Skip to main content
HomeChecklists › ISO 9001:2015 Gap Analysis Checklist

ISO 9001:2015 Gap Analysis Checklist

251 items Last updated: 2026-06-24
0% complete — 0 of 251 items
Status:
Section 4 — Context of the Organization 0/21
4.1
Does the organization identify and keep under review the external and internal factors that bear on its purpose, strategic direction, and ability to deliver the intended results of its QMS (e.g. via SWOT/PESTLE), and is that analysis actually used in planning rather than filed only for the audit?
The documented context analysis (SWOT, PESTLE, or equivalent) - verify it names issues specific to THIS organization (its markets, technology, supply chain, workforce, regulatory jurisdiction), not a generic template, and that both external and internal factors are covered.

Objective Evidence

  • The documented context analysis (SWOT, PESTLE, or equivalent) - verify it names issues specific to THIS organization (its markets, technology, supply chain, workforce, regulatory jurisdiction), not a generic template, and that both external and internal factors are covered.
  • Evidence the analysis is kept current - a dated review cadence (e.g. at management review) with changes captured when the market, regulations, or organization shift; an analysis dated years ago with no revisions is a red flag.
  • The link from context to QMS planning - trace at least two identified issues into actual decisions (risks/opportunities in 6.1, objectives in 6.2, scope in 4.3), showing the analysis drives planning rather than sitting in a binder.
  • Management-review minutes where context is discussed - confirm leadership is aware of the key external/internal factors and treats them as live inputs, not a once-a-year formality.
  • Supporting inputs feeding the analysis - market/competitive analysis, regulatory monitoring, customer feedback, internal capability or performance data - to confirm the issues are evidence-based, not opinion.

Common Nonconformities

  • Minor NC: The context analysis exists but was done once and never revised, despite changes in the market, regulations, or the organization since.
  • Minor NC: Issues listed are generic ('competition', 'the economy') and not specific to the organization, so they cannot drive any real planning.
  • Minor NC: No traceable link between identified issues and QMS planning (risks, objectives, scope) - the analysis is maintained for the audit, not used.
  • Observation: Context is documented by the quality function alone, with no evidence top management is aware of or engaged with the key factors.

Auditor Tips

Organizations must systematically identify and monitor both external and internal factors that could impact their QMS effectiveness and ability to meet objectives. EXTERNAL ISSUES: LEGAL & REGULATORY: - Industry-specific regulations - Changes in legislation - Compliance requirements - Certification requirements - Customer contractual requirements MARKET & COMPETITIVE: - Market demand and trends - Competitive landscape - Customer expectations evolution - Industry consolidation - New market entrants - Global economic conditions TECHNOLOGICAL: - Emerging technologies - Digital transformation - Automation opportunities - Obsolescence risks - Cybersecurity threats SOCIAL & CULTURAL: - Demographic changes - Social responsibility expectations - Cultural norms and values - Environmental concerns - Stakeholder activism INTERNAL ISSUES: ORGANIZATIONAL: - Company size and structure - Strategic direction - Organizational culture - Leadership stability - Change management capability CAPABILITIES: - Core competencies - Technology and equipment - Production capacity - Innovation capability - Process maturity RESOURCES: - Workforce skills and availability - Financial strength - Facility conditions - IT infrastructure - Knowledge management PERFORMANCE: - Quality metrics and trends - Customer satisfaction levels - Operational efficiency - Risk profile - Growth trajectory The organization must: 1. Identify relevant issues systematically 2. Understand how they affect QMS objectives 3. Monitor changes in these issues 4. Review regularly (e.g., management review) 5. Take action when issues change significantly

Follow-Up Questions

  • How frequently does the organization review its external and internal issues, and what triggers an unscheduled review?
  • Can you walk me through a recent example where an identified issue led to a change in QMS planning or objectives?
  • Who is responsible for monitoring changes in the regulatory or competitive landscape, and how are those changes communicated internally?

What to Sample

Review the most recent SWOT/PESTLE analysis or equivalent, and cross-reference with the last two management review minutes to confirm issues were discussed and acted upon.

Preview complete — 3 of 7 sections shown
Section 7 — Support 26 items Download to access
Section 8 — Operation 102 items Download to access
Section 9 — Performance Evaluation 37 items Download to access
Section 10 — Improvement 13 items Download to access

Frequently Asked Questions

What is ISO 9001?
ISO 9001:2015 is the international standard for quality management systems applicable to any organization regardless of size or industry. It is based on seven quality management principles: customer focus, leadership, engagement of people, process approach, improvement, evidence-based decision making, and relationship management.
What is a gap analysis for ISO 9001?
A gap analysis compares your current QMS against ISO 9001:2015 requirements to identify where you fully comply, partially comply, or have gaps. It is typically the first step before certification and helps prioritize implementation efforts. This checklist provides a systematic way to perform that assessment.
How is ISO 9001:2015 structured?
ISO 9001:2015 follows the High Level Structure (HLS) with 10 clauses. Clauses 1-3 are introductory. Clauses 4-10 contain the requirements: Context of the Organization (4), Leadership (5), Planning (6), Support (7), Operation (8), Performance Evaluation (9), and Improvement (10). This maps to the Plan-Do-Check-Act cycle.
What is the difference between ISO 9001:2015 and ISO 9001:2008?
The 2015 revision introduced risk-based thinking, removed the requirement for a quality manual, eliminated preventive action as a standalone requirement (incorporated into risk-based thinking), emphasized leadership engagement, and adopted the High Level Structure for compatibility with other ISO management system standards.

Get the Full 251-Item Checklist

Download the complete ISO 9001:2015 gap analysis checklist with all 251 expert items, objective evidence requirements, common nonconformities, auditor tips, and a professional scoring rubric.

Free download. No credit card required.

This checklist is an educational resource for audit preparation. It does not constitute professional regulatory advice. Always consult qualified auditors for certification decisions.