Manuals and the Management System Standards

The requirement for a “Quality Manual” from ISO 9001 is a long standing one from BS 5750 (the precursor to ISO 9001) and was typically a large document (“never mind the quality – feel the width”).

The current version of ISO 9001 still requires a “Quality Manual” as one of its documentation requirements but states that it needs (only) to include:

  • The scope of the QMS
  • The documented procedures established for the QMS or reference to them
  • A description of the interaction between the processes of the QMS

At its simplest this could be a sentence or two covering the scope, a list of procedures, and a system diagram or flowchart of the QMS processes.

ISO 14001 does not specify a manual but also requires documentation covering:

  • The scope of the EMS
  • The documented procedures established for the EMS or reference to them
  • A description of the interaction between the processes of the EMS

BS OHSAS 18001 again does not specify a manual but requires the same three elements to be documented:

  • The scope of the OH&S management system
  • The documented procedures established for the OH&S management system or reference to them
  • A description of the interaction between the processes of the OH&S management system

In summary then, none of these three standards require “manuals” in the physical sense but all three require key elements of each management system to be documented. None of these documents need be large and it should be possible to cover all three requirements in each case in a few pages.

Note that certification bodies sometimes expand the requirements of the standards to suit their own purposes and make their auditing and assessment easier but there is no foundation for this in the basic standards.

ISO is aiming to “standardise” the management standards over the next few years and I expect that the requirement in ISO 9001 for a “Quality Manual” will disappear and the standard will simply ask for the three elements as do the other standards. 

Integrating your management systems

As organisations adopt more formal management system standards (such as ISO 9001, ISO 14001, ISO/IEC 27001 and ISO/IEC 20000) these are frequently implemented as standalone systems.

However, there are 6 common elements in these management system standards that can be managed as a integrated management system across all these standards (including ISO 22000 and OHSAS 18001 as well) to the benefit of the whole organisation.

These common elements are:

  1. Policy
  2. Planning
  3. Implementation and operation
  4. Performance assessment
  5. Improvement, and
  6. Management review

Although each standard has its own specific requirements that need to be addressed, these six elements are present in all the above management system standards. ISO is working, through its ISO Guide 72, to ensure not only that these elements exist in all management system standards, but that they have the same clause numbers in each standard.

PAS 99:2006 Specification of common management system requirements as a framework for integration has been produced to help organisations benefit from consolidating the common requirements. If your organisation has adopted, or is adopting, more than one of these standards, the use of this integrated approach can reduce duplication and complexity and make internal and external audits more effective and efficient.

BS 10012:2009 Data Protection – Specification for a Personal Information Management System


The Data Protection Act applies to any organisation in the UK that holds personal information about living individuals. Compliance with the Data Protection Act is required by law and this standard will help you demonstrate compliance.

The BS 10012 standard:

  • provides a framework for developing an infrastructure to maintain and improve compliance
  • allows you to assess your current level of compliance, recognise weaknesses and provide opportunties for improvement
  • enables effective assessment of compliance by internal auditors and external assessors

This is provides in a straightforward format following the management system style of “plan-do-check-act”, also known as the Deming cycle, used in ISO 9001, ISO 14001, ISO 27001, etc.

The standard is available in hardcopy and PDF download for £100 (or £50 for BSI members) from BSI.

BSI also publish a simple guide to the Data Protection Act – Data Protection Pocket Guide – Essential Facts at Your Fingertips.