The IMS context of the organization is the foundation of an integrated management system. Clause 4 of the ISO high-level structure asks you to understand the organisation, the people who care about it and the boundaries of the system before you write a single procedure. Because ISO 9001, ISO 14001 and ISO 45001 share this clause, you can analyse context once and use it for all of them, instead of producing three separate documents that say the same thing.
This guide explains how to handle the IMS context of the organization: what clause 4 requires, how to identify issues and interested parties, how to set the scope, how to record it and how to keep it current.
Free gap assessment
Are you ready for the 2026 edition of ISO 9001?
Score yourself against the new edition, free, including the risk and opportunity split and the clause 10 renumbering that breaks converted checklists.
Run the free ISO 9001 gap assessment → or View premium report sample
What clause 4 requires across the standards
Clause 4 has four parts in the current editions of the management system standards built on the high-level structure. Clause 4.1 requires the organisation to determine external and internal issues that are relevant to its purpose and strategic direction and that affect its ability to achieve the intended results of the system. Clause 4.2 requires it to determine the interested parties relevant to the system and their relevant requirements. Clause 4.3 requires it to determine the scope of the system. Clause 4.4 requires it to establish, implement, maintain and continually improve the system, including the processes needed and their interactions. Our overview of Annex SL explains why the structure repeats across standards.
Each standard adds its own emphasis. Quality looks at customers and products, environment adds environmental conditions and compliance obligations, and health and safety adds workers and their participation.
Identifying issues for the IMS context of the organization
An issue is a factor that can help or hinder your ability to achieve your intended results. External issues arise outside the organisation, and internal issues arise within it. Consider both positive and negative factors.
| Type | Examples |
|---|---|
| External | Laws and regulation; market and competition; customer expectations; technology change; economic conditions; climate and natural hazards; supply chain; community attitudes |
| Internal | Strategy and culture; governance; workforce skills and turnover; infrastructure and equipment; knowledge; financial resources; systems and processes; safety performance |
A simple technique is a workshop using a PESTLE or SWOT framework, followed by a shortlist of the issues that matter most. Do not produce a long list for its own sake. An issue worth recording is one that would change a decision or a risk rating.
Climate change
Amendments published in 2024 to the management system standards added a requirement to determine whether climate change is a relevant issue, and to consider it within the needs of interested parties. Include a short statement of your conclusion, even if the answer is that climate change has limited relevance. Our guide to the ISO climate change amendment explains what changed, and ISO describes its work on the topic on its climate action page. A short conclusion is enough: state whether climate change affects your operations, supply chain, customers or legal obligations, and how you reached that view. If it does, add the relevant issue to your register and link it to a risk or objective.
Interested parties in the IMS context of the organization
Interested parties are the people and organisations that can affect, be affected by or perceive themselves to be affected by your decisions. They typically include customers, employees, contractors, owners and investors, suppliers, regulators, insurers, neighbours and communities, certification bodies and trade unions. For each, decide what they need or expect from you, and which of those needs become requirements you must, or choose to, meet.
A combined register is efficient. List each party once, show which standard each need relates to and mark obligations that are legal or contractual. Some needs are compulsory, such as legal requirements. Others are voluntary commitments that you adopt after considering them. Record which is which, because compliance obligations carry higher weight in audits and risk assessments.
Determining the scope
The scope states the boundaries and applicability of the system: which products and services, sites, activities and standards are covered. In deciding it, consider the issues and interested parties above, plus the activities you control or influence. The scope must be available as documented information and must not exclude activities or requirements that affect your ability to meet customer needs or your obligations. Exclusions are allowed only where the standard permits them and they do not undermine conformity.
An integrated scope statement can be a single paragraph naming the standards, sites, products and services, and any exclusions with reasons. Keep it precise. A vague scope such as “all activities” invites questions at certification, while a scope that omits a site that in fact affects the product invites a finding.
Processes and interactions
Clause 4.4 asks you to define the processes needed and how they interact. For an IMS, a single process map is enough: it shows core, management and support processes and the links between them. Mark where quality, environmental and health and safety requirements enter each process. This map becomes the backbone of the integrated management system manual and shapes the audit programme.
Linking context to risk and planning
Context is not an end in itself. Issues and interested party requirements feed the planning clauses, where you identify risks and opportunities and, for environment and safety, aspects and hazards. If a significant external issue, such as a new regulation, does not appear anywhere in the risk register, the link is broken. Our guide to the IMS risk register shows how to trace risks back to context, and the IMS implementation guide places the clause in the overall project.
A hypothetical example of the IMS context of the organization
The following is a hypothetical example invented for illustration. A food packaging company running quality, environmental and safety systems holds a half-day context workshop with managers from production, sales, engineering, HR and finance. They identify eight priority issues: tightening rules on recycled content, volatile resin prices, a skills shortage in maintenance, ageing extrusion equipment, growing customer demands for carbon data, a good safety record that risks complacency, flood risk at one site, and a new digital order system.
They also list ten interested parties, from major retail customers and the environmental regulator to the local community and the insurer, with needs for each. The output is a single two-page register. Each issue points to the risk register or an objective, and the scope statement names all three standards and both sites. At the next management review the register is updated, and the flood risk issue leads to a new action.
Recording the IMS context of the organization
The standards do not require a specific document for clause 4, but you need to show that the analysis was done, and that it is monitored and reviewed. A short register or table is usually enough. Include the date, the participants, the source of information, the issues, the interested parties and their needs, a link to the related risk or objective, and the review date. Avoid copying generic lists from the internet; auditors can tell when the content is not about your business.
Keeping the context current
The standards require you to monitor and review information about these issues and parties. Do so in management review, at least annually, and when a significant change occurs: a new law, a new customer segment, an acquisition, an incident. Ask each process owner to report changes at review meetings. Retire issues that no longer matter, and add new ones as they emerge.
Common mistakes with the IMS context of the organization
Frequent weaknesses include producing three separate analyses for three standards, copying a generic list, listing issues with no connection to risks or objectives, recording only threats, confusing interested parties with customers only, omitting workers and regulators, scope statements that are vague or inconsistent with the certificate, and never reviewing the analysis after the first year. Another is drafting clause 4 to satisfy the auditor, and never using it to make decisions.
Templates for the IMS context of the organization
Templates give you a fast start and a consistent format. The Integrated Management System Toolkit includes documents covering context, interested parties, scope and the wider system. Whatever format you use, tailor it to your own organisation and link it to your planning and management review.
IMS context of the organization FAQ
Do we need a separate context analysis for each standard?
No. Because the standards share clause 4, one analysis can serve all of them, with the topic-specific issues and requirements marked for quality, environment and health and safety.
Is a documented context analysis mandatory?
The standards require you to determine the issues and parties and to monitor them, but do not specify a document. In practice, a short record is the easiest way to show it.
Who should be involved in identifying issues?
Top management and people from major functions, so that strategy, operations and workforce views are all covered. A single quality manager is rarely enough.
How often should the context be reviewed?
At least annually as part of management review, and whenever significant changes occur in the organisation or its environment.
Must we consider climate change?
Following the 2024 amendments, you must determine whether climate change is a relevant issue for the system. Record your conclusion and the reasoning.