Clause 4 asks four questions in order. Who are you (4.1). Who do you have to keep happy (4.2). What does your system cover (4.3). And clause 4.4: how does it all work?
That last question is where most management systems either come alive or turn into a filing cabinet. It is hard to improve a process until you have clearly defined it, and you cannot defend a process to an auditor that nobody in the business could draw on a whiteboard.
The good news is that clause 4.4 does not ask for a wall of flowcharts. It asks you to understand how your business turns inputs into outputs, who owns each part, and what could go wrong. The rest of this guide shows a simple way to do that, which I explain to clients using Google Maps.

What clause 4.4 requires
ISO 9001 is the most specific of the standards here. Clause 4.4.1 asks you to determine the processes your quality management system needs, and for each one:
- The inputs required and the outputs expected.
- The sequence and interaction of the processes, meaning how they hand over to each other.
- The criteria and methods needed to make sure they operate effectively, including monitoring, measurement and performance indicators where those are needed.
- The resources needed, and that they are available.
- Responsibilities and authorities.
- The risks and opportunities determined under clause 6.1.
- How you evaluate the processes and change them when they are not achieving what was intended.
- How you improve them, and the system as a whole.
Clause 4.4.2 then asks you to maintain documented information to the extent necessary to support the operation of your processes, and to retain enough to be confident they are being carried out as planned.
ISO 45001, ISO 14001 and ISO/IEC 27001 have a clause 4.4 as well, but it is a single sentence: establish, implement, maintain and continually improve the management system, including the processes needed and their interactions. In an integrated management system, the ISO 9001 approach below covers all of them at once.
Notice what that list does not include: a flowchart. Plenty of certified businesses meet clause 4.4 with nothing more than a process matrix, a table listing each key process with its inputs, outputs, risks, resources, responsibilities and performance measures. That ticks every requirement. What it does not do is help anyone understand the work or improve it, because nobody learns how a job flows from a row in a table. The approach below meets the clause and gives your team something they will use.
Zoom out first: the Google Maps approach
Open Google Maps and zoom right out, and you see the whole country: the major cities and the highways between them, and nothing else. Zoom in and you see a city, its suburbs and main roads. Zoom in again and you are at street level, looking at a single address.
A process architecture works the same way. Three levels, each with a different job.
Level 1: the country view
One page that shows the whole business. Your core processes run left to right, in the order the work flows: typically enquiry and sales, contract or work acceptance, planning, delivery, handover, and on to invoicing, practical completion and the defects liability period. Underneath sit the support processes that keep it running, such as people, equipment, purchasing and IT. Above sit the management processes: planning, review and improvement.
This is the page that answers “what are your processes and how do they interact” in a single glance. It is also the page you will use most often at audit.
Level 2: the city view
Click into any box on level 1 and you get its level 2 process map. This is where clause 4.4 really lives. A swimlane layout works well because it shows who does what, and each process records:
- Inputs: what has to arrive before the process can start, such as a customer enquiry, your schedule of rates or a signed contract.
- Outputs: what the process produces, such as a fee proposal, a tender response or a job pack.
- Owner and authorities: who runs it, and who is allowed to sign what. Contract acceptance by the general manager, for example.
- Resources: the people, systems and tools it relies on. Your CRM, your job management software, the crew.
- Risks: what happens if it goes wrong, linked to your clause 6.1 risk register.
That last one is worth taking seriously. If the inputs are missing or the process is skipped, writing down exactly what goes wrong gives everyone a reason to follow it.
Level 3: street view
Level 2 says what needs to happen. It does not say how to do every step. That is level 3: work instructions for the steps that need them.
Two points about level 3. First, you do not need one for every step. Decide on risk and importance. A task done by a hundred workers, or by a role that turns over often, deserves an instruction so you are not training it from scratch every time. A task done once a year by the person who designed it probably does not.
Second, the format is entirely up to you. A short screen recording often beats a written procedure. Microsoft Clipchamp is already in most Microsoft 365 subscriptions. Record yourself creating a new job in your CRM with a voiceover, let it generate the transcript, and link the video from that step on the level 2 map. Someone who needs to know how simply clicks the step and watches.
The closer you zoom in, the more detail you get. Most people only ever need the level they are working at.
Outputs become inputs
The most useful thing a process map shows is the handover. The output of one process is the input to the next: the won proposal becomes the input to project kickoff, the completed job becomes the input to invoicing, and so on until the money is in the bank.
Handovers are where things fall through the cracks. In most businesses I work with, the riskiest point is the handover from sales to operations. Sales promised something, the job pack does not say it, and the site team finds out from the client. Mapping the handover, with a defined list of what has to be in the job pack before operations will accept it, fixes more problems than any procedure about either process on its own.
Build the clause requirements into the process
Here is the part that saves the most time. Your people do not need to know clause numbers. They need to know how the job is done.
So rather than training everyone in clause 8.2, build its requirements into your sales and contract process. Reviewing the customer’s requirements before you commit, checking you can actually deliver, and updating the quote when the customer changes their mind all become steps in the swimlane. The same goes for clause 8.4 in your purchasing process, 8.5 in delivery and 8.7 in how you deal with defects. The process meets the standard, and the team simply follows the process.
The same applies to clause 8.3. If you do not design, the map should show where the specification comes from instead. Our clause 8.3 guide covers how to tell.
Process KPIs: only where they earn their keep
Clause 4.4 asks for the monitoring, measurement and performance indicators needed to make your processes work. That word matters. A manufacturer tracking defect rates needs process measures. Most small service businesses do not need a KPI on every box.
If your CRM already reports something useful, such as the time from enquiry to proposal, use it. Otherwise, start with the handful of measures that tie back to your clause 6.2 objectives and add more only when you have a reason to.
Where clause 4.4 connects to everything else
Clause 4.4 is the frame the rest of the system hangs on:
- Clause 5.3: the owners and authorities on your level 2 maps are your roles and responsibilities.
- Clause 6.1: the risks on each map feed your risk register.
- Clause 7.1: the resources column shows what you need to keep available.
- Clause 9.2: your internal audit programme is planned around the importance of each process, the risks, recent changes and previous results. A new salesperson in a high-risk process might be audited monthly at first, then less often once the results are consistent.
- Clause 10.2: when something goes wrong, the process map is where you look first to find the root cause, and where the fix gets built in. See nonconformity and corrective action.
Where clause 4.4 goes wrong
- One giant flowchart. Everything on one page, every decision diamond, nobody can read it. Zoom out to level 1 and push the detail down.
- Maps that do not match reality. Drawn to look good for an auditor, ignored by the people doing the work. Walk the process with the people who run it before you draw it.
- Level 3 for everything. A work instruction under every step, most of which nobody reads. Decide on risk and importance.
- Drawn by the consultant alone. A consultant can draft a first version to get things moving, which helps, but it only works once the people who run the process have pulled it apart and fixed it.
- Arguing about the tool. Visio, Canva, Miro, a whiteboard photo. It does not matter. Use whatever your team will open and keep up to date.
Clause 4.4: FAQs
Does clause 4.4 require process maps or flowcharts?
No. It requires you to determine your processes, their inputs, outputs, interactions, resources, responsibilities and risks, and to keep documented information to the extent necessary. A simple process matrix covering those points meets the requirement. Process maps go further, because they are the clearest way most businesses find to show people how the work actually flows.
Do we need turtle diagrams?
No. A turtle diagram is one popular way to record the inputs, outputs, resources, people, methods and measures of a process. A swimlane map with the same information meets the requirement just as well.
How many processes should we have?
Enough to show how the business works, and no more. A small business often has somewhere between six and twelve core and support processes at level 1. If your level 1 page will not fit on one screen, you have probably gone too deep.
Do we need a KPI for every process?
No. The standard asks for the performance indicators needed for effective operation. Many small businesses measure only a few processes, tied to their quality objectives.
Does ISO 45001 or ISO 14001 have a clause 4.4?
Yes, but much shorter. Both require the management system to be established, implemented, maintained and continually improved, including the processes needed and their interactions. The ISO 9001 approach in this guide satisfies them in an integrated system.
How detailed should our work instructions be?
As detailed as the risk requires, and in whatever format works. A two-minute screen recording linked from the process map is often more useful than a ten-page procedure.
How Streamline can help
Streamline designs, implements, audits and mentors practical ISO management systems for Australian businesses. We build process architectures in the three levels described here: one page that shows the whole business, level 2 maps your team can follow, and level 3 instructions only where they earn their place. We can draft the first version from what you already have, or mentor your team through mapping it themselves. See our other ISO clause guides.
Speak with an experienced ISO auditor
For help with clause 4.4 or any part of your management system, contact us or email hello@streamline.business.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











