ISO9001 System Document Package (11) | Knowledge Management Procedure (7.1.6)
Document Description: This document is the implementation procedure for clause 7.1.6 "Organizational Knowledge" of ISO 9001:2015, and it is a second-level document (procedure document) within the quality management system (QMS). Its core function is to identify, acquire, maintain, apply, and update the knowledge required for the company's operations, ensuring that "when people leave, their experience stays," and preventing quality fluctuations due to the departure of key personnel, loss of process expertise, or repeated mistakes. It is applicable to a wide range of enterprise types: manufacturing companies can document process parameters, equipment adjustments, and inspection methods; service companies can document customer communication, solution design, and complaint handling; knowledge-intensive industries (software, design, consulting) should pay particular attention to this procedure, as their core assets are knowledge itself. The procedure focuses on solving four main issues: identification and classification of knowledge sources, conversion of tacit knowledge into explicit knowledge, establishment and maintenance of a knowledge base, and timely updating of knowledge in response to internal and external changes.
1. Purpose
To standardize the entire process of identifying, acquiring, maintaining, applying, and updating organizational knowledge within the company, ensuring that the knowledge necessary for the operation of each process is continuously available and fully applicable. This prevents knowledge loss and gaps, supports the continuous compliance of products and services, and provides knowledge assurance for the company to respond to internal and external changes and implement improvements, in line with clause 7.1.6 of ISO 9001:2015 and applicable laws, regulations, and customer requirements.
2. Scope
2.1 This procedure applies to the control of all organizational knowledge required for the operation of the quality management system (QMS) within the company, including:
(1) Internal knowledge sources: personal experience and skills of employees, operational know-how and process parameters, results of process improvements and innovations, cases of nonconforming products and corrective actions, customer complaint handling experiences, design and development lessons, equipment maintenance experiences, internal training materials, and courseware.
(2) External knowledge sources: updates to laws, regulations, and standards, customer requirements and feedback, requirements and suggestions from customer audits, best practices and benchmarking experiences from the industry, technical data and usage/maintenance experiences from suppliers and partners, professional journals, and industry reports, and external databases or consulting services when necessary.
2.2 Knowledge is categorized into two types, both of which are managed under this procedure:
(1) Explicit knowledge: knowledge that has been expressed and stored in the form of documents, drawings, databases, videos, and courseware, managed according to the "Document Control Procedure" and the "Record Control Procedure."
(2) Tacit knowledge: experience, skills, and judgment that exist in the minds of employees and have not yet been systematically expressed, which is the primary focus of this procedure.
2.3 This procedure does not apply to the highest-level core technical secrets within the company's commercial secrets (which are managed separately according to the company's confidentiality policy), but the protection measures for such knowledge must not hinder the acquisition and application of knowledge required for normal process operations.
3. Responsibilities
3.1 The Management Representative (or the Quality Department, as the knowledge management department):
(1) Manage the company's organizational knowledge comprehensively, establish, and maintain the "Organizational Knowledge List."
(2) Organize the identification, review, and updating of knowledge, and the daily maintenance of the knowledge base.
(3) Supervise the execution of knowledge management activities by various departments and include knowledge management in the scope of internal audits.
(4) Regularly report the adequacy and effectiveness of knowledge management to the management review.
3.2 Department Heads:
(1) Identify and collect the knowledge required and generated by their department, organize employees to fill in the knowledge entry and experience lesson registration.
(2) Organize the application and sharing of knowledge within their department (training, briefing, case studies).
(3) Arrange for the backup and succession of key position knowledge (AB roles, mentorship).
(4) Organize knowledge handover when personnel leave or transfer, and only process the departure formalities after the handover is completed and confirmed by the department head.
3.3 Human Resources Department:
(1) Assist in converting explicit knowledge into training materials and incorporate them into the new employee onboarding and ongoing training plans.
(2) Ensure the alignment between employee capability evaluation results and knowledge needs, and provide feedback on knowledge gaps to the knowledge management department.
3.4 Information Technology Department (or designated personnel):
(1) Responsible for the construction, permission management, and data backup of the knowledge base platform (or shared directory).
(2) Ensure the convenience of knowledge retrieval and the security of knowledge storage.
3.5 All Employees:
(1) Actively summarize and share experiences, lessons, and improvement suggestions from their work.
(2) Timely register experience lessons and fill in relevant records as required by the procedure.
(3) Consciously learn and apply the knowledge related to their position from the knowledge base.
3.6 General Manager: Provide necessary resources (platform, funding, time) for knowledge management and approve major knowledge management decisions.
4. Work Procedures
4.1 Identification and Classification of Knowledge
4.1.1 The knowledge management department should organize at least one comprehensive knowledge identification annually (which can be synchronized with the preparation of inputs for the annual management review), using the following methods:
(1) Process method: compare the process list (see the process identification chapter in the "Quality Manual") and analyze the knowledge required for each process to consistently produce conforming results, such as process parameters for production processes, key operational points for equipment, and inspection methods and criteria for inspection processes.
(2) Position method: identify the knowledge required for each position based on job descriptions, focusing on key positions, skill-based positions, and newly established positions.
(3) Event method: infer the missing knowledge from past nonconformities, customer complaints, equipment failures, and safety incidents.
4.1.2 The identification results should be registered in the "Organizational Knowledge List," which includes the following columns: knowledge code, knowledge name, category (internal/external, explicit/tacit), source, carrier/storage location, responsible person, importance (key/general), acquisition date, and update cycle.
4.1.3 Principles for determining importance:
(1) Key knowledge: the absence or loss of which will directly affect product conformity, process capability, or customer satisfaction, such as core process parameters, key inspection methods, special equipment adjustment techniques, and specific customer requirements.
(2) General knowledge: the absence of which will cause efficiency losses but not directly affect conformity, such as office software skills and general process experiences.
4.2 Acquisition of Knowledge
4.2.1 Internal knowledge acquisition channels:
(1) Experience lesson registration: after the completion of the handling of nonconformities, customer complaints, equipment failures, and safety incidents, the responsible department should fill in the "Experience Lesson Registration Form" within 5 working days. The form should include a brief description of the event, root cause, handling measures, preventive actions, and transferable experiences, and be submitted to the knowledge management department for inclusion in the knowledge base after review by the department head.
(2) Project summaries: after the completion of design and development projects, major improvement projects, and new product trials, the project team should summarize the technical highlights, failure lessons, and improvement suggestions, forming a "Project Summary Report" and including it in the knowledge base.
(3) Conversion of improvement results: mature results from rationalization proposals, QC group activities, and lean improvements should be organized into reusable methods or standards and included in the knowledge base.
(4) Conversion of tacit knowledge to explicit knowledge: for skill-based employees in key positions, convert their experience into explicit forms such as text, charts, and videos through interviews, video recordings, and the creation of operation point cards.
4.2.2 External knowledge acquisition channels:
(1) Track updates to laws, regulations, and standards related to the industry (this can be delegated to a third party or a designated person for regular searches).
(2) Collect customer requirements, customer feedback, and requirements and suggestions from customer audits.
(3) Participate in industry associations, exhibitions, and technical exchange meetings, and conduct benchmarking learning from leading companies.
(4) Obtain product technical data and usage/maintenance experiences from suppliers and partners.
(5) Subscribe to professional journals and industry reports, and purchase external databases or consulting services when necessary.
4.2.3 Knowledge entry process: the proposer fills in the "Knowledge Entry Application Form" (or directly submits it on the knowledge base platform), noting the content, source, category, and value of the knowledge. The department head initially reviews its authenticity and applicability, and the knowledge management department reviews and assigns a code before including it in the knowledge base. Knowledge deemed "key" must be approved by the Management Representative. If the review is not passed, the proposer should be informed of the reasons and provided with feedback.
4.3 Maintenance and Storage of Knowledge
4.3.1 The knowledge management department should establish a unified company knowledge base (which can be implemented using an OA knowledge module, shared server directory, Wiki, or dedicated knowledge management system), categorize and store knowledge by type (management, technology, process, inspection, equipment, customer complaint cases, training, external documents), and clearly define the maintenance responsible person for each category.
4.3.2 Knowledge coding rules: Zhi - category code - sequence number, such as "Zhi - GY - 015" indicating the 15th item of process knowledge; when the version changes, add the version number to the original code (e.g., Zhi - GY - 015 - V2).
4.3.3 Storage requirements:
(1) Explicit knowledge should be managed under control according to the "Document Control Procedure" to ensure that only the current effective version is used.
(2) The knowledge base should be backed up weekly, and important knowledge should have an additional backup stored off-site.
(3) Access permissions should be set according to job needs, with key knowledge accessible only to relevant personnel, but permission settings should not hinder normal application.
(4) Multimedia knowledge such as videos and photos should be labeled with the recording date and applicable equipment/product model to prevent misuse.
4.3.4 Measures for maintaining tacit knowledge:
(1) Implement an AB role system for key positions, where the B role must master the core knowledge of the A role within 6 months, and the department head should organize an assessment to confirm this.
(2) Before key personnel leave or transfer, they must complete the knowledge handover listed in the "Knowledge Handover List upon Departure" (including documents, system accounts, unfinished tasks, key contacts, and experience points). The handover must be completed and confirmed by the department head before the departure formalities can be processed.
(3) For high-skilled employees aged 60 or older or nearing retirement, arrange an experience succession plan 1-2 years in advance (mentorship, video recording, manual writing).
4.4 Sharing and Application of Knowledge
4.4.1 Sharing methods:
(1) Training conversion: the knowledge management department, in conjunction with the human resources department, should include key knowledge in the annual training plan and organize learning through classroom training, on-site practical sessions, and online courses. Training should be conducted according to the "Human Resources Management Procedure" and the third-level document "Employee Training Work Instruction."
(2) Case studies: for newly entered typical experience lessons, the knowledge management department should issue a "Quality Case Bulletin" or organize a special study session with relevant departments to prevent the recurrence of similar issues.
(3) Experience exchange: each department should organize at least one internal experience exchange meeting per quarter to share new knowledge and methods, and the meeting minutes should be stored in the knowledge base.
(4) Onboarding training: include knowledge base usage training in the new employee onboarding program, clearly specifying the search methods and submission requirements.
4.4.2 Application requirements:
(1) For activities such as design and development, process planning, risk analysis (FMEA), and problem solving (8D/corrective actions), the knowledge base should be searched first for relevant knowledge and historical cases to serve as input, and the knowledge codes should be noted in the corresponding records.
(2) When compiling or revising process documents, work instructions, and inspection specifications, confirmed effective knowledge should be integrated into these documents.
(3) Before providing tender proposals or technical solutions externally, search for and reference historical successful cases and experience lessons to avoid repeating mistakes.
4.5 Review and Update of Knowledge
4.5.1 Scenarios triggering updates:
(1) Changes in internal and external environments: updates to laws, regulations, or standards, changes in customer requirements, introduction of new processes/new equipment/new materials, organizational structure adjustments, and key personnel changes.
(2) Process changes: when implementing changes according to the "Change Management Procedure," simultaneously assess whether new knowledge is needed and whether existing knowledge remains applicable.
(3) Regular reviews: the knowledge management department should organize a comprehensive review of knowledge annually, synchronized with the management review.
4.5.2 Update content:
(1) Supplement new knowledge: follow the 4.2 process for entry.
(2) Revise old knowledge: update the version after confirmation through the original review channel, and archive the old version according to the "Document Control Procedure."
(3) Eliminate obsolete knowledge: for knowledge that is no longer applicable (such as requirements from repealed regulations or parameters from obsolete processes), mark it as "obsolete" or move it to the historical section to prevent misuse.
4.5.3 The knowledge management department should submit the "Knowledge Management Review Report" to the management review annually, which should include the size and growth of the knowledge base, examples and effects of knowledge application, knowledge gaps and risks (including the risk of knowledge loss in key positions), and improvement suggestions.
4.6 Process Overview (Textual Flowchart)
Identify knowledge needs (process method/position method/event method) → Categorize and register in the "Organizational Knowledge List" → Acquire through multiple channels (experience lessons/project summaries/external tracking/tacit to explicit) → Review and enter (coding, categorization, classification) → Store and back up (controlled management of the knowledge base) → Share and apply (training/case bulletins/exchange/onboarding/process reference) → Regular review and update (supplement/revise/eliminate) → Input to management review → Continuous improvement.
4.7 Related Forms
This procedure involves the "Organizational Knowledge List," "Knowledge Entry Application Form," "Experience Lesson Registration Form," "Project Summary Report," "Knowledge Handover List upon Departure," "Knowledge Management Review Report," and training records (training plan, sign-in sheet, effectiveness evaluation form, see "Human Resources Management Procedure").
5. Related Records
5.1 "Organizational Knowledge List" — long-term retention, dynamic updates.
5.2 "Knowledge Entry Application Form" — retained with the corresponding knowledge, at least 3 years.
5.3 "Experience Lesson Registration Form" — retained for at least 5 years, and for major quality issues, retained with the corresponding corrective action records.
5.4 "Project Summary Report" — retained with the project archives long-term.
5.5 "Knowledge Handover List upon Departure" — retained for 2 years after the employee's departure.
5.6 "Knowledge Management Review Report" — retained with the management review records long-term.
5.7 Record management should follow the "Record Control Procedure" (Chapter 4 of the document package), and records should be clearly written, complete in content, and traceable.
6. Related Documents
6.1 "Quality Manual" — Chapter 7.1.6 "Organizational Knowledge."
6.2 "Document Control Procedure," "Record Control Procedure," "Human Resources Management Procedure," "Design and Development Control Procedure," "Production Process Control Procedure," "Nonconforming and Corrective Action Procedure," "Continuous Improvement Procedure," "Change Management Procedure" (Chapters 3, 4, 8, 15, 17, 27, 28, 29 of the document package).
6.3 Third-level documents: "Employee Training Work Instruction," "Job Description and Qualification Compilation Guide," "Data Analysis and Statistical Tool Application Guide," etc.
6.4 Referenced standards: ISO 9001:2015 "Quality Management System Requirements" clause 7.1.6, GB/T 19001-2016 "Quality Management System Requirements."
Usage Instructions
1. How to Adapt to the Actual Situation of the Company
Organizational structure adaptation: the knowledge management function can be set up in the Quality Department, General Manager's Office, Technical Department, or Human Resources Department. The responsibilities in Section 3 should be modified accordingly. For micro-enterprises (50 people or fewer), the Management Representative can take on the knowledge management responsibilities without setting up a separate position, but the "Organizational Knowledge List" must be maintained by someone.
Industry-specific adaptation: manufacturing companies should focus on managing knowledge related to process parameters, equipment adjustments, and inspection methods; service companies should focus on managing knowledge related to service solutions, customer communication, and complaint handling; software/design companies should integrate knowledge management with project retrospectives and code/design asset libraries, and add clauses for version and permission management; for food/pharmaceutical industries with strong regulatory oversight, a separate clause for tracking regulatory knowledge should be added, specifying the tracking frequency and responsible person.
Selection of knowledge base carriers: for small-scale enterprises with a small amount of knowledge, a controlled shared directory with an index table (Excel) can be used without a system. For enterprises with a large amount of knowledge and frequent searches, it is recommended to use an OA knowledge module or a dedicated knowledge management system, and specify the platform name, permission setting method, and backup cycle in the procedure.
Determination of key knowledge: do not classify all knowledge as "key," as this can obscure priorities and increase the review burden. It is suggested to determine key knowledge based on whether its absence would affect conformity or whether it cannot be rebuilt in the short term, with key knowledge accounting for no more than 20% of the total knowledge.
Integration with the training system: knowledge management must be linked with training management — within 1 month of knowledge entry, it should be clear who needs to learn it and how. Otherwise, the knowledge base may become a "storage-only" repository, making it difficult to prove during audits that knowledge has been "applied within the necessary scope."
2. Audit Focus Points (Common Inspection Items for External and Internal Audits)
Ask the Management Representative and 2-3 department heads: "What knowledge is needed for your process operations? Where do you acquire it?" Verify the completeness and coverage of the identification against the "Organizational Knowledge List."
Check the knowledge base: randomly select 5-10 items of knowledge and verify that the codes, versions, responsible persons, and entry dates match the list. Check for knowledge that has not been updated for a long time or outdated standards that are still in the knowledge base.
Validate application evidence: select 1-2 recent problem-solving or design and development cases and check if the records reference historical experiences/lessons from the knowledge base, confirming that knowledge has been "applied" and not just "stored."
Check the closure of experience lessons: select a major customer complaint or nonconformity and trace whether the "Experience Lesson Registration Form" has been filled out, entered into the knowledge base, and converted into training or document modifications, forming a complete chain from "event → lesson → knowledge → application."
Check the succession of key positions: randomly select the AB role arrangements and departure handover records for key positions to confirm that personnel changes have not caused knowledge gaps. Ask new employees if they have received training on using the knowledge base.
Changes linkage: if there have been recent updates to regulations, introduction of new equipment, or organizational adjustments, check whether the knowledge base has been updated accordingly (implementation of the 4.5.1 trigger mechanism).
3. Common Mistakes to Avoid
Treating knowledge management as "document archiving" — only collecting documents without review or application, leading to a knowledge base that is never accessed. Knowledge should be promoted through training plans, process references, and case bulletins, and the application effects should be tracked.
Focusing only on explicit knowledge and neglecting tacit knowledge — if an auditor asks a senior technician "why is this parameter set this way" and the answer is "by experience" with no explicit results, it is a nonconformity. There should be evidence such as operation point cards, videos, and mentorship plans.
Delayed or missing experience lesson registration — if the "Experience Lesson Registration Form" is not filled out after closing a nonconformity, it can lead to the recurrence of similar issues. The "Nonconforming and Corrective Action Procedure" should clearly state that "experience lesson registration must be completed before closure" as a mandatory requirement.
No knowledge handover when key personnel leave — if a technical expert leaves and process parameters, customer relationships, and system accounts are lost, the "Knowledge Handover List upon Departure" must be strictly enforced and made a prerequisite for departure formalities.
Knowledge updates lag behind changes — if the knowledge base still contains old content after a standard change or regulatory update, it will be flagged as a nonconformity during audits. It is recommended to add a requirement in the "Change Management Procedure" to "complete related knowledge updates within 10 working days after a change."
Incorrect use of symbols: for time periods in this procedure and related records, use the full-width "~" (e.g., 5~10 working days, 6~12 months) to avoid using the half-width "~."
Identify, maintain, share, and update knowledge to prevent loss
Knowledge code: 2.3.1
Version: v20260809
Author: Quality Think Tank Quality Think Tank is dedicated to providing systematic professional knowledge, methodologies, and practical tools to quality management practitioners, helping companies continuously improve their quality capabilities.