Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

ISO Clause Guides

Tilt-shift miniature of a library reading room, with people working through open books and notes at a long table
The same management system clauses appear across ISO 9001, 27001, 42001, 14001 and 45001. These guides explain what each one actually asks for, in plain English.

Practical, plain-English guides to the clauses of the ISO management system standards, written by a working ISO Lead Auditor. Each one explains what the clause actually requires, what auditors look for, and how to satisfy it without inventing paperwork nobody uses.

The guides are split into two groups, and the split matters more than it first appears.

Why the guides are split this way

The modern management system standards share a common high-level structure, often called Annex SL. That is why ISO 9001, ISO 45001, ISO 14001, ISO 27001 and ISO 42001 all have a clause 4 for context, a clause 6 for planning, a clause 9 for performance evaluation, and so on. Those common clauses support every standard you hold, which is exactly why an integrated management system is cheaper to run than several parallel ones: you build the backbone once.

Each standard then adds requirements specific to its discipline, and those are not transferable. Clause 8.2 is the clearest warning. In ISO 9001 it covers requirements for products and services; in ISO 45001 it is emergency preparedness and response; in ISO 14001 it is also emergency preparedness and response. Same clause number, entirely different requirements. So the standard-specific guides are grouped under the standard they belong to, and should be read that way.

Common clauses: these support every standard

Build these once and they serve your quality, safety, environmental, information security and AI management systems together.

ClauseWhat it coversGuide
4.2Understanding the needs and expectations of interested parties, and building a register that does real workInterested parties: a deep dive into clause 4.2 (includes a free Excel register template)
4.3Determining the scope: you set the boundaries, not the auditor, and you justify anything determined not applicableClause 4.3: inside your periscope, not boiling the ocean
6.2Setting measurable objectives that support the policy, using the operational numbers you already trackSMARTER objectives and clause 6.2 (includes a free annual objectives register)
7.2Competence: proving people can actually do the work, and verifying it rather than assuming itDunning-Kruger and clause 7.2 competence
7.2Competence for AI use: the free training programs now offered by OpenAI and Anthropic, and how to turn them into the competence evidence the clause asks you to retainFree AI training for small business, and what it means for clause 7.2
7.3Awareness: what everyone working under your control must know about the policy, their own contribution and the consequences of ignoring itCyber security awareness training: what clause 7.3 requires (includes free resources from KnowBe4 and cyber.gov.au)
7.3Awareness in practice: building the behaviour and evidencing it with simulated phishing, rather than an attendance recordAwareness is a behaviour, not a slide deck: simulated phishing and clause 7.3
9.2Internal audit: the independent check the standard requires every yearIndependent ISO internal audits
10.2Nonconformity and corrective action: fixing the cause, not just the symptomNonconformance and corrective action
Common clauses from the shared Annex SL structure. One set of processes serves every standard you are certified to.

ISO 9001 specific clauses

ISO 9001 adds its own requirements, most of them concentrated in clause 8 where the operational detail lives.

ClauseWhat it coversGuide
7.1.6Organisational knowledge: the know-how the business depends on, and what happens when it walks out the doorKnowledge momentum: what clause 7.1.6 really asks of you
8.3Design and development: inputs, outputs, review, verification, validation, and the consequences-of-failure input most businesses missClause 8.3 design and development
Clause 7.1.6 has no equivalent in ISO 45001 or ISO 14001, which is why it sits here rather than with the common clauses.

ISO 45001 specific clauses

ClauseWhat it coversGuide
8.2Emergency preparedness and response: a rehearsed, hazard-matched response, not an evacuation planEmergency preparedness is not an evacuation plan
Note that ISO 45001 clause 8.2 is emergency preparedness, while ISO 9001 clause 8.2 covers requirements for products and services. The numbers do not transfer between standards.

ISO 27001 specific requirements

RequirementWhat it coversGuide
Annex AThe information security controls, and how to decide which ones apply to youISO 27001 controls explained
DocumentationWhat you actually need to produce to certify, without over-engineering itISO 27001 requirements checklist

The thinking behind these guides

Every guide here is written on the same principle: a management system should carry the least administrative overhead the standard will allow, and conformity should be a by-product of running the business well rather than a scramble before the surveillance audit. If that idea is new, start with what a Streamline management system is.

More guides are added as we write them. If there is a clause you would like covered, tell us and we will put it on the list.

Related reading

  • What is required for ISO 9001 certification
  • The ISO 9001 audit: what actually happens
  • Integrated management systems: running several standards together
  • Gap analysis: knowing where you stand before Stage 1

Speak with an experienced ISO auditor

If you would rather talk a clause through than read about it, contact us. You will deal directly with an experienced ISO auditor. Email hello@streamline.business or call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • Quality inspector in an Australian machining workshop checking a machined aluminium component against a tablet record, with CNC machines and Australian flags behind
    How Much Does ISO 9001 Certification Cost in…
  • Tilt-shift miniature naval shipyard inspection bay with a submarine hull section on keel blocks and workers in hi-vis checking tagged components in a parts quarantine area
    ISO 19443: The Nuclear Supply Chain Standard, and…
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Tilt-shift miniature of an AI data centre and microchip: AI tools and ISO 42001
    ISO 42001 AI Management Consulting, Audits & Mentoring
  • ISO 9001 quality management inspection
    ISO 9001 Quality Management Consulting, Audits & Mentoring

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire