ISO 14001:2015 replaced the former terms “documents,” “records,” and “procedures” with the unified concept of documented information. Clause 7.5 distinguishes between information to be maintained (living documents, procedures) and information to be retained (records, evidence). This flexibility reduces bureaucracy while ensuring critical information is available when needed.
Mandatory Documents to Maintain
Required “Maintain” Items (Procedures/Descriptions)
- EMS scope (Clause 4.3)
- Environmental policy (Clause 5.2)
- Risks and opportunities and processes to address them (Clause 6.1)
- Environmental aspects, impacts, criteria, and significant aspects (Clause 6.1.2)
- Compliance obligations (Clause 6.1.3)
- Operational planning and control processes (Clause 8.1)
- Emergency preparedness and response processes (Clause 8.2)
Mandatory Records to Retain
Required “Retain” Items (Evidence/Records)
- Environmental objectives (Clause 6.2.1)
- Evidence of competence (Clause 7.2)
- Communications evidence (Clause 7.4.1)
- Monitoring and measurement results (Clause 9.1.1)
- Compliance evaluation results (Clause 9.1.2)
- Audit program and results (Clause 9.2.2)
- Management review results (Clause 9.3)
- Nonconformity and corrective action results (Clause 10.2)
Document Control Requirements
Clause 7.5.3 requires documented information to be available and suitable for use where and when needed, adequately protected, and controlled for distribution, access, retrieval, storage, version management, retention, and disposition. This includes controlling documents of external origin that the organization determines necessary for the EMS.
Common Pitfalls
- Over-documenting — creating procedures beyond what the standard requires
- Obsolete documents not removed or clearly marked
- Records not retrievable when needed for audits
- Version control failures allowing outdated procedures to remain in use
- Documents not available at point of use
Frequently Asked Questions
What does ISO 14001 clause 7.5 require?
Clause 7.5 covers three areas. The EMS must include the documented information required by the standard plus whatever the organization determines is necessary for effectiveness. When creating and updating documented information, the organization must ensure appropriate identification, format, and review and approval. Documented information must be controlled so that it is available where needed and adequately protected, covering distribution, access, storage, version control, retention, and disposition.
What documented information is mandatory in ISO 14001:2015?
The standard requires, among others, the EMS scope, the environmental policy, environmental aspects and impacts with the significance criteria and the significant aspects, compliance obligations, risks and opportunities needing to be addressed, environmental objectives and plans, evidence of competence, evidence of communications, operational control information, emergency preparedness process information, monitoring and measurement results, compliance evaluation results, the internal audit programme and results, management review results, and nonconformity and corrective action records.
What replaced documents and records in ISO 14001:2015?
Both terms were replaced by documented information. The 2015 standard signals the old distinction through its verbs: maintain documented information corresponds to what used to be called a document, something kept current such as a procedure or register, while retain documented information corresponds to a record, evidence that something happened at a point in time.
Does ISO 14001 require documented procedures?
Not by name. The 2015 version removed the mandatory documented procedure requirements that existed in the 2004 version and instead requires processes to be established with documented information kept to the extent necessary for confidence that processes are carried out as planned. Most organizations still write procedures for complex or high-risk activities, because that is the simplest way to demonstrate consistent control.
How long must ISO 14001 records be retained?
The standard sets no retention periods; it requires you to define and control retention and disposition. Retention is normally driven by compliance obligations, since permits and regulations often specify periods such as three or five years, and by the certification cycle, since auditors typically sample back across the three-year cycle. Set the period in your control procedure and apply it consistently.
Ecesis handles document control, version history, retention, and access for clause 7.5.
Request a free 30-minute demo

