Why Your Production and Service Provision Procedure Fails

A production and service provision procedure is the document that defines the controlled conditions under which work is carried out, verified and released — the operating core of ISO 9001 Clauses 8.5 and 8.6, ISO 13485 Clause 7.5, the operational control clauses of ISO 14001 and ISO 45001, and ISO 7101 Clause 8.9. It is the procedure auditors spend the most time inside and the one organizations spend the least effort writing.

That imbalance has a cost, and it is not the one people expect. The common failure is not a missing procedure. It is a procedure that restates the clause, uses the standard's own conditional language, and leaves every difficult decision to whoever happens to pick up the work on a pressured Thursday afternoon. A production and service provision procedure written that way passes a document review and fails the floor.

Direct Answer: A production and service provision procedure defines the controlled conditions for producing product or delivering service — the documented information describing what is being produced, the monitoring and measurement at each stage, suitable infrastructure and process environment, competent people, validation where output cannot be verified afterwards, actions to prevent human error, and release authority. ISO 9001 places it at Clauses 8.5 and 8.6, ISO 13485 at Clause 7.5, ISO 14001 and ISO 45001 at Clause 8.1 operational planning and control, and ISO 7101 at Clause 8.9 provision of services.

This article works through what the requirement actually asks across all five standards, where the differences are real rather than cosmetic, and the one requirement that has sat in ISO 9001 since 2015 that most procedures still do not implement. If you would rather measure before you read, the free Production, Service and Operational Control Maturity Check scores eight elements in about six minutes and returns your weakest one immediately.


Five standards, one process

Where does a production and service provision procedure live in each standard?

Map. Match. Merge.

The first practical problem in writing a production and service provision procedure for more than one standard is that the five standards do not agree on where the requirement sits, what to call it, or how much of it to spell out. They agree almost entirely on what it has to achieve.

  • ISO 9001:2015 — Clauses 8.5 and 8.6. ISO 9001 is the most explicit of the five. Clause 8.5.1 lists the controlled conditions as lettered items, 8.5.2 covers identification and traceability, 8.5.3 property belonging to customers or external providers, 8.5.4 preservation, 8.5.5 post-delivery activities, 8.5.6 control of changes, and Clause 8.6 the release of products and services. A production and service provision procedure built to ISO 9001 has the clearest checklist to work from and, for that reason, the highest risk of being written as a restatement of it.
  • ISO 13485:2016 — Clause 7.5. The medical device standard keeps the pre-Annex SL structure, so none of the ISO 9001 numbering transfers. Clause 7.5.1 covers control of production and service provision, then the standard adds requirements the others do not have at all: cleanliness of product, installation activities, servicing activities, particular requirements for sterile devices, validation of processes, validation of sterilization, identification, traceability, customer property and preservation. Since the FDA Quality Management System Regulation took effect on February 2, 2026, those clauses are federal law in the United States by reference.
  • ISO 14001:2026 — Clause 8.1. Environmental management calls it operational planning and control, and it is written at a higher level of abstraction: establish criteria for the processes, control them in accordance with those criteria, and extend control to outsourced, externally provided and lifecycle-adjacent activity. The requirement is broader in reach and thinner in detail than ISO 9001's.
  • ISO 45001:2018 — Clause 8.1. Occupational health and safety uses the same operational-control language and then adds three things the quality standards do not: the hierarchy of controls at 8.1.2, management of change at 8.1.3, and procurement including contractors and outsourcing at 8.1.4. Emergency preparedness sits alongside at Clause 8.2.
  • ISO 7101:2023 — Clause 8.9. ISO 7101, the healthcare quality management standard, names it provision of services and asks the organization to define the controlled conditions needed to deliver services that are safe, effective and timely. Its neighbors are what make it different: people-centered care at 8.10, ethics at 8.11 and patient safety at 8.12 all sit inside the same clause, which means a healthcare production and service provision procedure carries obligations no factory procedure has ever had to consider.
Direct Answer: A single production and service provision procedure can serve all five standards, but not by writing to the lowest common denominator. Write to the ISO 9001 Clause 8.5 structure because it is the most explicit, then add the ISO 13485 Clause 7.5 device requirements, the ISO 45001 hierarchy of controls and contractor requirements, the ISO 14001 lifecycle and outsourcing reach, and the ISO 7101 service-user obligations as standard-specific sections. The common core is roughly seventy percent of the document.

That seventy-percent figure is the reason integrated systems are worth building at all, and it is also where they go wrong. MSI's guide to integrated management system implementation covers the general pattern; the specific trap in operational control is assuming the shared seventy percent is the whole document and letting the standard-specific thirty percent live in someone's head.


Controlled conditions

What does a production and service provision procedure actually have to control?

Define. Decide. Document.

ISO 9001 Clause 8.5.1 sets out controlled conditions as a lettered list. Read plainly, it is a competent specification for how to run work. Read as most procedures read it, it is a set of headings to be echoed back. The difference between those two readings is the entire difference between a production and service provision procedure that works and one that does not.

  • Documented information defining what is produced and what results are to be achieved. Not the drawing alone — the characteristics, the acceptance criteria, and the revision level in force at the moment the work is done.
  • Monitoring and measuring resources. The instruments themselves belong to a separate process; MSI covers it in control of monitoring and measuring equipment. What belongs here is which measurement happens at which stage, and by whom.
  • Monitoring and measurement activities at appropriate stages. The word doing the work is stages. Verification concentrated entirely at final inspection is a common and expensive design choice, because it detects at the point where rework costs the most.
  • Suitable infrastructure and process environment. Temperature, cleanliness, lighting, noise, workspace — and in service delivery, the systems access and information environment the work depends on.
  • Competent persons, including required qualification. Competence is the authorization to perform the work, not the training record that proves someone once attended.
  • Validation and periodic revalidation of processes where output cannot be verified by subsequent monitoring or measurement. This one has its own section below, because it is the most frequently misread requirement in the clause.
  • Implementation of actions to prevent human error. Also its own section, because it is the one most procedures do not implement at all.
  • Implementation of release, delivery and post-delivery activities. Who releases, on what authority, against what evidence.
Every conditional phrase in the standard — “as applicable,” “as appropriate,” “where necessary” — is a decision the standard has deliberately left to you. A procedure that repeats the phrase has not made the decision. It has copied the question onto a controlled document and filed it.

This is the single most useful test to apply to any production and service provision procedure, inherited or purchased. Take any paragraph and ask whether a competent new employee could act on it without asking a question. “Inspection shall be performed at appropriate frequencies” fails. “Inspect the first piece, then every twentieth piece, and every piece after any tooling change; outside the stated range the process stops and the supervisor is notified” passes. The same test runs through MSI's work on the seven marks of an effective ISO procedure, and it applies to every procedure family, not only this one.

Specificity is not bureaucracy. It is a decision made once, centrally, by someone with time to think, instead of forty times a year under pressure by whoever picked up the work. That is the whole economic argument for writing a production and service provision procedure properly, and it is why the document is worth more than the certificate it supports.

Direct Answer: The test of a production and service provision procedure is whether a competent new employee could act on any paragraph without asking a question. Conditional language carried over from the standard — “as applicable,” “as appropriate” — marks a decision the standard left to the organization and the procedure failed to make. Replacing each one with a named frequency, a named role and a named stop condition is the highest-value edit available to most organizations.

The clause almost nobody implements

The human-error requirement your production and service provision procedure probably ignores

Prevent. Not train.

ISO 9001 Clause 8.5.1 contains an item requiring the implementation of actions to prevent human error. In the 2015 edition it is item (g). It is a short requirement, it is unambiguous, and across 200+ certification and surveillance audits attended in 28 years, MSI consistently sees it answered with a sentence about operator training — which satisfies a different clause entirely.

There is a structural reason for that, and it is worth understanding because it explains why the gap is so evenly distributed across industries. The human-error requirement was new in the 2015 revision. It had no predecessor in ISO 9001:2008. Organizations transitioning to the 2015 edition worked, sensibly, from correspondence tables — mapping each old clause reference to its new home. A requirement with nothing to map from has no row in that table. It was not resisted or rejected. It was never looked at. And once the procedure was reissued with “as applicable” language inherited from the clause, nothing in the system ever raised it again.

Training is Clause 7.2 competence. It addresses whether a person knows how to do the work. The human-error requirement addresses what happens when a person who knows how to do the work does it wrong anyway — which is the normal case, not the exceptional one. A production and service provision procedure that answers the second question with the first has not answered it.

The three questions

Most treatments of error prevention stop at two questions: where can it go wrong, and how do we catch it. A production and service provision procedure that stops there is still a detection system. The third question is the one that separates a control from an intention.

  • One. Which steps can a competent, well-intentioned person still get wrong? Not which steps are difficult — which steps are confusable. Two fittings that thread into the same port. Two revision levels live on the floor at once. A screen where the default value is the one used least often. Error opportunity is a property of the process design, not of the person.
  • Two. What in the process prevents that error rather than catching it afterwards? A fixture that only accepts the part one way. A field that will not submit without the second value. A software interlock, a color code, a physical stop. Where prevention is not achievable, say so explicitly and place detection as close to the step as possible. The hierarchy here is the same logic ISO 45001 formalizes in the hierarchy of controls — eliminate, substitute, engineer, then administer, and only then rely on the person.
  • Three. How do you know the prevention is still working? Verified on the control itself, not on the output. A fixture that has worn, an interlock disabled during a maintenance call and never re-enabled, a validation rule switched off for a data migration — each of these is invisible in output data until the day it is not. Almost nobody asks this question, and it is the one the Production, Service and Operational Control Maturity Check scores hardest.

Classifying by consequence keeps this proportionate. An error that produces obvious scrap on the next operation needs less designed prevention than an error that leaves the building undetected. A production and service provision procedure that treats every step as equally error-prone produces a document nobody can follow; one that names the handful of steps where consequence is high, and designs for those, produces a control people actually use.

The asymmetry across the five standards

The human-error requirement is ISO 9001's alone, and that matters when a production and service provision procedure has to serve more than one standard. ISO 13485 Clause 7.5.1 has no equivalent lettered item — error prevention arrives in the device world through risk management and process validation instead. ISO 14001 and ISO 45001 reach the same place through the hierarchy of controls, where reliance on human behavior is explicitly the weakest tier rather than a named requirement. ISO 7101 folds it into patient safety at Clause 8.12.

Practically, that means the ISO 9001 and integrated versions of a production and service provision procedure need this as a named section with its own records, while the environmental and safety versions carry it inside operational control and the device version carries it inside validation and risk. Same discipline, four different homes. Getting that placement wrong is the most common reason a single procedure written for one standard reads as padded when reused for another. MSI's risk management procedure guidance covers the device-side route in detail.

Direct Answer: A production and service provision procedure satisfies the human-error requirement by naming the steps where a competent person can still err, designing a prevention into the process rather than a reminder into a training record, and verifying periodically that the prevention still functions. Operator training alone does not satisfy it — training addresses competence under Clause 7.2, which is a different requirement answering a different question.

Validation

When must a production and service provision procedure validate a process?

Prove. Requalify. Repeat.

The validation requirement is short enough to quote in a sentence and is misread more often than any other item in the clause. Validate any process where the resulting output cannot be verified by subsequent monitoring or measurement — including, in the device world, processes where deficiencies become apparent only after the product is in use.

Almost every production and service provision procedure in circulation reads that as an exception for special processes. Welding, heat treating, plating, molding, coating, sealing, sterilization, software. The list is real and the GHTF SG3 process validation guidance — still the reference document regulators defer to, now carried by IMDRF — names most of it explicitly. But treating the list as the requirement inverts the logic. The list is a set of examples. The requirement is a question: is the output fully verified before it reaches the customer? If not, validate.

In service delivery, unverifiable output is not the exception. It is the normal case. You cannot inspect a completed design review, a clinical handoff or a customer onboarding before the customer experiences it.

That has a consequence most service organizations have never been asked about. A consultancy, a logistics operator, a software business, a clinic — each one delivers output whose quality is only observable after delivery, and MSI client experience suggests the great majority arrive at certification with no validated processes at all, because the production and service provision procedure they inherited assumed a factory and the auditor read the same assumption back. Nothing in that exchange is dishonest. The clause simply never got applied to the work.

Direct Answer: A production and service provision procedure must validate any process whose output cannot be fully verified by later monitoring or measurement. Validation requires defined criteria for review and approval of the process, approval of equipment, qualification of people, defined methods and acceptance criteria, records, and defined triggers for revalidation. Service organizations are in scope: design review, handoff and onboarding processes are unverifiable before delivery in exactly the sense the clause means.

Revalidation is where validated systems quietly stop being valid

The failure mode is almost never an absent validation. It is a validation performed once, correctly, three or four years ago — after which the equipment was replaced, the operator changed, the resin supplier changed, the software was updated, or the cycle time was trimmed to meet demand. Each change was individually reasonable. None of them routed back to the validation, because nothing in the production and service provision procedure said they had to.

The fix is to define revalidation on named events with a calendar interval only as a backstop. Useful triggers: a change of equipment or tooling, a change of material or supplier, a change of process parameters, a move to a new location, a trend shift in process data, a complaint or field failure implicating the process, and a change to the specification the process was validated against. That last one is the interface to change control, which MSI covers in its work on ISO 9001 change management — Clause 8.5.6 in ISO 9001 and Clause 8.1.3 management of change in ISO 45001.

For medical devices the stakes are set by regulation rather than by preference. ISO 13485 Clause 7.5.6 carries the validation requirement and Clause 7.5.7 adds validation of sterilization processes, and since the QMSR took effect those clauses are enforceable through 21 CFR Part 820. The legacy production and process controls subpart remains a useful read for what an investigator is looking for on the floor. MSI's ISO 13485 gap analysis treats revalidation triggers as a scored item precisely because they are so consistently absent, and its analysis of the QMSR and ISO 13485 alignment covers what changed on February 2, 2026.

One further category is routinely missed: software used in the quality system itself. If a spreadsheet calculates an acceptance decision, or a workflow tool routes a release, that application is part of the process and its intended use has to be validated. MSI's coverage of ISO compliance automation works through what that means when the system is a platform rather than a workbook.


Identification and traceability

How much traceability does a production and service provision procedure need?

Identify. Trace. Recall.

ISO 9001 Clause 8.5.2 asks three things, and organizations reliably deliver the first, partially deliver the third, and skip the second.

  • Identify outputs by suitable means throughout production and service provision. Part numbers, job numbers, case numbers, ticket references. Almost always present.
  • Identify the status of outputs with respect to monitoring and measurement requirements. This is inspection status, and it is a control rather than a label. If a part awaiting inspection and a part that has passed look identical on the same bench, the production and service provision procedure has a defect no amount of record-keeping compensates for. In service work the equivalent is a case whose review state is visible only to the person who happens to be handling it.
  • Control unique identification where traceability is a requirement, and retain the documented information necessary to enable it. Note the conditional — where traceability is a requirement. Deciding whether it is, and to what depth, is the work.

That decision is the one almost no production and service provision procedure documents. Traceability has a direction, a reach and a granularity, and each is a separate choice. Forward from a received lot to every unit that consumed it; backward from a delivered unit to every input. Reach can stop at the organization's gates or extend to the supplier's lot and the customer's installation. Granularity can be batch, lot, or individual serial. Each combination has a real cost and a real recall consequence, and choosing deliberately is what separates a considered system from one that will discover its reach during an incident.

For medical devices the choice is largely made for you. ISO 13485 Clause 7.5.8 covers identification and Clause 7.5.9 traceability, with heavier requirements for implantable devices — records of components, materials and work environment conditions sufficient to reconstruct the device history. Under the QMSR those clauses carry federal obligations attached to them: unique device identification under Part 830 for Clause 7.5.8, and device tracking under Part 821 for Clause 7.5.9.1 where applicable. The supplemental provisions also add labeling and packaging inspection requirements the FDA judged ISO 13485 did not cover adequately on its own.

Service organizations have a traceability obligation too, and it is usually easier to meet than to notice: who performed the work, when, against which version of the specification, and who reviewed it. Where that chain is held only in an email thread, the production and service provision procedure has no traceability regardless of what the document claims. Where records live and who owns them belongs in document and records control, and a production and service provision procedure written without reference to it produces evidence nobody can retrieve.


Property and preservation

Customer property and preservation in a production and service provision procedure

Guard. Protect. Report.

Clause 8.5.3 covers property belonging to customers or external providers while it is under the organization's control: identify it, verify it, protect and safeguard it, and report loss, damage or unsuitability to the owner. ISO 13485 carries the same obligation at Clause 7.5.10.

The sleeper in this clause is the sentence most procedures leave out. Customer property includes intellectual property and personal data. A design file held under NDA, a customer list loaded into a system, a patient record, a set of credentials issued for an integration — all of it is customer property in the sense the clause means, and all of it is subject to the same identify, protect, report obligations as a crate of castings.

For any organization delivering service, that single sentence usually expands the scope of its production and service provision procedure more than any other requirement in Clause 8.5. It is also the point where operational control meets information security, which MSI treats directly in its work on medical device cybersecurity — noting that MSI does not implement ISO 27001, and that the management system foundation is what an information security system plugs into rather than a substitute for it.

Clause 8.5.4 then requires preservation of outputs during production and service provision to the extent necessary to maintain conformity — identification, handling, contamination control, packaging, storage, transmission and protection. ISO 13485 Clause 7.5.11 states it explicitly and adds cleanliness of product at Clause 7.5.2, along with particular requirements for sterile devices. The word worth pausing on in the ISO 9001 text is transmission: preservation applies to information in transit, not only to goods in a warehouse. Data integrity, backup, and version control are preservation controls, and a production and service provision procedure covering intangible output should say so.


After it ships

Post-delivery activities most production and service provision procedure documents stop short of

Install. Service. Learn.

Clause 8.5.5 requires the organization to meet requirements for post-delivery activities, and it tells you how to decide how far those extend: statutory and regulatory requirements, the potential undesired consequences associated with the products and services, the nature, use and intended lifetime of what was delivered, customer requirements, and customer feedback. Most procedures reproduce that list. Few use it to reach a conclusion.

Reaching a conclusion is the point. A production and service provision procedure should name which post-delivery activities are in scope for this organization — warranty work, field service, technical support, recycling and disposal obligations, decommissioning — and treat each as a controlled process with its own competence requirements, records and feedback path. Where an organization performs installation or servicing, ISO 13485 makes this explicit at Clauses 7.5.3 and 7.5.4, and requires servicing records to be analyzed as a potential source of complaint and reporting obligations.

The feedback path is the part with the most value and the least attention. Post-delivery data is the only place an organization learns what its process actually produced once the customer used it, and it is an input to risk, to design, and to management review. A production and service provision procedure that ends at the loading dock ends one step before the information that would improve it. Translating that loop into something a leadership team can act on is a large part of what experienced ISO consulting is for.


Change

Control of changes: where a production and service provision procedure breaks quietly

Review. Authorize. Record.

Clause 8.5.6 requires the organization to review and control changes for production or service provision to the extent necessary to ensure continuing conformity, and to retain documented information describing three things: the results of the review, the persons authorizing the change, and any necessary actions arising. Most procedures retain the first. Rather fewer retain the second. The third is retained almost nowhere.

That matters because the third item is the one that closes the loop. A change reviewed and authorized but not traced through to its consequences — the revalidation it triggered, the work instruction it obsoleted, the training it required, the fixture it made wrong — is a change that has been approved rather than controlled. A production and service provision procedure should treat those consequences as a named checklist inside the change record, not as something the reviewer is trusted to remember.

The change that damages a system is rarely the one that went through the process. It is the temporary one that did not, and then stayed.

Temporary change is the specific gap. A workaround introduced on a Friday because a fixture broke, intended to last one shift, still running six weeks later and now taught to new starters as the method. ISO 45001 is the only one of the five standards to confront this directly: Clause 8.1.3 covers management of change including temporary changes, and requires review of the consequences of unintended changes with action taken to mitigate adverse effects. Borrowing that requirement into a production and service provision procedure written for any of the other four is one of the highest-value additions available, and it costs a paragraph.

The other interface runs to validation. Any change to equipment, material, parameters or specification is a revalidation trigger, and the change record is where that determination should be made and recorded rather than left to be noticed later. MSI's coverage of change management workflow works through what that looks like when the routing is automated rather than remembered.


Release

Who holds release authority in your production and service provision procedure?

Verify. Authorize. Ship.

Clause 8.6 is short and consequential. Implement planned arrangements at appropriate stages to verify that requirements have been met. Do not release to the customer until those arrangements have been satisfactorily completed, unless otherwise approved by a relevant authority and, where applicable, by the customer. Retain evidence of conformity with the acceptance criteria, and traceability to the person or persons authorizing release.

Two phrases in that requirement carry most of the weight, and a production and service provision procedure that does not resolve both has left the most consequential decision in the process undefined.

  • “Traceability to the person authorizing release.” Not the department. Not the system. A named person, identifiable from the record. Where release is performed by a system on a rule, the rule's owner is the authority and the record has to say so.
  • “Unless otherwise approved by a relevant authority.” This is the concession route, and it is the most abused sentence in Clause 8. Left undefined it becomes a standing permission for anyone senior enough to release anything. A production and service provision procedure should name who holds concession authority, what the concession record must contain, what categories of nonconformity can never be released on concession, and whether customer approval is required — which for many regulated and contractual situations it is.
Direct Answer: A production and service provision procedure must name who holds release authority, what evidence they release against, and what the concession route looks like when release proceeds despite an incomplete verification. ISO 9001 Clause 8.6 requires retained evidence of conformity with acceptance criteria plus traceability to the individual authorizing release. Naming a department rather than a role, and leaving the concession route undefined, are the two most common defects in this clause.

For medical devices, release carries additional regulatory weight. ISO 13485 requires that product release and service delivery not proceed until planned arrangements are completed, and that records identify the person authorizing release. The QMSR adds device-specific obligations on top of the incorporated standard — the scope provision at 21 CFR 820.1 sets out how those requirements govern the methods, facilities and controls used in manufacture, packaging, labeling, storage and installation, and labeling accuracy must be inspected before release.


Environment and safety

What ISO 14001 and ISO 45001 add to a production and service provision procedure

Eliminate. Engineer. Extend.

Both environmental and occupational health and safety management place this requirement at Clause 8.1, operational planning and control, and both express it the same way: establish criteria for the processes, and control the processes in accordance with those criteria. That phrasing changes the shape of the document. A quality-side production and service provision procedure tends to be step-led — do this, then this, verify here. An environmental or safety one is criteria-led: here is the condition that must hold, here is what happens when it does not.

ISO 45001 adds three things the quality standards do not

  • The hierarchy of controls, Clause 8.1.2. Eliminate, substitute, engineer, then administrative controls, then personal protective equipment. The order is a requirement, not a preference, and a control selected out of order needs a documented reason. NIOSH sets out the same hierarchy and the reasoning behind it — the upper tiers work without depending on human behavior, which is precisely why they rank higher.
  • Procurement, contractors and outsourcing, Clause 8.1.4. The organization has to coordinate with contractors on hazards arising from their activities, and control outsourced functions that affect the management system. This is the most consistently under-built part of a safety production and service provision procedure, and the interface runs straight into purchasing and supplier control.
  • Emergency preparedness and response, Clause 8.2. Sitting alongside operational control rather than inside it, and requiring planned response, periodic testing and revision after testing or after an actual event.

ISO 14001 extends the reach rather than the detail

The environmental requirement is thinner in prescription and wider in scope. Control extends to outsourced processes, and the lifecycle perspective pulls in procurement specifications, design decisions, delivery, use and end-of-life treatment. ISO 14001:2026 published on April 15, 2026, with a 36-month transition closing around April 2029, and it sharpens the demonstration of environmental performance rather than the commitment to it — which lands directly on operational control, because performance is what controlled processes produce. MSI's combined ISO 9001 and ISO 14001 transition guidance treats the two revisions as one project, and its work on ISO 14001:2026 Clause 4.1 traces how context findings are expected to link through to the controls in Clause 8.

One structural note worth carrying into any multi-standard build: certification and accreditation oversight changed at the start of this year. Global ACI assumed the former roles of the International Accreditation Forum and the International Laboratory Accreditation Cooperation with effect from January 1, 2026, so references in older procedures and transition plans to IAF or ILAC guidance now point at bodies that no longer hold those functions.


Healthcare

ISO 7101 Clause 8.9 and the production and service provision procedure for healthcare

Safe. Effective. Timely.

ISO 7101:2023 was the first international consensus standard for healthcare quality management, and it places service provision at Clause 8.9 with a deceptively familiar instruction: define the controlled conditions needed to deliver services that are safe, effective and timely. A quality professional reading that sentence recognizes Clause 8.5.1 immediately.

What makes a healthcare production and service provision procedure genuinely different is not Clause 8.9 itself. It is what sits beside it. People-centered care at Clause 8.10 asks the organization to assess service-user experience, foster inclusivity, support health literacy, co-produce services with the people receiving them, and address workforce wellbeing. Ethics at Clause 8.11 requires processes to identify, investigate and resolve ethical dilemmas. Patient safety at Clause 8.12 applies across every setting in which services are delivered.

No manufacturing procedure has ever had to define a controlled condition for dignity, for co-production with the person receiving the output, or for the escalation of an ethical dilemma. A healthcare production and service provision procedure that is adapted from a factory template will be silent on all three, and the silence will not be obvious from the document.

That is the practical argument against adaptation. The controlled conditions in Clause 8.9 map cleanly enough — documented care pathways, competent and authorized clinicians, suitable environment and equipment, monitoring at defined points, and a defined handoff — but the surrounding obligations have no equivalent to inherit from. They have to be written. MSI's expanding work on ISO 7101 sits alongside its established ISO 13485 medical device practice, and the two are frequently confused: one governs the organization delivering care, the other the organization making the device used in it.


Interfaces

Where a production and service provision procedure connects to the rest of the system

Connect. Feed. Close.

A production and service provision procedure written in isolation produces a document that is internally coherent and externally disconnected. Six interfaces carry most of the load, and each one is a place where a requirement is either handed off cleanly or dropped between two owners.

  • Risk. Process risk determines how much control is proportionate, which steps get designed error prevention, and which processes get validated. MSI's risk management procedure guidance covers the criteria-setting that this procedure then consumes.
  • Purchasing. Outsourced processes remain the organization's responsibility, and contractor activity is explicitly in scope under ISO 45001. Purchasing and supplier control is where the provider is evaluated; this procedure is where their output enters the work.
  • Monitoring and measuring equipment. The verification steps this procedure requires are only as good as the instruments performing them. Control of monitoring and measuring equipment owns calibration, status and the impact decision when something is found out of tolerance.
  • Documents and records. Every record this procedure creates needs a location, an owning role and a retention period, set in document and records control. A record with an undetermined location reads, to anyone examining it, as a decision that was never made.
  • Internal audit. This process is audited by walking, not by reading. The document and the floor are two different objects and only one of them makes product. MSI's internal audit work schedules it as a floor activity for that reason.
  • Management review. Scrap and rework rates, validation status, concession volume, post-delivery findings and error-prevention verification results are all leadership-grade inputs. Presented as data they drive decisions; presented as impressions they drive nothing.

Two of MSI’s courses produce this documentation directly rather than supplying it. Catch. Correct. Continually Improve. builds the risk, nonconformity, corrective action and continual improvement procedures together — the four that most often get written in isolation and then found, at the third surveillance visit, not to talk to each other. The Design and Development video series covers the clause most organizations postpone, because the procedure has to describe work that is genuinely different every time.

The reach is wider than most organizations expect. A production and service provision procedure touches competence records, infrastructure and maintenance, nonconformity and corrective action, customer communication, and the process interaction map itself. That breadth is why it is usually the last procedure an organization writes properly and the first one an experienced auditor opens.


Two worked examples

What a weak production and service provision procedure looks like in practice

Observe. Diagnose. Correct.

One — the organization that believed Clause 8.5 did not apply to it

An engineering services business, thirty-odd staff, delivering design and analysis work under contract. Certified for years. Its production and service provision procedure ran to a page and a half and opened with a scope statement explaining that as the organization did not manufacture, production controls were not applicable; service provision was governed by project management. Nobody had challenged it, because the document was internally consistent and the sentence sounded reasonable.

Read against the clause, almost every controlled condition was in fact missing rather than inapplicable. There was no documented statement of the characteristics of the output or the results to be achieved — briefs varied by project manager. Verification happened once, at the end, which is final inspection by another name. Reviewer authorization was implied by seniority rather than defined. No process was validated, although no deliverable could be verified before the client used it. Status was invisible: a model awaiting check and a model signed off lived in the same folder, distinguished by a filename convention people mostly followed.

The correction was not a bigger document. It was six decisions: a defined output specification per project class, verification at named stages rather than at the end, named reviewer authorization by class, a validated review process with defined acceptance criteria, a visible status control, and a records table with no blanks. The production and service provision procedure grew by four pages and the rework rate moved because the checks moved earlier, not because anyone worked harder.

Two — the workaround that became the process

A manufacturer, mid-size, with a validated assembly process and a locating fixture that made a critical orientation error physically impossible. The fixture cracked on a Friday. The supervisor authorized a temporary method — a scribed line and a visual check — to finish the order. Entirely defensible for one shift.

Seven weeks later the fixture had not been replaced, the temporary method was being taught to new starters as the way the job is done, and the validated process existed only in the binder. Nothing in the system had raised it. The temporary change had no record because the production and service provision procedure had no route for temporary changes. The validated status had not been revisited because nobody had classified a broken fixture as a process change. And the error prevention that had been designed into the work had been replaced by an instruction to be careful, which is the definition of moving down the hierarchy of controls without a decision.

Both examples share one structure. Nothing was hidden and nobody was negligent. In each case a requirement had no owner, no trigger and no record — so the system had no mechanism for noticing. That is what a weak production and service provision procedure produces: not misconduct, but an absence of the thing that would have raised its hand.

The eight elements

How to score your own production and service provision procedure

Score. Prioritize. Fix.

Scoring element by element is more useful than reaching a single verdict, because almost no organization is uniformly weak. Most are strong on documented conditions and weak on error prevention, or strong on traceability and weak on change control — and knowing which one changes what happens on Monday.

Each element scores across four levels, described as observable behavior rather than intention: Documented, Controlled, Measured, Anticipatory. Controlled is a legitimate place to stop. A well-implemented certified system sits there, and an assessment that fails everyone is not an assessment. The point of the ladder is to show you the rung above the one you are on, not to imply that anything below the top is a deficiency.

  1. Controlled conditions. Are they defined specifically enough to act on, or carried over from the standard's conditional language?
  2. Competence and authorization. Is competence expressed as authorization to perform the work, or as a training record?
  3. Validation and revalidation. Are unverifiable processes identified and validated, and does revalidation trigger on named events rather than on a calendar alone?
  4. Human-error prevention. Are error opportunities named, prevented by design where possible, and the prevention itself verified?
  5. Identification, status and traceability. Is inspection status a control rather than a label, and is the traceability reach a documented decision?
  6. Preservation and property. Does preservation cover information in transit, and does customer property include intellectual property and personal data?
  7. Change control. Are temporary changes routed, and are consequential actions traced through rather than trusted to memory?
  8. Release. Is release authority held by a named role, and is the concession route defined and bounded?
Direct Answer: Score a production and service provision procedure across eight elements — controlled conditions, competence and authorization, validation and revalidation, human-error prevention, identification and traceability, preservation and property, change control, and release authority. Element-level scoring identifies the two or three worth fixing first, which is a more useful output than a single overall verdict.

Where to go next

Find the element holding your score down

Score. Fix. Build.
Free · about six minutes
Production, Service and Operational Control Maturity Check

Eighteen questions on a single-standard path, twenty-one if you run more than one. Score against a pressured Thursday afternoon rather than against what the procedure says. Your band and your weakest element appear immediately, before you enter anything — the element-by-element breakdown and the framework PDF are what the form unlocks.

Go →

The procedures themselves
ISO Procedure Templates and Guides

Complete, editable Word procedures written as working documents rather than outlines — with the judgment calls already made and explained, bracketed placeholders only where a value is genuinely yours to set, and the same eight-element maturity ladder the check scores against. Every procedure follows the same sixteen-section architecture, so adopting one teaches your people how to read the next. Written to each standard's own clauses rather than adapted from another — and purchasers receive the updated template at no charge when the standard it is built to is revised, which matters with ISO 9001:2026 expected in September.

Go →

Training
QMS Interviews

The skill this procedure depends on: getting an accurate account of how the work actually runs from the people running it. A procedure written from what the last auditor was told will describe a process nobody follows.

Go →

Free leadership training
Watch the ISO Executive Decision Briefs

Short executive-level videos for leaders deciding whether to pursue certification, which standards apply, and what the commitment actually involves. Built for the person approving the project rather than the person running it.

Go →

If the result surprises you, a conversation is usually quicker than a rewrite. MSI has supported 80+ certifications across 28 years and 200+ certification and surveillance audits attended. A planning session will tell you whether a low element is a real exposure or a recording gap — call 760-434-9141. Where the question is how the process actually behaves rather than how the document describes it, The Portrait is an independent read on the difference.

Common questions

production and service provision procedure: frequently asked questions

Ask. Answer. Apply.

What is a production and service provision procedure?

A production and service provision procedure is the documented process describing the controlled conditions under which product is made or service is delivered, verified and released. It covers what is being produced and to what criteria, monitoring and measurement at defined stages, infrastructure and environment, competent and authorized people, validation where output cannot be verified afterwards, actions to prevent human error, identification and traceability, preservation, change control and release authority.

Which ISO standards require a production and service provision procedure?

ISO 9001 at Clauses 8.5 and 8.6, ISO 13485 at Clause 7.5, ISO 14001 and ISO 45001 at Clause 8.1 operational planning and control, and ISO 7101 at Clause 8.9 provision of services. The requirement is common to all five, but the structure and level of prescription differ substantially between them.

Is a documented production and service provision procedure mandatory?

ISO 9001 requires documented information to the extent necessary to have confidence the processes are carried out as planned, rather than naming a mandatory procedure document. ISO 13485 is more prescriptive and requires documented procedures across much of Clause 7.5. In practice, an organization of any complexity cannot demonstrate the controlled conditions without a documented production and service provision procedure, and auditors will look for one.

Does ISO 9001 Clause 8.5 apply to service organizations?

Yes. Clause 8.5 is written to cover production and service provision in the same words throughout. A service organization that treats the clause as manufacturing-only typically finds, on examination, that the controlled conditions are missing rather than inapplicable — particularly validation, since service output usually cannot be verified before the customer experiences it.

What does “actions to prevent human error” mean in practice?

It means designing the process so that a competent person cannot easily make a foreseeable mistake, rather than instructing them to be careful. Fixtures that accept a part one way only, fields that will not submit without a value, interlocks, physical stops and color coding are prevention. Operator training addresses competence under Clause 7.2 and does not satisfy this requirement on its own.

When does a process have to be validated?

Whenever the resulting output cannot be verified by subsequent monitoring or measurement — including, for medical devices, where deficiencies would only become apparent after the product is in use. Welding, sterilization, molding and sealing are the usual examples, but the test is the requirement, not the list. Most service delivery processes meet it.

How much traceability does a production and service provision procedure need?

Only as much as is genuinely required — but the reach, direction and granularity should be a documented decision rather than an accident. Medical devices have the choice largely made for them through ISO 13485 Clauses 7.5.8 and 7.5.9 and, in the United States, unique device identification and device tracking obligations carried through the QMSR.

Can one procedure cover ISO 9001, ISO 13485, ISO 14001, ISO 45001 and ISO 7101?

It can, provided the standard-specific requirements are written as their own sections rather than averaged away. Roughly seventy percent of a multi-standard production and service provision procedure is common. The remaining thirty percent — device validation and traceability, the hierarchy of controls and contractor coordination, lifecycle and outsourcing reach, service-user and patient-safety obligations — is where the value sits and where single-standard templates quietly leave gaps.


Related reading

Adjacent procedures and guidance

Read. Compare. Build.
The seven marks that separate a procedure people use from one they work around.
The instruments behind every verification step this procedure requires.
Where outsourced processes and contractor activity are evaluated before they reach the work.
Where every record this procedure creates has to live, and who owns it.
The criteria that determine how much control is proportionate to each process.
How the shared spine and the standard-specific layers fit together across all five.

References and primary sources

About Management Systems International (MSI)

Diana Lynn, President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI’s early years, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

msi-international.com  ·  760-434-9141

Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 13 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply