ISO 9001 · Clause 5 · 5.2, 5.2.1, 5.2.2
The quality policy
In plain words
The quality policy is your shortest statement of principle: one page saying what quality stands for in your company. The standard demands four properties: it fits your purpose and context; it provides the framework for the quality objectives; it contains the commitment to meet requirements (customers, law, your own claims); and the commitment to continual improvement.
Then the second part (5.2.2): documented, communicated and understood within the company, and available to interested parties as appropriate.
The touchstone is not the paper. The touchstone is whether your people can give the policy back in their own words — not memorised, but understood. A policy that lives only in a frame on the wall meets the letter and misses the point.
Why this requirement exists
Without a declared direction, every objective is arbitrary. The policy is the yardstick against which objectives (6.2), decisions and daily work can be measured — publicly: it is the promise you may be measured against. That is exactly how auditors use it: they read the policy on day one and spend three days comparing it with what they see.
For leadership it is also a tool of relief: whoever writes the line down once (“keep the date or call early”) does not have to justify every single decision anew — the team can make it themselves.
What good looks like
In a company of 12 people: half a page, five concrete sentences — written by the leadership circle, not by a consultant. Concrete means: sentences that can hurt. “We deliver on the promised date or call before the customer has to ask” is policy; “highest quality is our aspiration” is wallpaper. The difference: the first sentence can be failed against — and that is exactly why it steers behaviour.
It is communicated not by posting alone but by conversation: discussed once in the team, explained at onboarding, quoted in the Monday huddle when a decision is due. And the two or three annual objectives derive recognisably from it — that is the “framework” the standard means.
What changes as you grow: From around 50 people the policy is translated into area objectives and becomes part of onboarding; from 100–250 people it goes multilingual, and many companies merge it with environmental and safety principles into one integrated policy. The core remains: few sentences that are genuinely yours — and that everyone in the house knows.
The minimum to pass
- A released, documented policy document — here the paper is mandatory.
- It recognisably contains the four required elements: fit for purpose and context, framework for objectives, commitment to meeting requirements, commitment to improvement.
- It is communicated — and the workforce can give back its core in their own words.
- It is available: internally at any time, externally as appropriate (customers do ask — a current copy on request is enough).
What an auditor asks for
- The released document itself — with date and approver.
- The question on the tour: “What does quality mean here?” Paraphrased answers count; word-perfect recitation raises suspicion instead.
- The trail to the objectives: which of your objectives implements which policy sentence?
- Availability: where does the team find it, how does a customer receive it?
- Currency: does the policy still fit the strategy — or has the business turned while the policy stood still?
Common traps
- The platitude policy. “Customer satisfaction is at the centre of everything” — every company on earth could sign it, none can be measured by it. Concrete sentences beat big words.
- Memorising before the audit. Auditors spot recitation instantly — and then ask what it means. Understanding cannot be crammed, only discussed.
- The consultant’s policy. If the managing director cannot freely explain their own policy, that is a 5.1 finding in 5.2 clothing.
- Never brought along. Strategy turned, new business line, the policy from five years ago. The policy ages with the context — the management review is the natural checkpoint.
- A policy without objectives. Objectives that have nothing to do with the policy expose the “framework” as a claim.
- The hidden policy. Nobody finds it, no party receives it. Availability is explicitly part of the requirement.
Worked example
The policy of Berger Präzisionsteile GmbH has five sentences, in essence: We manufacture precision our customers can measure. We keep promised dates — or call before the customer has to ask. Every mistake happens here at most once: we look for the cause, not the culprit. Knowledge belongs to the team, not to individual heads. We get measurably better every year.
Every sentence carries weight: the knowledge sentence comes straight from the knowledge-monopoly context issue (4.1) and covers the onboarding programme; from the improvement sentence derive the annual objectives — new-customer share 20% (from the opportunity overview, 6.1), scrap below 2%, the setup-sheet project completed. On the audit tour, the new machinist answered the policy question: “When it gets tight, we tell the customer before he has to ask — that’s law here.” Not a quote, full marks: that is exactly what an understood policy sounds like.
How easo covers it
The quality policy is mandatory documented information — in easo a row in the readiness denominator (clause 5.2):
- The quality-policy starter template brings the four required elements as structure; easo’s honest scaffolding prevents placeholder sentences from ever being released.
- Released, it is a signed, versioned document — who stands behind it and since when is cryptographically traceable; changes run through the same review path as a new version.
- Communication and availability: in the handbook it is one click away for everyone in the house (search included); for external parties you export a stamped PDF with the verification annex — a policy whose authenticity the recipient can verify themselves.
Stay in the loop
easo is available for macOS — the Windows version is coming soon. Leave us a note and we'll reach out the moment it lands.