ISO9001: Including statutory & regulatory requirements in the QMS (2024)

One of the requirements that are embedded within ISO 9001:2015 is the necessity to understand and include statutory and regulatory requirements within the Quality Management System (QMS); however, many people have difficulty with understanding how to do this. To help understand this process, there are three main questions to answer: what are these requirements, what does ISO 9001:2015 require, and how can I best include the requirements?

What are statutory and regulatory requirements?

By definition, “statutory” refers anything relating to a decree or act, and “regulatory” is related to state, national, or international laws and regulations – so, requirements of these sorts come from the legal system. These legal requirements are mandates that you need to follow for your products or services in order for them to be made legally available for sale. An example would be the safety requirements for sports helmets; helmets need to meet a certain level of testing to be considered safe for use, and any company that produces helmets needs to make sure their product meets these mandatory requirements.

What does ISO 9001:2015 mandate for these requirements?

In ISO 9001:2015, statutory and regulatory requirements are mentioned in conjunction with customer requirements. In all cases, your products and services need to meet customer and applicable statutory and regulatory requirements, and ISO 9001:2015 points out where you need to consider this in your QMS. This comes into consideration when understanding the needs of interested parties, understanding all requirements to ensure customer focus is maintained, determining and reviewing the requirements for your products and services, collecting design and development inputs, what control you will have on external providers, and post-delivery activities.


How can you best include these requirements in your QMS?

Of course, before you can include statutory and regulatory requirements in your QMS, you need to identify which are applicable to you, your processes, and your products and services. You need to know what laws and other mandatory requirements you need to meet in order to legally provide your products and services, and ISO 9001:2015 Appendix A.3 is very clear that it is for you to decide if any particular requirement of an interested party is relevant to your QMS. So, you need to have a way to identify the statutory and regulatory requirements that you need to meet, and you then need to ensure that you keep up to date on any changes.

Once you know the requirements you need to meet, you then need to find a way to bring them into your QMS. It does not make sense to try to have a separate method of controlling the activities that your employees need to do to meet statutory and regulatory requirements, so including these requirements in the processes, procedures, and documented information that your employees follow is advisable.

There are basically two main types of statutory and regulatory requirements to consider in your QMS:

ISO9001: Including statutory & regulatory requirements in the QMS (1)

  • Requirements applicable to your products or services: These requirements would include the specifications your products and services need to meet in order to be legally available for sale. This would include such items as safety testing standards (such as the helmet example above) or acceptable or unacceptable materials to use (such as restrictions on the use of asbestos). These requirements should be embedded into your product and service specifications that your employees use in design and production. If there are certain design requirements, such as material choice, these should be included within your design inputs and product specifications. If there are certain tests that are mandated, these should be included in any test instructions you have. You do not want to leave these requirements to chance, with the risk that separate information such as a second test plan was missed due to human error.
  • Requirements applicable to your processes and procedures: These requirements include mandates that need to be incorporated into your business processes and procedures. Some examples would be requirements for employee competence (such as vetting employees for a bonded carrier service) or safety requirements for employees working at heights to perform a process. The requirements need to become part of the way your process works so that employees know what to do when creating your products and services. If there is a documented procedure for performing the process, include these requirements within it; or, if you are controlling your process through adequate training, ensure that these requirements are included in the training. For the example of the competence requirements, these should be included with your other competence requirements for the job, such as a job description. All information for operating a process should be included in one location.

Don’t lose track of your statutory and regulatory requirements

The most important thing to remember about statutory and regulatory requirements is that it is your responsibility to identify them and then ensure that they are maintained and included in your QMS as applicable. By including these requirements within the documentation and practices of your QMS, you can better ensure that these important requirements are met and maintained, so that you can continue to legally provide your products and services by meeting all requirements that are applicable. Incorporating these requirements means that they are not easily forgotten.

For a better understanding of ISO 9001:2015 for statutory and regulatory requirements, check out this free online training:ISO 9001:2015 Foundations Course.

ISO9001: Including statutory & regulatory requirements in the QMS (2024)

FAQs

ISO9001: Including statutory & regulatory requirements in the QMS? ›

In ISO 9001:2015, statutory and regulatory requirements are mentioned in conjunction with customer requirements. In all cases, your products and services need to meet customer and applicable statutory and regulatory requirements, and ISO 9001:2015 points out where you need to consider this in your QMS.

Is ISO 9001 a regulatory requirement? ›

The ISO 9001 standard, in particular, requires certification. This certification does help in maintaining many legal requirements that companies face to ensure quality, but the standard itself is not required. ISO 9001 is followed by a significant number of companies in many countries across the world.

What do statutory and regulatory requirements mean? ›

Statutes also referred to as codes, are laws written and enacted by the legislative branch of government (e.g, U.S. Congress, state legislators). Regulations also referred to as rules, are written by agencies (e.g., Environmental Protection Agency) to supplement laws that were passed by the legislature.

What are ISO regulatory requirements? ›

ISO standards are internationally agreed by experts. Think of them as a formula that describes the best way of doing something. It could be about making a product, managing a process, delivering a service or supplying materials – standards cover a huge range of activities.

What is a regulatory requirement? ›

A regulatory requirement is a rule that a government entity imposes on an organization. Some federal and state laws govern virtually all organizations. Regulations govern how organizations manage their business and employees and how they interact with customers, among many other areas.

What is the difference between regulatory and compliance requirements? ›

Regulatory compliance focuses on aligning with external legal mandates such as laws and regulations in respective jurisdictions or industries. Corporate compliance is internal in nature with processes and procedures aimed at streamlining internal business requirements.

What are regulatory or compliance requirements? ›

Regulatory compliance is the process of adhering to laws, regulations, standards, and other rules set forth by governments and other regulatory bodies. It is an important aspect of doing business, as companies are required to follow certain laws and regulations to maintain their operations.

What is statutory and regulatory framework? ›

Legislative framework is the statutory or regulatory frameworks created by government. These are the laws and legislation created by government which guide, control or influence people, functions and the government itself.

What is ISO 9001 in layman's terms? ›

Being ISO 9001 certified means an organization is able to demonstrate the ability to consistently deliver products and services that meet and exceed customer and regulatory expectations. Conformity to ISO 9001 also means that the organization has an established QMS.

What are the 7 principles of ISO 9001? ›

What are the seven principles of quality management?
  • Engagement of people.
  • Customer focus.
  • Leadership.
  • Process approach.
  • Improvement.
  • Evidence-based decision making.
  • Relationship management.

What are the 5 elements of ISO 9001? ›

Additionally, ISO 9001:2015 added some new elements like :
  • Risk-based thinking.
  • Context of the organization.
  • Leadership.
  • Planning.
  • Support.
  • Operation.
  • Performance evaluation.
  • Improvement.
Jan 16, 2023

What is the ISO standard for QMS? ›

ISO 9001 is a standard that defines the requirements for a Quality Management System (QMS). It helps businesses and organizations be more efficient and improve customer satisfaction. The primary focus of the ISO 9001 standard is to meet customer requirements and strive to exceed customer expectations.

What are the six mandatory procedures as required by QMS ISO 9001? ›

Six procedure are- Control of Documents, Control of Records, Internal Audit, Corrective Action, Preventive Action, Control of Non Conforming Products." Six procedure are- Control of Documents, Control of Records, Internal Audit, Corrective Action, Preventive Action, Control of Non Conforming Products.

What is QMS checklist? ›

Assessment Checklist. This checklist serves as an initial guide to help you assess or implement a Quality Management System within your company. What is a Quality Management System (QMS)? A QMS is a system that serves to formally document processes and procedures within your organization.

Is ISO 9001 not a legal requirement? ›

There is NO legal obligation for obtaining ISO 9001. Nevertheless, it is a well-known accreditation that can influence other legal facets of a company. The widely accepted quality management concepts delineated by ISO 9001 result from their widespread recognition and extensive commercial advantages.

Is ISO a standard or regulation? ›

ISO standards are not actually regulations enforceable by law, but companies who choose to follow them stand to gain international credibility from their compliance.

Is ISO legally mandatory? ›

There is no legal requirement to have an ISO certification. That said, in some industries, customers may not work with a supplier that does not hold a certification. For instance, if you supply medical devices, you may be expect to hold ISO 13485.

References

Top Articles
Latest Posts
Article information

Author: Nathanael Baumbach

Last Updated:

Views: 5375

Rating: 4.4 / 5 (75 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Nathanael Baumbach

Birthday: 1998-12-02

Address: Apt. 829 751 Glover View, West Orlando, IN 22436

Phone: +901025288581

Job: Internal IT Coordinator

Hobby: Gunsmithing, Motor sports, Flying, Skiing, Hooping, Lego building, Ice skating

Introduction: My name is Nathanael Baumbach, I am a fantastic, nice, victorious, brave, healthy, cute, glorious person who loves writing and wants to share my knowledge and understanding with you.