Clause 4.2, Understanding the needs and expectations of interested parties, is one of the clauses I most often see treated as a tick-box exercise: a register filled in once, filed away, and never looked at again. It is also a piece of string. How far you take it depends entirely on the business, on which standards you run, and on how much you want the register to actually do for you. This guide walks from the bare minimum the clause will accept up to the version that quietly runs part of your management system.
Clause 4.2 is part of the common “Annex SL” high-level structure shared by the modern management-system standards, so it appears in much the same form across all of them, including ISO 9001, ISO 45001, ISO 14001, ISO 27001 and ISO 42001. It sits deliberately at the front of every standard, between 4.1 Organisational Context and 4.3 Scope. The logic is simple: to build a management system that satisfies everyone it needs to serve, you first work out who those parties are and what they need and expect, then make sure the system delivers it.

The fundamental requirement, and nothing more
Strip clause 4.2 back to its core and it asks for two things:
- Identify the interested parties relevant to the management system: the people, companies, authorities and groups that interface with your organisation.
- Identify their requirements, meaning their needs and expectations.
In ISO 9001, that is the whole clause: a quality management system can satisfy 4.2 by documenting, for each party, who they are and what they want. Two columns. But ISO 14001 and ISO 45001 go one step further inside clause 4.2 itself, which is where “nothing more” stops being true. Both require you to also determine which of those needs and expectations become the organisation’s compliance obligations (the term ISO 14001 uses) or its legal requirements and other requirements (ISO 45001). For an environmental or safety system that third determination is mandatory, so the bare two-column register is the ISO 9001 minimum, not a universal one.
The two information-focused standards take a third step of their own. ISO 27001 (information security) and ISO 42001 (AI management) keep those first two determinations, then require you to decide which of the interested parties’ requirements will be addressed through the management system. So the count of mandatory determinations inside clause 4.2 rises from two in ISO 9001, to three in ISO 14001 and ISO 45001 (the compliance-obligations step), to a different third in ISO 27001 and ISO 42001 (the in-scope step). Same clause number, four subtly different requirements depending on which standard is in front of you.
When I audit this clause, the tell is always the same at this level. The strongest registers name specific regulators, clients and neighbours rather than vague categories, and you can see a genuine cross-section of the business took part rather than one manager filling it out alone. Typical parties include certification bodies, owners, management, employees, suppliers and subcontractors, partners, clients, government agencies, finance and insurance providers, emergency services, landlords, neighbours, the public, unions, utilities, media and regulators.
The 2024 amendment: climate change now sits over the top
There is one more change that applies to every one of these standards at once. On 23 February 2024, ISO issued a common amendment on climate change to the whole family of management-system standards. It added a sentence to clause 4.1: the organisation shall determine whether climate change is a relevant issue for its context. And it added a note to clause 4.2: relevant interested parties can have requirements related to climate change.
The 4.1 line is a firm requirement. You must make the determination and be able to show it, even where your conclusion is that climate change is not material to what you do. The 4.2 addition is a note rather than a “shall”, but auditors and certification bodies now expect to see that you considered it as you worked through your interested parties. In practice that means asking, party by party, whether any of their needs or expectations are climate-related: a customer pushing for a lower-carbon supply chain, a regulator’s emissions reporting, an insurer pricing physical climate risk, an investor’s ESG expectations, a workforce that expects heat-stress controls. Where the answer is yes, that requirement belongs in the register like any other. Where it is no, a short line recording that you considered climate change and found nothing material is enough.
Because this now sits inside 4.1 and 4.2, our register template carries a climate-change prompt against each interested party, so the consideration is deliberate rather than something you scramble to justify at the next audit.
How far do you take it? The clause is a piece of string
Most businesses benefit from going further than the two-column minimum, and two of the standards actually require you to. Here is the ladder, and who pushes you up each rung.
Rung 1: who they are, and what they want. The base clause 4.2 requirement above. Needs and expectations, documented.
Rung 2: which requirements are legal obligations. Both ISO 14001 and ISO 45001 build this into clause 4.2, requiring you to determine which of those needs and expectations become the organisation’s compliance obligations (the ISO 14001 term) or its legal requirements and other requirements (ISO 45001). For those two standards it is mandatory. ISO 9001 does not require it, but separating the “we must” from the “they would like” is still worth doing, because the legal ones carry consequences the others do not.
Rung 3: which requirements the system will address. Both ISO 27001 (information security) and ISO 42001 (AI management) go a step further again, requiring you to determine which of these requirements will be addressed through the management system. This is a useful discipline in practice: not every expectation of every party is something your ISMS or AI management system is the right tool to meet, and saying so on the register keeps the scope honest.
Rung 4: how each requirement is addressed, and who owns it. No standard strictly requires this, but it is where the register stops being a list and starts being a management tool. Naming the process that meets the requirement, and the role accountable for it, is what turns 4.2 into something an auditor and a manager can both use.
Rung 5: the cherry on top, measuring effectiveness. A question that always comes up is: how do you measure whether these requirements are actually being fulfilled? None of the standards require you to answer it. But if you want to, you tie a measurable objective at clause 6.2 to each interested party, so the register connects to something you actually track. That is the difference between asserting you meet a party’s needs and being able to show it.
You do not have to climb the whole ladder. The point of clause 4.2 being a piece of string is that you cut it to the length your business, your standards and your appetite justify.
My preferred register layout
When I build one of these, the layout I reach for carries the register up to rung four as standard, with rung five available when the organisation wants it. Five columns:
- Interested Party
- Quality Requirements (including legal)
- How Quality Requirements are addressed
- Responsibility for managing quality requirements
- Associated Quality Objectives (the cherry on top, if you want it)
Here it is worked through with a typical ISO 9001 set of parties. Use it as a pattern rather than a template to copy, because column two onward is where your context lives:
| Interested Party | Quality Requirements (including legal) | How Quality Requirements are addressed | Responsibility for managing | Associated Quality Objectives |
|---|---|---|---|---|
| Customers | Conforming product or service, on-time delivery, responsiveness; Australian Consumer Law obligations (legal) | Contract review, delivery scheduling, complaints and feedback process | Account Manager | On-time delivery at or above 98%; two or fewer valid complaints per quarter |
| Employees and workers | A safe workplace (WHS law, legal), fair pay, clear instructions and training | Inductions, defined procedures, competency and training records | HR / Line Managers | Training-plan completion at or above 90% |
| Owners and shareholders | Profitability, growth, protected reputation | Business plan, KPI reporting, management review | Director | Revenue and margin targets met |
| Suppliers and subcontractors | Clear specifications, prompt payment on agreed terms (contractual, legal) | Approved supplier list, purchase-order terms, payment schedule | Procurement | Supplier conformance at or above 95% |
| Regulators and government | Compliance with applicable legislation and licence conditions (legal) | Legal and compliance-obligations register, obligation reviews | Compliance / Director | Zero material non-compliances |
| Certification body | Conformance to ISO 9001 and a maintained, effective system | Internal audit programme, management review, corrective action | Management Representative | Certification maintained; zero major non-conformities at surveillance |
Read across any row and the clause comes alive: a requirement (with the legal ones flagged), the process that meets it, a named owner, and, if you have taken the last step, a number that tells you whether the promise is being kept. Read down the objectives column and you have the first draft of your clause 6.2 objectives, built from the needs of the parties the system exists to serve.
Running more than one standard? Extend the register, do not duplicate it
This is where the layout earns its keep for an integrated management system. You do not build a separate interested-parties register for each standard. You keep the one list of interested parties in column one, then repeat columns two to five for each standard you run.
So a business certified to ISO 9001 and ISO 27001 keeps the same parties down the left, then sets out, side by side:
- Quality Requirements, How addressed, Responsibility, Quality Objectives
- Information Security Requirements, How addressed, Responsibility, Information Security Objectives
The interested parties rarely change between standards; a customer is still a customer. What changes is what each party needs from that system. A customer’s quality requirement is a conforming product on time; their information-security requirement is that you protect the data they hand you. Same party, different column set. You can expand the list of parties for a given standard where it makes sense (an ISMS often brings in parties a QMS does not), but the shared spine keeps the whole thing coherent and stops you maintaining three registers that quietly drift apart.
Here is the register above extended to add ISO 27001, shown with three representative parties. The quality block is unchanged; the information-security block simply repeats columns two to five for the same parties:
| Interested Party | Quality Requirements (incl. legal) | How Quality is addressed | Quality Responsibility | Quality Objective | Information Security Requirements (incl. legal) | How Info Sec is addressed | Info Sec Responsibility | Info Sec Objective |
|---|---|---|---|---|---|---|---|---|
| Customers | Conforming product or service, on-time delivery; Australian Consumer Law (legal) | Contract review, delivery scheduling, complaints process | Account Manager | On-time delivery at or above 98% | Protection of the personal and commercial data they share; Privacy Act and APP obligations (legal) | Access control, encryption, and data-handling controls from Annex A | ISMS Manager | Zero reportable data breaches |
| Employees and workers | Safe workplace (WHS law, legal), clear instructions, training | Inductions, defined procedures, competency records | HR / Line Managers | Training-plan completion at or above 90% | Fair handling of their own personal data; clarity on acceptable use (legal) | Acceptable-use policy, security-awareness training, access provisioning and revocation | ISMS Manager / HR | Security-awareness training completion at or above 95% |
| Certification body | Conformance to ISO 9001 and a maintained, effective system | Internal audit programme, management review, corrective action | Management Representative | Certification maintained; zero major non-conformities | Conformance to ISO 27001, a current Statement of Applicability, an effective ISMS | Internal audit, risk assessment and SoA upkeep, management review | Management Representative | Certification maintained; zero major non-conformities |
A register this wide is naturally happier in a spreadsheet than on a page, and in practice that is where it usually lives. The point is the structure: one column of interested parties on the left, then a four or five column block per standard, never a separate register per standard.
Free template: download our Interested Parties Register template (Excel) to start from. It includes both layouts above (single-standard and integrated), the worked examples, a climate-change column per the 2024 amendment, blank rows ready to complete, and a how-to tab explaining the piece-of-string approach.
That single, extended register is exactly the kind of integrated artefact that makes an integrated management system cheaper to run than several parallel ones.
Keeping it alive: clause 9.3
Clause 4.2 requires you to monitor and review information about interested parties and their requirements. The implication is that the register is kept current, not frozen at the date it was written.
The best way to satisfy this, and the one I recommend on every system, is to make a review of the interested parties register a standing input to the management review under clause 9.3. Parties change, requirements change, new regulators and new client demands appear. Reviewing the register at each management review means those changes are caught deliberately rather than discovered at the next audit. Reviewing it again under clause 6.3 Planning of Changes catches the rest, so a change to the business does not quietly leave a party unserved or introduce a new one unnoticed.
Interested parties (clause 4.2): FAQs
What is an interested party in ISO 9001?
Any person or organisation that can affect, be affected by, or believe itself to be affected by your management system: customers, employees, suppliers, regulators and more. Clause 4.2 asks you to determine who they are and what they need.
What is the minimum clause 4.2 requires?
For ISO 9001, identify the interested parties and identify their requirements (needs and expectations). ISO 14001 and ISO 45001 add one mandatory step inside 4.2: determining which of those become your compliance obligations (ISO 14001) or legal and other requirements (ISO 45001). Everything beyond that, how requirements are addressed, responsibilities and objectives, is good practice you choose to add.
How is clause 4.2 different in ISO 14001, ISO 45001 and ISO 27001?
ISO 14001 also asks you to determine which needs and expectations become your compliance obligations, and ISO 45001 which are, or could become, legal requirements and other requirements. ISO 27001 instead asks you to determine which requirements will be addressed through the management system. The base clause in ISO 9001 asks for none of these, though all are worth doing.
Do you have to link interested parties to objectives?
No. No standard requires it. Tying a measurable clause 6.2 objective to each party is the optional last step that lets you measure, rather than assert, that their requirements are being met.
How often should you review interested parties?
At least at each management review (clause 9.3), and whenever the business, market or obligations change (clause 6.3).
Do I need to include climate change in my interested parties register?
Since the 23 February 2024 amendment, clause 4.1 requires you to determine whether climate change is a relevant issue, and a note to clause 4.2 flags that interested parties can have climate-related requirements. You do not have to invent climate requirements where none exist, but you are expected to have considered, party by party, whether any of their needs are climate-related and to record the ones that are. A documented “considered, not material” position is fine where that is the honest answer.
How Streamline can help
Streamline designs, implements, audits and mentors practical ISO management systems, built around how your business actually operates. Whether you need a single standard or an integrated management system spanning quality, safety, environment, information security and AI, we build registers like the one above that do real work rather than sit in a folder. You deal directly with an experienced ISO auditor who knows exactly what accredited certification bodies look for. Already built your system in-house or with AI tools? We provide the independent internal audit that keeps it compliant and certification-ready.
Speak with an experienced ISO auditor
For help with clause 4.2 or any part of your management system, contact us. Email hello@streamline.business or call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











