What Does ISO 9001 Clause 8.5.4 Actually Require?
Clause 8.5.4 of ISO 9001:2015 is one of the shortest requirements in the standard, and I think that is exactly why it gets underestimated. The full text of the requirement is a single sentence: "The organization shall preserve the outputs during production and service provision, to the extent necessary to ensure conformity to requirements."
A note follows it, saying that preservation can include identification, handling, contamination control, packaging, storage, transmission or transportation, and protection.
That is the whole clause. There is no required procedure, no mandatory record and no prescribed method. What you have instead is an outcome you must be able to demonstrate: an output that conformed when it was made still conforms when it is used, shipped, delivered or handed over.
If you have ever opened a box of parts that left your plant clean and arrived rusty, or watched a software release degrade between the build server and the customer environment, you already understand what this clause is for. A conforming output that stops conforming before delivery is still a nonconformity, and the customer does not care where in your process it happened.
This guide walks through the clause phrase by phrase, shows how it plays out in manufacturing, service and digital settings, lists what auditors tend to ask for, and ends with a checklist you can use right away.
Where Clause 8.5.4 Sits in ISO 9001:2015
Clause 8.5.4 is one of six subclauses under 8.5, "Production and service provision":
| Clause | Title | What it covers |
|---|---|---|
| 8.5.1 | Control of production and service provision | Controlled conditions for producing outputs and delivering services |
| 8.5.2 | Identification and traceability | Identifying outputs and, where required, tracing them |
| 8.5.3 | Property belonging to customers or external providers | Care of items you do not own |
| 8.5.4 | Preservation | Keeping outputs conforming during production and service provision |
| 8.5.5 | Post-delivery activities | Warranty, maintenance, recycling, disposal |
| 8.5.6 | Control of changes | Reviewing and controlling changes that affect production or service |
The neighbors matter. Clause 8.5.2 supplies the identification that preservation depends on, because you cannot protect what you cannot tell apart from something else. Clause 8.5.3 applies similar care to customer-owned material. Clause 8.5.5 picks up where preservation ends, after delivery. Clause 8.5.4 is the bridge between making something right and getting it to the customer still right.
How the 2015 wording differs from ISO 9001:2008
Under the 2008 edition, the equivalent requirement was clause 7.5.5, "Preservation of product." It spoke of identification, handling, packaging, storage and protection, and it applied to the constituent parts of a product as well. The 2015 edition changed "product" to "outputs" and moved the list into a note, so the language now covers services, software, data and documents, not only physical goods. It also added the phrase "to the extent necessary to ensure conformity to requirements," which makes the clause risk-proportionate. A bag of screws and a vial of reagent do not need the same level of preservation, and the standard lets you say so.
Breaking Down the Clause Language
"Preserve the outputs"
Outputs are whatever your processes produce, and that includes work in progress, finished goods, components, deliverables, reports, software builds and customer data. The word "outputs" is broader than "product." A calibration certificate is an output. So is a client file on a shared drive.
"During production and service provision"
The scope is the period from the start of production or service delivery through to the point where you hand the output over. In practice this includes internal movement between work centers, interim storage, packaging, shipping and, for services, the time a deliverable sits in a queue or repository before the client receives it. Post-delivery protection is a separate topic under 8.5.5, although many organizations extend their preservation controls into delivery because that is where damage commonly happens.
"To the extent necessary to ensure conformity to requirements"
This is the phrase I would underline for any new quality manager. The standard does not ask you to wrap everything in foam. It asks you to protect outputs as far as needed to meet the requirements that apply, and those requirements come from several places: customer specifications, statutory and regulatory requirements, your own product standards, and what clause 8.2.2 calls requirements the organization considers necessary. Preservation is therefore defined by what could make the output nonconforming, not by a fixed list of controls.
The six items in the note
The note is not a mandatory checklist, but it is an excellent prompt for a risk review:
- Identification: labels, tags, lot markers, file naming, version control
- Handling: lifting methods, handling equipment, access permissions, ESD precautions
- Contamination control: cleanliness, cross-contamination, malware or unauthorized changes for digital outputs
- Packaging: protective materials, containers, tamper evidence, encrypted packages for data
- Storage: temperature, humidity, shelf life, segregation, stock rotation, backups
- Transmission or transportation: carriers, transit conditions, secure transfer protocols
- Protection: guarding against loss, theft, corrosion, unauthorized access or damage
Notice that "transmission" sits next to "transportation." That single word is the standard's acknowledgement that an output can travel over a network as easily as on a truck.
How to Decide What Preservation You Need
The clause leaves the "how" to you, so you need a repeatable way to decide. Here is the sequence I use with clients.
Step 1: List the outputs that can deteriorate
Walk your process map and ask, for each output, what condition it must be in when it leaves each stage. If you have not built a process map yet, the process approach guide explains how to map and measure processes in a way that makes this exercise much easier.
Step 2: Identify how each output could degrade
Think in terms of failure modes. Physical outputs corrode, crack, absorb moisture, expire, get contaminated or get mixed up. Service outputs get lost, delayed, altered or disclosed to the wrong person. Software and data outputs get corrupted, overwritten, or exposed.
Step 3: Tie each risk to a requirement
A risk only matters under 8.5.4 if it threatens conformity. A customer drawing that specifies a cleanliness level, a regulation that sets a storage temperature, or a contract that demands confidentiality turns a vague worry into an auditable requirement. This is also where clause 6.1 risk thinking feeds the operation, and the risk-based thinking implementation guide covers how to keep that proportionate.
Step 4: Choose controls proportionate to the risk
Match the control to the failure mode. Desiccant and sealed bags for moisture, temperature loggers for cold-chain items, locked cabinets for confidential records, checksum verification for file transfers, and so on.
Step 5: Assign responsibility and verify
Someone should own each control, and you should have a way to confirm it is working, whether that is a periodic walk-through, a storage-condition log, an incoming-damage report or a customer complaint trend.
Preservation Examples by Industry
The clause reads the same everywhere, but the controls look very different. This table shows how the six note items translate.
| Note item | Machine shop | Food or pharmaceutical distributor | Software or IT services firm | Consulting or professional services |
|---|---|---|---|---|
| Identification | Lot-labeled bins, traveler paperwork | Batch and expiry labels | Build numbers, release tags | Document control numbers, revision marks |
| Handling | Padded carts, no stacking of finished parts | Pallet handling rules, no-drop procedures | Role-based access to repositories | Restricted editing rights on client files |
| Contamination control | Separate ferrous and non-ferrous work | Segregation of allergens or incompatible items | Malware scanning of build artifacts | Clean-desk and confidentiality rules |
| Packaging | VCI bags, custom dunnage | Insulated shippers, sealed cartons | Signed, encrypted packages | Password-protected PDFs |
| Storage | Dry racks, oiled parts | Temperature-controlled zones, FIFO or FEFO | Versioned backups, retention rules | Controlled project folders |
| Transmission or transportation | Carrier selection, crating | Cold-chain carriers with loggers | Secure transfer protocols | Secure client portal |
| Protection | Corrosion inhibitors | Pest control, security | Access logging, disaster recovery | Backup and recovery testing |
A couple of observations. First, a services business rarely has a warehouse but nearly always has something to preserve, whether that is a client's records, a half-finished report or a configuration. Second, the same logic applies to organizations that buy in outputs from others. If a supplier stores or ships on your behalf, your preservation obligations do not disappear, and the outsourced process control guide explains how clause 8.4 and 8.5.4 interact in that case.
What Documented Information Does Clause 8.5.4 Require?
Clause 8.5.4 does not mention documented information at all. Unlike earlier editions, ISO 9001:2015 has no "documented procedure" requirement for preservation. That does not mean you can do without evidence, though. Clause 7.5.1 says the QMS must include documented information determined by the organization as necessary for the effectiveness of the QMS, and clause 4.4.2 asks you to maintain documented information to support operation of processes and retain documented information to have confidence that processes are carried out as planned.
In practical terms, the following are the records I see satisfy auditors most often:
- Work instructions or packaging specifications for outputs that need specific handling
- Storage and warehouse layout rules, including shelf-life and rotation rules
- Environmental monitoring logs where temperature or humidity matter
- Packaging validation or shipping test results for fragile or high-value items
- Incoming-damage and transit-loss records, with corrective actions
- Backup, restore-test and access-control records for digital outputs
A small business with simple outputs can meet the clause with a half-page of storage and packing rules and a few checks. A pharmaceutical distributor will need much more. Scale the documentation to the risk, which is what the clause itself invites.
How Clause 8.5.4 Connects to Other Requirements
Preservation does not live in isolation. Auditors tend to follow the thread across several clauses, so it helps to see the links.
- Clause 7.1.4, environment for the operation of processes: The conditions you maintain for production (temperature, cleanliness, humidity) often double as preservation controls.
- Clause 7.1.5, monitoring and measuring resources: If you rely on a data logger or thermometer to prove storage conditions, that instrument needs to be fit for purpose and, where required, calibrated.
- Clause 7.2, competence: People who handle sensitive outputs need training on how to do it. The ISO 9001 training guide covers how to structure that.
- Clause 8.4, external providers: Carriers, third-party warehouses and cloud hosts are external providers, so your preservation requirements should flow down to them.
- Clause 8.6, release of products and services: Release is not complete until planned arrangements, which may include packaging and preservation checks, are satisfactorily completed.
- Clause 8.7, control of nonconforming outputs: An output damaged in storage is a nonconforming output and must be identified, controlled and dispositioned.
- Clause 10.2, nonconformity and corrective action: Recurring damage or deterioration should trigger root cause analysis, not repeated rework.
Some sector standards add detail on top of the same clause number. IATF 16949:2016 has a supplemental clause 8.5.4.1 on preservation, which among other things addresses stock rotation. ISO 13485:2016 treats preservation of product in clause 7.5.11, with specific attention to storage conditions and shelf life. If you work in either world, treat ISO 9001 as the base and read the sector standard for the additions. For automotive suppliers in particular, the IATF 16949 gap analysis guide is a useful companion.
What Auditors Look For
Having sat on the other side of the table, I can tell you that preservation audits are mostly done by walking around. An auditor does not need a long conversation to find out whether you meet this clause; they look at what is on the shelves.
Expect questions like these:
- How do you decide how each output must be protected?
- Show me where finished goods or deliverables are held before shipment or release. How are they identified?
- What are the storage conditions for this item, and how do you know they are being met?
- How do you handle items with a shelf life, and what happens when one expires?
- How do you select and instruct carriers, and what happens when something arrives damaged?
- For digital outputs, how are files protected from loss, alteration and unauthorized access?
- Show me a case where preservation failed and what you did about it.
The most useful thing you can have ready is evidence that the controls you describe are actually used. A beautifully written storage procedure with open boxes of unlabeled parts on the floor will not survive an audit. The reverse, good floor practice with no written rules, is easier to fix but still worth documenting so the practice survives staff turnover.
Common findings
Based on what I see repeatedly, these are the patterns that produce nonconformities:
- Outputs stored in unmarked or unsegregated locations, so conforming and nonconforming items mix
- Shelf-life items past expiry still in the active stock area
- Temperature or humidity logs with gaps, or no evidence anyone reviewed them
- Packaging that has never been checked against actual transit damage
- Electronic files kept on personal drives or unmanaged shares with no backup
- Carriers selected on price alone, with no preservation requirements communicated
For a broader view of where audits tend to go wrong, the article on common ISO 9001 audit nonconformities is worth a read.
A Practical Implementation Checklist
Use this as a working list. Adapt it to your size and risk.
Scope and risk
- [ ] Listed outputs (including WIP, finished goods, services and digital deliverables) that could deteriorate or be damaged
- [ ] Identified the requirements (customer, regulatory, internal) that preservation must protect
- [ ] Documented the failure modes and the proportionate control for each
Identification and handling
- [ ] Labeling system that survives storage and transport
- [ ] Handling rules and equipment suited to the output
- [ ] Segregation of conforming, nonconforming and customer-owned items
Storage and packaging
- [ ] Defined storage areas with environmental limits where they matter
- [ ] Shelf-life tracking and stock rotation rule (FIFO or FEFO as appropriate)
- [ ] Packaging specifications tested against real shipping conditions
- [ ] Backup and retention rules for digital outputs, with periodic restore tests
Transport and transmission
- [ ] Carrier and transfer-method requirements communicated, or flowed down under clause 8.4
- [ ] Damage and loss reporting route that feeds corrective action
People and monitoring
- [ ] Staff trained on the handling and storage rules relevant to their jobs
- [ ] Monitoring equipment identified, and calibrated where its readings are relied on
- [ ] Preservation included in the internal audit program
On that last point, it is worth building a floor-level walk-through into your audits rather than relying on document review alone. The internal audits page lays out how to plan audits that look at real conditions.
Frequently Asked Mistakes
Treating preservation as a warehouse-only topic. If you deliver services or software, you still hold outputs that can be lost, altered or exposed. I think this is the most common misreading, and it leaves service organizations scrambling when an auditor asks about client data.
Writing a procedure and stopping there. Clause 8.5.4 is about results. An auditor will care much more about whether outputs are in good condition than about whether a procedure has a document number.
Over-engineering. The phrase "to the extent necessary" gives you room. If your outputs are durable and low risk, say so in your risk assessment and keep the controls light.
Ignoring the handoffs. Most damage happens when an output changes hands: between shifts, between departments, onto a truck, into a customer portal. Look hardest at those moments.
Frequently Asked Questions
Does ISO 9001:2015 require a documented procedure for preservation? No. The 2015 edition has no documented-procedure requirement for clause 8.5.4. You still need enough documented information to have confidence the process is carried out as planned, and the amount depends on risk and complexity.
Does clause 8.5.4 apply to service companies? Yes. The clause refers to outputs, which includes services, software, data and documents. A client file, a draft report or a software build all need to be preserved so they still conform at delivery.
What is the difference between clause 8.5.3 and clause 8.5.4? Clause 8.5.3 covers property that belongs to customers or external providers, such as customer-supplied material or data, and requires you to identify, verify, protect and safeguard it. Clause 8.5.4 covers your own outputs during production and service provision. Many organizations apply the same storage and handling controls to both.
How far does preservation extend after the output leaves your control? Clause 8.5.4 addresses preservation during production and service provision, which includes the delivery step you are responsible for. What happens after delivery, such as warranty and maintenance, falls under clause 8.5.5 on post-delivery activities.
Do I need to calibrate temperature loggers used for storage? If readings from the device are used as evidence that outputs conform, clause 7.1.5 applies and the device must be suitable and, where measurement traceability is required or you have determined it is necessary, calibrated or verified.
Where to Go from Here
If you are building or tightening your system, preservation is a good clause to test with a simple exercise: pick three outputs and follow each one from the last operation to the customer's hands, writing down every point where it could be damaged, mixed up or exposed. The gaps you find will be your real requirements, and they will be more useful than anything a template can tell you.
For the wider picture of how this clause fits into a full implementation, see the ISO 9001 implementation overview. If you want a second pair of eyes on your storage, packaging or digital-delivery controls before an audit, you can reach me through Certify Consulting.
Last updated: 2026-10-09
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.