
Practical, plain-English guides to the clauses of the ISO management system standards, written by a working ISO Lead Auditor. Each one explains what the clause actually requires, what auditors look for, and how to satisfy it without inventing paperwork nobody uses.
The guides are split into two groups, and the split matters more than it first appears.
Why the guides are split this way
The modern management system standards share a common high-level structure, often called Annex SL. That is why ISO 9001, ISO 45001, ISO 14001, ISO 27001 and ISO 42001 all have a clause 4 for context, a clause 6 for planning, a clause 9 for performance evaluation, and so on. Those common clauses support every standard you hold, which is exactly why an integrated management system is cheaper to run than several parallel ones: you build the backbone once.
Each standard then adds requirements specific to its discipline, and those are not transferable. Clause 8.2 is the clearest warning. In ISO 9001 it covers requirements for products and services; in ISO 45001 it is emergency preparedness and response; in ISO 14001 it is also emergency preparedness and response. Same clause number, entirely different requirements. So the standard-specific guides are grouped under the standard they belong to, and should be read that way.
Common clauses: these support every standard
Build these once and they serve your quality, safety, environmental, information security and AI management systems together.
| Clause | What it covers | Guide |
|---|---|---|
| 4.2 | Understanding the needs and expectations of interested parties, and building a register that does real work | Interested parties: a deep dive into clause 4.2 (includes a free Excel register template) |
| 4.3 | Determining the scope: you set the boundaries, not the auditor, and you justify anything determined not applicable | Clause 4.3: inside your periscope, not boiling the ocean |
| 6.2 | Setting measurable objectives that support the policy, using the operational numbers you already track | SMARTER objectives and clause 6.2 (includes a free annual objectives register) |
| 7.2 | Competence: proving people can actually do the work, and verifying it rather than assuming it | Dunning-Kruger and clause 7.2 competence |
| 7.2 | Competence for AI use: the free training programs now offered by OpenAI and Anthropic, and how to turn them into the competence evidence the clause asks you to retain | Free AI training for small business, and what it means for clause 7.2 |
| 7.3 | Awareness: what everyone working under your control must know about the policy, their own contribution and the consequences of ignoring it | Cyber security awareness training: what clause 7.3 requires (includes free resources from KnowBe4 and cyber.gov.au) |
| 7.3 | Awareness in practice: building the behaviour and evidencing it with simulated phishing, rather than an attendance record | Awareness is a behaviour, not a slide deck: simulated phishing and clause 7.3 |
| 9.2 | Internal audit: the independent check the standard requires every year | Independent ISO internal audits |
| 10.2 | Nonconformity and corrective action: fixing the cause, not just the symptom | Nonconformance and corrective action |
ISO 9001 specific clauses
ISO 9001 adds its own requirements, most of them concentrated in clause 8 where the operational detail lives.
| Clause | What it covers | Guide |
|---|---|---|
| 7.1.6 | Organisational knowledge: the know-how the business depends on, and what happens when it walks out the door | Knowledge momentum: what clause 7.1.6 really asks of you |
| 8.3 | Design and development: inputs, outputs, review, verification, validation, and the consequences-of-failure input most businesses miss | Clause 8.3 design and development |
ISO 45001 specific clauses
| Clause | What it covers | Guide |
|---|---|---|
| 8.2 | Emergency preparedness and response: a rehearsed, hazard-matched response, not an evacuation plan | Emergency preparedness is not an evacuation plan |
ISO 27001 specific requirements
| Requirement | What it covers | Guide |
|---|---|---|
| Annex A | The information security controls, and how to decide which ones apply to you | ISO 27001 controls explained |
| Documentation | What you actually need to produce to certify, without over-engineering it | ISO 27001 requirements checklist |
The thinking behind these guides
Every guide here is written on the same principle: a management system should carry the least administrative overhead the standard will allow, and conformity should be a by-product of running the business well rather than a scramble before the surveillance audit. If that idea is new, start with what a Streamline management system is.
More guides are added as we write them. If there is a clause you would like covered, tell us and we will put it on the list.
Related reading
- What is required for ISO 9001 certification
- The ISO 9001 audit: what actually happens
- Integrated management systems: running several standards together
- Gap analysis: knowing where you stand before Stage 1
Speak with an experienced ISO auditor
If you would rather talk a clause through than read about it, contact us. You will deal directly with an experienced ISO auditor. Email hello@streamline.business or call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990.











