Documents Required for ISO Certification in Thailand: Complete Checklist

Updated on: July 15, 2026

Published on: July 15, 2026 by Thai ISO Consultant Team

Checklist of documents required for ISO certification in Thailand

ISO certification in Thailand requires six core document categories: a quality policy, a scope document, quality objectives, procedures and work instructions, mandatory records, and a risk register. The exact list depends on your ISO standard and company size. Having the right documents ready before your audit prevents delays.

Missing a required record can stall your audit. Too many unnecessary documents create extra work. This checklist tells you exactly what you need — nothing more, nothing less.

Thai ISO Certification works in association with Kingsmen Certification Services to help Thai businesses build audit-ready documentation. This article supports our main guide to ISO Certification in Thailand.

Why Documentation Matters in ISO Certification

Documentation is not just paperwork. It is proof that your system works.

Auditors cannot watch every process your team runs. What they review are your records, procedures, and policies. These show your Quality Management System (QMS) is real and active.

ISO 9001:2015 uses the term “documented information.” You can use written procedures, flowcharts, or digital records. But flexibility does not mean optional. Some documents are still mandatory. Missing them causes a non-conformity at your audit.

Good documentation also helps day-to-day operations. It keeps your team consistent, cuts errors, and makes onboarding much easier.

Core Documents Required for ISO Certification

The table below covers the key ISO certification documentation checklist items. It shows what each document is for and what it looks like in practice. These apply to ISO 9001:2015 — the most common standard among Thai businesses.
Document TypePurposeExample
Quality PolicyStates your commitment to quality“We deliver services that meet customer requirements.”
Scope DocumentDefines what your QMS coversSites, products, and services in scope
Quality ObjectivesSets measurable targets“Reduce complaints by 20% in 12 months”
ProceduresExplains how key processes must runAudit procedure, supplier evaluation
Work InstructionsGives step-by-step task guidanceAssembly checklist, inspection protocol
Records / FormsProves activities happenedTraining logs, signed checklists
Risk RegisterLists risks and controlsRisk matrix with mitigation actions
Internal Audit ReportsProves audits were completedAudit schedule, findings, action items
Management Review MinutesShows leadership reviewed the QMSMeeting notes with decisions and actions
Corrective Action LogTracks issues and fixesNon-conformance reports, CAPA records

These are the mandatory documents for ISO certification that auditors check during any ISO 9001:2015 assessment. Other standards may need more. ISO 14001 needs an environmental aspects register. ISO 45001 needs hazard identification records.

Document Checklist by Company Size

Do small businesses need the same documents as large companies? No. ISO 9001:2015 states that documentation should match your organization’s size and complexity.

ISO Certification Document Checklist for Small Business

A small business typically needs this minimum set:

  • Quality policy (clause 5.2)
  • Scope of the QMS (clause 4.3)
  • Quality objectives (clause 6.2)
  • Supplier evaluation criteria (clause 8.4.1)
  • Training and competence records (clause 7.2)
  • Internal audit program and results (clause 9.2)
  • Management review minutes (clause 9.3)
  • Corrective action records (clause 10.2)

These eight items do not need to be complex. A one-page quality policy works. A short scope statement is fine. They just need to reflect how your business actually runs.

Mid-to-Large Business: Additional Documents

Larger organizations need a broader set of ISO documentation requirements, including:

  • Full procedures library for all major processes
  • Work instructions for each operational task
  • Risk register with identified risks and controls
  • Customer satisfaction monitoring records
  • Supplier evaluation and performance records
  • Calibration records for measurement equipment
  • Design and development records (where applicable)
  • Production and service provision records
  • Change control records

The rule is simple: document what you do, and do what you document. Auditors check whether your documents match your real operations — not how impressive they look.

What Is a Quality Manual and Do You Still Need One?

A quality manual describes your QMS — its scope, policies, and key procedures. Under ISO 9001:2008, it was required. Under ISO 9001:2015, it is not.

The 2015 revision dropped this rule. The goal was to cut unnecessary paperwork and give organizations more freedom.

Many Thai businesses still keep a quality manual. Here is why:

  • Client requirements: Some customers ask for one during supplier checks.
  • Staff onboarding: It gives new employees a clear overview of the QMS.
  • Internal reference: It combines your four core mandatory documents in one place.

If your clients need a quality manual, create one. If they do not, you have no ISO obligation to produce it. What matters is that your documents show your QMS is structured and active.

How Long Should You Keep ISO Records?

ISO 9001:2015 does not set exact retention periods. Your organization must define its own rules and document them.

All retained records must be:

  • Legible and clearly identifiable
  • Retrievable when auditors or your team need them
  • Protected from loss or unauthorized access

When setting your document retention period, consider:

  • Legal requirements in Thailand or your jurisdiction
  • Customer contracts — some sectors require 10 years or more
  • Sector-specific standards — ISO 13485 has its own retention rules
  • Your risk level — higher-risk organizations often keep records longer

For most Thai SMEs, standard practice looks like this:

  • Audit and management review records: 3–5 years
  • Training and competence records: Duration of employment, plus a set buffer
  • Corrective action records: 3–10 years, based on contract terms
  • Calibration records: Equipment life, plus an investigation window

Create a simple retention schedule. List each record type, how long to keep it, where it is stored, and who owns it. Keep that schedule under document control too.

Common Documentation Mistakes That Delay Certification

Poor documentation is the top reason ISO timelines run over. These are the mistakes auditors catch most often:

  • Documents don’t match real practice. If your procedure says one thing and your team does another, the auditor will catch it.
  • Training records are missing. Auditors always ask for proof of training. Gaps lead to a non-conformity.
  • Internal audits were skipped. They are mandatory. Skip them and you arrive at your external audit unprepared.
  • No version control. Without clear version numbers, old documents create compliance gaps.
  • Corrective action logs are too thin. Very few logged issues is a red flag. A healthy QMS finds and records problems regularly.
  • Over-documentation. Unnecessary procedures make your system hard to maintain. Keep it lean.

Building documentation for the first time? Reviewing an existing QMS? Thai ISO Certification can help you find gaps and fix them. Learn more about how to get ISO certification in Thailand. Or explore our Integrated Management System services if you are pursuing more than one standard.

Start Your Documentation with Expert Support

Getting your documentation right from the start saves time and cuts audit stress. The requirements are not as complex as they look — especially with the right support.

Thai ISO Certification works in association with Kingsmen Certification Services to help businesses across Thailand build audit-ready documentation for ISO 9001, ISO 14001, ISO 45001, and other recognized standards.

Ready to get started? Reach out for a free consultation or documentation support quote:

Frequently Asked Questions

What documents are required for ISO 9001 certification?

ISO 9001:2015 requires four core documents: your QMS scope, quality policy, quality objectives, and supplier evaluation criteria. You also need records for training, internal audits, management reviews, and corrective actions. The total number of records depends on your business size and how your processes work.

Do small businesses need the same documents as large companies?

No. ISO 9001:2015 lets you scale documentation to your size. Small businesses usually need a quality policy, scope statement, training records, audit results, and a corrective action log. Larger organizations need more — such as full procedures, work instructions, and a risk register.

Is a quality manual mandatory for ISO certification?

No. ISO 9001:2015 removed this requirement. Some clients still ask for one. If yours do, create it. If not, skip it. What matters is that your documents show your QMS is real and active.

How long should ISO records be kept?

ISO 9001:2015 does not set fixed periods. You define your own schedule. Base it on Thai laws, customer contracts, and sector rules. Most Thai SMEs keep audit and review records for 3–5 years. Keep training and corrective action records longer if your contracts require it.

Can a consultant help prepare ISO documentation in Thailand?

Yes. A consultant identifies what is missing, aligns your procedures with how your business works, and builds your full document set for audit. Thai ISO Certification — working in association with Kingsmen Certification Services — guides you through every step. This saves time and reduces your audit risk.

What happens if documentation does not match actual processes during an audit?

The auditor records it as a non-conformity. A major finding means you cannot be certified until it is resolved. A minor finding must also be fixed before certification is confirmed. Most organizations have up to three months to correct the issue and provide proof of the fix.

Get Free Consultation

Share your requirements and our ISO experts will guide you through the certification process.

Thai ISO Consultant Team

The Thai ISO Consultant Team is a group of certified ISO professionals specialising in Quality, Environmental, Health & Safety, and Information Security Management Systems. Working in association with Kingsmen Certification Services and with hands-on experience supporting startups, manufacturers, and enterprises across Thailand, the team helps organisations achieve internationally recognised certification efficiently and confidently. All content is reviewed for technical accuracy against ISO standard requirements and recognised certification body audit criteria.

Scroll to Top

Please share your details. Our consultant will contact you at the earliest.