Understanding the needs and expectations of interested parties
1. Introduction: Why the High-Level Structure Matters
The High-Level Structure (HLS)—also known as Annex SL—is the common framework adopted across all modern ISO management system standards. Whether an organisation implements ISO 9001, ISO 14001, ISO/IEC 27001, ISO 22301, ISO 37301, or ISO 42001, the core structure, terminology, and clause sequence remain the same.
This design was intentional:
- to enable integration, reduce duplication, and ensure consistency across governance, risk, compliance, and assurance disciplines.
At the heart of the HLS lies Clause 4: Context of the Organisation, and specifically Clause 4.2 – Understanding the needs and expectations of interested parties. This clause is a strategic anchor point—often underestimated, frequently under-implemented, and commonly raised as a finding during certification audits.
This article unpacks Clause 4.2 in practical, implementable terms. As an example, we have provided an overview of the HLS of ISO 42001: Artificial Intelligence Management System (AIMS)
2. The ISO High-Level Structure at a Glance
All HLS-based standards follow the same 10-clause layout:
- Scope
- Normative references
- Terms and definitions
- Context of the organisation
- Leadership
- Planning
- Support
- Operation
- Performance evaluation
- Improvement
Clause 4 sets the foundation. Without a proper understanding of context and stakeholders, everything that follows—risk assessments, objectives, controls, audits—rests on shaky ground.
3. Clause 4.2 Explained: What ISO Actually Requires
Clause 4.2 states that the organisation shall:
- Determine the interested parties that are relevant to the management system,
determine their relevant needs and expectations,
and monitor and review this information. - Three key obligations emerge:
- Identify interested parties
- Identify relevant needs and expectations
- Monitor and review changes over time
Importantly, ISO does not require you to satisfy all expectations—only those that are relevant and that may affect the management system’s ability to achieve its intended outcomes.
4. Who Are “Interested Parties”?
Interested parties (also referred to as stakeholders) are individuals or entities that can affect, be affected by, or perceive themselves to be affected by your organisation’s activities.
5. Typical Interested Parties Across ISO Standards
|
Category |
Practical Examples |
|
Customers / Clients |
Service recipients, contract holders |
|
Regulators |
Data protection authorities, environmental regulators |
|
Employees |
Permanent staff, contractors |
|
Shareholders / Board |
Directors, audit & risk committees |
|
Suppliers & Partners |
IT vendors, cloud providers, logistics partners |
|
Certification Bodies |
Accredited ISO certification bodies |
|
Society |
Communities, NGOs, general public |
The same stakeholder may have different expectations depending on the ISO standard being applied.
6. Practical Implementation of Clause 4.2
7.1 Step 1: Identify Interested Parties (Structured, Not Ad-Hoc)
A best-practice approach is to document interested parties in a formal register.
7.1.1 Example:
|
Interested Party |
Relationship |
|
Customers |
Receive services |
|
Employees |
Deliver services |
|
Regulator |
Enforces compliance |
|
Certification Body |
Verifies conformity |
|
IT Service Provider |
Supports infrastructure |
This register should be consistent across all ISO standards, forming the backbone of an Integrated Management System (IMS).
7.2 Step 2: Identify Needs and Expectations (Mapped to Risk)
Not all expectations are equal. ISO expects relevance-based filtering.
7.2.1 Example for ISO/IEC 27001:
|
Interested Party |
Need / Expectation |
Relevant? |
Reason |
|
Customers |
Confidentiality of data |
Yes |
Affects trust & compliance |
|
Employees |
Job security |
Indirect |
HR-related, not ISMS core |
|
Regulator |
POPIA compliance |
Yes |
Legal obligation |
|
IT Supplier |
Clear SLAs |
Yes |
Affects availability & integrity |
This step is where Clause 4.2 directly links to risk-based thinking (Clause 6).
7.3 Step 3: Link Clause 4.2 to Other ISO Clauses
Clause 4.2 is not a standalone exercise. It feeds directly into:
- Clause 5 (Leadership) – governance responsibilities
- Clause 6 (Planning) – risks, opportunities, objectives
- Clause 8 (Operation) – controls and processes
- Clause 9 (Performance Evaluation) – monitoring stakeholder satisfaction
If Clause 4.2 is weak, these clauses will fail under audit scrutiny.
7.3.1 Example: Clause 4.2 Across Multiple ISO Standards
Integrated Example
An organisation implementing ISO 9001, ISO 27001, and ISO 22301 may have:
|
Interested Party |
QMS (9001) |
ISMS (27001) |
BCMS (22301) |
|
Customers |
Quality of service |
Data protection |
Service continuity |
|
Employees |
Competence |
Security awareness |
Emergency roles |
|
Regulators |
Product compliance |
Data protection laws |
Critical service continuity |
This demonstrates the power of HLS—one stakeholder register, multiple lenses.
7. Common Audit Findings Related to Clause 4.2
Certification bodies frequently raise nonconformities where:
✖ Interested parties are listed but not reviewed
✖ Needs and expectations are generic or copied
✖ No link exists between Clause 4.2 and risk assessments
✖ The register exists but is not used operationally
Auditors expect evidence that Clause 4.2 is alive, not a static document.
8. Good Practice Tips for Sustainable Compliance
- Review interested parties at least annually
- Update after major changes (mergers, new regulations, incidents)
- Align Clause 4.2 with risk registers and compliance obligations
- Use consistent terminology across all ISO standards
- Treat Clause 4.2 as a governance tool, not an admin exercise
9. Strategic Value of Clause 4.2
When implemented properly, Clause 4.2:
- Strengthens governance and oversight
- Improves risk anticipation
- Enhances regulatory readiness
- Enables true ISO integration
- Reduces audit friction and findings
In mature organisations, Clause 4.2 becomes the lens through which strategy, risk, and assurance are aligned.
10. Closing Thought
The ISO High-Level Structure was designed to move organisations away from siloed compliance and toward integrated, context-aware management systems. Clause 4.2 is the starting point of that journey.
Get Clause 4.2 right—and the rest of the ISO system starts working with you, not against you.