Understanding the needs and expectations of interested parties

1. Introduction: Why the High-Level Structure Matters

The High-Level Structure (HLS)—also known as Annex SL—is the common framework adopted across all modern ISO management system standards. Whether an organisation implements ISO 9001, ISO 14001, ISO/IEC 27001, ISO 22301, ISO 37301, or ISO 42001, the core structure, terminology, and clause sequence remain the same.

This design was intentional:

  • to enable integration, reduce duplication, and ensure consistency across governance, risk, compliance, and assurance disciplines.

At the heart of the HLS lies Clause 4: Context of the Organisation, and specifically Clause 4.2 – Understanding the needs and expectations of interested parties. This clause is a strategic anchor point—often underestimated, frequently under-implemented, and commonly raised as a finding during certification audits.

This article unpacks Clause 4.2 in practical, implementable terms. As an example, we have provided an overview of the HLS of ISO 42001: Artificial Intelligence Management System (AIMS)

2. The ISO High-Level Structure at a Glance

All HLS-based standards follow the same 10-clause layout:

  • Scope
  • Normative references
  • Terms and definitions
  • Context of the organisation
  • Leadership
  • Planning
  • Support
  • Operation
  • Performance evaluation
  • Improvement

Clause 4 sets the foundation. Without a proper understanding of context and stakeholders, everything that follows—risk assessments, objectives, controls, audits—rests on shaky ground.

3. Clause 4.2 Explained: What ISO Actually Requires

Clause 4.2 states that the organisation shall:

  • Determine the interested parties that are relevant to the management system,
    determine their relevant needs and expectations,
    and monitor and review this information.
  • Three key obligations emerge:
  • Identify interested parties
  • Identify relevant needs and expectations
  • Monitor and review changes over time

Importantly, ISO does not require you to satisfy all expectations—only those that are relevant and that may affect the management system’s ability to achieve its intended outcomes.

4. Who Are “Interested Parties”?

Interested parties (also referred to as stakeholders) are individuals or entities that can affect, be affected by, or perceive themselves to be affected by your organisation’s activities.

5. Typical Interested Parties Across ISO Standards

Category

Practical Examples

Customers / Clients

Service recipients, contract holders

Regulators

Data protection authorities, environmental regulators

Employees

Permanent staff, contractors

Shareholders / Board

Directors, audit & risk committees

Suppliers & Partners

IT vendors, cloud providers, logistics partners

Certification Bodies

Accredited ISO certification bodies

Society

Communities, NGOs, general public

The same stakeholder may have different expectations depending on the ISO standard being applied.

6. Practical Implementation of Clause 4.2

7.1 Step 1: Identify Interested Parties (Structured, Not Ad-Hoc)

A best-practice approach is to document interested parties in a formal register.

7.1.1 Example:

Interested Party

Relationship

Customers

Receive services

Employees

Deliver services

Regulator

Enforces compliance

Certification Body

Verifies conformity

IT Service Provider

Supports infrastructure

This register should be consistent across all ISO standards, forming the backbone of an Integrated Management System (IMS).

7.2 Step 2: Identify Needs and Expectations (Mapped to Risk)

Not all expectations are equal. ISO expects relevance-based filtering.

7.2.1 Example for ISO/IEC 27001:

Interested Party

Need / Expectation

Relevant?

Reason

Customers

Confidentiality of data

Yes

Affects trust & compliance

Employees

Job security

Indirect

HR-related, not ISMS core

Regulator

POPIA compliance

Yes

Legal obligation

IT Supplier

Clear SLAs

Yes

Affects availability & integrity

This step is where Clause 4.2 directly links to risk-based thinking (Clause 6).

7.3 Step 3: Link Clause 4.2 to Other ISO Clauses

Clause 4.2 is not a standalone exercise. It feeds directly into:

  • Clause 5 (Leadership) – governance responsibilities
  • Clause 6 (Planning) – risks, opportunities, objectives
  • Clause 8 (Operation) – controls and processes
  • Clause 9 (Performance Evaluation) – monitoring stakeholder satisfaction

If Clause 4.2 is weak, these clauses will fail under audit scrutiny.

7.3.1 Example: Clause 4.2 Across Multiple ISO Standards

Integrated Example

An organisation implementing ISO 9001, ISO 27001, and ISO 22301 may have:

Interested Party

QMS (9001)

ISMS (27001)

BCMS (22301)

Customers

Quality of service

Data protection

Service continuity

Employees

Competence

Security awareness

Emergency roles

Regulators

Product compliance

Data protection laws

Critical service continuity

This demonstrates the power of HLS—one stakeholder register, multiple lenses.

7. Common Audit Findings Related to Clause 4.2

Certification bodies frequently raise nonconformities where:

✖ Interested parties are listed but not reviewed

✖ Needs and expectations are generic or copied

✖ No link exists between Clause 4.2 and risk assessments

✖ The register exists but is not used operationally

Auditors expect evidence that Clause 4.2 is alive, not a static document.

8. Good Practice Tips for Sustainable Compliance

  • Review interested parties at least annually
  • Update after major changes (mergers, new regulations, incidents)
  • Align Clause 4.2 with risk registers and compliance obligations
  • Use consistent terminology across all ISO standards
  • Treat Clause 4.2 as a governance tool, not an admin exercise

9. Strategic Value of Clause 4.2

When implemented properly, Clause 4.2:

  • Strengthens governance and oversight
  • Improves risk anticipation
  • Enhances regulatory readiness
  • Enables true ISO integration
  • Reduces audit friction and findings

In mature organisations, Clause 4.2 becomes the lens through which strategy, risk, and assurance are aligned.

10. Closing Thought

The ISO High-Level Structure was designed to move organisations away from siloed compliance and toward integrated, context-aware management systems. Clause 4.2 is the starting point of that journey.

Get Clause 4.2 right—and the rest of the ISO system starts working with you, not against you.