Loopyback

Blog

ISO 9001 Documented Information: What Clause 7.5 Actually Requires

ISO 9001:2015 deleted the mandatory quality manual and the six named procedures, and replaced them with one idea: documented information. That freedom is why documentation projects go sideways. Here is what clause 7.5 asks for, how screenshot-based guides measure up, and where the GDPR quietly sets a second set of rules.

By Suleyman Kurt· Founder of Loopyback· 4 August 2026

ISO 9001:2015 did something many quality managers still have not fully absorbed: it deleted the list. The 2008 version demanded a quality manual and six named documented procedures: document control, records control, internal audit, nonconforming product, corrective action, preventive action. The 2015 version replaced all of that with one concept, documented information, and one instruction: you determine how much you need.

That freedom is why ISO 9001 documentation projects go sideways. With no list to tick off, organisations produce either a 300-page binder nobody opens, or a wiki the auditor cannot trace back to a version, a date and a name.

Full disclosure: we build Loopyback, an EU-hosted process documentation tool, so we are not neutral. We are also not a QMS platform, and the limits of that are further down.

Worth knowing first: Edition 6 is close

As of the ISO catalogue entry, ISO 9001 sits at stage 60.00, "International Standard under publication", with Edition 6 expected around September 2026. The transition period for certified organisations is set by IAF resolution after publication. Three years is the widely assumed figure based on previous revisions, but until IAF publishes, treat it as expectation rather than fact.

The practical read: do not rebuild your documentation set now on the assumption that 7.5 is about to change beyond recognition. The direction of travel across ISO management standards has been toward less prescription about format, not more.

What clause 7.5 actually asks for

7.5.1 General. The QMS shall include the documented information the standard requires, plus whatever the organisation determines is necessary for effectiveness. The extent may legitimately differ by size, process complexity and competence of people.

7.5.2 Creating and updating. Three things must be appropriate: identification and description (title, date, author, reference number); format, for which the standard names language, software version and graphics as examples, and media; and review and approval for suitability and adequacy.

7.5.3.1 Control. Documented information must be available and suitable for use where and when needed, and adequately protected from loss of confidentiality, improper use or loss of integrity.

7.5.3.2 is the operational list: distribution, access, retrieval and use; storage and preservation including legibility; control of changes, meaning version control; and retention and disposition.

Two other clauses do most of the damage in real audits. 8.5.1(a) requires documented information defining the activities to be performed to be available under controlled conditions, meaning at the workstation, not in a folder someone can find on request. And 7.2(d) requires retained documented information as evidence of competence, which is where "we trained them, we just never wrote it down" collapses.

The formats, measured against the clause

Word file on a shared driveWiki pageRecorded step-by-step guide
Identification, author, date (7.5.2a)Often lost when copiedUsually visibleCaptured at recording
Approved version identifiable (7.5.2c)Filename versioning at bestRarely trackedVersion history per guide
Change control (7.5.3.2c)Manual disciplinePage historyAutomatic per revision
Available at point of use (8.5.1a)Requires finding the driveGood, if people searchGood, if the tool is in the browser
Drift is visibleNo, the words still read fineNoYes, the screenshot no longer matches the screen
Retention and disposition (7.5.3.2d)Whatever the drive policy isOften noneDepends on the tool, ask

The "drift is visible" row is the one people underestimate. A written procedure ages invisibly: two years after the ERP interface changed, the sentences still parse. A screenshot-based guide fails loudly, because the screen in the guide no longer matches the screen in front of the operator. For an evidence file, loud failure is a feature.

The layer ISO does not cover, and a European buyer should

ISO 9001 says nothing about the GDPR. But if your work instructions are screenshots of real systems, your QMS is now a personal data processing operation, and two obligations collide usefully.

Article 5(1)(c) requires data minimisation. A screenshot taken to show where the button is does not need the customer's name, address and order history in it. Automatic redaction is not a nicety here; it is what makes the screenshot proportionate to its purpose.

Article 5(1)(e) requires storage limitation. Clause 7.5.3.2(d) requires retention and disposition. That is the same discipline stated twice, and most organisations implement neither. If you are writing a retention rule for the QMS anyway, write one that satisfies both.

Then the question a certification auditor will not ask but your DPO should: where does this live? A screenshot library of your production systems is a detailed map of how your company operates. Under Article 28 you need a data processing agreement with whoever hosts it, and you are entitled to the sub-processor list. Ask any vendor, including us, three things: which country the storage region is in, who the sub-processors are, and what happens to your guides when you stop paying. Vagueness on any of the three is your answer. We go through this in more detail in our comparison of European SOP and documentation software.

Language

ISO 9001 does not require any particular language. Language appears only in 7.5.2(b), as an example of "format" you must consider, and ISO/IEC 17021-1 treats it as a matter of audit team composition.

National labour law is a different matter, and can require a local-language version of anything imposing an obligation on an employee, which many work instructions do. That constraint is separate from ISO, and we cover it in multilingual SOPs for European teams.

Common mistakes

Rebuilding the 2008 document set. Maintaining six documented procedures because the standard used to demand them is paperwork for a requirement withdrawn eleven years ago. Keep them if they are useful, not out of habit.

Confusing volume with control. Auditors do not score page count. A 12-step guide that is current beats a 40-page procedure two interface revisions stale.

No retention rule. 7.5.3.2(d) is the most commonly skipped clause, and the one that also carries GDPR consequences.

Screenshots with live personal data. Real customer records in a work instruction, distributed department-wide, is a minimisation problem you created yourself.

Approval that leaves no trace. "The quality manager reviewed it", with no date and no version, is not review and approval under 7.5.2(c).

Documenting the process you wish you had. Recording what people actually do surfaces the undocumented workaround. Writing from memory hides it until the auditor finds it.

What Loopyback does not do

We capture workflows and turn them into versioned, screenshot-based guides with automatic PII redaction, exportable to Markdown, PDF and HTML. That covers a good part of 7.5.2 and 7.5.3.2 for work instructions.

We are not an eQMS. No nonconformity register, no CAPA workflow, no management review module, no audit programme, no supplier evaluation, no electronic signature. If you need those, you need a quality management platform, and Loopyback sits alongside it as the layer that produces work instructions. Anyone selling a documentation tool as a complete ISO 9001 solution is overselling.

FAQ

Which documents are actually mandatory under ISO 9001:2015?

The standard requires documented information in specific places: the QMS scope, quality policy, quality objectives, evidence of competence, monitoring and measurement results, internal audit results, management review results, and nonconformity and corrective action results, among others. What it does not require is a quality manual or the six named 2008 procedures.

Do screenshots count as documented information?

Yes. 7.5.2(b) names graphics as part of format and treats media as an open choice. There is no requirement for prose. Identification, approval, version control and availability are what matter.

Can we keep everything in English as a Belgian or French company?

For ISO purposes, yes. For labour law purposes, not always: French and Belgian rules can make an English-only document unenforceable against an employee. Separate the runbooks from the documents that impose obligations, and translate the second group.

How long should we keep old versions of a work instruction?

ISO leaves it to you, which means you must decide and write it down. Set the period from the longest applicable legal or contractual requirement, then apply it consistently. Where a guide contains personal data in screenshots, GDPR storage limitation sets a ceiling, not a floor.

---

To see what versioned, redacted guides look like on your own processes, the free plan is enough to test the workflow. Paid plans start at €16 per month. Details on pricing.

SK
Suleyman Kurt

Founder of Loopyback

Suleyman is the founder of Loopyback, a Belgium based tool that turns workflows into step by step guides. He writes about documentation, SOPs and getting knowledge out of people's heads.

ISO 9001 Documented Information: What Clause 7.5 Actually Requires