Clause 8.6 is short. Two paragraphs and a two-item list of retained documented information, in most printings of ISO 9001:2015. And it's still one of the clauses I see get flagged in stage 2 audits and surveillance visits more often than its length would suggest.
Here's why. Clause 8.6, "Release of Products and Services," is the gate. Everything upstream — design, purchasing, production, service provision — funnels into a single decision point: does this go to the customer or not? If your organization can't show, with records, that the decision to release was verified and traceable to a person, the auditor doesn't care how good your production process looks. The gate is where they check first.
I've walked companies through this clause dozens of times, and the pattern is consistent: the release step exists, informally, in almost every organization. What's usually missing isn't the control — it's the evidence trail the standard actually requires.
What Clause 8.6 Actually Says
The text of ISO 9001:2015 clause 8.6 requires the organization to implement planned arrangements, at appropriate stages, to verify that product and service requirements have been met. It then states that release to the customer shall not proceed until those planned arrangements have been satisfactorily completed, unless otherwise approved by a relevant authority and, as applicable, by the customer. Finally, it requires the organization to retain documented information on the release, covering two specific things: evidence of conformity with the acceptance criteria, and traceability to the person or persons who authorized the release.
That's the whole clause. Three requirements, functionally:
- Planned arrangements — you've decided in advance what verification happens and when, not improvised it after the fact.
- No premature release — nothing ships until verification is satisfactorily completed, with a narrow, documented exception path.
- Retained records — evidence of conformity plus a named authorizer, kept as documented information under clause 7.5.
The clause sits inside Section 8, "Operation," immediately after 8.5 (Production and Service Provision) and immediately before 8.7 (Control of Nonconforming Outputs). That placement is not incidental. Clause 8.6 is the checkpoint between "we made it" and "it's out the door" — and 8.7 is what happens when the checkpoint says no.
The Release Checklist
Use this as a working audit tool, not just a reading exercise. For each item, you should be able to point to a specific document, record, or system field — not describe a practice in the abstract.
Planning and criteria
- [ ] Acceptance criteria are defined for each product or service line, tied to specification, drawing, contract, or regulatory requirement — not left to inspector judgment.
- [ ] The verification stage (or stages) where release checks occur is documented in the quality plan, control plan, or process flow — final inspection, in-process hold point, or both.
- [ ] Sampling plans, test methods, and pass/fail thresholds referenced in the acceptance criteria are current and traceable to a source document (e.g., ANSI/ASQ Z1.4, a customer spec, an internal test method).
Execution
- [ ] No shipment, delivery, or service completion occurs before the planned verification is satisfactorily completed — check this against actual shipping records, not procedure text.
- [ ] Where release before full verification does occur (concession release), it is approved by a relevant authority and, where required by contract or regulation, by the customer — and this approval is documented before release, not reconstructed afterward.
- [ ] The person performing the release verification has the competence, authority, and independence the process calls for (this connects directly to clause 7.2, Competence).
Records — the part auditors check hardest
- [ ] Evidence of conformity with acceptance criteria exists for each release — inspection results, test data, certificates of conformance, or equivalent — not just a checkbox saying "passed."
- [ ] Each release record shows who authorized it — a name, initials, or unique login, not a department stamp or a signature that could belong to more than one person.
- [ ] Records are retained per your documented-information retention schedule (clause 7.5.3) and are retrievable on request during an audit, not archived somewhere nobody can find in under ten minutes.
- [ ] Where release is electronic (ERP release flag, MES sign-off, e-signature), the system captures the same two data points the clause requires: conformity evidence and the authorizing person, with an audit trail that can't be silently edited.
Linkage to other clauses
- [ ] Nonconforming product identified before release routes to clause 8.7 controls, not around them.
- [ ] Identification and traceability (clause 8.5.2) let you connect a released lot or service instance back to the specific verification record that cleared it.
- [ ] Monitoring and measurement equipment used in release verification is calibrated and controlled per clause 7.1.5.
If every box above has a named document or record behind it, clause 8.6 is in good shape. If more than two or three are answered with "we sort of do that," that's your gap list for the next internal audit.
Documented Information: What "Evidence" Actually Means
The standard doesn't prescribe a form. That's deliberate — ISO 9001:2015 is written to be industry-agnostic, so clause 8.6 leaves the format of evidence to you. But "we trust our people" is not evidence of conformity, and it's the single most common finding I see auditors write up on this clause.
Acceptable evidence generally takes one of these shapes:
- A completed inspection or test record showing measured values against acceptance criteria, not just a pass/fail mark.
- A certificate of conformance or certificate of analysis, for purchased materials being released into a finished good.
- A signed final inspection report referencing the applicable drawing revision or spec number.
- A system-generated release log, provided the system retains both the conformity data and the authorizing user ID.
Traceability to the authorizing person is the second half, and it's the one that trips up organizations using shared logins, generic "QC" stamps, or verbal sign-off ("Bob said it was fine"). If two people can plausibly have made that release decision and the record doesn't disambiguate which one, you don't have traceability — you have a guess.
Release Methods Compared
Different release mechanisms satisfy clause 8.6 differently well. This is worth mapping before an audit, especially if your organization mixes methods across product lines.
| Release Method | Conformity Evidence Captured? | Authorizer Traceability | Common Weakness |
|---|---|---|---|
| Paper inspection report, signed | Yes, if fields are completed | Strong (individual signature) | Records get lost or filed inconsistently |
| Shared department stamp | Partial — often just "OK" | Weak — can't identify the individual | Fails traceability requirement outright |
| ERP/MES electronic release flag | Yes, if data fields are populated | Strong, if unique logins are enforced | Shared credentials defeat the whole control |
| Certificate of Conformance from supplier | Yes, for the supplied item | Depends on supplier's own signature practice | Doesn't cover your own value-added verification |
| Verbal or informal sign-off | No | None | Not defensible in an audit — avoid entirely |
If your organization relies on the shared-stamp or verbal-sign-off rows for anything customer-facing, that's the fastest fix available to you before your next audit. It typically costs nothing — enforcing individual logins or individual initials — and it closes the most commonly cited gap on this clause.
Concession Release: The Exception That Needs Its Own Procedure
The clause's own wording — "unless otherwise approved by a relevant authority and, as applicable, by the customer" — creates a legitimate path to release product before verification is complete, or with a known deviation. Auditors treat this path with more scrutiny, not less, because it's where controls tend to get skipped under schedule pressure.
A defensible concession release needs:
- A documented deviation or concession request, describing exactly what didn't meet the original criteria.
- Approval from someone with the authority to accept that risk — usually more senior than the routine release authority.
- Customer approval, captured in writing, when the contract or the nature of the deviation requires it.
- A record retained alongside the standard release evidence, not filed separately where it won't surface in a records pull.
I have seen more nonconformities written against "release before verification, informally approved" than against any other single failure mode in clause 8.6. The fix isn't complicated. It's a one-page concession form and a rule that nothing ships against it without the second signature.
How This Clause Shows Up in Audits
Third-party auditors sampling clause 8.6 typically pull a handful of recent shipments or completed service instances and ask you to produce the release record for each. What they're checking, in order:
- Does a record exist at all?
- Does it show conformity evidence against the defined acceptance criteria?
- Does it name the person who authorized release?
- Does the timing line up — was verification complete before the release date, not stamped retroactively?
- If a concession applies, is the approval chain documented and does it predate the shipment?
This is also a favorite spot for internal auditors to focus, since it's fast to sample and reveals a lot about process discipline elsewhere. If your organization is due for its next internal audit cycle, our guide on internal audits at iso9001expert.com/internal-audits/ walks through sampling strategy for clauses like this one.
The gate only works if the records prove it was closed before the product moved — everything else is process theater that looks compliant on paper and falls apart the moment a customer asks for evidence.
FAQ
Does clause 8.6 apply to services as well as physical products? Yes. The clause title explicitly covers "products and services," and the requirement to verify conformity before release applies equally to a completed service instance — a consulting deliverable, a calibration report, a completed repair — as it does to a manufactured part.
Can one person both perform the work and authorize its release? The standard doesn't prohibit this outright, but it does require the release record to show a defensible verification step, not a self-certification with no independent check. Many organizations build in a second reviewer for higher-risk products specifically to avoid this question coming up in an audit.
What's the difference between clause 8.6 and clause 8.7 (Nonconforming Outputs)? Clause 8.6 governs the decision to release conforming product. Clause 8.7 governs what happens when an output is found not to conform — it doesn't get released under 8.6 rules; it gets identified, segregated, and dispositioned under 8.7 rules, which may still end in a concession release documented under both clauses.
How long do we need to keep release records? ISO 9001:2015 doesn't set a fixed retention period; that's determined by your own documented-information controls under clause 7.5.3, often shaped by customer contracts, regulatory requirements (e.g., FDA, AS9100 supplements), or your own risk tolerance. Whatever period you set, it needs to be written down and followed consistently.
Is an electronic release flag in our ERP system sufficient documented information? It can be, provided the system captures both required data points — evidence of conformity and traceability to the authorizing individual — and the record can't be altered without leaving an audit trail. A green checkmark with no underlying data and no unique user ID behind it will not satisfy an auditor.
Get the full clause-by-clause requirements list, laid out for internal audit prep, from our downloadable checklist at iso9001expert.com/resources/checklist/download/. And if you want to see how release findings show up alongside other common gaps, our breakdown of frequent ISO 9001 nonconformities at iso9001expert.com/blog/most-common-iso-9001-audit-nonconformities-how-avoid-them/ is worth a look before your next audit cycle.
Last updated: 2026-08-14
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.