ISO 9001:2015 clause 7: Support

The 26 audit questions covering clause 7, each with the objective evidence to request, the nonconformities most often raised against it and what to sample. Part of the free ISO 9001:2015 gap analysis checklist, which holds 251 items across 7 clauses.

26 items in this clause 1 section 251 items in the full checklist ISO 9001:2015 · updated 2026-06-24

All 26 questions for clause 7

Open any row for its objective evidence, common nonconformities and auditor tips. You can check items off as you go. This browser remembers your progress across all 7 clauses of this checklist.

§7 Support 26 items · ~130 min
7.1.1 Has the organization worked out and provided the resources its QMS needs to be established, run, maintained, and improved, considering both internal capacity and what must come from outside?
Objective evidence
  • Evidence the organization determined and PROVIDED the resources its QMS needs - people, infrastructure, environment, monitoring resources, knowledge - across establish/run/maintain/improve.
  • Resource planning that weighs the capabilities and constraints of EXISTING internal resources before committing.
  • Evidence the organization determined what needs to be obtained from EXTERNAL providers versus done in-house.
  • Evidence resources are actually adequate in practice - check whether quality issues or delays trace to resource shortfalls.
  • Management-review consideration of resource adequacy (link to 9.3.2 d).
Common nonconformities
  • Minor NC: Resources needed for the QMS are not provided, with quality issues or delays traceable to the shortfall.
  • Minor NC: Resource needs are not planned; provision is reactive and constraint-driven.
  • Observation: Internal capability/constraint and external-provider options are not weighed when sizing resources.
  • Observation: Resource adequacy is not reviewed by management.
Auditor tip

Organizations must ensure adequate resources for the QMS. This is a fundamental requirement - without resources, the QMS cannot function effectively. RESOURCE DETERMINATION: - Assess what is needed for QMS - Consider all resource categories - Link to QMS objectives and plans - Ensure sufficiency and adequacy CONSIDERATIONS (a-b): a) INTERNAL RESOURCES - CAPABILITIES AND CONSTRAINTS: - Current workforce capabilities - Available infrastructure - Existing technology and equipment - Financial constraints - Capacity limitations - Competency gaps - Growth potential b) EXTERNAL PROVIDERS: - What cannot be provided internally - Outsourced services needed - Contracted resources - Consultants and specialists - Equipment rental/leasing - Technology vendors - Testing laboratories RESOURCE CATEGORIES: PEOPLE: - Sufficient headcount - Right skills and competencies - Succession planning - Organizational structure INFRASTRUCTURE (7.1.3): - Buildings and workspaces - Equipment and tools - IT systems and software - Transportation - Utilities and services ENVIRONMENT (7.1.4): - Physical conditions (temperature, humidity) - Cleanliness requirements - Safety conditions - Ergonomic factors - Social factors (stress reduction) MONITORING AND MEASURING (7.1.5): - Measurement equipment - Calibration resources - Testing equipment - Data analysis tools KNOWLEDGE (7.1.6): - Organizational knowledge base - Documented expertise - Training materials - Intellectual property PROVISION OF RESOURCES: - Budgeting and funding - Resource allocation decisions - Timely availability - Quality and suitability - Management commitment

What to sample

Review the last two management review meeting minutes for resource discussions. Cross-check budget allocations against stated QMS objectives.

Follow-up questions
  • How does management determine what resources are needed for the QMS each year?
  • Can you show me where resource constraints have been escalated and resolved?
  • How do you decide whether to source resources internally versus from external providers?
7.1.1 a) When sizing resources, does the organization weigh the capabilities and limits of what it already has internally?
Objective evidence
  • Capability assessments
  • Skills inventory
  • Equipment capacity analysis
  • Budget constraints documentation
  • Gap analysis reports
Common nonconformities
  • No awareness of constraints
  • Over-promising without capability
  • Capability gaps not identified
  • No assessment of internal resources
Auditor tip

Understand what your organization can and cannot do with existing resources. CAPABILITIES TO ASSESS: - Current workforce skills and competencies - Existing equipment and technology - Available infrastructure - Financial capacity - Organizational capacity - Technical expertise - Process capabilities CONSTRAINTS TO IDENTIFY: - Budget limitations - Staffing shortages - Equipment limitations - Facility constraints - Technology gaps - Time constraints - Capacity limits PURPOSE: - Realistic resource planning - Identify gaps to address - Make informed decisions - Avoid over-promising - Plan for capability development

What to sample

Review capacity planning documents or staffing plans. Compare current headcount and equipment utilization against workload forecasts.

Follow-up questions
  • What internal resource constraints are you currently managing, and how do they affect QMS performance?
  • How do you assess whether your current workforce and infrastructure are adequate for planned growth?
7.1.1 b) Is it clear what needs to be obtained from external providers rather than done in-house?
Objective evidence
  • Outsourcing decisions documentation
  • External provider list
  • Contracts and agreements
  • Make vs. buy analysis
Common nonconformities
  • No consideration of external options
  • External providers not managed
  • Critical gaps with no external solution
  • Over-reliance on external providers
Auditor tip

Determine what resources cannot or should not be provided internally. EXTERNAL RESOURCES TO CONSIDER: - Outsourced services - Contracted specialists - Consulting services - Testing and calibration services - Temporary staff - Equipment rental - Technology vendors - Training providers - Maintenance services FACTORS IN MAKE VS. BUY: - Core competency (keep in-house) - Cost effectiveness - Availability of skills - Quality requirements - Confidentiality needs - Speed and flexibility - Risk management EXTERNAL PROVIDER MANAGEMENT: - Selection criteria - Qualification process - Performance monitoring - Control requirements (see 8.4)

What to sample

Review 2-3 outsourcing decisions from the past year. Check that quality requirements were defined in contracts and performance monitored.

Follow-up questions
  • What criteria do you use to decide when to outsource versus build internal capability?
  • How do you ensure external resource providers meet your quality requirements?
7.1.2 Are the people needed to run and control the QMS processes determined and actually provided, in the right numbers and with the right skills?
Objective evidence
  • Evidence the people needed to operate and control the QMS processes are determined (numbers and skills) and actually provided.
  • Staffing/workforce plans and capacity analysis showing the organization sizes its people to the work, not just hopes it copes.
  • Coverage for critical processes - evidence key processes are not dependent on a single un-backed-up person (succession/cross-training).
  • Evidence quality issues or delays are not tracing to chronic understaffing.
  • Management-review consideration of staffing adequacy.
Common nonconformities
  • Minor NC: Chronic understaffing or single-person dependency on critical processes is causing quality issues or delays.
  • Minor NC: People needs are not determined against the processes, so staffing is reactive.
  • Observation: No succession or cross-training for critical roles, leaving the QMS exposed to key-person loss.
  • Observation: Staffing adequacy is not reviewed by management.
Auditor tip

Adequate and competent personnel must be provided for QMS effectiveness. DETERMINATION: - Identify personnel needs for each process - Determine required headcount - Identify skill and competency requirements - Consider workload and capacity - Plan for succession and turnover PROVISION: - Recruit and hire needed personnel - Allocate staff to QMS processes - Ensure availability when needed - Provide adequate team sizes - Replace departing personnel CONSIDERATIONS: - Process complexity and volume - Competency requirements (see 7.2) - Shift coverage and availability - Peak demand periods - Temporary vs. permanent needs - Internal development vs. external hiring - Contractor or temporary staff needs EFFECTIVENESS: - Right number of people - Right people in right roles - Sufficient capacity to meet demands - Backup and coverage plans - Retention of key personnel

What to sample

Compare staffing levels against workload in 2-3 key areas. Check for evidence of overtime, backlogs, or quality issues that may indicate understaffing.

Follow-up questions
  • How do you determine the number of people needed for each QMS process?
  • What do you do when you identify that you don't have enough qualified people for a critical process?
  • How do you handle temporary resource shortages (e.g., absences, peak demand)?
7.2 Does the organization define the competence needed for people whose work affects QMS performance, make sure they are competent (through education, training, or experience), act where there is a gap, and keep evidence of competence?
Objective evidence
  • The competence requirements per role - job descriptions or a competence matrix defining the education, training, skills, and experience needed for each role that affects QMS performance, including internal auditors.
  • For a sample of personnel in critical roles, evidence they meet those requirements - training records, qualifications, certifications (current, not expired), and on-the-job sign-offs - matched against the defined requirement, not just attendance.
  • Evidence of action where a gap exists - training provided, mentoring, or reassignment - showing competence gaps are actually closed, with a check on new hires working before their competence was verified.
  • Training-effectiveness evaluation - evidence the organization checked the training worked (assessment, observation, reduced errors), not just that it was delivered.
  • Retained documented information of competence (the records above), demonstrably maintained over time as roles and people change.
Common nonconformities
  • Major NC: Personnel performing work that affects conformity have no defined competence requirements, or are working without verified competence, with quality issues traceable to it.
  • Minor NC: Training is delivered but its effectiveness is never evaluated, so there is no evidence it achieved competence.
  • Minor NC: Competence requirements are defined but not enforced; records are missing or do not match the requirement.
  • Observation: New employees work unsupervised before their competence is verified, relying on later catch-up training.
Auditor tip

Personnel performing work affecting QMS must be competent. This ensures consistent quality and effectiveness. REQUIREMENTS BREAKDOWN (a-d): a) DETERMINE NECESSARY COMPETENCE: - Identify roles and positions affecting QMS - Define competence requirements for each role - Consider education requirements - Consider training requirements - Consider experience requirements - Specify skills and knowledge needed - Document in job descriptions or competence matrices Examples of roles requiring defined competence: - Production operators - Quality inspectors - Internal auditors - Design engineers - Customer service representatives - Maintenance technicians - Process owners b) ENSURE COMPETENCE: - Verify education credentials - Verify training completion - Verify relevant experience - Assess capability before assignment - Do not allow unqualified persons to perform critical work - Use combinations: education + training + experience c) ACQUIRE AND EVALUATE: - Training programs for skill gaps - On-the-job training - Mentoring and coaching - External courses and certifications - Job rotation and cross-training - Reassignment to better match skills - Hiring or contracting competent persons - EVALUATE EFFECTIVENESS of training/actions - Verify competence after training - Monitor performance improvements d) RETAIN DOCUMENTED INFORMATION: - Education records (degrees, diplomas) - Training records (courses, certifications) - Experience documentation (resumes, work history) - Competence assessments or evaluations - Qualification matrices - On-the-job training records - Effectiveness evaluations of training COMPETENCE ASSESSMENT METHODS: - Pre-employment verification - Skills testing - Practical demonstrations - Performance evaluations - Observation during work - Review of work outputs - Peer assessments - Customer feedback CONTINUOUS COMPETENCE: - Periodic reassessment - Refresher training - Updates for new processes/technology - Maintaining certifications - Continuous professional development

What to sample

Select 3-5 personnel in quality-critical roles. Verify their training records against the competence matrix and check for effectiveness evaluations.

Follow-up questions
  • How do you determine competence requirements for roles that affect product quality?
  • Show me how you evaluate whether training was effective — not just completed, but effective.
  • What happens when a competence gap is identified for someone already performing the work?
7.3 Are people doing work under the organization's control aware of the quality policy, the relevant objectives, how they contribute to QMS effectiveness, and what happens if requirements are not met?
Objective evidence
  • Evidence people doing work under the organization's control are aware of the quality policy and the relevant quality objectives - tested by asking, not just by training attendance.
  • Evidence they understand how they CONTRIBUTE to QMS effectiveness, including the benefits of improved performance - role-specific, not generic.
  • Evidence they are aware of the IMPLICATIONS of not conforming to QMS requirements.
  • Coverage of contractors/temporary staff in awareness, not just permanent employees.
  • Awareness verification - interviews, quizzes, or toolbox-talk records confirming awareness landed.
Common nonconformities
  • Minor NC: Personnel cannot explain how their work contributes to quality or what happens if requirements are not met - awareness is nominal.
  • Minor NC: Staff are unaware of the relevant quality objectives for their area.
  • Minor NC: Contractors/temporary staff are excluded from awareness activities.
  • Observation: Awareness is assumed from training attendance with no verification it was understood.
Auditor tip

Personnel must understand the QMS and their role in it. Awareness creates engagement and ensures everyone contributes to quality. AWARENESS REQUIREMENTS (a-d): a) QUALITY POLICY: - Personnel know the quality policy exists - Understand what it says - Understand how it applies to their work - Can explain it in their own words - See connection between policy and daily activities Communication methods: - Induction/orientation training - Posters and displays - Employee handbooks - Team meetings - Company communications - Intranet/digital displays b) RELEVANT QUALITY OBJECTIVES: - Know which objectives apply to their role - Understand the targets and timelines - Know current performance against objectives - See their department/team objectives - Understand how objectives drive improvement Communication methods: - Team meetings and briefings - Performance dashboards - Individual/team objectives - Regular updates on progress - Recognition of achievement c) CONTRIBUTION TO EFFECTIVENESS: - Understand their role in the QMS - Know how their work affects quality - Understand impact on customers - See how their work connects to results - Understand benefits of good performance - Motivated by understanding importance Key messages: - "Your work matters" - "This is how you contribute to quality" - "This is the impact of doing it well" - "This is how we all benefit from good performance" d) IMPLICATIONS OF NONCONFORMITY: - Understand consequences of not following QMS - Know potential impacts on customers - Understand safety implications - Know regulatory consequences - Understand business impact - Motivated to comply and report issues Key messages: - "What could go wrong" - "Why we have these requirements" - "Real examples of consequences" - "Importance of following procedures" SCOPE - "PERSONS DOING WORK UNDER CONTROL": - Permanent employees - Temporary workers - Contractors - Agency staff - Interns and trainees - Part-time workers - Remote workers - Anyone whose work affects QMS CREATING AWARENESS: - Orientation and induction programs - Ongoing training and communications - Team meetings and briefings - Visual management (posters, boards) - Digital communications (email, intranet) - Toolbox talks - Performance conversations - Recognition programs - Quality culture building VERIFYING AWARENESS: - Asking questions during audits/assessments - Quizzes or knowledge checks - Observation during work - Discussion in team meetings - Feedback and surveys - Demonstration of understanding

What to sample

Interview 2-3 shop floor or frontline employees. Ask them to describe the quality policy in their own words and explain how their work contributes to quality objectives.

Follow-up questions
  • How does the organization ensure that new employees understand the quality policy and their contribution to QMS effectiveness?
  • What consequences exist for non-compliance with QMS requirements, and are personnel aware of them?
7.4 Has the organization worked out the internal and external communications relevant to the QMS, including what, when, with whom, how, and who communicates?
Objective evidence
  • The defined internal and external QMS communications - a plan/matrix covering WHAT, WHEN, WITH WHOM, HOW, and WHO communicates (the 7.4 a-e elements).
  • Evidence the communications actually happen - meeting records, dashboards, newsletters, customer/supplier communications - matching the plan.
  • Evidence communication is two-way where needed (feedback channels), not purely top-down broadcast.
  • Evidence important quality information (objectives, performance, issues, changes) reaches the people who need it.
  • Clear responsibility for each communication, so nothing falls between roles.
Common nonconformities
  • Minor NC: Important quality information is not communicated to the people who need it, causing avoidable issues.
  • Minor NC: QMS communications are not defined (no what/when/who/how), so communication is ad hoc.
  • Observation: Communication is one-way with no feedback channel.
  • Observation: Responsibility for key communications is unclear, so some do not happen.
Auditor tip

Effective communication is essential for QMS success. The organization must plan and manage both internal and external communications. SCOPE OF COMMUNICATION: INTERNAL COMMUNICATIONS: - QMS performance and results - Quality objectives and progress - Quality policy and changes - Process changes and improvements - Nonconformities and corrective actions - Audit results and findings - Management review outcomes - Customer feedback - Improvement initiatives - Training and awareness information - Roles and responsibilities EXTERNAL COMMUNICATIONS: - Communication with customers - Communication with suppliers - Communication with regulators - Communication with certification bodies - Public/stakeholder communications about quality - Customer complaints and feedback - Product/service information - Quality certifications and achievements PLANNING ELEMENTS (a-e): a) WHAT TO COMMUNICATE: - Topics and content relevant to QMS - Information necessary for effectiveness - Required by standard or regulations - Important for stakeholders - Performance data and metrics - Changes and updates - Issues and resolutions b) WHEN TO COMMUNICATE: - Frequency (daily, weekly, monthly, quarterly, annually) - Timing (real-time, scheduled, as-needed) - Triggers (events, milestones, thresholds) - Regular schedules vs. ad-hoc - Urgent vs. routine communications c) WITH WHOM TO COMMUNICATE: INTERNAL: - Management team - All employees - Specific departments or teams - Process owners - Quality personnel - Individual role-holders EXTERNAL: - Customers - Suppliers and partners - Regulatory authorities - Certification bodies - External stakeholders d) HOW TO COMMUNICATE: - Meetings (team, management, all-hands) - Email and electronic communication - Intranet and portals - Reports and dashboards - Newsletters and bulletins - Posters and displays - Training sessions - Customer portals - Formal letters and documents - Phone calls and conferences - Digital platforms and tools e) WHO COMMUNICATES: - Responsibility for each communication - Management roles in communication - Quality manager - Department heads - Process owners - Customer service representatives - Authorized spokespersons EFFECTIVE COMMUNICATION CHARACTERISTICS: - Clear and understandable - Timely and relevant - Appropriate to audience - Two-way where needed - Documented when required - Verified for understanding - Accessible to intended recipients

What to sample

Review communication records for the last significant quality event (e.g., customer complaint, nonconformance). Verify the right people were informed at the right time.

Follow-up questions
  • What internal and external communications are relevant to the QMS, and who decides what to communicate?
  • How are quality-related communications tracked to ensure they reach the intended audience?
  • Can you show me an example of how a quality issue was communicated across departments?
7.4 a) Is it clear what the organization will communicate about the QMS (topics and content)?
Objective evidence
  • Communication plan listing topics
  • Meeting agendas with quality topics
  • Types of communications documented
Common nonconformities
  • No defined communication topics
  • Important topics missing
  • Ad-hoc, unplanned communications
Auditor tip

Define the topics and content of communications. INTERNAL COMMUNICATIONS - WHAT: - Quality policy and objectives - QMS performance results - Audit findings and actions - Nonconformities and corrections - Customer feedback - Process changes - Management review outcomes - Improvement initiatives - Roles and responsibilities - Training and awareness EXTERNAL COMMUNICATIONS - WHAT: - Product/service information - Customer requirements handling - Complaints and feedback - Regulatory compliance status - Quality certifications - Supplier information exchange

What to sample

Review the communication plan or procedure. Verify it covers key QMS topics (policy, objectives, performance data, changes).

Follow-up questions
  • How do you decide what quality information needs formal communication versus informal channels?
  • Is there a defined list of QMS topics that require structured communication?
7.4 b) Is the timing and frequency of QMS communications defined?
Objective evidence
  • Communication schedule
  • Meeting calendars
  • Reporting frequency documentation
Common nonconformities
  • No defined communication timing
  • Irregular or unpredictable communications
  • Delays in important communications
Auditor tip

Define the timing and frequency of communications. TIMING CONSIDERATIONS: - Regular scheduled communications - Event-triggered communications - Real-time or immediate needs - Periodic reporting cycles FREQUENCY EXAMPLES: - Daily briefings/huddles - Weekly team meetings - Monthly performance reports - Quarterly management reviews - Annual policy reviews - As-needed urgent communications TRIGGERS: - Audit completion - Nonconformity detection - Customer complaint - Process change - Achievement of objectives

What to sample

Check timing of communications for a recent nonconformance or customer complaint. Verify communication happened within defined timeframes.

Follow-up questions
  • Are there defined triggers or schedules for quality communications?
  • How quickly are urgent quality issues communicated to affected parties?
7.4 c) Is the audience for each QMS communication defined (who it goes to, internal and external)?
Objective evidence
  • Communication matrix with audiences
  • Distribution lists
  • Stakeholder communication plans
Common nonconformities
  • No audience defined
  • Wrong people receiving information
  • Key stakeholders missed
Auditor tip

Define the audience for each communication. INTERNAL AUDIENCES: - Top management - All employees - Specific departments - Process owners - Quality personnel - New employees - Specific teams EXTERNAL AUDIENCES: - Customers - Suppliers - Regulatory authorities - Certification bodies - Other stakeholders CONSIDERATIONS: - Right information to right people - Need-to-know basis - Confidentiality requirements - Accessibility needs

What to sample

For a recent quality communication, verify the distribution list was appropriate and that recipients confirmed receipt.

Follow-up questions
  • How do you ensure that quality communications reach all relevant parties, including remote or shift workers?
  • Who is responsible for communicating QMS changes to external interested parties?
7.4 d) Are the methods and channels for QMS communication defined (meetings, email, intranet, dashboards, and so on)?
Objective evidence
  • Communication methods documented
  • Multiple channels available
  • Technology platforms used
Common nonconformities
  • No defined methods
  • Single channel only
  • Methods inappropriate for content
Auditor tip

Define the methods and channels for communication. COMMUNICATION METHODS: - Meetings (team, department, all-hands) - Email - Intranet/portals - Newsletters - Posters and displays - Reports and dashboards - Training sessions - Phone calls - Video conferences - Mobile apps - Customer portals - Formal letters CONSIDERATIONS: - Appropriate for content - Accessible to audience - Two-way when needed - Documentation requirements - Urgency level

What to sample

Review how the last management review outputs were communicated. Verify the method was appropriate for the audience and content.

Follow-up questions
  • What communication methods do you use for different types of quality information (email, meetings, notice boards, etc.)?
  • How do you verify that communications were received and understood?
7.4 e) Is responsibility defined for who actually carries out each QMS communication?
Objective evidence
  • Communication responsibilities assigned
  • Role descriptions including communication
  • Authorized communicator lists
Common nonconformities
  • No responsibility assigned
  • Wrong level communicating
  • Inconsistent messages from different sources
Auditor tip

Define responsibility for each communication. COMMUNICATION RESPONSIBILITIES: - Top management communications - Quality manager communications - Department head communications - Process owner communications - Customer service communications - Authorized spokespersons CONSIDERATIONS: - Authority level appropriate - Competence to communicate - Accountability for accuracy - Consistency of message - Approval requirements EXAMPLES: - CEO: Strategic quality communications - Quality Manager: QMS performance reports - Department Heads: Team-level communications - Customer Service: Customer complaint responses

What to sample

Review the communication procedure for assigned responsibilities. Verify that designated communicators are aware of their roles.

Follow-up questions
  • Are communication responsibilities clearly assigned for different types of quality information?
  • Who is responsible for external communications about quality (e.g., to customers, regulators)?
7.5.1 Does the QMS include both the documented information ISO 9001 requires and whatever else the organization needs for the QMS to be effective?
Objective evidence
  • Evidence the QMS includes the documented information ISO 9001 specifically REQUIRES (scope, policy, objectives, and the clause-mandated records).
  • Evidence the organization has also determined the ADDITIONAL documented information it needs for QMS effectiveness, appropriate to its size and complexity.
  • An index/list of the documented information, so the system is known and managed rather than scattered.
  • A check the extent is proportionate - enough to control the QMS without bureaucratic excess or dangerous gaps.
  • Evidence the documented information is actually used, not maintained solely for the audit.
Common nonconformities
  • Minor NC: Documented information that ISO 9001 specifically requires (e.g. scope, objectives, or a mandated record) is missing.
  • Minor NC: Documentation is excessive and burdensome, or so thin key processes are uncontrolled.
  • Observation: Documentation exists but is not used in practice.
  • Observation: There is no index/list, so the documented information is unmanaged and hard to find.
Auditor tip

The QMS must include documented information as required by ISO 9001 and as needed for effectiveness. Flexibility allowed based on organization context. TWO CATEGORIES OF DOCUMENTED INFORMATION: a) REQUIRED BY ISO 9001: These are mandatory - the standard explicitly states "documented information shall be maintained" or "shall be retained": MAINTAINED (current, controlled): - Scope of QMS (4.3) - Quality policy (5.2) - Quality objectives (6.2) - Operational planning and control information (8.1) - Design and development information (8.3) - Product/service requirements (8.2) - Criteria for processes and product acceptance (8.5, 8.6) RETAINED (records, evidence): - Evidence of competence (7.2) - Monitoring and measurement results (9.1) - Internal audit program and results (9.2) - Management review results (9.3) - Nonconformity and corrective action records (10.2) - Many operational records throughout Clause 8 b) DETERMINED BY ORGANIZATION AS NECESSARY: - Procedures where needed for effectiveness - Work instructions for complex operations - Process descriptions - Forms and templates - Specifications - Additional records beyond minimum required - Supporting documentation EXTENT OF DOCUMENTATION - FLEXIBILITY: SIZE AND TYPE: - Small organizations may need less documentation - Large organizations may need more structure - Service organizations different from manufacturing - Simple processes need less documentation COMPLEXITY: - Complex processes need more detailed documentation - Interrelated processes may need process maps - Simple processes can be less documented COMPETENCE: - Highly competent personnel need fewer instructions - Less experienced workers may need detailed procedures - Turnover rate affects documentation needs KEY PRINCIPLE: Document what you need for effectiveness - not more, not less. ISO 9001:2015 does NOT require a Quality Manual (unlike 2008 version). FORMS OF DOCUMENTED INFORMATION: - Paper or electronic - Documents (procedures, instructions, specifications) - Records (evidence of results) - Any medium or format

What to sample

Check the document master list against actual documents in use. Verify at least 3 documents are at current revision and accessible at point of use.

Follow-up questions
  • How do you determine which documents and records the QMS requires beyond those explicitly mandated by ISO 9001?
  • How do you ensure documented information is kept current and accessible to those who need it?
7.5.1 a) Is the documented information that ISO 9001 specifically requires present (scope, policy, objectives, and the rest)?
Objective evidence
  • Complete set of ISO 9001 required documents
  • Records required by standard
  • Checklist of mandatory documented information
Common nonconformities
  • Missing mandatory documented information
  • Required records not retained
  • No scope or policy documented
Auditor tip

ISO 9001 mandates specific documented information. MAINTAINED (Procedures/Documents): - Scope of QMS (4.3) - Quality policy (5.2) - Quality objectives (6.2) - Operational planning information (8.1) - Product requirements (8.2) RETAINED (Records): - Competence evidence (7.2) - Monitoring results (9.1) - Audit results (9.2) - Management review results (9.3) - Nonconformity records (10.2) - Numerous operational records (Clause 8) These are minimum requirements - not optional.

What to sample

Cross-reference the organization's document register against ISO 9001 mandatory documented information requirements. Flag any gaps.

Follow-up questions
  • Can you show me your list of documented information required by ISO 9001?
  • How do you verify completeness — that nothing required by the standard is missing?
7.5.1 b) Beyond what ISO 9001 mandates, is the additional documented information the organization needs for effectiveness identified?
Objective evidence
  • Procedures beyond minimum requirements
  • Work instructions for complex operations
  • Additional forms and records
Common nonconformities
  • No additional documentation where needed
  • Excessive unnecessary documentation
  • Documentation not suited to organization
Auditor tip

Organization determines additional documentation needs. ORGANIZATION-DETERMINED DOCUMENTATION: - Procedures where needed - Work instructions - Process descriptions - Forms and templates - Specifications - Additional records - Guidelines and standards FACTORS TO CONSIDER: - Process complexity - Personnel competence - Risk level - Customer requirements - Regulatory needs - Size of organization FLEXIBILITY: - More complex = more documentation - Less experienced staff = more instructions - Higher risk = more controls documented - Don't document just for documentation's sake

What to sample

Review the rationale for 2-3 organization-specific procedures. Verify they serve a clear purpose and are maintained current.

Follow-up questions
  • Beyond ISO 9001 requirements, what additional documents has your organization determined are necessary?
  • What criteria do you use to decide whether a process needs documented information?
7.5.2 When documents are created or updated, are they properly identified and described, in a suitable format and media, and reviewed and approved for suitability and adequacy before use?
Objective evidence
  • A sample of documents - verify each carries proper identification and description (title, date, author/owner, reference/number).
  • Evidence documents are in a suitable format and media (language, software version, graphics; paper or electronic) for their use.
  • Evidence of review and approval for suitability and adequacy BEFORE issue - signatures or system approvals on the current versions.
  • A document creation/update process with version/revision history, so changes are controlled.
  • A check that unapproved or draft documents are not in active use.
Common nonconformities
  • Minor NC: Documents in use lack identification (no title, number, or date) or evidence of approval before issue.
  • Minor NC: No version control, so it cannot be confirmed a document is current.
  • Minor NC: Unapproved or draft documents are in active use.
  • Observation: Documents are in a format/media unsuited to their point of use (e.g. unreadable on the floor).
Auditor tip

Controls needed when creating or updating documents to ensure they are fit for purpose and properly managed. REQUIREMENTS (a-c): a) IDENTIFICATION AND DESCRIPTION: - Unique identifier (document number, code) - Title (clear, descriptive) - Date (creation, revision, effective date) - Author or originator - Version or revision number - Reference number or code - Purpose or scope statement Examples: - QP-001 Document Control Procedure, Rev 3, 2024-01-15 - WI-MFG-042 Assembly Work Instruction v2.1 - FORM-QA-15 Inspection Record b) FORMAT AND MEDIA: FORMAT considerations: - Language appropriate to users - Software version compatibility - Graphics, diagrams, photos as needed - Layout and structure - Readability and clarity - Accessibility (e.g., large print if needed) MEDIA considerations: - Paper documents - Electronic files (PDF, Word, etc.) - Database or system-based - Intranet or portal - Mobile-accessible - Video or multimedia - Mix of media as appropriate c) REVIEW AND APPROVAL: REVIEW for: - Technical accuracy - Completeness - Clarity and usability - Compliance with requirements - Consistency with other documents - Suitability for intended purpose APPROVAL: - By authorized person(s) - Appropriate level of authority - Documented approval (signature, electronic) - Before use or implementation UPDATING PROCESS: - Request for change - Draft revision - Review and approval (same as creation) - Version control - Effective date - Communication of changes - Withdrawal of obsolete version - Retention of superseded versions if needed

What to sample

Trace the creation history of 2 recent documents. Verify proper identification, format, review, and approval at each stage.

Follow-up questions
  • Walk me through how a new procedure is created, reviewed, approved, and distributed.
  • How do you ensure consistent identification and formatting of documented information?
  • Who has authority to approve different types of documents?
7.5.2 a) Do documents carry proper identification and description (title, date, author, reference number)?
Objective evidence
  • Document numbering system
  • Documents with proper identification
  • Version control evidence
Common nonconformities
  • Documents without identification
  • Undated documents
  • No version numbers
Auditor tip

Documents must be properly identified. IDENTIFICATION ELEMENTS: - Unique document number/code - Title (clear and descriptive) - Date (creation, revision, effective) - Author or originator - Version or revision number - Reference number EXAMPLES: - QP-001 Document Control Rev 3, 2024-01-15 - WI-MFG-042 Assembly Instructions v2.1 - FORM-QA-15 Inspection Record

What to sample

Check 5 documents for consistent identification (number, title, revision, date). Verify naming conventions are followed.

Follow-up questions
  • What is your document numbering and identification scheme?
  • How do you ensure each document can be uniquely identified and its purpose understood?
7.5.2 b) Are documents in a suitable format and media (language, software version, graphics; paper or electronic)?
Objective evidence
  • Appropriate document formats
  • Multiple media types as needed
  • Format standards documented
Common nonconformities
  • Incompatible formats
  • Poor quality documents
  • Inaccessible media
Auditor tip

Documents must be in suitable format and media. FORMAT CONSIDERATIONS: - Appropriate language - Software version compatibility - Graphics/diagrams as needed - Layout and structure - Readability - Accessibility MEDIA CONSIDERATIONS: - Paper documents - Electronic files (PDF, Word, etc.) - Database-based - Intranet/portal - Video/multimedia - Mobile-accessible

What to sample

Verify that document format standards are applied consistently. Check that electronic documents are accessible from relevant workstations.

Follow-up questions
  • What formats and media do you use for documented information (paper, electronic, or both)?
  • How do you ensure electronic documents remain readable and accessible over time?
7.5.2 c) Are documents reviewed and approved for suitability and adequacy before they are issued?
Objective evidence
  • Approval signatures/records
  • Review and approval process
  • Authorized approver list
Common nonconformities
  • No approval evidence
  • Unapproved documents in use
  • Changes without approval
Auditor tip

Documents must be reviewed and approved before use. REVIEW FOR: - Technical accuracy - Completeness - Clarity and usability - Compliance with requirements - Consistency with other documents - Suitability for intended purpose APPROVAL: - By authorized person(s) - Appropriate authority level - Documented approval - Before use/implementation

What to sample

Check 3 recently revised documents for evidence of proper review and approval by authorized personnel.

Follow-up questions
  • Who reviews and approves documents, and how is their authority defined?
  • How do you handle situations where the original approver is unavailable?
7.5.3 Is documented information controlled across its lifecycle so it is available where needed and adequately protected?
Objective evidence
  • The document-control procedure and master list of controlled documents - verify documents are reviewed/approved before issue, current revisions are identified, and the right version is available at the point of use, not a mix of paper and stale copies.
  • Obsolete-document control - evidence superseded versions are removed from use or clearly marked, so nobody works to an old revision (a frequent shop-floor finding).
  • Protection of documented information - access controls/permissions, read-only or controlled-edit on records, and backup/recovery for electronic information - so records cannot be casually altered and are not lost in a system failure.
  • Control of external-origin documents (standards, customer drawings, regulations) - a register and evidence the current versions are identified and controlled.
  • Retention and disposition - a retention schedule meeting legal/contractual needs, with controlled archival and disposal; check records stay legible and retrievable across the retention period.
Common nonconformities
  • Major NC: Obsolete documents are in active use at the point of work (old revisions on the floor), so work is performed to superseded requirements.
  • Minor NC: No version control or master list, so it cannot be confirmed which document revision is current.
  • Minor NC: Electronic records can be altered without control or audit trail, undermining their integrity as evidence.
  • Observation: External documents (standards, customer specs) are not identified or controlled, so the organization may be working to withdrawn versions.
Auditor tip

Documented information must be controlled to ensure it is available, protected, and maintained properly throughout its lifecycle. PRIMARY CONTROL OBJECTIVES (a-b): a) AVAILABLE AND SUITABLE: - Right information - Right place - Right time - Right format - Current version - Accessible to those who need it - Usable and fit for purpose b) ADEQUATELY PROTECTED: - Confidentiality (protect sensitive information) - Integrity (prevent unauthorized changes) - Proper use (prevent misuse) - Security (prevent loss or damage) - Backup and recovery CONTROL ACTIVITIES (c-f): c) DISTRIBUTION, ACCESS, RETRIEVAL, USE: - Who has access to what documents - How documents are distributed - Where documents are stored/filed - How to find and retrieve documents - Permissions and restrictions - Read-only vs. edit access - Ensuring current versions are used d) STORAGE AND PRESERVATION: - Physical storage (filing systems, archives) - Electronic storage (servers, cloud, databases) - Environmental controls (temperature, humidity) - Backup systems - Preservation of legibility over time - Protection from damage or deterioration - Organized and retrievable e) CONTROL OF CHANGES: - Version control system - Change authorization - Tracking revisions - Identifying current version - Removing obsolete versions from use - Change history - Preventing use of outdated documents f) RETENTION AND DISPOSITION: - How long to keep documents/records - Retention schedules or requirements - Legal/regulatory retention requirements - Archiving of superseded documents - Secure destruction when no longer needed - Disposition authorization EXTERNAL DOCUMENTS: - Standards, regulations, codes - Customer specifications and drawings - Supplier documents - External procedures or instructions - Must be identified and controlled - Keep current and available RECORDS (EVIDENCE OF CONFORMITY): - Must be protected from unintended alteration - Cannot be changed after creation - If electronic, protect against editing - Audit trail if changes are necessary - Ensures integrity of evidence PRACTICAL IMPLEMENTATION: - Document control procedure - Document management system (paper or electronic) - Master list of documents - Access controls and permissions - Version control system - Obsolete document controls - Backup procedures - Retention schedule

What to sample

Attempt to access 2-3 controlled documents at point of use. Verify they are current revision, legible, and properly controlled.

Follow-up questions
  • How do you control access to documented information to prevent unauthorized changes?
  • What is your process for distributing updated documents and withdrawing obsolete ones?
  • How do you manage documented information from external sources (e.g., customer specs, standards)?
7.5.3 a) Is documented information controlled so it is available and suitable for use, in the right place at the right time, current version?
Objective evidence
  • Documents accessible at workstations
  • Electronic access systems
  • Current versions available
Common nonconformities
  • Documents not accessible
  • Outdated versions in use
  • Information unavailable when needed
Auditor tip

Information must be accessible when needed. AVAILABLE MEANS: - Accessible at point of use - Right information - Right location - Right time - Current version SUITABLE MEANS: - Fit for intended purpose - Right format - Understandable - Usable by intended users

What to sample

Visit 2-3 work areas and verify that relevant procedures and work instructions are accessible. Ask operators how they access documents.

Follow-up questions
  • How do you ensure the right documents are available where and when they are needed?
  • What happens if someone cannot access a document they need to do their job?
7.5.3 b) Is documented information adequately protected (from loss of confidentiality, improper use, or loss of integrity)?
Objective evidence
  • Access controls implemented
  • Backup systems
  • Security measures documented
Common nonconformities
  • No protection measures
  • Confidential info exposed
  • Records easily altered
Auditor tip

Documents and records must be protected. PROTECTION FROM: - Loss of confidentiality (unauthorized access) - Improper use (misuse) - Loss of integrity (unauthorized changes) - Physical damage/loss - Cyber threats PROTECTION METHODS: - Access controls - Password protection - Encryption - Locked storage - Backup systems - Read-only settings

What to sample

Verify backup schedules for electronic documents. Check physical document storage conditions for protection from damage.

Follow-up questions
  • How do you protect documents from loss, damage, or unauthorized alteration?
  • What backup procedures exist for electronic documented information?
7.5.3 c) Are distribution, access, retrieval, and use of documents managed (who gets what, who can view or edit)?
Objective evidence
  • Distribution procedures
  • Access control lists
  • Document retrieval system
  • Usage guidance
Common nonconformities
  • Uncontrolled distribution
  • No access controls
  • Documents hard to find
Auditor tip

Manage how documents are shared and used. DISTRIBUTION: - Controlled distribution lists - Electronic distribution - Ensuring right people get documents - Communicating changes ACCESS: - Who can view what - Permission levels - Read vs. edit rights - Authorization controls RETRIEVAL: - Finding documents easily - Search capabilities - Filing/indexing systems - Archive access USE: - Using correct versions - Proper application - Training on documents

What to sample

Check access permissions in the document management system. Verify that role-based access is enforced and appropriate.

Follow-up questions
  • How do you control who can access, modify, and distribute different types of documents?
  • What access controls exist in your document management system?
7.5.3 d) Are storage and preservation handled so documents stay legible and retrievable over time?
Objective evidence
  • Storage systems (physical/electronic)
  • Backup procedures
  • Environmental controls
  • Legibility verification
Common nonconformities
  • Poor storage conditions
  • No backup systems
  • Deteriorating documents
  • Illegible records
Auditor tip

Documents and records must be properly stored. STORAGE: - Physical (filing, cabinets, archives) - Electronic (servers, cloud, databases) - Organized and systematic - Retrievable PRESERVATION: - Protection from damage - Environmental controls - Backup and redundancy - Migration of formats - Legibility over time

What to sample

Select 3 types of quality records. Verify retention periods are defined and records from 2+ years ago are still retrievable and legible.

Follow-up questions
  • What are your retention requirements for quality records, and how do they align with regulatory and contractual obligations?
  • How do you ensure records remain legible and retrievable throughout their retention period?
7.5.3 e) Are changes to documents controlled (version control, change history, authorization)?
Objective evidence
  • Version control system
  • Revision history records
  • Change authorization records
  • Obsolete document controls
Common nonconformities
  • No version control
  • Obsolete documents in use
  • Unauthorized changes
  • No change history
Auditor tip

Changes to documents must be controlled. VERSION CONTROL: - Tracking revisions - Identifying current version - Change history maintained - Revision numbering CHANGE CONTROL: - Authorization of changes - Review of changes - Distribution of updates - Obsolete version control

What to sample

Review revision history of 2-3 documents. Verify changes are identified, dated, and the nature of change is described.

Follow-up questions
  • How are changes to documented information identified and tracked (e.g., revision history, redlining)?
  • Can you show me a document where changes were made and how the change history is recorded?
7.5.3 f) Are retention periods and disposition defined for documents and records (meeting legal, regulatory, and contractual needs)?
Objective evidence
  • Retention schedule
  • Retention period assignments
  • Disposal procedures
  • Disposal records
Common nonconformities
  • No retention schedule
  • Premature disposal
  • Records kept indefinitely
  • Insecure disposal
Auditor tip

Define how long to keep documents and how to dispose. RETENTION: - How long to keep documents/records - Legal/regulatory requirements - Customer contract requirements - Organizational needs - Retention schedule DISPOSITION: - Secure destruction when no longer needed - Authorization for disposal - Disposal methods (shredding, deletion) - Records of disposal

What to sample

Check how obsolete documents are handled — verify they are clearly marked or removed from circulation. Look for any uncontrolled copies in work areas.

Follow-up questions
  • What is your process for disposing of obsolete documents and expired records?
  • How do you prevent obsolete documents from being used unintentionally?

Each item shows its evidence, common nonconformities and auditor tips. The clause index has the PDF of all 251 items, formatted for a clipboard.