ISO 9001:2015 Gap Analysis Checklist
Objective Evidence
- The documented context analysis (SWOT, PESTLE, or equivalent) - verify it names issues specific to THIS organization (its markets, technology, supply chain, workforce, regulatory jurisdiction), not a generic template, and that both external and internal factors are covered.
- Evidence the analysis is kept current - a dated review cadence (e.g. at management review) with changes captured when the market, regulations, or organization shift; an analysis dated years ago with no revisions is a red flag.
- The link from context to QMS planning - trace at least two identified issues into actual decisions (risks/opportunities in 6.1, objectives in 6.2, scope in 4.3), showing the analysis drives planning rather than sitting in a binder.
- Management-review minutes where context is discussed - confirm leadership is aware of the key external/internal factors and treats them as live inputs, not a once-a-year formality.
- Supporting inputs feeding the analysis - market/competitive analysis, regulatory monitoring, customer feedback, internal capability or performance data - to confirm the issues are evidence-based, not opinion.
Common Nonconformities
- Minor NC: The context analysis exists but was done once and never revised, despite changes in the market, regulations, or the organization since.
- Minor NC: Issues listed are generic ('competition', 'the economy') and not specific to the organization, so they cannot drive any real planning.
- Minor NC: No traceable link between identified issues and QMS planning (risks, objectives, scope) - the analysis is maintained for the audit, not used.
- Observation: Context is documented by the quality function alone, with no evidence top management is aware of or engaged with the key factors.
Auditor Tips
Organizations must systematically identify and monitor both external and internal factors that could impact their QMS effectiveness and ability to meet objectives. EXTERNAL ISSUES: LEGAL & REGULATORY: - Industry-specific regulations - Changes in legislation - Compliance requirements - Certification requirements - Customer contractual requirements MARKET & COMPETITIVE: - Market demand and trends - Competitive landscape - Customer expectations evolution - Industry consolidation - New market entrants - Global economic conditions TECHNOLOGICAL: - Emerging technologies - Digital transformation - Automation opportunities - Obsolescence risks - Cybersecurity threats SOCIAL & CULTURAL: - Demographic changes - Social responsibility expectations - Cultural norms and values - Environmental concerns - Stakeholder activism INTERNAL ISSUES: ORGANIZATIONAL: - Company size and structure - Strategic direction - Organizational culture - Leadership stability - Change management capability CAPABILITIES: - Core competencies - Technology and equipment - Production capacity - Innovation capability - Process maturity RESOURCES: - Workforce skills and availability - Financial strength - Facility conditions - IT infrastructure - Knowledge management PERFORMANCE: - Quality metrics and trends - Customer satisfaction levels - Operational efficiency - Risk profile - Growth trajectory The organization must: 1. Identify relevant issues systematically 2. Understand how they affect QMS objectives 3. Monitor changes in these issues 4. Review regularly (e.g., management review) 5. Take action when issues change significantly
Follow-Up Questions
- How frequently does the organization review its external and internal issues, and what triggers an unscheduled review?
- Can you walk me through a recent example where an identified issue led to a change in QMS planning or objectives?
- Who is responsible for monitoring changes in the regulatory or competitive landscape, and how are those changes communicated internally?
What to Sample
Review the most recent SWOT/PESTLE analysis or equivalent, and cross-reference with the last two management review minutes to confirm issues were discussed and acted upon.
Objective Evidence
- The interested-parties register - verify it goes beyond customers to the parties that actually affect or are affected by the QMS (regulators, suppliers, employees, owners), and is specific to this organization.
- The requirements determined for each relevant party - statutory, regulatory, contractual, and expectation-based - not just 'customers want quality'.
- Evidence the analysis is monitored and reviewed as parties and their requirements change (e.g. new regulations), with a dated cadence.
- Traceability from interested-party requirements into QMS planning (scope, objectives, processes, compliance obligations) - showing it is used, not filed.
- Distinction between mandatory (must comply) and voluntary (chosen) requirements, so the organization knows its hard obligations.
Common Nonconformities
- Minor NC: Only customers are identified as interested parties; statutory/regulatory authorities and other affecting parties are omitted.
- Minor NC: Interested-party requirements are not linked to QMS planning, so the analysis has no effect.
- Minor NC: The analysis is not reviewed or updated as parties and requirements change.
- Observation: The register is a generic template not tailored to the organization's actual stakeholders.
Auditor Tips
Organizations must identify stakeholders who can impact the QMS or be impacted by it, and understand their needs and expectations. KEY INTERESTED PARTIES: CUSTOMERS: - End users of products/services - Direct customers (B2B, B2C) - Distributors and resellers - Requirements: quality, delivery, price, service, innovation REGULATORY/STATUTORY: - Government regulatory bodies - Industry regulators - Standards organizations - Requirements: compliance, safety, environmental protection SUPPLIERS/PARTNERS: - Raw material suppliers - Service providers - Outsource providers - Technology partners - Requirements: fair terms, stability, partnership, payment EMPLOYEES: - Direct employees - Contractors - Unions/worker representatives - Requirements: safety, compensation, development, job security OWNERS/INVESTORS: - Shareholders - Private equity owners - Board of directors - Requirements: profitability, growth, risk management, compliance COMMUNITY/SOCIETY: - Local communities - NGOs and advocacy groups - General public - Requirements: environmental protection, social responsibility, employment The organization must: 1. Identify relevant interested parties (not exhaustive list) 2. Determine their requirements relevant to QMS 3. Understand which requirements are mandatory vs. discretionary 4. Monitor changes in interested parties and their requirements 5. Review regularly and update as needed IMPORTANT: Focus on parties and requirements that are RELEVANT to the QMS ability to consistently provide conforming products and services.
Follow-Up Questions
- Beyond customers and regulators, which other interested parties have been identified, and how were their requirements determined?
- How does the organization detect when a new interested party becomes relevant or when existing requirements change?
- Can you trace a specific interested party requirement through to where it is addressed in the QMS?
What to Sample
Examine the interested parties register or matrix, then verify at least two entries are linked to specific QMS processes or documented requirements.
Objective Evidence
- The documented QMS scope statement - verify it defines clear boundaries (sites/locations, products/services) and is available as documented information.
- Justification for any exclusions - confirm only requirements that genuinely cannot apply are excluded, and that no requirement affecting conformity or customer satisfaction is dodged (a non-applicable clause is justified; a skipped one is not).
- Evidence the scope reflects the 4.1 context and 4.2 interested-party requirements that drove it.
- A check that the scope matches actual operations - the activities, sites, and products the organization really performs, not a narrowed scope of convenience.
- Evidence the scope is reviewed for continuing adequacy (e.g. at management review) when the business changes (new sites, products, services).
Common Nonconformities
- Major NC: A requirement that affects the conformity of products/services or customer satisfaction has been excluded from scope, so part of the QMS is not applied.
- Minor NC: The scope does not match actual operations (sites or products performed but not in scope, or the reverse).
- Minor NC: Exclusions are taken without justification.
- Observation: The scope has never been reviewed or updated despite changes to the business.
Auditor Tips
The QMS scope defines what the organization's QMS covers and any permissible exclusions. This is a critical document for certification. DETERMINING SCOPE - CONSIDERATIONS: BOUNDARIES: - Physical locations (sites, facilities, warehouses) - Organizational units (divisions, departments, subsidiaries) - Processes (design, manufacturing, service, support) - Products and services covered - Geographic regions INPUTS TO SCOPE (Must Consider): - External/internal issues from 4.1 - Interested party requirements from 4.2 - Products and services offered - Organizational structure - Business model - Complexity of operations EXCLUSIONS: - ISO 9001:2015 allows NO EXCLUSIONS except Clause 8.3 (Design and Development) - Clause 7 requirements cannot be excluded - Any exclusion must be justified - Exclusions must not affect ability to provide conforming products/services - Exclusions must not affect customer satisfaction COMMON ACCEPTABLE EXCLUSIONS: - 8.3 Design and Development (if organization doesn't design) - Example: Pure distributor or reseller with no design responsibility UNACCEPTABLE EXCLUSIONS: - Cannot exclude management responsibility (Clause 5) - Cannot exclude resource management (Clause 7) - Cannot exclude production/service provision if that's what you do - Cannot exclude measurement and improvement (Clauses 9 & 10) SCOPE STATEMENT MUST INCLUDE: 1. Products and services covered 2. Sites/locations covered 3. Processes covered 4. Any justified exclusions (rare) 5. Organizational units covered SCOPE MUST BE: - Documented - Available (to interested parties if requested) - Maintained (kept current) - Realistic and achievable - Aligned with business reality
Follow-Up Questions
- What exclusions, if any, have been made from the scope, and what is the documented justification for each?
- How does the scope statement account for outsourced processes or remote operational sites?
- When was the scope last reviewed, and did any changes in context or interested party requirements trigger an update?
What to Sample
Compare the documented QMS scope against the organization's actual product/service portfolio and site locations to confirm completeness and accuracy of boundaries.
Objective Evidence
- The overall picture of the process-based QMS - a process map showing the QMS processes and their interactions, demonstrating the organization manages quality as a system of interacting processes rather than a set of disconnected procedures.
- Evidence the processes needed for the QMS are determined and applied throughout the organization, including their inputs, outputs, sequence, and interaction.
- Evidence the processes are resourced, owned, and managed to deliver their intended results (links to 4.4.1 a-h).
- The documented information maintained to support process operation and retained to confirm processes run as planned (4.4.2).
- Evidence the QMS and its processes are continually improved, not static since certification.
Common Nonconformities
- Minor NC: The QMS is a collection of disconnected procedures rather than a managed system of interacting processes.
- Minor NC: Process interactions are not defined, so the handoffs between processes are uncontrolled.
- Minor NC: Processes are documented but not actually managed (no owners, performance measures, or improvement).
- Observation: The process approach exists on paper (a process map) but the organization runs day-to-day on departmental silos.
Auditor Tips
This is the foundation of the process-based approach in ISO 9001:2015. Organizations must identify, document, and manage all QMS processes. PROCESS-BASED APPROACH REQUIREMENTS: a) DETERMINE INPUTS AND OUTPUTS: - What goes into each process (materials, information, requirements) - What comes out of each process (products, services, information) - Specifications for inputs and outputs - Customer requirements as inputs b) SEQUENCE AND INTERACTION: - Process flow/process map - How processes connect and depend on each other - Interfaces between processes - Handoffs and responsibilities - Process hierarchy (core, support, management processes) c) CRITERIA AND METHODS: - How to know if process is working (KPIs, metrics) - Monitoring methods (real-time, periodic) - Measurement methods (inspection, testing, audit) - Performance indicators (quality, delivery, cost, safety) - Acceptance criteria for outputs - Process controls to ensure consistent results d) RESOURCES: - People (competence, number) - Equipment and infrastructure - Work environment - Knowledge and information - Budget allocation - Ensure availability when needed e) RESPONSIBILITIES AND AUTHORITIES: - Process owners assigned - Clear roles and responsibilities - Authority to make decisions - Accountability for results - Communication channels f) RISKS AND OPPORTUNITIES: - Process-level risk assessment - Actions to address risks - Opportunities for improvement - Link to 6.1 (overall risk management) - Preventive actions g) EVALUATE AND CHANGE: - Regular process performance reviews - Analyze results vs. targets - Implement changes when needed - Process capability analysis - Corrective actions - Process audits h) IMPROVE: - Continual improvement initiatives - Innovation in processes - Best practice adoption - Process optimization - Technology improvements DOCUMENTED INFORMATION: - As necessary to support operations - As necessary to demonstrate conformity - Can be procedures, work instructions, forms, records - ISO 9001:2015 gives flexibility on format and extent PROCESS TYPES: - Management processes (planning, review, improvement) - Core processes (design, production, service delivery) - Support processes (HR, IT, maintenance, procurement) - Measurement processes (monitoring, audit, analysis)
Follow-Up Questions
- How does the organization identify when a new process needs to be added to the QMS or an existing one modified?
- Can you describe the mechanism for continual improvement of the QMS as a system, beyond individual process improvements?
- How are process interactions verified when changes are made to one process that affects others?
What to Sample
Review the process map or turtle diagrams for the three most critical processes, verifying that inputs, outputs, and interactions are current and reflect actual practice.
Objective Evidence
- Interested parties register/matrix
- Stakeholder analysis document
- Context of organization analysis
- Customer list/database
- Regulatory authority identification
- Supplier register
- Organizational chart showing internal stakeholders
- Stakeholder mapping exercise results
- Minutes from management discussions on stakeholders
Common Nonconformities
- Only customers listed as interested parties
- Generic template list not tailored to organization
- Missing regulatory/statutory authorities
- No internal interested parties identified
- List not reviewed since initial creation
- No rationale for why parties are relevant
- Obvious stakeholders missing (e.g., suppliers)
Auditor Tips
Organizations must identify all stakeholders who can affect or be affected by the QMS's ability to provide conforming products/services. TYPES OF INTERESTED PARTIES TO CONSIDER: EXTERNAL INTERESTED PARTIES: - Customers (direct customers, end users, distributors) - Regulatory authorities (government, industry regulators) - Suppliers and outsourced providers - Shareholders/owners/investors - Competitors (influencing market expectations) - Community and society - Industry associations - Notified bodies/certification bodies - Insurance companies - Media/press - NGOs and advocacy groups INTERNAL INTERESTED PARTIES: - Employees and workers - Management team - Board of directors - Trade unions/worker representatives - Contractors working on-site - Parent company (if subsidiary) HOW TO DETERMINE RELEVANCE: - Can they impact the QMS effectiveness? - Can they impact product/service conformity? - Are they affected by the QMS? - Do they have statutory/regulatory authority? - Do they have contractual relationship? - Do they have significant influence? NOT ALL INTERESTED PARTIES ARE RELEVANT: - Focus on those with genuine impact on QMS - The list is not meant to be exhaustive - Prioritize by level of impact/influence
Follow-Up Questions
- What methodology was used to identify relevant interested parties, and how comprehensive was the assessment?
- Are there any interested parties that were considered but determined to be not relevant, and what was the rationale?
What to Sample
Review the interested parties identification process and confirm it covers at minimum: customers, employees, suppliers, regulators, and owners/shareholders.
Objective Evidence
- Context analysis (SWOT, PESTLE) informing scope
- Scope statement referencing context factors
- Minutes showing context consideration in scope decisions
- Risk assessment linked to scope determination
- Strategic plan alignment with QMS scope
Common Nonconformities
- Scope determined without reference to context
- Context analysis exists but not linked to scope
- Scope doesn't reflect organizational reality
- External factors ignored in scope determination
Auditor Tips
The scope must take into account the context analysis from clause 4.1. HOW CONTEXT INFLUENCES SCOPE: EXTERNAL ISSUES AFFECTING SCOPE: - Market characteristics and geographic reach - Regulatory jurisdiction and requirements - Supply chain considerations - Technology and infrastructure availability - Economic conditions - Competition and industry dynamics - Customer expectations and requirements INTERNAL ISSUES AFFECTING SCOPE: - Organizational structure and complexity - Available resources and capabilities - Strategic direction and priorities - Current processes and systems - Locations and facilities - Products/services offered - Competencies available LINKING CONTEXT TO SCOPE: - If you operate in multiple jurisdictions, scope should reflect this - If you offer diverse products, determine which are in scope - If you have multiple sites, define which are included - If you outsource key processes, address in scope - If regulatory requirements mandate coverage, cannot exclude The scope should be realistic given the organization's context.
Follow-Up Questions
- Can you demonstrate how the issues identified in clause 4.1 influenced the determination of the QMS scope?
- Were any external issues such as regulatory changes or market shifts factored into scope boundaries?
What to Sample
Cross-reference the scope statement with the documented context analysis to verify traceability between identified issues and scope decisions.
Objective Evidence
- The process map or interaction diagram - verify it shows the actual QMS processes and how each one's outputs feed the next (not an org chart relabelled as processes), and that support and management processes are included, not just the core value stream.
- Process definitions for the key processes - for a sample, confirm inputs, outputs, owner, and the criteria/methods used to know the process is performing are defined (linking to 4.4.1 a-e).
- Evidence the processes are managed as a system - process KPIs reviewed, interactions monitored at the handoffs (e.g. sales-to-operations, design-to-production), and action taken where a process underperforms.
- Process changes and improvements - records showing processes are evaluated and improved over time (4.4.1 g-h), not frozen since certification.
- Documented information supporting and evidencing the processes (4.4.2) - procedures/instructions where needed, and records that show the processes ran as planned.
Common Nonconformities
- Minor NC: Processes are listed but their sequence and interactions are not defined, so the handoffs between processes (the usual failure points) are uncontrolled.
- Minor NC: The 'process map' is an org chart or a list of departments, not the actual processes and their flows.
- Minor NC: No process-level criteria or performance measures, so the organization cannot tell whether a given process is achieving its intended results.
- Observation: Processes were defined at certification and never revisited, with no evidence of evaluation or improvement (4.4.1 g-h).
Auditor Tips
Clause 4.4.1 establishes the overall requirement for a process-based QMS. The organization must identify all necessary processes and manage their interactions.
Follow-Up Questions
- How many processes are defined within the QMS, and how was the level of detail determined for each?
- What approach does the organization use to define process interactions, such as a process map, interaction matrix, or turtle diagrams?
- How does the organization ensure that all processes needed for the QMS are identified and none are inadvertently omitted?
What to Sample
Select three processes from different functional areas and verify each has defined inputs, outputs, criteria, resources, responsibilities, and risk considerations.
Objective Evidence
- Requirements register by interested party
- Customer requirements documentation
- Regulatory/legal requirements register
- Contract review records
- Supplier agreements
- Service level agreements (SLAs)
- Employee handbook/policies
- Customer specifications received
- Compliance obligations checklist
- Licensing and permit requirements
- Customer surveys and feedback
Common Nonconformities
- Requirements not linked to specific interested parties
- Only customer requirements documented
- Regulatory requirements missing or incomplete
- Requirements documented but not integrated into QMS
- No process to monitor changes in requirements
- Generic requirements not tailored to organization
- Requirements not reviewed periodically
Auditor Tips
Once interested parties are identified, the organization must determine their specific requirements that are relevant to the QMS. TYPES OF REQUIREMENTS TO DETERMINE: CUSTOMER REQUIREMENTS: - Product/service specifications - Delivery requirements - Quality expectations - Price/value expectations - Service level requirements - Warranty and support expectations - Communication preferences REGULATORY/STATUTORY REQUIREMENTS: - Legal compliance obligations - Industry-specific regulations - Environmental requirements - Health and safety requirements - Reporting obligations - Licensing/certification requirements SUPPLIER REQUIREMENTS: - Fair payment terms - Clear specifications - Predictable demand/forecasting - Partnership expectations - Communication of changes EMPLOYEE REQUIREMENTS: - Safe working conditions - Fair compensation - Training and development - Clear expectations and feedback - Resources to do the job OWNER/INVESTOR REQUIREMENTS: - Financial performance - Risk management - Compliance - Growth and sustainability - Reputation management DETERMINING RELEVANCE TO QMS: - Does it affect product/service conformity? - Does it affect customer satisfaction? - Is it a legal obligation? - Is it in contractual agreements? - Does it impact QMS effectiveness? Importantly, not all requirements of interested parties are relevant to the QMS; focus on those that genuinely affect the ability to provide conforming products and services and enhance customer satisfaction.
Follow-Up Questions
- How does the organization distinguish between mandatory requirements (statutory, regulatory) and voluntary expectations of interested parties?
- What process exists for translating interested party requirements into actionable QMS requirements?
What to Sample
Select two interested parties and trace their documented requirements through to where they are addressed in QMS procedures or process controls.
Objective Evidence
- Interested party requirements matrix linked to scope
- Customer requirements driving scope decisions
- Regulatory requirements mandating scope coverage
- Contract requirements specifying scope
- Documentation showing interested party input to scope
Common Nonconformities
- Interested party requirements not considered in scope
- Customer requirements excluded from scope without justification
- Regulatory requirements not reflected in scope
- Scope doesn't address key stakeholder needs
Auditor Tips
The scope must consider what interested parties require from the QMS. HOW INTERESTED PARTY REQUIREMENTS INFLUENCE SCOPE: CUSTOMER REQUIREMENTS: - Specific product/service requirements may mandate scope inclusion - Customer contract requirements (e.g., require certification) - Customer audits may expect certain scope coverage REGULATORY REQUIREMENTS: - Mandatory requirements cannot be excluded from scope - Licensing may require specific processes in scope - Compliance obligations define minimum scope SUPPLIER/PARTNER REQUIREMENTS: - Key suppliers may require certified scope - Partnership agreements may specify scope expectations EMPLOYEE REQUIREMENTS: - Health and safety obligations in scope - Training requirements in scope OWNER/INVESTOR REQUIREMENTS: - Risk management expectations - Governance requirements PRACTICAL APPLICATION: - If customers require ISO certification, scope must cover relevant processes - If regulators mandate certain controls, cannot exclude from scope - If contract specifies coverage, scope must include - If notified body audit scope, must align
Follow-Up Questions
- How were the requirements of interested parties factored into scope decisions, particularly regarding product or service boundaries?
- Are there contractual or regulatory requirements from interested parties that necessitated expanding or narrowing the scope?
What to Sample
Verify that key interested party requirements (e.g., customer contract terms, regulatory mandates) are reflected in the scope boundaries and any exclusion justifications.
Objective Evidence
- Process flow diagrams with inputs/outputs
- SIPOC diagrams
- Turtle diagrams
- Process descriptions listing inputs/outputs
- Work instructions specifying input requirements
- Output specifications and acceptance criteria
- Process interface definitions
Common Nonconformities
- Processes without defined inputs
- No output specifications
- Input/output mismatch between processes
- Undocumented process triggers
- No acceptance criteria for outputs
Auditor Tips
Each process must have clearly defined inputs and outputs. PROCESS INPUTS: - Materials, components, raw materials - Information and data - Customer requirements and specifications - Design information - Outputs from preceding processes - Resources (people, equipment, environment) - Documented information (procedures, instructions) PROCESS OUTPUTS: - Products or services (intermediate or final) - Information and records - Decisions and approvals - Reports and documentation - Inputs to subsequent processes - Waste and by-products DEFINING INPUTS AND OUTPUTS: - Identify what triggers the process (inputs) - Identify what the process produces (outputs) - Define specifications/criteria for inputs - Define acceptance criteria for outputs - Ensure output of one process matches input needs of next TOOLS FOR DOCUMENTATION: - Process flow diagrams showing I/O - Turtle diagrams (SIPOC alternative) - SIPOC diagrams (Suppliers, Inputs, Process, Outputs, Customers) - Process descriptions/procedures
Follow-Up Questions
- For the key operational processes, how are inputs verified as adequate before the process begins?
- How does the organization confirm that process outputs meet the requirements of downstream processes or the customer?
What to Sample
Select one core realization process and one support process; verify that inputs and expected outputs are formally defined and that actual outputs match specifications.
Objective Evidence
- Product/service catalog matching scope
- Scope statement with clear product/service definitions
- Product line documentation
- Service descriptions
- Certificate showing products/services covered
Common Nonconformities
- Scope vague about products/services
- Scope doesn't match actual offerings
- Products marketed as certified but not in scope
- Significant products/services excluded without justification
Auditor Tips
The scope must clearly define which products and services are covered. PRODUCTS AND SERVICES CONSIDERATION: WHAT TO CONSIDER: - Full product/service portfolio - Product families and categories - Service offerings and support - Custom vs. standard offerings - New product development activities - Legacy products still supported - Products in different lifecycle stages SCOPE STATEMENT SHOULD: - List product/service types covered - Be specific enough to be meaningful - Be broad enough for flexibility - Match what organization actually provides - Match what certification certificate will state EXAMPLES OF SCOPE STATEMENTS: - "Design, manufacture, and distribution of medical devices" - "Provision of IT consulting and software development services" - "Manufacturing of precision machined components for aerospace" - "Design and installation of HVAC systems" EXCLUSIONS: - If certain products/services excluded, must justify - Cannot exclude if it affects conformity - Design (8.3) is common exclusion if not performed CONSIDERATIONS: - Are all offered products/services in scope? - If partial coverage, is it justified? - Does scope match marketing claims? - Does scope match certification expectations?
Follow-Up Questions
- Does the scope explicitly list all product and service categories offered by the organization?
- Have any products or services been added or discontinued since the last scope review, and was the scope updated accordingly?
What to Sample
Compare the products and services listed in the scope statement against the current sales catalogue, product line documentation, or service agreements.
Objective Evidence
- Process map or process interaction diagram
- Process flow charts
- Process interaction matrix
- Swimlane diagrams
- Business process model (BPM)
- Quality manual process description
- Interface control documents
Common Nonconformities
- No overall process map
- Processes documented in isolation
- Unclear handoffs between processes
- Missing links between processes
- Process sequence not logical
- Interactions not understood by staff
Auditor Tips
Processes don't operate in isolation - they interact and depend on each other. PROCESS SEQUENCE: - Order in which processes occur - Which processes come before/after - Parallel vs. sequential processes - Critical path through processes - Process flow from customer order to delivery PROCESS INTERACTION: - How processes connect to each other - What information/materials flow between processes - Dependencies between processes - Handoff points and responsibilities - Feedback loops between processes PROCESS CATEGORIES (typical): - Management processes (strategy, planning, review) - Core/operational processes (design, production, delivery) - Support processes (HR, IT, maintenance, purchasing) - Measurement processes (audit, monitoring, analysis) DOCUMENTATION APPROACHES: - High-level process map showing all processes - Process interaction matrix - Detailed flow charts for key processes - Interface definitions between processes - Swimlane diagrams showing responsibilities
Follow-Up Questions
- How is the sequence of processes documented, and does it reflect the actual operational flow?
- When a process change occurs, how are upstream and downstream process owners notified of potential impacts on interactions?
What to Sample
Review the process interaction map or matrix and verify it against actual workflow by tracing one product or service from order intake through delivery.
Objective Evidence
- Process KPIs and targets
- Process control plans
- Work instructions with acceptance criteria
- SPC charts and process capability data
- Process monitoring records
- Performance dashboards
- Inspection and test procedures
- Process validation records
Common Nonconformities
- No defined process performance indicators
- Processes without acceptance criteria
- No monitoring of process performance
- KPIs not linked to process effectiveness
- No action taken when processes fail targets
- Ad-hoc process control methods
Auditor Tips
Each process needs defined criteria for success and methods to control it. PROCESS CRITERIA: - Acceptance criteria for outputs - Performance targets and objectives - Process capability requirements - Quality standards to meet - Tolerance limits - Customer specifications PROCESS CONTROL METHODS: - Procedures and work instructions - Process parameters to control - Inspection and testing methods - Statistical process control (SPC) - Automated controls - Verification and validation methods MONITORING AND MEASUREMENT: - What to measure (key parameters) - How often to measure (frequency) - How to measure (methods, instruments) - Who performs measurement - How to record results - Actions when out of spec PERFORMANCE INDICATORS (KPIs): - Quality metrics (defect rate, yield, first-pass quality) - Delivery metrics (on-time, lead time) - Efficiency metrics (throughput, productivity) - Cost metrics (cost per unit, rework cost) - Customer metrics (complaints, satisfaction) - Safety metrics (incidents, near-misses) KEY CONCEPT: Processes must be "controlled" - not just performed, but actively managed to achieve consistent results.
Follow-Up Questions
- What key performance indicators are established for each process, and how were the target values determined?
- How frequently are process performance indicators reviewed, and what actions are taken when targets are not met?
- Are the monitoring methods validated as appropriate for the characteristics being measured?
What to Sample
Review performance dashboards or KPI reports for two processes; verify that criteria are defined, measurements are taken at stated frequency, and trend data shows evidence of action on adverse results.
Objective Evidence
- Resource allocation plans
- Staffing plans and schedules
- Equipment lists and maintenance records
- Training records and competency matrix
- Budget allocation
- Capacity planning documents
- Infrastructure maintenance plans
- Skills matrices
Common Nonconformities
- Resources not identified for processes
- Chronic resource shortages
- No resource planning
- Equipment unavailable when needed
- Insufficient trained personnel
- Resources not aligned with process needs
Auditor Tips
Processes require resources to function effectively. TYPES OF RESOURCES: HUMAN RESOURCES: - Number of people needed - Competencies required - Training needs - Shift patterns and coverage INFRASTRUCTURE: - Equipment and machinery - Tools and instruments - Buildings and workspace - IT systems and software - Utilities (power, water, compressed air) - Transportation ENVIRONMENT: - Controlled conditions (temperature, humidity, cleanliness) - Safety equipment and conditions - Ergonomic considerations KNOWLEDGE AND INFORMATION: - Technical knowledge - Process documentation - Standards and specifications - Organizational knowledge FINANCIAL RESOURCES: - Operating budget - Capital for equipment - Training budget ENSURING AVAILABILITY: - Resource planning and scheduling - Maintenance programs - Backup/redundancy for critical resources - Capacity planning - Skills matrix and training plans
Follow-Up Questions
- How does the organization determine resource requirements for each process, including personnel, equipment, and infrastructure?
- What happens when resource constraints are identified that could affect process performance?
What to Sample
Select one process and verify that resource allocations (staffing, equipment, budget) are documented and that current availability matches the defined requirements.
Objective Evidence
- Process owner assignments
- Job descriptions with process responsibilities
- RACI matrices
- Organizational charts
- Procedures with roles defined
- Authority matrices
- Delegation of authority documents
- Approval limits documentation
Common Nonconformities
- No process owners assigned
- Unclear responsibilities
- Responsibility without authority
- Multiple people think they own same process
- No one accountable for process performance
- Roles not communicated to staff
Auditor Tips
Every process needs clear ownership and defined authorities. PROCESS OWNER: - Person accountable for process performance - Authority to make changes to process - Responsible for process improvement - Monitors process metrics - Reports on process performance RESPONSIBILITIES TO DEFINE: - Who performs each activity - Who reviews and approves outputs - Who handles nonconformities - Who makes decisions - Who communicates with other processes - Who maintains records AUTHORITIES TO DEFINE: - Authority to approve outputs - Authority to release product - Authority to stop the process - Authority to make changes - Authority to access resources - Authority to accept nonconforming product DOCUMENTATION OF R&A: - Job descriptions - Process procedures - Organizational charts - RACI matrices (Responsible, Accountable, Consulted, Informed) - Approval matrices - Delegation of authority documents IMPORTANT: Responsibility without authority is ineffective. Process owners must have authority to act.
Follow-Up Questions
- Are process owners formally appointed, and do they have documented authority commensurate with their responsibilities?
- How do process owners demonstrate accountability for process performance and improvement?
What to Sample
Review the organizational chart or responsibility matrix, then interview one process owner to confirm they understand and actively exercise their defined authority.
Objective Evidence
- Process FMEA (Failure Mode and Effects Analysis)
- Process risk assessments
- Risk registers by process
- Control plans addressing risks
- Risk treatment actions and records
- Opportunity assessment records
- Management review discussing process risks
Common Nonconformities
- No risk consideration at process level
- Risks identified but no actions taken
- Only focusing on risks, ignoring opportunities
- Process risks not linked to 6.1 actions
- Risk thinking not embedded in process management
Auditor Tips
Each process must consider and address risks and opportunities. PROCESS-LEVEL RISK THINKING: RISK IDENTIFICATION: - What could go wrong in this process? - What factors could cause process failure? - What are the consequences of failure? - What external factors could impact the process? TYPES OF PROCESS RISKS: - Quality risks (defects, nonconformities) - Delivery risks (delays, capacity issues) - Resource risks (equipment failure, staff turnover) - Supply risks (supplier issues, material shortages) - Compliance risks (regulatory, customer requirements) - Safety risks (accidents, injuries) RISK TREATMENT: - Avoid the risk (eliminate the activity) - Mitigate the risk (controls to reduce likelihood/impact) - Transfer the risk (insurance, outsourcing) - Accept the risk (with monitoring) OPPORTUNITY IDENTIFICATION: - How can this process be improved? - What efficiencies can be gained? - What new capabilities can be developed? - How can customer satisfaction be enhanced? LINK TO CLAUSE 6.1: - Process-level risks feed into overall risk assessment - Actions must be planned and implemented - Effectiveness must be evaluated ISO 9001 calls for "risk-based thinking," not formal risk management.
Follow-Up Questions
- How are the risks and opportunities identified under clause 6.1 integrated into individual process controls?
- Can you provide an example where a process-level risk led to a specific control or mitigation action?
What to Sample
Select two processes and verify that the risks identified in the risk register are addressed by specific controls or actions within those process procedures.
Objective Evidence
- Process performance reviews
- Process audit reports
- KPI trend analysis
- Management review minutes discussing processes
- Change requests and approvals
- Process improvement records
- Before/after comparison data
- Updated procedures following changes
Common Nonconformities
- Processes never evaluated
- Poor performance but no changes made
- Changes made without evaluation
- No process for making changes
- Changes not controlled or documented
- Impact of changes not assessed
Auditor Tips
Processes must be regularly evaluated and changed when needed. PROCESS EVALUATION: WHAT TO EVALUATE: - Are processes achieving intended results? - Are process KPIs meeting targets? - Is process output conforming to requirements? - Are there recurring problems? - Is the process efficient? - Are resources adequate? HOW TO EVALUATE: - Review process performance data - Analyze trends in KPIs - Internal process audits - Management reviews - Customer feedback analysis - Nonconformity analysis - Benchmarking against best practices WHEN TO EVALUATE: - Regularly (scheduled reviews) - After significant changes - When problems occur - When targets not met - As part of management review - During internal audits IMPLEMENTING CHANGES: - Identify need for change - Plan the change (including risk assessment) - Implement in controlled manner - Verify effectiveness - Update documentation - Communicate changes - Train affected personnel CHANGE CONTROL: - Changes should be managed, not ad-hoc - Consider impact on other processes - Maintain documented information
Follow-Up Questions
- What triggers a process evaluation beyond routine scheduled reviews?
- Can you provide a recent example where a process evaluation resulted in a change to achieve intended results?
What to Sample
Review process audit results or management review outputs for evidence of process evaluations and resulting changes implemented within the last 12 months.
Objective Evidence
- Improvement projects and records
- Before/after metrics showing improvement
- Lean/Six Sigma projects
- Kaizen event records
- Employee suggestion program
- Cost of quality trending down
- Customer satisfaction trending up
- Process capability improvements
- Innovation initiatives
Common Nonconformities
- No improvement activities
- Same problems recurring
- No improvement culture
- Improvements not sustained
- No resources for improvement
- Reactive only, no proactive improvement
Auditor Tips
Continual improvement is a core principle of ISO 9001. IMPROVEMENT FOCUS AREAS: PROCESS IMPROVEMENT: - Increase efficiency (reduce waste, time, cost) - Improve effectiveness (better results, fewer defects) - Enhance capability (more consistent, capable processes) - Reduce variation - Improve customer satisfaction QMS IMPROVEMENT: - Better integration of processes - More effective documentation - Improved communication - Enhanced risk management - Better use of technology - Stronger quality culture SOURCES OF IMPROVEMENT: - Analysis of data and trends - Audit findings - Customer feedback and complaints - Employee suggestions - Benchmarking - Management review outputs - Corrective action analysis - New technology opportunities IMPROVEMENT METHODOLOGIES: - PDCA (Plan-Do-Check-Act) - Lean (waste elimination) - Six Sigma (variation reduction) - Kaizen (continuous small improvements) - Process reengineering (major changes) - 8D problem solving - Root cause analysis IMPROVEMENT CULTURE: - Leadership commitment - Employee engagement - Recognition of improvements - Resources for improvement - Learning from failures
Follow-Up Questions
- How does the organization prioritize which processes to improve, and what methodology is used?
- Can you describe the relationship between process-level improvements and overall QMS improvement?
What to Sample
Review the continual improvement log or corrective action records for evidence of process improvements initiated and completed in the current audit cycle.
Objective Evidence
- The documented information MAINTAINED to support process operation - procedures, instructions, and forms for the key processes - present and used, not just on a shelf.
- The records RETAINED to have confidence processes ran as planned - completed forms, inspection/test records, logs - for a sample of processes.
- Evidence the EXTENT of documentation is appropriate to the organization's size and complexity - enough to control the processes, not bureaucratic overkill or dangerously thin.
- Document control applied to the maintained information (current, approved, available) and records (retrievable, protected) - link to 7.5.
- A check that the documented information is actually FOLLOWED in practice - the procedure matches what people do.
Common Nonconformities
- Minor NC: Records needed to show key processes ran as planned are not retained, so there is no evidence of conformity.
- Minor NC: Maintained documentation exists but is not followed in practice - the procedure and the work diverge.
- Minor NC: Documentation is excessive and bureaucratic, or so thin that key processes are uncontrolled.
- Observation: Documented information is not readily accessible to the people who need it at the point of work.
Auditor Tips
ISO 9001:2015 requires documented information but gives flexibility on extent. TWO TYPES OF DOCUMENTED INFORMATION: MAINTAINED (Procedures/Instructions): - "How we do things" - Procedures, work instructions, forms - Process descriptions - Guidelines and standards - These are controlled and kept current RETAINED (Records/Evidence): - "Evidence that we did things" - Completed forms and checklists - Test results and inspection records - Audit reports - Meeting minutes - These are preserved and protected "TO THE EXTENT NECESSARY": - ISO 9001 does not mandate specific documents - Organization determines what's needed based on: * Complexity of processes * Competence of personnel * Risk involved * Customer/regulatory requirements * Size of organization FACTORS AFFECTING EXTENT: - Simple processes with experienced staff = less documentation - Complex processes with high risk = more documentation - Regulatory requirements may mandate specific documents - Customer requirements may specify documentation KEY POINT: Documentation should add value, not be bureaucracy. Right-size documentation to actual needs.
Follow-Up Questions
- How does the organization determine the extent of documented information needed for each process?
- What is the retention policy for quality records, and how does it align with regulatory and contractual requirements?
- How does the organization ensure that documented information remains legible, identifiable, and retrievable over its retention period?
What to Sample
Select a high-risk process and verify both types of documented information exist: operational documents (procedures, work instructions) and retained records (completed forms, logs, test results).
Objective Evidence
- Procedures for key processes
- Work instructions
- Process flowcharts
- Forms and templates
- Controlled document list
- Document control procedures
- Evidence of document approval
- Evidence of document availability
Common Nonconformities
- No procedures exist
- Procedures outdated or not followed
- No document control system
- Documents not accessible
- Excessive unnecessary documentation
Auditor Tips
Documented information that is "maintained" = procedures, instructions, guidance. EXAMPLES OF MAINTAINED DOCUMENTED INFORMATION: - Quality policy and objectives - QMS scope - Process procedures - Work instructions - Forms and templates (blank) - Specifications - Standards - Guidelines CHARACTERISTICS: - Current/active documents - Subject to change control - Reviewed and approved - Available at point of use - Version controlled - Obsolete versions removed/controlled DOCUMENT CONTROL REQUIREMENTS (per 7.5): - Identification and description - Format and media - Review and approval - Availability and access - Protection - Change control - Retention and disposition RIGHT-SIZING: - Not every process needs detailed procedures - Consider complexity and risk - Consider competence of personnel - Competent staff may need less written instruction - High-risk or complex processes need more documentation
Follow-Up Questions
- How does the organization decide which operational documents (procedures, work instructions, forms) are necessary for each process?
- What is the document review and approval process, and how are obsolete documents prevented from unintended use?
What to Sample
Verify that the document master list is current, then select two procedures and confirm they are the latest revision and accessible at the point of use.
Objective Evidence
- Completed quality records
- Record retention schedule
- Record storage system (physical/electronic)
- Evidence of record protection (backups)
- Record retrieval capability
- Record access controls
- Record disposal procedures and evidence
Common Nonconformities
- No records retained
- Records incomplete or missing
- No retention schedule
- Records not retrievable
- Records not protected
- Premature disposal of records
Auditor Tips
Documented information that is "retained" = records, evidence. EXAMPLES OF RETAINED DOCUMENTED INFORMATION: - Completed forms and checklists - Inspection and test records - Audit reports - Management review minutes - Training records - Calibration records - Supplier evaluation records - Customer complaint records - Corrective action records - Design records - Production records CHARACTERISTICS: - Evidence of activities performed - Not changed after creation (immutable) - Protected from loss or damage - Retrievable when needed - Retained for defined periods - Eventually disposed of properly RECORD CONTROL REQUIREMENTS (per 7.5): - Identification - Storage (secure, protected) - Protection (backup, access control) - Retrieval (findable when needed) - Retention (how long to keep) - Disposition (how to dispose) RETENTION PERIODS: - Based on legal/regulatory requirements - Based on customer requirements - Based on product lifecycle - Based on organizational needs - Should be defined in record retention schedule
Follow-Up Questions
- How does the organization determine which records must be retained as evidence of process conformity?
- Can you demonstrate that records are available from a process completed six months ago?
What to Sample
Request records from a completed process (e.g., a production batch or service delivery from the past quarter) and verify they are retrievable, complete, and legible.
Objective Evidence
- Management-review records with top-management attendance and substantive input - verify leaders (not just the quality manager) attend, challenge the data, and make decisions, rather than receiving a presentation and signing off.
- Evidence the QMS is integrated into business decisions - strategic plans, budgets, and resourcing decisions that reflect quality objectives; QMS requirements built into how the business runs, not a parallel 'quality system'.
- Resource decisions - approvals (headcount, equipment, training, improvement projects) showing leadership provides what the QMS needs, with a check on cases where resources were requested and denied.
- Communications from top management about quality - town halls, all-hands, written messages - confirming leaders visibly promote the importance of effective quality management and of meeting requirements.
- Top-management engagement in improvement and corrective action - evidence leaders sponsor improvement initiatives and engage on significant nonconformities, rather than delegating them entirely.
Common Nonconformities
- Major NC: Top management is absent from management reviews or treats them as a quality-department exercise; the quality manager makes and owns all QMS decisions.
- Minor NC: Leadership cannot demonstrate the QMS is integrated with the business; quality runs as a separate compliance system disconnected from strategy.
- Minor NC: Resources needed for the QMS are routinely requested and denied, with quality treated as a cost rather than a business priority.
- Observation: Quality policy and objectives are signed by top management, but there is little other visible leadership involvement or communication about quality.
Auditor Tips
Top management must actively lead the QMS, not delegate accountability. This is about demonstrable action and involvement, not just signing documents. KEY LEADERSHIP ACTIONS: a) ACCOUNTABILITY - Cannot be delegated: - Top management owns QMS effectiveness - Personal responsibility for results - Cannot say "quality manager's problem" b) POLICY & OBJECTIVES: - Establish quality policy - Set quality objectives - Ensure alignment with business strategy - Ensure context-appropriate c) INTEGRATION: - QMS not separate from business - Embed in daily operations - Part of business planning - Not a parallel system d) PROMOTE PROCESS APPROACH & RISK-BASED THINKING: - Champion process thinking - Encourage risk awareness - Model risk-based decision making e) ENSURE RESOURCES: - Provide budget for QMS - Allocate personnel - Approve equipment/infrastructure - Make resources available when needed f) COMMUNICATE IMPORTANCE: - Talk about quality regularly - Include in meetings/communications - Recognize quality achievements - Address quality issues publicly g) ENSURE INTENDED RESULTS: - Monitor QMS performance - Review results - Take action when results not achieved - Drive towards objectives h) ENGAGE AND DIRECT PEOPLE: - Active involvement with staff - Provide direction - Support and enable - Remove barriers i) PROMOTE IMPROVEMENT: - Champion continuous improvement - Support improvement initiatives - Celebrate improvements - Challenge status quo j) SUPPORT MANAGEMENT ROLES: - Empower other managers - Ensure they lead in their areas - Provide authority and resources - Hold them accountable EVIDENCE OF LEADERSHIP: - Presence in management reviews - Decisions on resources and priorities - Communication to organization - Personal involvement in audits/reviews - Action on improvement opportunities
Follow-Up Questions
- How does top management personally demonstrate accountability for the effectiveness of the QMS beyond signing off on documents?
- Can you describe a recent decision where top management prioritized quality over schedule or cost pressures?
- How does top management stay informed about QMS performance between formal management reviews?
What to Sample
Review management review attendance records, resource allocation decisions, and internal communications from top management that reference quality objectives or QMS performance.
Objective Evidence
- The documented quality policy - verify it is appropriate to the organization's purpose and context (reflects what it actually does), and is authorized by top management.
- Evidence the policy provides a framework for setting quality objectives - the objectives can be traced to policy commitments.
- Explicit commitments in the policy to satisfy applicable requirements AND to continually improve the QMS (both must be present).
- Evidence the policy is reviewed for continuing suitability as the organization and context change, not frozen since certification.
- A check the policy is meaningful and usable - not a generic template nobody can connect to the work.
Common Nonconformities
- Minor NC: The quality policy is a generic template that does not reflect the organization's actual purpose or context.
- Minor NC: The policy omits a required commitment - to satisfy applicable requirements, or to continual improvement.
- Minor NC: The policy provides no framework from which quality objectives can be derived.
- Observation: The policy has never been reviewed for continuing suitability.
Auditor Tips
The quality policy is a top-level statement of the organization's intentions and direction regarding quality. QUALITY POLICY MUST: a) BE APPROPRIATE: - Reflects the organization's actual purpose - Aligned with business context (4.1) - Supports strategic direction - Relevant to what the organization does - Not generic or copy-pasted from template b) PROVIDE FRAMEWORK FOR OBJECTIVES: - Broad enough to encompass quality objectives - Directional guidance for setting objectives - Quality objectives derive from policy - Policy enables measurable goals c) COMMITMENT TO SATISFY REQUIREMENTS: - Explicit commitment to meet requirements - Customer requirements - Statutory and regulatory requirements - Organization's own requirements - Clear commitment statement d) COMMITMENT TO CONTINUAL IMPROVEMENT: - Explicit commitment to improve - Ongoing improvement mindset - Not just maintain status quo - Culture of getting better QUALITY POLICY CHARACTERISTICS: - Brief and memorable (1-2 paragraphs typical) - Clear and understandable language - Authentic to the organization - Approved by top management - Documented - Not overly generic or vague
Follow-Up Questions
- When was the quality policy last reviewed, and what prompted any revisions?
- How does the quality policy connect to the organization's strategic direction identified in clause 4.1?
- Can members of the operational workforce articulate the quality policy in their own words?
What to Sample
Obtain the current quality policy document, verify the approval date and signatories, then interview two to three employees at different levels to assess understanding and application.
Objective Evidence
- Evidence responsibilities and authorities for relevant roles are assigned, communicated, and understood - job descriptions, a RACI, or process-owner assignments, confirmed by asking people what they own.
- Specific assignment of authority for ensuring the QMS conforms to ISO 9001 and for reporting QMS performance to top management (the named 5.3 responsibilities).
- Assignment of authority for ensuring processes deliver intended outputs (process owners) and for promoting customer focus across the organization.
- Assignment of authority for maintaining QMS integrity when changes are planned and made.
- Evidence authority matches responsibility - people held accountable for outcomes actually have the authority to act.
Common Nonconformities
- Minor NC: Roles and responsibilities for the QMS are not assigned or communicated, so accountability is unclear.
- Minor NC: No one is assigned authority for ensuring QMS conformance or for reporting QMS performance to top management.
- Minor NC: Responsibility is assigned without matching authority, so owners cannot actually act.
- Observation: All QMS responsibility effectively rests with the quality manager, with no distribution to process owners.
Auditor Tips
Top management must ensure roles are clearly defined and communicated. While these responsibilities can be assigned to others, top management retains accountability. KEY REQUIREMENTS: ASSIGN, COMMUNICATE, AND UNDERSTAND: - ASSIGN: Specific people given specific responsibilities - COMMUNICATE: Roles and responsibilities made known - UNDERSTAND: People understand what they're responsible for SPECIFIC RESPONSIBILITIES TO ASSIGN: a) QMS CONFORMANCE: - Someone responsible for ensuring QMS meets ISO 9001 - Often Quality Manager or similar role - Monitors compliance with standard - Coordinates QMS activities - Can be distributed across multiple roles b) PROCESS PERFORMANCE: - Process owners ensuring processes deliver outputs - Monitoring process performance - Taking action when processes underperform - Each process should have an owner - Clear accountability for results c) REPORTING TO TOP MANAGEMENT: - Someone responsible for QMS performance reporting - Prepare management review inputs - Report on improvement opportunities - Provide QMS metrics and analysis - Regular communication with top management d) PROMOTING CUSTOMER FOCUS: - Someone ensures customer focus is promoted - Not just sales/customer service - Throughout entire organization - Customer perspective kept front and center - Voice of customer communicated e) MAINTAINING QMS INTEGRITY DURING CHANGES: - Someone ensures QMS not compromised during change - When processes change, QMS requirements still met - When organization changes, QMS adapts appropriately - Change management with QMS in mind IMPORTANT NOTES: - No requirement for "Management Representative" role (removed in 2015) - Responsibilities can be assigned to one person or distributed - Top management retains ACCOUNTABILITY even if responsibility assigned - Responsibilities should be documented (org charts, job descriptions, etc.) - People assigned must have appropriate authority to fulfill responsibilities DOCUMENTATION: - Organizational charts - Job descriptions - Responsibility matrices (RACI charts) - Process ownership assignments - Authority delegations - Position descriptions
Follow-Up Questions
- How are roles, responsibilities, and authorities communicated to personnel, and how is understanding verified?
- What happens when a key quality role becomes vacant, and how is continuity ensured?
- Are there any responsibilities that overlap or create conflicts of interest between roles?
What to Sample
Review the organizational chart, responsibility assignment matrix, and job descriptions for key quality roles; interview two role holders to confirm they understand their authority boundaries.
Objective Evidence
- Management review attendance by top management
- Decisions made by top management on QMS issues
- Top management actions on audit findings
- Resource decisions for QMS
- Communications from top management taking ownership
Common Nonconformities
- Top management delegates all QMS decisions
- No top management presence in QMS activities
- Quality manager held accountable instead of top management
- Top management unaware of QMS performance
Auditor Tips
Accountability for QMS effectiveness cannot be delegated. KEY POINTS: - Top management personally owns QMS effectiveness - Cannot delegate this accountability to quality manager - Responsible for overall QMS performance and results - Must answer for QMS failures - Demonstrated through active involvement - Not just signing off but owning outcomes HOW ACCOUNTABILITY IS DEMONSTRATED: - Active participation in management reviews - Making key QMS decisions - Taking action when QMS underperforms - Responding to audit findings - Ensuring resources for QMS - Personal engagement with QMS issues
Follow-Up Questions
- In what specific ways does top management take accountability rather than delegating all QMS responsibilities?
- How does top management respond when audit findings indicate QMS ineffectiveness?
What to Sample
Review management review minutes for evidence of top management taking ownership of QMS performance issues and directing corrective actions with allocated resources.
Objective Evidence
- Quality policy aligned with organization's actual work
- Evidence policy reviewed against context
- Strategic plan showing policy alignment
- Policy specific to industry/products
Common Nonconformities
- Generic copy-paste policy
- Policy disconnected from strategy
- Policy doesn't reflect actual business
- Policy not reviewed for appropriateness
Auditor Tips
Policy must fit the organization, not be generic. APPROPRIATE TO PURPOSE: - Reflects what the organization does - Relevant to products/services offered - Aligns with mission and vision - Meaningful to the organization's work APPROPRIATE TO CONTEXT: - Considers external context (4.1) - Considers internal context (4.1) - Appropriate to industry/sector - Reflects regulatory environment - Suitable for organization size/complexity SUPPORTS STRATEGIC DIRECTION: - Aligned with business strategy - Enables strategic goals - Consistent with organizational values - Supports long-term objectives AVOID: - Generic policies from templates - Policies that could apply to any organization - Disconnection from business reality - Conflicting with strategic goals
Follow-Up Questions
- How does the organization verify that the quality policy remains appropriate when the business context changes?
- Can you explain how the policy's commitments translate into operational decisions?
What to Sample
Compare the quality policy statements against recent strategic planning outputs and verify alignment with the context analysis from clause 4.1.
Objective Evidence
- Assignment of QMS conformance responsibility
- Job description for quality role
- Organizational chart showing quality function
- Documentation of responsibility assignment
Common Nonconformities
- No one assigned this responsibility
- Responsibility unclear or informal
- No authority to act
- QMS conformance nobody's job
Auditor Tips
Someone must be responsible for ensuring the QMS meets ISO 9001. RESPONSIBILITY INCLUDES: - Ensuring QMS meets all ISO 9001 requirements - Monitoring QMS compliance - Addressing gaps in compliance - Coordinating QMS activities - Preparing for audits - Maintaining system integrity WHO CAN BE ASSIGNED: - Quality Manager/Director - QMS Coordinator - Distributed across multiple people - No "Management Representative" title required NOTE ON MANAGEMENT REPRESENTATIVE: - ISO 9001:2015 removed specific MR requirement - Responsibilities can be distributed - Still need someone(s) accountable - Top management retains accountability AUTHORITY NEEDED: - Access to all areas and information - Ability to implement changes - Authority to enforce compliance - Resources to maintain system
Follow-Up Questions
- Who has been assigned responsibility for ensuring QMS conformity to ISO 9001, and what authority do they have to stop nonconforming work?
- How does this person escalate systemic QMS issues to top management?
What to Sample
Verify the appointment of the management representative or equivalent role, and review evidence of their reporting to top management on QMS conformity.
Objective Evidence
- Quality policy document
- Quality objectives documentation
- Strategic plan showing alignment
- Top management approval of policy/objectives
- Management review of policy/objectives
Common Nonconformities
- No quality policy or objectives
- Policy/objectives disconnected from strategy
- Generic policy not relevant to organization
- Objectives not achievable in current context
Auditor Tips
Top management must ensure policy and objectives exist and align with strategy. REQUIREMENTS: - Quality policy established (see 5.2) - Quality objectives established (see 6.2) - Both compatible with organizational context (4.1) - Both support strategic direction - Policy and objectives work together COMPATIBILITY MEANS: - Policy reflects business purpose - Objectives achievable given context - Strategic goals supported by quality goals - No conflict between business and quality direction
Follow-Up Questions
- How does top management ensure that quality objectives are established at relevant functions and levels?
- What process ensures that the quality policy and objectives are aligned and mutually reinforcing?
What to Sample
Review the quality objectives register and verify that objectives exist for each relevant function, with documented links back to the quality policy commitments.
Objective Evidence
- Quality objectives derived from policy
- Clear link between policy and objectives
- Policy statements that enable objectives
- Documentation showing policy-objective relationship
Common Nonconformities
- Policy doesn't support objectives
- No connection between policy and objectives
- Objectives unrelated to policy statements
- Policy too vague for objectives
Auditor Tips
Policy enables setting measurable objectives. FRAMEWORK MEANS: - Policy provides direction for objectives - Objectives can be derived from policy - Policy themes translate to measurable goals - Policy is broad enough to encompass objectives - Connection between policy and objectives is clear HOW POLICY PROVIDES FRAMEWORK: - Policy commitments become objective areas - Policy statements guide objective setting - Example: Policy says "deliver on time" → Objective: 95% on-time delivery - Example: Policy says "continuously improve" → Objective: 10% defect reduction RELATIONSHIP: - Policy = What we commit to (direction) - Objectives = Measurable targets to achieve policy - Policy and objectives must align - Objectives demonstrate policy implementation
Follow-Up Questions
- Can you demonstrate how the quality policy is used as a framework when setting or revising quality objectives?
- How do objective owners trace their objectives back to specific policy commitments?
What to Sample
Select two quality objectives and trace each back to a specific quality policy statement to verify the framework relationship is maintained.
Objective Evidence
- Process ownership assignments
- Process documentation with owners identified
- Performance metrics by process
- Process owner accountability
Common Nonconformities
- Processes with no owners
- Owners not accountable for results
- No monitoring of process outputs
- Process failures without accountability
Auditor Tips
Process owners must be assigned and held accountable for results. RESPONSIBILITY INCLUDES: - Ensuring processes achieve intended outputs - Monitoring process performance - Taking action when processes underperform - Maintaining process effectiveness - Process improvement PROCESS OWNER CONCEPT: - Each process should have an owner - Owner accountable for process results - Owner has authority to make changes - Owner monitors process performance - Owner reports on process status EXAMPLES: - Production Manager owns production process - Sales Manager owns sales/quotation process - HR Manager owns recruitment process - Design Manager owns design process INTENDED OUTPUTS: - What the process is supposed to produce - Conforming products/services - Required documentation - Decisions and approvals
Follow-Up Questions
- How do process owners ensure that their processes deliver intended outputs consistently?
- What reporting mechanism exists for process owners to flag when processes are not performing as planned?
What to Sample
Interview one process owner and verify they can demonstrate current process performance data, recent process changes, and how deviations are managed.
Objective Evidence
- Business processes including QMS requirements
- Strategic plans including quality elements
- Business dashboards with quality metrics
- Process documentation with integrated QMS
- Business decisions considering quality
Common Nonconformities
- QMS separate from business operations
- Two sets of processes (business vs. quality)
- QMS seen as overhead not value
- No quality in business planning
Auditor Tips
QMS must be integrated, not a parallel system. INTEGRATION MEANS: - QMS is part of how business operates - Not a separate "quality system" - QMS requirements embedded in daily operations - Quality considerations in all business decisions - No disconnect between business and QMS EXAMPLES OF INTEGRATION: - Quality metrics in business dashboards - QMS requirements in process procedures - Quality considerations in business planning - Risk-based thinking in all decisions - Customer focus embedded throughout AVOID: - QMS as compliance exercise only - Separate "quality documentation" ignored in practice - Quality vs. business mentality - QMS seen as burden not enabler
Follow-Up Questions
- How has top management ensured that QMS requirements are embedded in business processes rather than treated as a parallel system?
- Can you give an example of a business process where quality requirements are integrated into day-to-day operations?
What to Sample
Select one operational process (e.g., procurement, production planning) and verify that QMS requirements are built into the standard operating procedure rather than addressed in a separate quality overlay.
Objective Evidence
- Policy statement including commitment to requirements
- Policy text mentioning customer/regulatory compliance
- Explicit requirement satisfaction commitment
Common Nonconformities
- Policy has no commitment to requirements
- Commitment vague or implied only
- Missing regulatory/statutory commitment
- Only customer requirements mentioned
Auditor Tips
Policy must explicitly commit to meeting requirements. APPLICABLE REQUIREMENTS INCLUDE: - Customer requirements - Statutory requirements (laws) - Regulatory requirements (regulations) - ISO 9001 requirements - Organization's own requirements - Industry standards COMMITMENT MEANS: - Explicit statement in policy - Not implied, but stated - Organization pledges to meet requirements - Binding commitment to all applicable requirements EXAMPLES OF COMMITMENT STATEMENTS: - "We are committed to meeting customer requirements" - "We comply with all applicable regulations" - "We satisfy all requirements relevant to our products" NOT JUST CUSTOMER: - All applicable requirements - Legal compliance - Regulatory compliance - Standard compliance - Contractual compliance
Follow-Up Questions
- How does the quality policy address compliance with applicable statutory, regulatory, and customer requirements?
- Is the commitment to satisfy requirements general, or does it reference specific categories of requirements relevant to the organization?
What to Sample
Review the quality policy text for an explicit commitment to meeting applicable requirements, then verify that a register of applicable requirements exists and is current.
Objective Evidence
- QMS performance reports
- Management review input reports
- Regular quality reports to leadership
- Improvement recommendations
Common Nonconformities
- No reporting to top management
- Top management unaware of QMS status
- No regular performance updates
- No one responsible for reporting
Auditor Tips
Someone must report QMS performance to top management. REPORTING RESPONSIBILITY INCLUDES: - Preparing QMS performance reports - Gathering and analyzing QMS data - Identifying improvement opportunities - Presenting at management reviews - Regular updates to leadership WHAT TO REPORT: - QMS performance against objectives - Audit results - Customer satisfaction - Process performance - Nonconformity and corrective action status - Risks and opportunities - Improvement opportunities TO TOP MANAGEMENT: - Regular reporting (not just management review) - Timely information for decisions - Accurate and relevant data - Actionable recommendations LINK TO 9.3 (Management Review): - Provides input to management review - Ensures review has quality data - Facilitates effective decision-making
Follow-Up Questions
- Who is responsible for reporting on QMS performance to top management, and how frequently does this reporting occur?
- What format does the performance reporting take, and does it include both quantitative metrics and qualitative assessments?
What to Sample
Review the last two QMS performance reports submitted to top management and verify they cover key metrics including customer satisfaction, process performance, and nonconformity trends.
Objective Evidence
- Leadership communications mentioning processes/risks
- Meeting minutes showing process/risk discussions
- Training on process approach and risk thinking
- Process maps used in business discussions
- Risk considerations in management decisions
Common Nonconformities
- No awareness of process approach
- Risk not considered in decisions
- Functional silos without process thinking
- Reactive firefighting culture
Auditor Tips
Top management must actively promote these core concepts. PROCESS APPROACH: - Understanding activities as interconnected processes - Managing inputs, outputs, and interactions - Process ownership and accountability - Process performance measurement - Process improvement RISK-BASED THINKING: - Considering risks in decisions - Proactive risk identification - Addressing risks and opportunities - Risk-aware culture - Not just formal risk management HOW TO PROMOTE: - Talk about processes and risks in meetings - Ask process and risk questions - Model risk-based decision making - Recognize process improvements - Provide training and awareness - Use process and risk language
Follow-Up Questions
- How has top management promoted the process approach throughout the organization?
- What evidence exists that risk-based thinking is applied in operational decision-making, not just in formal risk assessments?
What to Sample
Review training records or communications from top management promoting process approach and risk-based thinking, then interview two middle managers to assess whether these concepts influence their daily decisions.
Objective Evidence
- Policy statement with continual improvement commitment
- Policy text mentioning improvement/enhancement
- Explicit QMS improvement commitment
Common Nonconformities
- No mention of improvement in policy
- Only maintenance, no improvement
- Improvement commitment vague
- No QMS improvement mentioned
Auditor Tips
Policy must explicitly commit to ongoing improvement. CONTINUAL IMPROVEMENT COMMITMENT: - Explicit statement in policy - Not just maintaining status quo - Commitment to getting better - Ongoing improvement mindset - Improvement of the QMS itself WHAT CONTINUAL IMPROVEMENT MEANS: - Recurring activity to enhance performance - Not one-time, but ongoing - Small incremental and larger breakthrough improvements - PDCA cycle applied continuously - Learning and getting better EXAMPLES OF COMMITMENT STATEMENTS: - "We are committed to continually improving our QMS" - "We strive for continuous improvement in quality" - "We pursue ongoing enhancement of our processes" FOCUS ON QMS: - Commitment specifically includes QMS improvement - Not just product/service improvement - Improving the system that delivers quality
Follow-Up Questions
- How is the commitment to continual improvement operationalized beyond the policy statement?
- Can you point to specific improvement initiatives that were driven by the quality policy commitment?
What to Sample
Verify the policy includes an explicit continual improvement commitment, then review the improvement log for evidence that improvement initiatives reference or align with this commitment.
Objective Evidence
- Assignment of customer focus responsibility
- Customer communication activities
- Customer awareness training
- Customer focus programs
Common Nonconformities
- Customer focus only in sales
- No one promoting customer awareness
- Customer feedback not shared
- Customer issues hidden from organization
Auditor Tips
Someone must champion customer focus across the organization. RESPONSIBILITY INCLUDES: - Promoting customer awareness - Championing customer needs - Communicating customer feedback - Ensuring customer focus in all areas - Voice of customer representation THROUGHOUT THE ORGANIZATION: - Not just sales or customer service - All functions and departments - All levels of the organization - Everyone understands customer importance HOW TO PROMOTE: - Share customer feedback widely - Include customer perspective in decisions - Train on customer requirements - Celebrate customer successes - Address customer issues visibly - Customer metrics visible to all WHO CAN BE ASSIGNED: - Could be quality manager - Could be customer service manager - Could be any senior leader - Could be distributed responsibility
Follow-Up Questions
- How is customer focus promoted across functions that do not have direct customer contact?
- What mechanisms exist for customer feedback to reach personnel in production, design, or support functions?
What to Sample
Interview personnel in a non-customer-facing function (e.g., warehouse, maintenance) and assess whether they understand how their work affects customer satisfaction.
Objective Evidence
- Budget allocation for QMS activities
- Staffing plans for quality roles
- Resource request approvals
- Capital investment in quality
- Training budget allocation
- Management review discussing resources
Common Nonconformities
- Chronic resource shortages
- QMS resource requests consistently denied
- Understaffed quality function
- No budget for quality improvements
Auditor Tips
Top management must ensure QMS has necessary resources. TYPES OF RESOURCES: - People (staffing, competence) - Infrastructure (facilities, equipment, IT) - Environment (workplace conditions) - Monitoring and measuring resources - Knowledge (organizational knowledge) - Financial resources (budget) TOP MANAGEMENT RESPONSIBILITY: - Approve resource requests - Allocate budget for QMS - Prioritize QMS resource needs - Remove resource barriers - Ensure timely availability - Address resource constraints NOT JUST APPROVING: - Proactively ensuring availability - Anticipating resource needs - Not waiting for problems to provide resources
Follow-Up Questions
- Has there been a recent instance where a resource request for the QMS was denied, and what was the justification?
- How does the budgeting process account for QMS resource needs including training, equipment calibration, and system maintenance?
What to Sample
Review the QMS budget allocation or resource plans for the current period, and cross-reference with any unfulfilled resource requests documented in management reviews.
Objective Evidence
- Evidence the policy is available and maintained as documented information (controlled, current, accessible).
- Evidence the policy is communicated AND understood within the organization - confirmed by asking staff what it means for their work, not just whether it is posted.
- Evidence the policy is APPLIED - reflected in how decisions and work are actually done, not just displayed.
- Evidence the policy is available to relevant interested parties where appropriate (e.g. on the website, to customers).
- Communication records - induction, training, intranet, displays - showing the policy was actively shared, not passively posted.
Common Nonconformities
- Minor NC: Employees are unaware of the quality policy or cannot explain what it means for their work, so it is communicated in name only.
- Minor NC: The policy is not accessible to the people who need it (locked in an office, not shared at induction).
- Minor NC: The policy is not made available to relevant interested parties where appropriate.
- Observation: The policy is posted but there is no evidence it is applied in actual decisions and work.
Auditor Tips
The quality policy must be actively communicated and available, not just sitting in a file. COMMUNICATION REQUIREMENTS: a) AVAILABLE AND MAINTAINED: - Documented (can be electronic or paper) - Accessible to those who need it - Version controlled - Current version available - Maintained (kept up to date) b) COMMUNICATED, UNDERSTOOD, AND APPLIED: - COMMUNICATED: Actively shared with employees * New employee orientation * Periodic reminders * Posted in visible locations * Included in training * On intranet or company portal - UNDERSTOOD: Employees comprehend it * Explained not just posted * Training on meaning and application * Managers discuss with teams * Awareness verified - APPLIED: Put into practice * Used in decision-making * Referenced in work activities * Guides behavior and priorities * Lives in daily operations c) AVAILABLE TO INTERESTED PARTIES: - Available to external parties as appropriate: * Customers (if requested) * Suppliers/partners * Certification bodies * Public (on website often) - Don't need to proactively distribute to all - Must be available when requested - Transparency and accessibility COMMUNICATION METHODS: - Posters/displays in facilities - Employee handbook - Intranet/company portal - Company website - New hire orientation - All-hands meetings - Email communications - Team meetings - Quality training sessions - Quality manual (if exists)
Follow-Up Questions
- Through what channels is the quality policy communicated to all personnel, and how is receipt confirmed?
- How is the quality policy made available to external interested parties when appropriate?
- When was the quality policy last updated, and how was the revised version communicated?
What to Sample
Check for the quality policy display at key locations (reception, shop floor, intranet), verify document control records show it is a controlled document, and ask three employees from different departments to explain it.
Objective Evidence
- Change management process including QMS
- QMS impact assessment for changes
- Documentation updates after changes
- Verification of QMS after changes
Common Nonconformities
- QMS ignored during organizational changes
- Changes break QMS processes
- Documentation not updated
- No QMS oversight of changes
Auditor Tips
Someone must ensure QMS remains effective when changes occur. RESPONSIBILITY INCLUDES: - Overseeing QMS changes - Ensuring changes don't break the system - Managing QMS transition during change - Validating QMS effectiveness after changes - Preventing unintended consequences TYPES OF CHANGES REQUIRING ATTENTION: - Organizational restructuring - Process changes - System upgrades - Scope changes - Mergers/acquisitions - Technology changes - Personnel changes (especially key roles) - Documentation changes INTEGRITY MEANS: - QMS continues to meet ISO 9001 - Processes remain effective - Documentation stays aligned - Responsibilities stay clear - Nothing falls through cracks CHANGE MANAGEMENT: - Plan changes with QMS in mind - Assess impact on QMS - Update documentation - Train affected personnel - Verify effectiveness after change
Follow-Up Questions
- How is QMS integrity maintained during organizational changes such as restructuring, mergers, or system transitions?
- What change management controls exist to prevent uncontrolled changes that could compromise QMS integrity?
What to Sample
Review records from a recent organizational change (restructuring, system migration, process redesign) and verify that QMS integrity was explicitly considered and maintained throughout the transition.
Objective Evidence
- Communications from top management about quality
- Town hall presentations mentioning quality
- Email communications about quality importance
- Quality messages in employee communications
- Leaders discussing quality in meetings
Common Nonconformities
- No communication about quality from leadership
- Quality only mentioned during audits
- Mixed messages about quality priority
- Actions contradict quality communications
Auditor Tips
Top management must actively communicate quality importance. WHAT TO COMMUNICATE: - Why quality matters to the organization - Importance of meeting QMS requirements - Connection between quality and business success - Customer focus importance - Individual responsibility for quality HOW TO COMMUNICATE: - Town halls and all-hands meetings - Email and written communications - One-on-one conversations - Team meetings - Performance discussions - Reinforcing messages regularly ACTIONS SPEAK LOUDER: - Communication backed by action - Walking the talk - Visible commitment not just words - Consistent messaging - Quality in all communications
Follow-Up Questions
- What specific communication methods does top management use to reinforce the importance of quality management?
- How does the organization verify that these communications are understood and taken seriously at the operational level?
What to Sample
Review internal communications (town halls, newsletters, email directives) from top management within the last 12 months for quality-related messaging, and interview two frontline employees about their awareness.
Objective Evidence
- Quality policy document
- Policy in document control system
- Policy accessible in multiple locations
- Policy version control
- Evidence policy is maintained current
Common Nonconformities
- Policy not documented
- Policy not accessible
- Policy out of date
- No version control on policy
Auditor Tips
Policy must be documented, accessible, and kept current. AVAILABLE MEANS: - Accessible to those who need it - Can be found when needed - Not locked away or hidden - Easily accessible formats - Multiple locations if needed MAINTAINED MEANS: - Kept up to date - Reviewed for continued adequacy - Version controlled - Current version available - Obsolete versions removed/controlled DOCUMENTED INFORMATION: - Written format (paper or electronic) - Part of controlled documentation - Subject to document control requirements - Can be in quality manual, standalone document, or other format
Follow-Up Questions
- Is the quality policy maintained under document control with revision history and approval signatures?
- Where is the documented quality policy stored, and who has access?
What to Sample
Verify the quality policy is registered in the document control system with current revision status, approval date, and authorized signatories.
Objective Evidence
- QMS performance reports to top management
- Management review outputs
- Actions taken when results not achieved
- Quality metrics trending toward objectives
- Evidence of QMS producing conforming products
Common Nonconformities
- QMS not meeting objectives
- No monitoring of QMS results
- Poor results with no management action
- QMS exists but doesn't deliver value
Auditor Tips
Top management must ensure QMS delivers what it's supposed to. INTENDED RESULTS OF QMS: - Conforming products and services - Enhanced customer satisfaction - Addressing risks and opportunities - Meeting quality objectives - Effective processes - Continual improvement HOW TO ENSURE: - Monitor QMS performance - Review results regularly - Take action when results not achieved - Management reviews - Analyze trends - Address root causes of failures ACTIVE INVOLVEMENT: - Not passive waiting for reports - Driving towards results - Removing barriers to success - Taking corrective action
Follow-Up Questions
- What evidence demonstrates that the QMS is achieving its intended results, and how does top management monitor this?
- When the QMS has not achieved intended results, what actions has top management directed?
What to Sample
Review the most recent management review output for evidence that QMS effectiveness was evaluated against intended results and that actions were assigned where gaps were identified.
Objective Evidence
- Communication records (orientation, training)
- Policy posted in facilities
- Employee awareness verification
- Policy in employee materials
- Evidence of policy application in decisions
Common Nonconformities
- Employees unaware of policy
- Policy not communicated
- No understanding of policy meaning
- Policy not applied in practice
Auditor Tips
Policy must be effectively communicated to and used by employees. COMMUNICATED: - Actively shared with employees - Not just posted, but explained - Multiple communication channels - Regular reinforcement - Part of onboarding COMMUNICATION METHODS: - New employee orientation - Posted in work areas - Company intranet/portal - Employee handbook - Team meetings - All-hands meetings - Training sessions UNDERSTOOD: - Employees comprehend the policy - Not just memorized, but meaningful - Can explain what it means - Know how it applies to their work - Awareness verified APPLIED: - Put into practice daily - Guides decisions and behavior - Referenced in work activities - Lives in operations, not just on paper - Visible in how work is done
Follow-Up Questions
- What methods are used to ensure the quality policy is not just communicated but understood and applied?
- How does the organization assess whether personnel at all levels can relate their work to the quality policy?
What to Sample
Interview employees at three organizational levels (management, supervisory, operational) and assess whether they can explain how the quality policy applies to their specific role.
Objective Evidence
- Employee engagement initiatives
- Quality suggestion programs
- Training and development programs
- Recognition for quality contributions
- Leadership accessibility and engagement
Common Nonconformities
- No employee engagement in quality
- Top-down only approach
- No support for employees
- Employees disconnected from QMS
Auditor Tips
Top management must actively engage people in quality. ENGAGE: - Involve people in quality activities - Listen to ideas and feedback - Create opportunities for participation - Foster quality ownership at all levels - Recognize contributions DIRECT: - Provide clear direction - Set expectations - Guide priorities - Give feedback - Align efforts toward objectives SUPPORT: - Provide resources needed - Remove barriers - Enable success - Provide training and development - Be available and accessible ALL THREE TOGETHER: - Not just directing (command) - Not just supporting (enablement without direction) - Active engagement creates commitment
Follow-Up Questions
- How does top management engage and support personnel to contribute to QMS effectiveness?
- What recognition or incentive mechanisms exist to encourage employee contributions to quality improvement?
What to Sample
Review employee engagement survey results, suggestion program records, or improvement team participation data for evidence that personnel are actively contributing to QMS effectiveness.
Objective Evidence
- Policy on company website
- Policy available on request
- Policy shared with customers/suppliers
- External access to policy documented
Common Nonconformities
- Policy not available externally at all
- Refusal to share policy when requested
- No external access mechanism
Auditor Tips
External parties should have access to policy when appropriate. AVAILABLE TO INTERESTED PARTIES: - Customers (current and potential) - Suppliers and partners - Regulators and certification bodies - Shareholders/investors - Public (if appropriate) AS APPROPRIATE MEANS: - Not mandatory for all parties - Organization determines appropriateness - Consider who needs/wants access - Balance transparency with practicality WAYS TO MAKE AVAILABLE: - Company website (common approach) - On request (provide when asked) - In proposals/contracts - In marketing materials - In supplier portals - At reception/lobby NOT REQUIRED: - Proactive distribution to all - Forcing policy on parties - Universal publication
Follow-Up Questions
- Which external interested parties have been provided access to the quality policy, and through what means?
- Is the quality policy published on the organization's website or included in customer-facing documentation?
What to Sample
Verify the quality policy is accessible to relevant external parties (e.g., posted on the website, included in supplier agreements, available on request) and confirm the version matches the internal controlled copy.
Objective Evidence
- Improvement initiatives supported by management
- Leadership communications promoting improvement
- Recognition programs for improvements
- Resources allocated for improvement
- Improvement metrics and trends
Common Nonconformities
- No improvement culture
- Status quo accepted
- Improvement ideas rejected
- No resources for improvement
Auditor Tips
Top management must actively promote continual improvement. PROMOTING IMPROVEMENT: - Champion improvement mindset - Encourage improvement ideas - Support improvement projects - Allocate resources for improvement - Recognize improvement achievements - Challenge status quo ACTIONS TO PROMOTE: - Talk about improvement regularly - Ask "how can we do better?" - Celebrate successful improvements - Provide improvement training - Create improvement opportunities - Lead by example CULTURE OF IMPROVEMENT: - Not accepting "good enough" - Learning from failures - Innovation encouraged - Kaizen/continuous improvement embedded
Follow-Up Questions
- How does top management actively promote improvement beyond formal corrective action processes?
- Can you describe a recent improvement initiative that was championed by top management?
What to Sample
Review improvement project records, innovation initiatives, or Kaizen event logs for evidence of top management sponsorship or active participation in improvement activities.
Objective Evidence
- Management development programs
- Delegation of quality responsibilities
- Manager involvement in quality activities
- Recognition of manager quality leadership
- Manager-level quality objectives and accountability
Common Nonconformities
- Only top management involved in quality
- Managers not empowered for quality
- No quality leadership at department level
- Middle management bypassed on quality
Auditor Tips
Top management must enable other managers to lead quality in their areas. SUPPORTING OTHER MANAGERS: - Empower them to lead - Provide authority to act - Ensure they have resources - Hold them accountable for quality in their area - Develop their quality leadership capability CASCADING LEADERSHIP: - Quality leadership not just at top - All managers lead quality in their areas - Production managers lead production quality - Service managers lead service quality - Department heads own department quality HOW TO SUPPORT: - Delegate authority - Provide training - Include in quality planning - Recognize their quality leadership - Remove barriers they face
Follow-Up Questions
- How does top management support department heads and middle managers in demonstrating quality leadership within their areas?
- What development opportunities or resources are provided to help other managers fulfill their leadership role in quality?
What to Sample
Interview two department managers about the support they receive from top management for quality leadership, and review training or development records related to quality management competence for management roles.
Objective Evidence
- Evidence top management ensures customer and applicable statutory/regulatory requirements are determined, understood, and consistently met - not just delegated to sales/quality.
- Evidence leadership ensures the risks and opportunities that can affect conformity and customer satisfaction are determined and addressed (link to 6.1).
- Customer-satisfaction data and complaint trends reviewed by top management, with action - showing the focus is maintained, not seasonal.
- Customer-focused objectives owned at leadership level, and evidence management acts on customer issues (visits, escalations, improvement initiatives).
- Evidence customer focus reaches across the organization (operations, design, support), not only the sales department.
Common Nonconformities
- Minor NC: Customer focus lives only in the sales/customer-service function; operations and other areas show no customer-requirement awareness.
- Minor NC: Customer complaints and satisfaction data are not reviewed by top management, so leadership is unaware of customer issues.
- Minor NC: Risks/opportunities affecting conformity and customer satisfaction are not determined or addressed by leadership.
- Observation: Customer satisfaction is declining with no leadership-driven response.
Auditor Tips
Top management must ensure customer focus is maintained throughout the organization, not just in sales or customer service. KEY REQUIREMENTS: a) DETERMINE, UNDERSTAND, AND MEET REQUIREMENTS: - Customer requirements identified and documented - Statutory/regulatory requirements understood - Requirements translated into specifications - Requirements consistently delivered - Processes ensure requirement fulfillment b) RISKS AND OPPORTUNITIES: - Risks to product/service conformity identified - Risks to customer satisfaction addressed - Opportunities to enhance satisfaction pursued - Risk-based approach to customer satisfaction - Proactive management of customer-related risks c) MAINTAIN CUSTOMER SATISFACTION FOCUS: - Customer satisfaction actively monitored - Improvement actions to enhance satisfaction - Customer feedback acted upon - Customer-centric culture - Continuous focus on customer needs LEADERSHIP ACTIONS FOR CUSTOMER FOCUS: - Set customer satisfaction objectives - Review customer feedback regularly - Visit customers personally - Respond to customer issues - Celebrate customer successes - Include customer metrics in dashboards - Make customer-focused decisions - Resource customer satisfaction initiatives
Follow-Up Questions
- How does top management ensure that customer focus permeates the entire organization and is not confined to sales or customer service?
- What mechanisms exist for top management to stay directly informed about customer satisfaction trends?
- How does the organization balance customer requirements with statutory and regulatory obligations when they conflict?
What to Sample
Review customer satisfaction data presented to top management, along with evidence of actions taken in response to negative trends or specific customer complaints.
Objective Evidence
- Customer requirements register
- Regulatory requirements register
- Contract review records
- Product specifications
- Compliance verification records
- Customer satisfaction data showing requirements met
Common Nonconformities
- Requirements not documented
- Staff unaware of requirements
- Recurring failures to meet requirements
- Regulatory requirements unknown
Auditor Tips
All applicable requirements must be identified, comprehended, and fulfilled. THREE-PART REQUIREMENT: DETERMINED: - Customer requirements identified - Statutory requirements identified (laws) - Regulatory requirements identified (regulations) - Documented and accessible - Kept current UNDERSTOOD: - Meaning comprehended by organization - Translated into specifications - Communicated to relevant functions - Staff trained on requirements - Impact on processes understood CONSISTENTLY MET: - Not just sometimes but always - Processes designed to meet requirements - Verification that requirements are met - Conforming products and services - Monitoring compliance TYPES OF REQUIREMENTS: - Customer specifications - Delivery requirements - Contractual obligations - Industry standards - Government regulations - Safety requirements - Environmental requirements
Follow-Up Questions
- How are customer requirements captured and flowed down to operational processes?
- What process exists for identifying applicable statutory and regulatory requirements for each product or service?
What to Sample
Select a recent customer order or project and trace the flow of customer and regulatory requirements from contract review through to production or service delivery.
Objective Evidence
- Risk assessments for customer-related risks
- Actions to address customer risks
- Opportunity analysis for customer satisfaction
- Contingency plans for customer delivery
- Management review of customer risks
Common Nonconformities
- No customer risk assessment
- Reactive only approach
- Opportunities ignored
- Customer risks not monitored
Auditor Tips
Customer-related risks and opportunities must be proactively managed. RISKS TO CONFORMITY: - Supplier failures - Process capability issues - Design weaknesses - Human error - Equipment failures - Material issues - Regulatory changes RISKS TO CUSTOMER SATISFACTION: - Delivery delays - Quality issues - Service failures - Communication breakdowns - Unmet expectations - Competitor actions OPPORTUNITIES TO ENHANCE: - Exceeding expectations - Innovation in products/services - Improved delivery performance - Better customer communication - Added value services - Technology improvements ADDRESSING MEANS: - Risk mitigation actions - Preventive measures - Contingency plans - Opportunity capture plans - Resource allocation - Monitoring and review
Follow-Up Questions
- How are risks to product and service conformity identified and addressed at the leadership level?
- What process ensures that risks affecting customer satisfaction are escalated to top management?
What to Sample
Review the risk register for entries related to product/service conformity and customer satisfaction, and verify that mitigation actions have been implemented and are effective.
Objective Evidence
- Customer satisfaction monitoring system
- Customer satisfaction trends
- Customer-focused improvement initiatives
- Customer feedback mechanisms
- Management attention to customer issues
- Customer objectives and targets
Common Nonconformities
- Declining customer satisfaction ignored
- No ongoing customer focus
- Customer focus only during audits
- No customer satisfaction measurement
Auditor Tips
Customer satisfaction must be an ongoing focus, not periodic attention. MAINTAINING FOCUS MEANS: - Continuous priority on customer satisfaction - Not just during audits or reviews - Embedded in organizational culture - Regular attention and action - Improvement not just maintenance ENHANCING MEANS: - Getting better, not just maintaining - Continually improving satisfaction - Seeking ways to delight customers - Not just meeting minimum requirements - Going beyond expectations HOW TO MAINTAIN FOCUS: - Customer metrics in dashboards - Regular customer reviews - Customer agenda items in meetings - Customer visits and engagement - Customer feedback analysis - Customer satisfaction objectives - Customer-focused improvement projects - Recognition for customer excellence LEADERSHIP ROLE: - Model customer focus - Prioritize customer issues - Celebrate customer successes - Address customer failures personally
Follow-Up Questions
- What metrics does the organization use to measure and monitor customer satisfaction?
- How does top management ensure that customer satisfaction improvement remains a strategic priority?
What to Sample
Review customer satisfaction measurement methods (surveys, NPS, complaint rates) and trending data, then verify that improvement actions are tracked and reviewed by top management.
Objective Evidence
- The risk-and-opportunity register or equivalent - verify entries trace back to the 4.1 context and 4.2 interested-party requirements, cover opportunities as well as threats, and are owned rather than anonymous.
- For a sample of risks, the planned actions - confirm each has a defined action, owner, and timeline, and that the response is proportionate (no major effort on trivial risks, no critical risk left with a token action).
- Evidence risk actions are integrated into the QMS processes (4.4) - the actions live inside process procedures and daily operations, not in a separate risk document nobody uses.
- Effectiveness evaluation - records showing the organization later checked whether the risk actions worked and whether opportunities were captured, closing the loop.
- Evidence the register is kept live - dated reviews (e.g. at management review), with new risks added as context changes, rather than a one-time exercise frozen since certification.
Common Nonconformities
- Minor NC: Risks and opportunities are documented for the audit but not used - no actions, no owners, no link to processes or decisions.
- Minor NC: Only negative risks are considered; opportunities (the other half of clause 6.1) are absent.
- Minor NC: No traceable link between the 4.1/4.2 context and the risks identified, so the register is generic rather than organization-specific.
- Observation: Risk responses are disproportionate (heavy effort on trivial risks, or critical risks with token actions), suggesting risk-based thinking is procedural rather than real.
Auditor Tips
Organizations must systematically identify and address risks and opportunities affecting the QMS. This is risk-based thinking in action - not just risk management, but also opportunity management. KEY CONCEPTS: DETERMINING RISKS AND OPPORTUNITIES: - Based on organizational context (4.1) - Based on interested party needs (4.2) - Consider both threats and opportunities - Think broadly: strategic, operational, compliance - Consider internal and external factors PURPOSES (a-d): a) ASSURANCE - Ensure QMS achieves intended results b) ENHANCEMENT - Capitalize on positive opportunities c) PREVENTION - Reduce or eliminate negative effects d) IMPROVEMENT - Drive continuous improvement PLANNING ACTIONS (e-f): e) DEFINE ACTIONS: - What will be done to address each risk/opportunity - Who is responsible - Resources required - Timelines - Success criteria f) INTEGRATION AND EVALUATION: - How actions integrate into QMS processes - How effectiveness will be measured - Monitoring and review mechanisms - Feedback loops for learning PROPORTIONALITY: - Actions must match the significance of the risk/opportunity - Don't over-engineer responses to minor risks - Don't under-resource major opportunities - Risk-based allocation of effort and resources RISK TREATMENT OPTIONS: - Avoid: Eliminate the activity causing risk - Accept: Take informed decision to proceed - Mitigate: Reduce likelihood or impact - Transfer: Share with others (insurance, outsourcing) - Exploit: Actively pursue opportunities OPPORTUNITY EXAMPLES: - New market entry - Technology adoption - Process innovation - Customer partnerships - Product development - Efficiency improvements - Competitive advantages
Follow-Up Questions
- How does the organization's risk and opportunity assessment connect to the context analysis from clause 4.1 and interested parties from clause 4.2?
- What methodology is used to assess and prioritize risks and opportunities?
- How frequently is the risk and opportunity register reviewed and updated?
What to Sample
Review the risk and opportunity register or assessment, verify it references issues from 4.1 and requirements from 4.2, and confirm it has been reviewed within the defined review cycle.
Objective Evidence
- The quality-objectives register - verify objectives are SMART (specific, measurable, with targets, owners, and deadlines), not aspirations like 'improve quality', and that each is consistent with a commitment in the quality policy.
- Cascade evidence - objectives set at relevant functions, levels, AND processes (not only a corporate headline), with departmental/process objectives that ladder up to the organization's goals.
- Relevance to conformity and customer satisfaction - confirm objectives target product/service conformity and customer outcomes, not purely internal vanity metrics.
- Monitoring evidence - dashboards or reports showing each objective is tracked against its target with real data and reviewed (e.g. at management review), not set-and-forgotten.
- Communication evidence - that the people responsible for an objective actually know it; ask a process owner what their objective is and how they are tracking against it.
Common Nonconformities
- Minor NC: Objectives are vague and unmeasurable ('improve quality', 'enhance satisfaction'), so achievement cannot be determined.
- Minor NC: Objectives exist only at top-management level and are not cascaded to the functions, levels, and processes that deliver them.
- Minor NC: Objectives are not monitored - there is no data showing progress against targets.
- Observation: Personnel responsible for an objective are unaware of it, indicating objectives are documented but not lived.
Auditor Tips
Quality objectives are specific, measurable targets that drive QMS performance. They must cascade throughout the organization - not just at top level. ESTABLISHMENT REQUIREMENTS: WHERE TO SET OBJECTIVES: - Relevant functions (departments, teams) - Relevant levels (strategic, operational, tactical) - Relevant processes (key QMS processes) Examples: - Corporate level: Customer satisfaction score - Department level: Defect reduction in manufacturing - Process level: On-time delivery for order fulfillment - Product level: Reliability targets for new product OBJECTIVE CHARACTERISTICS (a-g): a) CONSISTENT WITH QUALITY POLICY: - Align with quality policy commitments - Support policy intent - Demonstrate policy in action b) MEASURABLE: - Quantifiable metrics - Clear target values - Defined measurement methods - Objective success criteria Examples of measurable objectives: - "Achieve 95% on-time delivery by Q4" - "Reduce customer complaints by 20% this year" - "Improve first-pass yield to 98%" - "Complete 100% of audits on schedule" c) APPLICABLE REQUIREMENTS: - Consider customer requirements - Consider statutory/regulatory requirements - Consider contractual obligations - Ensure compliance objectives included d) RELEVANT TO CONFORMITY AND SATISFACTION: - Link to product/service quality - Link to customer satisfaction - Drive quality outcomes - Impact customer experience e) MONITORED: - Regular tracking and reporting - Progress reviews - Performance dashboards - Trend analysis f) COMMUNICATED: - Shared with relevant personnel - Understood by those responsible - Visible throughout organization - Regular updates on progress g) UPDATED AS APPROPRIATE: - Reviewed periodically - Revised based on changes in context - Adjusted based on performance - Remain relevant and challenging DOCUMENTATION: - Objectives must be documented - Accessible to those who need them - Version controlled if updated - Retained as evidence
Follow-Up Questions
- At which organizational levels and for which functions have quality objectives been established?
- How does the organization ensure that quality objectives are measurable with defined targets and timeframes?
- How are quality objectives communicated to the personnel responsible for achieving them?
What to Sample
Review the quality objectives register across at least three organizational levels or functions, verify each objective has a measurable target and due date, and confirm responsible parties are aware of their objectives.
Objective Evidence
- Evidence QMS changes are planned in a controlled way - a change process and records showing the purpose and potential consequences of the change were considered before implementation.
- Consideration of QMS integrity, resource needs, and the allocation or reallocation of responsibilities and authorities for the change (the 6.3 a-d factors).
- Impact/risk assessment for significant changes, so unintended consequences are caught before they hit.
- Evidence documentation was updated and affected people informed after the change.
- Evidence change effectiveness was reviewed - the change achieved its purpose without breaking the system.
Common Nonconformities
- Minor NC: QMS changes are made without planning or consideration of consequences, risking unintended effects on conformity.
- Minor NC: Resource needs and responsibility reallocation are not considered when planning a change.
- Minor NC: Documentation is not updated after a change, so people work to superseded information.
- Observation: Changes are reactive with no review of whether they achieved their purpose or harmed QMS integrity.
Auditor Tips
Changes to the QMS must be planned and controlled to maintain system integrity and effectiveness. This prevents unintended consequences from hasty changes. SCOPE OF CHANGES: Examples of QMS changes requiring planning: - New processes or process changes - Organizational restructuring - New products or services - New technology implementation - Changes to quality objectives - New facilities or locations - Significant supplier changes - Changes to scope of QMS - Major procedure revisions - Changes in management structure - Mergers or acquisitions - New regulatory requirements PLANNING CONSIDERATIONS (a-d): a) PURPOSE AND CONSEQUENCES: - Why is the change needed? - What are intended benefits? - What are potential risks? - What could go wrong? - Impact on product/service quality - Impact on customer satisfaction - Impact on compliance - Unintended side effects b) INTEGRITY OF QMS: - Will QMS remain effective? - Are all processes still covered? - Are interfaces maintained? - Are requirements still met? - Is system coherence maintained? - Are policies and procedures aligned? - Are records and documentation updated? c) AVAILABILITY OF RESOURCES: - People: Do we have the right skills? - Budget: Is funding available? - Time: Is timeline realistic? - Equipment: Is infrastructure adequate? - Information: Do we have needed data/knowledge? - External support: Are consultants/partners needed? d) RESPONSIBILITIES AND AUTHORITIES: - Who owns the change? - Who is responsible for implementation? - Who has authority to approve? - How are roles impacted? - Are new responsibilities needed? - Are authorities redefined? - Is training required for new roles? CHANGE MANAGEMENT PROCESS: 1. Identify need for change 2. Define scope and objectives 3. Assess risks and consequences 4. Plan implementation (what, who, when, how) 5. Ensure resources 6. Define/assign responsibilities 7. Communicate change 8. Implement change 9. Verify effectiveness 10. Update documentation 11. Lessons learned RELATIONSHIP TO OTHER CLAUSES: - 4.4: Change must maintain process approach - 8.1: Operational planning and control - 8.5.6: Production/service provision changes
Follow-Up Questions
- Can you describe a recent change to the QMS and how it was planned, including impact assessment and resource considerations?
- How does the organization ensure that QMS integrity is maintained during and after changes?
- What approval process is required before implementing changes that affect the QMS?
What to Sample
Select a recent QMS change (process modification, organizational restructuring, system upgrade) and verify that a change plan addressed purpose, consequences, resource needs, and responsibility assignments.
Objective Evidence
- Risk assessment identifying QMS risks
- Opportunity assessment for QMS enhancement
- Analysis of threats to QMS effectiveness
- Risk register linked to QMS outcomes
Common Nonconformities
- Risks not linked to QMS results
- Only generic risks considered
- No QMS-specific risk analysis
- Intended results not defined
Auditor Tips
Risks and opportunities must be identified that could affect QMS success. INTENDED RESULTS OF QMS: - Conforming products and services - Enhanced customer satisfaction - Effective processes - Continual improvement - Meeting quality objectives ASSURANCE THROUGH RISK/OPPORTUNITY MANAGEMENT: - Identify what could prevent intended results - Identify what could help achieve intended results - Ensure confidence in QMS outcomes - Proactive approach to QMS performance RISKS TO QMS RESULTS: - Process failures - Resource constraints - Competence gaps - Equipment failures - Supplier issues - Regulatory changes - Market changes OPPORTUNITIES FOR QMS: - Process improvements - Technology adoption - Better methods - Enhanced capabilities
Follow-Up Questions
- What specific risks have been identified that could prevent the QMS from achieving its intended results?
- How does the organization distinguish between risks to QMS effectiveness and general business risks?
What to Sample
Review the risk register for entries specifically linked to QMS intended results (customer satisfaction, conformity, continual improvement) and verify mitigation actions are defined.
Objective Evidence
- Objectives linked to policy statements
- Documentation showing policy-objective relationship
- Review records checking consistency
Common Nonconformities
- Objectives contradict policy
- No link between policy and objectives
- Objectives unrelated to policy themes
Auditor Tips
Objectives must align with and support the quality policy. CONSISTENCY MEANS: - Objectives support policy commitments - No conflict between policy and objectives - Objectives demonstrate policy in action - Clear link from policy to objectives HOW TO ENSURE CONSISTENCY: - Review policy when setting objectives - Derive objectives from policy themes - Check alignment during objective review - Document the policy-objective link EXAMPLE: Policy: "We are committed to customer satisfaction" Objective: "Achieve customer satisfaction score of 4.5/5.0" Policy: "We continually improve our processes" Objective: "Reduce defect rate by 15% this year"
Follow-Up Questions
- Can you demonstrate the traceability between each quality objective and the corresponding quality policy commitment?
- When the quality policy was last revised, were quality objectives reviewed for continued alignment?
What to Sample
Map each quality objective to its parent quality policy statement and verify that all policy commitments are reflected in at least one objective.
Objective Evidence
- Opportunity register
- Enhancement initiatives
- Improvement opportunities identified
- Strategic opportunities analysis
Common Nonconformities
- Only negative risks considered
- No opportunity identification
- Defensive mindset only
- No pursuit of improvements
Auditor Tips
Opportunities should be identified to make good things even better. DESIRABLE EFFECTS TO ENHANCE: - Customer satisfaction - Product quality - Process efficiency - Employee engagement - Market position - Profitability - Innovation OPPORTUNITY THINKING: - Not just avoiding risks - Actively seeking improvements - Building on strengths - Capitalizing on opportunities - Proactive not just reactive EXAMPLES: - New technology to improve quality - Market opportunity to expand - Process improvement to reduce costs - Partnership opportunity for innovation - Customer collaboration opportunity
Follow-Up Questions
- What opportunities has the organization identified to enhance QMS outcomes or create competitive advantage?
- How are opportunities evaluated and prioritized for action?
What to Sample
Review the opportunity section of the risk and opportunity register and verify that at least two opportunities have defined actions and responsible owners.
Objective Evidence
- Objectives with numeric targets
- Measurement methods defined
- Tracking data for objectives
- SMART objective documentation
Common Nonconformities
- Vague objectives without metrics
- No way to measure achievement
- Subjective success criteria
Auditor Tips
Objectives must have quantifiable metrics and targets. MEASURABLE MEANS: - Specific numeric targets - Clear metrics to track - Defined measurement methods - Objective way to determine achievement - Can answer "did we achieve it?" with data GOOD MEASURABLE OBJECTIVES: - "Achieve 95% on-time delivery by December" - "Reduce customer complaints by 20%" - "Improve first-pass yield to 98%" - "Complete 100% of scheduled audits" - "Achieve zero critical nonconformities" POOR UNMEASURABLE OBJECTIVES: - "Improve quality" (how much? what metric?) - "Be more customer-focused" (unmeasurable) - "Enhance processes" (vague) SMART FRAMEWORK: - Specific: Clear and defined - Measurable: Quantifiable - Achievable: Realistic - Relevant: Tied to business needs - Time-bound: Has deadline
Follow-Up Questions
- What measurement methods and data sources are used to track progress toward each quality objective?
- How does the organization ensure that the metrics chosen actually reflect the intent of the objective?
What to Sample
Select three quality objectives and verify each has a quantified target (not vague language like 'improve' or 'enhance') with a defined measurement method and data source.
Objective Evidence
- Risk register with negative risks
- Preventive actions planned
- Risk mitigation controls
- Corrective action for realized risks
Common Nonconformities
- Only reactive to problems
- No preventive risk management
- Undesired effects recurring
- Known risks unaddressed
Auditor Tips
Risks must be identified and managed to prevent negative outcomes. UNDESIRED EFFECTS TO PREVENT/REDUCE: - Nonconforming products/services - Customer complaints - Delivery failures - Safety incidents - Regulatory non-compliance - Rework and waste - Customer loss - Reputation damage PREVENTION VS REDUCTION: - Prevention: Eliminate risk entirely - Reduction: Lower likelihood or impact - Choose approach based on risk significance - Some risks cannot be eliminated RISK TREATMENT OPTIONS: - Avoid: Don't do the activity - Mitigate: Add controls to reduce - Transfer: Insurance, outsourcing - Accept: Tolerate with monitoring PROACTIVE APPROACH: - Address risks before they occur - Not just reactive fire-fighting - Preventive action mindset - Early warning systems
Follow-Up Questions
- What undesired effects has the organization identified, and what preventive or mitigating actions are in place?
- How does the organization evaluate whether its risk mitigation actions are effective in reducing undesired effects?
What to Sample
Select two high-rated risks from the register, verify that preventive actions are implemented, and review effectiveness data showing the undesired effects are controlled.
Objective Evidence
- Objectives addressing regulatory requirements
- Customer requirement-driven objectives
- Compliance objectives
- Requirements review when setting objectives
Common Nonconformities
- Objectives ignore regulatory requirements
- Customer requirements not reflected
- Compliance not addressed in objectives
Auditor Tips
Objectives should address relevant requirements from various sources. APPLICABLE REQUIREMENTS TO CONSIDER: - Customer requirements - Statutory and regulatory requirements - Contractual requirements - ISO 9001 requirements - Industry standards - Organizational requirements HOW TO INCORPORATE: - Review requirements when setting objectives - Include compliance-related objectives - Ensure regulatory compliance is addressed - Consider customer expectations EXAMPLES: - Regulatory requirement → Objective: 100% compliance - Customer requirement → Objective: Meet delivery targets - Contract requirement → Objective: Achieve quality specs
Follow-Up Questions
- How are applicable customer, statutory, and regulatory requirements considered when setting quality objectives?
- Can you provide an example of a quality objective that was established in response to a specific regulatory or customer requirement?
What to Sample
Review quality objectives for explicit references to applicable requirements, and cross-check against the requirements register to verify completeness.
Objective Evidence
- Improvement initiatives from risk/opportunity analysis
- Innovation projects from opportunities
- Process improvements from risk prevention
- Learning from risk events
Common Nonconformities
- Risk management not driving improvement
- Static, no improvement from opportunities
- Same risks recurring without learning
- Opportunities not converted to improvements
Auditor Tips
Risk and opportunity management should drive continual improvement. IMPROVEMENT THROUGH RISK/OPPORTUNITY: - Addressing risks improves reliability - Pursuing opportunities improves capability - Learning from risks prevents recurrence - Innovation comes from opportunities TYPES OF IMPROVEMENT: - Product/service improvement - Process improvement - QMS improvement - Performance improvement - Capability improvement - Efficiency improvement LINK TO CONTINUAL IMPROVEMENT: - Risk-based thinking enables improvement - Opportunities drive innovation - Prevention is improvement - Proactive better than reactive IMPROVEMENT OPPORTUNITIES: - Technology advances - Best practice adoption - Customer feedback - Audit findings - Process analysis - Benchmarking insights
Follow-Up Questions
- How does the organization use risk and opportunity assessment to identify areas for improvement?
- Can you provide an example where addressing a risk or opportunity led to a measurable improvement in QMS performance?
What to Sample
Review improvement initiatives or corrective actions that originated from the risk and opportunity assessment process, and verify at least one has resulted in measurable improvement.
Objective Evidence
- Objectives linked to product quality
- Customer satisfaction objectives
- Conformity improvement targets
- Customer-focused metrics
Common Nonconformities
- Objectives unrelated to quality
- No customer satisfaction objectives
- Only internal focus, no customer perspective
Auditor Tips
Objectives must focus on product quality and customer outcomes. RELEVANCE TO CONFORMITY: - Objectives drive product/service quality - Focus on meeting specifications - Reduce defects and nonconformities - Improve process capability - Enhance quality outcomes RELEVANCE TO CUSTOMER SATISFACTION: - Objectives improve customer experience - Address customer needs and expectations - Drive customer loyalty - Reduce customer complaints - Enhance service quality EXAMPLES: Conformity objectives: - First-pass yield target - Defect rate reduction - Specification compliance - Process capability (Cpk) targets Customer satisfaction objectives: - Customer satisfaction score - Net Promoter Score (NPS) - Complaint reduction - On-time delivery - Response time targets
Follow-Up Questions
- How do quality objectives address both product/service conformity and customer satisfaction enhancement?
- Are there objectives covering both operational performance and customer experience dimensions?
What to Sample
Categorize quality objectives by theme (conformity, satisfaction, efficiency, improvement) and verify that product/service conformity and customer satisfaction are both covered.
Objective Evidence
- Action plans for risks and opportunities
- Risk treatment plans
- Responsibility assignments for actions
- Resources allocated for risk actions
- Timeline for risk response actions
Common Nonconformities
- Risks identified but no actions
- Actions not assigned to anyone
- No resources for risk actions
- Plans exist but not executed
Auditor Tips
Identified risks and opportunities need planned response actions. ACTION PLANNING: - Define specific actions for each risk/opportunity - Assign responsibility for actions - Allocate resources - Set timelines - Define success criteria TYPES OF ACTIONS: - Preventive actions (before risk materializes) - Mitigating actions (reduce likelihood/impact) - Contingency plans (if risk occurs) - Opportunity pursuit actions - Monitoring actions ACTION CHARACTERISTICS: - Proportionate to significance - Practical and feasible - Resourced appropriately - Owned by specific person - Time-bound NOT JUST IDENTIFICATION: - Risks identified but actions not planned = gap - Must move from assessment to action - Plans must be executed - Results must be tracked
Follow-Up Questions
- How are actions to address risks and opportunities integrated into QMS processes rather than managed as standalone activities?
- What criteria determine whether a risk requires a formal action plan versus an existing process control?
What to Sample
Select two actions from the risk treatment plan and verify they have been implemented within the relevant QMS processes, with assigned owners and completion dates.
Objective Evidence
- Objective monitoring records
- Performance dashboards
- Progress reports
- Trend analysis charts
- Management review of objective status
Common Nonconformities
- Objectives set but not tracked
- No regular monitoring
- Data not collected for objectives
- No action on poor performance
Auditor Tips
Progress toward objectives must be tracked regularly. MONITORING MEANS: - Regular tracking of performance - Data collection for metrics - Progress reporting - Trend analysis - Comparison to targets MONITORING FREQUENCY: - Depends on objective nature - More frequent for critical objectives - At least quarterly for most - Monthly or real-time for operational MONITORING ACTIVITIES: - Collect performance data - Calculate metrics - Compare to targets - Identify variances - Analyze trends - Report status RESPONSE TO MONITORING: - Take action if off-track - Investigate negative trends - Recognize positive achievement - Adjust plans as needed
Follow-Up Questions
- At what frequency are quality objectives monitored, and who is responsible for the monitoring?
- What happens when monitoring indicates an objective is at risk of not being achieved?
What to Sample
Review monitoring records for quality objectives over the last two reporting periods and verify that monitoring occurred at the defined frequency and that underperformance triggered documented action.
Objective Evidence
- Risk actions integrated in process documentation
- Evidence of action implementation
- Effectiveness evaluation records
- Review of risk status post-actions
- Management review of risk actions effectiveness
Common Nonconformities
- Actions not integrated into processes
- Separate risk system disconnected from QMS
- No effectiveness evaluation
- Actions completed but not verified effective
Auditor Tips
Risk actions must be integrated into processes and effectiveness evaluated. INTEGRATION INTO QMS PROCESSES: - Actions embedded in process procedures - Not separate from daily operations - Part of how work is done - Controls built into processes - Risk thinking in all activities IMPLEMENTATION: - Execute the planned actions - Follow through on plans - Monitor progress of actions - Adjust as needed - Complete actions timely EVALUATE EFFECTIVENESS: - Did actions address the risk/opportunity? - Were outcomes achieved? - Was risk reduced/eliminated? - Was opportunity captured? - Were there unintended consequences? EVALUATION METHODS: - Review of risk status after actions - Audit of implemented controls - Analysis of incident data - Management review of effectiveness - KPIs for risk management CONTINUOUS CYCLE: - Evaluate effectiveness - Learn from results - Adjust actions as needed - Improve risk management approach
Follow-Up Questions
- How does the organization evaluate whether actions taken to address risks and opportunities were effective?
- What evidence exists that risk actions are integrated into QMS processes as described in clause 4.4?
What to Sample
Select one risk mitigation action and trace it from planning through implementation to effectiveness evaluation, verifying integration into the relevant QMS process.
Objective Evidence
- Communication records
- Objectives posted/displayed
- Meeting minutes discussing objectives
- Employee awareness of objectives
Common Nonconformities
- Employees unaware of objectives
- No communication of objectives
- Objectives known only to quality dept
- No progress updates shared
Auditor Tips
Objectives must be shared with relevant personnel. COMMUNICATION MEANS: - Sharing objectives with those affected - Ensuring awareness of objectives - Explaining relevance to roles - Regular updates on progress - Visibility of objectives WHO TO COMMUNICATE TO: - All affected employees - Those responsible for achievement - Those whose work contributes - Management and leadership - Relevant stakeholders HOW TO COMMUNICATE: - Team meetings - Company communications - Posted displays - Intranet/portal - Performance discussions - Training sessions - Dashboards visible to all WHAT TO COMMUNICATE: - The objectives themselves - Why they matter - How each person contributes - Progress and status - Actions needed
Follow-Up Questions
- Through what channels are quality objectives communicated to relevant personnel?
- How does the organization verify that personnel understand the objectives relevant to their function?
What to Sample
Interview personnel from two different functions and verify they can state the quality objectives relevant to their area, including targets and their role in achieving them.
Objective Evidence
- Objective revision records
- Management review of objectives
- Updated objectives documentation
- Justification for objective changes
Common Nonconformities
- Same objectives for years unchanged
- Objectives out of date
- No review of objective relevance
- Achieved objectives not replaced
Auditor Tips
Objectives should be reviewed and revised when needed. UPDATING MEANS: - Reviewing continued relevance - Adjusting targets based on performance - Revising based on changed circumstances - Setting new objectives when achieved - Removing obsolete objectives TRIGGERS FOR UPDATE: - Strategic direction changes - Context changes (4.1) - Customer requirements change - Objectives achieved (set new) - Objectives no longer relevant - Performance indicates need to adjust - Regulatory changes UPDATE FREQUENCY: - At least annual review - More frequent if context changes - Part of management review - Responsive to significant events MAINTAIN CHALLENGE: - Don't lower targets to easy levels - Raise targets when consistently achieved - Keep objectives stretching but achievable - Balance ambition with realism
Follow-Up Questions
- Under what circumstances are quality objectives updated, and what triggers the review?
- How does the organization ensure that updated objectives remain aligned with the quality policy and current business context?
What to Sample
Review the revision history of quality objectives and verify that updates correspond to changes in context, interested party requirements, or performance data.
Objective Evidence
- For each quality objective, the plan covering WHAT will be done, WHAT resources are needed, WHO is responsible, WHEN it will be completed, and HOW results will be evaluated (the five 6.2.2 elements).
- Action plans/project plans with milestones and named owners - showing the 'how' actually exists behind the objective, not just a target.
- Resource allocation behind the plans (budget, people, time) - confirming the objectives are resourced, not aspirational.
- Progress tracking against the plans - evidence the plans are executed and monitored, not filed.
- Defined evaluation criteria - how the organization will know the objective was achieved.
Common Nonconformities
- Minor NC: Objectives are set but there are no plans to achieve them (no what/who/when/resources), so they are targets without a path.
- Minor NC: Plans exist but ownership or resources are not assigned, so nothing drives them.
- Minor NC: No defined evaluation criteria, so achievement cannot be judged.
- Observation: Objective planning is done only when an audit is announced.
Auditor Tips
Setting objectives is not enough - there must be plans to achieve them. This is the "how" to complement the "what" of objectives. PLANNING ELEMENTS (a-e): a) WHAT WILL BE DONE: - Specific actions and activities - Projects or initiatives - Process changes - Milestones and deliverables - Steps to reach the objective Example: To achieve 95% on-time delivery - Implement new scheduling system - Train production planners - Improve supplier delivery performance - Reduce changeover times b) RESOURCES REQUIRED: - Budget and financial resources - Personnel and skills - Equipment and technology - Time allocation - External support (consultants, partners) c) RESPONSIBILITY: - Who owns the objective - Who leads each action - Who is accountable for results - Authority and empowerment - Clear ownership at appropriate level d) TIMING: - Completion dates for objective - Milestones and deadlines - Project timeline - Review points - Realistic and achievable timeframes e) EVALUATION OF RESULTS: - How success will be measured - Metrics and KPIs - Data collection methods - Review frequency - Success criteria INTEGRATION: - Can be part of strategic planning - Can be in business plans - Can be in project plans - Can be in performance management systems - Don't create separate system if existing processes work PRACTICAL IMPLEMENTATION: - Action plans for each objective - Gantt charts or project schedules - Resource allocation in budgets - Responsibility matrices (RACI) - Performance dashboards - Regular review meetings
Follow-Up Questions
- Does the organization have documented action plans for achieving each quality objective?
- How are action plans for quality objectives tracked and reviewed for progress?
- What process ensures that resources allocated to objective achievement are adequate and available?
What to Sample
Review action plans for the three highest-priority quality objectives and verify each plan addresses what will be done, resources required, responsibility, timeline, and evaluation method.
Objective Evidence
- Action plans listing activities
- Project plans with tasks
- Improvement initiatives defined
- Process change plans
Common Nonconformities
- Objectives without actions
- Vague plans with no specifics
- Generic action items
- No clear steps defined
Auditor Tips
Specific actions and activities must be identified. WHAT WILL BE DONE: - Specific actions to take - Activities and tasks - Projects to undertake - Process changes to make - Steps toward the objective - Milestones to achieve EXAMPLES: For objective "95% on-time delivery": - Implement new scheduling system - Train production planners - Establish supplier performance program - Reduce changeover times - Add capacity in bottleneck areas LEVEL OF DETAIL: - Enough to guide implementation - Specific enough to track - Clear enough to assign - Practical and actionable
Follow-Up Questions
- Are the planned actions specific enough to be actionable, or are they expressed in vague terms?
- How were the actions determined to be sufficient to achieve the objective?
What to Sample
Review action items for one quality objective and verify each action is specific, with a clear deliverable that contributes to achieving the overall objective.
Objective Evidence
- Budget allocation for objectives
- Staffing plans
- Resource requirements documentation
- Capital requests for equipment
Common Nonconformities
- No resources allocated
- Insufficient budget
- People overloaded
- Resource planning ignored
Auditor Tips
Resources needed for objective achievement must be identified. TYPES OF RESOURCES: - Budget and financial resources - People (number, skills, time) - Equipment and technology - Facilities and infrastructure - Materials and supplies - External support (consultants) - Training and development RESOURCE PLANNING: - Estimate resource needs realistically - Secure budget approval - Allocate people to tasks - Acquire necessary equipment - Schedule resource availability AVOIDING RESOURCE GAPS: - Plan resources upfront - Get commitment from management - Identify resource constraints early - Have contingency plans
Follow-Up Questions
- How are resource requirements estimated for each action, and are budgets formally allocated?
- What happens when required resources exceed available capacity?
What to Sample
Verify that resource requirements (budget, personnel, equipment, time) are documented for at least two quality objective action plans and cross-reference against actual allocations.
Objective Evidence
- Objective ownership assignments
- RACI matrices
- Action item owners assigned
- Performance objectives linked to individuals
Common Nonconformities
- No one assigned
- Unclear ownership
- Multiple people think they own it
- Responsibility without authority
Auditor Tips
Clear ownership and accountability must be assigned. RESPONSIBILITY MEANS: - Named individual responsible for objective - Person accountable for results - Owner of the action plan - Point of contact for progress ASSIGNMENT CONSIDERATIONS: - Appropriate authority given - Competence to achieve - Capacity to take on - Clarity of expectations - Empowerment to act LEVELS OF RESPONSIBILITY: - Overall objective owner - Action item owners - Supporting roles - Management sponsor RACI FRAMEWORK: - Responsible: Does the work - Accountable: Answers for results - Consulted: Provides input - Informed: Kept updated
Follow-Up Questions
- Are responsible individuals named for each action, and do they have the authority to execute?
- How is accountability maintained when responsibilities span multiple departments?
What to Sample
Review responsibility assignments for quality objective actions and verify that named individuals acknowledge their responsibilities and have appropriate authority.
Objective Evidence
- Timelines for objectives
- Milestone schedules
- Gantt charts or project schedules
- Deadline tracking
Common Nonconformities
- No timelines set
- Unrealistic deadlines
- No milestones defined
- Timelines consistently missed
Auditor Tips
Timelines and deadlines must be established. TIMING ELEMENTS: - Target completion date for objective - Milestones along the way - Deadlines for action items - Review points - Checkpoints for progress REALISTIC TIMELINES: - Achievable given resources - Allow for dependencies - Include buffer for issues - Balance urgency with feasibility - Consider competing priorities SCHEDULE MANAGEMENT: - Track against timeline - Identify delays early - Escalate when behind - Adjust as needed - Report on timing regularly
Follow-Up Questions
- Are completion dates realistic and based on resource availability and complexity?
- How are overdue actions escalated and managed?
What to Sample
Check the timeline for quality objective actions, identify any that are overdue, and verify that overdue items have documented explanations and revised completion dates.
Objective Evidence
- Evaluation criteria documented
- Success measures defined
- Review and evaluation records
- Achievement assessments
Common Nonconformities
- No evaluation method defined
- Subjective success criteria
- No review of achievement
- Results not assessed
Auditor Tips
Success criteria and evaluation methods must be defined. EVALUATION ELEMENTS: - How to measure achievement - Success criteria defined - Data collection methods - Evaluation frequency - Who evaluates EVALUATION METHODS: - Compare to target metrics - Review milestone achievement - Analyze trend data - Assess qualitative outcomes - Get stakeholder feedback SUCCESS CRITERIA: - Clear definition of success - Measurable indicators - Objective assessment - Documented evidence EVALUATION TIMING: - During progress (interim reviews) - At completion (final evaluation) - Management review - Audit verification
Follow-Up Questions
- What criteria will be used to determine whether actions taken have successfully achieved the quality objective?
- How does the organization distinguish between completing an action and achieving the intended result?
What to Sample
Review the evaluation criteria for one quality objective and verify that effectiveness is measured against the objective target, not merely by action completion.
Frequently Asked Questions
Get the Full 251-Item Checklist
Download the complete ISO 9001:2015 gap analysis checklist with all 251 expert items, objective evidence requirements, common nonconformities, auditor tips, and a professional scoring rubric.
This checklist is an educational resource for audit preparation. It does not constitute professional regulatory advice. Always consult qualified auditors for certification decisions.