Skip to main content
What must be documented series - #2 – ISO14001

What must be documented series - #2 – ISO14001

| admin | Blog

This is the second in my series about minimum documentation requirements for ISO standards.  It came about as a result of a recent successful audit with one of my larger clients who passed their annual ISO9001:2015 and ISO14001:2015 Audits, lasting a total of eight days, with no nonconformances raised.

When I started with this client, one of their main ‘issues’ was that there was too much ‘paperwork’ associated with ISO.  Now there is none.  I say none, there are a few basic things that they must have in place, and these are described below.  Otherwise, all the documented information that they have, be that on hard copy or increasingly on soft copy, is required either for their customers, the environment, their workers, or as compliance requirements.  None of it is required by ISO.

Last time my focus was on ISO9001, and now I look at ISO14001.

Like ISO9001:2015, ISO14001:2015 now only refers to documented information.  There is no longer any reference to documented procedures, records, documentation or a manual.  Largely it is up to the individual organisation what they require.

Again, like ISO9001, documented information has two prefixes in ISO14001:2015.  Where is says ‘maintain’ documented information, this means that the organisation needs to have a written document in place. 

ISO14001:2015 has eight times in where this is the case.  Two of these are clear, in that the organisation must have a documented Scope of their activities (4.3); and Environmental Policy (5.2).   In addition, organisations must maintain documented information of their Environmental Objectives (6.2.1); their risks and opportunities associated with their Context (6.1.1); Environmental Aspects (6.1.2); Compliance Obligations (6.1.3); and how these are all to be managed/reduced (6.1.4).

The remaining one, being Operational planning and control (8.1), states that documented information is to be maintained ‘to the extent necessary to have confidence that processes are carried out as planned’.  In other words, it is up to the organisation how many or how few pieces of documented information are maintained to be conformant with this clause. 

Where it says ‘retain’ documented information, this means that the organisation needs to somehow, in whatever way is most suitable for them, keep some form of evidence that can be viewed.  In ISO14001:2015 retain documented information is stated ten times. 

However, in the Documented information clause itself (7.5.1), ISO14001:2015 notes that the extent of documented information can vary due to the size and complexity of organisations, the need to demonstrate fulfilment of compliance obligations and the competence of the persons involved.  In other words, it is up to organisations. Indeed if any documented information to be maintained or retained, the organisation can choose what the most suitable format is, be that a flow-chart, a picture, a table of information, a website, a certificate or whatever suits them best.

Or put another way, the organisation can choose the amount of documented information it needs to demonstrate, for example, that it has complied with a piece of environmental legislation.  An example of this could be demonstrating compliance with the Ozone Depleting Substances (Qualifications) Regulations (Northern Ireland) 2011 by verifying that the air conditioning companies used are REFCOM qualified (where the REFCOM website holding the air conditioning company registered details becomes the documented information).  

I said at the start of this post that my client above had little or no ISO documentation in place.  This is true, their focus for the environment is on reducing their environmental impact and complying with any legal or other requirements.  However, it is noticeable that in this case by focusing on reducing their environmental impact and demonstrating their environmental compliance requirements, just how many of the pieces of documented information described in ISO14001:2015 they find that they need. 

Next time I’ll look at what must be documented in ISO45001.

Trevor Patterson is a QHSE Consultant and also conducts ISO audits on behalf of one of the main Certification Bodies.