Why Customer Focus Sits in the Leadership Clause
Most people who work with ISO 9001 know that customer satisfaction is measured under Clause 9.1.2 and that customer requirements are captured under Clause 8.2. What surprises some quality managers is that customer focus also appears in Clause 5, right inside the leadership and commitment section. That placement is deliberate. ISO 9001 is telling you that customer focus is not a measurement activity or a customer service function. It is a leadership responsibility.
On this page
Clause 5.1.2 is short. It contains three requirements, and on first reading they can seem obvious. But when you audit organisations against this clause, you quickly discover that the obvious things are often the ones that get the least attention. This article walks through each requirement in plain terms, explains what genuine conformance looks like in practice, and gives you the questions and evidence you should be looking at whether you are preparing for a certification audit or running an internal audit of your own system.
What Clause 5.1.2 Actually Says
The clause requires top management to demonstrate leadership and commitment with respect to customer focus by ensuring that:
- Customer and applicable statutory and regulatory requirements are determined, understood, and consistently met.
- The risks and opportunities that can affect conformity of products and services and the ability to enhance customer satisfaction are determined and addressed.
- The focus on enhancing customer satisfaction is maintained.
Three requirements. Each one connects to other parts of the standard, which is why auditing this clause properly means following threads across the whole system rather than just reading a policy statement.
Exemplar Global Recognised Training ProviderRTP No. 310970Requirement One: Determining and Meeting Customer Requirements
What this means in practice
The first requirement links directly to Clause 8.2, which deals with how your organisation captures requirements for products and services. But Clause 5.1.2 asks something different. It asks whether top management has ensured that this process exists, that it works, and that requirements are consistently met. The emphasis is on top management ownership, not just process existence.
In a certification audit, an auditor will ask a senior leader how they know that customer requirements are being captured correctly. A good answer involves the leader describing the review process, citing recent examples where requirements were clarified with a customer before work began, and pointing to evidence that statutory and regulatory requirements have been identified and built into the delivery process.
A weak answer is a blank look followed by a reference to the quality manager. That does not demonstrate leadership. It demonstrates delegation without oversight.
The statutory and regulatory piece
This part of the requirement catches organisations out more than the customer requirements piece. Statutory and regulatory requirements relevant to your products and services are not optional. They are part of what your customer expects, even if the customer never mentions them explicitly. A construction company that meets every client specification but ignores relevant building codes has not met customer requirements in the full sense of the clause.
Top management needs to be able to demonstrate that the organisation has identified the applicable legal requirements, that these are kept current, and that they feed into how products and services are designed, produced, and delivered. This is not just a compliance function. It is a leadership responsibility under Clause 5.1.2.
Requirement Two: Risks and Opportunities That Affect Customer Satisfaction
The connection to Clause 6.1
The second requirement links customer focus to risk based thinking. When ISO 9001 says top management must ensure that risks and opportunities affecting the ability to enhance customer satisfaction are determined and addressed, it is asking whether your risk process actually considers the customer perspective.
Many organisations run a risk register that focuses on operational risks, financial risks, and safety risks. Customer satisfaction risks are either absent or buried at the bottom. That is a conformance gap under both Clause 5.1.2 and Clause 6.1.
Examples of customer satisfaction risks that should appear in a well maintained risk register include:
- Key supplier delays that could affect delivery commitments.
- Staff turnover in roles that hold critical customer relationships or technical knowledge.
- Changes in regulatory requirements that affect product compliance.
- New competitors offering faster delivery or lower cost alternatives.
- Technology changes that affect how customers want to interact with your organisation.
What auditors look for here
When auditing this requirement, the question is not whether a risk register exists. The question is whether customer satisfaction is genuinely represented in it and whether top management reviews and acts on it. Look for evidence that the management review covers risks and opportunities related to customers, not just internal operational issues. Check whether the outputs of management review include decisions that were made in response to customer related risks.
If the management review minutes show a list of KPIs with no discussion of what the trends mean for customers, that is a gap worth noting. If the risk register has not been updated since the last certification audit and customer related risks are absent, that is a more serious finding.
Requirement Three: Maintaining the Focus on Enhancing Customer Satisfaction
Enhancement versus just meeting requirements
The third requirement uses the word enhancing, not just maintaining. That distinction matters. An organisation that consistently delivers what it promised is conforming. An organisation that looks for ways to deliver more value, reduce customer effort, or improve the experience is enhancing. ISO 9001 asks top management to maintain that forward looking orientation.
In practice, this means top management should be able to describe what they are doing to improve customer satisfaction, not just what they are measuring. If the only answer is that the organisation sends a survey once a year and the score has stayed steady, that is not enhancement. That is monitoring.
Enhancement looks like using customer feedback to change a process. It looks like a management review decision to invest in faster response times after complaint data showed a pattern. It looks like a new onboarding process that was designed after customers said they found the start of a project confusing.
The role of customer satisfaction data
Clause 9.1.2 requires the organisation to monitor customer perceptions. The data gathered under that clause is the fuel for Clause 5.1.2. Top management should be consuming that data, asking questions about it, and making decisions based on it. If customer satisfaction data is collected by the quality team, reviewed by the quality team, and filed by the quality team without ever reaching the leadership table in a meaningful way, the organisation has a conformance issue under Clause 5.1.2.
This is one of the most common findings in certification audits. The data exists. The measurement process works. But the link between customer satisfaction data and leadership decision making is weak or absent. For a deeper look at how this measurement clause works, see our article on understanding ISO 9001 customer satisfaction requirements.
Who Counts as Top Management Under This Clause
This is worth addressing directly because it causes confusion. Top management under ISO 9001 means the person or group of people who direct and control the organisation at the highest level within the scope of the QMS. In a large organisation with a certified division, that might be the general manager of that division rather than the CEO of the parent company. In a small business, it might be the owner.
What it does not mean is the quality manager, unless the quality manager genuinely has the authority to direct and control the organisation. In most organisations, the quality manager is responsible for managing the system, not for leading the business. Clause 5.1.2 is aimed at the people who make strategic decisions, allocate resources, and set the direction of the business.
When you audit Clause 5.1.2, you need to interview the people who actually hold that authority. Interviewing the quality manager about leadership commitment will not give you the evidence you need. You need to sit down with the CEO, the managing director, or the general manager and ask them directly.
Common Nonconformities Under Clause 5.1.2
Based on what comes up repeatedly in certification audits and internal audits, these are the most common ways organisations fall short of this clause:
- Customer requirements are captured at the operational level but top management has no visibility of whether they are consistently met. The process exists but leadership oversight is absent.
- The risk register does not include customer satisfaction risks. Risks are framed around operations and finance, with no explicit consideration of what could affect the customer experience.
- Customer satisfaction data is collected but not discussed at management review in a way that drives decisions. The data appears as a number in a report rather than as a topic for analysis and action.
- Top management cannot describe what the organisation is doing to enhance customer satisfaction. They can describe what is being measured but not what is being improved.
- Statutory and regulatory requirements are not formally identified and maintained. The organisation relies on individuals knowing the rules rather than having a documented and reviewed list of applicable requirements.
For a broader look at how Clause 5 nonconformities present in audits, see the article on the most common ISO 9001 Clause 5 nonconformities.
Audit Questions to Ask Top Management
If you are auditing Clause 5.1.2, these are the kinds of questions that will generate useful evidence. They are open questions designed to prompt a genuine response rather than a yes or no answer.
- How do you make sure the organisation understands what customers actually need, beyond what is written in a contract?
- What statutory or regulatory requirements apply to your products and services, and how do you keep that list current?
- When did you last review the risks that could affect your ability to satisfy customers? What came out of that review?
- Walk me through the last time customer feedback changed something in the way you operate.
- How does customer satisfaction performance reach you, and what decisions have you made based on it in the last twelve months?
- What are you actively working on to improve the customer experience, not just maintain it?
The answers to these questions will tell you very quickly whether customer focus is genuinely embedded in leadership thinking or whether it is a compliance exercise managed somewhere below the leadership team.
How Clause 5.1.2 Connects to the Rest of the Standard
One of the useful things about understanding this clause well is that it helps you see the standard as a connected system rather than a list of separate requirements. Clause 5.1.2 draws on and feeds into:
- Clause 4.2: Interested parties, including customers, are identified and their requirements understood.
- Clause 6.1: Risks and opportunities, including those affecting customer satisfaction, are determined and addressed.
- Clause 8.2: Customer requirements are determined and reviewed before commitments are made.
- Clause 9.1.2: Customer satisfaction is monitored and the results are analysed.
- Clause 9.3: Management review includes customer satisfaction performance and drives decisions.
When you audit Clause 5.1.2 and find a weakness, it is worth checking whether the same weakness shows up in these related clauses. A leadership team that is disconnected from customer focus will usually leave evidence across multiple parts of the system, not just in one clause.
Exemplar Global Recognised Training ProviderRTP No. 310970Preparing for a Certification Audit Against This Clause
If you are a quality manager preparing your organisation for a certification audit, the most important thing you can do for Clause 5.1.2 is prepare your senior leaders for the conversation. An auditor will want to speak with top management directly. The quality manager cannot answer on their behalf.
Brief your leaders on what the clause requires. Make sure they can talk about customer requirements, risks related to customers, and what the organisation is doing to improve. Make sure the management review minutes show genuine engagement with customer satisfaction data, not just a table of numbers. Make sure the risk register includes customer related risks that have been reviewed and acted on.
If any of those things are missing, fix them before the audit. Not by creating paper that looks good, but by having the real conversations at the leadership level that the clause is asking for.
Building Real Customer Focus Into Leadership Practice
The intent behind Clause 5.1.2 is not to create a compliance checkbox. It is to make sure that the people who run the organisation keep customers at the centre of how they think about the business. That is harder than it sounds, especially in organisations where leadership attention is pulled toward financial performance, operational efficiency, and internal priorities.
The standard is asking top management to ensure that customer requirements are met, that risks to customer satisfaction are managed, and that the organisation is always looking for ways to do better. When leadership genuinely owns those three things, the rest of the quality management system tends to work better as well. When leadership treats customer focus as something the quality team handles, the system becomes a compliance exercise rather than a business tool.
If you want to develop the skills to audit leadership commitment effectively, including how to interview top management, assess evidence of genuine engagement, and identify gaps that matter, the ISO 9001 Internal Auditor and Lead Auditor courses at Audit Workshop are built around exactly that kind of practical auditing capability. The training is delivered by an auditor who has conducted hundreds of certification audits and knows where the real findings hide.













