Management system guidance
4.0 Context of the Organization
ISO Navigator Pro™ is a free tool that provides practical, expert guidance for businesses wishing to interpret and better implement the requirements of ISO 9001:2015, ISO 14001:2015 and ISO 45001:2018.
Our range of templates cover the requirements of ISO 9001:2015, ISO 14001:2015 and ISO 45001:2018, and offer an easy way to implement your next management system.
4.1 Understanding your organization and its context
Determining the context of your organization is a requirement that is new to ISO 9001:2015, ISO 14001:2015 and ISO 45001:2018. Also known as contextual intelligence, this approach is not new to those familiar with business planning and strategic development, but it is new in terms of its specific inclusion into ISO management system standards.
Your organization is now required to identify and assess all internal issues and external issues that could impact upon your management system’s ability to deliver its intended results.
You will need to develop a methodology to understand the needs and expectations of all interested parties. If you need a procedure to help with determining your organization's context, click here.
Identify the stakeholders of your organization's management system and capture their relevant requirements that might influence the type and complexity of your management system.
We suggest that you use the context analysis template to help determine internal issues relevant to your organization's purpose and strategic direction that may affect its ability to achieve the intended result(s) of its management system.
This information should be retained as a strategy or tactical planning document to underpin your organization’s policies and to provide a road map to achieve future goals.
Your organization should identify and asses all internal and external issues that could impact upon your management system's ability to deliver its intended results. You should allow time to develop an understanding of the key internal and external factors that influence your business, and to set up processes to capture, monitor and review these issues.
The following types of documents and tools often help to provide a source of contextual information:
- Policy statement(s) regarding your organization's purpose and strategic direction;
- Individual strategy documents underpinning your organization's policies that provide a road map to achieve its goals;
- Records of meetings where context is routinely discussed and monitored;
- Structured risk assessments of external and internal issues;
- Use of PESTLE template (Political, Economic, Social, Technological, Legal, Environmental) analysis tools for external issues;
- Use of SWOT template (Strengths, Weaknesses, Opportunities, Threats) analysis tools for internal issues;
- Documented information describing organizational context, included as part of a quality manual.
A review of organizational context could include interviews with senior management, questionnaires, surveys and research. Cross-functional input is essential for the specific expertise required to identify the full breadth of issues, such as finance, training, human resources, commercial, engineering and design, etc.
Not only will this ensure a broader appreciation of organizational context but also wider engagement, particularly with those functions not previously involved with the management system.
You will need to determine and understand the various quality, safety and environmental conditions that could become inputs to internal and external issues, which are typically experienced in your type of organization that can have positive or negative impacts. It is important to remember that Clause 4.1 'Understanding the Organization and its Context' interacts with the following clauses:
- Clause 4.3 - 'When determining the scope, the organization shall consider the external and internal issues referred to in 4.1';
- Clause 5.1.1 - 'Top management shall ensure that the quality, environmental or health & safety policies and objectives are established for the QMS and compatible with the organization’s strategic direction and its context';
- Clause 5.2.1a - 'Top management shall establish, review and maintain its quality, environmental or health & safety policies appropriate to the purpose and context of the organization';
- Clause 6.1.1 - 'When planning the QMS, the organization shall consider issues referred to in 4.1 and determine risks and opportunities that need to be addressed';
- Clause 9.3.1 - 'The management review shall be planned and carried out taking into consideration changes in external and internal issues relevant to its QMS that includes its strategic direction'.
There should be no need to have separate a contextual description for each environmental, health and safety or quality management system. In theory; a single, integrated, contextual statement that suits the requirements of each management system since there would be a degree of overlap between the context of a H&S MS, a QMS or an EMS.
In practice however, the needs and expectations; and the types of interested party will likely have some degree of overlap too, as well as, subtle but important differences which would require clear definition. You should consider the focus of your QMS as being different to the focus of your EMS, or your H&S management system; your organizational context must reflect that.
To help understand your business's internal issues, at the micro-level, you need to understand its strengths and weaknesses and be able to identify relevant opportunities and threats.
Undertake a SWOT analysis to review and evaluate current business strategies, the position and direction of your organization, business propositions and other commercial leads.
The SWOT analysis should be developed in such a way that the weaknesses and threats become inputs to determining risk and opportunity. Internal issues might typically be influenced the following:
- Organizational activities;
- Types of product and service;
- Strategic direction;
- Capabilities (people, knowledge, processes, systems);
- Quality, safety and environmental conditions capable of affecting or being affected by your organization.
Sources of information relating to internal issues might include:
- Organizational structure, including the identification of roles and responsibilities and governance arrangements;
- External reports showing how well your business is performing;
- Statements relating to your organization's mission, vision and core values;
- Emphasis placed upon business ethics and organizational codes of conduct;
- Feedback obtained from employees through opinion surveys;
- Information management systems and processes for capturing and deploying knowledge and lessons learned;
- Organizational capability studies, identification of load/capacity and resource requirements to achieve demand;
- Register of identified internal risks and their treatment.
The ISO standards do not specify that internal issues, or their monitoring and review be documented, so there might not be ‘lists of internal issues’ or records of reviews. However, information can be obtained via interviews with relevant Top management in relation to your organization’s context and its strategic direction, the identified issues and conditions, and how these may affect the intended outcomes of your management system.
External issues might include political, financial or economic trends, customer demographics or emerging product developments. You should undertake a PESTLE analysis in order to establish a suitable understanding of these circumstances, and the market in which your business operates at the macro level.
PESTLE analysis provides a framework for measuring market and growth potential according to external political, economic, social, technological, legal and environmental factors. External issues might typically be influenced the following:
- Cultural, social, political and regulatory;
- Financial, economic, natural and competitive issues, whether international, national, regional or local;
- Quality, safety and environmental conditions capable of affecting or being affected by your organization.
Sources of information relating to external issues might include:
- Reports relating to market environment, economic conditions, new technology, new markets, customer expectations;
- Reports relating to supplier intelligence, political considerations, investment opportunities, social factors etc.;
- Identification of factors relating to changes in legislation and regulation, including environmental and H&S impact;
- Feedback relating to product/service performance and lessons learned;
- Register of identified external risks and their treatment.
A workshop approach often allows ideas to be shared and provides an effective and efficient way of achieving a valuable outcome. The workshop could simply be a discussion identifying the issues that can be mapped out using Political, Economic, Social, Technological, Legal and Environmental (PESTLE) analysis. This method helps to structure the conversation and will also help to achieve buy-in to what is often seen as a peripheral or niche area.
To be compliant, evidence should be reviewed that proves that your business has identified all pertinent internal and external issues at periodic intervals. Although there is no requirement for any documented information to defining organizational context, it is helpful to retain the following types of documented information to help justify compliance:
- Business plans and strategy reviews;
- Quality manual
- Competitor analysis;
- Economic reports from business sectors or consultant’s reports;
- SWOT template analysis output;
- PESTLE template analysis output;
- Risk and opportunity assessments;
- Statement contained within a Management System Manual;
- Minutes of management review meetings (that show decisions and actions relating organizational context);
- Process maps, tables, spreadsheets, mind mapping diagrams.
To assess whether your organization has a high-level, conceptual understanding of its internal and external issues that affect it, either positively or negatively, its ability to achieve the intended outcomes, you should describe the processes used by your organization to identify internal and external issues and make reference to all objective evidence, including examples of these issues.
More information on PDCA
Free internal audit checklists
Check out our free internal audit checklists. The audit checklist template is just one of the many tools which are available from the auditor’s toolbox that help ensure your audits address the necessary requirements.
Over 8,000 companies and globally recognized brands have relied on our templates to provide a path to improve, collaborate, and to enhance their operations to achieve certification, please see our client list for more information.