Most of the time a quality manager thinks about production ending at shipment. The unit leaves the dock, the service is rendered, the invoice goes out, and the process moves to the next order. ISO 9001:2015 clause 8.5.5 exists because that assumption is often wrong, and the standard makes you prove you've thought about it rather than just assumed it.
I'm Jared Clark, Principal Consultant at Certify Consulting, and clause 8.5.5 is one I see organizations either over-build or ignore entirely. Manufacturers with warranty programs tend to over-document it. Service companies and B2B suppliers tend to skip it altogether, on the theory that "post-delivery" only applies to physical products with moving parts. Neither instinct holds up under an actual audit, so let's walk through what the clause says, what it doesn't say, and what evidence an auditor is actually going to ask for.
What ISO 9001:2015 Clause 8.5.5 Actually Requires
Clause 8.5.5 sits inside section 8.5, "Production and service provision," alongside 8.5.1 (control of production and service provision), 8.5.4 (preservation), and 8.5.6 (control of changes). The clause text is short. It says the organization shall meet requirements for post-delivery activities associated with its products and services, and in determining the extent of those activities, it shall consider five things:
- (a) statutory and regulatory requirements
- (b) the potential undesired consequences associated with its products and services
- (c) the nature, use, and intended lifetime of its products and services
- (d) customer requirements
- (e) customer feedback
A note attached to the clause gives three examples of what post-delivery activities look like in practice: actions under warranty provisions, contractual obligations such as maintenance services, and supplementary services such as recycling or final disposal.
Here's the part people miss: clause 8.5.5 does not require you to offer a warranty, run a maintenance program, or take products back for disposal. It requires you to run the five factors above and document what you concluded, including the conclusion that none of it applies to your product line. A company that sells a consumable, single-use product with no regulatory tail and no meaningful undesired-consequence risk might legitimately determine that post-delivery activity is minimal. The clause is satisfied by the analysis, not by the size of the program that comes out of it.
Why This Clause Exists
Production and service provision, as the standard defines it, is easy to picture as something that stops when the product changes hands. But ISO 9001:2015 was written by people who had watched what happens when it doesn't: warranty claims nobody tracked, recalled parts nobody could trace, maintenance obligations buried in a contract that quality never read. Clause 8.5.5 forces the connection between what quality management does and what happens to the product after quality management's usual visibility ends.
In my view, this is one of the more quietly important clauses in the whole standard, because it's the place where legal exposure, customer experience, and the quality system are supposed to meet. A defect discovered six months after delivery is still a nonconformity under clause 8.7, still customer feedback under 9.1.2, and still a trigger for corrective action under 10.2 — but only if somebody built the post-delivery channel that catches it in the first place.
The Five Considerations, Decoded
Reading the clause text doesn't tell you what an auditor will actually ask to see. This table maps each factor to what it means in practice and the kind of evidence that typically satisfies it.
| Clause 8.5.5 Factor | What It Means in Practice | Typical Evidence |
|---|---|---|
| (a) Statutory and regulatory requirements | Laws that impose obligations after the sale — recall duties, retention periods, reporting thresholds | List of applicable regulations per product line; legal/regulatory register cross-referenced to products |
| (b) Potential undesired consequences | What happens if the product or service fails in the field — safety harm, property damage, business interruption | Risk assessment or FMEA (failure mode and effects analysis) showing post-delivery failure modes considered |
| (c) Nature, use, and intended lifetime | How long the product is expected to function and under what conditions | Product lifecycle documentation, expected service life, spare-parts availability plan |
| (d) Customer requirements | Contractual post-delivery obligations the customer imposed | Contract review records, purchase order terms, SLA (service-level agreement) documents |
| (e) Customer feedback | What customers are actually reporting after delivery | Complaint log, warranty claim data, service call records tied back to design or process review |
An auditor who asks "show me your post-delivery process" is really asking you to walk this table backward — to point at each factor and show where the decision was made and where it's recorded.
What Counts as a Post-Delivery Activity
The clause's note names warranty, maintenance, and disposal, but the range in practice is wider than that. A few examples I've walked clients through:
- Manufacturing: warranty repair, replacement-parts availability, field service, product recalls, calibration recalls on measuring instruments already in customer hands.
- Software and technology services: patches, security updates, end-of-life support windows, data migration assistance when a platform is retired.
- Construction and project-based work: defect liability periods, punch-list closeout, as-built documentation delivered after substantial completion, warranty callbacks on workmanship.
- Food, pharmaceutical, and regulated products: traceability that supports a recall, expiration monitoring, adverse-event reporting obligations.
- Consulting and professional services: post-engagement support windows, document retention for the client's audit trail, follow-up review meetings written into the statement of work.
Construction is worth its own mention, because it's one of the categories where clause 8.5.5 gets tested the hardest and most literally. A general contractor's "delivery" is substantial completion, but the defect liability period — often one year under standard AIA or similar contract language — runs well past that date, and warranty callbacks during that window are squarely post-delivery activity under the standard. I've written more on how project-based quality management in construction differs from a fixed-line manufacturing model in our guide to ISO 9001 for construction companies, and clause 8.5.5 is one of the places that difference shows up most clearly in an audit.
The Regulatory Layer Underneath Factor (a)
Factor (a) — statutory and regulatory requirements — is where clause 8.5.5 stops being an internal documentation exercise and starts touching real legal exposure. A few concrete examples worth knowing by name rather than by vague reference:
The EU General Product Safety Regulation (EU) 2023/988, applicable since December 13, 2024, requires economic operators placing products on the EU market to take corrective action — including recall — when they become aware a product poses a risk, and to maintain the technical documentation needed to support that response.
In the United States, section 15(b) of the Consumer Product Safety Act (15 U.S.C. § 2064(b)) requires manufacturers, importers, distributors, and retailers to notify the Consumer Product Safety Commission immediately upon obtaining information reasonably supporting the conclusion that a product contains a defect that constitutes a substantial product hazard, or that creates an unreasonable risk of serious injury or death. Neither of these obligations is optional based on whether your quality manual mentions it — the clause 8.5.5 analysis is what forces you to notice the obligation exists before it's tested by an actual incident.
Machinery manufacturers will have their own version of this under the EU Machinery Regulation (EU) 2023/1230, which requires technical documentation to be retained for at least ten years after the machinery has been placed on the market or put into service. That regulation isn't in force yet, though — it applies from 20 January 2027, and until then the governing law is the Machinery Directive 2006/42/EC. Once 2023/1230 does apply, that retention requirement is a post-delivery obligation in the clearest sense: it exists specifically to support activity — investigation, corrective action, liability defense — that only becomes necessary after the sale is long closed. I go deeper on the broader compliance shift in our breakdown of the EU Machinery Regulation, which is worth reading alongside this clause if you sell into the EU.
None of this means every organization needs a recall plan. It means factor (a) can't be answered with "not applicable" without first checking what actually applies to your product category and your markets.
How Clause 8.5.5 Relates to the Rest of the Standard
Clause 8.5.5 doesn't operate alone. It hands off to, and receives from, several other clauses, and auditors will trace those connections rather than treat 8.5.5 as an isolated checkbox.
| Related Clause | How It Connects to 8.5.5 |
|---|---|
| 8.7 — Control of nonconforming outputs | A defect discovered after delivery still has to be controlled and dispositioned under 8.7, even though the product already shipped |
| 9.1.2 — Customer satisfaction | Post-delivery feedback (factor e) is one of the direct inputs to customer satisfaction monitoring |
| 10.2 — Nonconformity and corrective action | Field failures caught through post-delivery activity feed corrective action, and can trigger root-cause work back in design or production |
| 7.5.3 — Control of documented information | Retention periods for post-delivery records (warranty logs, technical files) are governed by the same document-control rules as everything else |
| 8.5.6 — Control of changes | A post-delivery finding that leads to a design or process change has to go back through change control, not get patched informally |
If your quality manual treats 8.5.5 as a stand-alone section with no cross-references to these clauses, that's usually a sign the process was written to satisfy the audit rather than to actually catch problems.
Common Nonconformities Auditors Write Against This Clause
Having sat on both sides of this conversation, the findings against 8.5.5 tend to cluster into the same few patterns:
- No documented analysis of the five factors. The organization has a warranty program, but nobody can show the reasoning that led to it — or, more often, nobody can show why other factors were ruled out.
- Warranty and complaint data that never reaches design or process owners. The service department logs calls; nobody upstream ever sees them. This is a 9.1.2 and 10.2 gap wearing an 8.5.5 label.
- Regulatory obligations not identified. Factor (a) gets a one-line "N/A" with no evidence that anyone checked applicable recall, retention, or reporting laws for the product category.
- Retention periods that don't match regulatory or contractual requirements. Records get purged on a standard document-retention schedule that predates the actual legal obligation.
- Service and project-based businesses assuming the clause doesn't apply to them. It applies to services as much as products — the clause text says "products and services" explicitly.
Building an 8.5.5 Process That Holds Up
A workable post-delivery process doesn't need to be elaborate. It needs to show the same thing every clause in ISO 9001 ultimately asks for: that a decision was made deliberately, on stated criteria, and that the decision gets revisited when the criteria change. In practice that means:
- Running the five-factor analysis at the product or product-family level, not once for the whole company.
- Documenting the conclusion even when the conclusion is "no post-delivery activity required" — silence in the record reads as an oversight, not a decision.
- Routing warranty claims, service calls, and customer feedback into the same corrective action and management review inputs the rest of the system already uses, rather than building a parallel tracking system nobody reconciles.
- Setting record retention periods against the actual regulatory or contractual requirement, not a generic default.
- Reviewing the analysis when a product changes, a new market opens, or a regulation changes — factor (a) in particular has a shelf life.
That last point matters more than it looks. A five-factor analysis done once during initial certification and never revisited is a snapshot of a moment, not a live process — and drift between the two is exactly what a recertification audit is designed to surface. If your system hasn't been walked through end to end recently, our internal audit resources cover how to structure that review before an external auditor does it for you.
Frequently Asked Questions
Does ISO 9001 require every company to offer a warranty? No. Clause 8.5.5 requires you to consider whether post-delivery activities — including warranty — are needed, based on the five factors in the clause. If the analysis concludes no warranty is warranted, that conclusion, documented, satisfies the clause.
How long do post-delivery records need to be retained? ISO 9001 itself doesn't set a fixed retention period; that's governed by clause 7.5.3 and whatever statutory, regulatory, or contractual requirement applies to your product. A machinery manufacturer selling into the EU, for example, faces a minimum ten-year technical documentation retention period today under the Machinery Directive 2006/42/EC; the incoming EU Machinery Regulation (EU) 2023/1230 carries the same ten-year requirement forward, tied to when the machinery is placed on the market or put into service, once it applies on 20 January 2027.
Does clause 8.5.5 apply to service businesses, or only to manufacturers? It applies to both. The clause text explicitly says "products and services." A consulting firm's post-engagement support window, a software vendor's patch and update commitments, and a contractor's defect liability period are all post-delivery activities under this clause.
What's the difference between clause 8.5.5 and clause 8.7? Clause 8.5.5 is about determining what obligations exist after delivery and building the process to meet them. Clause 8.7 (control of nonconforming outputs) is about what happens when something specific goes wrong — including a defect found after delivery. A mature system uses 8.5.5 to build the channel that feeds problems into 8.7, not as a substitute for it.
What evidence should I have ready if an auditor asks about post-delivery activities? At minimum: the documented five-factor analysis for your major product or service lines, a record of warranty or complaint data and where it fed back into the business, your applicable regulatory register for post-sale obligations, and documented retention periods tied to their actual legal or contractual basis rather than a generic default.
Clause 8.5.5 is a short clause with a long tail. Get the analysis right once, keep it current, and the evidence takes care of itself the next time someone asks.
Last updated: 2026-09-18
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.