Skip to main content
Westlink Intranet

Command Palette

Search for a command to run...

?
INTERNAL
Back to Compliance

ISO 9001:2015

ISO 9001:2015 — Quality management systems — Requirements

Requirements
123
Last reviewed
14/04/2026
Next review
14/04/2027
Source
5th edition, 2015-09-15

Reconciliation notes

Raw 'shall' word count in cl 4-10 normative body: 132. Extracted requirements: 123 (one row per shall-bearing sentence; 9 shall-words consolidate into compound sentences — one sentence with multiple 'shall' words becomes one row, per audit convention that assesses at clause/sentence granularity rather than per-word). Informative references: 3 (Introduction + Annex A + Annex B + Bibliography shalls, captured separately, not counted as requirements). PDF cross-check: 135 document-total shalls vs EPUB 136 — within ±2% tolerance; PDF text extraction is lossy at ligatures. Evidence populated in Step 10a (2026-04-14) via rules-based mapping: Full=10, Partial=101, Referenced-only=0, Gap=12, NotApplicable=0. Gap severity Critical=12, High=37, Medium=42, Low=22. Path C verification pass (2026-04-15): 62 Manual-only Partial rows reassessed against actual QHSE-MAN-001 content; 24 upgraded Partial→Full, 20 downgraded Partial→Gap, 18 retained Partial. Post-Path-C coverage: Full=34, Partial=57, Gap=32. Severity across all rated rows (Partial + Gap): Critical=12, High=33, Medium=25, Low=19. Gap-only severity: Critical=12, High=11, Medium=4, Low=5.

Requirements

Showing 123 of 123 requirements

IDClauseRequirementApplicabilityCoverageEvidenceGap
ISO9001-2015-4.1-014.1The organization shall determine external and internal issues that are relevant to its purpose and its strategic direction and that affect its ability to achieve the intended result(s) of its quality management system.ApplicableFull
ISO9001-2015-4.1-024.1The organization shall monitor and review information about these external and internal issues.ApplicableFull
  • QHSE-MAN-001 §4.1Manual §4.1 states context analysis reviewed at each management review and updated when significant changes occur.
ISO9001-2015-4.2-014.2Due to their effect or potential effect on the organization’s ability to consistently provide products and services that meet customer and applicable statutory and regulatory requirements, the organization shall determine: a) the interested parties that are relevant to the quality management system; b) the requirements of these interested parties that are relevant to the quality management system.ApplicableFull
ISO9001-2015-4.2-024.2The organization shall monitor and review information about these interested parties and their relevant requirements.ApplicablePartial
  • QHSE-MAN-001WMS Manual — interested parties section.
  • GOV-POL-013Modern Slavery Policy addresses supplier supply-chain interested parties.
  • GOV-POL-012 §Organisational ContextPolicy §Organisational Context — DISP and JOSCAR contractual anti-bribery requirements determined as compliance obligations — cl.4.2.
Medium
Confirm interested-parties register is maintained and reviewed.
ISO9001-2015-4.3-014.3The organization shall determine the boundaries and applicability of the quality management system to establish its scope.ApplicableFull
ISO9001-2015-4.3-024.3When determining this scope, the organization shall consider: a) the external and internal issues referred to in 4.1 ; b) the requirements of relevant interested parties referred to in 4.2 ; c) the products and services of the organization.ApplicableFull
ISO9001-2015-4.3-034.3The organization shall apply all the requirements of this International Standard if they are applicable within the determined scope of its quality management system.ApplicableFull
ISO9001-2015-4.3-044.3The scope of the organization’s quality management system shall be available and be maintained as documented information.ApplicableFull
ISO9001-2015-4.3-054.3The scope shall state the types of products and services covered, and provide justification for any requirement of this International Standard that the organization determines is not applicable to the scope of its quality management system.ApplicableFull
ISO9001-2015-4.4.1-014.4.1The organization shall determine the processes needed for the quality management system and their application throughout the organization, and shall: a) determine the inputs required and the outputs expected from these processes; b) determine the sequence and interaction of these processes; c) determine and apply the criteria and methods (including monitoring, measurements and related performance indicators) needed to ensure the effective operation and control of these processes; d) determine the resources needed for these processes and ensure their availability; e) assign the responsibilities and authorities for these processes; f) address the risks and opportunities as determined in accordance with the requirements of 6.1 ; g) evaluate these processes and implement any changes needed to ensure that these processes achieve their intended results; h) improve the processes and the quality management system.ApplicablePartial
  • QHSE-MAN-001 §3.3Manual §3.3 Process Model covers PDCA process interactions at a summary level; ISO a)–h) enumeration (inputs/outputs, sequence, criteria/indicators, resources, responsibilities, risks, evaluation, improvement) not all explicit in Manual — supporting procedures carry the detail.
Medium
Verify process map documenting inputs, outputs, sequence, responsibilities, and resources.
ISO9001-2015-4.4.2-014.4.24.4.2 To the extent necessary, the organization shall: a) maintain documented information to support the operation of its processes; b) retain documented information to have confidence that the processes are being carried out as planned.ApplicableFull
  • QHSE-MAN-001 §7.5Manual §7.5 Documented Information covers creation, approval, review, version control, classification, retention, accessibility — all per GOV-STD-001 and GOV-PRO-002.
ISO9001-2015-5.1.1-015.1.1Top management shall demonstrate leadership and commitment with respect to the quality management system by: a) taking accountability for the effectiveness of the quality management system; b) ensuring that the quality policy and quality objectives are established for the quality management system and are compatible with the context and strategic direction of the organization; c) ensuring the integration of the quality management system requirements into the organization’s business processes; d) promoting the use of the process approach and risk-based thinking; e) ensuring that the resources needed for the quality management system are available; f) communicating the importance of effective quality management and of conforming to the quality management system requirements; g) ensuring that the quality management system achieves its intended results; h) engaging, directing and supporting persons to contribute to the effectiveness of the quality management system; i) promoting improvement; j) supporting other relevant management roles to demonstrate their leadership as it applies to their areas of responsibility.ApplicablePartialLow
Confirm manual documents how top management demonstrates the seven specific commitments in cl 5.1.1 a-j.
ISO9001-2015-5.1.2-015.1.2Top management shall demonstrate leadership and commitment with respect to customer focus by ensuring that: a) customer and applicable statutory and regulatory requirements are determined, understood and consistently met; b) the risks and opportunities that can affect conformity of products and services and the ability to enhance customer satisfaction are determined and addressed; c) the focus on enhancing customer satisfaction is maintained.ApplicablePartialLow
ISO9001-2015-5.2.1-015.2.1Top management shall establish, implement and maintain a quality policy that: a) is appropriate to the purpose and context of the organization and supports its strategic direction; b) provides a framework for setting quality objectives; c) includes a commitment to satisfy applicable requirements; d) includes a commitment to continual improvement of the quality management system.ApplicableFull
  • GOV-POL-001Quality Policy — approved by CEO, satisfies cl 5.2.1 establish/framework.
  • GOV-POL-002 §IMS IntegrationWHS Policy IMS integration row anchors the cross-system quality policy linkage (GOV-POL-002 + GOV-POL-001 published as integrated suite).
ISO9001-2015-5.2.2-015.2.2The quality policy shall: a) be available and be maintained as documented information; b) be communicated, understood and applied within the organization; c) be available to relevant interested parties, as appropriate.ApplicablePartial
  • GOV-POL-001Quality Policy — maintained as documented information, available to relevant parties.
  • QHSE-MAN-001Manual documents policy communication.
  • GOV-POL-016 §ReviewSocial Media Usage Policy — commits to Available on WMS.
ISO9001-2015-5.3-015.3Top management shall ensure that the responsibilities and authorities for relevant roles are assigned, communicated and understood within the organization.ApplicableFull
ISO9001-2015-5.3-025.3Top management shall assign the responsibility and authority for: a) ensuring that the quality management system conforms to the requirements of this International Standard; b) ensuring that the processes are delivering their intended outputs; c) reporting on the performance of the quality management system and on opportunities for improvement (see 10.1 ), in particular to top management; d) ensuring the promotion of customer focus throughout the organization; e) ensuring that the integrity of the quality management system is maintained when changes to the quality management system are planned and implemented.ApplicablePartial
  • QHSE-MAN-001 §5.1Manual §5.1 assigns CEO accountability for WMS intended outcomes; ISO 5.3 a)–e) specific assignments (conformance, outputs, customer focus promotion, integrity during change, reporting to top management) not individually enumerated in the Manual.
Low
Verify manual includes role assignments for QMS conformity, process integrity, reporting to top management.
ISO9001-2015-6.1.1-016.1.16.1.1 When planning for the quality management system, the organization shall consider the issues referred to in 4.1 and the requirements referred to in 4.2 and determine the risks and opportunities that need to be addressed to: a) give assurance that the quality management system can achieve its intended result(s); b) enhance desirable effects; c) prevent, or reduce, undesired effects; d) achieve improvement.ApplicablePartial
  • QHSE-MAN-001Risks and opportunities section.
  • QHSE-PRO-001Hazard/Incident Procedure covers safety risks (ISO 45001); quality risks need analogous treatment.
  • GOV-POL-001 §Policy CommitmentsPolicy commits to risk-based approach aligned to ISO 31000 — cl.6.1 actions to address risks and opportunities.
  • GOV-POL-021Risk Management Policy — ISO 31000-aligned enterprise framework for determining and addressing risks and opportunities across the WMS.
High
Quality-specific risk assessment process may be absent. QHSE-PRO-001 is safety-focused; need either a quality risk procedure or explicit QMS risk treatment in manual.
ISO9001-2015-6.1.2-016.1.26.1.2 The organization shall plan: a) actions to address these risks and opportunities; b) how to: 1) integrate and implement the actions into its quality management system processes (see 4.4 ); 2) evaluate the effectiveness of these actions.ApplicablePartial
  • QHSE-MAN-001 §6.1Manual §6.1 states risk-based approach aligned with ISO 31000 applied at strategic/operational/project levels; ISO 6.1.2 a)–b) integration/evaluation/effectiveness loop details are in QHSE-PRO-002 (referenced).
  • GOV-POL-021Risk Management Policy — establishes the ISO 31000 process (identify, analyse, evaluate, treat) and integration of risk actions across the WMS.
High
Quality risk register with actions to address risks/opportunities, integrated into QMS processes, evaluated for effectiveness.
ISO9001-2015-6.1.2-026.1.2Actions taken to address risks and opportunities shall be proportionate to the potential impact on the conformity of products and services.ApplicablePartial
  • QHSE-MAN-001 §6.1Manual §6.1 describes risk-based approach but proportionality principle ('proportionate to potential impact') not explicitly stated — relies on QHSE-PRO-002 Risk Management Procedure.
  • GOV-POL-021Risk Management Policy — risk rated on a consistent likelihood/consequence basis with treatment evaluated against the risk criteria (proportionality).
High
Quality risk register with actions to address risks/opportunities, integrated into QMS processes, evaluated for effectiveness.
ISO9001-2015-6.2.1-016.2.16.2.1 The organization shall establish quality objectives at relevant functions, levels and processes needed for the quality management system.ApplicableFull
  • QHSE-MAN-001 §6.2Manual §6.2 establishes measurable objectives for quality, WHS, environmental performance set at management review, communicated, KPI-monitored.
ISO9001-2015-6.2.1-026.2.1The quality objectives shall: a) be consistent with the quality policy; b) be measurable; c) take into account applicable requirements; d) be relevant to conformity of products and services and to enhancement of customer satisfaction; e) be monitored; f) be communicated; g) be updated as appropriate.ApplicablePartial
  • QHSE-MAN-001 §6.2Manual §6.2 addresses measurable/monitored/updated; ISO 6.2.1 a)–g) not all explicit — consistency with quality policy, relevance to conformity and customer satisfaction, and communication not individually enumerated.
Medium
Confirm manual contains SMART quality objectives at relevant functions/levels, consistent with quality policy, measurable, with communication and update protocols.
ISO9001-2015-6.2.1-036.2.1The organization shall maintain documented information on the quality objectives.ApplicableFull
  • QHSE-MAN-001 §6.2Manual §6.2: 'Current objectives are maintained in the management system platform' — authoritative documented information.
ISO9001-2015-6.2.2-016.2.26.2.2 When planning how to achieve its quality objectives, the organization shall determine: a) what will be done; b) what resources will be required; c) who will be responsible; d) when it will be completed; e) how the results will be evaluated.ApplicablePartial
  • QHSE-MAN-001 §6.2Manual §6.2 mentions monitoring and updating but ISO 6.2.2 a)–e) plan-to-achieve elements (what, resources, responsible, completion date, evaluation method) not all documented in the Manual.
Medium
ISO9001-2015-6.3-016.3When the organization determines the need for changes to the quality management system, the changes shall be carried out in a planned manner (see 4.4 ).ApplicableFull
ISO9001-2015-6.3-026.3The organization shall consider: a) the purpose of the changes and their potential consequences; b) the integrity of the quality management system; c) the availability of resources; d) the allocation or reallocation of responsibilities and authorities.ApplicablePartialMedium
Change management for QMS itself (beyond documents) — new services, reorganisations, system changes.
ISO9001-2015-7.1.1-017.1.1The organization shall determine and provide the resources needed for the establishment, implementation, maintenance and continual improvement of the quality management system.ApplicableFull
  • QHSE-MAN-001 §7.1Manual §7.1: 'CEO ensures adequate resources for WMS implementation and continual improvement — personnel, infrastructure (offices, IT, vehicles, equipment), and work environment'.
ISO9001-2015-7.1.1-027.1.1The organization shall consider: a) the capabilities of, and constraints on, existing internal resources; b) what needs to be obtained from external providers.ApplicablePartial
  • QHSE-MAN-001 §7.1Manual §7.1 states resources assessed at management review and during project planning; internal-vs-external capability/constraint consideration implied but not explicitly structured.
Low
ISO9001-2015-7.1.2-017.1.2The organization shall determine and provide the persons necessary for the effective implementation of its quality management system and for the operation and control of its processes.ApplicableFull
  • QHSE-MAN-001 §7.1Manual §7.1 and §7.2 determine and provide persons with appropriate competence for effective QMS implementation.
ISO9001-2015-7.1.3-017.1.3The organization shall determine, provide and maintain the infrastructure necessary for the operation of its processes and to achieve conformity of products and services.ApplicablePartial
  • QHSE-MAN-001 §7.1Manual §7.1 mentions infrastructure (offices, IT systems, vehicles, equipment) at summary level; specific infrastructure determination/maintenance process not detailed.
Low
Infrastructure management — facilities, equipment, ICT. Manual reference; verify detail.
ISO9001-2015-7.1.4-017.1.4The organization shall determine, provide and maintain the environment necessary for the operation of its processes and to achieve conformity of products and services.ApplicablePartial
  • QHSE-MAN-001 §7.1Manual §7.1 mentions 'work environment appropriate for service delivery'; ISO 7.1.4 psychological/social/physical factor framework not explicitly addressed.
  • GOV-POL-010 §Organisational ContextPolicy commits to inclusive work environment — cl.7.1.4 environment for the operation of processes.
Low
ISO9001-2015-7.1.5.1-017.1.5.1The organization shall determine and provide the resources needed to ensure valid and reliable results when monitoring or measuring is used to verify the conformity of products and services to requirements.ApplicableFull
  • QHSE-MAN-001 §9.2Manual §9.2 Calibrated and Verified Monitoring Equipment commits to monitoring/measurement equipment calibrated or verified at specified intervals (fuel flow meters, noise meters, weighbridges, spill volume, gas detectors).
ISO9001-2015-7.1.5.1-027.1.5.1The organization shall ensure that the resources provided: a) are suitable for the specific type of monitoring and measurement activities being undertaken; b) are maintained to ensure their continuing fitness for their purpose.ApplicableFull
  • QHSE-MAN-001 §9.2Manual §9.2 specifies verification method and frequency per equipment type (OEM certificate, NMI-traceable verification, lab calibration, field bump test); out-of-calibration equipment removed from service to maintain fitness.
ISO9001-2015-7.1.5.1-037.1.5.1The organization shall retain appropriate documented information as evidence of fitness for purpose of the monitoring and measurement resources.ApplicableFull
  • QHSE-MAN-001 §9.2Manual §9.2 maintains a calibrated and verified equipment register; calibration and verification records are retained in accordance with GOV-SCH-001.
ISO9001-2015-7.1.5.2-017.1.5.2When measurement traceability is a requirement, or is considered by the organization to be an essential part of providing confidence in the validity of measurement results, measuring equipment shall be: a) calibrated or verified, or both, at specified intervals, or prior to use, against measurement standards traceable to international or national measurement standards; when no such standards exist, the basis used for calibration or verification shall be retained as documented information; b) identified in order to determine their status; c) safeguarded from adjustments, damage or deterioration that would invalidate the calibration status and subsequent measurement results.ApplicableGapLow
Manual silent on measurement traceability. Low applicability — where Westlink relies on measurements (mass, dimension for NHVR, fuel quantity, strapping tension), these are typically taken on externally calibrated equipment. Document the approach or exclude under cl 4.3.
ISO9001-2015-7.1.5.2-027.1.5.2The organization shall determine if the validity of previous measurement results has been adversely affected when measuring equipment is found to be unfit for its intended purpose, and shall take appropriate action as necessary.ApplicableGapLow
Manual silent on assessing validity of prior measurement results when equipment found unfit. See 7.1.5.2-01 rationale.
ISO9001-2015-7.1.6-017.1.6The organization shall determine the knowledge necessary for the operation of its processes and to achieve conformity of products and services.ApplicablePartial
  • QHSE-MAN-001 §4.1Manual §4.1.2 identifies 'workforce competence, restricted operation licensing, succession planning for specialist roles' as an internal issue; §7.2 Competence addresses acquisition. ISO 7.1.6 determination of organisational knowledge not a dedicated Manual section.
Low
Organisational knowledge capture — lessons learned, knowledge management.
ISO9001-2015-7.1.6-027.1.6This knowledge shall be maintained and be made available to the extent necessary.ApplicableGapMedium
Manual does not describe how organisational knowledge is maintained or made available. Succession planning noted as a context issue (§4.1.2) but no maintenance system. Add organisational knowledge clause to Manual or supporting procedure.
ISO9001-2015-7.1.6-037.1.6When addressing changing needs and trends, the organization shall consider its current knowledge and determine how to acquire or access any necessary additional knowledge and required updates.ApplicableGapMedium
Manual silent on considering current knowledge against changing needs and trends, and on acquiring/accessing additional knowledge.
ISO9001-2015-7.2-017.2The organization shall: a) determine the necessary competence of person(s) doing work under its control that affects the performance and effectiveness of the quality management system; b) ensure that these persons are competent on the basis of appropriate education, training, or experience; c) where applicable, take actions to acquire the necessary competence, and evaluate the effectiveness of the actions taken; d) retain appropriate documented information as evidence of competence.ApplicableFull
ISO9001-2015-7.3-017.3The organization shall ensure that persons doing work under the organization’s control are aware of: a) the quality policy; b) relevant quality objectives; c) their contribution to the effectiveness of the quality management system, including the benefits of improved performance; d) the implications of not conforming with the quality management system requirements.ApplicableFull
ISO9001-2015-7.4-017.4The organization shall determine the internal and external communications relevant to the quality management system, including: a) on what it will communicate; b) when to communicate; c) with whom to communicate; d) how to communicate; e) who communicates.ApplicableFull
  • QHSE-MAN-001 §7.4Manual §7.4 states 'structured internal and external communication processes'; ISO 7.4 a)–e) parameters (what, when, with whom, how, who communicates) not individually enumerated.
  • GOV-POL-013 §ReviewPolicy is available to suppliers and interested parties on request — cl.7.4 communication.
  • GOV-POL-009 §ReviewPolicy available to interested parties on request — cl.7.4 communication.
  • GOV-POL-010 §ReviewPolicy available to interested parties on request — cl.7.4.
  • GOV-POL-019 §ReviewPolicy §Review — policy available to interested parties on request — communication cl.7.4.
  • GOV-POL-012 §ReviewAvailable to interested parties on request
  • GOV-POL-018 §Policy CommitmentsAvailable to all officers, workers, contractors, suppliers
  • GOV-POL-015 §ReviewPrivacy Policy — commits to Available to interested parties.
  • GOV-POL-016 §ScopeSocial Media Usage Policy — commits to Available on WMS; all platforms, business and personal use; official accounts and personal opinions.
ISO9001-2015-7.5.1-017.5.1The organization’s quality management system shall include: a) documented information required by this International Standard; b) documented information determined by the organization as being necessary for the effectiveness of the quality management system.ApplicableFull
  • GOV-PRO-002 §3Document Control — scope covers both standard-required and organisation-determined documented information.
  • QHSE-MAN-001WMS Manual — top-level documented information register.
  • GOV-POL-019 §Policy CommitmentsPolicy §Policy Commitments — the Gifts and Hospitality Register is maintained as documented information — cl.7.5.1.
ISO9001-2015-7.5.2-017.5.2When creating and updating documented information, the organization shall ensure appropriate: a) identification and description (e.g. a title, date, author, or reference number); b) format (e.g. language, software version, graphics) and media (e.g. paper, electronic); c) review and approval for suitability and adequacy.ApplicableFull
  • GOV-PRO-002 §4Creation and update workflow — identification, format, review/approval.
  • GOV-STD-001Document Management Standard — identification and description.
ISO9001-2015-7.5.3.1-017.5.3.1Standard shall be controlled to ensure: a) it is available and suitable for use, where and when it is needed; b) it is adequately protected (e.g. from loss of confidentiality, improper use, or loss of integrity).ApplicableFull
ISO9001-2015-7.5.3.2-017.5.3.27.5.3.2 For the control of documented information, the organization shall address the following activities, as applicable: a) distribution, access, retrieval and use; b) storage and preservation, including preservation of legibility; c) control of changes (e.g. version control); d) retention and disposition.ApplicablePartialLow
Per pilot: verify GOV-PRO-002 explicitly enumerates all four activities (a-d) and handles external-origin documents.
ISO9001-2015-7.5.3.2-027.5.3.2Documented information of external origin determined by the organization to be necessary for the planning and operation of the quality management system shall be identified as appropriate, and be controlled.ApplicableFull
  • GOV-PRO-002 §5-7Distribution, access, retrieval, change control, external docs.
  • GOV-SCH-001Document Retention Schedule.
  • TEC-PRO-001 §Records and RetentionTEC-PRO-001 §Records and Retention establishes the Cyber Incident Register and the retention periods (permanent for ransomware payment reports, NDB statements, DISO notifications).
ISO9001-2015-7.5.3.2-037.5.3.2Documented information retained as evidence of conformity shall be protected from unintended alterations.ApplicablePartialLow
Per pilot: verify GOV-PRO-002 explicitly enumerates all four activities (a-d) and handles external-origin documents.
ISO9001-2015-8.1-018.1The organization shall plan, implement and control the processes (see 4.4 ) needed to meet the requirements for the provision of products and services, and to implement the actions determined in Clause 6 , by: a) determining the requirements for the products and services; b) establishing criteria for: 1) the processes; 2) the acceptance of products and services; c) determining the resources needed to achieve conformity to the product and service requirements; d) implementing control of the processes in accordance with the criteria; e) determining, maintaining and retaining documented information to the extent necessary: 1) to have confidence that the processes have been carried out as planned; 2) to demonstrate the conformity of products and services to their requirements.ApplicableFull
  • QHSE-MAN-001 §8.1Manual §8.1: 'Westlink plans, implements, and controls operational processes to meet requirements for service delivery' — considering client requirements, legislation, risk, resources, WHS hazards, environmental aspects.
  • QHSE-PRO-013 §Treatment Planning / Change & Non-ConformanceQMS process control over obsolescence-driven change and nonconforming-output handling.
  • OPS-MAN-002 §Chartering ProcessOperational planning and control of the chartering service — three phases, responsibilities, acceptance (fixture).
ISO9001-2015-8.1-028.1The output of this planning shall be suitable for the organization’s operations.ApplicablePartial
  • QHSE-MAN-001 §8.1Manual §8.1 implies output suitability through proportional controls; not an explicit statement.
Medium
Operational Planning implies output suitability through risk-proportionate controls, but the obligation is not stated explicitly.
ISO9001-2015-8.1-038.1The organization shall control planned changes and review the consequences of unintended changes, taking action to mitigate any adverse effects, as necessary.ApplicableFull
  • QHSE-MAN-001 §6.3Manual §6.3 Management of Change explicitly addresses planned changes (identify, assess risks, plan, communicate, verify effectiveness) and changes affecting WMS scope are CEO-approved.
ISO9001-2015-8.1-048.1The organization shall ensure that outsourced processes are controlled (see 8.4 ).ApplicableFull
  • QHSE-MAN-001 §8.3Manual §8.3 covers control of outsourced processes via tiered prequalification (GOV-PRO-003/005), performance monitoring, and contractor WHS requirements (QHSE-GDL-001).
ISO9001-2015-8.2.1-018.2.1Communication with customers shall include: a) providing information relating to products and services; b) handling enquiries, contracts or orders, including changes; c) obtaining customer feedback relating to products and services, including customer complaints; d) handling or controlling customer property; e) establishing specific requirements for contingency actions, when relevant.ApplicablePartialMedium
Customer communication procedure — enquiries, contracts, feedback, property handling, emergencies.
ISO9001-2015-8.2.2-018.2.2When determining the requirements for the products and services to be offered to customers, the organization shall ensure that: a) the requirements for the products and services are defined, including: 1) any applicable statutory and regulatory requirements; 2) those considered necessary by the organization; b) the organization can meet the claims for the products and services it offers.ApplicablePartialMedium
ISO9001-2015-8.2.3.1-018.2.3.18.2.3.1 The organization shall ensure that it has the ability to meet the requirements for products and services to be offered to customers.ApplicablePartialMedium
Review of requirements for products/services — COM-PRO-002 maps the tender/execution-phase legal and insurance review (CEO GO/NO-GO); residual gap: order confirmation and change control procedure.
ISO9001-2015-8.2.3.1-028.2.3.1The organization shall conduct a review before committing to supply products and services to a customer, to include: a) requirements specified by the customer, including the requirements for delivery and post-delivery activities; b) requirements not stated by the customer, but necessary for the specified or intended use, when known; c) requirements specified by the organization; d) statutory and regulatory requirements applicable to the products and services; e) contract or order requirements differing from those previously expressed.ApplicablePartialMedium
Review of requirements for products/services — COM-PRO-002 maps the tender/execution-phase legal and insurance review (CEO GO/NO-GO); residual gap: order confirmation and change control procedure.
ISO9001-2015-8.2.3.1-038.2.3.1The organization shall ensure that contract or order requirements differing from those previously defined are resolved.ApplicableFull
ISO9001-2015-8.2.3.1-048.2.3.1The customer’s requirements shall be confirmed by the organization before acceptance, when the customer does not provide a documented statement of their requirements.ApplicableFull
ISO9001-2015-8.2.3.2-018.2.3.28.2.3.2 The organization shall retain documented information, as applicable: a) on the results of the review; b) on any new requirements for the products and services.ApplicablePartialMedium
Review of requirements for products/services — tender review, order confirmation, change control procedure gap.
ISO9001-2015-8.2.4-018.2.4The organization shall ensure that relevant documented information is amended, and that relevant persons are made aware of the changed requirements, when the requirements for products and services are changed.ApplicablePartialMedium
ISO9001-2015-8.3.1-018.3.1The organization shall establish, implement and maintain a design and development process that is appropriate to ensure the subsequent provision of products and services.ApplicableFull
  • OPS-PRO-004 §Design Process and PlanningOPS-PRO-004 §Design Process and Planning establishes and maintains Westlink's design and development process and the applicability test for when an engagement involves design. Coverage Partial - documented in rev 1; residual is the design records accruing from the first designed engagements.
ISO9001-2015-8.3.2-018.3.2In determining the stages and controls for design and development, the organization shall consider: a) the nature, duration and complexity of the design and development activities; b) the required process stages, including applicable design and development reviews; c) the required design and development verification and validation activities; d) the responsibilities and authorities involved in the design and development process; e) the internal and external resource needs for the design and development of products and services; f) the need to control interfaces between persons involved in the design and development process; g) the need for involvement of customers and users in the design and development process; h) the requirements for subsequent provision of products and services; i) the level of control expected for the design and development process by customers and other relevant interested parties; j) the documented information needed to demonstrate that design and development requirements have been met.ApplicableFull
  • OPS-PRO-004 §Design Process and PlanningOPS-PRO-004 §Design Process and Planning sets how each design activity is planned - the stages and controls, reviews, verification and validation, responsibilities, resources, interfaces and documented information considered. Coverage Partial - documented in rev 1; residual is completed design plans from live engagements.
ISO9001-2015-8.3.3-018.3.3The organization shall determine the requirements essential for the specific types of products and services to be designed and developed.ApplicableFull
  • OPS-PRO-004 §Design InputsOPS-PRO-004 §Design Inputs requires the requirements essential for each solution to be determined. Coverage Partial - documented in rev 1; residual is the input records accruing from designed engagements.
ISO9001-2015-8.3.3-028.3.3The organization shall consider: a) functional and performance requirements; b) information derived from previous similar design and development activities; c) statutory and regulatory requirements; d) standards or codes of practice that the organization has committed to implement; e) potential consequences of failure due to the nature of the products and services.ApplicableFull
  • OPS-PRO-004 §Design InputsOPS-PRO-004 §Design Inputs requires functional/performance requirements, prior-solution lessons, statutory and regulatory requirements, codes of practice and consequences of failure to be considered as design inputs. Coverage Partial - documented in rev 1; residual is the input records accruing from designed engagements.
ISO9001-2015-8.3.3-038.3.3Inputs shall be adequate for design and development purposes, complete and unambiguous.ApplicableFull
  • OPS-PRO-004 §Design InputsOPS-PRO-004 §Design Inputs requires inputs to be adequate, complete and unambiguous before design proceeds. Coverage Partial - documented in rev 1; residual is the input records accruing from designed engagements.
ISO9001-2015-8.3.3-048.3.3Conflicting design and development inputs shall be resolved.ApplicableFull
  • OPS-PRO-004 §Design InputsOPS-PRO-004 §Design Inputs requires conflicting design inputs to be resolved and the resolution recorded before design is progressed. Coverage Partial - documented in rev 1; residual is the conflict-resolution records from live engagements.
ISO9001-2015-8.3.3-058.3.3The organization shall retain documented information on design and development inputs.ApplicableFull
  • OPS-PRO-004 §Design InputsOPS-PRO-004 §Design Inputs requires documented information on design inputs to be retained. Coverage Partial - documented in rev 1; residual is the retained input records from designed engagements.
ISO9001-2015-8.3.4-018.3.4The organization shall apply controls to the design and development process to ensure that: a) the results to be achieved are defined; b) reviews are conducted to evaluate the ability of the results of design and development to meet requirements; c) verification activities are conducted to ensure that the design and development outputs meet the input requirements; d) validation activities are conducted to ensure that the resulting products and services meet the requirements for the specified application or intended use; e) any necessary actions are taken on problems determined during the reviews, or verification and validation activities; f) documented information of these activities is retained.ApplicableFull
  • OPS-PRO-004 §Design Controls — Review, Verification and ValidationOPS-PRO-004 §Design Controls applies controls to define the results, conduct design reviews, verification and validation, and act on problems, and bars release until they are complete. Coverage Partial - documented in rev 1; residual is the review, verification and validation records from live engagements.
ISO9001-2015-8.3.5-018.3.5The organization shall ensure that design and development outputs: a) meet the input requirements; b) are adequate for the subsequent processes for the provision of products and services; c) include or reference monitoring and measuring requirements, as appropriate, and acceptance criteria; d) specify the characteristics of the products and services that are essential for their intended purpose and their safe and proper provision.ApplicableFull
  • OPS-PRO-004 §Design OutputsOPS-PRO-004 §Design Outputs requires outputs to meet inputs, be adequate for provision, reference monitoring and acceptance criteria, and specify essential characteristics. Coverage Partial - documented in rev 1; residual is the design output documents from live engagements.
ISO9001-2015-8.3.5-028.3.5The organization shall retain documented information on design and development outputs.ApplicableFull
  • OPS-PRO-004 §Design OutputsOPS-PRO-004 §Design Outputs requires documented information on design outputs to be retained. Coverage Partial - documented in rev 1; residual is the retained output records from designed engagements.
ISO9001-2015-8.3.6-018.3.6The organization shall identify, review and control changes made during, or subsequent to, the design and development of products and services, to the extent necessary to ensure that there is no adverse impact on conformity to requirements.ApplicableFull
  • OPS-PRO-004 §Design and Development ChangesOPS-PRO-004 §Design and Development Changes requires changes during or after design to be identified, reviewed, authorised and controlled to prevent adverse impact on conformity. Coverage Partial - documented in rev 1; residual is the change records from live engagements.
ISO9001-2015-8.3.6-028.3.6The organization shall retain documented information on: a) design and development changes; b) the results of reviews; c) the authorization of the changes; d) the actions taken to prevent adverse impacts.ApplicableFull
  • OPS-PRO-004 §Design and Development ChangesOPS-PRO-004 §Design and Development Changes requires documented information on changes, reviews, authorisations and actions to be retained. Coverage Partial - documented in rev 1; residual is the retained change records from live engagements.
ISO9001-2015-8.4.1-018.4.1The organization shall ensure that externally provided processes, products and services conform to requirements.ApplicableFull
ISO9001-2015-8.4.1-028.4.1The organization shall determine the controls to be applied to externally provided processes, products and services when: a) products and services from external providers are intended for incorporation into the organization’s own products and services; b) products and services are provided directly to the customer(s) by external providers on behalf of the organization; c) a process, or part of a process, is provided by an external provider as a result of a decision by the organization.ApplicablePartial
  • GOV-POL-013Modern Slavery Policy — supplier vetting.
  • QHSE-MAN-001Supplier control section.
  • QHSE-PRO-002 §6.1QHSE-PRO-002 §6.1 critical-supplier criteria determine the level of control applied to each engagement.
  • GOV-PRO-003Supplier Prequalification — Major: prequalification questionnaire + QHSE/technical/financial capability assessment determine the controls applied to each major external provider.
  • GOV-PRO-005Supplier Prequalification — Minor: proportionate lower-tier controls (basic due diligence + QHSE minimum check) evidence the risk-based determination of control level.
Medium
Control determination for external providers is documented in the live GOV-PRO-003/005 prequalification processes (Major/Minor control tiers) and QHSE-PRO-002 §6.1. Residual: the comprehensive QHSE-PRO-002 Supplier & Subcontractor Management Procedure (deeper monitoring/re-evaluation) is pending CEO approval.
ISO9001-2015-8.4.1-038.4.1The organization shall determine and apply criteria for the evaluation, selection, monitoring of performance, and re-evaluation of external providers, based on their ability to provide processes or products and services in accordance with requirements.ApplicableFull
ISO9001-2015-8.4.1-048.4.1The organization shall retain documented information of these activities and any necessary actions arising from the evaluations.ApplicableFull
  • GOV-POL-013Modern Slavery Policy — supplier vetting.
  • QHSE-MAN-001Supplier control section.
  • QHSE-PRO-002 §6.5, 6.7QHSE-PRO-002 §6.5 records the supplier and on-boarding decision; §6.7 retains performance review records.
ISO9001-2015-8.4.2-018.4.2The organization shall ensure that externally provided processes, products and services do not adversely affect the organization’s ability to consistently deliver conforming products and services to its customers.ApplicableFull
  • GOV-POL-013Modern Slavery Policy — supplier vetting.
  • QHSE-MAN-001Supplier control section.
  • QHSE-PRO-002 §6.2, 6.5QHSE-PRO-002 §6.2.3 acceptance criteria and §6.5 on-boarding controls ensure externally provided processes do not adversely affect Westlink delivery.
  • GOV-PRO-003Supplier Prequalification — Major: QHSE Capability Assessment, Technical Capability Review and Financial Standing Check before approval ensure external providers do not adversely affect Westlink's delivery of conforming services.
ISO9001-2015-8.4.2-028.4.2The organization shall: a) ensure that externally provided processes remain within the control of its quality management system; b) define both the controls that it intends to apply to an external provider and those it intends to apply to the resulting output; c) take into consideration: 1) the potential impact of the externally provided processes, products and services on the organization’s ability to consistently meet customer and applicable statutory and regulatory requirements; 2) the effectiveness of the controls applied by the external provider; d) determine the verification, or other activities, necessary to ensure that the externally provided processes, products and services meet requirements.ApplicablePartial
  • GOV-POL-013Modern Slavery Policy — supplier vetting.
  • QHSE-MAN-001Supplier control section.
  • QHSE-PRO-002 §6.5QHSE-PRO-002 §6.5 documents the type and extent of control applied to outsourced processes and the controls applied to external providers.
  • GOV-PRO-003Supplier Prequalification — Major: Assessment Report + approval gate define the controls applied to the provider and the output; the Scheduled Periodic Review determines ongoing verification activity.
Medium
Definition of controls over providers/outputs and verification activity is documented in the live GOV-PRO-003 (Assessment Report, approval gate, Scheduled Periodic Review) and QHSE-PRO-002 §6.5. Residual: comprehensive QHSE-PRO-002 procedure pending CEO approval.
ISO9001-2015-8.4.3-018.4.3The organization shall ensure the adequacy of requirements prior to their communication to the external provider.ApplicablePartial
  • QHSE-PRO-002 §6.5, 6.7QHSE-PRO-002 §6.5 (purchase orders and framework agreements) and §6.7 ensure requirements are adequate before communication to external providers.
High
Supplier/subcontractor management procedure gap — criteria, evaluation, re-evaluation, monitoring. Flagged in JOSCAR gap analysis (Q58, Q61, Q64).
ISO9001-2015-8.4.3-028.4.3The organization shall communicate to external providers its requirements for: a) the processes, products and services to be provided; b) the approval of: 1) products and services; 2) methods, processes and equipment; 3) the release of products and services; c) competence, including any required qualification of persons; d) the external providers’ interactions with the organization; e) control and monitoring of the external providers’ performance to be applied by the organization; f) verification or validation activities that the organization, or its customer, intends to perform at the external providers’ premises.ApplicablePartial
  • GOV-POL-013Modern Slavery Policy — supplier vetting.
  • QHSE-PRO-002 §6.7, 6.9QHSE-PRO-002 §6.7 communicates performance requirements to external providers; §6.9 communicates Code of Conduct expectations.
High
Supplier/subcontractor management procedure gap — criteria, evaluation, re-evaluation, monitoring. Flagged in JOSCAR gap analysis (Q58, Q61, Q64).
ISO9001-2015-8.5.1-018.5.1The organization shall implement production and service provision under controlled conditions.ApplicableFull
  • QHSE-MAN-001 §8.1Manual §8.1 (operational planning and control), §8.5 (WHS operational controls), §8.6 (environmental operational controls) collectively implement service provision under controlled conditions for logistics context.
ISO9001-2015-8.5.1-028.5.1Controlled conditions shall include, as applicable: a) the availability of documented information that defines: 1) the characteristics of the products to be produced, the services to be provided, or the activities to be performed; 2) the results to be achieved; b) the availability and use of suitable monitoring and measuring resources; c) the implementation of monitoring and measurement activities at appropriate stages to verify that criteria for control of processes or outputs, and acceptance criteria for products and services, have been met; d) the use of suitable infrastructure and environment for the operation of processes; e) the appointment of competent persons, including any required qualification; f) the validation, and periodic revalidation, of the ability to achieve planned results of the processes for production and service provision, where the resulting output cannot be verified by subsequent monitoring or measurement; g) the implementation of actions to prevent human error; h) the implementation of release, delivery and post-delivery activities.ApplicablePartial
  • QHSE-MAN-001 §8.5Manual §8.5/§8.6 cover SWMS, JHA, permits, PPE, competence; ISO 8.5.1 a)–h) (e.g., characteristics documented, validation of processes where output cannot be verified, prevention of human error, release/delivery/post-delivery) not all explicit for logistics service delivery.
High
Service delivery procedure — controlled conditions, resources, monitoring, competent personnel, infrastructure. Logistics operations procedure gap.
ISO9001-2015-8.5.2-018.5.2The organization shall use suitable means to identify outputs when it is necessary to ensure the conformity of products and services.ApplicableFull
  • QHSE-TPL-014 §§13PQMP §13 — client files marked with order number; documents/reports created on behalf of the client carry the Project Document Number.
  • GOV-PRO-001Business Process Overview establishes the unique Westlink Project Number at project establishment.
ISO9001-2015-8.5.2-028.5.2The organization shall identify the status of outputs with respect to monitoring and measurement requirements throughout production and service provision.ApplicablePartial
  • QHSE-TPL-014 §§11.2PQMP §11.2 — products inspected on receipt and prior to final acceptance to verify conformity; §13 records maintained to report output.
Medium
Monitoring/measurement status of outputs documented at project level via QHSE-TPL-014 PQMP §11.2 (inspection on receipt / prior to acceptance). Residual: not described at Manual level — inspection-on-receipt, in-transit condition checks and delivery verification markers not yet in QHSE-MAN-001.
ISO9001-2015-8.5.2-038.5.2The organization shall control the unique identification of the outputs when traceability is a requirement, and shall retain the documented information necessary to enable traceability.ApplicablePartial
  • QHSE-TPL-014 §§13PQMP §13 — project team establishes the level and method of traceability, maintained and controlled to satisfy contract/client requirements; records retained to enable reporting on service outputs.
Medium
Unique identification where traceability is required, and retention of documented information, documented at project level via QHSE-TPL-014 PQMP §13. Residual: QHSE-MAN-001 does not yet cross-reference; Defence freight / DG / consignment traceability remains client-contract-driven at project level.
ISO9001-2015-8.5.3-018.5.3The organization shall exercise care with property belonging to customers or external providers while it is under the organization’s control or being used by the organization.ApplicablePartial
  • QHSE-TPL-014 §§13.1PQMP §13.1 — Westlink exercises the highest care over client physical and intellectual property while under its control; terms clarified in Standard Trading Conditions.
Medium
Care of customer property documented at project level via QHSE-TPL-014 PQMP §13.1. Residual: the system Manual (QHSE-MAN-001) does not yet describe customer-property care — should cross-reference the PQMP given custody/transport of customer cargo is core 3PL business.
ISO9001-2015-8.5.3-028.5.3The organization shall identify, verify, protect and safeguard customers’ or external providers’ property provided for use or incorporation into the products and services.ApplicablePartial
  • QHSE-TPL-014 §§13.1PQMP §13.1 — customer-supplied product inspected on receipt for transit damage, identification and quantity, and documentation; satisfactory product properly identified, stored and cared for to prevent unauthorised use, loss or deterioration.
Medium
Identify/verify/protect/safeguard of customer property documented at project level via QHSE-TPL-014 PQMP §13.1. Residual: not yet reflected in QHSE-MAN-001 or the policy suite at system level.
ISO9001-2015-8.5.3-038.5.3When the property of a customer or external provider is lost, damaged or otherwise found to be unsuitable for use, the organization shall report this to the customer or external provider and retain documented information on what has occurred.ApplicablePartial
  • QHSE-TPL-014 §§13.1PQMP §13.1 — when client-supplied product is found damaged or unsuitable for use, details are recorded and referred to the client for advice.
Medium
Reporting of lost/damaged/unsuitable customer property and retention of documented information is described in QHSE-TPL-014 PQMP §13.1. Residual: operational practice not yet governed at QHSE-MAN-001 / system level.
ISO9001-2015-8.5.4-018.5.4The organization shall preserve the outputs during production and service provision, to the extent necessary to ensure conformity to requirements.ApplicablePartial
  • QHSE-TPL-014 §§13.2PQMP §13.2 — Westlink preserves conformity of materials, components and product while under its control, covering identification, handling, packaging, storage, transmission/transportation and protection.
Medium
Preservation of outputs documented at project level via QHSE-TPL-014 PQMP §13.2 (handling, packaging, storage, transport, protection). Residual: not yet described at QHSE-MAN-001 level for warehousing / rigging / marine and road transport damage prevention.
ISO9001-2015-8.5.5-018.5.5The organization shall meet requirements for post-delivery activities associated with the products and services.ApplicableGapMedium
Manual silent on meeting post-delivery requirements (warranty, contractual obligations, maintenance, disposal). Less acute for a service company than a manufacturer but defence and heavy-haulage contracts often impose post-delivery obligations.
ISO9001-2015-8.5.5-028.5.5In determining the extent of post-delivery activities that are required, the organization shall consider: a) statutory and regulatory requirements; b) the potential undesired consequences associated with its products and services; c) the nature, use and intended lifetime of its products and services; d) customer requirements; e) customer feedback.ApplicableGapMedium
Manual silent on determining extent of post-delivery activities (statutory/regulatory, consequences, nature/use/intended lifetime, customer requirements, customer feedback).
ISO9001-2015-8.5.6-018.5.6The organization shall review and control changes for production or service provision, to the extent necessary to ensure continuing conformity with requirements.ApplicablePartialLow
ISO9001-2015-8.5.6-028.5.6The organization shall retain documented information describing the results of the review of changes, the person(s) authorizing the change, and any necessary actions arising from the review.ApplicablePartialLow
ISO9001-2015-8.6-018.6The organization shall implement planned arrangements, at appropriate stages, to verify that the product and service requirements have been met.ApplicableFull
  • QHSE-TPL-014 §§11.2, §16PQMP §11.2 — products inspected on receipt and prior to final acceptance; §10 sets acceptance criteria, inspection requirements and monitoring activities; §16 covers monitoring/measurement.
  • GOV-PRO-001Business Process Overview includes a Project Closeout (HSEQ, Technical and Commercial) verification gate before end of process.
ISO9001-2015-8.6-028.6The release of products and services to the customer shall not proceed until the planned arrangements have been satisfactorily completed, unless otherwise approved by a relevant authority and, as applicable, by the customer.ApplicablePartial
  • QHSE-TPL-014 §§2.1, §11.2PQMP §11.2 — release on final acceptance against specified requirements; §2.1 — no deviations without the written authority of the Project Manager and Project Quality Manager.
  • GOV-PRO-001Project Closeout gate precedes end of process; customer acceptance captured before closeout.
Medium
Authority-based release partly documented via QHSE-TPL-014 PQMP §2.1/§11.2 (PM/PQM authority; acceptance before release). Residual: an explicit 'release shall not proceed until planned arrangements complete' control is not defined at QHSE-MAN-001 level.
ISO9001-2015-8.6-038.6The organization shall retain documented information on the release of products and services.ApplicablePartial
  • QHSE-TPL-014 §§12.1, §13PQMP §13 — records maintained to enable accurate reporting on service outputs; §12.1 references the Inspection Release Certificate on receipt/acceptance of materials.
Medium
Retention of release documentation partly covered via QHSE-TPL-014 PQMP §12.1/§13. Residual: PoD and handover records exist operationally but are not yet governed by Manual-level (QHSE-MAN-001) control specific to release of services.
ISO9001-2015-8.6-048.6The documented information shall include: a) evidence of conformity with the acceptance criteria; b) traceability to the person(s) authorizing the release.ApplicablePartial
  • QHSE-TPL-014 §§2.1, §11.2PQMP §11.2 — acceptance against specified requirements provides conformity evidence; §2.1 — release deviations require written PM/PQM authority (traceability to authoriser).
Medium
Release records (conformity evidence + traceability to the authorising person) partly covered via QHSE-TPL-014 PQMP §2.1/§11.2. Residual: a structured release record explicitly capturing conformity-with-acceptance-criteria and the releasing person is not yet mandated at QHSE-MAN-001 level — remains a residual audit-finding risk until formalised.
ISO9001-2015-8.7.1-018.7.18.7.1 The organization shall ensure that outputs that do not conform to their requirements are identified and controlled to prevent their unintended use or delivery.ApplicableFull
  • QHSE-PRO-001Hazard/Incident procedure (safety-focused); covers nonconformity reporting in part.
  • QHSE-MAN-001
  • QHSE-PRO-009Quality Non-Conformance and Corrective Action procedure — non-conforming items identified, segregated and quarantined as not fit for use, no further work until disposition (control of nonconforming outputs).
ISO9001-2015-8.7.1-028.7.1The organization shall take appropriate action based on the nature of the nonconformity and its effect on the conformity of products and services.ApplicableFull
  • QHSE-PRO-001Hazard/Incident procedure (safety-focused); covers nonconformity reporting in part.
  • QHSE-MAN-001
  • QHSE-PRO-009Disposition determined by the nature of the non-conformity and its effect on the conformity of products and services; rework cost assessed.
ISO9001-2015-8.7.1-038.7.1This shall also apply to nonconforming products and services detected after delivery of products, during or after the provision of services.ApplicableFull
  • QHSE-PRO-001Hazard/Incident procedure (safety-focused); covers nonconformity reporting in part.
  • QHSE-MAN-001
  • QHSE-PRO-009Scope expressly applies to non-conformances detected after delivery of a product or during or after provision of a service.
ISO9001-2015-8.7.1-048.7.1The organization shall deal with nonconforming outputs in one or more of the following ways: a) correction; b) segregation, containment, return or suspension of provision of products and services; c) informing the customer; d) obtaining authorization for acceptance under concession.ApplicableFull
  • QHSE-PRO-001Hazard/Incident procedure (safety-focused); covers nonconformity reporting in part.
  • QHSE-MAN-001
  • QHSE-PRO-009Non-conforming outputs dealt with by correction (rectification), segregation/quarantine/suspension of work, and Responsible Manager review and approval of the disposition (authorisation).
ISO9001-2015-8.7.1-058.7.1Conformity to the requirements shall be verified when nonconforming outputs are corrected.ApplicableFull
  • QHSE-PRO-001Hazard/Incident procedure (safety-focused); covers nonconformity reporting in part.
  • QHSE-MAN-001
  • QHSE-PRO-009Closeout verifies conformity by re-inspection and confirmation of final conformance when non-conforming outputs are corrected.
ISO9001-2015-8.7.2-018.7.28.7.2 The organization shall retain documented information that: a) describes the nonconformity; b) describes the actions taken; c) describes any concessions obtained; d) identifies the authority deciding the action in respect of the nonconformity.ApplicableFull
  • QHSE-PRO-001
  • QHSE-MAN-001
  • QHSE-PRO-009Records — the NCR register (isCompliant) retains the description of the non-conformance, actions taken, any concession obtained and the deciding authority.
ISO9001-2015-9.1.1-019.1.1The organization shall determine: a) what needs to be monitored and measured; b) the methods for monitoring, measurement, analysis and evaluation needed to ensure valid results; c) when the monitoring and measuring shall be performed; d) when the results from monitoring and measurement shall be analysed and evaluated.ApplicableFull
  • QHSE-MAN-001 §9.1Manual §9.1 restates ISO intent ('determines what needs to be monitored and measured, methods, timing, analysis timing') but the specific determinations are in the management system platform and QHSE-PRO procedures rather than the Manual itself.
  • GOV-POL-010 §Policy CommitmentsInclusion metrics and reporting commitment — cl.9.1.1 monitoring, measurement, analysis and evaluation general.
ISO9001-2015-9.1.1-029.1.1The organization shall evaluate the performance and the effectiveness of the quality management system.ApplicableFull
  • QHSE-MAN-001 §9.4Manual §9.4 Management Review explicitly assesses continuing suitability, adequacy, and effectiveness of the WMS — ISO 9.1.1 evaluation is delivered through the management review process.
ISO9001-2015-9.1.1-039.1.1The organization shall retain appropriate documented information as evidence of the results.ApplicableFull
  • QHSE-MAN-001 §9.4Manual §9.4: 'Management review records are retained in the management system platform.' Documented information retained.
ISO9001-2015-9.1.2-019.1.2The organization shall monitor customers’ perceptions of the degree to which their needs and expectations have been fulfilled.ApplicableFull
  • QHSE-MAN-001 §9.2Manual §9.2: Westlink monitors client satisfaction through project meetings, verbal feedback, formal feedback records, and post-project reviews.
ISO9001-2015-9.1.2-029.1.2The organization shall determine the methods for obtaining, monitoring and reviewing this information.ApplicableFull
  • QHSE-MAN-001 §9.2Manual §9.2 describes methods (project meetings, verbal feedback, formal feedback records, post-project reviews) and trend analysis at management review.
ISO9001-2015-9.1.3-019.1.3The organization shall analyse and evaluate appropriate data and information arising from monitoring and measurement.ApplicablePartial
  • QHSE-MAN-001 §9.4Manual §9.4.1 Management Review Inputs include WMS performance data, nonconformities, audit results — analysis occurs but Manual does not describe analysis methodology.
Medium
Analysis and evaluation of data — trending, decision-making inputs.
ISO9001-2015-9.1.3-029.1.3The results of analysis shall be used to evaluate: a) conformity of products and services; b) the degree of customer satisfaction; c) the performance and effectiveness of the quality management system; d) if planning has been implemented effectively; e) the effectiveness of actions taken to address risks and opportunities; f) the performance of external providers; g) the need for improvements to the quality management system.ApplicablePartial
  • QHSE-MAN-001 §9.4Manual §9.4.1 inputs cover most of ISO 9.1.3 a)–g) (conformity, satisfaction, QMS performance, action effectiveness, supplier performance, improvement needs) but not individually enumerated against ISO headings.
Medium
Analysis and evaluation of data — trending, decision-making inputs.
ISO9001-2015-9.2.1-019.2.19.2.1 The organization shall conduct internal audits at planned intervals to provide information on whether the quality management system: a) conforms to: 1) the organization’s own requirements for its quality management system; 2) the requirements of this International Standard; b) is effectively implemented and maintained.ApplicableFull
  • QHSE-MAN-001 §9.3Manual §9.3: Westlink conducts internal audits at planned intervals to verify conformity to ISO 9001/45001/14001 and WMS requirements; audit programme considers process importance, changes, prior results.
ISO9001-2015-9.2.2-019.2.29.2.2 The organization shall: a) plan, establish, implement and maintain an audit programme(s) including the frequency, methods, responsibilities, planning requirements and reporting, which shall take into consideration the importance of the processes concerned, changes affecting the organization, and the results of previous audits; b) define the audit criteria and scope for each audit; c) select auditors and conduct audits to ensure objectivity and the impartiality of the audit process; d) ensure that the results of the audits are reported to relevant management; e) take appropriate correction and corrective actions without undue delay; f) retain documented information as evidence of the implementation of the audit programme and the audit results.ApplicableFull
  • QHSE-MAN-001 §9.3Manual §9.3 covers audit frequency (at least annually per process + trigger-based), auditor competence and independence, findings classified (NCR/observation/OFI) and tracked through corrective action.
ISO9001-2015-9.3.1-019.3.1Top management shall review the organization’s quality management system, at planned intervals, to ensure its continuing suitability, adequacy, effectiveness and alignment with the strategic direction of the organization.ApplicableFull
  • QHSE-MAN-001 §9.4Manual §9.4: 'CEO chairs an annual management review to assess the continuing suitability, adequacy, and effectiveness of the WMS.'
  • GOV-POL-001 §ReviewAnnual review in management review cycle — cl.9.3.1 management review general.
  • GOV-POL-013 §ReviewAnnual review with risk assessment outcomes — cl.9.3.1 management review with modern-slavery risk inputs.
  • GOV-POL-009 §ReviewAnnual EEO review in management review cycle — cl.9.3.1.
  • GOV-POL-010 §ReviewAnnual I&D review in management review cycle — cl.9.3.1.
  • GOV-POL-012 §ReviewPolicy §Review — annual review with bribery and corruption risk assessment in the management review cycle — cl.9.3.1.
  • GOV-POL-019 §ReviewPolicy §Review — annual review in the management review cycle — cl.9.3.1.
  • GOV-POL-018 §ReviewAnnual review
  • GOV-POL-015 §ReviewPrivacy Policy — commits to Annual review.
  • GOV-POL-016 §ReviewSocial Media Usage Policy — commits to Annual review.
ISO9001-2015-9.3.2-019.3.2The management review shall be planned and carried out taking into consideration: a) the status of actions from previous management reviews; b) changes in external and internal issues that are relevant to the quality management system; c) information on the performance and effectiveness of the quality management system, including trends in: 1) customer satisfaction and feedback from relevant interested parties; 2) the extent to which quality objectives have been met; 3) process performance and conformity of products and services; 4) nonconformities and corrective actions; 5) monitoring and measurement results; 6) audit results; 7) the performance of external providers; d) the adequacy of resources; e) the effectiveness of actions taken to address risks and opportunities (see 6.1 ); f) opportunities for improvement.ApplicableFull
  • QHSE-MAN-001 §9.4.1Manual §9.4.1 enumerates Management Review Inputs: prior actions, external/internal issue changes, performance data, client satisfaction, resource adequacy, risk/opportunity effectiveness, improvement opportunities.
ISO9001-2015-9.3.3-019.3.3The outputs of the management review shall include decisions and actions related to: a) opportunities for improvement; b) any need for changes to the quality management system; c) resource needs.ApplicableFull
  • QHSE-MAN-001 §9.4.2Manual §9.4.2 enumerates outputs: continual improvement decisions, WMS changes, resource requirements, updated objectives/targets.
ISO9001-2015-9.3.3-029.3.3The organization shall retain documented information as evidence of the results of management reviews.ApplicableFull
  • QHSE-MAN-001 §9.4Manual §9.4: 'Management review records are retained in the management system platform.'
ISO9001-2015-10.1-0110.1The organization shall determine and select opportunities for improvement and implement any necessary actions to meet customer requirements and enhance customer satisfaction.ApplicableFull
  • QHSE-MAN-001 §10.3Manual §10.3 Continual Improvement identifies and selects improvement opportunities via performance analysis, audit findings, lessons learned, worker consultation, benchmarking, technology adoption.
ISO9001-2015-10.1-0210.1These shall include: a) improving products and services to meet requirements as well as to address future needs and expectations; b) correcting, preventing or reducing undesired effects; c) improving the performance and effectiveness of the quality management system.ApplicablePartial
  • QHSE-MAN-001 §10.3Manual §10.3 covers WMS effectiveness improvement; ISO 10.1 a)–c) (improve products/services to meet and anticipate needs; correct/prevent/reduce undesired effects; improve QMS performance) not individually enumerated.
Low
ISO9001-2015-10.2.1-0110.2.110.2.1 When a nonconformity occurs, including any arising from complaints, the organization shall: a) react to the nonconformity and, as applicable: 1) take action to control and correct it; 2) deal with the consequences; b) evaluate the need for action to eliminate the cause(s) of the nonconformity, in order that it does not recur or occur elsewhere, by: 1) reviewing and analysing the nonconformity; 2) determining the causes of the nonconformity; 3) determining if similar nonconformities exist, or could potentially occur; c) implement any action needed; d) review the effectiveness of any corrective action taken; e) update risks and opportunities determined during planning, if necessary; f) make changes to the quality management system, if necessary.ApplicableFull
  • QHSE-PRO-001Hazard/Incident covers corrective action for safety.
  • QHSE-MAN-001
  • GOV-POL-011 §Policy CommitmentsCorrective action for systemic grievance issues — cl.10.2.1 nonconformity and corrective action (QMS side).
  • GOV-POL-018 §Policy CommitmentsCommitment — investigation with procedural fairness
  • QHSE-PRO-009Reacts and corrects, evaluates need for action to eliminate causes, determines root cause (Root Cause Analysis framework), implements corrective action, and reviews effectiveness at monitoring/closeout.
  • HR-PRO-003 §Possible outcomesSystemic grievances managed as corrective action (new policies, training, monitoring) to prevent recurrence.
ISO9001-2015-10.2.1-0210.2.1Corrective actions shall be appropriate to the effects of the nonconformities encountered.ApplicableFull
  • QHSE-PRO-001Hazard/Incident covers corrective action for safety.
  • QHSE-MAN-001
  • QHSE-PRO-009Root Cause Analysis framework — corrective actions proportionate and appropriate to the effects of the non-conformances; systemic action for recurring root causes.
ISO9001-2015-10.2.2-0110.2.210.2.2 The organization shall retain documented information as evidence of: a) the nature of the nonconformities and any subsequent actions taken; b) the results of any corrective action.ApplicableFull
ISO9001-2015-10.3-0110.3The organization shall continually improve the suitability, adequacy and effectiveness of the quality management system.ApplicableFull
  • QHSE-MAN-001 §10.3Manual §10.3: 'Westlink continually improves the suitability, adequacy, and effectiveness of the WMS.'
ISO9001-2015-10.3-0210.3The organization shall consider the results of analysis and evaluation, and the outputs from management review, to determine if there are needs or opportunities that shall be addressed as part of continual improvement.ApplicablePartial
  • QHSE-MAN-001 §10.3Manual §10.3 lists improvement inputs but does not explicitly state that analysis results and management review outputs are considered to determine need/opportunity for action.
Low
Source document

ISO 9001:2015 — Quality management systems — Requirements

123 normative shall-statements extracted from ISO 9001:2015 (source: new files/ISO_9001_2015(en).epub). The frontmatter requirements array is the source of truth — this body is rendered by scripts/render_compliance.py.

Coverage summary

CoverageCount
✅ Full72
🟡 Partial45
🟠 Ref-only0
🔴 Gap6
— N/A0

Gap severity distribution

SeverityCount
🔴 Critical0
🟠 High6
🟡 Medium29
🟢 Low15

Requirements

Clause 4 — Context of the organization

IDCoverageEvidenceGapNotes
ISO9001-2015-4.1-01✅ FullQHSE-MAN-001 §‘4.1’
[GOV-POL-001 §Organisational Context](/wms/GOV-POL-001#sOrganisational Context)
[GOV-POL-013 §Organisational Context](/wms/GOV-POL-013#sOrganisational Context)
[GOV-POL-009 §Organisational Context](/wms/GOV-POL-009#sOrganisational Context)
[GOV-POL-010 §Organisational Context](/wms/GOV-POL-010#sOrganisational Context)
[GOV-POL-012 §Organisational Context](/wms/GOV-POL-012#sOrganisational Context)
[GOV-POL-019 §Organisational Context](/wms/GOV-POL-019#sOrganisational Context)
[GOV-POL-018 §Organisational Context](/wms/GOV-POL-018#sOrganisational Context)
ISO9001-2015-4.1-02✅ FullQHSE-MAN-001 §‘4.1’
ISO9001-2015-4.2-01✅ FullQHSE-MAN-001
GOV-POL-013
[GOV-POL-001 §Organisational Context](/wms/GOV-POL-001#sOrganisational Context)
[GOV-POL-009 §Organisational Context](/wms/GOV-POL-009#sOrganisational Context)
[GOV-POL-010 §Organisational Context](/wms/GOV-POL-010#sOrganisational Context)
[GOV-POL-012 §Organisational Context](/wms/GOV-POL-012#sOrganisational Context)
[GOV-POL-019 §Organisational Context](/wms/GOV-POL-019#sOrganisational Context)
[GOV-POL-018 §Organisational Context](/wms/GOV-POL-018#sOrganisational Context)
[GOV-POL-015 §Organisational Context](/wms/GOV-POL-015#sOrganisational Context)
ISO9001-2015-4.2-02🟡 PartialQHSE-MAN-001
GOV-POL-013
[GOV-POL-012 §Organisational Context](/wms/GOV-POL-012#sOrganisational Context)
🟡 MediumConfirm interested-parties register is maintained and reviewed.
ISO9001-2015-4.3-01✅ FullQHSE-MAN-001 §Scope
ISO9001-2015-4.3-02✅ FullQHSE-MAN-001 §Scope
ISO9001-2015-4.3-03✅ FullQHSE-MAN-001 §Scope
ISO9001-2015-4.3-04✅ FullQHSE-MAN-001 §Scope
ISO9001-2015-4.3-05✅ FullQHSE-MAN-001 §Scope
ISO9001-2015-4.4.1-01🟡 PartialQHSE-MAN-001 §‘3.3’🟡 MediumVerify process map documenting inputs, outputs, sequence, responsibilities, and resources.
ISO9001-2015-4.4.2-01✅ FullQHSE-MAN-001 §‘7.5’

Clause 5 — Leadership

IDCoverageEvidenceGapNotes
ISO9001-2015-5.1.1-01🟡 PartialGOV-POL-001
QHSE-MAN-001
GOV-POL-013 §Responsibilities
GOV-POL-009 §Responsibilities
GOV-POL-010 §Responsibilities
GOV-POL-012 §Responsibilities
GOV-POL-019 §Responsibilities
GOV-POL-018 §Responsibilities
GOV-POL-015 §Responsibilities
GOV-POL-016 §Responsibilities
🟢 LowConfirm manual documents how top management demonstrates the seven specific commitments in cl 5.1.1 a-j.
ISO9001-2015-5.1.2-01🟡 PartialGOV-POL-001
QHSE-MAN-001
🟢 Low
ISO9001-2015-5.2.1-01✅ FullGOV-POL-001
[GOV-POL-002 §IMS Integration](/wms/GOV-POL-002#sIMS Integration)
ISO9001-2015-5.2.2-01🟡 PartialGOV-POL-001
QHSE-MAN-001
GOV-POL-016 §Review
ISO9001-2015-5.3-01✅ FullQHSE-MAN-001 §‘5.2’
GOV-POL-001 §Responsibilities
GOV-POL-013 §Responsibilities
GOV-POL-009 §Responsibilities
GOV-POL-010 §Responsibilities
GOV-POL-012 §Responsibilities
GOV-POL-019 §Responsibilities
GOV-POL-015 §Responsibilities
GOV-POL-016 §Responsibilities
ISO9001-2015-5.3-02🟡 PartialQHSE-MAN-001 §‘5.1’🟢 LowVerify manual includes role assignments for QMS conformity, process integrity, reporting to top management.

Clause 6 — Planning

IDCoverageEvidenceGapNotes
ISO9001-2015-6.1.1-01🟡 PartialQHSE-MAN-001
QHSE-PRO-001
[GOV-POL-001 §Policy Commitments](/wms/GOV-POL-001#sPolicy Commitments)
GOV-POL-021
🟠 HighQuality-specific risk assessment process may be absent. QHSE-PRO-001 is safety-focused; need either a quality risk procedure or explicit QMS risk treatment in manual.
ISO9001-2015-6.1.2-01🟡 PartialQHSE-MAN-001 §‘6.1’
GOV-POL-021
🟠 HighQuality risk register with actions to address risks/opportunities, integrated into QMS processes, evaluated for effectiveness.
ISO9001-2015-6.1.2-02🟡 PartialQHSE-MAN-001 §‘6.1’
GOV-POL-021
🟠 HighQuality risk register with actions to address risks/opportunities, integrated into QMS processes, evaluated for effectiveness.
ISO9001-2015-6.2.1-01✅ FullQHSE-MAN-001 §‘6.2’
ISO9001-2015-6.2.1-02🟡 PartialQHSE-MAN-001 §‘6.2’🟡 MediumConfirm manual contains SMART quality objectives at relevant functions/levels, consistent with quality policy, measurable, with communication and update protocols.
ISO9001-2015-6.2.1-03✅ FullQHSE-MAN-001 §‘6.2’
ISO9001-2015-6.2.2-01🟡 PartialQHSE-MAN-001 §‘6.2’🟡 Medium
ISO9001-2015-6.3-01✅ FullQHSE-MAN-001
GOV-PRO-002
ISO9001-2015-6.3-02🟡 PartialQHSE-MAN-001
GOV-PRO-002
🟡 MediumChange management for QMS itself (beyond documents) — new services, reorganisations, system changes.

Clause 7 — Support

IDCoverageEvidenceGapNotes
ISO9001-2015-7.1.1-01✅ FullQHSE-MAN-001 §‘7.1’
ISO9001-2015-7.1.1-02🟡 PartialQHSE-MAN-001 §‘7.1’🟢 Low
ISO9001-2015-7.1.2-01✅ FullQHSE-MAN-001 §‘7.1’
ISO9001-2015-7.1.3-01🟡 PartialQHSE-MAN-001 §‘7.1’🟢 LowInfrastructure management — facilities, equipment, ICT. Manual reference; verify detail.
ISO9001-2015-7.1.4-01🟡 PartialQHSE-MAN-001 §‘7.1’
[GOV-POL-010 §Organisational Context](/wms/GOV-POL-010#sOrganisational Context)
🟢 Low
ISO9001-2015-7.1.5.1-01✅ FullQHSE-MAN-001 §‘9.2’
ISO9001-2015-7.1.5.1-02✅ FullQHSE-MAN-001 §‘9.2’
ISO9001-2015-7.1.5.1-03✅ FullQHSE-MAN-001 §‘9.2’
ISO9001-2015-7.1.5.2-01🔴 Gap🟢 LowManual silent on measurement traceability. Low applicability — where Westlink relies on measurements (mass, dimension for NHVR, fuel quantity, strapping tension), these are typically taken on externally calibrated equipment. Document the approach or exclude under cl 4.3.
ISO9001-2015-7.1.5.2-02🔴 Gap🟢 LowManual silent on assessing validity of prior measurement results when equipment found unfit. See 7.1.5.2-01 rationale.
ISO9001-2015-7.1.6-01🟡 PartialQHSE-MAN-001 §‘4.1’🟢 LowOrganisational knowledge capture — lessons learned, knowledge management.
ISO9001-2015-7.1.6-02🔴 Gap🟡 MediumManual does not describe how organisational knowledge is maintained or made available. Succession planning noted as a context issue (§4.1.2) but no maintenance system. Add organisational knowledge clause to Manual or supporting procedure.
ISO9001-2015-7.1.6-03🔴 Gap🟡 MediumManual silent on considering current knowledge against changing needs and trends, and on acquiring/accessing additional knowledge.
ISO9001-2015-7.2-01✅ FullQHSE-MAN-001
[GOV-POL-001 §Policy Commitments](/wms/GOV-POL-001#sPolicy Commitments)
[GOV-POL-013 §Policy Commitments](/wms/GOV-POL-013#sPolicy Commitments)
[GOV-POL-009 §Policy Commitments](/wms/GOV-POL-009#sPolicy Commitments)
[GOV-POL-010 §Policy Commitments](/wms/GOV-POL-010#sPolicy Commitments)
[HR-GDL-003 §‘Training Needs Analysis / Competency Framework / Records’](/wms/HR-GDL-003#s’Training Needs Analysis / Competency Framework / Records’)
ISO9001-2015-7.3-01✅ FullQHSE-MAN-001
GOV-POL-016
[GOV-POL-001 §Policy Commitments](/wms/GOV-POL-001#sPolicy Commitments)
[HR-GDL-003 §‘Competency Framework / Continuous Improvement’](/wms/HR-GDL-003#s’Competency Framework / Continuous Improvement’)
ISO9001-2015-7.4-01✅ FullQHSE-MAN-001 §‘7.4’
GOV-POL-013 §Review
GOV-POL-009 §Review
GOV-POL-010 §Review
GOV-POL-019 §Review
GOV-POL-012 §Review
[GOV-POL-018 §Policy Commitments](/wms/GOV-POL-018#sPolicy Commitments)
GOV-POL-015 §Review
GOV-POL-016 §Scope
ISO9001-2015-7.5.1-01✅ FullGOV-PRO-002 §3
QHSE-MAN-001
[GOV-POL-019 §Policy Commitments](/wms/GOV-POL-019#sPolicy Commitments)
ISO9001-2015-7.5.2-01✅ FullGOV-PRO-002 §4
GOV-STD-001
ISO9001-2015-7.5.3.1-01✅ FullGOV-PRO-002 §5
GOV-STD-001
[GOV-POL-018 §Policy Commitments](/wms/GOV-POL-018#sPolicy Commitments)
ISO9001-2015-7.5.3.2-01🟡 PartialGOV-PRO-002 §5-7
GOV-SCH-001
[GOV-POL-018 §Policy Commitments](/wms/GOV-POL-018#sPolicy Commitments)
[TEC-PRO-001 §‘Records and Retention’](/wms/TEC-PRO-001#s’Records and Retention’)
[QHSE-PRO-013 §‘Records & Systems of Record / Appendix A’](/wms/QHSE-PRO-013#s’Records & Systems of Record / Appendix A’)
🟢 LowPer pilot: verify GOV-PRO-002 explicitly enumerates all four activities (a-d) and handles external-origin documents.
ISO9001-2015-7.5.3.2-02✅ FullGOV-PRO-002 §5-7
GOV-SCH-001
[TEC-PRO-001 §‘Records and Retention’](/wms/TEC-PRO-001#s’Records and Retention’)
ISO9001-2015-7.5.3.2-03🟡 PartialGOV-PRO-002 §5-7
GOV-SCH-001
🟢 LowPer pilot: verify GOV-PRO-002 explicitly enumerates all four activities (a-d) and handles external-origin documents.

Clause 8 — Operation

IDCoverageEvidenceGapNotes
ISO9001-2015-8.1-01✅ FullQHSE-MAN-001 §‘8.1’
[QHSE-PRO-013 §‘Treatment Planning / Change & Non-Conformance’](/wms/QHSE-PRO-013#s’Treatment Planning / Change & Non-Conformance’)
[OPS-MAN-002 §‘Chartering Process’](/wms/OPS-MAN-002#s’Chartering Process’)
ISO9001-2015-8.1-02🟡 PartialQHSE-MAN-001 §‘8.1’🟡 MediumOperational Planning implies output suitability through risk-proportionate controls, but the obligation is not stated explicitly.
ISO9001-2015-8.1-03✅ FullQHSE-MAN-001 §‘6.3’
ISO9001-2015-8.1-04✅ FullQHSE-MAN-001 §‘8.3’
ISO9001-2015-8.2.1-01🟡 PartialCOM-DOC-001
COM-DOC-002
[BD-GDL-002 §‘Sales Process Stages 1-3 / Marketing’](/wms/BD-GDL-002#s’Sales Process Stages 1-3 / Marketing’)
🟡 MediumCustomer communication procedure — enquiries, contracts, feedback, property handling, emergencies.
ISO9001-2015-8.2.2-01🟡 PartialCOM-DOC-001
COM-DOC-002
[BD-GDL-002 §‘Lead Qualification / Opportunity’](/wms/BD-GDL-002#s’Lead Qualification / Opportunity’)
🟡 Medium
ISO9001-2015-8.2.3.1-01🟡 PartialCOM-DOC-001
COM-DOC-002
COM-PRO-002
🟡 MediumReview of requirements for products/services — COM-PRO-002 maps the tender/execution-phase legal and insurance review (CEO GO/NO-GO); residual gap: order confirmation and change control procedure.
ISO9001-2015-8.2.3.1-02🟡 PartialCOM-DOC-001
COM-DOC-002
COM-PRO-002
[BD-GDL-002 §‘Opportunity / Close’](/wms/BD-GDL-002#s’Opportunity / Close’)
🟡 MediumReview of requirements for products/services — COM-PRO-002 maps the tender/execution-phase legal and insurance review (CEO GO/NO-GO); residual gap: order confirmation and change control procedure.
ISO9001-2015-8.2.3.1-03✅ FullCOM-DOC-001
COM-DOC-002
COM-PRO-002
ISO9001-2015-8.2.3.1-04✅ FullCOM-DOC-001
COM-DOC-002
COM-PRO-002
ISO9001-2015-8.2.3.2-01🟡 PartialCOM-DOC-001
COM-DOC-002
🟡 MediumReview of requirements for products/services — tender review, order confirmation, change control procedure gap.
ISO9001-2015-8.2.4-01🟡 PartialCOM-DOC-001
COM-DOC-002
🟡 Medium
ISO9001-2015-8.3.1-01✅ Full[OPS-PRO-004 §Design Process and Planning](/wms/OPS-PRO-004#sDesign Process and Planning)
ISO9001-2015-8.3.2-01✅ Full[OPS-PRO-004 §Design Process and Planning](/wms/OPS-PRO-004#sDesign Process and Planning)
ISO9001-2015-8.3.3-01✅ Full[OPS-PRO-004 §Design Inputs](/wms/OPS-PRO-004#sDesign Inputs)
ISO9001-2015-8.3.3-02✅ Full[OPS-PRO-004 §Design Inputs](/wms/OPS-PRO-004#sDesign Inputs)
ISO9001-2015-8.3.3-03✅ Full[OPS-PRO-004 §Design Inputs](/wms/OPS-PRO-004#sDesign Inputs)
ISO9001-2015-8.3.3-04✅ Full[OPS-PRO-004 §Design Inputs](/wms/OPS-PRO-004#sDesign Inputs)
ISO9001-2015-8.3.3-05✅ Full[OPS-PRO-004 §Design Inputs](/wms/OPS-PRO-004#sDesign Inputs)
ISO9001-2015-8.3.4-01✅ Full[OPS-PRO-004 §Design Controls — Review, Verification and Validation](/wms/OPS-PRO-004#sDesign Controls — Review, Verification and Validation)
ISO9001-2015-8.3.5-01✅ Full[OPS-PRO-004 §Design Outputs](/wms/OPS-PRO-004#sDesign Outputs)
ISO9001-2015-8.3.5-02✅ Full[OPS-PRO-004 §Design Outputs](/wms/OPS-PRO-004#sDesign Outputs)
ISO9001-2015-8.3.6-01✅ Full[OPS-PRO-004 §Design and Development Changes](/wms/OPS-PRO-004#sDesign and Development Changes)
ISO9001-2015-8.3.6-02✅ Full[OPS-PRO-004 §Design and Development Changes](/wms/OPS-PRO-004#sDesign and Development Changes)
ISO9001-2015-8.4.1-01✅ FullGOV-POL-013
QHSE-MAN-001
[GOV-POL-001 §Policy Commitments](/wms/GOV-POL-001#sPolicy Commitments)
QHSE-PRO-002 §‘6’
[QHSE-PRO-013 §‘Key Principles / Procurement’](/wms/QHSE-PRO-013#s’Key Principles / Procurement’)
[OPS-MAN-002 §‘Chartering Process (Phase 1-3)’](/wms/OPS-MAN-002#s’Chartering Process (Phase 1-3)‘)
ISO9001-2015-8.4.1-02🟡 PartialGOV-POL-013
QHSE-MAN-001
QHSE-PRO-002 §‘6.1’
GOV-PRO-003
GOV-PRO-005
🟡 MediumControl determination for external providers is documented in the live GOV-PRO-003/005 prequalification processes (Major/Minor control tiers) and QHSE-PRO-002 §6.1. Residual: the comprehensive QHSE-PRO-002 Supplier & Subcontractor Management Procedure (deeper monitoring/re-evaluation) is pending CEO approval.
ISO9001-2015-8.4.1-03✅ FullGOV-POL-013
QHSE-MAN-001
QHSE-POL-001 §Responsibilities
QHSE-PRO-002 §‘6.2’
[QHSE-GDL-001 §‘Prequalification / Compliance Monitoring’](/wms/QHSE-GDL-001#s’Prequalification / Compliance Monitoring’)
ISO9001-2015-8.4.1-04✅ FullGOV-POL-013
QHSE-MAN-001
[QHSE-PRO-002 §‘6.5, 6.7’](/wms/QHSE-PRO-002#s’6.5, 6.7’)
ISO9001-2015-8.4.2-01✅ FullGOV-POL-013
QHSE-MAN-001
[QHSE-PRO-002 §‘6.2, 6.5’](/wms/QHSE-PRO-002#s’6.2, 6.5’)
GOV-PRO-003
ISO9001-2015-8.4.2-02🟡 PartialGOV-POL-013
QHSE-MAN-001
QHSE-PRO-002 §‘6.5’
GOV-PRO-003
🟡 MediumDefinition of controls over providers/outputs and verification activity is documented in the live GOV-PRO-003 (Assessment Report, approval gate, Scheduled Periodic Review) and QHSE-PRO-002 §6.5. Residual: comprehensive QHSE-PRO-002 procedure pending CEO approval.
ISO9001-2015-8.4.3-01🟡 Partial[QHSE-PRO-002 §‘6.5, 6.7’](/wms/QHSE-PRO-002#s’6.5, 6.7’)🟠 HighSupplier/subcontractor management procedure gap — criteria, evaluation, re-evaluation, monitoring. Flagged in JOSCAR gap analysis (Q58, Q61, Q64).
ISO9001-2015-8.4.3-02🟡 PartialGOV-POL-013
[QHSE-PRO-002 §‘6.7, 6.9’](/wms/QHSE-PRO-002#s’6.7, 6.9’)
🟠 HighSupplier/subcontractor management procedure gap — criteria, evaluation, re-evaluation, monitoring. Flagged in JOSCAR gap analysis (Q58, Q61, Q64).
ISO9001-2015-8.5.1-01✅ FullQHSE-MAN-001 §‘8.1’
ISO9001-2015-8.5.1-02🟡 PartialQHSE-MAN-001 §‘8.5’🟠 HighService delivery procedure — controlled conditions, resources, monitoring, competent personnel, infrastructure. Logistics operations procedure gap.
ISO9001-2015-8.5.2-01✅ FullQHSE-TPL-014 §§13
GOV-PRO-001
ISO9001-2015-8.5.2-02🟡 PartialQHSE-TPL-014 §§11.2🟡 MediumMonitoring/measurement status of outputs documented at project level via QHSE-TPL-014 PQMP §11.2 (inspection on receipt / prior to acceptance). Residual: not described at Manual level — inspection-on-receipt, in-transit condition checks and delivery verification markers not yet in QHSE-MAN-001.
ISO9001-2015-8.5.2-03🟡 PartialQHSE-TPL-014 §§13🟡 MediumUnique identification where traceability is required, and retention of documented information, documented at project level via QHSE-TPL-014 PQMP §13. Residual: QHSE-MAN-001 does not yet cross-reference; Defence freight / DG / consignment traceability remains client-contract-driven at project level.
ISO9001-2015-8.5.3-01🟡 PartialQHSE-TPL-014 §§13.1🟡 MediumCare of customer property documented at project level via QHSE-TPL-014 PQMP §13.1. Residual: the system Manual (QHSE-MAN-001) does not yet describe customer-property care — should cross-reference the PQMP given custody/transport of customer cargo is core 3PL business.
ISO9001-2015-8.5.3-02🟡 PartialQHSE-TPL-014 §§13.1🟡 MediumIdentify/verify/protect/safeguard of customer property documented at project level via QHSE-TPL-014 PQMP §13.1. Residual: not yet reflected in QHSE-MAN-001 or the policy suite at system level.
ISO9001-2015-8.5.3-03🟡 PartialQHSE-TPL-014 §§13.1🟡 MediumReporting of lost/damaged/unsuitable customer property and retention of documented information is described in QHSE-TPL-014 PQMP §13.1. Residual: operational practice not yet governed at QHSE-MAN-001 / system level.
ISO9001-2015-8.5.4-01🟡 PartialQHSE-TPL-014 §§13.2🟡 MediumPreservation of outputs documented at project level via QHSE-TPL-014 PQMP §13.2 (handling, packaging, storage, transport, protection). Residual: not yet described at QHSE-MAN-001 level for warehousing / rigging / marine and road transport damage prevention.
ISO9001-2015-8.5.5-01🔴 Gap🟡 MediumManual silent on meeting post-delivery requirements (warranty, contractual obligations, maintenance, disposal). Less acute for a service company than a manufacturer but defence and heavy-haulage contracts often impose post-delivery obligations.
ISO9001-2015-8.5.5-02🔴 Gap🟡 MediumManual silent on determining extent of post-delivery activities (statutory/regulatory, consequences, nature/use/intended lifetime, customer requirements, customer feedback).
ISO9001-2015-8.5.6-01🟡 PartialQHSE-MAN-001🟢 Low
ISO9001-2015-8.5.6-02🟡 PartialQHSE-MAN-001🟢 Low
ISO9001-2015-8.6-01✅ Full[QHSE-TPL-014 §§11.2, §16](/wms/QHSE-TPL-014#s§11.2, §16)
GOV-PRO-001
ISO9001-2015-8.6-02🟡 Partial[QHSE-TPL-014 §§2.1, §11.2](/wms/QHSE-TPL-014#s§2.1, §11.2)
GOV-PRO-001
🟡 MediumAuthority-based release partly documented via QHSE-TPL-014 PQMP §2.1/§11.2 (PM/PQM authority; acceptance before release). Residual: an explicit ‘release shall not proceed until planned arrangements complete’ control is not defined at QHSE-MAN-001 level.
ISO9001-2015-8.6-03🟡 Partial[QHSE-TPL-014 §§12.1, §13](/wms/QHSE-TPL-014#s§12.1, §13)🟡 MediumRetention of release documentation partly covered via QHSE-TPL-014 PQMP §12.1/§13. Residual: PoD and handover records exist operationally but are not yet governed by Manual-level (QHSE-MAN-001) control specific to release of services.
ISO9001-2015-8.6-04🟡 Partial[QHSE-TPL-014 §§2.1, §11.2](/wms/QHSE-TPL-014#s§2.1, §11.2)🟡 MediumRelease records (conformity evidence + traceability to the authorising person) partly covered via QHSE-TPL-014 PQMP §2.1/§11.2. Residual: a structured release record explicitly capturing conformity-with-acceptance-criteria and the releasing person is not yet mandated at QHSE-MAN-001 level — remains a residual audit-finding risk until formalised.
ISO9001-2015-8.7.1-01✅ FullQHSE-PRO-001
QHSE-MAN-001
QHSE-PRO-009
ISO9001-2015-8.7.1-02✅ FullQHSE-PRO-001
QHSE-MAN-001
QHSE-PRO-009
ISO9001-2015-8.7.1-03✅ FullQHSE-PRO-001
QHSE-MAN-001
QHSE-PRO-009
ISO9001-2015-8.7.1-04✅ FullQHSE-PRO-001
QHSE-MAN-001
QHSE-PRO-009
ISO9001-2015-8.7.1-05✅ FullQHSE-PRO-001
QHSE-MAN-001
QHSE-PRO-009
ISO9001-2015-8.7.2-01✅ FullQHSE-PRO-001
QHSE-MAN-001
QHSE-PRO-009

Clause 9 — Performance evaluation

IDCoverageEvidenceGapNotes
ISO9001-2015-9.1.1-01✅ FullQHSE-MAN-001 §‘9.1’
[GOV-POL-010 §Policy Commitments](/wms/GOV-POL-010#sPolicy Commitments)
ISO9001-2015-9.1.1-02✅ FullQHSE-MAN-001 §‘9.4’
ISO9001-2015-9.1.1-03✅ FullQHSE-MAN-001 §‘9.4’
ISO9001-2015-9.1.2-01✅ FullQHSE-MAN-001 §‘9.2’
ISO9001-2015-9.1.2-02✅ FullQHSE-MAN-001 §‘9.2’
ISO9001-2015-9.1.3-01🟡 PartialQHSE-MAN-001 §‘9.4’🟡 MediumAnalysis and evaluation of data — trending, decision-making inputs.
ISO9001-2015-9.1.3-02🟡 PartialQHSE-MAN-001 §‘9.4’🟡 MediumAnalysis and evaluation of data — trending, decision-making inputs.
ISO9001-2015-9.2.1-01✅ FullQHSE-MAN-001 §‘9.3’
ISO9001-2015-9.2.2-01✅ FullQHSE-MAN-001 §‘9.3’
ISO9001-2015-9.3.1-01✅ FullQHSE-MAN-001 §‘9.4’
GOV-POL-001 §Review
GOV-POL-013 §Review
GOV-POL-009 §Review
GOV-POL-010 §Review
GOV-POL-012 §Review
GOV-POL-019 §Review
GOV-POL-018 §Review
GOV-POL-015 §Review
GOV-POL-016 §Review
ISO9001-2015-9.3.2-01✅ FullQHSE-MAN-001 §9.4.1
ISO9001-2015-9.3.3-01✅ FullQHSE-MAN-001 §9.4.2
ISO9001-2015-9.3.3-02✅ FullQHSE-MAN-001 §‘9.4’

Clause 10 — Improvement

IDCoverageEvidenceGapNotes
ISO9001-2015-10.1-01✅ FullQHSE-MAN-001 §‘10.3’
ISO9001-2015-10.1-02🟡 PartialQHSE-MAN-001 §‘10.3’🟢 Low
ISO9001-2015-10.2.1-01✅ FullQHSE-PRO-001
QHSE-MAN-001
[GOV-POL-011 §Policy Commitments](/wms/GOV-POL-011#sPolicy Commitments)
[GOV-POL-018 §Policy Commitments](/wms/GOV-POL-018#sPolicy Commitments)
QHSE-PRO-009
[HR-PRO-003 §‘Possible outcomes’](/wms/HR-PRO-003#s’Possible outcomes’)
ISO9001-2015-10.2.1-02✅ FullQHSE-PRO-001
QHSE-MAN-001
QHSE-PRO-009
ISO9001-2015-10.2.2-01✅ FullQHSE-PRO-001
QHSE-MAN-001
QHSE-PRO-009
ISO9001-2015-10.3-01✅ FullQHSE-MAN-001 §‘10.3’
ISO9001-2015-10.3-02🟡 PartialQHSE-MAN-001 §‘10.3’🟢 Low

Informative references

Shall-statements appearing in the Introduction and informative annexes. Captured for context; not counted as requirements.

ClauseTextRefers to
IntroductionIn this International Standard, the following verbal forms are used: — “shall” indicates a requirement; — “should” indicates a recommendation; — “may” indicates a permission; — “can” indicates a possibility or a capability.
Annex A (informative)Although 6.1 specifies that the organization shall plan actions to address risks, there is no requirement for formal methods for risk management or a documented risk management process.6.1
Annex A (informative)Where this International Standard refers to “information” rather than “documented information” (e.g. in 4.1 : “The organization shall monitor and review the information about these external and internal issues”), there is no requirement that this information is to be documented.4.1

Rendered from frontmatter by scripts/render_compliance.py. Source extraction: scripts/extract_iso9001_requirements.py. Evidence population: scripts/populate_iso9001_evidence.py. Validate: scripts/compliance_validate.py.