Why the Quality Policy Gets Audited So Often
The quality policy is one of the first documents an auditor asks to see. It sits at the top of your management system, and it tells an auditor a great deal about whether top management genuinely understands what ISO 9001 requires. A policy that reads like a marketing brochure, or one that could apply to any organisation on the planet, is a red flag. A policy that is specific, signed, communicated, and visibly connected to your quality objectives is exactly what Clause 5.2 is asking for.
On this page
This article walks through every requirement in Clause 5.2 of ISO 9001:2015, explains what auditors actually look for, and gives you practical guidance on writing a policy that will hold up under scrutiny. If you are a quality manager preparing for certification, or an internal auditor reviewing your organisation's documented information, this is the guidance you need.
What Clause 5.2 Actually Requires
Clause 5.2 is split into two sub-clauses: 5.2.1, which deals with establishing the policy, and 5.2.2, which deals with communicating it. Both are equally important, and both are audited.
Clause 5.2.1: Establishing the Quality Policy
The standard requires that top management establish, implement, and maintain a quality policy that does all of the following:
- Is appropriate to the purpose and context of the organisation
- Provides a framework for setting quality objectives
- Includes a commitment to satisfy applicable requirements
- Includes a commitment to continual improvement of the quality management system
Each of those four points carries real weight. Let us go through them one by one.
Appropriate to Purpose and Context
This is where many policies fall flat. A policy that says “We are committed to delivering quality products and services to our customers” tells an auditor nothing about what the organisation actually does. Clause 4.1 requires you to understand the context of your organisation, and your quality policy should reflect that understanding.
If you are a civil engineering contractor working on infrastructure projects across regional Australia, your policy should reflect that. If you run a registered training organisation delivering nationally recognised qualifications, your policy should speak to that environment. The purpose of the organisation shapes what quality means in practice, and the policy should make that connection visible.
Auditors will cross-reference your policy against the outputs of your context analysis. If there is no logical relationship between the two, expect a finding.
A Framework for Quality Objectives
The policy does not set the objectives itself. That is done under Clause 6.2. What the policy must do is provide a framework that makes the objectives possible. Think of it as the direction of travel. The objectives are the specific destinations.
In practice, this means the policy should contain commitments that are broad enough to generate measurable objectives. If your policy commits to customer satisfaction, your objectives should include a specific measure of it. If your policy commits to on-time delivery, your objectives should track it. The linkage between the two should be visible and logical.
A common audit finding is a quality policy that mentions commitments to customer focus and continual improvement, but quality objectives that have no connection to either. The policy and the objectives need to tell a consistent story. You can see worked examples of what this looks like in practice in our article on example quality objectives that pass an audit.
Commitment to Satisfy Applicable Requirements
This includes both the requirements of the ISO 9001 standard itself and any statutory, regulatory, or contractual requirements that apply to your products and services. The policy does not need to list every piece of legislation, but it must make a clear and unambiguous commitment to meeting applicable requirements.
Auditors will test this commitment during the audit by looking at whether your processes actually reflect it. A policy that says you are committed to meeting requirements, but where your organisation has no process for identifying or monitoring legal and contractual obligations, will generate a nonconformity.
Commitment to Continual Improvement
This is not optional wording. The standard explicitly requires the commitment to continual improvement of the QMS to appear in the policy. The word “continual” is deliberate. It means ongoing and sustained, not a one-off project.
Auditors will look for evidence that this commitment translates into action. That means looking at corrective action records, internal audit findings and how they were addressed, management review outputs, and whether quality objectives are being reviewed and updated over time. A policy that mentions continual improvement but where the management system has not changed in three years will raise questions.
Exemplar Global Recognised Training ProviderRTP No. 310970Clause 5.2.2: Communicating the Quality Policy
Having a well-written policy is only half the requirement. Clause 5.2.2 requires that the quality policy be available as documented information, be communicated within the organisation, be available to relevant interested parties, and be appropriate for the organisation.
Available as Documented Information
The quality policy must be documented. This is one of the few pieces of documented information that ISO 9001 explicitly mandates. It needs to be controlled under your document control process, with a version number, review date, and approval signature.
Auditors will check that the copy on the wall, the intranet, or the quality manual is the current version. A mismatch between the approved document and what is displayed is a classic minor nonconformity. Keep your document control tight here.
Communicated Within the Organisation
This is where many organisations get caught. Having the policy on the intranet is not the same as communicating it. Auditors will interview workers at various levels and ask whether they are aware of the quality policy and what it means for their role.
The test is not whether workers can recite the policy word for word. The test is whether they understand what quality means in their job and how their work contributes to the organisation's quality commitments. A production operator who can explain why checking their work before it moves to the next stage matters is demonstrating awareness of the policy in practice.
Induction training records, toolbox talks, team meeting agendas, and awareness posters are all evidence of communication. None of them are sufficient on their own. The best evidence is workers who can speak to the policy's intent in plain language.
Available to Relevant Interested Parties
This does not mean you must send the policy to every customer and supplier. It means that where interested parties have a legitimate interest in your quality commitments, the policy should be accessible to them. For many organisations, this means publishing the policy on their website or making it available on request. For others, particularly those in supply chains where customers require evidence of quality management, it may mean including it in tender responses or supplier documentation packages.
What Makes a Quality Policy Fail an Audit
After conducting hundreds of certification audits, the same weaknesses appear repeatedly. Here is what to watch for.
Generic Language With No Connection to the Business
Policies that could belong to any organisation in any industry are a problem. If you removed the company name from your policy and it could fit any of your competitors, it is not appropriate to the purpose and context of your organisation. Rewrite it with specific reference to what you do, who you serve, and what quality means in your operating environment.
No Linkage to Quality Objectives
If your policy commits to customer satisfaction but your quality objectives make no mention of it, the framework requirement is not met. Map your policy commitments to your objectives and make sure the connection is explicit. Our article on ISO 9001 Clause 6.2 quality objectives explains how to set objectives that are consistent with the policy.
Not Signed or Not Current
A policy without a signature from top management is a document without ownership. ISO 9001 places responsibility for the quality policy firmly with top management under Clause 5.1. The signature is evidence of that ownership. Similarly, a policy that was last reviewed five years ago and has not been updated despite significant changes to the business is unlikely to still be appropriate to the current context.
Workers Cannot Speak to It
If an auditor interviews three workers and none of them can explain what the quality policy means for their work, that is a communication failure. Training records might show the policy was covered in induction, but awareness is demonstrated through understanding, not attendance at a session.
The Policy Is Hidden
If the auditor has to ask multiple people where to find the quality policy, or if the version on display is different from the controlled document, document control is failing. The policy should be easy to find and the version on display should match the approved document.
How to Write a Quality Policy That Holds Up
Here is a practical approach to writing or reviewing your quality policy.
Start With Your Context
Pull out the outputs of your Clause 4.1 context analysis and your Clause 4.2 interested parties register. What are the key issues affecting your organisation? What do your customers and other interested parties need from you? The policy should reflect an understanding of this environment. If your context analysis identifies regulatory compliance as a critical issue, the policy should speak to that. If customer delivery performance is a key concern, the policy should address it.
Make Specific Commitments
The four requirements of Clause 5.2.1 give you the structure. Work through each one and make sure your policy addresses it in language that is specific to your organisation. Avoid vague commitments like “we strive for excellence.” Instead, commit to things you can actually measure and demonstrate. For example, a commitment to meeting agreed delivery schedules, maintaining product conformity, and improving the effectiveness of your management system is specific, testable, and directly linked to what your quality objectives should be measuring.
Keep It Short
A quality policy does not need to be a page long. A well-written policy of four to six sentences that covers all four requirements is more effective than a lengthy document that dilutes the key commitments in filler language. Short, clear, and specific is the goal.
Get Top Management to Own It
The policy must be established by top management, not written by the quality manager and signed off reluctantly. In practice, the quality manager usually drafts it, but the content should reflect genuine management commitment. Sit down with your senior leadership team, explain what the policy needs to achieve, and make sure the final version reflects their actual priorities. If the CEO cannot speak to what the policy means, it has not been communicated effectively at the top level either.
Build a Communication Plan
Once the policy is finalised, plan how you will communicate it. Induction training for new starters, refresher sessions for existing staff, inclusion in team meeting agendas, and display in work areas are all reasonable approaches. Document your communication activities so you have evidence to show an auditor. The goal is not compliance theatre. The goal is genuine awareness.
Auditing the Quality Policy: What Auditors Check
If you are an internal auditor reviewing the quality policy, here is what to look for during your audit.
- Is the policy documented and controlled with a version number and approval signature?
- Does the policy reflect the organisation's purpose and context?
- Does the policy provide a framework for quality objectives, and is that framework reflected in the actual objectives?
- Does the policy commit to satisfying applicable requirements?
- Does the policy commit to continual improvement of the QMS?
- Is the current version displayed and accessible in work areas?
- Can workers at various levels explain what the policy means for their work?
- Is there evidence that the policy has been communicated, such as training records or meeting minutes?
- Is the policy available to relevant interested parties?
- Has the policy been reviewed when significant changes occurred in the organisation?
For a deeper look at how auditors approach this clause during a certification or surveillance audit, see our article on how to audit the quality policy against ISO 9001 Clause 5.2.
Common Nonconformities Under Clause 5.2
The most frequent nonconformities raised against Clause 5.2 in certification audits fall into three categories. First, the policy does not provide a framework for quality objectives because the objectives have no logical connection to the policy's commitments. Second, the policy has not been communicated effectively, evidenced by workers who are unaware of it or unable to explain its relevance to their role. Third, the documented policy is not the current approved version, either because document control has failed or because the policy was updated but the displayed copies were not replaced.
Minor nonconformities in this area are common. Major nonconformities are less frequent but do occur, particularly where there is no quality policy at all, where the policy has not been signed by top management, or where there is a complete absence of evidence that it has ever been communicated to the workforce.
For a broader view of what commonly goes wrong across Clause 5, see our article on the most common ISO 9001 Clause 5 nonconformities.
Exemplar Global Recognised Training ProviderRTP No. 310970Keeping the Policy Current
The quality policy is not a set-and-forget document. ISO 9001 requires you to maintain it, which means reviewing it when circumstances change. Significant changes to the organisation's context, changes in customer requirements, changes in the regulatory environment, or changes in the strategic direction of the business are all triggers for reviewing the policy.
Build a policy review into your management review process under Clause 9.3. If the management review considers changes in external and internal issues and changes in the needs and expectations of interested parties, the quality policy should be checked for continued appropriateness at the same time. Document the outcome of that review, even if the conclusion is that no changes are needed.
Training for Auditors Who Review Quality Policies
If you are an internal auditor responsible for auditing your organisation's quality policy, or if you are preparing to conduct certification audits as a lead auditor, understanding how to evaluate documented information like the quality policy is a core competency. Knowing what the standard requires, what good looks like, and where the common gaps are is the difference between a surface-level review and an audit that adds genuine value.
At Audit Workshop, our ISO 9001 Internal Auditor and Lead Auditor training courses cover exactly this kind of practical clause interpretation. Dilawar Laghari, our lead trainer with over 14 years of compliance experience and 500 or more external certification audits behind him, teaches auditors how to evaluate the quality policy in the context of the whole management system, not just as a standalone document. Our courses are available live and self-paced, making them accessible whether you are working full time or preparing for a specific audit milestone.













