ISO 9001:2015 clause 4: Context of the organization

The 21 audit questions covering clause 4, each with the objective evidence to request, the nonconformities most often raised against it and what to sample. Part of the free ISO 9001:2015 gap analysis checklist, which holds 251 items across 7 clauses.

21 items in this clause 1 section 251 items in the full checklist ISO 9001:2015 · updated 2026-06-24

All 21 questions for clause 4

Open any row for its objective evidence, common nonconformities and auditor tips. You can check items off as you go. This browser remembers your progress across all 7 clauses of this checklist.

§4 Context of the organization 21 items · ~105 min
4.1 Does the organization identify and keep under review the external and internal factors that bear on its purpose, strategic direction, and ability to deliver the intended results of its QMS (e.g. via SWOT/PESTLE), and is that analysis actually used in planning rather than filed only for the audit?
Objective evidence
  • The documented context analysis (SWOT, PESTLE, or equivalent) - verify it names issues specific to THIS organization (its markets, technology, supply chain, workforce, regulatory jurisdiction), not a generic template, and that both external and internal factors are covered.
  • Evidence the analysis is kept current - a dated review cadence (e.g. at management review) with changes captured when the market, regulations, or organization shift; an analysis dated years ago with no revisions is a red flag.
  • The link from context to QMS planning - trace at least two identified issues into actual decisions (risks/opportunities in 6.1, objectives in 6.2, scope in 4.3), showing the analysis drives planning rather than sitting in a binder.
  • Management-review minutes where context is discussed - confirm leadership is aware of the key external/internal factors and treats them as live inputs, not a once-a-year formality.
  • Supporting inputs feeding the analysis - market/competitive analysis, regulatory monitoring, customer feedback, internal capability or performance data - to confirm the issues are evidence-based, not opinion.
Common nonconformities
  • Minor NC: The context analysis exists but was done once and never revised, despite changes in the market, regulations, or the organization since.
  • Minor NC: Issues listed are generic ('competition', 'the economy') and not specific to the organization, so they cannot drive any real planning.
  • Minor NC: No traceable link between identified issues and QMS planning (risks, objectives, scope) - the analysis is maintained for the audit, not used.
  • Observation: Context is documented by the quality function alone, with no evidence top management is aware of or engaged with the key factors.
Auditor tip

Organizations must systematically identify and monitor both external and internal factors that could impact their QMS effectiveness and ability to meet objectives. EXTERNAL ISSUES: LEGAL & REGULATORY: - Industry-specific regulations - Changes in legislation - Compliance requirements - Certification requirements - Customer contractual requirements MARKET & COMPETITIVE: - Market demand and trends - Competitive landscape - Customer expectations evolution - Industry consolidation - New market entrants - Global economic conditions TECHNOLOGICAL: - Emerging technologies - Digital transformation - Automation opportunities - Obsolescence risks - Cybersecurity threats SOCIAL & CULTURAL: - Demographic changes - Social responsibility expectations - Cultural norms and values - Environmental concerns - Stakeholder activism INTERNAL ISSUES: ORGANIZATIONAL: - Company size and structure - Strategic direction - Organizational culture - Leadership stability - Change management capability CAPABILITIES: - Core competencies - Technology and equipment - Production capacity - Innovation capability - Process maturity RESOURCES: - Workforce skills and availability - Financial strength - Facility conditions - IT infrastructure - Knowledge management PERFORMANCE: - Quality metrics and trends - Customer satisfaction levels - Operational efficiency - Risk profile - Growth trajectory The organization must: 1. Identify relevant issues systematically 2. Understand how they affect QMS objectives 3. Monitor changes in these issues 4. Review regularly (e.g., management review) 5. Take action when issues change significantly

What to sample

Review the most recent SWOT/PESTLE analysis or equivalent, and cross-reference with the last two management review minutes to confirm issues were discussed and acted upon.

Follow-up questions
  • How frequently does the organization review its external and internal issues, and what triggers an unscheduled review?
  • Can you walk me through a recent example where an identified issue led to a change in QMS planning or objectives?
  • Who is responsible for monitoring changes in the regulatory or competitive landscape, and how are those changes communicated internally?
4.2 Has the organization worked out which interested parties matter to the QMS and what each of them needs from it, and does it keep that understanding current as those parties and their requirements change?
Objective evidence
  • The interested-parties register - verify it goes beyond customers to the parties that actually affect or are affected by the QMS (regulators, suppliers, employees, owners), and is specific to this organization.
  • The requirements determined for each relevant party - statutory, regulatory, contractual, and expectation-based - not just 'customers want quality'.
  • Evidence the analysis is monitored and reviewed as parties and their requirements change (e.g. new regulations), with a dated cadence.
  • Traceability from interested-party requirements into QMS planning (scope, objectives, processes, compliance obligations) - showing it is used, not filed.
  • Distinction between mandatory (must comply) and voluntary (chosen) requirements, so the organization knows its hard obligations.
Common nonconformities
  • Minor NC: Only customers are identified as interested parties; statutory/regulatory authorities and other affecting parties are omitted.
  • Minor NC: Interested-party requirements are not linked to QMS planning, so the analysis has no effect.
  • Minor NC: The analysis is not reviewed or updated as parties and requirements change.
  • Observation: The register is a generic template not tailored to the organization's actual stakeholders.
Auditor tip

Organizations must identify stakeholders who can impact the QMS or be impacted by it, and understand their needs and expectations. KEY INTERESTED PARTIES: CUSTOMERS: - End users of products/services - Direct customers (B2B, B2C) - Distributors and resellers - Requirements: quality, delivery, price, service, innovation REGULATORY/STATUTORY: - Government regulatory bodies - Industry regulators - Standards organizations - Requirements: compliance, safety, environmental protection SUPPLIERS/PARTNERS: - Raw material suppliers - Service providers - Outsource providers - Technology partners - Requirements: fair terms, stability, partnership, payment EMPLOYEES: - Direct employees - Contractors - Unions/worker representatives - Requirements: safety, compensation, development, job security OWNERS/INVESTORS: - Shareholders - Private equity owners - Board of directors - Requirements: profitability, growth, risk management, compliance COMMUNITY/SOCIETY: - Local communities - NGOs and advocacy groups - General public - Requirements: environmental protection, social responsibility, employment The organization must: 1. Identify relevant interested parties (not exhaustive list) 2. Determine their requirements relevant to QMS 3. Understand which requirements are mandatory vs. discretionary 4. Monitor changes in interested parties and their requirements 5. Review regularly and update as needed IMPORTANT: Focus on parties and requirements that are RELEVANT to the QMS ability to consistently provide conforming products and services.

What to sample

Examine the interested parties register or matrix, then verify at least two entries are linked to specific QMS processes or documented requirements.

Follow-up questions
  • Beyond customers and regulators, which other interested parties have been identified, and how were their requirements determined?
  • How does the organization detect when a new interested party becomes relevant or when existing requirements change?
  • Can you trace a specific interested party requirement through to where it is addressed in the QMS?
4.2 a) Which interested parties relevant to the QMS has the organization recognized as in scope, and how did it decide who counts (customers, regulators, suppliers, employees, and others)?
Objective evidence
  • Interested parties register/matrix
  • Stakeholder analysis document
  • Context of organization analysis
  • Customer list/database
  • Regulatory authority identification
  • Supplier register
  • Organizational chart showing internal stakeholders
  • Stakeholder mapping exercise results
  • Minutes from management discussions on stakeholders
Common nonconformities
  • Only customers listed as interested parties
  • Generic template list not tailored to organization
  • Missing regulatory/statutory authorities
  • No internal interested parties identified
  • List not reviewed since initial creation
  • No rationale for why parties are relevant
  • Obvious stakeholders missing (e.g., suppliers)
Auditor tip

Organizations must identify all stakeholders who can affect or be affected by the QMS's ability to provide conforming products/services. TYPES OF INTERESTED PARTIES TO CONSIDER: EXTERNAL INTERESTED PARTIES: - Customers (direct customers, end users, distributors) - Regulatory authorities (government, industry regulators) - Suppliers and outsourced providers - Shareholders/owners/investors - Competitors (influencing market expectations) - Community and society - Industry associations - Notified bodies/certification bodies - Insurance companies - Media/press - NGOs and advocacy groups INTERNAL INTERESTED PARTIES: - Employees and workers - Management team - Board of directors - Trade unions/worker representatives - Contractors working on-site - Parent company (if subsidiary) HOW TO DETERMINE RELEVANCE: - Can they impact the QMS effectiveness? - Can they impact product/service conformity? - Are they affected by the QMS? - Do they have statutory/regulatory authority? - Do they have contractual relationship? - Do they have significant influence? NOT ALL INTERESTED PARTIES ARE RELEVANT: - Focus on those with genuine impact on QMS - The list is not meant to be exhaustive - Prioritize by level of impact/influence

What to sample

Review the interested parties identification process and confirm it covers at minimum: customers, employees, suppliers, regulators, and owners/shareholders.

Follow-up questions
  • What methodology was used to identify relevant interested parties, and how comprehensive was the assessment?
  • Are there any interested parties that were considered but determined to be not relevant, and what was the rationale?
4.2 b) For the interested parties it recognized, has the organization pinned down their specific requirements that are relevant to the QMS (statutory, regulatory, contractual, and customer)?
Objective evidence
  • Requirements register by interested party
  • Customer requirements documentation
  • Regulatory/legal requirements register
  • Contract review records
  • Supplier agreements
  • Service level agreements (SLAs)
  • Employee handbook/policies
  • Customer specifications received
  • Compliance obligations checklist
  • Licensing and permit requirements
  • Customer surveys and feedback
Common nonconformities
  • Requirements not linked to specific interested parties
  • Only customer requirements documented
  • Regulatory requirements missing or incomplete
  • Requirements documented but not integrated into QMS
  • No process to monitor changes in requirements
  • Generic requirements not tailored to organization
  • Requirements not reviewed periodically
Auditor tip

Once interested parties are identified, the organization must determine their specific requirements that are relevant to the QMS. TYPES OF REQUIREMENTS TO DETERMINE: CUSTOMER REQUIREMENTS: - Product/service specifications - Delivery requirements - Quality expectations - Price/value expectations - Service level requirements - Warranty and support expectations - Communication preferences REGULATORY/STATUTORY REQUIREMENTS: - Legal compliance obligations - Industry-specific regulations - Environmental requirements - Health and safety requirements - Reporting obligations - Licensing/certification requirements SUPPLIER REQUIREMENTS: - Fair payment terms - Clear specifications - Predictable demand/forecasting - Partnership expectations - Communication of changes EMPLOYEE REQUIREMENTS: - Safe working conditions - Fair compensation - Training and development - Clear expectations and feedback - Resources to do the job OWNER/INVESTOR REQUIREMENTS: - Financial performance - Risk management - Compliance - Growth and sustainability - Reputation management DETERMINING RELEVANCE TO QMS: - Does it affect product/service conformity? - Does it affect customer satisfaction? - Is it a legal obligation? - Is it in contractual agreements? - Does it impact QMS effectiveness? Importantly, not all requirements of interested parties are relevant to the QMS; focus on those that genuinely affect the ability to provide conforming products and services and enhance customer satisfaction.

What to sample

Select two interested parties and trace their documented requirements through to where they are addressed in QMS procedures or process controls.

Follow-up questions
  • How does the organization distinguish between mandatory requirements (statutory, regulatory) and voluntary expectations of interested parties?
  • What process exists for translating interested party requirements into actionable QMS requirements?
4.3 Is the QMS scope defined in terms of clear boundaries and applicability (sites, products and services, and any justified exclusions), and does it reflect the context, interested-party requirements, and the organization's products and services?
Objective evidence
  • The documented QMS scope statement - verify it defines clear boundaries (sites/locations, products/services) and is available as documented information.
  • Justification for any exclusions - confirm only requirements that genuinely cannot apply are excluded, and that no requirement affecting conformity or customer satisfaction is dodged (a non-applicable clause is justified; a skipped one is not).
  • Evidence the scope reflects the 4.1 context and 4.2 interested-party requirements that drove it.
  • A check that the scope matches actual operations - the activities, sites, and products the organization really performs, not a narrowed scope of convenience.
  • Evidence the scope is reviewed for continuing adequacy (e.g. at management review) when the business changes (new sites, products, services).
Common nonconformities
  • Major NC: A requirement that affects the conformity of products/services or customer satisfaction has been excluded from scope, so part of the QMS is not applied.
  • Minor NC: The scope does not match actual operations (sites or products performed but not in scope, or the reverse).
  • Minor NC: Exclusions are taken without justification.
  • Observation: The scope has never been reviewed or updated despite changes to the business.
Auditor tip

The QMS scope defines what the organization's QMS covers and any permissible exclusions. This is a critical document for certification. DETERMINING SCOPE - CONSIDERATIONS: BOUNDARIES: - Physical locations (sites, facilities, warehouses) - Organizational units (divisions, departments, subsidiaries) - Processes (design, manufacturing, service, support) - Products and services covered - Geographic regions INPUTS TO SCOPE (Must Consider): - External/internal issues from 4.1 - Interested party requirements from 4.2 - Products and services offered - Organizational structure - Business model - Complexity of operations EXCLUSIONS: - ISO 9001:2015 allows NO EXCLUSIONS except Clause 8.3 (Design and Development) - Clause 7 requirements cannot be excluded - Any exclusion must be justified - Exclusions must not affect ability to provide conforming products/services - Exclusions must not affect customer satisfaction COMMON ACCEPTABLE EXCLUSIONS: - 8.3 Design and Development (if organization doesn't design) - Example: Pure distributor or reseller with no design responsibility UNACCEPTABLE EXCLUSIONS: - Cannot exclude management responsibility (Clause 5) - Cannot exclude resource management (Clause 7) - Cannot exclude production/service provision if that's what you do - Cannot exclude measurement and improvement (Clauses 9 & 10) SCOPE STATEMENT MUST INCLUDE: 1. Products and services covered 2. Sites/locations covered 3. Processes covered 4. Any justified exclusions (rare) 5. Organizational units covered SCOPE MUST BE: - Documented - Available (to interested parties if requested) - Maintained (kept current) - Realistic and achievable - Aligned with business reality

What to sample

Compare the documented QMS scope against the organization's actual product/service portfolio and site locations to confirm completeness and accuracy of boundaries.

Follow-up questions
  • What exclusions, if any, have been made from the scope, and what is the documented justification for each?
  • How does the scope statement account for outsourced processes or remote operational sites?
  • When was the scope last reviewed, and did any changes in context or interested party requirements trigger an update?
4.3 a) When setting the QMS scope, did the organization take the external and internal issues from its 4.1 context analysis into account, and can it show that link?
Objective evidence
  • Context analysis (SWOT, PESTLE) informing scope
  • Scope statement referencing context factors
  • Minutes showing context consideration in scope decisions
  • Risk assessment linked to scope determination
  • Strategic plan alignment with QMS scope
Common nonconformities
  • Scope determined without reference to context
  • Context analysis exists but not linked to scope
  • Scope doesn't reflect organizational reality
  • External factors ignored in scope determination
Auditor tip

The scope must take into account the context analysis from clause 4.1. HOW CONTEXT INFLUENCES SCOPE: EXTERNAL ISSUES AFFECTING SCOPE: - Market characteristics and geographic reach - Regulatory jurisdiction and requirements - Supply chain considerations - Technology and infrastructure availability - Economic conditions - Competition and industry dynamics - Customer expectations and requirements INTERNAL ISSUES AFFECTING SCOPE: - Organizational structure and complexity - Available resources and capabilities - Strategic direction and priorities - Current processes and systems - Locations and facilities - Products/services offered - Competencies available LINKING CONTEXT TO SCOPE: - If you operate in multiple jurisdictions, scope should reflect this - If you offer diverse products, determine which are in scope - If you have multiple sites, define which are included - If you outsource key processes, address in scope - If regulatory requirements mandate coverage, cannot exclude The scope should be realistic given the organization's context.

What to sample

Cross-reference the scope statement with the documented context analysis to verify traceability between identified issues and scope decisions.

Follow-up questions
  • Can you demonstrate how the issues identified in clause 4.1 influenced the determination of the QMS scope?
  • Were any external issues such as regulatory changes or market shifts factored into scope boundaries?
4.3 b) Does the defined scope take account of what relevant interested parties require from the QMS, including customer and regulatory obligations?
Objective evidence
  • Interested party requirements matrix linked to scope
  • Customer requirements driving scope decisions
  • Regulatory requirements mandating scope coverage
  • Contract requirements specifying scope
  • Documentation showing interested party input to scope
Common nonconformities
  • Interested party requirements not considered in scope
  • Customer requirements excluded from scope without justification
  • Regulatory requirements not reflected in scope
  • Scope doesn't address key stakeholder needs
Auditor tip

The scope must consider what interested parties require from the QMS. HOW INTERESTED PARTY REQUIREMENTS INFLUENCE SCOPE: CUSTOMER REQUIREMENTS: - Specific product/service requirements may mandate scope inclusion - Customer contract requirements (e.g., require certification) - Customer audits may expect certain scope coverage REGULATORY REQUIREMENTS: - Mandatory requirements cannot be excluded from scope - Licensing may require specific processes in scope - Compliance obligations define minimum scope SUPPLIER/PARTNER REQUIREMENTS: - Key suppliers may require certified scope - Partnership agreements may specify scope expectations EMPLOYEE REQUIREMENTS: - Health and safety obligations in scope - Training requirements in scope OWNER/INVESTOR REQUIREMENTS: - Risk management expectations - Governance requirements PRACTICAL APPLICATION: - If customers require ISO certification, scope must cover relevant processes - If regulators mandate certain controls, cannot exclude from scope - If contract specifies coverage, scope must include - If notified body audit scope, must align

What to sample

Verify that key interested party requirements (e.g., customer contract terms, regulatory mandates) are reflected in the scope boundaries and any exclusion justifications.

Follow-up questions
  • How were the requirements of interested parties factored into scope decisions, particularly regarding product or service boundaries?
  • Are there contractual or regulatory requirements from interested parties that necessitated expanding or narrowing the scope?
4.3 c) Does the scope clearly state which products and services across the organization's portfolio the QMS covers?
Objective evidence
  • Product/service catalog matching scope
  • Scope statement with clear product/service definitions
  • Product line documentation
  • Service descriptions
  • Certificate showing products/services covered
Common nonconformities
  • Scope vague about products/services
  • Scope doesn't match actual offerings
  • Products marketed as certified but not in scope
  • Significant products/services excluded without justification
Auditor tip

The scope must clearly define which products and services are covered. PRODUCTS AND SERVICES CONSIDERATION: WHAT TO CONSIDER: - Full product/service portfolio - Product families and categories - Service offerings and support - Custom vs. standard offerings - New product development activities - Legacy products still supported - Products in different lifecycle stages SCOPE STATEMENT SHOULD: - List product/service types covered - Be specific enough to be meaningful - Be broad enough for flexibility - Match what organization actually provides - Match what certification certificate will state EXAMPLES OF SCOPE STATEMENTS: - "Design, manufacture, and distribution of medical devices" - "Provision of IT consulting and software development services" - "Manufacturing of precision machined components for aerospace" - "Design and installation of HVAC systems" EXCLUSIONS: - If certain products/services excluded, must justify - Cannot exclude if it affects conformity - Design (8.3) is common exclusion if not performed CONSIDERATIONS: - Are all offered products/services in scope? - If partial coverage, is it justified? - Does scope match marketing claims? - Does scope match certification expectations?

What to sample

Compare the products and services listed in the scope statement against the current sales catalogue, product line documentation, or service agreements.

Follow-up questions
  • Does the scope explicitly list all product and service categories offered by the organization?
  • Have any products or services been added or discontinued since the last scope review, and was the scope updated accordingly?
4.4 Can the organization demonstrate a process-based QMS, where the necessary processes and their interactions are identified, resourced, and managed to deliver intended results, rather than a set of disconnected procedures?
Objective evidence
  • The overall picture of the process-based QMS - a process map showing the QMS processes and their interactions, demonstrating the organization manages quality as a system of interacting processes rather than a set of disconnected procedures.
  • Evidence the processes needed for the QMS are determined and applied throughout the organization, including their inputs, outputs, sequence, and interaction.
  • Evidence the processes are resourced, owned, and managed to deliver their intended results (links to 4.4.1 a-h).
  • The documented information maintained to support process operation and retained to confirm processes run as planned (4.4.2).
  • Evidence the QMS and its processes are continually improved, not static since certification.
Common nonconformities
  • Minor NC: The QMS is a collection of disconnected procedures rather than a managed system of interacting processes.
  • Minor NC: Process interactions are not defined, so the handoffs between processes are uncontrolled.
  • Minor NC: Processes are documented but not actually managed (no owners, performance measures, or improvement).
  • Observation: The process approach exists on paper (a process map) but the organization runs day-to-day on departmental silos.
Auditor tip

This is the foundation of the process-based approach in ISO 9001:2015. Organizations must identify, document, and manage all QMS processes. PROCESS-BASED APPROACH REQUIREMENTS: a) DETERMINE INPUTS AND OUTPUTS: - What goes into each process (materials, information, requirements) - What comes out of each process (products, services, information) - Specifications for inputs and outputs - Customer requirements as inputs b) SEQUENCE AND INTERACTION: - Process flow/process map - How processes connect and depend on each other - Interfaces between processes - Handoffs and responsibilities - Process hierarchy (core, support, management processes) c) CRITERIA AND METHODS: - How to know if process is working (KPIs, metrics) - Monitoring methods (real-time, periodic) - Measurement methods (inspection, testing, audit) - Performance indicators (quality, delivery, cost, safety) - Acceptance criteria for outputs - Process controls to ensure consistent results d) RESOURCES: - People (competence, number) - Equipment and infrastructure - Work environment - Knowledge and information - Budget allocation - Ensure availability when needed e) RESPONSIBILITIES AND AUTHORITIES: - Process owners assigned - Clear roles and responsibilities - Authority to make decisions - Accountability for results - Communication channels f) RISKS AND OPPORTUNITIES: - Process-level risk assessment - Actions to address risks - Opportunities for improvement - Link to 6.1 (overall risk management) - Preventive actions g) EVALUATE AND CHANGE: - Regular process performance reviews - Analyze results vs. targets - Implement changes when needed - Process capability analysis - Corrective actions - Process audits h) IMPROVE: - Continual improvement initiatives - Innovation in processes - Best practice adoption - Process optimization - Technology improvements DOCUMENTED INFORMATION: - As necessary to support operations - As necessary to demonstrate conformity - Can be procedures, work instructions, forms, records - ISO 9001:2015 gives flexibility on format and extent PROCESS TYPES: - Management processes (planning, review, improvement) - Core processes (design, production, service delivery) - Support processes (HR, IT, maintenance, procurement) - Measurement processes (monitoring, audit, analysis)

What to sample

Review the process map or turtle diagrams for the three most critical processes, verifying that inputs, outputs, and interactions are current and reflect actual practice.

Follow-up questions
  • How does the organization identify when a new process needs to be added to the QMS or an existing one modified?
  • Can you describe the mechanism for continual improvement of the QMS as a system, beyond individual process improvements?
  • How are process interactions verified when changes are made to one process that affects others?
4.4.1 Has the organization stood up, and does it maintain and continually improve, a QMS built around its processes and their interactions, with evidence the processes are managed as a system?
Objective evidence
  • The process map or interaction diagram - verify it shows the actual QMS processes and how each one's outputs feed the next (not an org chart relabelled as processes), and that support and management processes are included, not just the core value stream.
  • Process definitions for the key processes - for a sample, confirm inputs, outputs, owner, and the criteria/methods used to know the process is performing are defined (linking to 4.4.1 a-e).
  • Evidence the processes are managed as a system - process KPIs reviewed, interactions monitored at the handoffs (e.g. sales-to-operations, design-to-production), and action taken where a process underperforms.
  • Process changes and improvements - records showing processes are evaluated and improved over time (4.4.1 g-h), not frozen since certification.
  • Documented information supporting and evidencing the processes (4.4.2) - procedures/instructions where needed, and records that show the processes ran as planned.
Common nonconformities
  • Minor NC: Processes are listed but their sequence and interactions are not defined, so the handoffs between processes (the usual failure points) are uncontrolled.
  • Minor NC: The 'process map' is an org chart or a list of departments, not the actual processes and their flows.
  • Minor NC: No process-level criteria or performance measures, so the organization cannot tell whether a given process is achieving its intended results.
  • Observation: Processes were defined at certification and never revisited, with no evidence of evaluation or improvement (4.4.1 g-h).
Auditor tip

Clause 4.4.1 establishes the overall requirement for a process-based QMS. The organization must identify all necessary processes and manage their interactions.

What to sample

Select three processes from different functional areas and verify each has defined inputs, outputs, criteria, resources, responsibilities, and risk considerations.

Follow-up questions
  • How many processes are defined within the QMS, and how was the level of detail determined for each?
  • What approach does the organization use to define process interactions, such as a process map, interaction matrix, or turtle diagrams?
  • How does the organization ensure that all processes needed for the QMS are identified and none are inadvertently omitted?
4.4.1 a) For each QMS process, are the required inputs and the expected outputs clearly defined?
Objective evidence
  • Process flow diagrams with inputs/outputs
  • SIPOC diagrams
  • Turtle diagrams
  • Process descriptions listing inputs/outputs
  • Work instructions specifying input requirements
  • Output specifications and acceptance criteria
  • Process interface definitions
Common nonconformities
  • Processes without defined inputs
  • No output specifications
  • Input/output mismatch between processes
  • Undocumented process triggers
  • No acceptance criteria for outputs
Auditor tip

Each process must have clearly defined inputs and outputs. PROCESS INPUTS: - Materials, components, raw materials - Information and data - Customer requirements and specifications - Design information - Outputs from preceding processes - Resources (people, equipment, environment) - Documented information (procedures, instructions) PROCESS OUTPUTS: - Products or services (intermediate or final) - Information and records - Decisions and approvals - Reports and documentation - Inputs to subsequent processes - Waste and by-products DEFINING INPUTS AND OUTPUTS: - Identify what triggers the process (inputs) - Identify what the process produces (outputs) - Define specifications/criteria for inputs - Define acceptance criteria for outputs - Ensure output of one process matches input needs of next TOOLS FOR DOCUMENTATION: - Process flow diagrams showing I/O - Turtle diagrams (SIPOC alternative) - SIPOC diagrams (Suppliers, Inputs, Process, Outputs, Customers) - Process descriptions/procedures

What to sample

Select one core realization process and one support process; verify that inputs and expected outputs are formally defined and that actual outputs match specifications.

Follow-up questions
  • For the key operational processes, how are inputs verified as adequate before the process begins?
  • How does the organization confirm that process outputs meet the requirements of downstream processes or the customer?
4.4.1 b) Are the sequence and interactions between processes mapped, so it is clear how the output of one feeds the next?
Objective evidence
  • Process map or process interaction diagram
  • Process flow charts
  • Process interaction matrix
  • Swimlane diagrams
  • Business process model (BPM)
  • Quality manual process description
  • Interface control documents
Common nonconformities
  • No overall process map
  • Processes documented in isolation
  • Unclear handoffs between processes
  • Missing links between processes
  • Process sequence not logical
  • Interactions not understood by staff
Auditor tip

Processes don't operate in isolation - they interact and depend on each other. PROCESS SEQUENCE: - Order in which processes occur - Which processes come before/after - Parallel vs. sequential processes - Critical path through processes - Process flow from customer order to delivery PROCESS INTERACTION: - How processes connect to each other - What information/materials flow between processes - Dependencies between processes - Handoff points and responsibilities - Feedback loops between processes PROCESS CATEGORIES (typical): - Management processes (strategy, planning, review) - Core/operational processes (design, production, delivery) - Support processes (HR, IT, maintenance, purchasing) - Measurement processes (audit, monitoring, analysis) DOCUMENTATION APPROACHES: - High-level process map showing all processes - Process interaction matrix - Detailed flow charts for key processes - Interface definitions between processes - Swimlane diagrams showing responsibilities

What to sample

Review the process interaction map or matrix and verify it against actual workflow by tracing one product or service from order intake through delivery.

Follow-up questions
  • How is the sequence of processes documented, and does it reflect the actual operational flow?
  • When a process change occurs, how are upstream and downstream process owners notified of potential impacts on interactions?
4.4.1 c) Are the criteria, methods, and performance indicators needed to operate and control each process defined, so the organization can tell whether a process is performing?
Objective evidence
  • Process KPIs and targets
  • Process control plans
  • Work instructions with acceptance criteria
  • SPC charts and process capability data
  • Process monitoring records
  • Performance dashboards
  • Inspection and test procedures
  • Process validation records
Common nonconformities
  • No defined process performance indicators
  • Processes without acceptance criteria
  • No monitoring of process performance
  • KPIs not linked to process effectiveness
  • No action taken when processes fail targets
  • Ad-hoc process control methods
Auditor tip

Each process needs defined criteria for success and methods to control it. PROCESS CRITERIA: - Acceptance criteria for outputs - Performance targets and objectives - Process capability requirements - Quality standards to meet - Tolerance limits - Customer specifications PROCESS CONTROL METHODS: - Procedures and work instructions - Process parameters to control - Inspection and testing methods - Statistical process control (SPC) - Automated controls - Verification and validation methods MONITORING AND MEASUREMENT: - What to measure (key parameters) - How often to measure (frequency) - How to measure (methods, instruments) - Who performs measurement - How to record results - Actions when out of spec PERFORMANCE INDICATORS (KPIs): - Quality metrics (defect rate, yield, first-pass quality) - Delivery metrics (on-time, lead time) - Efficiency metrics (throughput, productivity) - Cost metrics (cost per unit, rework cost) - Customer metrics (complaints, satisfaction) - Safety metrics (incidents, near-misses) KEY CONCEPT: Processes must be "controlled" - not just performed, but actively managed to achieve consistent results.

What to sample

Review performance dashboards or KPI reports for two processes; verify that criteria are defined, measurements are taken at stated frequency, and trend data shows evidence of action on adverse results.

Follow-up questions
  • What key performance indicators are established for each process, and how were the target values determined?
  • How frequently are process performance indicators reviewed, and what actions are taken when targets are not met?
  • Are the monitoring methods validated as appropriate for the characteristics being measured?
4.4.1 d) Are the resources each process needs identified, and is their availability actually ensured?
Objective evidence
  • Resource allocation plans
  • Staffing plans and schedules
  • Equipment lists and maintenance records
  • Training records and competency matrix
  • Budget allocation
  • Capacity planning documents
  • Infrastructure maintenance plans
  • Skills matrices
Common nonconformities
  • Resources not identified for processes
  • Chronic resource shortages
  • No resource planning
  • Equipment unavailable when needed
  • Insufficient trained personnel
  • Resources not aligned with process needs
Auditor tip

Processes require resources to function effectively. TYPES OF RESOURCES: HUMAN RESOURCES: - Number of people needed - Competencies required - Training needs - Shift patterns and coverage INFRASTRUCTURE: - Equipment and machinery - Tools and instruments - Buildings and workspace - IT systems and software - Utilities (power, water, compressed air) - Transportation ENVIRONMENT: - Controlled conditions (temperature, humidity, cleanliness) - Safety equipment and conditions - Ergonomic considerations KNOWLEDGE AND INFORMATION: - Technical knowledge - Process documentation - Standards and specifications - Organizational knowledge FINANCIAL RESOURCES: - Operating budget - Capital for equipment - Training budget ENSURING AVAILABILITY: - Resource planning and scheduling - Maintenance programs - Backup/redundancy for critical resources - Capacity planning - Skills matrix and training plans

What to sample

Select one process and verify that resource allocations (staffing, equipment, budget) are documented and that current availability matches the defined requirements.

Follow-up questions
  • How does the organization determine resource requirements for each process, including personnel, equipment, and infrastructure?
  • What happens when resource constraints are identified that could affect process performance?
4.4.1 e) Is ownership clear for each process, with defined responsibilities and authorities (for example, a named process owner)?
Objective evidence
  • Process owner assignments
  • Job descriptions with process responsibilities
  • RACI matrices
  • Organizational charts
  • Procedures with roles defined
  • Authority matrices
  • Delegation of authority documents
  • Approval limits documentation
Common nonconformities
  • No process owners assigned
  • Unclear responsibilities
  • Responsibility without authority
  • Multiple people think they own same process
  • No one accountable for process performance
  • Roles not communicated to staff
Auditor tip

Every process needs clear ownership and defined authorities. PROCESS OWNER: - Person accountable for process performance - Authority to make changes to process - Responsible for process improvement - Monitors process metrics - Reports on process performance RESPONSIBILITIES TO DEFINE: - Who performs each activity - Who reviews and approves outputs - Who handles nonconformities - Who makes decisions - Who communicates with other processes - Who maintains records AUTHORITIES TO DEFINE: - Authority to approve outputs - Authority to release product - Authority to stop the process - Authority to make changes - Authority to access resources - Authority to accept nonconforming product DOCUMENTATION OF R&A: - Job descriptions - Process procedures - Organizational charts - RACI matrices (Responsible, Accountable, Consulted, Informed) - Approval matrices - Delegation of authority documents IMPORTANT: Responsibility without authority is ineffective. Process owners must have authority to act.

What to sample

Review the organizational chart or responsibility matrix, then interview one process owner to confirm they understand and actively exercise their defined authority.

Follow-up questions
  • Are process owners formally appointed, and do they have documented authority commensurate with their responsibilities?
  • How do process owners demonstrate accountability for process performance and improvement?
4.4.1 f) Are the risks and opportunities for each process identified and acted on, in line with the organization's 6.1 approach?
Objective evidence
  • Process FMEA (Failure Mode and Effects Analysis)
  • Process risk assessments
  • Risk registers by process
  • Control plans addressing risks
  • Risk treatment actions and records
  • Opportunity assessment records
  • Management review discussing process risks
Common nonconformities
  • No risk consideration at process level
  • Risks identified but no actions taken
  • Only focusing on risks, ignoring opportunities
  • Process risks not linked to 6.1 actions
  • Risk thinking not embedded in process management
Auditor tip

Each process must consider and address risks and opportunities. PROCESS-LEVEL RISK THINKING: RISK IDENTIFICATION: - What could go wrong in this process? - What factors could cause process failure? - What are the consequences of failure? - What external factors could impact the process? TYPES OF PROCESS RISKS: - Quality risks (defects, nonconformities) - Delivery risks (delays, capacity issues) - Resource risks (equipment failure, staff turnover) - Supply risks (supplier issues, material shortages) - Compliance risks (regulatory, customer requirements) - Safety risks (accidents, injuries) RISK TREATMENT: - Avoid the risk (eliminate the activity) - Mitigate the risk (controls to reduce likelihood/impact) - Transfer the risk (insurance, outsourcing) - Accept the risk (with monitoring) OPPORTUNITY IDENTIFICATION: - How can this process be improved? - What efficiencies can be gained? - What new capabilities can be developed? - How can customer satisfaction be enhanced? LINK TO CLAUSE 6.1: - Process-level risks feed into overall risk assessment - Actions must be planned and implemented - Effectiveness must be evaluated ISO 9001 calls for "risk-based thinking," not formal risk management.

What to sample

Select two processes and verify that the risks identified in the risk register are addressed by specific controls or actions within those process procedures.

Follow-up questions
  • How are the risks and opportunities identified under clause 6.1 integrated into individual process controls?
  • Can you provide an example where a process-level risk led to a specific control or mitigation action?
4.4.1 g) Does the organization evaluate its processes and make the changes needed when they are not achieving intended results?
Objective evidence
  • Process performance reviews
  • Process audit reports
  • KPI trend analysis
  • Management review minutes discussing processes
  • Change requests and approvals
  • Process improvement records
  • Before/after comparison data
  • Updated procedures following changes
Common nonconformities
  • Processes never evaluated
  • Poor performance but no changes made
  • Changes made without evaluation
  • No process for making changes
  • Changes not controlled or documented
  • Impact of changes not assessed
Auditor tip

Processes must be regularly evaluated and changed when needed. PROCESS EVALUATION: WHAT TO EVALUATE: - Are processes achieving intended results? - Are process KPIs meeting targets? - Is process output conforming to requirements? - Are there recurring problems? - Is the process efficient? - Are resources adequate? HOW TO EVALUATE: - Review process performance data - Analyze trends in KPIs - Internal process audits - Management reviews - Customer feedback analysis - Nonconformity analysis - Benchmarking against best practices WHEN TO EVALUATE: - Regularly (scheduled reviews) - After significant changes - When problems occur - When targets not met - As part of management review - During internal audits IMPLEMENTING CHANGES: - Identify need for change - Plan the change (including risk assessment) - Implement in controlled manner - Verify effectiveness - Update documentation - Communicate changes - Train affected personnel CHANGE CONTROL: - Changes should be managed, not ad-hoc - Consider impact on other processes - Maintain documented information

What to sample

Review process audit results or management review outputs for evidence of process evaluations and resulting changes implemented within the last 12 months.

Follow-up questions
  • What triggers a process evaluation beyond routine scheduled reviews?
  • Can you provide a recent example where a process evaluation resulted in a change to achieve intended results?
4.4.1 h) Is there evidence the organization improves its processes and the QMS over time, not just keeps them running?
Objective evidence
  • Improvement projects and records
  • Before/after metrics showing improvement
  • Lean/Six Sigma projects
  • Kaizen event records
  • Employee suggestion program
  • Cost of quality trending down
  • Customer satisfaction trending up
  • Process capability improvements
  • Innovation initiatives
Common nonconformities
  • No improvement activities
  • Same problems recurring
  • No improvement culture
  • Improvements not sustained
  • No resources for improvement
  • Reactive only, no proactive improvement
Auditor tip

Continual improvement is a core principle of ISO 9001. IMPROVEMENT FOCUS AREAS: PROCESS IMPROVEMENT: - Increase efficiency (reduce waste, time, cost) - Improve effectiveness (better results, fewer defects) - Enhance capability (more consistent, capable processes) - Reduce variation - Improve customer satisfaction QMS IMPROVEMENT: - Better integration of processes - More effective documentation - Improved communication - Enhanced risk management - Better use of technology - Stronger quality culture SOURCES OF IMPROVEMENT: - Analysis of data and trends - Audit findings - Customer feedback and complaints - Employee suggestions - Benchmarking - Management review outputs - Corrective action analysis - New technology opportunities IMPROVEMENT METHODOLOGIES: - PDCA (Plan-Do-Check-Act) - Lean (waste elimination) - Six Sigma (variation reduction) - Kaizen (continuous small improvements) - Process reengineering (major changes) - 8D problem solving - Root cause analysis IMPROVEMENT CULTURE: - Leadership commitment - Employee engagement - Recognition of improvements - Resources for improvement - Learning from failures

What to sample

Review the continual improvement log or corrective action records for evidence of process improvements initiated and completed in the current audit cycle.

Follow-up questions
  • How does the organization prioritize which processes to improve, and what methodology is used?
  • Can you describe the relationship between process-level improvements and overall QMS improvement?
4.4.2 Does the organization maintain the documented information needed to operate its processes and retain the records needed to show those processes run as planned, with the extent justified rather than excessive?
Objective evidence
  • The documented information MAINTAINED to support process operation - procedures, instructions, and forms for the key processes - present and used, not just on a shelf.
  • The records RETAINED to have confidence processes ran as planned - completed forms, inspection/test records, logs - for a sample of processes.
  • Evidence the EXTENT of documentation is appropriate to the organization's size and complexity - enough to control the processes, not bureaucratic overkill or dangerously thin.
  • Document control applied to the maintained information (current, approved, available) and records (retrievable, protected) - link to 7.5.
  • A check that the documented information is actually FOLLOWED in practice - the procedure matches what people do.
Common nonconformities
  • Minor NC: Records needed to show key processes ran as planned are not retained, so there is no evidence of conformity.
  • Minor NC: Maintained documentation exists but is not followed in practice - the procedure and the work diverge.
  • Minor NC: Documentation is excessive and bureaucratic, or so thin that key processes are uncontrolled.
  • Observation: Documented information is not readily accessible to the people who need it at the point of work.
Auditor tip

ISO 9001:2015 requires documented information but gives flexibility on extent. TWO TYPES OF DOCUMENTED INFORMATION: MAINTAINED (Procedures/Instructions): - "How we do things" - Procedures, work instructions, forms - Process descriptions - Guidelines and standards - These are controlled and kept current RETAINED (Records/Evidence): - "Evidence that we did things" - Completed forms and checklists - Test results and inspection records - Audit reports - Meeting minutes - These are preserved and protected "TO THE EXTENT NECESSARY": - ISO 9001 does not mandate specific documents - Organization determines what's needed based on: * Complexity of processes * Competence of personnel * Risk involved * Customer/regulatory requirements * Size of organization FACTORS AFFECTING EXTENT: - Simple processes with experienced staff = less documentation - Complex processes with high risk = more documentation - Regulatory requirements may mandate specific documents - Customer requirements may specify documentation KEY POINT: Documentation should add value, not be bureaucracy. Right-size documentation to actual needs.

What to sample

Select a high-risk process and verify both types of documented information exist: operational documents (procedures, work instructions) and retained records (completed forms, logs, test results).

Follow-up questions
  • How does the organization determine the extent of documented information needed for each process?
  • What is the retention policy for quality records, and how does it align with regulatory and contractual requirements?
  • How does the organization ensure that documented information remains legible, identifiable, and retrievable over its retention period?
4.4.2 a) Is the documented information needed to support process operation (procedures, work instructions, forms) maintained and kept current?
Objective evidence
  • Procedures for key processes
  • Work instructions
  • Process flowcharts
  • Forms and templates
  • Controlled document list
  • Document control procedures
  • Evidence of document approval
  • Evidence of document availability
Common nonconformities
  • No procedures exist
  • Procedures outdated or not followed
  • No document control system
  • Documents not accessible
  • Excessive unnecessary documentation
Auditor tip

Documented information that is "maintained" = procedures, instructions, guidance. EXAMPLES OF MAINTAINED DOCUMENTED INFORMATION: - Quality policy and objectives - QMS scope - Process procedures - Work instructions - Forms and templates (blank) - Specifications - Standards - Guidelines CHARACTERISTICS: - Current/active documents - Subject to change control - Reviewed and approved - Available at point of use - Version controlled - Obsolete versions removed/controlled DOCUMENT CONTROL REQUIREMENTS (per 7.5): - Identification and description - Format and media - Review and approval - Availability and access - Protection - Change control - Retention and disposition RIGHT-SIZING: - Not every process needs detailed procedures - Consider complexity and risk - Consider competence of personnel - Competent staff may need less written instruction - High-risk or complex processes need more documentation

What to sample

Verify that the document master list is current, then select two procedures and confirm they are the latest revision and accessible at the point of use.

Follow-up questions
  • How does the organization decide which operational documents (procedures, work instructions, forms) are necessary for each process?
  • What is the document review and approval process, and how are obsolete documents prevented from unintended use?
4.4.2 b) Does the organization keep the records needed to have confidence its processes are being carried out as planned?
Objective evidence
  • Completed quality records
  • Record retention schedule
  • Record storage system (physical/electronic)
  • Evidence of record protection (backups)
  • Record retrieval capability
  • Record access controls
  • Record disposal procedures and evidence
Common nonconformities
  • No records retained
  • Records incomplete or missing
  • No retention schedule
  • Records not retrievable
  • Records not protected
  • Premature disposal of records
Auditor tip

Documented information that is "retained" = records, evidence. EXAMPLES OF RETAINED DOCUMENTED INFORMATION: - Completed forms and checklists - Inspection and test records - Audit reports - Management review minutes - Training records - Calibration records - Supplier evaluation records - Customer complaint records - Corrective action records - Design records - Production records CHARACTERISTICS: - Evidence of activities performed - Not changed after creation (immutable) - Protected from loss or damage - Retrievable when needed - Retained for defined periods - Eventually disposed of properly RECORD CONTROL REQUIREMENTS (per 7.5): - Identification - Storage (secure, protected) - Protection (backup, access control) - Retrieval (findable when needed) - Retention (how long to keep) - Disposition (how to dispose) RETENTION PERIODS: - Based on legal/regulatory requirements - Based on customer requirements - Based on product lifecycle - Based on organizational needs - Should be defined in record retention schedule

What to sample

Request records from a completed process (e.g., a production batch or service delivery from the past quarter) and verify they are retrievable, complete, and legible.

Follow-up questions
  • How does the organization determine which records must be retained as evidence of process conformity?
  • Can you demonstrate that records are available from a process completed six months ago?

Each item shows its evidence, common nonconformities and auditor tips. The clause index has the PDF of all 251 items, formatted for a clipboard.