ISO 9001:2015 clause 6: Planning

The 22 audit questions covering clause 6, each with the objective evidence to request, the nonconformities most often raised against it and what to sample. Part of the free ISO 9001:2015 gap analysis checklist, which holds 251 items across 7 clauses.

22 items in this clause 1 section 251 items in the full checklist ISO 9001:2015 · updated 2026-06-24

All 22 questions for clause 6

Open any row for its objective evidence, common nonconformities and auditor tips. You can check items off as you go. This browser remembers your progress across all 7 clauses of this checklist.

§6 Planning 22 items · ~110 min
6.1 Drawing on its 4.1 context and 4.2 interested-party requirements, has the organization worked out the risks and opportunities its QMS needs to address, and planned how it will act on them?
Objective evidence
  • The risk-and-opportunity register or equivalent - verify entries trace back to the 4.1 context and 4.2 interested-party requirements, cover opportunities as well as threats, and are owned rather than anonymous.
  • For a sample of risks, the planned actions - confirm each has a defined action, owner, and timeline, and that the response is proportionate (no major effort on trivial risks, no critical risk left with a token action).
  • Evidence risk actions are integrated into the QMS processes (4.4) - the actions live inside process procedures and daily operations, not in a separate risk document nobody uses.
  • Effectiveness evaluation - records showing the organization later checked whether the risk actions worked and whether opportunities were captured, closing the loop.
  • Evidence the register is kept live - dated reviews (e.g. at management review), with new risks added as context changes, rather than a one-time exercise frozen since certification.
Common nonconformities
  • Minor NC: Risks and opportunities are documented for the audit but not used - no actions, no owners, no link to processes or decisions.
  • Minor NC: Only negative risks are considered; opportunities (the other half of clause 6.1) are absent.
  • Minor NC: No traceable link between the 4.1/4.2 context and the risks identified, so the register is generic rather than organization-specific.
  • Observation: Risk responses are disproportionate (heavy effort on trivial risks, or critical risks with token actions), suggesting risk-based thinking is procedural rather than real.
Auditor tip

Organizations must systematically identify and address risks and opportunities affecting the QMS. This is risk-based thinking in action - not just risk management, but also opportunity management. KEY CONCEPTS: DETERMINING RISKS AND OPPORTUNITIES: - Based on organizational context (4.1) - Based on interested party needs (4.2) - Consider both threats and opportunities - Think broadly: strategic, operational, compliance - Consider internal and external factors PURPOSES (a-d): a) ASSURANCE - Ensure QMS achieves intended results b) ENHANCEMENT - Capitalize on positive opportunities c) PREVENTION - Reduce or eliminate negative effects d) IMPROVEMENT - Drive continuous improvement PLANNING ACTIONS (e-f): e) DEFINE ACTIONS: - What will be done to address each risk/opportunity - Who is responsible - Resources required - Timelines - Success criteria f) INTEGRATION AND EVALUATION: - How actions integrate into QMS processes - How effectiveness will be measured - Monitoring and review mechanisms - Feedback loops for learning PROPORTIONALITY: - Actions must match the significance of the risk/opportunity - Don't over-engineer responses to minor risks - Don't under-resource major opportunities - Risk-based allocation of effort and resources RISK TREATMENT OPTIONS: - Avoid: Eliminate the activity causing risk - Accept: Take informed decision to proceed - Mitigate: Reduce likelihood or impact - Transfer: Share with others (insurance, outsourcing) - Exploit: Actively pursue opportunities OPPORTUNITY EXAMPLES: - New market entry - Technology adoption - Process innovation - Customer partnerships - Product development - Efficiency improvements - Competitive advantages

What to sample

Review the risk and opportunity register or assessment, verify it references issues from 4.1 and requirements from 4.2, and confirm it has been reviewed within the defined review cycle.

Follow-up questions
  • How does the organization's risk and opportunity assessment connect to the context analysis from clause 4.1 and interested parties from clause 4.2?
  • What methodology is used to assess and prioritize risks and opportunities?
  • How frequently is the risk and opportunity register reviewed and updated?
6.1 a) Among the risks and opportunities it determined, has the organization captured those needed to give assurance the QMS can achieve its intended results?
Objective evidence
  • Risk assessment identifying QMS risks
  • Opportunity assessment for QMS enhancement
  • Analysis of threats to QMS effectiveness
  • Risk register linked to QMS outcomes
Common nonconformities
  • Risks not linked to QMS results
  • Only generic risks considered
  • No QMS-specific risk analysis
  • Intended results not defined
Auditor tip

Risks and opportunities must be identified that could affect QMS success. INTENDED RESULTS OF QMS: - Conforming products and services - Enhanced customer satisfaction - Effective processes - Continual improvement - Meeting quality objectives ASSURANCE THROUGH RISK/OPPORTUNITY MANAGEMENT: - Identify what could prevent intended results - Identify what could help achieve intended results - Ensure confidence in QMS outcomes - Proactive approach to QMS performance RISKS TO QMS RESULTS: - Process failures - Resource constraints - Competence gaps - Equipment failures - Supplier issues - Regulatory changes - Market changes OPPORTUNITIES FOR QMS: - Process improvements - Technology adoption - Better methods - Enhanced capabilities

What to sample

Review the risk register for entries specifically linked to QMS intended results (customer satisfaction, conformity, continual improvement) and verify mitigation actions are defined.

Follow-up questions
  • What specific risks have been identified that could prevent the QMS from achieving its intended results?
  • How does the organization distinguish between risks to QMS effectiveness and general business risks?
6.1 b) Are opportunities to strengthen desirable effects (such as customer satisfaction, quality, and efficiency) identified, not just risks?
Objective evidence
  • Opportunity register
  • Enhancement initiatives
  • Improvement opportunities identified
  • Strategic opportunities analysis
Common nonconformities
  • Only negative risks considered
  • No opportunity identification
  • Defensive mindset only
  • No pursuit of improvements
Auditor tip

Opportunities should be identified to make good things even better. DESIRABLE EFFECTS TO ENHANCE: - Customer satisfaction - Product quality - Process efficiency - Employee engagement - Market position - Profitability - Innovation OPPORTUNITY THINKING: - Not just avoiding risks - Actively seeking improvements - Building on strengths - Capitalizing on opportunities - Proactive not just reactive EXAMPLES: - New technology to improve quality - Market opportunity to expand - Process improvement to reduce costs - Partnership opportunity for innovation - Customer collaboration opportunity

What to sample

Review the opportunity section of the risk and opportunity register and verify that at least two opportunities have defined actions and responsible owners.

Follow-up questions
  • What opportunities has the organization identified to enhance QMS outcomes or create competitive advantage?
  • How are opportunities evaluated and prioritized for action?
6.1 c) Are the risks that could cause undesired effects (nonconformities, complaints, delivery failures, safety or compliance issues) identified so they can be prevented or reduced?
Objective evidence
  • Risk register with negative risks
  • Preventive actions planned
  • Risk mitigation controls
  • Corrective action for realized risks
Common nonconformities
  • Only reactive to problems
  • No preventive risk management
  • Undesired effects recurring
  • Known risks unaddressed
Auditor tip

Risks must be identified and managed to prevent negative outcomes. UNDESIRED EFFECTS TO PREVENT/REDUCE: - Nonconforming products/services - Customer complaints - Delivery failures - Safety incidents - Regulatory non-compliance - Rework and waste - Customer loss - Reputation damage PREVENTION VS REDUCTION: - Prevention: Eliminate risk entirely - Reduction: Lower likelihood or impact - Choose approach based on risk significance - Some risks cannot be eliminated RISK TREATMENT OPTIONS: - Avoid: Don't do the activity - Mitigate: Add controls to reduce - Transfer: Insurance, outsourcing - Accept: Tolerate with monitoring PROACTIVE APPROACH: - Address risks before they occur - Not just reactive fire-fighting - Preventive action mindset - Early warning systems

What to sample

Select two high-rated risks from the register, verify that preventive actions are implemented, and review effectiveness data showing the undesired effects are controlled.

Follow-up questions
  • What undesired effects has the organization identified, and what preventive or mitigating actions are in place?
  • How does the organization evaluate whether its risk mitigation actions are effective in reducing undesired effects?
6.1 d) Has the organization looked at how addressing risks and opportunities can drive improvement, not just hold the line?
Objective evidence
  • Improvement initiatives from risk/opportunity analysis
  • Innovation projects from opportunities
  • Process improvements from risk prevention
  • Learning from risk events
Common nonconformities
  • Risk management not driving improvement
  • Static, no improvement from opportunities
  • Same risks recurring without learning
  • Opportunities not converted to improvements
Auditor tip

Risk and opportunity management should drive continual improvement. IMPROVEMENT THROUGH RISK/OPPORTUNITY: - Addressing risks improves reliability - Pursuing opportunities improves capability - Learning from risks prevents recurrence - Innovation comes from opportunities TYPES OF IMPROVEMENT: - Product/service improvement - Process improvement - QMS improvement - Performance improvement - Capability improvement - Efficiency improvement LINK TO CONTINUAL IMPROVEMENT: - Risk-based thinking enables improvement - Opportunities drive innovation - Prevention is improvement - Proactive better than reactive IMPROVEMENT OPPORTUNITIES: - Technology advances - Best practice adoption - Customer feedback - Audit findings - Process analysis - Benchmarking insights

What to sample

Review improvement initiatives or corrective actions that originated from the risk and opportunity assessment process, and verify at least one has resulted in measurable improvement.

Follow-up questions
  • How does the organization use risk and opportunity assessment to identify areas for improvement?
  • Can you provide an example where addressing a risk or opportunity led to a measurable improvement in QMS performance?
6.1 e) For the risks and opportunities it identified, has the organization planned specific actions, with owners, resources, and timelines?
Objective evidence
  • Action plans for risks and opportunities
  • Risk treatment plans
  • Responsibility assignments for actions
  • Resources allocated for risk actions
  • Timeline for risk response actions
Common nonconformities
  • Risks identified but no actions
  • Actions not assigned to anyone
  • No resources for risk actions
  • Plans exist but not executed
Auditor tip

Identified risks and opportunities need planned response actions. ACTION PLANNING: - Define specific actions for each risk/opportunity - Assign responsibility for actions - Allocate resources - Set timelines - Define success criteria TYPES OF ACTIONS: - Preventive actions (before risk materializes) - Mitigating actions (reduce likelihood/impact) - Contingency plans (if risk occurs) - Opportunity pursuit actions - Monitoring actions ACTION CHARACTERISTICS: - Proportionate to significance - Practical and feasible - Resourced appropriately - Owned by specific person - Time-bound NOT JUST IDENTIFICATION: - Risks identified but actions not planned = gap - Must move from assessment to action - Plans must be executed - Results must be tracked

What to sample

Select two actions from the risk treatment plan and verify they have been implemented within the relevant QMS processes, with assigned owners and completion dates.

Follow-up questions
  • How are actions to address risks and opportunities integrated into QMS processes rather than managed as standalone activities?
  • What criteria determine whether a risk requires a formal action plan versus an existing process control?
6.1 f) Is there a plan for folding these actions into the QMS processes (per 4.4) and for evaluating whether they were effective?
Objective evidence
  • Risk actions integrated in process documentation
  • Evidence of action implementation
  • Effectiveness evaluation records
  • Review of risk status post-actions
  • Management review of risk actions effectiveness
Common nonconformities
  • Actions not integrated into processes
  • Separate risk system disconnected from QMS
  • No effectiveness evaluation
  • Actions completed but not verified effective
Auditor tip

Risk actions must be integrated into processes and effectiveness evaluated. INTEGRATION INTO QMS PROCESSES: - Actions embedded in process procedures - Not separate from daily operations - Part of how work is done - Controls built into processes - Risk thinking in all activities IMPLEMENTATION: - Execute the planned actions - Follow through on plans - Monitor progress of actions - Adjust as needed - Complete actions timely EVALUATE EFFECTIVENESS: - Did actions address the risk/opportunity? - Were outcomes achieved? - Was risk reduced/eliminated? - Was opportunity captured? - Were there unintended consequences? EVALUATION METHODS: - Review of risk status after actions - Audit of implemented controls - Analysis of incident data - Management review of effectiveness - KPIs for risk management CONTINUOUS CYCLE: - Evaluate effectiveness - Learn from results - Adjust actions as needed - Improve risk management approach

What to sample

Select one risk mitigation action and trace it from planning through implementation to effectiveness evaluation, verifying integration into the relevant QMS process.

Follow-up questions
  • How does the organization evaluate whether actions taken to address risks and opportunities were effective?
  • What evidence exists that risk actions are integrated into QMS processes as described in clause 4.4?
6.2.1 Are measurable quality objectives set at the relevant functions, levels, and processes, and are they consistent with the quality policy?
Objective evidence
  • The quality-objectives register - verify objectives are SMART (specific, measurable, with targets, owners, and deadlines), not aspirations like 'improve quality', and that each is consistent with a commitment in the quality policy.
  • Cascade evidence - objectives set at relevant functions, levels, AND processes (not only a corporate headline), with departmental/process objectives that ladder up to the organization's goals.
  • Relevance to conformity and customer satisfaction - confirm objectives target product/service conformity and customer outcomes, not purely internal vanity metrics.
  • Monitoring evidence - dashboards or reports showing each objective is tracked against its target with real data and reviewed (e.g. at management review), not set-and-forgotten.
  • Communication evidence - that the people responsible for an objective actually know it; ask a process owner what their objective is and how they are tracking against it.
Common nonconformities
  • Minor NC: Objectives are vague and unmeasurable ('improve quality', 'enhance satisfaction'), so achievement cannot be determined.
  • Minor NC: Objectives exist only at top-management level and are not cascaded to the functions, levels, and processes that deliver them.
  • Minor NC: Objectives are not monitored - there is no data showing progress against targets.
  • Observation: Personnel responsible for an objective are unaware of it, indicating objectives are documented but not lived.
Auditor tip

Quality objectives are specific, measurable targets that drive QMS performance. They must cascade throughout the organization - not just at top level. ESTABLISHMENT REQUIREMENTS: WHERE TO SET OBJECTIVES: - Relevant functions (departments, teams) - Relevant levels (strategic, operational, tactical) - Relevant processes (key QMS processes) Examples: - Corporate level: Customer satisfaction score - Department level: Defect reduction in manufacturing - Process level: On-time delivery for order fulfillment - Product level: Reliability targets for new product OBJECTIVE CHARACTERISTICS (a-g): a) CONSISTENT WITH QUALITY POLICY: - Align with quality policy commitments - Support policy intent - Demonstrate policy in action b) MEASURABLE: - Quantifiable metrics - Clear target values - Defined measurement methods - Objective success criteria Examples of measurable objectives: - "Achieve 95% on-time delivery by Q4" - "Reduce customer complaints by 20% this year" - "Improve first-pass yield to 98%" - "Complete 100% of audits on schedule" c) APPLICABLE REQUIREMENTS: - Consider customer requirements - Consider statutory/regulatory requirements - Consider contractual obligations - Ensure compliance objectives included d) RELEVANT TO CONFORMITY AND SATISFACTION: - Link to product/service quality - Link to customer satisfaction - Drive quality outcomes - Impact customer experience e) MONITORED: - Regular tracking and reporting - Progress reviews - Performance dashboards - Trend analysis f) COMMUNICATED: - Shared with relevant personnel - Understood by those responsible - Visible throughout organization - Regular updates on progress g) UPDATED AS APPROPRIATE: - Reviewed periodically - Revised based on changes in context - Adjusted based on performance - Remain relevant and challenging DOCUMENTATION: - Objectives must be documented - Accessible to those who need them - Version controlled if updated - Retained as evidence

What to sample

Review the quality objectives register across at least three organizational levels or functions, verify each objective has a measurable target and due date, and confirm responsible parties are aware of their objectives.

Follow-up questions
  • At which organizational levels and for which functions have quality objectives been established?
  • How does the organization ensure that quality objectives are measurable with defined targets and timeframes?
  • How are quality objectives communicated to the personnel responsible for achieving them?
6.2.1 a) Are the quality objectives consistent with the quality policy, so there is a clear line from policy commitments to objectives?
Objective evidence
  • Objectives linked to policy statements
  • Documentation showing policy-objective relationship
  • Review records checking consistency
Common nonconformities
  • Objectives contradict policy
  • No link between policy and objectives
  • Objectives unrelated to policy themes
Auditor tip

Objectives must align with and support the quality policy. CONSISTENCY MEANS: - Objectives support policy commitments - No conflict between policy and objectives - Objectives demonstrate policy in action - Clear link from policy to objectives HOW TO ENSURE CONSISTENCY: - Review policy when setting objectives - Derive objectives from policy themes - Check alignment during objective review - Document the policy-objective link EXAMPLE: Policy: "We are committed to customer satisfaction" Objective: "Achieve customer satisfaction score of 4.5/5.0" Policy: "We continually improve our processes" Objective: "Reduce defect rate by 15% this year"

What to sample

Map each quality objective to its parent quality policy statement and verify that all policy commitments are reflected in at least one objective.

Follow-up questions
  • Can you demonstrate the traceability between each quality objective and the corresponding quality policy commitment?
  • When the quality policy was last revised, were quality objectives reviewed for continued alignment?
6.2.1 b) Are the quality objectives genuinely measurable, with specific metrics and targets rather than vague aspirations?
Objective evidence
  • Objectives with numeric targets
  • Measurement methods defined
  • Tracking data for objectives
  • SMART objective documentation
Common nonconformities
  • Vague objectives without metrics
  • No way to measure achievement
  • Subjective success criteria
Auditor tip

Objectives must have quantifiable metrics and targets. MEASURABLE MEANS: - Specific numeric targets - Clear metrics to track - Defined measurement methods - Objective way to determine achievement - Can answer "did we achieve it?" with data GOOD MEASURABLE OBJECTIVES: - "Achieve 95% on-time delivery by December" - "Reduce customer complaints by 20%" - "Improve first-pass yield to 98%" - "Complete 100% of scheduled audits" - "Achieve zero critical nonconformities" POOR UNMEASURABLE OBJECTIVES: - "Improve quality" (how much? what metric?) - "Be more customer-focused" (unmeasurable) - "Enhance processes" (vague) SMART FRAMEWORK: - Specific: Clear and defined - Measurable: Quantifiable - Achievable: Realistic - Relevant: Tied to business needs - Time-bound: Has deadline

What to sample

Select three quality objectives and verify each has a quantified target (not vague language like 'improve' or 'enhance') with a defined measurement method and data source.

Follow-up questions
  • What measurement methods and data sources are used to track progress toward each quality objective?
  • How does the organization ensure that the metrics chosen actually reflect the intent of the objective?
6.2.1 c) Do the quality objectives take applicable requirements into account (customer, statutory, regulatory, contractual)?
Objective evidence
  • Objectives addressing regulatory requirements
  • Customer requirement-driven objectives
  • Compliance objectives
  • Requirements review when setting objectives
Common nonconformities
  • Objectives ignore regulatory requirements
  • Customer requirements not reflected
  • Compliance not addressed in objectives
Auditor tip

Objectives should address relevant requirements from various sources. APPLICABLE REQUIREMENTS TO CONSIDER: - Customer requirements - Statutory and regulatory requirements - Contractual requirements - ISO 9001 requirements - Industry standards - Organizational requirements HOW TO INCORPORATE: - Review requirements when setting objectives - Include compliance-related objectives - Ensure regulatory compliance is addressed - Consider customer expectations EXAMPLES: - Regulatory requirement → Objective: 100% compliance - Customer requirement → Objective: Meet delivery targets - Contract requirement → Objective: Achieve quality specs

What to sample

Review quality objectives for explicit references to applicable requirements, and cross-check against the requirements register to verify completeness.

Follow-up questions
  • How are applicable customer, statutory, and regulatory requirements considered when setting quality objectives?
  • Can you provide an example of a quality objective that was established in response to a specific regulatory or customer requirement?
6.2.1 d) Are the quality objectives relevant to the conformity of products and services and to enhancing customer satisfaction, rather than purely internal metrics?
Objective evidence
  • Objectives linked to product quality
  • Customer satisfaction objectives
  • Conformity improvement targets
  • Customer-focused metrics
Common nonconformities
  • Objectives unrelated to quality
  • No customer satisfaction objectives
  • Only internal focus, no customer perspective
Auditor tip

Objectives must focus on product quality and customer outcomes. RELEVANCE TO CONFORMITY: - Objectives drive product/service quality - Focus on meeting specifications - Reduce defects and nonconformities - Improve process capability - Enhance quality outcomes RELEVANCE TO CUSTOMER SATISFACTION: - Objectives improve customer experience - Address customer needs and expectations - Drive customer loyalty - Reduce customer complaints - Enhance service quality EXAMPLES: Conformity objectives: - First-pass yield target - Defect rate reduction - Specification compliance - Process capability (Cpk) targets Customer satisfaction objectives: - Customer satisfaction score - Net Promoter Score (NPS) - Complaint reduction - On-time delivery - Response time targets

What to sample

Categorize quality objectives by theme (conformity, satisfaction, efficiency, improvement) and verify that product/service conformity and customer satisfaction are both covered.

Follow-up questions
  • How do quality objectives address both product/service conformity and customer satisfaction enhancement?
  • Are there objectives covering both operational performance and customer experience dimensions?
6.2.1 e) Is progress toward each quality objective monitored regularly with data, rather than checked only once a year?
Objective evidence
  • Objective monitoring records
  • Performance dashboards
  • Progress reports
  • Trend analysis charts
  • Management review of objective status
Common nonconformities
  • Objectives set but not tracked
  • No regular monitoring
  • Data not collected for objectives
  • No action on poor performance
Auditor tip

Progress toward objectives must be tracked regularly. MONITORING MEANS: - Regular tracking of performance - Data collection for metrics - Progress reporting - Trend analysis - Comparison to targets MONITORING FREQUENCY: - Depends on objective nature - More frequent for critical objectives - At least quarterly for most - Monthly or real-time for operational MONITORING ACTIVITIES: - Collect performance data - Calculate metrics - Compare to targets - Identify variances - Analyze trends - Report status RESPONSE TO MONITORING: - Take action if off-track - Investigate negative trends - Recognize positive achievement - Adjust plans as needed

What to sample

Review monitoring records for quality objectives over the last two reporting periods and verify that monitoring occurred at the defined frequency and that underperformance triggered documented action.

Follow-up questions
  • At what frequency are quality objectives monitored, and who is responsible for the monitoring?
  • What happens when monitoring indicates an objective is at risk of not being achieved?
6.2.1 f) Are the quality objectives communicated to the people who need to know them?
Objective evidence
  • Communication records
  • Objectives posted/displayed
  • Meeting minutes discussing objectives
  • Employee awareness of objectives
Common nonconformities
  • Employees unaware of objectives
  • No communication of objectives
  • Objectives known only to quality dept
  • No progress updates shared
Auditor tip

Objectives must be shared with relevant personnel. COMMUNICATION MEANS: - Sharing objectives with those affected - Ensuring awareness of objectives - Explaining relevance to roles - Regular updates on progress - Visibility of objectives WHO TO COMMUNICATE TO: - All affected employees - Those responsible for achievement - Those whose work contributes - Management and leadership - Relevant stakeholders HOW TO COMMUNICATE: - Team meetings - Company communications - Posted displays - Intranet/portal - Performance discussions - Training sessions - Dashboards visible to all WHAT TO COMMUNICATE: - The objectives themselves - Why they matter - How each person contributes - Progress and status - Actions needed

What to sample

Interview personnel from two different functions and verify they can state the quality objectives relevant to their area, including targets and their role in achieving them.

Follow-up questions
  • Through what channels are quality objectives communicated to relevant personnel?
  • How does the organization verify that personnel understand the objectives relevant to their function?
6.2.1 g) Are the quality objectives reviewed and updated when circumstances change or targets are met?
Objective evidence
  • Objective revision records
  • Management review of objectives
  • Updated objectives documentation
  • Justification for objective changes
Common nonconformities
  • Same objectives for years unchanged
  • Objectives out of date
  • No review of objective relevance
  • Achieved objectives not replaced
Auditor tip

Objectives should be reviewed and revised when needed. UPDATING MEANS: - Reviewing continued relevance - Adjusting targets based on performance - Revising based on changed circumstances - Setting new objectives when achieved - Removing obsolete objectives TRIGGERS FOR UPDATE: - Strategic direction changes - Context changes (4.1) - Customer requirements change - Objectives achieved (set new) - Objectives no longer relevant - Performance indicates need to adjust - Regulatory changes UPDATE FREQUENCY: - At least annual review - More frequent if context changes - Part of management review - Responsive to significant events MAINTAIN CHALLENGE: - Don't lower targets to easy levels - Raise targets when consistently achieved - Keep objectives stretching but achievable - Balance ambition with realism

What to sample

Review the revision history of quality objectives and verify that updates correspond to changes in context, interested party requirements, or performance data.

Follow-up questions
  • Under what circumstances are quality objectives updated, and what triggers the review?
  • How does the organization ensure that updated objectives remain aligned with the quality policy and current business context?
6.2.2 For each objective, is there a plan covering what will be done, what resources are needed, who is responsible, when it will be done, and how results will be evaluated, so the 'how' backs up the 'what'?
Objective evidence
  • For each quality objective, the plan covering WHAT will be done, WHAT resources are needed, WHO is responsible, WHEN it will be completed, and HOW results will be evaluated (the five 6.2.2 elements).
  • Action plans/project plans with milestones and named owners - showing the 'how' actually exists behind the objective, not just a target.
  • Resource allocation behind the plans (budget, people, time) - confirming the objectives are resourced, not aspirational.
  • Progress tracking against the plans - evidence the plans are executed and monitored, not filed.
  • Defined evaluation criteria - how the organization will know the objective was achieved.
Common nonconformities
  • Minor NC: Objectives are set but there are no plans to achieve them (no what/who/when/resources), so they are targets without a path.
  • Minor NC: Plans exist but ownership or resources are not assigned, so nothing drives them.
  • Minor NC: No defined evaluation criteria, so achievement cannot be judged.
  • Observation: Objective planning is done only when an audit is announced.
Auditor tip

Setting objectives is not enough - there must be plans to achieve them. This is the "how" to complement the "what" of objectives. PLANNING ELEMENTS (a-e): a) WHAT WILL BE DONE: - Specific actions and activities - Projects or initiatives - Process changes - Milestones and deliverables - Steps to reach the objective Example: To achieve 95% on-time delivery - Implement new scheduling system - Train production planners - Improve supplier delivery performance - Reduce changeover times b) RESOURCES REQUIRED: - Budget and financial resources - Personnel and skills - Equipment and technology - Time allocation - External support (consultants, partners) c) RESPONSIBILITY: - Who owns the objective - Who leads each action - Who is accountable for results - Authority and empowerment - Clear ownership at appropriate level d) TIMING: - Completion dates for objective - Milestones and deadlines - Project timeline - Review points - Realistic and achievable timeframes e) EVALUATION OF RESULTS: - How success will be measured - Metrics and KPIs - Data collection methods - Review frequency - Success criteria INTEGRATION: - Can be part of strategic planning - Can be in business plans - Can be in project plans - Can be in performance management systems - Don't create separate system if existing processes work PRACTICAL IMPLEMENTATION: - Action plans for each objective - Gantt charts or project schedules - Resource allocation in budgets - Responsibility matrices (RACI) - Performance dashboards - Regular review meetings

What to sample

Review action plans for the three highest-priority quality objectives and verify each plan addresses what will be done, resources required, responsibility, timeline, and evaluation method.

Follow-up questions
  • Does the organization have documented action plans for achieving each quality objective?
  • How are action plans for quality objectives tracked and reviewed for progress?
  • What process ensures that resources allocated to objective achievement are adequate and available?
6.2.2 a) Does the plan for each objective state what specifically will be done (the actions, activities, or projects)?
Objective evidence
  • Action plans listing activities
  • Project plans with tasks
  • Improvement initiatives defined
  • Process change plans
Common nonconformities
  • Objectives without actions
  • Vague plans with no specifics
  • Generic action items
  • No clear steps defined
Auditor tip

Specific actions and activities must be identified. WHAT WILL BE DONE: - Specific actions to take - Activities and tasks - Projects to undertake - Process changes to make - Steps toward the objective - Milestones to achieve EXAMPLES: For objective "95% on-time delivery": - Implement new scheduling system - Train production planners - Establish supplier performance program - Reduce changeover times - Add capacity in bottleneck areas LEVEL OF DETAIL: - Enough to guide implementation - Specific enough to track - Clear enough to assign - Practical and actionable

What to sample

Review action items for one quality objective and verify each action is specific, with a clear deliverable that contributes to achieving the overall objective.

Follow-up questions
  • Are the planned actions specific enough to be actionable, or are they expressed in vague terms?
  • How were the actions determined to be sufficient to achieve the objective?
6.2.2 b) Does the plan identify what resources will be required (budget, people, equipment, materials)?
Objective evidence
  • Budget allocation for objectives
  • Staffing plans
  • Resource requirements documentation
  • Capital requests for equipment
Common nonconformities
  • No resources allocated
  • Insufficient budget
  • People overloaded
  • Resource planning ignored
Auditor tip

Resources needed for objective achievement must be identified. TYPES OF RESOURCES: - Budget and financial resources - People (number, skills, time) - Equipment and technology - Facilities and infrastructure - Materials and supplies - External support (consultants) - Training and development RESOURCE PLANNING: - Estimate resource needs realistically - Secure budget approval - Allocate people to tasks - Acquire necessary equipment - Schedule resource availability AVOIDING RESOURCE GAPS: - Plan resources upfront - Get commitment from management - Identify resource constraints early - Have contingency plans

What to sample

Verify that resource requirements (budget, personnel, equipment, time) are documented for at least two quality objective action plans and cross-reference against actual allocations.

Follow-up questions
  • How are resource requirements estimated for each action, and are budgets formally allocated?
  • What happens when required resources exceed available capacity?
6.2.2 c) Does the plan name who is responsible for each objective and its actions?
Objective evidence
  • Objective ownership assignments
  • RACI matrices
  • Action item owners assigned
  • Performance objectives linked to individuals
Common nonconformities
  • No one assigned
  • Unclear ownership
  • Multiple people think they own it
  • Responsibility without authority
Auditor tip

Clear ownership and accountability must be assigned. RESPONSIBILITY MEANS: - Named individual responsible for objective - Person accountable for results - Owner of the action plan - Point of contact for progress ASSIGNMENT CONSIDERATIONS: - Appropriate authority given - Competence to achieve - Capacity to take on - Clarity of expectations - Empowerment to act LEVELS OF RESPONSIBILITY: - Overall objective owner - Action item owners - Supporting roles - Management sponsor RACI FRAMEWORK: - Responsible: Does the work - Accountable: Answers for results - Consulted: Provides input - Informed: Kept updated

What to sample

Review responsibility assignments for quality objective actions and verify that named individuals acknowledge their responsibilities and have appropriate authority.

Follow-up questions
  • Are responsible individuals named for each action, and do they have the authority to execute?
  • How is accountability maintained when responsibilities span multiple departments?
6.2.2 d) Does the plan set when each objective and its milestones will be completed?
Objective evidence
  • Timelines for objectives
  • Milestone schedules
  • Gantt charts or project schedules
  • Deadline tracking
Common nonconformities
  • No timelines set
  • Unrealistic deadlines
  • No milestones defined
  • Timelines consistently missed
Auditor tip

Timelines and deadlines must be established. TIMING ELEMENTS: - Target completion date for objective - Milestones along the way - Deadlines for action items - Review points - Checkpoints for progress REALISTIC TIMELINES: - Achievable given resources - Allow for dependencies - Include buffer for issues - Balance urgency with feasibility - Consider competing priorities SCHEDULE MANAGEMENT: - Track against timeline - Identify delays early - Escalate when behind - Adjust as needed - Report on timing regularly

What to sample

Check the timeline for quality objective actions, identify any that are overdue, and verify that overdue items have documented explanations and revised completion dates.

Follow-up questions
  • Are completion dates realistic and based on resource availability and complexity?
  • How are overdue actions escalated and managed?
6.2.2 e) Does the plan define how the results will be evaluated, with success criteria and measurement methods?
Objective evidence
  • Evaluation criteria documented
  • Success measures defined
  • Review and evaluation records
  • Achievement assessments
Common nonconformities
  • No evaluation method defined
  • Subjective success criteria
  • No review of achievement
  • Results not assessed
Auditor tip

Success criteria and evaluation methods must be defined. EVALUATION ELEMENTS: - How to measure achievement - Success criteria defined - Data collection methods - Evaluation frequency - Who evaluates EVALUATION METHODS: - Compare to target metrics - Review milestone achievement - Analyze trend data - Assess qualitative outcomes - Get stakeholder feedback SUCCESS CRITERIA: - Clear definition of success - Measurable indicators - Objective assessment - Documented evidence EVALUATION TIMING: - During progress (interim reviews) - At completion (final evaluation) - Management review - Audit verification

What to sample

Review the evaluation criteria for one quality objective and verify that effectiveness is measured against the objective target, not merely by action completion.

Follow-up questions
  • What criteria will be used to determine whether actions taken have successfully achieved the quality objective?
  • How does the organization distinguish between completing an action and achieving the intended result?
6.3 When changes to the QMS are needed, are they planned in a controlled way that weighs their purpose and consequences, protects system integrity, and considers resources and role assignments, rather than being made on the fly?
Objective evidence
  • Evidence QMS changes are planned in a controlled way - a change process and records showing the purpose and potential consequences of the change were considered before implementation.
  • Consideration of QMS integrity, resource needs, and the allocation or reallocation of responsibilities and authorities for the change (the 6.3 a-d factors).
  • Impact/risk assessment for significant changes, so unintended consequences are caught before they hit.
  • Evidence documentation was updated and affected people informed after the change.
  • Evidence change effectiveness was reviewed - the change achieved its purpose without breaking the system.
Common nonconformities
  • Minor NC: QMS changes are made without planning or consideration of consequences, risking unintended effects on conformity.
  • Minor NC: Resource needs and responsibility reallocation are not considered when planning a change.
  • Minor NC: Documentation is not updated after a change, so people work to superseded information.
  • Observation: Changes are reactive with no review of whether they achieved their purpose or harmed QMS integrity.
Auditor tip

Changes to the QMS must be planned and controlled to maintain system integrity and effectiveness. This prevents unintended consequences from hasty changes. SCOPE OF CHANGES: Examples of QMS changes requiring planning: - New processes or process changes - Organizational restructuring - New products or services - New technology implementation - Changes to quality objectives - New facilities or locations - Significant supplier changes - Changes to scope of QMS - Major procedure revisions - Changes in management structure - Mergers or acquisitions - New regulatory requirements PLANNING CONSIDERATIONS (a-d): a) PURPOSE AND CONSEQUENCES: - Why is the change needed? - What are intended benefits? - What are potential risks? - What could go wrong? - Impact on product/service quality - Impact on customer satisfaction - Impact on compliance - Unintended side effects b) INTEGRITY OF QMS: - Will QMS remain effective? - Are all processes still covered? - Are interfaces maintained? - Are requirements still met? - Is system coherence maintained? - Are policies and procedures aligned? - Are records and documentation updated? c) AVAILABILITY OF RESOURCES: - People: Do we have the right skills? - Budget: Is funding available? - Time: Is timeline realistic? - Equipment: Is infrastructure adequate? - Information: Do we have needed data/knowledge? - External support: Are consultants/partners needed? d) RESPONSIBILITIES AND AUTHORITIES: - Who owns the change? - Who is responsible for implementation? - Who has authority to approve? - How are roles impacted? - Are new responsibilities needed? - Are authorities redefined? - Is training required for new roles? CHANGE MANAGEMENT PROCESS: 1. Identify need for change 2. Define scope and objectives 3. Assess risks and consequences 4. Plan implementation (what, who, when, how) 5. Ensure resources 6. Define/assign responsibilities 7. Communicate change 8. Implement change 9. Verify effectiveness 10. Update documentation 11. Lessons learned RELATIONSHIP TO OTHER CLAUSES: - 4.4: Change must maintain process approach - 8.1: Operational planning and control - 8.5.6: Production/service provision changes

What to sample

Select a recent QMS change (process modification, organizational restructuring, system upgrade) and verify that a change plan addressed purpose, consequences, resource needs, and responsibility assignments.

Follow-up questions
  • Can you describe a recent change to the QMS and how it was planned, including impact assessment and resource considerations?
  • How does the organization ensure that QMS integrity is maintained during and after changes?
  • What approval process is required before implementing changes that affect the QMS?

Each item shows its evidence, common nonconformities and auditor tips. The clause index has the PDF of all 251 items, formatted for a clipboard.