asking you to identify the controls and measures that actually make the process work.
Resources
Each process needs resources to function. Clause 4.4.1 requires you to determine what resources are needed and ensure they are available. Resources include people with the right competence, equipment, infrastructure, and the work environment.
This requirement connects directly to Clause 7.1, which covers resources in detail. The point at the 4.4 level is that resource needs should be identified at the process level, not just managed generically across the organisation.
Responsibilities and Authorities
Someone needs to own each process. The standard requires you to assign responsibilities and authorities for processes. This does not mean every task needs a named individual. It means each process has a clear owner who is accountable for its performance and who has the authority to make decisions about it.
In small organisations, one person might own several processes. In larger ones, process ownership might sit with a department manager or a specialist role. What matters is that the ownership is clear and that the process owner actually understands and manages the process, rather than just having their name on a document.
Risks and Opportunities
Clause 4.4.1 requires you to address the risks and opportunities determined in accordance with Clause 6.1. This is where risk-based thinking becomes embedded in the process approach. Every process has things that could go wrong and things that could be improved or exploited.
At the process level, this means asking: what could prevent this process from achieving its intended output? What could cause it to produce a nonconforming output? What opportunities exist to improve the process or deliver better results for customers?
Auditors will check that risk and opportunity thinking is not just a standalone exercise done once a year. It should be visible in how processes are designed and controlled.
Evaluation and Improvement
The standard requires you to evaluate these processes and implement any changes needed to ensure they achieve their intended results. This is the Plan-Do-Check-Act cycle applied at the process level. You run the process, measure its performance, evaluate the results, and improve where needed.
This requirement is what separates a living QMS from a static documentation exercise. If your process performance data is not being used to drive improvement decisions, you are not meeting this requirement, regardless of how much documentation you have.
Improvement of Processes and the QMS
The final element of 4.4.1 requires you to improve the processes and the QMS itself. This connects to Clause 10, which covers improvement more broadly. At the 4.4 level, the point is that improvement is not something separate from running the system. It is built into how you manage every process.
Clause 4.4.2: Documented Information
Clause 4.4.2 addresses documented information for the QMS and its processes. It contains two requirements that are often misunderstood.
First, the organisation must maintain documented information to the extent necessary to support the operation of its processes. This means you need documents, procedures, work instructions, or whatever format makes sense, to the degree that people actually need them to run processes consistently. If a process is simple and well understood by everyone involved, minimal documentation may be sufficient. If it is complex, variable, or safety critical, more detailed documentation is appropriate.
Second, the organisation must retain documented information to the extent necessary to have confidence that the processes are being carried out as planned. This means records. You need evidence that processes actually ran as intended, not just that you have a procedure saying how they should run.
This distinction between documents (which tell people what to do) and records (which prove it was done) is fundamental to ISO 9001. Auditors spend a significant portion of every audit looking at records, because records are the evidence that the system is operating, not just existing on paper.
The phrase to the extent necessary appears twice in 4.4.2, and it is deliberate. ISO 9001 does not prescribe how much documentation you need. That judgement belongs to the organisation. But the organisation needs to be able to justify its choices. If a process consistently produces nonconforming outputs and there are no records showing how the process was controlled, the absence of documentation becomes a nonconformity.
What Auditors Actually Look For in Clause 4.4
When an auditor assesses Clause 4.4, they are not looking for a list of processes on a document. They are looking for evidence that the organisation genuinely understands and manages its system. Here is what that looks like in practice.
Process Identification That Reflects Reality
The processes identified in the QMS should match what actually happens in the organisation. Auditors frequently encounter systems where the documented processes bear little resemblance to how work is actually done. If the QMS says design is a process but the organisation does no design work, that is a problem. If the organisation does significant design work but the QMS barely mentions it, that is also a problem.
A good auditor will walk through the process map with the quality manager and then go and talk to the people doing the work. If the two pictures do not match, there is something to investigate.
Evidence of Process Monitoring
Auditors will look for evidence that process performance is being measured and that the results are being used. This might include quality objectives data, process KPIs, customer satisfaction results, internal audit findings, or nonconformity trends. The question is not just whether data exists, but whether someone is looking at it and doing something with it.
Visible Risk Thinking
Auditors will check whether risk-based thinking is embedded in process management. This means looking at whether controls in processes are designed to address known risks, whether process changes are evaluated for risk before implementation, and whether opportunities for improvement are being identified and acted on.
Outsourced Processes
Clause 4.4.1 includes a specific note about outsourced processes. If an organisation outsources any process that affects product or service conformity, that process must be controlled. The type and extent of control depends on factors like the risk of nonconformity and the competence of the external provider.
This is a common audit finding. Organisations often manage their internal processes well but have weak controls over outsourced activities. An auditor will ask about outsourced processes specifically and look for evidence that they are included in the QMS scope and controlled appropriately.
For a detailed look at how ISO 9001 handles outsourced processes and supplier management, see our article on ISO 9001 Clause 8.4: managing outsourced processes and suppliers.
Common Nonconformities Against Clause 4.4
Based on real audit experience, these are the issues that come up most often when Clause 4.4 is assessed.
Processes Listed But Not Managed
The organisation has a process map or a list of QMS processes, but there is no evidence of active management. No performance data, no assigned owners, no connection to the organisation's objectives. The system exists on paper but not in practice. This is typically raised as a major nonconformity because it goes to the core of what the clause requires.
Missing Sequence and Interaction
The organisation has identified individual processes but has not considered how they interact. There are gaps at the interfaces, where one process ends and another begins, and these gaps are where nonconformities tend to occur. An auditor who traces a product through the system and finds that no one is responsible for the handover between processes has found a real weakness.
Documented Information Not Reflecting Current Practice
Procedures describe how processes used to work, not how they work now. This is extremely common in organisations that have changed their operations but not updated their QMS documentation. The records show the actual practice, but the documents say something different. Auditors pick this up quickly by comparing what people describe in interviews with what the documented procedures say.
Outsourced Processes Not Identified
The organisation has outsourced significant activities, such as testing, logistics, or IT support, but these are not included in the QMS. There are no controls, no performance monitoring, and no documented information about how these processes are managed. This is a straightforward nonconformity against the outsourced process requirement in 4.4.1.
No Evidence of Evaluation and Improvement
Process performance data is collected but never reviewed. Improvement actions are not connected to process evaluation results. The QMS is running on autopilot with no evidence that anyone is checking whether it is actually working. Auditors look for management review records, corrective action trends, and objective performance data to assess whether this requirement is being met.
Practical Tips for Implementing Clause 4.4 Well
If you are building or improving a QMS, here is what actually works.
Start with the processes that matter most to your customers and your business outcomes. Do not try to map every activity in the organisation. Focus on the processes that directly affect product and service quality, and build outward from there.
Use turtle diagrams or simple process maps that people in the business actually understand and use. A complex flowchart that only the quality manager can interpret is not useful. The goal is shared understanding, not impressive documentation.
Assign genuine process owners, not just names on a document. A process owner should be the person who knows the process best, has the authority to change it, and is accountable for its performance. In many organisations, this is a supervisor or team leader, not a manager.
Connect process performance to your quality objectives. If you have a quality objective around on-time delivery, there should be a process that owns delivery performance, a measure that tracks it, and a review mechanism that uses the data to drive improvement.
Review your outsourced processes honestly. If you rely on external providers for anything that affects what your customers receive, those processes need to be in your QMS. This does not mean writing procedures for your suppliers. It means having controls, monitoring their performance, and taking action when they fall short.
For a practical guide to planning your internal audits to cover these processes systematically, our article on how to plan an ISO 9001 internal audit schedule for the year offers a useful framework.
Exemplar Global Recognised Training ProviderRTP No. 310970How Clause 4.4 Connects to the Rest of ISO 9001
Clause 4.4 does not stand alone. It is the foundation that every other clause builds on. Understanding these connections helps you see why the clause matters so much.
Clause 5.1 requires top management to promote the process approach. Clause 6.1 requires risks and opportunities to be determined, which feeds directly into how processes are controlled. Clause 7 covers the resources, competence, and documented information that processes need. Clause 8 covers the operational processes themselves. Clause 9 covers monitoring and measurement of process performance. Clause 10 covers improvement of processes and the system.
When an auditor assesses a QMS, they are essentially checking whether Clause 4.4 is being implemented across all of these areas. A weak Clause 4.4 implementation tends to produce weaknesses throughout the entire system.
If you want to understand how the full clause structure of ISO 9001 fits together, our article on ISO 9001 clauses explained in plain English provides a useful overview of the whole standard.
Building Real Competence in QMS Auditing
Understanding Clause 4.4 at a conceptual level is one thing. Being able to audit it effectively, or implement it well in a real organisation, requires a different kind of knowledge. You need to know what questions to ask, what evidence to look for, and how to judge whether a process approach is genuinely embedded or just documented for appearance.
This is the kind of practical knowledge that comes from structured auditor training. At Audit Workshop, our ISO 9001 internal auditor and lead auditor courses are built around real audit scenarios, not just clause-by-clause theory. You will work through process-based auditing techniques, learn how to follow an audit trail through a QMS, and develop the judgement to distinguish a system that works from one that only looks like it does on paper.
Whether you are a quality manager wanting to strengthen your internal audit programme, or a professional pursuing lead auditor credentials, our courses give you the practical skills that make the difference in real audits.










