Clause 4 is the introduction to the standard, and it asks four questions in order. Who are you (4.1). Who do you have to keep happy (4.2). What does your management system cover (4.3). How does the system work (4.4). Everything that follows in clauses 5 to 10 is built on the answers.
Clause 4.1 is the first of the four, and it is the one most often handed to a consultant, filled in from a template and never looked at again. That is a shame, because it is also the clause that decides whether the rest of the system is about your business or about somebody else’s.
The requirement itself is short. The organisation shall determine the external and internal issues that are relevant to its purpose, and that affect its ability to achieve the intended results of its management system. It shall then monitor and review information about those issues.
Read what that does and does not say. It tells you what to end up with. It says nothing whatsoever about how you get there.

What clause 4.1 requires
Three things, and no more than three:
- Determine external issues relevant to your purpose and to the intended results of the management system.
- Determine internal issues on the same test.
- Monitor and review information about those issues, because the answer changes.
The standard then helps you out with notes rather than requirements. Issues can be positive or negative, which is worth pausing on, because most context registers we see list only threats. The external context note points at the legal, technological, competitive, market, cultural, social and economic environment, at whatever level applies to you, international through to local. The internal context note points at your values, culture, knowledge and performance.
Notes in an ISO standard are guidance, not requirements. You cannot be raised a nonconformity for failing to consider “cultural environment” as a discrete heading. You can be raised one for having no credible determination at all.
The standard says what. You choose how.
This is the part worth being firm about, because it is where a lot of unnecessary work and a lot of unnecessary argument comes from.
A “shall” statement sets the requirement. The method is yours. Clause 4.1 requires you to determine your internal and external issues. It does not require a SWOT analysis. It does not require a PESTEL. It does not require a context register, a context procedure, or a document called anything in particular. If your issues are genuinely determined, monitored and reviewed, you have met clause 4.1, whatever the workings look like.
That includes the certification auditor. An auditor’s job is to test whether the shall statement has been fulfilled, not to prescribe the method by which you fulfilled it. If you are told that clause 4.1 requires a SWOT, ask which sub-clause says so. It does not exist. What the auditor can legitimately do, and should, is probe whether your determination is real: whether you can explain how you arrived at these issues, whether they match the business they claim to describe, whether anyone has looked at them since, and whether they actually feed clause 6.1 where risks and opportunities get planned.
This is the same principle that governs clause 4.3, where you determine the scope, not the auditor. The difference is worth holding onto: in 4.3 you choose the boundary, in 4.1 you choose the method.
Four ways to determine your issues
None of these is required. All of them work, and most organisations already have one of them sitting in a drawer.
| Method | What it gives you | Best when |
|---|---|---|
| SWOT analysis | Strengths and weaknesses are your internal issues. Opportunities and threats are your external ones. The mapping to clause 4.1 is almost one to one, which is why it is the most common choice. | You are starting from nothing and want the fastest defensible route. |
| PESTEL analysis | Political, economic, social, technological, environmental and legal factors. Entirely external, so it needs an internal counterpart alongside it. | Your risks are mostly regulatory, market or macro, and the external picture needs more depth than a SWOT quadrant gives. |
| Business plan | Most business plans already contain a market analysis, a competitor position, a resourcing picture and a risk section. That is clause 4.1 in all but name. | You have a current one. Do not write a second document that says the same thing. |
| Strategic plan | Strategic goals, and the internal and external issues that stand between you and them. This is the closest fit to what ISO 9001 asks for, for reasons in the next section. | You have set a direction and want the management system pointed at it. |
The practical advice is the same in every case: start from a document you already maintain for commercial reasons. A context register built only to satisfy an auditor gets written once and dies. A strategic plan or business plan gets revisited because the business depends on it, and clause 4.1 asks you to monitor and review, which is a great deal easier when the source document was going to be reviewed anyway.
If you go the business plan route, a simple layout does most of the work. For each strategic priority, record how you will measure it, then the internal and external issues that could help or hinder it. The risks that fall out of those issues go straight into your risk register, and the priorities themselves become the source for your objectives. One document, kept for the business, now covers clause 4.1 and feeds 6.1 and 6.2.
One caution. Many business plans are dollars and cents only. If yours holds only revenue and margin targets, it will not carry a safety or environmental management system. Add the priorities that matter there too, such as zero lost time injuries or reduced waste to landfill, or the plan will not support the standards you are certifying to.
If you have none of these, our guide to whether a strategic plan is a mystical art or common sense is the place to start, because it produces the input rather than the paperwork.
Strategic direction, and why ISO 9001 is the odd one out
Here is a difference that matters if you run more than one standard, and that almost nobody points out.
ISO 9001 clause 4.1 asks for issues relevant to your purpose and your strategic direction. The other management system standards do not mention strategic direction at all. They ask for issues relevant to your purpose and to the intended results, or intended outcomes, of the management system.
| Standard | What its clause 4.1 anchors the issues to |
|---|---|
| ISO 9001 | Your purpose and your strategic direction, and the intended results of the quality management system. The only one that names strategy explicitly. |
| ISO 14001 | Your purpose and the intended outcomes of the environmental management system, and uniquely, environmental conditions being affected by or capable of affecting the organisation. Context runs both ways. |
| ISO 45001 | Your purpose and the intended outcomes of the OH&S management system. |
| ISO/IEC 27001 | Your purpose and the intended outcomes of the information security management system. |
| ISO/IEC 42001 | Your purpose and the intended outcomes of the AI management system, plus a determination of your role or roles with respect to AI, which then drives your scope. |
Does the difference change what you do? For most organisations, less than it looks. Strategic direction is a natural way to answer “what are the intended results of this system” whichever standard you hold. But the wording gives you two useful things.
First, in ISO 9001 it is an explicit invitation to connect the quality system to where the business is going, rather than to a quality manual. If your strategic direction is to move into defence supply chains, your quality context includes that, and so should your objectives.
Second, in an integrated management system, one context determination serves all your standards. You do not need five. You need one that is honest about the business, with the discipline-specific additions noted above sitting alongside it: environmental conditions for 14001, your AI role for 42001.
Climate change is a shall inside clause 4.1
Since the amendment of 23 February 2024, clause 4.1 carries one more requirement: the organisation shall determine whether climate change is a relevant issue.
Note carefully what that asks. The shall is to determine whether, not to treat it as relevant. You are allowed to conclude that it is not, provided the conclusion is genuine and you can show the reasoning. What you cannot do is leave the question unanswered:
Climate change has been considered as an external issue. Our operations are office-based and single-site, with no significant energy, water or supply chain exposure. Physical and transition climate risk is assessed as not material to the intended results of the quality management system. This determination is reviewed annually at management review.
That answers the shall, shows the thinking and closes the door. A context register with no mention of climate at all is now a straightforward finding.
The same amendment added a note to clause 4.2 about interested parties and climate, and it reaches every standard in the family. Our clause 4.2 guide covers the amendment in full and shows how to carry it into an interested parties register. Where the answer to the 4.1 question is yes, and it increasingly is once your customers become climate reporters, the work itself is a climate risk assessment, driven by the questions arriving through Scope 3 supplier questionnaires.
One note on the current editions. ISO 14001:2026 was published on 15 April 2026 and makes climate and environmental conditions explicit in its own right, with transition running to 30 April 2029. ISO 9001:2026 was published on 16 September 2026. Neither changes the shape of clause 4.1 described here, but see our guides to the ISO 9001:2026 transition and the ISO 14001:2026 transition for the detail.
What clause 4.1 does not require
It does not require documented information. Read the clause again and look for the words. They are not there. Clause 4.3 requires the scope to be maintained as documented information. Clause 4.1 does not require anything of the sort.
That surprises people, and it is immediately followed by a sensible question: then how do I show an auditor I have done it?
The answer is that the evidence trail is built for you elsewhere. Clause 9.3 management review requires you to consider changes in the external and internal issues relevant to the management system as a standing input. So your management review minutes carry a dated record of the issues being reviewed, by the people accountable for them, at a defined frequency. That is stronger evidence of monitoring and review than any register, because a register proves the list exists while minutes prove somebody looked at it.
Clause 6.1 then requires you to consider the 4.1 issues when determining risks and opportunities. So your risk register shows the issues being used.
Determined, monitored, reviewed and used. If you can show those four things, the absence of a document titled “Context of the Organisation” is not a nonconformity. Most organisations still choose to keep one, because it is a convenient single place to hold the answer, and that is a perfectly good reason. Just know that you are choosing it, not complying with it.
Where clause 4.1 goes wrong
- It is generic. The issues could belong to any business in any industry. “Competition”, “skilled staff shortages”, “economic conditions”. True of everyone, useful to no one, and the fastest way to signal that a template was filled in.
- It lists only threats. The standard says issues can be positive or negative. A context with no opportunities in it feeds a clause 6.1 process that can only ever produce risks to mitigate, never opportunities to pursue.
- It was written once. Dated three years ago, unchanged, while the business has moved into two new markets. This fails the monitor and review requirement directly, and it is visible at a glance.
- It never connects to anything. The issues do not appear in the risk register, in the objectives, or in the management review. Clause 4.1 is an input clause. If nothing downstream uses it, it was decoration.
- It was written by the consultant. The issues facing your business are known by the people running it. An external party can facilitate the session and challenge the answers, which is genuinely useful, but a context determination handed over as a finished deliverable is somebody else’s guess about your business.
Clause 4.1 FAQs
Does clause 4.1 require a SWOT analysis?
No. Clause 4.1 requires you to determine your internal and external issues. It does not prescribe a method. A SWOT is a popular and effective way to do it, and so are a PESTEL, a business plan and a strategic plan. Any method that produces a genuine determination meets the requirement.
Does clause 4.1 require a documented procedure or register?
No. Clause 4.1 contains no documented information requirement. You do need to be able to demonstrate that the issues were determined and are being monitored and reviewed, and in practice that evidence usually sits in management review records under clause 9.3 and in the risk and opportunity work under clause 6.1. Many organisations keep a register anyway because it is convenient.
What is the difference between clause 4.1 and clause 4.2?
Clause 4.1 is about issues: the internal and external conditions affecting your ability to achieve the intended results of the system. Clause 4.2 is about parties: who has an interest in your management system and what they need from you. See our guide to clause 4.2 and interested parties.
Why does ISO 9001 mention strategic direction when the other standards do not?
ISO 9001 clause 4.1 anchors the issues to your purpose and your strategic direction. ISO 14001, ISO 45001, ISO/IEC 27001 and ISO/IEC 42001 anchor them to your purpose and the intended outcomes of their respective management systems. In practice the two lead to similar places, but the ISO 9001 wording is an explicit invitation to align the quality system with where the business is heading.
Do we need a separate clause 4.1 for each standard we hold?
No. One context determination can serve an integrated management system, with the discipline-specific additions alongside it: environmental conditions for ISO 14001, and your role with respect to AI for ISO/IEC 42001.
Is climate change now mandatory in clause 4.1?
Considering it is. Since the February 2024 amendment, the organisation shall determine whether climate change is a relevant issue. You may conclude that it is not, provided the conclusion is genuine and you can show the reasoning. What is no longer acceptable is not addressing the question.
How often should we review our context?
At minimum, whenever the management review runs, because changes to internal and external issues are a required input to it. In practice, also whenever something material moves: a new market, a new site, an acquisition, a significant regulatory change or a major client win or loss.
Can the auditor tell us our context is wrong?
An auditor can and should test whether your determination is credible, complete and used, and can raise a finding if it is generic, stale or disconnected from the rest of the system. What an auditor should not do is require a particular method or document format, because the standard does not.
How Streamline can help
Streamline designs, implements, audits and mentors practical ISO management systems for Australian businesses. Clause 4.1 is a short clause with long consequences, because every risk, objective and control downstream is built on the answer.
We run context determination as a facilitated session with the people who actually know the business, using whichever method fits what you already maintain, and we make sure the output lands where it has to land: in your risks and opportunities, your objectives and your management review. If you would rather build it yourself, ISO mentoring coaches your team through it, and an independent internal audit tells you whether it holds up before a certification body sees it.
Speak with an experienced ISO auditor
For help with clause 4.1 or any part of your management system, contact us. Email hello@streamline.business or call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











