Of all the clauses in ISO 9001, quality objectives are the one I most often see treated as a box-ticking chore, and it shows at audit. A wall of vague aspirations like “improve customer satisfaction” with no number attached is the single most common finding I raise under clause 6.2. Objectives that are written well, on the other hand, quietly run the business. Here is how we help clients get them right, whichever standard they are certifying to.
Clause 6.2 is the same in every standard
Because the modern management-system standards share the common Annex SL structure, clause 6.2 is effectively identical across all of them. It just takes the name of the discipline:
- ISO 9001, quality objectives
- ISO 45001, occupational health and safety objectives
- ISO 14001, environmental objectives
- ISO 27001, information security objectives
- ISO 42001, AI management objectives
The mechanics do not change. So while this guide uses quality as the running example, everything in it applies equally to your safety, environmental, information security or AI objectives, and to the single combined set you would run in an integrated management system.
What clause 6.2 requires
Clause 6.2.1 requires you to establish objectives at the relevant functions, levels and processes needed for the management system, and it sets conditions: the objectives must be consistent with the policy, measurable, monitored, communicated and updated as needed.
Clause 6.2.2 then requires that, when you plan how to achieve each objective, you determine:
- what will be done,
- what resources will be required,
- who is responsible,
- when it will be completed,
- how the results will be evaluated.
In plain terms: an objective is not a number on a poster. It is a number, with an owner, a plan, a due date and a way of checking whether you got there.
Objectives exist to deliver the policy (clause 5.2)
This is the part most often missed. Your objectives are not free-floating targets. They are how you make the policy at clause 5.2 real and measurable.
Every standard requires top management to establish a policy at 5.2: a quality policy, an OHS policy, an environmental policy, an information security policy, an AI policy. The policy states the organisation’s commitments and intent. On its own it is words. Clause 6.2 is where those words get a number attached. If your quality policy commits to “delivering on time, every time,” then an on-time-delivery objective is the evidence you mean it. An auditor reads the policy, then looks for the objectives that carry each commitment, and the two should line up cleanly.
It is also worth connecting objectives back to clause 4.2, interested parties. The needs and expectations of your customers, regulators, workers and owners are exactly the things worth setting objectives against. If you have built an interested parties register, its final column is a natural first draft of your objectives: each key requirement becomes something you measure.
How SMARTER objectives help
While ISO does not specify it, we recommend SMARTER objectives that underpin the goals in the organisation’s strategic plan, support the policy, and follow this philosophy:
- S (Specific): clearly articulate what you are trying to achieve, relevant to conformity of products and services and to enhancing customer and interested-party satisfaction.
- M (Measurable): objectives should be quantitative, with data to establish a baseline and allow ongoing measurement.
- A (Achievable): realistic and attainable. There is no point in an objective that cannot be reached.
- R (Relevant): supports the policy and the strategic plan.
- T (Time-bound): a completion date, or a set frequency for an ongoing target.
- E (Evaluated): evaluated at management review, under clause 9.3.
- R (Reviewed): reviewed at management review, under clause 9.3, and revised as things change.

The best objectives are usually the ones you already track
Here is the shift that makes this easy. Most businesses already monitor and measure key performance information, not because a standard told them to, but because it matters to running the business. Delivery performance, rework, scrap, downtime, complaints, safety incidents, project margin: this data is already being captured, often on dashboards and in monthly reports that leadership actually looks at.
That operational reporting is almost always the perfect source of management-system objectives. The mistake I see is businesses inventing a separate set of “objectives for the auditor” that nobody uses, while the real numbers that run the company sit in a dashboard the system never mentions. Align the system with your operations instead: take the targets you already care about and make them your objectives. The system stops being a parallel burden and starts describing how the business is actually run, which is the whole point of clause 6.2.
Lead and lag metrics
When you choose which numbers to set objectives against, balance two kinds.
Lag metrics measure the outcome after it has happened. They tell you whether you succeeded, but only once it is too late to change it. Examples: DIFOT (delivered in full, on time), rework or scrap rate, first-pass yield, customer complaints, lost-time injury frequency rate, number of security incidents.
Lead metrics measure the upstream activity that drives those outcomes. They are predictive, and crucially you can act on them before the result lands. Examples: preventive maintenance completed on schedule (drives DIFOT and reduces breakdowns), training-plan completion (drives competence and reduces error), near-miss reports raised (a leading indicator of safety culture), internal audit actions closed on time, phishing-simulation results (a leading indicator of information-security awareness).
Lead metrics are the more important of the two, because they are the ones you can still influence. A register full of lag metrics tells you how last quarter went; a register that pairs each lag metric with the lead metric that drives it tells you how next quarter is shaping up, while there is still time to act. A strong objective set has both: the lag outcome you are accountable for, and the lead activity you manage day to day to get there.
| Objective (example) | Metric | Lead or lag |
|---|---|---|
| Deliver reliably to customers | DIFOT (delivered in full, on time) at or above 98% | Lag |
| Keep the plant running so delivery holds up | Preventive maintenance completed on schedule at or above 95% | Lead |
| Reduce the cost of poor quality | Rework and scrap at or below 2% of output | Lag |
| Build the competence that prevents error | Training-plan completion at or above 90% | Lead |
| Keep people safe | Lost-time injury frequency rate trending down | Lag |
| Surface hazards before they cause harm | Near-miss reports raised each month at or above target | Lead |
Sample objectives for each standard
The shape is the same every time: a commitment from your policy at clause 5.2, a number you already track, a call on whether it is lead or lag, and a target with an owner. What changes is the subject matter. Treat these as prompts rather than a menu to copy.
ISO 9001, quality objectives
| Policy commitment it supports (5.2) | Objective and measure | Lead or lag |
|---|---|---|
| Satisfy customer requirements consistently | DIFOT at or above 98% | Lag |
| Enhance customer satisfaction | Customer satisfaction score at or above 8.5 out of 10 | Lag |
| Prevent error rather than catch it | Preventive maintenance completed to schedule at or above 95% | Lead |
| Continually improve the system | Corrective actions closed by the agreed date at or above 90% | Lead |
ISO 45001, occupational health and safety objectives
| Policy commitment it supports (5.2) | Objective and measure | Lead or lag |
|---|---|---|
| Provide safe and healthy working conditions | Lost time injury frequency rate trending down | Lag |
| Eliminate hazards and reduce OHS risks | Hazards closed out within 30 days at or above 90% | Lead |
| Consultation and participation of workers | Toolbox talks held to schedule at or above 95% | Lead |
| Fulfil legal and other requirements | Legal obligations register reviewed each quarter with no overdue actions | Lead |
ISO 14001, environmental objectives
| Policy commitment it supports (5.2) | Objective and measure | Lead or lag |
|---|---|---|
| Protect the environment and prevent pollution | Waste diverted from landfill at or above 60% | Lag |
| Fulfil compliance obligations | Licence conditions met with no notices received | Lag |
| Control the significant aspects you own | Spill kit and bund inspections completed to schedule at or above 95% | Lead |
| Build environmental awareness | Environmental inductions completed before site access, 100% | Lead |
ISO 27001, information security objectives
| Policy commitment it supports (5.2) | Objective and measure | Lead or lag |
|---|---|---|
| Protect the confidentiality, integrity and availability of information | Reportable security incidents, zero | Lag |
| Manage information security risks | Critical and high vulnerabilities remediated within 30 days at or above 95% | Lead |
| Build security awareness across staff | Phishing simulation fail rate at or below 5% | Lead |
| Meet contractual and interested party requirements | Privileged access reviews completed each quarter, 100% | Lead |
ISO 42001, AI management objectives
| Policy commitment it supports (5.2) | Objective and measure | Lead or lag |
|---|---|---|
| Develop and use AI responsibly | AI systems on the inventory with a completed impact assessment, 100% | Lead |
| Maintain meaningful human oversight | High impact AI decisions with a documented human review, 100% | Lead |
| Fulfil legal and interested party obligations | AI systems reviewed against applicable obligations each quarter | Lead |
| Respond when AI systems behave unexpectedly | AI incidents resolved within the agreed time at or above 90% | Lag |
Notice how few of these need a new measurement system. Nearly all of them are numbers the business already has, pointed at a policy commitment and given a target.
If you run an integrated management system you do not need five registers. One register, with a column naming the standard and policy each objective serves, is enough, and it makes the common thread visible at management review.
A sample objectives register
We put all of this into one place: an objectives register that carries each objective from the policy it supports through to the metric, the lead-or-lag call, the target, the owner and the monthly performance data. It is the same practical artefact we use on live systems.
Free template: download our Objectives Register template (Excel) to start from. It is an annual register: worked examples across quality, safety, environmental, information security and AI with lead and lag metrics flagged, twelve month columns to record actual performance (fill the ones that match each objective’s frequency, so a monthly objective uses all twelve and a quarterly one uses four), blank rows to complete, and a how-to tab covering clause 6.2, the 5.2 policy link and lead versus lag.
Who needs to know about the objectives?
Objectives should be communicated to everyone whose role has a direct or indirect bearing on the result, along with the monitoring and review data, so ownership and accountability are clear. An objective nobody has been told about is not going to be met.
A practical tell at audit
Whatever the standard, I look for whether an objective has an owner who can talk about it without reading from a screen. If the person responsible can tell me the current number, the target and why it matters, the objective is alive. If nobody in the room owns it, it is decoration, and that is exactly where the management system stops driving improvement.
Government funding for ISO certification
Grants may be available to help with the cost of ISO certification. See our guide to Government Grants & Funding for ISO Certification (AU).
Summary
Objectives, and being able to measure the performance of the management system, are how you identify problems and demonstrate continual improvement. Build them from the operational numbers you already track, pair each lag outcome with the lead activity that drives it, tie them to the policy at 5.2 and the interested parties at 4.2, and review them at management review under 9.3. Do that and clause 6.2 stops being a chore and starts running the business. It all supports the quality policy and the goals in the organisation’s strategic plan.
Speak with an experienced ISO auditor
If you’d like help setting meaningful SMARTER objectives for your management system, you’ll work directly with an experienced ISO auditor and our systems are built to certify first time. Email hello@streamline.business, call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990, or get in touch here.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











