ISO Clause 5: Leadership Explained — this guide is part of our series on the ISO harmonized structure, the shared clause framework behind most ISO management system standards.
Most ISO management system standards share the same skeleton. It is set out in Annex SL, Appendix 2 of the ISO/IEC Directives Part 1 — the harmonized structure — and it gives every adopting standard the same ten clauses, the same core text and the same defined terms. Learn clause 5 once and you have learned it for ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22301, ISO 42001 and the rest.
What ISO clause 5 actually asks for
Clause 5 moves accountability to the top of the organization. Under the harmonized structure the
old role of a “management representative” who owned the system on everyone else’s behalf was
deliberately removed. Top management can delegate the work, but not the accountability, and auditors
are expected to interview them directly.
5.1 Leadership and commitment
Top management must demonstrate leadership and commitment by taking accountability for
effectiveness, ensuring the policy and objectives are established and compatible with strategic
direction, integrating requirements into business processes, providing resources, communicating the
importance of conformity, ensuring intended outcomes are achieved, directing and supporting people,
promoting improvement, and supporting other management roles.
ISO 9001 adds 5.1.2 customer focus. ISO 45001 adds a notably stronger set of duties around worker
protection and a culture in which workers can report incidents without reprisal.
5.2 Policy
Establish a policy appropriate to the purpose and context of the organization, providing a framework
for objectives, including commitments to satisfy applicable requirements and to continual improvement.
It must be documented, communicated within the organization, and available to interested parties as
appropriate.
A policy that could be pasted onto any other company’s letterhead without alteration is the classic
weak point. “Appropriate to the purpose and context” means it should reference what you actually do
and the issues you identified in clause 4.
5.3 Organizational roles, responsibilities and authorities
Top management must ensure responsibilities and authorities for relevant roles are assigned,
communicated and understood. Two specific assignments are called out: ensuring the system conforms to
the standard, and reporting on its performance to top management.
Documented information ISO clause 5 expects
- The policy itself — documented information is explicitly required
- Evidence of communication: intranet posting, induction records, briefing notes
- Role descriptions, an organization chart, or a responsibility matrix covering system roles
- Evidence of top management engagement — review minutes, resourcing decisions, signed objectives
Common audit findings against ISO clause 5
- Generic policy. No link to context, no mention of what the organization does.
- Top management cannot describe the system. Auditors ask directors, not the
compliance manager. If the CEO cannot state the policy commitments or name a current objective, that
is a clause 5.1 finding regardless of how good the documentation is. - A management representative in all but name. Delegation is allowed; abdication is
not. Accountability must visibly sit with top management. - Responsibilities assigned but not communicated. The standard requires assigned,
communicated and understood.
Policies and role definitions, already written.
Each toolkit includes a policy aligned to the clause 5 commitments, plus role and responsibility definitions you can assign and communicate straight away.
Which standards ISO clause 5 applies to
The harmonized structure covers the great majority of ISO management system standards, including ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22301, ISO 20000-1, ISO 22000, ISO 42001, ISO 37301, ISO 50001, ISO 55001, ISO 41001, ISO 21001, ISO 28000 and ISO 39001. Adopting standards may add sub-clauses of their own, but they do not renumber the ten top-level clauses.
Two exceptions worth knowing. ISO 13485:2016 deliberately did not adopt the harmonized structure — its technical committee kept the older clause 4 to 8 layout to stay closer to medical device regulation, so the clause numbers on this page do not map to it. ISO/IEC 17025 and ISO 15189 are conformity assessment standards for laboratories rather than management system standards in the Annex SL sense, and they use their own structure.
Toolkits that implement ISO clause 5
Each of these standards uses the harmonized structure, so clause 5 applies to all of them. The toolkit for each ships the documented information the clause requires.
ISO 9001 · ISO 14001 · ISO 45001 · ISO 27001 · ISO 22301 · ISO 42001 · ISO 20000 · ISO 22000 · ISO 27701 · ISO 37301 · ISO 50001 · ISO 55001 · ISO 41001 · ISO 21001 · ISO 28000 · ISO 39001
ISO clause 5: frequently asked questions
Does ISO still require a management representative?
No. The harmonized structure removed that role. The responsibilities still exist and must be assigned under 5.3, but accountability sits with top management and cannot be delegated away.
How long should a policy be?
One page is usually enough. What matters is that it fits your purpose and context, provides a framework for objectives, and contains the commitments the standard requires.
References for ISO clause 5
- ISO/IEC Directives and Policies — where Annex SL and the harmonized structure are published.
- ISO management system standards — the full list of standards that adopt this structure.
Beyond ISO clause 5: the rest of the series
Clauses 4 to 10 are the harmonized structure shared by most ISO management system standards. Each guide in this series covers one clause across every standard that uses it.
- Clause 4: Context of the Organization
- Clause 5: Leadership — you are here
- Clause 6: Planning
- Clause 7: Support
- Clause 8: Operation
- Clause 9: Performance Evaluation
- Clause 10: Improvement