ISO 9001 · Clause 4 · 4.4
The QMS and its processes
In plain words
This clause is the backbone of the whole standard: your quality management is not a binder — it is the sum of your processes. What is required: determine your processes — which exist, how they connect, what goes in and comes out — give each one an owner, know how you tell whether a process works, resource it and improve it.
Documentation the clause demands only “to the extent necessary”: as much as it takes for the processes to run reliably — and not one binder more. For a well-practised twelve-person shop that means: a process landscape on one page, and depth where mistakes hurt. No more.
The classic visible result is the process map: management processes on top, the core processes as a chain from customer need to delivery in the middle, support processes underneath. It is not a mandatory format — but it is the best one-page picture a QMS can draw of itself.
Why this requirement exists
Quality happens in flows of work, not in documents. An order turns out well because enquiry, work preparation, production and inspection mesh cleanly — and it turns out badly where a handover snags. Exactly there, at the interfaces, most errors live: the clause forces them into view.
The second purpose is steerability. Only when a process has a name, an owner and a criterion (“on-time delivery”, “scrap rate”, “quote turnaround”) can it be managed rather than merely experienced. The whole rest of the standard builds on this: audits examine processes (9.2), figures evaluate processes (9.1), the management review steers processes (9.3). Without 4.4, all three hang in the air.
What good looks like
In a company of 12 people: a process landscape on one page — three to five core processes as a chain, two or three management and support processes around them. Three entries per process: the owner, one or two criteria by which working shows itself, and the documents that belong to it. No forty SIPOC sheets; depth only where risk or staff changes demand it.
The three tiers sort themselves by a single question. The core processes are the chain the customer pays for — from the first contact to the fulfilled service; at a manufacturer usually enquiry → order review → work preparation → production → inspection → dispatch, at a service provider request → offer → delivery → acceptance. The management processes steer the whole: business planning, management review, improvement — they produce no product, they set the direction. The support processes keep the chain running without being value creation themselves: purchasing, goods-in, maintenance, people and onboarding, measuring-equipment management, IT. The rule of thumb for sorting: what does the customer pay for? → core. What sets the direction? → management. What enables the work? → support. If a process seems to fit two tiers, place it where its main effect lies — the tier is a thinking aid, not an exam question. And prefer few large processes to many small ones: “production” is one process, not seven machine groups.
You recognise a good landscape by its use: new employees learn the company from it, the audit programme follows its processes, the figures in the management review are its criteria. A map that only hangs in the manual is decoration — one you can explain the company with is the QMS.
What changes as you grow: From around 50 people the core processes get real indicators with targets and their own process meetings; interfaces get described explicitly (who hands over what, in which quality, by when). From 100–250 people process owners carry budget and improvement responsibility, and the landscape splits by site or business line. The core remains: few real processes, clear ownership, criteria someone actually looks at.
The minimum to pass
- A process overview exists — the processes are named, their sequence and interplay recognisable.
- Every process has an owner — a person, not “the team”.
- For every core process it can be said how working shows itself — one criterion or figure is enough at small scale.
- The documented information to the extent necessary is there and controlled — the procedures and records your processes really need.
- The overview matches reality — the processes carry the names people actually use on the floor.
What an auditor asks for
- The process landscape — and the test on it: can the owner explain their process freely, without the sheet?
- Per core process: the criterion and its recent values — and what happened when a value tipped.
- One interface in detail: how does the order travel from order handling into production, and how does production know it has everything?
- The link to the other clauses: does the audit programme (9.2) follow the processes? Do the figures (9.1) and the management review (9.3) evaluate the same criteria?
- Whether outsourced processes (extended workbench, external bookkeeping with quality relevance) are controlled — the bridge to 8.4.
Common traps
- The wallpaper. Forty laminated process sheets with turtle diagrams nobody ever opens. “The extent necessary” is a ceiling, not a floor — the standard itself permits you leanness.
- Org chart instead of process. Departments are not processes: “Sales” is a group; “from quote to order” is a process. The chain thinks from the customer, not from boxes.
- The consultant map. A generic landscape nobody recognises themselves in, with process names nobody on the floor uses. If the shop says “work prep” and the map says “order-to-cash”, something is off.
- Processes without owners. If three processes list the same person, or none, ownership is theory — and a standard audit question.
- Criteria nobody looks at. A figure untouched for a year is worse than none: it proves the steering is only claimed.
- The forgotten outside. Outsourced processes belong in the overview — whoever doesn’t think of the hardening shop or the external dispatch as a controlled process has a hole in the chain.
Worked example
The process landscape of Berger Präzisionsteile GmbH fits on one page. Management: company steering (managing director — criterion: the year’s objectives met). The core chain: from quote to order (managing director — quote hit rate, order review complete) → production (Marco — on-time delivery, scrap rate) → inspect & dispatch (Lea — complaint rate, first articles on time). Support: purchasing (managing director — supplier rating), maintenance (Marco — unplanned downtime), people & onboarding (managing director — onboarding plan fulfilled). The hardening shop runs as an outsourced step inside production — controlled through purchasing.
The map is used three ways. The audit programme (9.2) plans one audit per process per year — the worked example for that lives on the internal-audit clause page. The criteria are exactly the figures that land on the management-review table. And when the new machinist started, the map was page one of his onboarding: “this is how an order flows here.” More process documentation than this page plus production’s setup and inspection sheets Berger does not have — and has never yet needed.
How easo covers it
In easo, clause 4.4 is not a drawn slide but derived reality:
- You maintain your processes once, as the process registry in the company settings (management / core / support, signed and versioned) — the handbook’s process landscape draws itself from it, including the order of the core chain.
- Every document carries its process as a head fact — so the landscape shows live, per process, the released documents and their review health; a hand-maintained second truth does not exist.
- The audit programme (9.2) derives from the same registry — processes without an audit in the cycle become visible. Registry, landscape and audit plan cannot drift apart, because they have one source.
- Clause 4.4 itself is a row in the readiness denominator; the process-landscape starter template brings structure and guidance with it.
Stay in the loop
easo is available for macOS — the Windows version is coming soon. Leave us a note and we'll reach out the moment it lands.