Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 21001 mandatory documents explained

ISO 21001 Mandatory Documents: The Complete Clause-by-Clause List

ISO 21001 mandatory documents are the documented information ISO 21001:2025 requires an educational organization management system (EOMS) to maintain and the records it requires it to retain — and the list is shorter than most first-cycle implementations produce, because the standard follows the harmonized structure’s rule of naming a small set of documents and leaving the rest to the organisation’s judgement under clause 7.5. There is no EOMS manual in the list, no required procedure format and no specified number of policies. What the standard does name falls into two groups: the documents that describe the system (scope, policy, objectives, operational planning) and the records that prove it operated (competence, design and development, delivery, release, monitoring and satisfaction results, audits, management review, nonconformities). This guide lists the ISO 21001 mandatory documents clause by clause against the 2025 edition’s structure, explains what each has to contain to survive an audit, separates the education-specific records from the shared core, and names the second tier that no clause requires and every auditor asks for.

ISO 21001 mandatory documents: what to maintain and what to retain
Maintained documents: scope, policy, objectives, operational planning · Retained records: competence, design and development, delivery, release, satisfaction and monitoring, audit, management review, nonconformity and corrective action.

How ISO 21001 defines documented information

ISO 21001:2025 uses the harmonized structure’s single term. Clause 3.10 defines documented information as “information required to be controlled and maintained by an organization and the medium on which it is contained”, and its second note settles the old document-versus-record question: documented information can refer to the management system and its processes, to “information created in order for the organization to operate (documentation)” and to “evidence of results achieved (records)”. Where the text says the organisation shall maintain documented information, it means a living document; where it says retain, it means a record. Clause 7.5 then requires the documented information the standard specifies plus whatever the organisation itself determines is necessary for the effectiveness of the EOMS — and that second half is where most of a real system lives. Our guide to ISO 21001:2025 covers the edition; this post covers what it makes you write down.

The ISO 21001 mandatory documents, clause by clause

Clause (ISO 21001:2025) Documented information Maintain or retain What the auditor tests
4.3 Scope of the EOMS The scope: educational products and services, sites, delivery modes, and any requirement the organisation determines does not apply Maintain That the scope matches what is delivered and that exclusions are justified
5.2 Educational organization policy The policy, available as documented information Maintain Commitments, framework for objectives, communication, availability to interested parties
6.2 Educational organization objectives The objectives and the plans to achieve them Maintain Measurable, monitored, per beneficiary group where relevant
7.2 Competence Evidence of competence of educators and staff Retain Competence determined, actions taken, effectiveness evaluated — not just qualifications held
7.5 Documented information Control of documented information: identification, format, review, approval, distribution, access, retention, disposition Maintain Current versions in use; obsolete ones controlled
8.1 Operational planning and control Documented information to the extent necessary to have confidence processes are carried out as planned and to demonstrate conformity of educational products and services Maintain and retain Programme plans, timetables, delivery records that show planned versus delivered
8.2 Requirements for the educational products and services Results of the review of requirements, and any new requirements Retain Learner and beneficiary requirements determined, reviewed and changes recorded — admission, programme and assessment requirements
8.3 Design and development of the educational products and services Design inputs, controls (reviews, verification, validation), outputs and changes Retain Curriculum, learning outcomes and assessment methods designed as a governed process with review points
8.4 Control of externally provided processes, products and services Evaluation, selection, monitoring and re-evaluation of external providers Retain Placement providers, external educators, e-learning platforms, awarding partners
8.5 Delivery of the educational products and services Records needed to enable traceability and to evidence delivery, including the identification and control of learner property and changes Retain Attendance and progress records, learner work, special-needs provisions, changes to delivery
8.6 Release of the educational products and services Evidence of conformity with acceptance criteria and traceability to the person authorising release Retain Assessment results, moderation, certification decisions and who signed them off
8.7 Control of educational nonconforming outputs The nonconformity, actions taken, concessions and the authority deciding Retain Assessment errors, missed learning outcomes, complaints upheld — and what was done
9.1 Monitoring, measurement, analysis and evaluation Evidence of the results, including satisfaction of learners, other beneficiaries and staff Retain Survey data and outcomes data per group, analysed and acted on
9.2 Internal audit The audit programme and the audit results Retain Programme by risk; reports; findings closed
9.3 Management review Evidence of the results of management reviews Retain Inputs covered, decisions and actions recorded
10 Improvement The nature of nonconformities, actions taken and the results of corrective action Retain Root cause, action, effectiveness check

The clause headings are the 2025 edition’s; the documented-information requirements within clauses 8.2 to 8.7 follow the harmonized text ISO 21001 shares with ISO 9001, applied to educational products and services. Confirm the exact wording against your copy of the standard before you build the register, because the audit criteria are the text, not this table. Our guide to ISO 9001 mandatory documents shows the same structure on the quality side.

The education-specific records among ISO 21001 mandatory documents

Six of the entries above are where an EOMS differs from a QMS in practice, and where first-cycle audits raise findings.

  1. Requirements of learners and other beneficiaries (8.2). ISO 21001 separates the learner from the beneficiary — a parent, an employer, a funder — and expects requirements to be determined for each. A record that captures “the customer’s” requirements has collapsed the distinction the standard is built on.
  2. Design and development records (8.3). The curriculum — defined in 3.28 as “what, why, how and how well learners should learn” — is a design output. Inputs (needs, regulatory requirements, prior programmes), review and approval points, learning outcomes, assessment methods and changes all need records; most providers document delivery and not design.
  3. Delivery and special-needs records (8.5). The standard defines a learner with special needs as one whose “educational needs cannot be met through regular instruction and assessment practices”. The record is what changed for that learner.
  4. Release and assessment integrity (8.6). The 2025 edition’s one named change is revised assessment text. Records of formative and summative assessment, moderation, appeals and who authorised results are the release evidence.
  5. Educator competence (7.2). An educator is “a person who performs teaching activities” — employees, volunteers or external providers. Competence records cover all three, and show development, not only certificates.
  6. Satisfaction of three groups (9.1). Learners, other beneficiaries and staff. One survey for everybody produces one record where the standard’s scope expects three. Our guide to learner satisfaction under clause 9.1 covers the design.

Beyond the ISO 21001 mandatory documents: what auditors still expect

Not named by a clause Why the auditor asks for it Where it usually lives
Interested-party and beneficiary analysis 4.2 requires the needs and expectations to be determined; Annex C classifies interested parties; a written analysis is the only practical evidence Context register
Risk and opportunity register 6.1 requires actions to address risks and opportunities to be planned; auditors follow the register into objectives and controls Planning file
Programme portfolio and curriculum documents The design outputs of 8.3 in their delivered form Academic or training office
Learner communication and complaints records Annex D covers communication with interested parties; ISO 10002 is in the bibliography; complaints feed 8.7 and 10 Student services
Data protection position for learner data Data security and protection is one of the eleven EOMS principles; ISO/IEC 27001 is in the bibliography Privacy or IT
Health and safety arrangements Annex G outlines health and safety considerations for educational organisations Facilities or HSE
EOMS manual Not required; useful only as an index to where each clause is met Optional

Building the documented-information register

  1. One row per clause requirement, with the document or record name, owner, location, review date and retention period.
  2. Mark maintain versus retain so version control applies to the first and retention rules to the second.
  3. Add the organisation’s own documented information under 7.5 — procedures, forms, templates — with the same columns.
  4. Cross-reference the internal audit programme so every row is sampled at least once per cycle; our ISO 21001 internal audit checklist follows the same clauses.
  5. Retire anything citing the 2018 edition, which is withdrawn along with its 2024 amendment.

Frequently asked questions

How many ISO 21001 mandatory documents are there?
Sixteen clause-level requirements in the table above: four maintained documents (scope, policy, objectives, operational planning) and twelve retained records, from competence to corrective action. The count depends on how you group them; the register, not the number, is what matters.

Does ISO 21001 require a manual?
No. Clause 7.5 requires the documented information the standard specifies and whatever the organisation determines is necessary. A manual is optional and earns nothing at audit unless it evidences activity.

What is the difference between maintain and retain?
Maintain means a living, version-controlled document such as the policy or scope; retain means a record kept as evidence of a result, such as assessment records or audit reports. ISO 21001 uses the single term documented information for both, per clause 3.10.

Which documents are unique to ISO 21001?
Records of beneficiary requirements, curriculum design and development, delivery and special-needs provision, assessment and release, educator competence and satisfaction of learners, other beneficiaries and staff. The rest is harmonized core text shared with ISO 9001.

Do we need documented procedures?
Only where the organisation determines they are necessary under 7.5 or under 8.1’s confidence requirement. Most providers write procedures for admission, design, assessment, appeals and complaints because the audit tests those processes.

Where this leaves you

Build the register from the sixteen clause requirements, mark each as maintained or retained, and spend the effort on the six education-specific records — beneficiary requirements, design and development, delivery and special needs, assessment and release, educator competence and three-group satisfaction — because that is where the ISO 21001 mandatory documents differ from a quality system and where the audit will look hardest.

References

More on ISO 21001

Every document and record in the register — the EOMS manual and policy, scope, objectives, beneficiary analysis, programme design and assessment procedures, competence records, satisfaction instruments, audit and review templates — is drafted in the ISO 21001 Educational Management Toolkit (43 templates), or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.