Quality KPIs under ISO 9001 clause 9.1: the standard names none of them
The quality dashboard carries twenty-four tiles. Complaint rate, on-time delivery, scrap, rework, findings per quarter, training hours, open actions. All green or amber, all refreshed monthly, all introduced at some point for a reason nobody quite remembers.
Then an auditor asks which of those figures demonstrates the effectiveness of the quality management system, and where it is established when they get evaluated. Both questions come straight out of the standard, and most dashboards answer neither.
The standard names no metric
This deserves saying plainly, because it is rarely said: ISO 9001:2015 contains no requirement about which indicators a quality management system must maintain. No list, no minimum count, no examples carrying obligation [1].
What clause 9.1.1 requires is different in kind — that the organization determine for itself what needs to be monitored and measured. That shift is not a formality. It makes the selection the object of the audit, not the metric. The defensible answer to “why this indicator?” is a reasoned one, and there is no correct answer to compare it against.
So when a mandatory KPI turns up in a discussion, the useful question is which clause it comes from. Usually it comes from a sector scheme, a customer-specific requirement, or the template the system was built from years ago. For automotive supply the picture is different: IATF 16949 and the customer-specific requirements layered on top of it do add concrete obligations, as IATF 16949 audit requirements sets out. None of them follows from ISO 9001 alone.
What follows from this for target-setting itself — and why SMART plays no part in it — is covered in the article on quality objectives under ISO 9001 clause 6.2.
Effectiveness is not efficiency
Get this distinction wrong and half the dashboard falls outside the standard’s scope.
Effectiveness, in ISO 9000’s definition, is the extent to which planned activities are realized and planned results are achieved. The APG cites that definition in its paper on effectiveness with the reference ISO 9000:2015, 3.7.11 [3]. Efficiency relates the result achieved to the resources used to achieve it.
ISO 9001 asks for the first, consistently. The APG guidance on improvement says so without qualification: the requirement in ISO 9001 is for improvement of the effectiveness of the QMS [4].
For efficiency the line runs exactly between two documents. ISO 9004:2018 recommends in clause 10.5 that internal audits assess the implementation, effectiveness and efficiency of the organization’s management systems. The APG quotes that passage in full and appends, immediately, the note that this ISO 9004 guidance is not an auditable requirement for an ISO 9001 audit [4].
In practice: cycle times, cost per transaction and utilisation rates are legitimate and often valuable management measures. They do not demonstrate the effectiveness of the system, and they carry no weight in a certification audit. Build a metric set exclusively from efficiency measures and clause 9.1 has nothing to look at.
Four determinations, and the fourth is almost always missing
Clause 9.1.1 requires four determinations before anything is measured at all [1]:
| Determination under 9.1.1 | What it usually becomes in practice |
|---|---|
| What needs to be monitored and measured | Usually present — this is the metric list |
| The methods for monitoring, measurement, analysis and evaluation needed to ensure valid results | Often implicit. A complaint rate without a defined numerator and denominator is not a method |
| When the monitoring and measuring shall be performed | Usually governed, often as a monthly cadence |
| When the results shall be analysed and evaluated | Almost always missing |
The fourth row is the finding. The standard separates the moment of measurement from the moment of evaluation and requires a determination for each. That is not pedantry. A tile refreshed monthly is a measurement; who turns it into a judgement, and when, is a different question, and without an answer the evaluation drifts to the only place it happens anyway — the week before the management review, once a year, under time pressure.
Two further requirements sit in the same clause, independent of those four: the organization shall evaluate the performance and the effectiveness of the quality management system, and shall retain appropriate documented information as evidence of the results [1]. Evidence of the results — not of the readings. A chart without a recorded conclusion does not cleanly satisfy that.
Objectives must be measurable, not necessarily quantified
Here a primary source dismantles a widespread article of faith.
ISO/TC 176 maintains, with the International Accreditation Forum, the ISO 9001 Auditing Practices Group, which publishes free guidance on how requirements should be looked at in an audit. Its paper on policy, objectives and management review states that quality objectives are to be measurable and verifiable, but not necessarily quantified; qualitative results may also be relevant, and a yes/no answer on achieving an objective is acceptable provided it is supported by evidence [2].
The same paper notes that there is no specified way of identifying or documenting quality objectives — they may appear through business plans, management review outputs or annual budgets, and it is for auditors to satisfy themselves that the objectives are adequately documented [2]. It also expects evidence that objectives are cascaded through the organization’s structure and processes, linking strategic objectives to management objectives and down to specific operational activities [2].
ISO 9004:2018, the guidance standard on sustained success, calibrates it as a recommendation: objectives should be quantified where possible [5]. That qualifier — where possible — is what tends to get lost.
Assessment: the compulsion to produce a number creates a characteristic failure mode, the objective that can be quantified because it does not matter. Training hours per employee are easy to count and say almost nothing about whether the system works. Whether release rules are actually applied after a process change is harder to capture, and entirely verifiable with a sample and a yes/no result — and far more informative.
A side finding: the term numbers moved in 2026
If your procedures quote the definition of effectiveness, check the reference.
ISO 9000 has been in its fifth edition since May 2026, prepared by ISO/TC 176/SC 1. It cancels and replaces the 2015 edition and has been technically revised. The title was shortened from Quality management systems — Fundamentals and vocabulary to Quality management — Fundamentals and vocabulary; the fundamental concepts and quality management principles moved from Clause 2 to Clause 4, leaving Clause 2 as normative references, of which there are none; terms were added and definitions modified [6].
The renumbering came with it. Effectiveness, listed at 3.7.11 in the 2015 edition, is at 3.7.17 in the 2026 edition; performance is at 3.7.3 and customer satisfaction at 3.9.13 [6]. There are still seven quality management principles, now in 4.2 [6].
Assessment: a small thing with an awkward effect. Procedures, training material and question catalogues that cite “ISO 9000:2015, 3.7.11” for the definition of effectiveness now cite a withdrawn edition, under a number that designates something else in the current one. Worth clearing in a single pass — the same housekeeping that arrives at larger scale with ISO 9001:2026, described in ISO 9001:2026 and the internal audit.
What 9.1.3 makes you evaluate
Clause 9.1.3 requires the organization to analyse and evaluate appropriate data and information arising from monitoring and measurement — the APG quotes that sentence verbatim against the reference 9.1.3 [3]. The standard then fixes what the results of that analysis have to be used to evaluate [1]:
- conformity of products and services
- the degree of customer satisfaction
- the performance and effectiveness of the quality management system
- whether planning has been implemented effectively
- the effectiveness of actions taken to address risks and opportunities
- the performance of external providers
- the need for improvements to the quality management system
This is the most usable checklist the standard offers on the subject of metrics, and it is rarely used as one, because it does not describe what to measure. It describes which statements have to be answerable at the end. The route to your own metric set runs backwards through it: which of these seven does this indicator serve? If none, it may still be a sound commercial measure — but it does not belong in the evaluation required by clause 9.
The overlap with the management review inputs in 9.3.2 is not coincidence; it is how the chapter is built. Clause 9.1 produces the analysis, clause 9.3 turns it into decisions. Build the two separately and you do the work twice.
How much improvement is enough?
This comes up in every second management discussion, and the primary source answers it cleanly.
The APG guidance on improvement states that it would be almost impossible to raise a nonconformity reading “there was not enough improvement” [4]. It also explains why. An improvement objective follows from three factors together — corporate objectives, customer needs and the level of performance the market normally expects — and none of them alone determines what counts as enough. The paper illustrates this with aerospace, where the accepted rate of nonconforming delivered product is zero per cent: an improvement from 50 per cent to 40 per cent would be an improvement and still be indefensible, while a target moving from 0.50 to 0.40 per cent sits near the market norm [4].
Two further clarifications from the same paper matter for metric practice. There is no requirement to set improvement objectives for all processes at any one time [4]. But the floor is real: an organization with no policy and no objectives relating to improvement is clearly not complying with the standard [4].
And the loop closes here: where top management has set a realistic objective for a process and there is no evidence of improvement, that information must be fed back into the management review so that top management can decide what action is appropriate — readjusting the objective, or providing other means to affect the process [4].
The most common design error
Assessment: a large share of the metrics kept in quality management measure the quality function’s workload rather than the state of the system. Audits performed, findings recorded, actions closed, training hours delivered — these are activity records. They rise when more work is done and say nothing about effectiveness.
The test is simple: can the metric improve without anything changing in the system? Findings recorded falls when inspection gets less rigorous. On-time closure rises when due dates get more generous. Both movements are green and both mean nothing.
Statements about the system only emerge from measures that span two stages — the share of findings closed with a documented effectiveness check, or the number of requirements that recur across audit cycles. Those are harder to produce because they presuppose an unbroken data chain, which is the subject of from audit to management review. How to carry finding, action and effectiveness evidence together is covered in audit findings and the effectiveness record.
ISO 9004 as freely usable guidance on indicators
If you want a method for indicators, ISO 9001 is the wrong place to look and ISO 9004:2018 is the right one. It devotes a full clause 10 to the analysis and evaluation of an organization’s performance, structured as general, performance indicators, performance analysis, performance evaluation, internal audit, self-assessment and reviews [5].
Two notes on standing. ISO 9004:2018 is the fourth edition, still current, last reviewed and confirmed rather than replaced [5]. And it is guidance, not requirements — the APG says plainly that it is not auditable in an ISO 9001 audit [4]. That makes it more useful for this purpose rather than less: you can adopt its method without acquiring new obligations to evidence.
What a tool has to do here
The requirement in 9.1.1 to fix the evaluation moment separately from the measurement moment is hard to represent in a spreadsheet, where the two collapse into one because the file opens when somebody needs it. Where that boundary lies is covered in Excel or software in quality management.
qportal produces the data side of this today: findings carrying clause and process references, actions with an owner, a due date and an effectiveness criterion, audit programmes with evidence of their execution. Those are precisely the records from which statements about audit results, nonconformities and corrective actions can be derived without manual assembly. The audit side is on the audit management page, the action side on the actions and CAPA page.
Roadmap note: indicator definitions and automated preparation for the management review are on the roadmap and are not shipped. The sequence is deliberate — an indicator is only ever as sound as the capture beneath it.
Conclusion
ISO 9001 prescribes no metrics, and replaces that with a harder demand: justify the selection, fix the method, determine when evaluation happens, and document the result.
Three guardrails from the primary sources shed the most ballast in practice. Objectives must be measurable, not quantified. What is required is effectiveness, not efficiency. And there is no threshold for “enough improvement” — what is auditable is the derivation, not the magnitude.
If you change one thing, change this: run your metric set backwards through the seven evaluation targets in 9.1.3. Anything serving none of them does not belong in quality reporting — and anything serving one but assigned to nobody is not yet an evaluation.
Sources
- ISO 9001:2015, Quality management systems — Requirements. International Organization for Standardization, Geneva; consulted in the bilingual edition DIN EN ISO 9001:2015-11, Beuth Verlag, Berlin. (Clauses 6.2, 9.1.1, 9.1.2, 9.1.3, 9.3.2, 10.1, 10.3)
- ISO 9001 Auditing Practices Group: Guidance on: Policy, Objectives and Management Review. Edition 1, 2016-01-13, issued by ISO/TC 176 together with the International Accreditation Forum. https://committee.iso.org/home/tc176/iso-9001-auditing-practices-group.html (accessed 2026-09-02)
- ISO 9001 Auditing Practices Group: Guidance on: Effectiveness — Aligning the QMS with the achievement of organizational and business success. 2016. Consulted for the references it cites: ISO 9000:2015, 3.7.11 and ISO 9001:2015, 9.1.3 and 10.3. (accessed 2026-09-02)
- ISO 9001 Auditing Practices Group: Guidance on: Improvement. Edition 1, 2016-01-13. Reproduces ISO 9004:2018 clause 10.5 in full, together with the note that this guidance is not an auditable requirement in an ISO 9001 audit. (accessed 2026-09-02)
- ISO 9004:2018, Quality management — Quality of an organization — Guidance to achieve sustained success. Fourth edition, ISO/TC 176/SC 2. Clause 7.3 on quantifying objectives from the freely available reading sample; clause 10 structure (general, performance indicators, performance analysis, performance evaluation, internal audit, self-assessment, reviews) from the table of contents of the same sample. https://www.iso.org/standard/70397.html (accessed 2026-09-02)
- ISO 9000:2026, Quality management — Fundamentals and vocabulary. Fifth edition, 2026-05, ISO/TC 176/SC 1. Summary of changes and structure from the Foreword of the freely available reading sample; the term numbers 3.7.3, 3.7.17 and 3.9.13 are taken from the cross-references in the body text of that same sample. (accessed 2026-09-02)
The APG papers carry an explicit disclaimer that they have not been subject to an endorsement process by ISO, ISO/TC 176 or IAF; they are expert interpretation, not requirements. The International Accreditation Forum ceased operations on 2026-01-01 and was folded together with ILAC into Global ACI; the papers remain available through ISO/TC 176.
Consultancy, certification-body and content-marketing pages are not cited. Normative text is copyrighted; requirements are paraphrased here with a clause reference. Where this text goes beyond the sourced evidence, it is marked as an assessment.
Frequently asked questions
- Which KPIs does ISO 9001 require?
- None. ISO 9001:2015 requires in 9.1.1 that the organization determine for itself what needs to be monitored and measured, and by what methods. The standard names no list, no minimum number and no specific metric such as complaint rate or on-time delivery. If someone quotes a mandatory KPI, ask for the clause.
- Do quality objectives have to be expressed as numbers?
- No. The ISO 9001 Auditing Practices Group states that quality objectives are to be measurable and verifiable, but not necessarily quantified, and that qualitative results may also be relevant — a yes/no answer on whether an objective was achieved is acceptable provided it is supported by evidence. ISO 9004:2018 puts it as a recommendation in 7.3: objectives should be quantified where possible.
- What is the difference between effectiveness and efficiency?
- Effectiveness, as ISO 9000 defines it, is the extent to which planned activities are realized and planned results are achieved — it asks whether the objective was met. Efficiency relates the result achieved to the resources used. ISO 9001 requires effectiveness throughout and never efficiency. ISO 9004:2018 additionally recommends looking at efficiency, but it is guidance and is not auditable in an ISO 9001 audit.
- How much improvement is enough for ISO 9001?
- There is no threshold. The APG guidance on improvement states that it would be almost impossible to raise a nonconformity on the grounds that there was not enough improvement. What is auditable instead is how the organization derived its improvement objectives — from corporate objectives, customer needs and market expectations — and whether it set improvement objectives at all.
- Does every process need a metric?
- No. The APG guidance states explicitly that there is no requirement to set improvement objectives for all processes at any one time. The more useful rule runs the other way: measure where a decision depends on the measurement. A metric with no decision attached to it produces work but no steering.