ISO 9001 is often described by engineers as “a documentation exercise for management” — but clause 8.3 (Design and Development) directly governs how you structure design reviews, manage design changes, and verify that your outputs meet requirements. Understanding it makes you a better engineer, not just a more compliant one.
ISO 9001:2015 is the world’s most widely adopted quality management system (QMS) standard, with over one million certified organizations globally. Most mechanical engineers work in companies that are either certified or supply to certified customers. Yet many engineers interact with ISO 9001 only through the frustration of documentation requests and internal audits. This guide explains what the standard actually requires from a working engineer’s perspective — not from a quality manager’s perspective — and addresses common misconceptions.
What ISO 9001 Is (and Isn’t)
ISO 9001:2015 specifies requirements for a quality management system. It does not specify product requirements, engineering methods, or design standards — it requires the organization to determine requirements and demonstrate it has a systematic process for meeting them. The standard is deliberately product-agnostic; it applies equally to a bakery, a software company, and a precision machine manufacturer.
The 2015 revision (replacing ISO 9001:2008) moved strongly toward a risk-based thinking framework (clause 6.1) and process approach (clause 4.4) rather than prescriptive procedure documentation. The change has practical significance: ISO 9001:2015 does NOT require a Quality Manual, mandatory procedures for every process, or a specific set of documents. It requires that processes are defined, understood, applied consistently, monitored for effectiveness, and improved. How this is documented is largely up to the organization.
Clause 8.3: Design and Development — What It Means for You
Clause 8.3 is the core design-engineering requirement. It requires the organization to establish, implement, and maintain a design and development process with the following elements:
8.3.2 — Design and Development Planning: Determine the stages of the design process, review and verification activities at each stage, and responsibilities. In practical terms: a project plan that shows what design reviews will happen, when, and who approves them. This does not have to be a formal FMEA or stage-gate system — it just needs to be systematic and appropriate to the project complexity.
8.3.3 — Design and Development Inputs: Document the requirements that design must satisfy — functional requirements, performance requirements, regulatory and legal requirements, applicable standards, and lessons learned from previous similar designs. For a machine designer, this maps to a Design Input Specification or Requirements Document at the start of a project. The standard requires this to be documented and reviewed for completeness and conflict.
8.3.4 — Design and Development Controls: Three activities are required: reviews (evaluate ability to meet requirements at defined stages), verification (confirm outputs meet input requirements — calculations, analysis, test), and validation (confirm the product meets intended use in actual or simulated conditions — prototype testing, field trials). These can be combined in practice, but all three must happen to some degree appropriate to the risk level of the design.
8.3.5 — Design and Development Outputs: The outputs of the design process must be documented in a form suitable for downstream use (manufacturing, purchasing, maintenance). This means drawings, specifications, material lists, and work instructions must be documented and approved before release. Traceability to the design inputs must be demonstrable.
8.3.6 — Design and Development Changes: Changes after initial design release must be identified, reviewed (for impact on previously approved outputs), authorized, and documented. In a PDM/PLM system, this is handled by the ECO (Engineering Change Order) process. The standard requires documented evidence that changes are controlled — informal “verbal changes” to drawings are a nonconformance.
Document Control: What the Standard Actually Requires
Clause 7.5 addresses “documented information” — what was called “document and record control” in old versions. The requirements are:
• Documents must be available, suitable for use, and adequately protected
• Distribution, access, retrieval, and use must be controlled
• Changes to documents must be reviewed and approved
• Obsolete versions must be prevented from unintended use
For engineering departments, this means: drawings must have revision control (revision letter/number, approval signature, effective date), only the current approved revision should be accessible to production, and superseded drawings must be clearly marked as obsolete or removed from the distribution system. A PDM/PLM system (SolidWorks PDM, PTC Windchill, Siemens Teamcenter) or even a well-managed shared network folder with enforced folder permissions can satisfy this requirement. What does not satisfy it: engineers keeping personal copies of drawings that are not version-controlled, or using printed drawings that may not reflect the current revision.
Nonconformance Handling (Clause 8.7 and 10.2)
When a product or service does not meet requirements — a part out of drawing tolerance, a weld that fails inspection, a machined surface with the wrong finish — the organization must control it. ISO 9001 requires:
1. Detection and segregation: Identify and contain nonconforming product to prevent unintended use or delivery
2. Disposition decision: Correct (rework), concession (accept as-is with customer approval if delivery required), or scrap
3. Root cause analysis: For significant or recurring nonconformances, investigate the root cause (not just the symptom)
4. Corrective action: Implement changes to prevent recurrence — process change, design change, training, new inspection step
5. Records: Document what happened, what was decided, and what corrective action was taken
For mechanical engineers, understanding this process matters because design errors generate nonconformances. If a tolerance is systematically missed in production, the root cause may be an overly tight tolerance specification, an unclear drawing note, or inadequate design-for-manufacturability review — all of which are design issues, not just production issues. A mature QMS connects nonconformance data back to the design team as a feedback loop.
Internal Audits: What Auditors Actually Look For
Clause 9.2 requires planned internal audits to evaluate conformance to the QMS and to the standard itself. When an internal auditor audits the engineering function, they are typically looking for:
• Evidence of design planning (project plans, design review records, stage-gate approvals)
• Evidence of design input documentation (requirements specifications, customer requirements captured)
• Evidence of design verification activities (calculations, test reports, analysis reports) and that these are traceable to specific design inputs
• Evidence that design changes are controlled (ECO records, revision history on drawings)
• Evidence that lessons learned from previous designs (including nonconformances) feed into new design projects
The most common audit findings in engineering departments: design changes not going through ECO process (“informal changes”), design inputs not formally documented (requirements known in someone’s head but not written down), and verification records not traceable to specific requirements.
Risk-Based Thinking in Design
Clause 6.1 and 8.3.2 together require that risk be considered in the design process. ISO 9001 does not mandate FMEA, FTA, or any specific risk analysis method — but it does require that significant risks to meeting requirements are identified and addressed. In practice, for most machine design companies, this means:
• Identifying which design features are safety-critical or require special control
• Determining the appropriate level of design review, calculation, and testing for the risk level
• Documenting the basis for key design decisions (why a 10 mm shaft was chosen, what the safety factor is, what standard was followed)
A simple risk register in the design project file, cross-referencing risks to the design activities taken to address them, can satisfy this requirement without implementing a full FMEA process.
Common Misconceptions
“We need a procedure for everything.” False. ISO 9001:2015 requires documented information only where the organization determines it is necessary to ensure effective planning and operation of processes, and where the standard specifically requires records. Procedures are a means to an end — consistent process execution — not an end in themselves.
“ISO 9001 certification means the product is good quality.” False. ISO 9001 certifies that the organization has a systematic process for defining quality requirements and working toward them. An organization can be ISO 9001 certified while producing mediocre products, as long as it can show systematic process conformance. Quality of product output depends on the adequacy of the requirements the organization sets for itself and its ability to meet them.
“Engineers don’t need to know the standard — that’s quality’s job.” False. Engineers are responsible for the design and development outputs that ISO 9001 Clause 8.3 regulates. Understanding what the standard requires helps engineers structure their work in a compliant way rather than fighting the QMS as bureaucratic overhead.
Conclusion
ISO 9001 at its core asks three questions: Did you understand what was required? Did you design/build/deliver something that meets those requirements? Do you know what to do when it doesn’t? For a mechanical engineer, this translates directly into capturing design inputs, performing and documenting verification, controlling design changes, and closing the loop on quality problems. Engineers who understand this framing find that ISO 9001 aligns with good engineering practice — it is only burdensome when implemented as a paperwork exercise disconnected from the actual design process.



コメント