ISO 9001 · Clause 5 · 5.3
Roles, responsibilities and authorities
In plain words
This clause asks two simple questions: who is responsible for what — and who may decide what? Both must be assigned, communicated and understood in the company. For four things in particular the standard demands clear ownership: that the QMS conforms to the standard; that leadership receives reports on QMS performance; that customer focus is promoted throughout the house; and that the integrity of the QMS is preserved when things change — a move, new software, a new structure.
What the standard no longer demands: a named “quality management representative”. Responsibilities may be distributed — at 12 people everyone wears several hats anyway. What is demanded is that the hats are worn consciously: responsibility and authority belong together (whoever is supposed to stop defects must be allowed to stop the machine), and for critical roles it is clear who deputises.
Why this requirement exists
“Here, everyone is responsible” means in practice: nobody is. The clause exists because quality responsibility without a name evaporates — the check everyone assumed was done; the release nobody felt entitled to make; the complaint that sat for three days because it was unclear whose desk it was.
The second purpose is protection against silent overload: in small companies, QMS duties tend to gather unnoticed with one person. Whoever writes the responsibilities down once sees the clusters — and can distribute them before that one person’s holiday halts the system. It is the same pattern as the knowledge monopoly in the context (4.1), one level up.
What good looks like
In a company of 12 people: half a page, as a table — per role the core responsibility, the key authorities (what may this role release, stop, decide) and the deputy. No org chart needed: boxes show hierarchy, the standard asks about responsibility — not the same thing. The release questions matter most: who releases documents? Who releases product? Who may stop on a nonconformity?
And: the overview is known in the team. The test is banal and hard at once — every person knows without looking what they may release and who deputises for them.
What changes as you grow: From around 50 people, role descriptions and a signature/release policy join, and deputising becomes formal rather than shouted across the shop. From 100–250 people, leadership delegates releases in a structured way (who releases up to which impact), and the QMS reporting line to management gets a fixed rhythm. The core remains: responsibility with a name, authority to match, deputies settled.
The minimum to pass
- A traceable assignment of the key QMS responsibilities: conformity, reporting to leadership, document and product releases, customer focus, integrity through change.
- Authorities are thought through — being responsible and being allowed to decide do not fall apart.
- Deputies for critical roles are named (releases, inspections).
- The assignment is communicated — the team knows it without opening the binder.
What an auditor asks for
- The role overview itself — and its age: does it still match today’s staffing?
- The spot check in conversation: “What may you release? Who deputises for you?” — asked across the house.
- Consistency with practice: who actually released the recent documents and products — the same people the overview allows?
- The deputy case in concrete terms: your QA was on holiday for three weeks — who inspected, and how did that person know how?
- After recent changes (new machine, new software, reorganisation): who made sure the QMS came along?
Common traps
- Org chart instead of role clarity. The org chart answers who reports to whom — not who releases first articles. The standard asks the second.
- The secret representative. Officially distributed, in fact one person does everything quality-related. The single point of failure shows at the latest during holidays — or in the audit, when only one person can answer.
- Responsibility without authority. QA “is responsible” for product quality but may not stop a delivery. Such constructions break in the first real case.
- No deputy. Holiday season as a QMS pause: no releases, no inspections, a growing pile. One line per critical role solves it.
- Paper roles. The matrix says A, daily work does B. Auditors find this through the release spot check in minutes — and then the whole overview wobbles.
- “Everyone is responsible.” The opposite of assignment. Shared values: yes. Shared release authority: no.
Worked example
The role sheet of Berger Präzisionsteile GmbH is half a page:
| Role | Core responsibility | Key authorities | Deputy |
|---|---|---|---|
| Managing director (Frau Berger) | Policy, objectives, management review; QMS conformity | Release of policies & procedures; resources | Marco (releases) |
| Production manager (Marco) | Production process; integrity through technical change | Series release; stop on nonconformity | Frau Berger |
| Quality assurance (Lea) | Measuring equipment; quarterly QMS report to the MD | First-article release; stop on nonconformity | Marco (per her checklist) |
| Every machinist | Report nonconformities | Stop and ask when in doubt | — |
The last row is the most important one — and it is lived: when the new machinist stopped a batch over a dimension doubt, there was explicit praise in front of the team although the doubt proved unfounded. (“Better one stop too many” — the same culture that carries the internal audit.) The deputy case is tested: during Lea’s three-week holiday, Marco took the first-article releases following her checklist; a single tricky sample went to the external measuring lab. No backlog, no silent self-release.
How easo covers it
Clause 5.3 requires no mandatory document — it does not count in the readiness denominator. But in easo, roles are not paper — they are enforced reality:
- The role ladder (reader → author → reviewer → approver → admin) is enforced by the engine: only someone whose signature carries the approver role can release — a role overview that cannot drift from practice.
- The People view shows the lived assignment: who holds which role, since when, with which devices — and on departure, access and keys are ended traceably.
- The half-page role sheet itself (authorities and deputies beyond document releases) is easiest kept as a short controlled document on 5.3 — versioned and signed like everything else.
Stay in the loop
easo is available for macOS — the Windows version is coming soon. Leave us a note and we'll reach out the moment it lands.