SGRII Insights · ISO 9001:2015 · 2026
Operational Planning & Control — Where Strategy Meets the Shop Floor
Clause 8.1 is the hinge between system design and system execution. Most organisations have one or the other. The ones that have both are the ones whose QMS actually runs operations.
SGRII Performance & Digital Solutions
QMS Practice · April 2026 · 9 min read
SGRII Pillar Lens
Risk
Clause 8.1 translates risk-based planning into controlled operations. It is the point where the prospective work of Clauses 4–7 becomes the executable work of Clause 8. When operational controls are absent or informal, the system produces conforming outputs by luck rather than design — and luck is not auditable.
The Bridge Clause Nobody Treats as a Bridge
Clause 8.1 requires the organisation to plan, implement, and control the processes needed to meet requirements for the provision of products and services, and to implement the actions determined in Clause 6 (planning). This is the structural bridge between everything the organisation has planned in Clauses 4–7 and everything it must execute in Clauses 8.2–8.7. Without Clause 8.1, the QMS is a set of policies and plans with no mechanism for translating them into controlled operations.
In audit, the test is direct: can the organisation demonstrate that operational processes were planned with defined criteria, that process inputs and outputs are determined, that resources were allocated, and that acceptance criteria were established before the process was executed? If the answer is “we do it the way we’ve always done it” without documented criteria, the clause is not met — regardless of whether the outputs are acceptable.
The distinction matters because Clause 8.1 is about controlled process execution, not successful outcomes. An organisation that produces conforming products through uncontrolled processes is producing conforming products by luck. The standard requires the controls — because controls are what make the outcome repeatable.
Process Criteria — The Missing Operating Parameters
Clause 8.1 requires the organisation to determine “the criteria for the processes” and “acceptance criteria for products and services.” These are distinct requirements. Process criteria define how the process should operate — temperatures, speeds, tolerances, sequences, timings, environmental conditions. Acceptance criteria define what the output must be — dimensions, performance characteristics, visual standards, test results.
In many SMEs, acceptance criteria exist (often in customer specifications or technical drawings) but process criteria do not. The process runs on tribal knowledge — an experienced operator knows the right settings, the correct sequence, the adjustment points. When that operator is absent, the process produces variable results. When questioned at audit, the organisation can show what the product should look like but not how the process should run. This is a conformance gap with both audit and operational consequences.
The SGRII framework treats process criteria as a first-class operational requirement. Each core procedure includes not just the procedural steps but the critical parameters that define controlled operation. This converts tribal knowledge into system knowledge — surviving staff changes, shift rotations, and the inevitable day when the experienced operator isn’t there.
Outsourced Processes — Control Without Ownership
Clause 8.1 includes a specific requirement that is routinely overlooked: “The organization shall control planned changes and review the consequences of unintended changes, taking action to mitigate any adverse effects, as necessary.” It also requires control of outsourced processes. An outsourced process is not a purchased product — it’s a process that the organisation has decided not to perform internally but that remains within the scope of the QMS.
The distinction is critical. Heat treatment performed by a subcontractor is an outsourced process. Buying bolts from a fastener supplier is a purchased product. The level of control required differs: outsourced processes must be controlled as defined processes within the QMS, with verification arrangements, performance criteria, and evaluation mechanisms that go beyond incoming goods inspection.
Auditors testing this clause will ask: “Which of your processes are outsourced? How do you define the controls for those processes? How do you verify the outsourced process is meeting your criteria?” If the organisation treats outsourced processes identically to purchased products — a supplier evaluation form and an incoming inspection — the clause is not fully met.
Change Control Within Operations
The change control requirement within Clause 8.1 is distinct from the broader QMS change planning in Clause 6.3. Clause 6.3 addresses changes to the management system itself — structural, policy, or organisational changes. Clause 8.1 addresses operational changes: a process parameter modification, a raw material substitution, a tooling change, a supplier switch, an equipment upgrade.
In SMEs, these operational changes happen frequently and informally. A production manager switches to a cheaper raw material because the usual supplier has a backlog. An engineer adjusts a machine setting to accommodate a tool that’s wearing. A shift lead changes the sequence of operations to accommodate an urgent order. Each of these is a Clause 8.1 event that should be planned, reviewed for consequences, and documented — not because the standard demands paperwork, but because uncontrolled changes are the primary source of nonconforming output.
When a nonconformity investigation traces back to an undocumented change, the root cause is not “operator error.” The root cause is a system that didn’t capture, evaluate, and authorise the change before it was implemented. This is the SGRII position throughout: system deficiency is always the root cause. The system either failed to prevent the error or failed to detect the condition that enabled it.
THE SGRII ISO 9001:2015 QMS FRAMEWORK
Operational planning procedures with defined process criteria, outsourced process controls, and change management workflows built for real SME operations.
EXPLORE THE QMS FRAMEWORK ›Join the Conversation
Can your organisation demonstrate defined process criteria — not just acceptance criteria — for every key operational process? And do your outsourced processes receive greater control than your purchased products?
Practitioner perspectives that challenge or extend this analysis are particularly welcome. Leave your comment below — the SGRII team responds to every substantive contribution.
Build it, don’t just read about it
SGRII ISO 9001:2015 QMS Framework
Six-module QMS with clause-referenced procedures, registers and an audit pack for SMEs.
View the Framework → Get the newsletterCoverage is not compliance. SGRII frameworks provide structured coverage, templates and guidance. They are designed for audit defensibility and structured for certification readiness; they do not certify you, do not guarantee a successful audit, and are not legal advice. The official ISO standard remains the only authoritative source of requirements.