Guides / ISO 9001
ISO 9001 process maps: clause 4.4, turtle diagrams & documented information
An ISO 9001 process map is the visual representation of a process inside a Quality Management System (QMS) that satisfies clauses 4.4 (process approach) and 7.5 (documented information). The most common formats are swimlane flowcharts, turtle diagrams, and SIPOC diagrams — each addresses a different audit question.
What ISO 9001:2015 actually requires
ISO 9001:2015 clause 4.4 requires the organization to "determine the processes needed for the quality management system" and to "determine the sequence and interaction of these processes." That's the bedrock requirement that makes process mapping mandatory — though the standard never specifies a notation.
Clause 7.5 then requires "documented information" to be controlled — meaning your process maps need version numbers, owners, and approval dates visible on the artifact itself.
Documented information defined
ISO 9001:2015 replaced "documents" and "records" with the umbrella term documented information. The standard explicitly requires documented information for:
- Scope of the QMS (4.3)
- Quality policy (5.2.2)
- Quality objectives (6.2.1)
- Evidence of fitness for purpose of monitoring equipment (7.1.5.1)
- Competence (7.2)
- Operational planning and control (8.1)
- Design and development outputs (8.3.5)
- Externally provided processes (8.4.1)
- Nonconformity and corrective action (10.2.2)
Process maps live inside this controlled documentation set.
Turtle diagrams explained
A turtle diagram is a single-page summary of one process, organized into six legs around a central process box:
- Inputs — what triggers and feeds the process
- Outputs — deliverables and downstream handoffs
- With what — equipment, software, infrastructure
- With whom — roles, competencies, training
- How — procedures, work instructions, methods
- How measured — KPIs, metrics, performance indicators
Auditors love turtle diagrams because they answer five of the most common clause 4.4 audit questions on one page.
SIPOC for ISO 9001
SIPOC (Suppliers → Inputs → Process → Outputs → Customers) is a five-column high-level overview, ideal for the top of your process documentation pyramid. Use it to show how a process connects upstream and downstream — particularly useful for satisfying clause 4.4's "sequence and interaction" requirement.
Pair the SIPOC with a detailed swimlane flowchart and you've covered both the bird's-eye view and the operational detail.
The 'six documented procedures' myth
ISO 9001:2008 mandated six specific documented procedures. ISO 9001:2015 removed that explicit list — you now decide which procedures need to be documented based on risk and process complexity. That said, in practice most certified organizations still maintain documented procedures for:
- Control of documented information
- Internal audit
- Control of nonconforming output
- Corrective action
- Management review
- Risk management
Process interaction matrix
To prove "sequence and interaction" (4.4.1.b), build a process interaction matrix: rows and columns list every identified process; each cell marks where one process passes inputs to another. Pair the matrix with a top-level process map showing arrows between process boxes.
Worked example: purchasing process map
A typical ISO 9001 purchasing process map (clause 8.4 — externally provided processes, products, and services) includes:
- Purchase requisition created (Requester)
- Supplier qualification check (Procurement)
- Approval per delegation of authority (Manager)
- PO issued (Procurement)
- Goods/services received and inspected (Receiver)
- Nonconforming product handling — if applicable (Quality)
- Invoice three-way match (AP)
- Payment (Treasury)
Each step gets a swimlane, every decision shows both branches, and the nonconformance path links to your corrective action procedure (clause 10.2).
Audit-ready process map checklist
- Process owner named on the diagram
- Version number and effective date visible
- Inputs, outputs, and external interfaces shown
- Decision diamonds with both branches drawn
- References to related procedures and work instructions
- KPIs / process measures called out
- Linked to risk register (clause 6.1) for high-risk steps
Frequently asked questions
How many process maps does ISO 9001 require?
The standard doesn't specify a number. You map every process inside your QMS scope — typically 8 to 20 for a small-to-mid organization. The exact set depends on your operations, but auditors expect to see the management process, all customer-facing processes (sales, design, production, delivery), and support processes (HR, purchasing, infrastructure, internal audit).
What documents does ISO 9001:2015 require?
The standard explicitly requires documented information for the QMS scope, quality policy, quality objectives, operational planning, nonconformity handling, internal audits, management reviews, and several other items listed in clause 7.5. Beyond those, you decide what additional procedures or work instructions to document based on risk and complexity.
Turtle diagram vs. SIPOC: which should I use?
Use a turtle diagram when you need a single-page deep dive on one process — it covers inputs, outputs, methods, resources, people, and measures. Use SIPOC when you need a high-level overview showing how a process connects to suppliers and customers. Most certified organizations use both: SIPOC at the top of the documentation pyramid, turtle diagrams or swimlane flowcharts underneath.
Does ISO 9001 require a specific notation like BPMN?
No. ISO 9001 is notation-agnostic. Swimlane flowcharts, BPMN, EPC, turtle diagrams, and SIPOC are all acceptable. Choose the format your auditors and operators can read fluently — clarity trumps formal notation.
How is ISO 9001 different from ISO 14001 process mapping?
The mapping techniques are identical. The difference is scope: ISO 9001 maps quality-related processes, ISO 14001 maps environmental aspects and impacts. Many organizations run an integrated management system (IMS) and use the same diagrams to satisfy both standards, with clause-mapping annotations to show which boxes serve which standard.
Can I generate these diagrams from a spreadsheet?
Yes. Querychart turns a structured spreadsheet (one row per step, with role, action, and decision columns) into a connected swimlane flowchart automatically. When the process changes, you edit the row and the diagram updates — no manual redrawing.
Generate your ISO 9001 process flowchart from a spreadsheet in Querychart →