# ISO Standards Coverage Map

> Which template covers which ISO standard. Two layers:
> (1) **Annex SL generic docs** – shared 10-clause structure every
> certifiable management system standard (MSS) uses, and
> (2) **standard-specific docs** – the artifacts unique to each standard.
> ISO texts are copyrighted; these templates implement the required
> document structure only. For certification, buy the standard.

## Layer 1 – Annex SL generic docs (work for EVERY MSS)

ISO 9001, 14001, 27001, 45001, 50001, 22000, 22301, 37001, 37301,
42001, 55001, 20000-1, 21001, 28000, 20121... all share:

| Clause | Requirement | Template |
|--------|-------------|----------|
| 4.3 | Scope | `ms-scope.md` |
| 5.2 | Policy | `quality-policy.md` / `information-security-policy.md` |
| 6.2 | Objectives | `objectives-register.md` |
| 7.2 | Competence | competence section in `iso-procedure.md` + training records |
| 7.5 | Documented information | `controlled-document.md`, `iso-15489-records-schedule.md` |
| 8 | Operation | `iso-procedure.md` (per process) |
| 9.2 | Internal audit | `internal-audit-program.md` |
| 9.3 | Management review | `management-review.md` |
| 10.2 | Nonconformity/CAPA | `capa-nonconformity.md` |

## Layer 2 – Standard-specific artifacts

| Standard | Domain | Specific templates |
|----------|--------|--------------------|
| **ISO 9001:2015** | Quality | + `iso-10002-complaints.md`, supplier eval in `supplier-security-assessment.md` |
| **ISO/IEC 27001:2022** | InfoSec | `risk-methodology`, `risk-register`, `risk-treatment-plan`, `statement-of-applicability`, `asset-inventory`, `incident-response-plan`, `legal-register`, `acceptable-use-policy`, `supplier-security-assessment` |
| **ISO 14001:2015** | Environment | `iso-14001-environmental-aspects.md` |
| **ISO 45001:2018** | OH&S | `iso-45001-hazard-register.md` |
| **ISO 50001:2018** | Energy | `iso-50001-energy-review.md` |
| **ISO 22000:2018** | Food safety | `iso-22000-haccp-plan.md` |
| **ISO 22301:2019** | Continuity | `business-continuity.md` |
| **ISO 37001:2016** | Anti-bribery | `iso-37001-anti-bribery.md` |
| **ISO 55001:2014** | Asset mgmt | `iso-55001-samp.md` |
| **ISO/IEC 20000-1:2018** | ITSM | `iso-20000-service-catalog.md` |
| **ISO/IEC 42001:2023** | AI mgmt | `iso-42001-ai-management.md` |
| **ISO 13485:2016** | Medical devices | `iso-13485-design-controls.md` |
| **ISO 14971:2019** | Device risk | `iso-14971-risk-file.md` |
| **ISO 26262** | Automotive safety | `iso-26262-hara.md` (also IEC 61508 SIL) |
| **ISO/IEC 17025:2017** | Labs | `iso-17025-method-validation.md` |
| **ISO/IEC 25010** | SW quality | `iso-25010-quality-evaluation.md` |
| **ISO 10002** | Complaints | `iso-10002-complaints.md` |
| **ISO 15489** | Records | `iso-15489-records-schedule.md` |
| **ISO/IEC 27701** | Privacy | `dpia.md` |
| **ISO 31000** | Risk | `risk-methodology.md`, `risk-register.md` |
| **ISO 19011** | Auditing | `internal-audit-program.md` |

## Standards covered by generic docs alone

These MSS need no unique artifacts beyond the Annex SL layer – use
scope/policy/objectives/procedure/audit/review/CAPA templates:

- ISO 37301 (compliance MS) – use `legal-register.md` + generics
- ISO 21001 (educational orgs), ISO 41001 (facility mgmt),
  ISO 28000 (supply chain security), ISO 20121 (event sustainability),
  ISO 46001 (water efficiency), ISO 39001 (road safety)

## Related non-ISO frameworks people pair with these

| Framework | Covered by |
|-----------|------------|
| SOC 2 | ISMS templates + audit program |
| GDPR/CCPA | `dpia.md`, `legal-lite/privacy-policy.md` |
| NIST CSF 2.0 | `risk-register.md`, `incident-response-plan.md` |
