Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO clause 8 operation explained — Annex SL harmonized structure

ISO Clause 8: Operation Explained

ISO Clause 8: Operation Explained — this guide is part of our series on the ISO harmonized structure, the shared clause framework behind most ISO management system standards.

Most ISO management system standards share the same skeleton. It is set out in Annex SL, Appendix 2 of the ISO/IEC Directives Part 1 — the harmonized structure — and it gives every adopting standard the same ten clauses, the same core text and the same defined terms. Learn clause 8 once and you have learned it for ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22301, ISO 42001 and the rest.

What ISO clause 8 actually asks for

Clause 8 is where the management system meets the actual work. It is also the clause that varies
most between standards, because operation is inherently specific to what is being managed.

8.1 Operational planning and control

The common core requires you to plan, implement and control the processes needed to meet
requirements and to implement the actions determined in clause 6, by establishing criteria for the
processes, implementing control in accordance with those criteria, and keeping documented information
to the extent necessary to have confidence the processes have been carried out as planned.

Two further requirements sit inside 8.1 and are routinely missed. Planned changes must be
controlled
and the consequences of unintended changes reviewed, with action taken to mitigate
adverse effects. And outsourced processes must be controlled. Outsourcing the activity
never outsources the obligation.

How far clause 8 expands by standard

This is where you should stop thinking generically and read your own standard:

  • ISO 9001 runs to 8.7 —
    requirements for products and services, design and development, control of externally provided
    processes, production and service provision, release, and control of nonconforming outputs.
  • ISO 27001 is unusually short:
    8.1 operational planning and control, 8.2 information security risk assessment, 8.3 risk treatment.
    The substance lives in Annex A instead.
  • ISO 45001 covers eliminating
    hazards and reducing risk, management of change, procurement including contractors and outsourcing,
    and emergency preparedness and response.
  • ISO 22301 carries the heaviest
    clause 8 of all: business impact analysis, risk assessment, business continuity strategies and
    solutions, plans and procedures, and exercise programmes.
  • ISO 14001 adds emergency
    preparedness and response and a life cycle perspective on operational control.

Documented information ISO clause 8 expects

  • Operational procedures or work instructions to the extent needed for confidence
  • Process criteria — the standards to which work is judged acceptable
  • Records demonstrating processes ran as planned
  • Controls over outsourced processes: contracts, service levels, monitoring evidence
  • Change control records for planned operational change

Common audit findings against ISO clause 8

  • Outsourced processes not controlled. A cloud provider, contract manufacturer or
    managed service inside the scope with no defined controls or monitoring.
  • No process criteria. Work is performed but nothing states what “done correctly”
    means, so conformity cannot be judged.
  • Change made without review of consequences, contrary to the explicit requirement
    in 8.1.
  • Clause 6 actions never reaching operations. Risk treatments planned but not
    implemented in the processes that would deliver them.

Operational procedures for your standard.

Because clause 8 is the most standard-specific, each toolkit ships the operational procedures its own standard demands — from BIA and continuity plans to design control and emergency response.

Explore the toolkit →

Which standards ISO clause 8 applies to

The harmonized structure covers the great majority of ISO management system standards, including ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22301, ISO 20000-1, ISO 22000, ISO 42001, ISO 37301, ISO 50001, ISO 55001, ISO 41001, ISO 21001, ISO 28000 and ISO 39001. Adopting standards may add sub-clauses of their own, but they do not renumber the ten top-level clauses.

Two exceptions worth knowing. ISO 13485:2016 deliberately did not adopt the harmonized structure — its technical committee kept the older clause 4 to 8 layout to stay closer to medical device regulation, so the clause numbers on this page do not map to it. ISO/IEC 17025 and ISO 15189 are conformity assessment standards for laboratories rather than management system standards in the Annex SL sense, and they use their own structure.

Toolkits that implement ISO clause 8

Each of these standards uses the harmonized structure, so clause 8 applies to all of them. The toolkit for each ships the documented information the clause requires.

ISO 9001 · ISO 14001 · ISO 45001 · ISO 27001 · ISO 22301 · ISO 42001 · ISO 20000 · ISO 22000 · ISO 27701 · ISO 37301 · ISO 50001 · ISO 55001 · ISO 41001 · ISO 21001 · ISO 28000 · ISO 39001

ISO clause 8: frequently asked questions

Why is clause 8 so short in ISO 27001?

Because the operational detail sits in Annex A instead. ISO 27001 clause 8 has three sub-clauses covering operational planning, risk assessment and risk treatment.

Can we outsource a process that is in scope?

Yes, but you must control it. Clause 8.1 requires outsourced processes to be controlled, and the accountability for conformity stays with you.

References for ISO clause 8

Beyond ISO clause 8: the rest of the series

Clauses 4 to 10 are the harmonized structure shared by most ISO management system standards. Each guide in this series covers one clause across every standard that uses it.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.