ISO 9001 Clause 5.3 Explained: Roles, Responsibilities and Authorities
Who is responsible for what?
When people do not clearly understand their responsibilities, things can quickly fall through the cracks.
Who approves suppliers? Who investigates customer complaints? Who carries out internal audits? Who monitors quality objectives? And who has the authority to stop work when there is a quality problem?
If nobody knows the answer – or everyone assumes somebody else is responsible – your QMS is going to struggle.
In this instalment of our ISO 9001 Explained series, we break down ISO 9001 Clause 5.3 in plain English. We’ll look at organisational roles, responsibilities and authorities, the difference between responsibility and authority, common mistakes organisations make and what an ISO 9001 auditor is likely to look for.
What is ISO 9001 Clause 5.3?
ISO 9001 Clause 5.3 covers organisational roles, responsibilities and authorities within the Quality Management System.
In plain English, ISO 9001 expects people within your organisation to understand:
- what they are responsible for;
- what decisions they have the authority to make;
- what they are accountable for; and
- who has responsibility for ensuring the QMS continues to perform effectively.
This does not mean every employee needs a complicated, multi-page job description.
It does mean responsibilities and authorities need to be assigned, communicated and understood.
When responsibilities are unclear, tasks get missed, decisions are delayed and problems remain unresolved. Eventually, customers notice.
ISO 9001 Clause 5.3: Responsibility vs authority
One of the most important elements of ISO 9001 Clause 5.3 is understanding the distinction between responsibility and authority.
Giving somebody responsibility for achieving something does not necessarily mean you have given them the authority required to achieve it.
Why responsibility and authority matter under ISO 9001 Clause 5.3
Imagine a manager is given responsibility for improving delivery performance.
To achieve that objective, they might need to:
- authorise overtime;
- change production schedules;
- arrange additional training;
- purchase equipment; or
- make changes to operational processes.
If they are held responsible for improving delivery performance but cannot authorise any of these actions, do they really have sufficient authority to achieve the result?
Probably not.
Responsibility without appropriate authority often leads to frustration and poor performance.
ISO 9001 Clause 5.3 therefore requires organisations to consider both sides of the equation. People should understand what they are expected to achieve and have appropriate authority to fulfil their responsibilities effectively.
A practical ISO 9001 Clause 5.3 example
Consider something relatively common: a customer submits a complaint about a faulty product.
Several questions immediately arise.
Who investigates the complaint? Who decides whether affected products should be quarantined? Who approves corrective action? Who communicates with the customer?
In an organisation with clearly established roles and responsibilities, the process can begin immediately.
The relevant people understand what they need to do, what decisions they can make and when an issue needs to be escalated.
Now consider an organisation where those responsibilities are unclear.
The complaint arrives in someone’s inbox. They assume somebody else is dealing with it. Another employee believes the Quality Department owns the entire issue. Nobody is sure who can quarantine the product or approve the corrective action.
Meanwhile, the customer waits.
That delay can quickly undermine customer confidence.
This is exactly the type of confusion ISO 9001 Clause 5.3 is designed to prevent.
ISO 9001 Clause 5.3 and the management representative
One of the notable changes introduced with ISO 9001:2015 was the removal of the specific requirement to appoint a management representative.
If you worked with earlier versions of ISO 9001, you might remember this role. One person was often appointed as the organisation’s management representative and, in practice, could become known as the “ISO person”.
ISO 9001:2015 no longer specifically requires organisations to appoint somebody to that position.
That does not mean you cannot have a Quality Manager, QMS Manager or another person responsible for coordinating elements of your management system.
You absolutely can.
ISO 9001 Clause 5.3 and leadership accountability
The important distinction is between delegating activities and delegating accountability.
Top management can allocate responsibilities and delegate individual QMS activities, but leadership remains accountable for the effectiveness of the Quality Management System.
In other words, ISO 9001 should not become something leadership simply hands over to the Quality Manager.
Quality needs to be integrated into how the organisation is managed.
Common ISO 9001 Clause 5.3 mistakes
One of the most common problems with ISO 9001 Clause 5.3 is assuming everyone already knows what their responsibilities are.
Senior management might believe responsibilities are obvious. However, ask several employees questions such as:
- Who approves new suppliers?
- Who updates controlled documents?
- Who reviews quality objectives?
- Who approves corrective actions?
- Who can stop work when a quality problem is identified?
You may receive very different answers.
That inconsistency is a warning sign.
Giving responsibility without authority
Another common ISO 9001 Clause 5.3 mistake is giving someone responsibility without sufficient authority.
For example, an employee might be told they are responsible for improving quality performance while having little or no influence over training, equipment, resources or processes.
They are effectively being held accountable for an outcome without being given the means to influence it.
That is why clearly defining both responsibilities and authorities is so important.
How ISO 9001 Clause 5.3 can improve teamwork
Clearly defining responsibilities does not mean creating organisational silos or encouraging people to say, “That’s not my job.”
In fact, the opposite can be true.
Organisations with clearly understood responsibilities can often respond to problems more quickly because people do not waste time determining who owns an issue.
Everyone understands their role within the wider process.
People can still collaborate across departments and functions, but there is clarity over ownership, decision-making and escalation.
ISO 9001 Clause 5.3 can therefore support teamwork by removing uncertainty about who is responsible for what.
What will an auditor look for under ISO 9001 Clause 5.3?
An ISO 9001 auditor may not immediately ask to see your organisation chart or everybody’s job description.
Instead, they are likely to test whether responsibilities and authorities are actually understood.
That often means talking directly to employees.
ISO 9001 Clause 5.3 audit questions
An auditor might ask questions such as:
“Can you describe your role?”
“What are you responsible for?”
“What would you do if you identified a quality problem?”
“Who has the authority to stop work if something isn’t right?”
“Who is responsible for approving this?”
They may then ask similar questions elsewhere in the organisation.
The objective is to determine whether organisational roles, responsibilities and authorities have been assigned, communicated and understood consistently.
If three people give three completely different answers about who owns the same process, that may indicate a weakness in the system.
Does ISO 9001 Clause 5.3 require job descriptions?
Not necessarily.
ISO 9001 Clause 5.3 does not specifically require every employee to have a formal job description.
Job descriptions can certainly be useful, but they are only one way of communicating responsibilities and authorities.
Depending on your organisation, you might use:
- organisation charts;
- process maps;
- procedures;
- responsibility matrices;
- competency matrices;
- role profiles;
- workflow systems; or
- documented authorities and approval levels.
You might also use a combination of these approaches.
The important point is not the format.
What matters is whether people genuinely understand their responsibilities and authorities.
Creating paperwork purely to demonstrate compliance misses the point. An impressive folder of job descriptions achieves very little if employees themselves are unclear about who does what.
How to demonstrate conformity with ISO 9001 Clause 5.3
A useful starting point when assessing conformity with ISO 9001 Clause 5.3 is to look at your key QMS processes and ask three simple questions:
Who owns this? Who carries it out? Who has the authority to make the necessary decisions?
Consider areas such as:
- supplier approval;
- document control;
- customer complaints;
- nonconforming outputs;
- corrective actions;
- internal audits;
- quality objectives; and
- management review.
Then check whether the answers are understood consistently.
Don’t only ask senior management.
Speak to the people actually carrying out the work.
If management says one person is responsible for a process but employees believe responsibility sits somewhere else, you have identified an opportunity to improve your QMS before an auditor does.
ISO 9001 Clause 5.3: Key takeaways
There are four important points to remember from ISO 9001 Clause 5.3.
1. People need to understand their responsibilities
Everyone should know what they are expected to do within the QMS and where their responsibilities begin and end.
2. Responsibility needs appropriate authority
If somebody is expected to deliver an outcome, they need sufficient authority to carry out their responsibilities effectively.
3. Leadership can delegate activities, but not accountability
Top management remains accountable for the effectiveness of the QMS, even when specific responsibilities and activities are assigned to other people.
4. Clear responsibilities create consistency
When people understand who owns what, problems can be addressed faster and important activities are less likely to fall through the cracks.
Final thoughts on ISO 9001 Clause 5.3
ISO 9001 Clause 5.3 completes the leadership requirements covered by Clause 5 of ISO 9001.
Across Clauses 5.1, 5.2 and 5.3, there is a consistent message: leadership is not simply about approving documents or attending management reviews.
It is about taking ownership of the Quality Management System, establishing an appropriate Quality Policy and ensuring people throughout the organisation understand the part they play in delivering quality.
For ISO 9001 Clause 5.3 specifically, the principle is straightforward:
Clear responsibility creates consistency. Confusion creates mistakes.
Take a look around your own organisation. If you asked several employees who owns your key quality processes, would they all give you the same answer?
Next in our ISO 9001 Explained series, we move into Clause 6: Planning, beginning with ISO 9001 Clause 6.1 – Actions to Address Risks and Opportunities.
Share
Book a Free Consultation Consultation Consultation Consultation
Get free advice and guidance tailored to your business needs
Related Resources
ISO 9001 Clause 5.2: Quality Policy Explained
ISO 9001 Clause 5.2: How to Create a Quality Policy That Works Welcome back to our ISO 9001 Explained series. In the previous article, we

ISO 9001 Clause 5.1 Explained: Leadership and Commitment Made Simple
ISO 9001 Clause 5.1 Explained: Why Leadership Owns Quality – Not the Quality Manager Many organisations proudly display signs declaring that “Quality is Our Number
Book a Free Consultation Consultation Consultation Consultation
Get free advice and guidance tailored to your business needs