Last updated 6 October 2026
ISO 14001:2026 requires ten items to be available as documented information: scope, policy, planning processes, aspects with criteria and significant aspects, compliance obligations, risks and opportunities, objectives, operational processes, emergency processes and the audit programme. It requires evidence of seven more: competence, communications, monitoring results, compliance evaluation, audit implementation and results, management review results, and nonconformities with corrective actions.
A new SHEQ manager at a juice plant once sent me her document list the week before a stage 1 audit. Four lever-arch files of procedures, a manual that ran to eighty pages, and a document register in perfect order. There was no list of significant aspects anywhere in it, and no compliance evaluation record either. She had plenty of paper and was missing two of the things the standard actually asks for.
Know exactly what your system needs with ISO 14001:2026 Understanding and Implementation. You build every required item for your own site, from the context register to the management review pack, in about 24 hours of self paced study. R4 800.
What changed in documented information wording in ISO 14001:2026?
The old “maintain documented information” is now “available as documented information”, and “retain documented information as evidence” is now “available as evidence of”. Annex A.3 confirms the intent has not changed.
Most practitioners still think in documents and records, and that is fine. “Available as documented information” covers what we used to call documents: things you keep current. “Available as evidence of” covers what we used to call records: proof that something happened. Annex A.3 explains that “available” means the organisation can obtain, use or provide the information, and that “evidence” here is not a legal test.
Annex A.2 adds that you do not have to adopt the standard’s terms. If your site calls them procedures and records, keep calling them that. You do not need to rename a single file to move to the 2026 edition.
What must be available as documented information?
Ten items, listed below by clause. Three of them, the processes in 6.1.1, 8.1 and 8.2, are required only to the extent needed to have confidence that the processes are carried out as planned.
| Clause | What must be available | Note |
|---|---|---|
| 4.3 | The scope of the environmental management system | Also available to interested parties |
| 5.2 | The environmental policy | Also communicated within the organisation and available to interested parties |
| 6.1.1 | The processes needed to meet 6.1.2 to 6.1.5 | To the extent necessary for confidence |
| 6.1.2 | Environmental aspects and associated impacts, the criteria used to determine significance, and the significant environmental aspects | Three things, often held in one register |
| 6.1.3 | Compliance obligations | Usually the legal register |
| 6.1.4 | The risks and opportunities that need to be addressed | Now its own sub-clause in 2026 |
| 6.2.1 f) | Environmental objectives | Now listed as item f) |
| 8.1 | The operational planning and control processes | To the extent necessary for confidence |
| 8.2 | The emergency preparedness and response processes | To the extent necessary for confidence |
| 9.2.2 | The internal audit programme or programmes | The programme itself is now required, a 2026 change |
The audit programme line is the one sites upgrading from 2015 miss. In 2015 you had to keep evidence that the programme was implemented. In 2026 the programme itself must be available too, and clause 9.2.2 a) asks for objectives, criteria and scope for each audit.
What evidence must be available?
Seven kinds of evidence, which most people still call records. These are the proof an auditor samples to see whether the system works.
| Clause | Evidence of | Typical examples on a food site |
|---|---|---|
| 7.2 | Competence | Training records, qualifications, assessments for the boiler attendant, effluent operator and internal auditors |
| 7.4.1 | Communications, as appropriate | Replies to a neighbour’s complaint, reports sent to the municipality |
| 9.1.1 | Monitoring, measurement, analysis and evaluation results | Effluent lab results, water and energy readings, trend analysis |
| 9.1.2 | Compliance evaluation results | Signed evaluations with findings and actions |
| 9.2.2 | Implementation of the audit programme and the audit results | Audit plans, reports, findings |
| 9.3.3 | Results of management reviews | Minutes covering conclusions, decisions and actions |
| 10.2 | Nature of nonconformities, actions taken and results of corrective action | Nonconformity and corrective action log with root cause and effectiveness check |
Then there is 7.5.1 b): any other documented information you decide is necessary for the system to be effective. That is your call, and Annex A.7.5 lists reasons to add more: transparency, accountability, continuity, training and auditing. Retention should also be consistent with your compliance obligations.
Build all seventeen items for your own site, checked against model answers as you go. Enrol in ISO 14001:2026 Understanding and Implementation: 6 modules and a three-sitting workshop, about 24 hours on your phone, R4 800 all in.
Do you need procedures or an environmental manual?
No manual. Annex A.7.5 says one is not needed. Written procedures are needed only where your planning, operational and emergency processes would not be carried out as planned without them.
That “to the extent necessary” wording in 6.1.1, 8.1 and 8.2 gives you room. A CIP dump at a ready meals plant, done by rotating night shift cleaners, probably needs a written operating criterion at the point of use. A forklift battery change done by one trained technician might not. Decide on the basis of risk, the competence of the people and how often the task changes hands. The 7.5.1 NOTE says the same: the extent of documented information depends on size, activities, complexity, the need to show compliance, and competence.
On a combined site, use what you already have. Annex A.4.4 allows processes and documented information from other functions or a parent company to be used. Your FSSC 22000 document control, competence records and corrective action log can carry the environmental items too.
How must documented information be controlled?
Clause 7.5.2 covers creating and updating it: identification, format and media, and review and approval. Clause 7.5.3 covers control: available and suitable where and when needed, adequately protected, with distribution, access, storage, version control, retention and disposition addressed as applicable.
Two parts of 7.5.3 trip sites up. The first is documents of external origin. Your trade effluent permit, Atmospheric Emission Licence, water use authorisation and the refrigeration plant manufacturer’s manual are all documented information of external origin needed for the system. They must be identified and controlled. I have audited sites with immaculate internal procedures and a trade effluent permit that had expired in a drawer.
The second is legibility and preservation. A spill kit checklist that lives on a clipboard in a wet area is documented information. If the ink runs, it is not available. Paper or electronic both work under 7.5.2 b). Choose what survives where it is used.
Not sure which ISO 14001 course fits your job? WhatsApp ASC on +27 61 483 0381.
How do you build your documented information list, step by step?
Start from the seventeen required items, add what your site needs, and give each one an owner, a location and a retention rule. One master list is enough.
- Copy the ten “available as documented information” items and the seven “available as evidence of” items into a master list, each against its clause.
- For each item, write where it lives today and who owns it. Gaps will show at once.
- Add your documents of external origin: permits, licences, authorisations, contracts and manufacturer manuals.
- Add the 7.5.1 b) items you decide you need, such as operating criteria at critical points or a monitoring plan.
- Set retention for each type, consistent with your compliance obligations and your certification cycle.
- Decide access: who can view and who can change. The 7.5.3 NOTE allows both.
- Test it. Pick three items and ask the owner to produce them within five minutes. That is what the auditor will do.
For the order in which these items get built, read how to implement ISO 14001:2026. Sites already certified to 2015 can check their file against preparing for your ISO 14001:2026 transition audit, and internal auditors can test it with the ISO 14001:2026 internal audit checklist. The full course ladder is on the ISO 14001 training hub.
Frequently asked questions
Does ISO 14001:2026 still use maintain and retain?
No. The 2026 edition says “available as documented information” where 2015 said maintain, and “available as evidence of” where it said retain. Annex A.3 confirms the intent has not changed.
Do I need to rename my documents and records for ISO 14001:2026?
No. Annex A.2 says you do not have to adopt the standard’s terms, so you can keep calling them procedures, records and documentation.
Is an environmental manual required by ISO 14001?
No. Annex A.7.5 says no manual is needed. You need the documented information the clauses require, plus anything else you decide is necessary under clause 7.5.1 b).
How long must ISO 14001 records be kept?
The standard sets no retention period. Set retention under clause 7.5.3 and keep it consistent with your compliance obligations, which may set their own periods.
Does ISO 14001 documented information have to be electronic?
No. Clause 7.5.2 b) allows paper or electronic media. What matters is that it is available where needed, protected and controlled under clause 7.5.3.
What new documented information does ISO 14001:2026 require?
The internal audit programme itself must now be available as documented information under clause 9.2.2. Risks and opportunities to be addressed now sit in their own sub-clause, 6.1.4, and most other items carry over from 2015 with new wording.
Which ASC course builds your documented information with you?
ISO 14001:2026 Understanding and Implementation builds every required item with you, on your own site, from scope and policy through the registers to the audit programme and management review pack. You leave with a system an auditor can sample in five minutes.
R4 800, one payment. No VAT is charged, so the price shown is the price paid. Teams of five or more: contact ASC for a team rate.
- You finish with your context and environmental conditions register, interested party register, aspects register, compliance obligations register and risk and opportunity register
- Plus objectives, change record, emergency plan, monitoring plan, audit programme and management review pack
- Module 4 covers documented information, operational control, externally provided processes and emergency preparedness
- 6 modules, 67 lessons and workshop sittings, about 24 hours, on phone or laptop
- All activities marked automatically the moment you submit, pass mark 70 percent
- ASC certificate of completion naming the course, code and date, with a verification code
- Is it for me? Yes if you run, build or upgrade the system: SHEQ, QA and environmental managers, EMS coordinators and consultants.
- How long does it take? About 24 hours in short lessons, three workshop sittings and a final assessment.
- Will it work at my site? Yes. Work on your own site, or on one of three case sites built from real audit patterns.
Upgrading a 2015 file? Transition to ISO 14001:2026 (R1 950) sorts every change into no action, confirm or build. Auditing the file? ISO 14001:2026 Internal Auditor is R3 850 on a limited period special. Staff awareness: Introduction to ISO 14001:2026 (R1 495).
ISO 14001 is copyright and is not reproduced here. ASC is not affiliated with ISO.
Sources
- ISO 14001:2026, Environmental management systems, ISO
- ISO 19011:2026, Guidelines for auditing management systems, ISO
- National Water Act 36 of 1998