ISO 21001 mandatory documents are the documented information ISO 21001:2025 requires an educational organization management system (EOMS) to maintain and the records it requires it to retain — and the list is shorter than most first-cycle implementations produce, because the standard follows the harmonized structure’s rule of naming a small set of documents and leaving the rest to the organisation’s judgement under clause 7.5. There is no EOMS manual in the list, no required procedure format and no specified number of policies. What the standard does name falls into two groups: the documents that describe the system (scope, policy, objectives, operational planning) and the records that prove it operated (competence, design and development, delivery, release, monitoring and satisfaction results, audits, management review, nonconformities). This guide lists the ISO 21001 mandatory documents clause by clause against the 2025 edition’s structure, explains what each has to contain to survive an audit, separates the education-specific records from the shared core, and names the second tier that no clause requires and every auditor asks for.

How ISO 21001 defines documented information
ISO 21001:2025 uses the harmonized structure’s single term. Clause 3.10 defines documented information as “information required to be controlled and maintained by an organization and the medium on which it is contained”, and its second note settles the old document-versus-record question: documented information can refer to the management system and its processes, to “information created in order for the organization to operate (documentation)” and to “evidence of results achieved (records)”. Where the text says the organisation shall maintain documented information, it means a living document; where it says retain, it means a record. Clause 7.5 then requires the documented information the standard specifies plus whatever the organisation itself determines is necessary for the effectiveness of the EOMS — and that second half is where most of a real system lives. Our guide to ISO 21001:2025 covers the edition; this post covers what it makes you write down.
The ISO 21001 mandatory documents, clause by clause
| Clause (ISO 21001:2025) | Documented information | Maintain or retain | What the auditor tests |
|---|---|---|---|
| 4.3 Scope of the EOMS | The scope: educational products and services, sites, delivery modes, and any requirement the organisation determines does not apply | Maintain | That the scope matches what is delivered and that exclusions are justified |
| 5.2 Educational organization policy | The policy, available as documented information | Maintain | Commitments, framework for objectives, communication, availability to interested parties |
| 6.2 Educational organization objectives | The objectives and the plans to achieve them | Maintain | Measurable, monitored, per beneficiary group where relevant |
| 7.2 Competence | Evidence of competence of educators and staff | Retain | Competence determined, actions taken, effectiveness evaluated — not just qualifications held |
| 7.5 Documented information | Control of documented information: identification, format, review, approval, distribution, access, retention, disposition | Maintain | Current versions in use; obsolete ones controlled |
| 8.1 Operational planning and control | Documented information to the extent necessary to have confidence processes are carried out as planned and to demonstrate conformity of educational products and services | Maintain and retain | Programme plans, timetables, delivery records that show planned versus delivered |
| 8.2 Requirements for the educational products and services | Results of the review of requirements, and any new requirements | Retain | Learner and beneficiary requirements determined, reviewed and changes recorded — admission, programme and assessment requirements |
| 8.3 Design and development of the educational products and services | Design inputs, controls (reviews, verification, validation), outputs and changes | Retain | Curriculum, learning outcomes and assessment methods designed as a governed process with review points |
| 8.4 Control of externally provided processes, products and services | Evaluation, selection, monitoring and re-evaluation of external providers | Retain | Placement providers, external educators, e-learning platforms, awarding partners |
| 8.5 Delivery of the educational products and services | Records needed to enable traceability and to evidence delivery, including the identification and control of learner property and changes | Retain | Attendance and progress records, learner work, special-needs provisions, changes to delivery |
| 8.6 Release of the educational products and services | Evidence of conformity with acceptance criteria and traceability to the person authorising release | Retain | Assessment results, moderation, certification decisions and who signed them off |
| 8.7 Control of educational nonconforming outputs | The nonconformity, actions taken, concessions and the authority deciding | Retain | Assessment errors, missed learning outcomes, complaints upheld — and what was done |
| 9.1 Monitoring, measurement, analysis and evaluation | Evidence of the results, including satisfaction of learners, other beneficiaries and staff | Retain | Survey data and outcomes data per group, analysed and acted on |
| 9.2 Internal audit | The audit programme and the audit results | Retain | Programme by risk; reports; findings closed |
| 9.3 Management review | Evidence of the results of management reviews | Retain | Inputs covered, decisions and actions recorded |
| 10 Improvement | The nature of nonconformities, actions taken and the results of corrective action | Retain | Root cause, action, effectiveness check |
The clause headings are the 2025 edition’s; the documented-information requirements within clauses 8.2 to 8.7 follow the harmonized text ISO 21001 shares with ISO 9001, applied to educational products and services. Confirm the exact wording against your copy of the standard before you build the register, because the audit criteria are the text, not this table. Our guide to ISO 9001 mandatory documents shows the same structure on the quality side.
The education-specific records among ISO 21001 mandatory documents
Six of the entries above are where an EOMS differs from a QMS in practice, and where first-cycle audits raise findings.
- Requirements of learners and other beneficiaries (8.2). ISO 21001 separates the learner from the beneficiary — a parent, an employer, a funder — and expects requirements to be determined for each. A record that captures “the customer’s” requirements has collapsed the distinction the standard is built on.
- Design and development records (8.3). The curriculum — defined in 3.28 as “what, why, how and how well learners should learn” — is a design output. Inputs (needs, regulatory requirements, prior programmes), review and approval points, learning outcomes, assessment methods and changes all need records; most providers document delivery and not design.
- Delivery and special-needs records (8.5). The standard defines a learner with special needs as one whose “educational needs cannot be met through regular instruction and assessment practices”. The record is what changed for that learner.
- Release and assessment integrity (8.6). The 2025 edition’s one named change is revised assessment text. Records of formative and summative assessment, moderation, appeals and who authorised results are the release evidence.
- Educator competence (7.2). An educator is “a person who performs teaching activities” — employees, volunteers or external providers. Competence records cover all three, and show development, not only certificates.
- Satisfaction of three groups (9.1). Learners, other beneficiaries and staff. One survey for everybody produces one record where the standard’s scope expects three. Our guide to learner satisfaction under clause 9.1 covers the design.
Beyond the ISO 21001 mandatory documents: what auditors still expect
| Not named by a clause | Why the auditor asks for it | Where it usually lives |
|---|---|---|
| Interested-party and beneficiary analysis | 4.2 requires the needs and expectations to be determined; Annex C classifies interested parties; a written analysis is the only practical evidence | Context register |
| Risk and opportunity register | 6.1 requires actions to address risks and opportunities to be planned; auditors follow the register into objectives and controls | Planning file |
| Programme portfolio and curriculum documents | The design outputs of 8.3 in their delivered form | Academic or training office |
| Learner communication and complaints records | Annex D covers communication with interested parties; ISO 10002 is in the bibliography; complaints feed 8.7 and 10 | Student services |
| Data protection position for learner data | Data security and protection is one of the eleven EOMS principles; ISO/IEC 27001 is in the bibliography | Privacy or IT |
| Health and safety arrangements | Annex G outlines health and safety considerations for educational organisations | Facilities or HSE |
| EOMS manual | Not required; useful only as an index to where each clause is met | Optional |
Building the documented-information register
- One row per clause requirement, with the document or record name, owner, location, review date and retention period.
- Mark maintain versus retain so version control applies to the first and retention rules to the second.
- Add the organisation’s own documented information under 7.5 — procedures, forms, templates — with the same columns.
- Cross-reference the internal audit programme so every row is sampled at least once per cycle; our ISO 21001 internal audit checklist follows the same clauses.
- Retire anything citing the 2018 edition, which is withdrawn along with its 2024 amendment.
Frequently asked questions
How many ISO 21001 mandatory documents are there?
Sixteen clause-level requirements in the table above: four maintained documents (scope, policy, objectives, operational planning) and twelve retained records, from competence to corrective action. The count depends on how you group them; the register, not the number, is what matters.
Does ISO 21001 require a manual?
No. Clause 7.5 requires the documented information the standard specifies and whatever the organisation determines is necessary. A manual is optional and earns nothing at audit unless it evidences activity.
What is the difference between maintain and retain?
Maintain means a living, version-controlled document such as the policy or scope; retain means a record kept as evidence of a result, such as assessment records or audit reports. ISO 21001 uses the single term documented information for both, per clause 3.10.
Which documents are unique to ISO 21001?
Records of beneficiary requirements, curriculum design and development, delivery and special-needs provision, assessment and release, educator competence and satisfaction of learners, other beneficiaries and staff. The rest is harmonized core text shared with ISO 9001.
Do we need documented procedures?
Only where the organisation determines they are necessary under 7.5 or under 8.1’s confidence requirement. Most providers write procedures for admission, design, assessment, appeals and complaints because the audit tests those processes.
Where this leaves you
Build the register from the sixteen clause requirements, mark each as maintained or retained, and spend the effort on the six education-specific records — beneficiary requirements, design and development, delivery and special needs, assessment and release, educator competence and three-group satisfaction — because that is where the ISO 21001 mandatory documents differ from a quality system and where the audit will look hardest.
References
- ISO 21001:2025 — Educational organizations — Management systems for educational organizations — Second edition, July 2025; clause 3.10 and the clause structure are readable on the ISO Online Browsing Platform.
- ISO 10002 — Quality management — Customer satisfaction — Guidelines for complaints handling — Cited in the ISO 21001 bibliography for complaints handling.
More on ISO 21001
- ISO 21001 mandatory documents — you are here
- ISO 21001:2025 explained
- ISO 21001 implementation in six steps
- ISO 21001 internal audit checklist
- The EOMS policy
- ISO 21001 certification cost
Every document and record in the register — the EOMS manual and policy, scope, objectives, beneficiary analysis, programme design and assessment procedures, competence records, satisfaction instruments, audit and review templates — is drafted in the ISO 21001 Educational Management Toolkit (43 templates), or start with the free templates.