ISO 9001:2015 clause 8: Operation

The 102 audit questions covering clause 8, each with the objective evidence to request, the nonconformities most often raised against it and what to sample. Part of the free ISO 9001:2015 gap analysis checklist, which holds 251 items across 7 clauses.

102 items in this clause 1 section 251 items in the full checklist ISO 9001:2015 · updated 2026-06-24

All 102 questions for clause 8

Open any row for its objective evidence, common nonconformities and auditor tips. You can check items off as you go. This browser remembers your progress across all 7 clauses of this checklist.

§8 Operation 102 items · ~510 min
8.1 Are the operational processes needed to deliver products and services planned, implemented, and controlled (per 4.4), with requirements, acceptance criteria, resources, and the records to prove they were carried out as planned?
Objective evidence
  • Evidence the operational processes are PLANNED - the requirements for the products/services determined, acceptance criteria set, and resources for conformity identified (8.1 a-c).
  • Evidence the processes are CONTROLLED to the criteria, with the documented information needed to run them and to demonstrate conformity (8.1 d-e).
  • Process control plans/quality plans for the key product/service lines, tying requirements to controls.
  • Evidence planned changes are controlled and the consequences of unintended changes reviewed/mitigated.
  • Evidence outsourced processes are controlled within this operational planning (link to 8.4).
Common nonconformities
  • Minor NC: Operational processes are not planned - no defined requirements, acceptance criteria, or controls, so conformity cannot be assured or demonstrated.
  • Minor NC: Acceptance criteria for processes and outputs are not established.
  • Minor NC: The documented information needed to have confidence the processes ran as planned is not retained.
  • Observation: Changes to operations are made without control, and unintended changes are not reviewed.
Auditor tip

Organizations must plan and control all operational processes to ensure consistent delivery of conforming products and services. PLANNING AND CONTROL ELEMENTS (a-e): a) DETERMINE REQUIREMENTS: - Product/service specifications - Customer requirements - Statutory and regulatory requirements - Organizational requirements - Industry standards - Performance criteria - Delivery requirements b) ESTABLISH CRITERIA: 1) PROCESS CRITERIA: - Process parameters and controls - Operating conditions - Key process indicators - Process monitoring points - Process limits and tolerances - Workflow and sequence 2) ACCEPTANCE CRITERIA: - Product/service specifications - Quality standards - Test and inspection criteria - Pass/fail limits - Visual standards - Performance requirements c) DETERMINE RESOURCES: - Personnel and competencies - Equipment and infrastructure - Materials and supplies - Technology and systems - Information and documentation - External resources (outsourcing) d) IMPLEMENT CONTROL: - Execute processes per criteria - Monitor process performance - Control process variables - Verify conformity - Take corrective action when needed - Ensure consistency and repeatability e) DOCUMENTED INFORMATION: 1) CONFIDENCE IN PLANNED EXECUTION: - Process documentation (procedures, instructions) - Process records (batch records, logs) - Evidence of control activities - Monitoring records 2) DEMONSTRATE CONFORMITY: - Inspection and test records - Verification records - Certificates of conformity - Release approvals - Traceability records SUITABILITY FOR OPERATIONS: - Planning must be practical and implementable - Appropriate to organization's context - Scalable and flexible - Integrated with business operations CONTROL OF CHANGES: - PLANNED CHANGES: * Controlled implementation (see 6.3) * Risk assessment * Verification of effectiveness * Documentation updated - UNINTENDED CHANGES: * Detected and reviewed * Consequences assessed * Adverse effects mitigated * Corrective action if needed OUTSOURCED PROCESSES: - Must be controlled (see 8.4) - Organization retains responsibility - Verification of outsourced outputs

What to sample

Review quality plans or process control plans for 2 key products/services. Verify criteria, resources, and controls are defined and followed.

Follow-up questions
  • How do you plan and control the processes needed to deliver your products and services?
  • Walk me through how you manage unintended changes to your operational processes.
  • How do you ensure outsourced processes are controlled to the same standard as internal ones?
8.1 a) As part of operational planning, are the requirements for the products and services clearly determined (customer, statutory/regulatory, and internal)?
Objective evidence
  • Product specifications
  • Customer requirements documents
  • Regulatory requirements list
Common nonconformities
  • Requirements not defined
  • Unclear specifications
  • Missing regulatory requirements
Auditor tip

Product and service requirements must be clearly defined. REQUIREMENTS TO DETERMINE: - Customer specifications - Statutory/regulatory requirements - Industry standards - Internal quality standards - Performance criteria - Safety requirements - Delivery requirements

What to sample

Select 2-3 recent orders/projects. Verify requirements were determined and documented before work started.

Follow-up questions
  • How are product and service requirements determined before production or service delivery begins?
  • How do you handle conflicting requirements from customers, regulations, and internal standards?
8.1 b) Are criteria established both for the processes themselves and for the acceptance of the products and services?
Objective evidence
  • Process specifications
  • Acceptance criteria documentation
  • Quality standards
Common nonconformities
  • No process criteria
  • No acceptance criteria
  • Vague or undefined standards
Auditor tip

Both process and acceptance criteria must be established. PROCESS CRITERIA: - Operating parameters - Control points - Process limits - Quality checkpoints - Key performance indicators ACCEPTANCE CRITERIA: - Pass/fail specifications - Quality standards - Test requirements - Visual standards - Performance thresholds

What to sample

Review process control documentation for a critical process. Verify measurable criteria exist for both the process and the output.

Follow-up questions
  • What process criteria (parameters, settings, conditions) are established for your key processes?
  • How are acceptance criteria for products and services defined, and who approves them?
8.1 c) Are the resources needed to achieve conformity to product and service requirements determined (people, equipment, materials, facilities, information)?
Objective evidence
  • Resource planning documents
  • Capacity planning
  • Equipment lists
Common nonconformities
  • Resources not determined
  • Insufficient resources
  • No resource planning
Auditor tip

Identify all resources required for conforming outputs. RESOURCES TO DETERMINE: - Personnel and competencies - Equipment and machinery - Materials and components - Facilities - Information systems - Monitoring equipment - External resources

What to sample

Review resource allocation for 2 recent production orders. Verify people, equipment, and materials were planned and available.

Follow-up questions
  • How do you determine what resources are needed for each production run or service delivery?
  • What happens when required resources are not available at the planned time?
8.1 d) Are the processes actually controlled in line with the criteria that were established, not just on paper?
Objective evidence
  • Process control records
  • Monitoring data
  • Control charts
Common nonconformities
  • Processes not controlled
  • No monitoring
  • Criteria not followed
Auditor tip

Execute and control processes per established criteria. IMPLEMENT CONTROL: - Execute processes per procedures - Monitor key parameters - Control process variables - Verify against criteria - Take corrective action when needed - Ensure consistency

What to sample

Observe a key process in operation. Verify that controls match documented criteria and operators follow procedures.

Follow-up questions
  • How do you verify that processes are being controlled according to defined criteria during execution?
  • What monitoring or in-process checks are performed?
8.1 e) Is documented information determined, maintained, and retained to the extent needed to have confidence the processes ran as planned and to demonstrate conformity?
Objective evidence
  • Process documentation
  • Production records
  • Inspection records
  • Test records
Common nonconformities
  • No documented information
  • Records incomplete
  • Cannot demonstrate conformity
Auditor tip

Document and record information for process and conformity evidence. FOR PROCESS CONFIDENCE: - Process procedures - Work instructions - Process records and logs - Monitoring records FOR CONFORMITY DEMONSTRATION: - Inspection records - Test results - Verification evidence - Release records - Traceability records

What to sample

Review batch records or service delivery records for 2-3 recent jobs. Verify they provide confidence that processes were executed as planned.

Follow-up questions
  • What records do you maintain to demonstrate that processes were carried out as planned?
  • How do you determine the extent of documentation needed for each process?
8.2.1 Does customer communication cover the things it should: product and service information, enquiries and orders (including changes), customer feedback and complaints, handling of customer property, and contingency arrangements where relevant?
Objective evidence
  • Evidence customer communication covers product/service information, enquiries/contracts/orders (including changes), and obtaining customer feedback including complaints (the core 8.2.1 elements).
  • Evidence it covers handling/controlling customer property where applicable.
  • Evidence it establishes specific requirements for contingency actions where relevant (e.g. recall, business continuity).
  • Communication/CRM records and complaint-handling records showing the processes actually run.
  • A check that customer enquiries and orders are acknowledged and changes are captured, not lost.
Common nonconformities
  • Minor NC: There is no defined process for handling customer complaints or feedback, so the voice of the customer is not captured.
  • Minor NC: Customer enquiries/orders are not acknowledged or order changes are not captured, causing disputes.
  • Minor NC: Handling of customer property is not addressed in customer communication where it applies.
  • Observation: Contingency-action requirements are not established with customers where the product/service warrants it.
Auditor tip

Effective communication with customers must cover all key interactions throughout the product/service lifecycle. COMMUNICATION ELEMENTS (a-e): a) PROVIDING INFORMATION: - Product/service features and specifications - Pricing and terms - Availability and delivery times - Technical information - User manuals and instructions - Safety information - Warranty information - Marketing materials b) HANDLING ENQUIRIES, CONTRACTS, ORDERS: - Respond to customer inquiries - Quote preparation and submission - Order acknowledgment and confirmation - Contract negotiation and finalization - Order processing - Changes to contracts or orders - Communication of status and updates c) CUSTOMER FEEDBACK AND COMPLAINTS: - Mechanisms to receive feedback - Customer satisfaction surveys - Complaint handling process - Complaint acknowledgment and response - Feedback analysis and use - Follow-up with customers - Closure and verification of satisfaction d) CUSTOMER PROPERTY: - Receipt and identification - Protection and safeguarding - Use as intended - Maintenance and storage - Return or disposal - Reporting damage or loss Examples: - Materials provided for processing - Customer-owned tooling - Confidential information/IP - Personal data (GDPR compliance) - Equipment loaned by customer e) CONTINGENCY ACTIONS: - Emergency contact procedures - Service interruption plans - Product recall procedures - Business continuity communication - Crisis communication - Customer notification requirements

What to sample

Review customer communication logs for 3 recent interactions. Verify all five communication elements (a-e) are addressed.

Follow-up questions
  • Walk me through your process for communicating with customers from inquiry through delivery.
  • How do you handle customer complaints and ensure they are resolved satisfactorily?
  • What contingency communication plans exist for service disruptions?
8.2.1 a Does customer communication include providing clear, accurate information about the products and services?
Objective evidence
  • Product catalogs and brochures
  • Technical data sheets
  • User manuals and instructions
  • Website product information
  • Safety data sheets (if applicable)
  • Warranty documentation
  • Terms and conditions
Common nonconformities
  • No product information available to customers
  • Inaccurate or misleading product information
  • Missing technical specifications
  • No safety information provided when needed
Auditor tip

Organizations must provide clear, accurate information to customers about their products and services including: - Product/service features and specifications - Pricing and terms - Availability and delivery times - Technical information and user manuals - Safety information and warnings - Warranty information - Marketing materials (must be accurate)

What to sample

Review product literature, website content, or catalogs. Verify information matches current specifications.

Follow-up questions
  • How do you provide product/service information to prospective and existing customers?
  • How do you ensure product information is accurate and current?
8.2.1 b Does customer communication cover handling of enquiries, contracts, and orders, including changes to them?
Objective evidence
  • Inquiry response records
  • Quotation records
  • Order acknowledgments
  • Contract review records
  • Order change documentation
  • CRM system records
Common nonconformities
  • Customer inquiries not responded to
  • Orders accepted without acknowledgment
  • No process for order changes
  • Contract/order changes not communicated
Auditor tip

Organizations must have processes to handle: - Customer inquiries and quote requests - Order acknowledgment and confirmation - Contract negotiation and finalization - Order processing and status updates - Changes to contracts or orders - Communication of delivery status

What to sample

Trace 2-3 recent orders from inquiry through acknowledgment. Verify changes were documented and communicated.

Follow-up questions
  • How do you process customer inquiries, quotes, orders, and order changes?
  • What is your turnaround time for responding to customer inquiries?
8.2.1 c Does customer communication include obtaining customer feedback, including complaints?
Objective evidence
  • Customer feedback mechanisms
  • Complaint handling procedure and records
  • Customer satisfaction survey process
  • Feedback analysis reports
  • Complaint resolution records
Common nonconformities
  • No complaint handling process
  • Customer feedback not sought or used
  • Complaints not documented or tracked
  • No analysis of customer feedback
Auditor tip

Organizations must have mechanisms to receive and process: - Customer feedback (positive and negative) - Customer satisfaction surveys - Customer complaints - Product/service reviews - Suggestions for improvement - Follow-up and closure verification

What to sample

Review customer satisfaction survey results and complaint logs from the past 6 months. Verify feedback is analyzed and acted upon.

Follow-up questions
  • What methods do you use to obtain customer feedback beyond complaint handling?
  • How is customer feedback data analyzed and used for improvement?
8.2.1 d Does customer communication address the handling and control of customer property?
Objective evidence
  • Customer property handling procedure
  • Customer property registers and tracking
  • Communication records about customer property
  • Damage or loss notification records
Common nonconformities
  • Customer property not controlled or protected
  • Loss or damage to customer property unreported
  • No identification of customer property
  • Customer property mixed with organization's property
Auditor tip

Organizations must communicate with customers regarding their property: - Receipt and identification of customer property - Protection and safeguarding - Use as intended - Maintenance and storage - Return or disposal - Reporting damage or loss Customer property can include: - Materials provided for processing - Customer-owned tooling - Confidential information/IP - Personal data (GDPR compliance) - Equipment loaned by customer

What to sample

If applicable, inspect customer property storage/handling. Verify identification, protection, and tracking records.

Follow-up questions
  • What types of customer property do you handle, and how is each type protected?
  • Can you show me your process for reporting loss or damage of customer property?
8.2.1 e Where relevant, does customer communication cover specific requirements for contingency actions (for example emergency, recall, or business-continuity arrangements)?
Objective evidence
  • Contingency plans and procedures
  • Emergency customer notification procedures
  • Business continuity communication plans
  • Recall procedures with customer notification
Common nonconformities
  • No contingency communication plans
  • Customers not notified of disruptions
  • No emergency contact procedures
  • Service interruptions without customer communication
Auditor tip

When relevant, organizations must communicate with customers about: - Emergency contact procedures - Service interruption plans - Product recall procedures - Business continuity communication - Crisis communication - Customer notification requirements - Alternative supply arrangements

What to sample

Review business continuity or contingency plans. Verify customer communication is addressed for disruption scenarios.

Follow-up questions
  • What contingency actions have you established for situations that could affect customers?
  • How are customers notified when contingency plans are activated?
8.2.2 Before committing to supply, does the organization make sure the product and service requirements (including statutory/regulatory) are defined and that it can actually meet its claims?
Objective evidence
  • The defined product/service requirements - specifications, terms, and the list of applicable statutory and regulatory requirements - showing requirements are determined BEFORE the organization offers the product/service, not after problems arise.
  • Evidence statutory/regulatory requirements specific to the product are identified (safety, labeling, environmental, import/export, data protection) - not just a generic 'we comply with applicable laws' statement.
  • Evidence the organization can MEET the claims it makes - capability/capacity analysis or feasibility checks behind marketing and catalog claims.
  • Accuracy of public claims - marketing materials, catalogs, and SLAs checked against what the organization can actually deliver, so claims are not overstated.
  • For changed or new offerings, evidence requirements were re-determined rather than assumed from a previous product.
Common nonconformities
  • Minor NC: Applicable statutory/regulatory requirements for the product/service are not identified, so the organization cannot demonstrate it determined them.
  • Minor NC: Marketing or catalog claims are made that the organization cannot substantiate or consistently meet.
  • Minor NC: Requirements are not defined before the product/service is offered, so commitments are made without knowing what must be met.
  • Observation: Capability to meet a new offering's requirements is assumed rather than verified, risking commitments beyond capacity.
Auditor tip

All requirements must be identified before committing to provide products/services. REQUIREMENT DETERMINATION (a-b): a) REQUIREMENTS DEFINED: 1) STATUTORY AND REGULATORY: - Laws and regulations applicable to product/service - Safety requirements - Environmental regulations - Industry-specific regulations - Import/export requirements - Labeling requirements - Data protection laws 2) ORGANIZATIONAL REQUIREMENTS: - Internal quality standards - Design standards - Packaging requirements - Delivery requirements - Documentation requirements - Additional customer service standards Also consider (from 8.2.3): - Customer-specified requirements - Delivery and post-delivery requirements - Requirements not stated but necessary b) ABILITY TO MEET CLAIMS: - Can organization actually deliver? - Capacity and capability verification - Resource availability - Technical feasibility - Timeline achievability - Don't promise what cannot be delivered - Marketing claims must be achievable PRACTICAL APPLICATION: - Standard products: Requirements defined in specifications - Custom orders: Determine requirements for each order - Internet sales: Requirements in product information - Catalog sales: Requirements in catalog specifications - Services: Service specifications and SLAs DOCUMENTATION: - Product/service specifications - Applicable standards and regulations - Terms and conditions - Marketing materials (must be accurate) - Catalogs and brochures

What to sample

Review requirement specifications for 3 recent orders. Verify statutory, regulatory, and organizational requirements are included beyond customer-stated needs.

Follow-up questions
  • How do you ensure all requirements for products and services are fully defined before committing to deliver?
  • What happens when customer requirements conflict with statutory/regulatory requirements?
8.2.2 a Are the requirements for the products and services defined, including any applicable statutory and regulatory requirements and those the organization considers necessary?
Objective evidence
  • Product/service specifications
  • List of applicable statutory and regulatory requirements
  • Regulatory compliance documentation
  • Design specifications
  • Internal quality standards
Common nonconformities
  • Requirements not defined before offering products/services
  • Regulatory requirements not identified
  • Product specifications incomplete
  • Organizational standards not documented
Auditor tip

All requirements for products/services must be defined before offering to customers: 1) STATUTORY AND REGULATORY REQUIREMENTS: - Laws and regulations applicable to product/service - Safety requirements - Environmental regulations - Industry-specific regulations - Import/export requirements - Labeling requirements - Data protection laws 2) ORGANIZATIONAL REQUIREMENTS: - Internal quality standards - Design standards - Packaging requirements - Delivery requirements - Documentation requirements - Additional customer service standards

What to sample

Review contract review records for evidence that unstated but necessary requirements were identified (e.g., packaging, labeling, safety).

Follow-up questions
  • How do you capture requirements that the customer has not explicitly stated but that are necessary for intended use?
  • Who is responsible for identifying implied requirements?
8.2.2 b Has the organization satisfied itself it can meet the claims it makes for the products and services it offers (capacity, capability, feasibility)?
Objective evidence
  • Feasibility assessments
  • Capability and capacity analysis
  • Marketing materials (verified accurate)
  • Resource planning documentation
  • Technical capability assessments
Common nonconformities
  • Marketing claims that cannot be met
  • Accepting orders beyond capability
  • No verification of ability to deliver
  • Commitments made without checking feasibility
Auditor tip

Organizations must verify they can deliver what they promise: - Capacity and capability verification - Resource availability assessment - Technical feasibility analysis - Timeline achievability - Marketing claims must be achievable - Don't promise what cannot be delivered

What to sample

Check the regulatory requirements register. Verify it is current and matches applicable regulations for sampled products/services.

Follow-up questions
  • What statutory and regulatory requirements apply to your products/services, and how do you stay current?
  • How do you identify requirements that you set for yourself beyond customer and legal requirements?
8.2.3 Before committing to supply, does the organization review the requirements (customer-stated, implied, its own, statutory/regulatory, and any order changes) and confirm it can meet them, resolving any differences first?
Objective evidence
  • The contract/order-review procedure and a sample of review records - verify a review actually happens BEFORE the organization commits to an order, covering customer-stated requirements, implied/intended-use requirements, the organization's own requirements, and applicable statutory/regulatory requirements.
  • Evidence the organization confirmed it can MEET the requirements before accepting - capacity, capability, lead-time, and any special-process checks - not just logged the order.
  • Resolution of differences - records showing where an order differed from the quotation or prior understanding, the difference was identified and resolved with the customer before proceeding.
  • Confirmation of requirements where the customer gives no documented statement (e.g. verbal/phone orders) - evidence the requirements were confirmed back before acceptance.
  • For catalog/web sales where a per-order review is impractical, the product information made available to customers in lieu of an individual review.
Common nonconformities
  • Major NC: Orders are accepted and worked without any review of requirements or feasibility, leading to commitments the organization cannot meet.
  • Minor NC: Differences between the quotation and the final order are not identified or resolved, so the organization and customer proceed on different understandings.
  • Minor NC: Statutory/regulatory requirements are not considered in the review - only customer-stated ones.
  • Observation: Verbal orders are accepted without confirming the requirements back to the customer in a retrievable form.
Auditor tip

Contract/order review ensures all requirements are understood and can be met before committing to customers. REVIEW BEFORE COMMITMENT: - Must occur before accepting order/contract - Verify ability to meet requirements - Resolve any ambiguities or conflicts - Documented decision to proceed or not REQUIREMENTS TO REVIEW (a-e): a) CUSTOMER-SPECIFIED: - Product/service specifications stated by customer - Delivery requirements (dates, locations, methods) - Post-delivery activities (installation, training, support, warranty) - Packaging and labeling - Documentation requirements b) UNSTATED BUT NECESSARY: - Requirements implied by intended use - Industry norms and expectations - Safety requirements - Performance expectations - Compatibility requirements - "Fitness for purpose" requirements c) ORGANIZATIONAL REQUIREMENTS: - Internal standards or policies - Quality standards - Additional service elements - Documentation standards d) STATUTORY AND REGULATORY: - Applicable laws and regulations - Safety standards - Environmental requirements - Industry-specific regulations e) DIFFERENCES FROM PREVIOUS: - Changes from quotation to order - Modifications to standing orders - Contract amendments - Changes from previous similar orders - Must be identified and resolved CONFIRMATION OF REQUIREMENTS: - If customer provides written order: Review it - If verbal or informal: Confirm requirements in writing - Ensure mutual understanding - Customer acknowledgment if possible DOCUMENTED INFORMATION: - Results of review (approval, conditions, notes) - Any new or changed requirements - Resolution of differences - Evidence of ability to meet requirements PRACTICAL APPROACHES: - Complex/custom orders: Formal contract review meeting - Standard products: Streamlined review against capabilities - Repeat orders: Review changes from previous order - Internet sales: Review is product information vs. order - Catalog sales: Review built into order processing

What to sample

Review contract review records for 3 recent orders of varying complexity. Verify all applicable checks were performed and documented.

Follow-up questions
  • Walk me through your contract review process — what checks are performed before accepting an order?
  • How do you resolve differences between quoted and ordered requirements?
  • What records do you retain from the review process?
8.2.3 a Does the pre-commitment review cover the requirements the customer specified, including delivery and post-delivery activities?
Objective evidence
  • Customer purchase orders reviewed
  • Delivery requirements documented
  • Post-delivery activity agreements
  • Customer specification review records
Common nonconformities
  • Customer requirements not documented
  • Delivery requirements unclear or missing
  • Post-delivery obligations not understood
Auditor tip

Review must include all customer-stated requirements: - Product/service specifications stated by customer - Delivery requirements (dates, locations, methods) - Post-delivery activities (installation, training, support, warranty) - Packaging and labeling requirements - Documentation requirements - Service level expectations

What to sample

Check 2-3 orders for evidence of capacity/capability review before acceptance, including delivery timeline feasibility.

Follow-up questions
  • How do you verify your ability to meet delivery and post-delivery requirements before accepting an order?
  • Have you ever had to decline an order because you couldn't meet the requirements?
8.2.3 b Does the pre-commitment review also catch the requirements the customer did not state but that the intended use makes necessary (the implied, fitness-for-purpose expectations)?
Objective evidence
  • Review records showing unstated requirements identified
  • Intended use analysis
  • Industry standard requirements identified
  • Safety requirements documentation
Common nonconformities
  • Implicit requirements not considered
  • Fitness for purpose not evaluated
  • Industry norms ignored
Auditor tip

Review must consider implied requirements: - Requirements implied by intended use - Industry norms and expectations - Safety requirements not explicitly stated - Performance expectations - Compatibility requirements - "Fitness for purpose" requirements - Common sense expectations for the product type

What to sample

Review 2-3 orders where customer requirements were clarified. Verify the clarification was documented and confirmed.

Follow-up questions
  • How do you ensure requirements specified by the customer are clearly understood and documented?
  • What happens when customer requirements are ambiguous or incomplete?
8.2.3 c Does the pre-commitment review cover the organization's own requirements for the products and services?
Objective evidence
  • Internal quality standards applied
  • Organizational requirements documented in review
  • Standard terms and conditions
  • Quality specifications used
Common nonconformities
  • Internal standards not applied to orders
  • Organizational requirements inconsistent
  • No documentation of organizational requirements
Auditor tip

Review must include organization's own requirements: - Internal standards or policies - Quality standards and specifications - Additional service elements offered - Documentation standards - Packaging and handling standards - Requirements beyond what customer requests

What to sample

Look for orders where requirements changed between quote and order stage. Verify differences were identified and resolved.

Follow-up questions
  • When requirements differ from those previously expressed (e.g., quote vs. order), how are differences resolved?
  • Can you show me an example where a discrepancy was identified and resolved?
8.2.3 d Does the pre-commitment review cover the applicable statutory and regulatory requirements?
Objective evidence
  • Regulatory requirements checklist
  • Compliance verification records
  • Applicable standards identified
  • Regulatory certification status
Common nonconformities
  • Regulatory requirements not considered
  • Non-compliant products accepted
  • Legal requirements unknown
Auditor tip

Review must verify all applicable legal requirements: - Applicable laws and regulations - Safety standards - Environmental requirements - Industry-specific regulations - Import/export regulations - Labeling requirements - Product certifications required

What to sample

Verify that contract review records for 2-3 orders include confirmation that statutory and regulatory requirements were addressed.

Follow-up questions
  • What applicable statutory and regulatory requirements are verified during contract review?
  • How do you ensure regulatory requirements are checked for every order, not just new products?
8.2.3 e Does the pre-commitment review identify and resolve any differences between the order or contract and what was previously expressed (for example quotation versus order)?
Objective evidence
  • Quotation vs. order comparison
  • Resolution of differences documented
  • Change documentation
  • Customer confirmation of resolution
Common nonconformities
  • Differences between quote and order not identified
  • Unresolved requirements differences
  • Changes not communicated internally
Auditor tip

Review must identify and resolve any differences: - Changes from quotation to order - Modifications to standing orders - Contract amendments - Changes from previous similar orders - Differences must be identified and RESOLVED before proceeding

What to sample

If applicable, review a case where a new or modified product/service was requested. Verify how requirements were established.

Follow-up questions
  • How are requirements for products/services not previously defined handled during review?
  • What process exists for establishing new product/service specifications?
8.2.4 When product or service requirements change, is the relevant documented information amended and are the affected people made aware of the changed requirements?
Objective evidence
  • Evidence that when product/service requirements change, the relevant documented information is AMENDED - updated specs, work orders, or job tickets reflecting the change.
  • Evidence the affected PEOPLE are made aware of the changed requirements (acknowledgments, communications, re-briefing).
  • A change-control mechanism (ECOs, change notices) tying the requirement change to the documents and people it affects.
  • A check that production/service is not still running to the old requirements after a change.
  • Approval of the change before it takes effect.
Common nonconformities
  • Minor NC: Documentation is not amended when requirements change, so production runs to outdated specifications.
  • Minor NC: Affected personnel are not informed of changed requirements, causing nonconformities.
  • Observation: There is no controlled mechanism linking a requirement change to the documents and people it affects.
  • Observation: Customer complaints trace to changes that were agreed but never implemented.
Auditor tip

When requirements change, documentation must be updated and affected personnel must be informed to prevent errors and nonconformities. CHANGE MANAGEMENT: TYPICAL CHANGES: - Customer-requested changes during order execution - Engineering changes during production - Specification revisions - Delivery date changes - Quantity changes - Contract amendments - Regulatory requirement updates AMEND DOCUMENTED INFORMATION: - Update specifications - Revise work orders or job packets - Update production plans - Revise drawings or designs - Update quality plans - Modify procedures if needed - Update contracts or orders MAKE RELEVANT PERSONS AWARE: - Notify all affected personnel - Production/operations teams - Quality inspection - Design/engineering - Purchasing - Logistics/shipping - Customer service - Communication methods: meetings, emails, work order notes, etc. ENSURING EFFECTIVENESS: - Change approval process - Documented change notices - Acknowledgment by affected persons - Verification that changes are implemented - Prevent use of obsolete information INTEGRATION: - Link to document control (7.5.3) - Link to change planning (6.3) - Link to contract review updates (8.2.3)

What to sample

Review 2-3 order amendments or change orders. Verify documented information was amended and relevant persons were made aware.

Follow-up questions
  • How do you handle changes to customer requirements after an order has been accepted?
  • How do you ensure all affected parties are notified of requirement changes?
8.3.1 If the organization designs products or services, does it have a design and development process appropriate to ensuring conforming provision? (If design is excluded, is that exclusion justified?)
Objective evidence
  • The QMS scope (4.3) - confirm whether design is included or excluded; if excluded, verify the justification is real (the organization builds only to customer or established designs) and not a way to dodge design controls it actually performs.
  • The design-and-development procedure or process description - verify it is appropriate to the organization's products/services (a software house and a machine shop need different rigor) and covers planning through to release (8.3.2-8.3.6).
  • Design plans for actual projects - confirm the process is used in practice, with stages, reviews, and responsibilities defined per project, not just a procedure on the shelf.
  • Design project records across the full lifecycle - inputs, outputs, reviews, verification, validation, and changes - showing the defined process was followed end to end on real work.
  • Evidence design controls scale with risk and complexity - a simple modification and a novel product show appropriately different levels of control.
Common nonconformities
  • Major NC: The organization performs design (configuring, developing, or adapting products/services) but has excluded design from its QMS scope, so design is uncontrolled.
  • Minor NC: Design activities happen but there is no defined design process, so each project is handled ad hoc with inconsistent rigor.
  • Minor NC: A design procedure exists but is not appropriate to the products/services - either far heavier than needed, or too light for the risk involved.
  • Observation: The design process is documented but project records show it is not actually followed (missing reviews, no verification/validation evidence).
Auditor tip

Organizations performing design must have a systematic design and development process appropriate to their products/services. APPLICABILITY: - Required if organization designs products or services - Can be excluded if only producing to customer designs - Applies to products, services, processes, or systems - Must be declared in QMS scope (4.3) DESIGN PROCESS REQUIREMENTS: - Establish: Define the process - Implement: Put it into practice - Maintain: Keep it current and effective APPROPRIATENESS: - Suitable for type of design activities - Scalable to complexity - Adequate controls and rigor - Industry-appropriate methods SCOPE OF DESIGN: - New product/service design - Product/service modifications - Process design - System design - Service design (transport, hospitality, professional services, etc.) DESIGN STAGES COVERED IN 8.3: - Planning (8.3.2) - Inputs (8.3.3) - Controls (8.3.4) - Outputs (8.3.5) - Changes (8.3.6)

What to sample

Review the design and development procedure. Select 1-2 recent design projects and trace through the full process.

Follow-up questions
  • Describe your design and development process from concept through release.
  • How do you ensure the design process is appropriate for the complexity and risk of the product/service?
  • If design and development is excluded, what is the justification?
8.3.2 Is design and development planned with the right factors in view: the nature, duration, and complexity of the work; the stages and reviews; verification and validation; responsibilities; and the resources and documented information needed?
Objective evidence
  • The design plans for actual projects - verify planning accounts for the nature, duration, and complexity of the design work, and the required process stages and reviews.
  • Evidence planning defines the required verification and validation activities and the responsibilities and authorities involved.
  • Evidence planning addresses internal/external resource needs and the control of interfaces between the people involved (handoffs).
  • Consideration of the customer/user involvement and the level of control interested parties expect over the design.
  • Identification of the documented information needed to demonstrate design requirements were met.
Common nonconformities
  • Minor NC: Design projects are not planned, so stages, reviews, responsibilities, and resources are handled ad hoc.
  • Minor NC: Interfaces between the people/functions involved in design are not controlled, so handoffs fail.
  • Observation: Verification and validation activities are not planned up front, leading to gaps late in the project.
  • Observation: Resource needs for the design are not planned, causing schedule or quality pressure.
Auditor tip

Design must be planned considering all factors affecting success and control.

What to sample

Review design plans for 2 recent projects. Verify all elements (a-j) are addressed proportionate to complexity.

Follow-up questions
  • How do you plan design and development activities for a new product or service?
  • What factors determine the stages, reviews, and controls needed for a design project?
8.3.2.a Does design planning account for the nature, duration, and complexity of the design work?
Objective evidence
  • Design project plan addressing complexity
  • Risk assessment for design complexity
  • Resource allocation based on project nature
  • Timeline appropriate to complexity
Common nonconformities
  • One-size-fits-all design process
  • No consideration of project complexity
  • Unrealistic timelines for complex designs
Auditor tip

Design planning must account for the inherent characteristics of the design project: - NATURE: Type of product/service (new vs modification, simple vs complex) - DURATION: Timeline and milestones - COMPLEXITY: Technical difficulty, number of interfaces, regulatory burden

What to sample

Compare design plans for a simple vs. complex project. Verify the level of planning is proportionate to risk.

Follow-up questions
  • How do you define the nature, duration, and complexity of design activities?
  • How does complexity assessment influence the level of control applied?
8.3.2.b Does design planning account for the required process stages, including the applicable design reviews?
Objective evidence
  • Design process flow with defined stages
  • Stage-gate criteria
  • Design review schedule
  • Phase completion checklists
Common nonconformities
  • No defined design stages
  • Skipping design reviews
  • Unclear stage transitions
Auditor tip

Design must proceed through defined stages with review gates: - Stage-gate approach (concept, preliminary, detailed, etc.) - Design reviews at appropriate milestones - Clear entry/exit criteria for each stage

What to sample

Review a design project timeline. Verify required reviews and verifications were planned and scheduled.

Follow-up questions
  • What design stages are defined, and what gates or reviews occur between stages?
  • How do you decide what reviews are needed at each stage?
8.3.2.c Does design planning account for the required verification and validation activities?
Objective evidence
  • Verification and validation plan
  • Test protocols planned at design start
  • V&V resource allocation
  • Acceptance criteria defined early
Common nonconformities
  • V&V not planned upfront
  • Verification or validation omitted
  • Inadequate V&V resources
Auditor tip

Planning must include verification and validation activities: - VERIFICATION: Confirm design meets input requirements (built it right) - VALIDATION: Confirm product meets user needs (built the right thing) - Both must be planned at the start

What to sample

Check design V&V plans and records for 1-2 projects. Verify both verification and validation were planned and conducted.

Follow-up questions
  • What verification and validation activities are required for your designs?
  • How do you distinguish between verification (meets spec) and validation (meets use)?
8.3.2.d Does design planning account for the responsibilities and authorities involved in the design work?
Objective evidence
  • Design team organization chart
  • RACI matrix for design activities
  • Approval authority matrix
  • Design responsibility assignments
Common nonconformities
  • Unclear design responsibilities
  • No designated design authority
  • Approval confusion
Auditor tip

Clear assignment of who does what: - Design team roles and responsibilities - Decision-making authority - Approval authorities - Review participants

What to sample

Review project organization charts or responsibility matrices for 1-2 design projects.

Follow-up questions
  • What are the defined responsibilities and authorities within the design team?
  • How do you handle design decisions when team members disagree?
8.3.2.e Does design planning account for the internal and external resources the design work needs?
Objective evidence
  • Design resource plan
  • Budget allocation for design
  • External resource contracts
  • Capacity planning for design team
Common nonconformities
  • Under-resourced design projects
  • No external resource planning
  • Budget constraints impacting quality
Auditor tip

Ensure adequate resources: - Internal: Staff, equipment, facilities, tools - External: Consultants, contractors, testing services - Budget and schedule considerations

What to sample

Review resource allocations for a recent design project. Verify needed expertise was identified and provided.

Follow-up questions
  • What internal and external resources are typically needed for design projects?
  • How do you manage external design partners or consultants?
8.3.2.f Does design planning account for the need to control interfaces between the people involved in the design work (handoffs between team members and functions)?
Objective evidence
  • Interface management plan
  • Communication protocols
  • Handoff checklists
  • Cross-functional meeting records
Common nonconformities
  • Poor communication between design groups
  • No interface management
  • Design handoff problems
Auditor tip

Manage communication and handoffs: - Between design team members - Between design and other functions (manufacturing, quality, etc.) - Between internal and external parties - Clear interface protocols

What to sample

For a design involving multiple teams, review how interfaces were managed (e.g., design review meetings, shared documents).

Follow-up questions
  • How do you manage interfaces between different design team members or departments?
  • What communication mechanisms ensure design information flows correctly between parties?
8.3.2.g Does design planning account for the involvement of customers and users in the design work (input, review, validation)?
Objective evidence
  • Customer involvement plan
  • Voice of customer inputs
  • Customer design review participation
  • User testing records
Common nonconformities
  • No customer input to design
  • Design isolated from end users
  • Customer feedback ignored
Auditor tip

Consider customer/user participation: - Input on requirements - Review of design concepts - User testing and feedback - Validation participation - Beta testing or pilot programs

What to sample

Review evidence of customer/user involvement in 1-2 design projects (e.g., requirements workshops, prototype reviews, user testing).

Follow-up questions
  • How do you involve customers and users in the design process?
  • At what stages do you seek customer input or feedback on designs?
8.3.2.h Does design planning account for what the subsequent provision of the products and services will require (manufacturability, serviceability)?
Objective evidence
  • Design for manufacturing reviews
  • Serviceability requirements in design
  • Production input to design
  • DFM/DFA analysis
Common nonconformities
  • Design without production input
  • Manufacturing issues from poor design
  • Service problems due to design
Auditor tip

Design for manufacturability/serviceability: - Production/operations requirements - Service and maintenance considerations - Supply chain constraints - End-of-life considerations

What to sample

Check design reviews for consideration of manufacturability, serviceability, and post-delivery requirements.

Follow-up questions
  • What requirements apply to subsequent production and service provision that must be considered during design?
  • How do you ensure designs are producible and serviceable?
8.3.2.i Does design planning account for the level of control customers and other interested parties expect over the design work?
Objective evidence
  • Customer design control requirements
  • Regulatory submission plan
  • Customer approval points defined
  • Third-party review schedule
Common nonconformities
  • Customer control requirements not addressed
  • Regulatory oversight missed
  • Insufficient customer communication
Auditor tip

Customer oversight requirements: - Customer approval gates - Progress reporting requirements - Regulatory oversight - Third-party reviews or certifications

What to sample

Review contracts for customer-specified design control requirements. Verify these are reflected in design plans.

Follow-up questions
  • What level of control is expected by customers and relevant interested parties over the design process?
  • How do you accommodate customer design review requirements?
8.3.2.j Does design planning account for the documented information needed to show the design and development requirements have been met?
Objective evidence
  • Design documentation plan
  • Design history file template
  • Document requirements matrix
  • Records to be maintained list
Common nonconformities
  • No documentation planning
  • Incomplete design records
  • Documentation created after the fact
Auditor tip

Plan documentation requirements: - Design history file contents - Records to be created - Evidence of compliance - Traceability documentation

What to sample

Review the design history file for a recently completed project. Verify it contains evidence that all requirements were met.

Follow-up questions
  • What documented information do you retain to demonstrate design requirements have been met?
  • How do you ensure the design file is complete before release?
8.3.3 Are the design and development inputs (the requirements the design must meet) determined and complete, drawing on function, performance, statutory/regulatory needs, and lessons from similar designs, with conflicts resolved?
Objective evidence
  • The documented design inputs for actual projects - verify they capture functional and performance requirements, applicable statutory/regulatory requirements, relevant standards/codes, and the consequences of failure appropriate to the product.
  • Evidence inputs draw on information from previous similar designs - lessons learned, failure history, reusable elements - so the organization is not repeating past mistakes.
  • Review/approval of the inputs before design proceeds - confirming they are complete, unambiguous, and agreed, not a moving target.
  • Resolution of conflicting inputs - records showing where requirements clashed (e.g. cost vs performance, two standards) the conflict was identified and resolved before design work continued.
  • Traceability from inputs forward into outputs and verification, so each input can be shown to have been addressed.
Common nonconformities
  • Major NC: Applicable statutory/regulatory requirements are not captured as design inputs, so a compliance gap is designed in from the start.
  • Minor NC: Design inputs are incomplete or ambiguous, leaving key requirements to be interpreted during design.
  • Minor NC: Conflicting inputs are not identified or resolved before design proceeds.
  • Observation: Inputs do not draw on lessons from previous similar designs, so known failure modes recur.
Auditor tip

Design inputs are requirements that form the basis for design. Must be clear, complete, and without conflicts.

What to sample

Review design input documents for 2 projects. Verify all five categories (a-e) are addressed and inputs are adequate.

Follow-up questions
  • How do you ensure all necessary design inputs are identified and documented before design work begins?
  • How do you resolve conflicting or ambiguous design inputs?
8.3.3.a Among the design inputs, are the functional and performance requirements determined?
Objective evidence
  • Functional requirements specification
  • Performance requirements document
  • Technical specifications
  • Customer technical requirements
Common nonconformities
  • Vague functional requirements
  • No measurable performance criteria
  • Missing critical functions
Auditor tip

Define what the product/service must DO and how well: - Functions it must perform - Performance specifications (speed, accuracy, capacity, etc.) - Operating parameters - Environmental conditions

What to sample

Trace customer requirements through to design input specifications. Verify nothing was lost in translation.

Follow-up questions
  • How do you translate customer needs into functional and performance requirements?
  • How do you validate that design inputs accurately capture what the customer needs?
8.3.3.b Do the design inputs draw on information from previous similar designs?
Objective evidence
  • Lessons learned from previous designs
  • Reference to similar product designs
  • Historical problem analysis
  • Design reuse documentation
Common nonconformities
  • Repeating past design mistakes
  • Not leveraging previous experience
  • No lessons learned review
Auditor tip

Leverage lessons learned: - Previous similar designs - Historical data and problems - Best practices from past projects - Reusable design elements

What to sample

Verify design inputs include applicable regulations (e.g., safety standards, environmental requirements). Cross-check against regulatory register.

Follow-up questions
  • What statutory and regulatory requirements apply to your product designs?
  • How do you stay current with changing regulations that affect design?
8.3.3.c Among the design inputs, are the applicable statutory and regulatory requirements determined?
Objective evidence
  • Regulatory requirements checklist
  • Applicable standards list
  • Compliance matrix
  • Regulatory affairs input
Common nonconformities
  • Regulatory requirements missed
  • Non-compliance discovered late
  • No regulatory input to design
Auditor tip

Identify all legal and regulatory requirements: - Safety regulations - Environmental regulations - Industry-specific requirements - Import/export requirements - Labeling and marking requirements

What to sample

Check design inputs for reference to applicable standards. Verify the correct versions are cited.

Follow-up questions
  • How do you leverage standards and codes of practice as design inputs?
  • Which industry standards are routinely applied to your designs?
8.3.3.d Do the design inputs include the standards or codes of practice the organization has committed to apply?
Objective evidence
  • Applicable standards list
  • Customer-specified standards
  • Industry code compliance
  • Certification requirements
Common nonconformities
  • Committed standards not in design inputs
  • Standard compliance gaps
  • Certification requirements missed
Auditor tip

Include voluntary commitments: - Industry standards adopted - Customer-specified standards - Quality standards - Professional codes of practice - Certifications sought

What to sample

Look for evidence that lessons learned, warranty data, or field failure information were considered as design inputs.

Follow-up questions
  • How do you capture lessons learned from previous similar designs?
  • What mechanisms exist to feed failure data from existing products back into new designs?
8.3.3.e Do the design inputs consider the potential consequences of failure given the nature of the products and services?
Objective evidence
  • Failure modes and effects analysis (FMEA)
  • Risk assessment for design
  • Safety-critical requirements identification
  • Design for reliability
Common nonconformities
  • No failure consequence analysis
  • Safety-critical functions not identified
  • Inadequate safety margins
Auditor tip

Risk-based design input: - Safety consequences of failure - Financial consequences - Reputational consequences - Environmental consequences - Appropriate safety factors and redundancy

What to sample

Review risk assessments or FMEAs associated with design projects. Verify consequences of failure were considered in design inputs.

Follow-up questions
  • What are the potential consequences of failure for this design, and how are they addressed?
  • Do you perform risk assessments (e.g., FMEA) as part of design input?
8.3.4 Are design controls applied so that results are defined, reviews held, and verification and validation carried out, with any necessary actions identified, before the design is released?
Objective evidence
  • Design-review records at the planned stages - verify reviews evaluate the design's ability to meet requirements, include the right cross-functional participants, and capture actions, not just a sign-off.
  • Design-verification records - evidence the outputs were checked against the inputs ('did we build it right?') by analysis, test, or comparison, with traceability from each input to its verification.
  • Design-validation records - evidence the resulting product/service meets the intended use ('did we build the right thing?'), validated under actual or simulated use conditions before full release.
  • Records of actions taken on problems found during review, verification, or validation - showing issues were resolved and re-checked, not noted and ignored.
  • The retained documented information of all these activities, demonstrating control over the design before it was released.
Common nonconformities
  • Major NC: A product/service was released without design validation, so there is no evidence it meets the intended use - a common source of field failures.
  • Minor NC: Verification and validation are conflated or one is missing; the organization checks the design against inputs but never confirms fitness for intended use (or vice versa).
  • Minor NC: Design reviews are sign-offs with no evidence of genuine evaluation, cross-functional input, or resulting actions.
  • Observation: Problems identified during review/verification/validation are recorded but their resolution and re-check are not evidenced.
Auditor tip

Design must be reviewed, verified, and validated to ensure it meets requirements and is fit for purpose. - REVIEW: Systematic examination at stages - VERIFICATION: Does design meet inputs? (built it right) - VALIDATION: Does it meet user needs? (built the right thing)

What to sample

Review design review, verification, and validation records for 1-2 projects. Verify each type of control was conducted at appropriate stages.

Follow-up questions
  • What controls are applied during the design process to ensure outputs meet inputs?
  • How are design reviews, verification, and validation distinguished and conducted?
8.3.4.a Among the design controls, are the results to be achieved clearly defined?
Objective evidence
  • Design objectives documentation
  • Success criteria definition
  • Deliverables list
  • Target specifications
Common nonconformities
  • Undefined design goals
  • No success criteria
  • Unclear deliverables
Auditor tip

Clear definition of expected outcomes: - Design objectives - Success criteria - Deliverables defined - Measurable outcomes

What to sample

Check that expected results were defined before V&V activities were conducted. Verify criteria were established in advance.

Follow-up questions
  • What results are defined as required outcomes for design reviews, verification, and validation?
  • How do you determine pass/fail criteria for design verification tests?
8.3.4.b Among the design controls, are reviews held to evaluate whether the results meet requirements?
Objective evidence
  • Design review meeting records
  • Review checklists
  • Action items from reviews
  • Participants and signatures
Common nonconformities
  • No formal design reviews
  • Reviews without action follow-up
  • Key stakeholders missing from reviews
Auditor tip

Systematic design reviews: - Scheduled review meetings - Cross-functional participation - Assessment against requirements - Action items and follow-up

What to sample

Review attendance records for 2-3 design reviews. Verify appropriate functions were represented (e.g., quality, manufacturing, customer).

Follow-up questions
  • Who participates in design reviews, and how are participants selected?
  • How do you ensure review participants have the right expertise?
8.3.4.c Among the design controls, is verification carried out to confirm the outputs meet the inputs?
Objective evidence
  • Design verification reports
  • Test reports showing input compliance
  • Requirements traceability matrix
  • Verification test protocols and results
Common nonconformities
  • No design verification
  • Verification gaps
  • Input requirements not traced to verification
Auditor tip

Verify design against inputs (did we build it right?): - Comparison of outputs to inputs - Analysis, testing, demonstration - Traceability of verification activities - Documentation of verification results

What to sample

Review verification records showing that outputs were checked against each input requirement. Look for traceability matrices.

Follow-up questions
  • How do you verify that design outputs meet design input requirements?
  • What verification methods do you use (analysis, testing, comparison to proven designs)?
8.3.4.d Among the design controls, is validation carried out to confirm the result meets the intended use?
Objective evidence
  • Design validation reports
  • User acceptance testing results
  • Field trial results
  • Validation protocol and results
Common nonconformities
  • No design validation
  • Validation not representative of use
  • User testing not performed
Auditor tip

Validate for intended use (did we build the right thing?): - Testing under actual or simulated use conditions - User acceptance testing - Field trials or beta testing - Confirmation of fitness for purpose

What to sample

Review validation records (e.g., user acceptance testing, field trials, customer approval). Verify validation conditions represent intended use.

Follow-up questions
  • How do you validate that the final design meets the needs of the intended use?
  • Under what conditions is validation performed (e.g., simulated vs. actual use)?
8.3.4.e Among the design controls, are any necessary actions taken on problems found during reviews, verification, or validation?
Objective evidence
  • Design problem resolution records
  • Action items tracking and closure
  • Corrective actions for design issues
  • Re-verification/re-validation records
Common nonconformities
  • Design problems not addressed
  • Actions not tracked to closure
  • Repeated design issues
Auditor tip

Address problems found: - Action items from reviews - Corrective actions for test failures - Root cause analysis for significant issues - Verification that actions were effective

What to sample

Review action items from 2-3 design reviews. Verify all were addressed and closed before proceeding to the next stage.

Follow-up questions
  • How are actions from design reviews tracked to closure?
  • Can you show me an example of a problem identified during design review and how it was resolved?
8.3.4.f Among the design controls, is documented information of these activities retained?
Objective evidence
  • Design history file
  • Design review records
  • V&V documentation
  • Complete design record retention
Common nonconformities
  • Missing design records
  • Incomplete documentation
  • Records not retained properly
Auditor tip

Maintain design records: - Review records - Verification records - Validation records - Problem resolution records - Design history file

What to sample

Verify design review minutes, V&V records, and action logs are retained per the retention policy.

Follow-up questions
  • What documented information is retained from design controls?
  • How long are design records retained?
8.3.5 Do the design and development outputs meet the input requirements, suit the downstream processes, reference acceptance criteria, and specify the characteristics essential for safe and proper use?
Objective evidence
  • The design outputs for actual projects - specifications, drawings, BOMs, process specs - verify each output requirement traces back to a design input (no input left unaddressed, no unexplained output).
  • Evidence outputs are adequate for the downstream processes - enough detail for production/service provision to be carried out without re-interpreting the design.
  • Acceptance criteria in or referenced by the outputs - so production and inspection know what 'good' looks like.
  • Specification of the characteristics essential for the product's intended purpose and its safe and proper provision (critical-to-quality or safety characteristics flagged).
  • Approval of outputs before release to production/service, confirming they were checked against inputs.
Common nonconformities
  • Major NC: Design outputs do not specify the characteristics essential for safe and proper use, so safety-critical features are not controlled downstream.
  • Minor NC: Outputs do not reference acceptance criteria, leaving production and inspection without a pass/fail basis.
  • Minor NC: Outputs cannot be traced back to inputs, so it cannot be confirmed all input requirements were met.
  • Observation: Outputs lack the detail the downstream processes need, forcing production to interpret the design.
Auditor tip

Design outputs are the results of design (specifications, drawings, procedures) that enable production/provision and define acceptance criteria.

What to sample

Review design output packages for 1-2 products. Verify they contain all elements needed for production (drawings, specs, test methods, acceptance criteria).

Follow-up questions
  • How do you ensure design outputs are in a form suitable for subsequent production and service operations?
  • What approval process applies before design outputs are released?
8.3.5.a Do the design outputs meet the input requirements (traceable, with no input left unaddressed)?
Objective evidence
  • Requirements traceability matrix
  • Design verification showing input compliance
  • Design review confirming requirements met
  • Design output specification vs. input comparison
Common nonconformities
  • Outputs don't address all inputs
  • No traceability
  • Unverified requirements
Auditor tip

Outputs must satisfy inputs: - Traceability from outputs to inputs - All input requirements addressed - Verification that outputs meet inputs - No unmet requirements

What to sample

Check a design traceability matrix or equivalent. Verify each input requirement maps to a specific output element.

Follow-up questions
  • How do you demonstrate that design outputs meet design input requirements?
  • Is there a traceability matrix linking inputs to outputs?
8.3.5.b Are the design outputs adequate for the downstream processes that provide the products and services?
Objective evidence
  • Manufacturing readiness review
  • Process specifications
  • Bill of materials
  • Production documentation package
Common nonconformities
  • Design outputs insufficient for production
  • Manufacturing issues due to incomplete design
  • Missing specifications
Auditor tip

Outputs enable production/service provision: - Sufficient detail for manufacturing/operations - Process specifications included - Tooling and equipment requirements defined - Material specifications complete

What to sample

Show design outputs to a production team member. Verify they contain sufficient information for production without ambiguity.

Follow-up questions
  • How do design outputs specify what is needed for production and service provision?
  • Are production and inspection personnel able to work from the design outputs as provided?
8.3.5.c Do the design outputs include or reference monitoring and measuring requirements and acceptance criteria?
Objective evidence
  • Inspection and test plan
  • Acceptance criteria specifications
  • Quality control plan
  • Measurement requirements
Common nonconformities
  • No acceptance criteria defined
  • Unclear inspection requirements
  • Missing measurement specifications
Auditor tip

Define how to verify the product/service: - Inspection and test requirements - Acceptance criteria (pass/fail) - Measurement requirements - Quality control points

What to sample

Review inspection and test plans derived from design outputs. Verify acceptance criteria are clear and measurable.

Follow-up questions
  • How do design outputs reference or include monitoring and measuring requirements?
  • Where are acceptance criteria specified in the design output package?
8.3.5.d Do the design outputs specify the product and service characteristics essential for their intended purpose and safe and proper provision?
Objective evidence
  • Critical characteristics list
  • Safety-critical feature identification
  • Key product characteristics
  • Special requirements documentation
Common nonconformities
  • Critical characteristics not identified
  • Safety features not specified
  • Essential features unclear
Auditor tip

Critical characteristics identified: - Safety-critical features - Key performance characteristics - Features essential for function - Special handling or storage requirements

What to sample

Review critical-to-quality or critical-to-safety characteristics identified in design outputs. Verify they flow into production controls.

Follow-up questions
  • How do design outputs specify characteristics essential for safe and proper use?
  • What characteristics are identified as critical or safety-related?
8.3.6 Are design and development changes identified, reviewed, and controlled to avoid adverse impact on conformity, with the changes and resulting actions recorded?
Objective evidence
  • Design-change records (ECOs/change notices) - verify changes are identified, reviewed, and controlled, with the change and its authorization recorded.
  • Impact assessment for design changes - evidence the effect on conformity and on already-delivered product was considered before the change.
  • Verification/validation of the change as needed, so the change itself does not introduce a new defect.
  • Updated design documentation reflecting the change, controlled per 7.5.
  • Records of the actions arising from the change.
Common nonconformities
  • Major NC: Design changes are made without review or control, risking conformity and affecting product already in production or the field.
  • Minor NC: No impact assessment before a design change, so downstream consequences are not caught.
  • Minor NC: Design changes are not recorded or authorized.
  • Observation: Changes are not verified/validated, so the change introduces new issues.
Auditor tip

Design changes must be controlled to prevent unintended consequences and ensure continued conformity to requirements.

What to sample

Review 3-5 recent design change records. Verify impact assessment, review, approval, and communication to affected parties.

Follow-up questions
  • How are design changes identified, reviewed, and controlled?
  • Who has authority to approve design changes, and what reviews are required?
  • How do you assess the impact of a design change on already-delivered products?
8.4.1 Does the organization make sure externally provided processes, products, and services conform to requirements, with the type and extent of control based on their impact?
Objective evidence
  • The purchasing/supplier-control procedure and approved-supplier list - verify suppliers of products, services, and outsourced processes that affect conformity are selected against defined criteria, not just whoever is cheapest or incumbent.
  • Initial evaluation/approval records for a sample of suppliers - showing each was assessed for capability before use (audit, certification, sample approval, history).
  • Ongoing performance monitoring - scorecards or metrics (quality, on-time delivery, responsiveness) showing suppliers are tracked over time, with re-evaluation at defined intervals.
  • Action records where a supplier underperformed - corrective-action requests to the supplier, escalation, or removal from the approved list - showing monitoring has teeth.
  • Evidence outsourced processes are controlled as part of the QMS (not treated as someone else's problem), with the organization retaining responsibility for conformity.
Common nonconformities
  • Major NC: Suppliers of critical products/services or outsourced processes are used with no evaluation or controls, and quality problems are traceable to them.
  • Minor NC: An approved-supplier list exists but suppliers are never re-evaluated, so approval is a one-time event regardless of subsequent performance.
  • Minor NC: Supplier performance is not monitored, so recurring supplier issues go unaddressed.
  • Observation: Outsourced processes are excluded from QMS control on the assumption the supplier's own system is sufficient, with no verification.
Auditor tip

Organization must control suppliers and outsourced processes to ensure they meet requirements. This is critical as external providers affect quality. SCOPE OF EXTERNAL PROVISION (a-c): a) PRODUCTS/SERVICES FOR INCORPORATION: - Raw materials - Components and parts - Sub-assemblies - Services incorporated into product Examples: Steel for manufacturing, software components, packaging b) DIRECT TO CUSTOMER ON BEHALF OF ORGANIZATION: - Distribution services - Installation services - Customer support outsourced - Products drop-shipped Examples: Third-party logistics, contracted installation teams c) OUTSOURCED PROCESSES: - Processes organization chooses to outsource - Organization retains responsibility Examples: Heat treatment, calibration, testing, manufacturing steps SUPPLIER MANAGEMENT ACTIVITIES: 1. EVALUATION: - Initial assessment before selection - Capability assessment - Quality system evaluation - Risk assessment 2. SELECTION: - Criteria-based selection - Approval process - Qualified/approved supplier list 3. MONITORING PERFORMANCE: - Ongoing performance tracking - Quality metrics (defect rates, on-time delivery) - Scorecards or ratings - Inspection/verification of supplies 4. RE-EVALUATION: - Periodic reassessment - Based on performance - Continued approval or corrective action CRITERIA FOR EVALUATION: - Quality capability - Technical capability - Delivery performance - Cost competitiveness - Quality system (e.g., ISO 9001 certified) - Financial stability - Capacity - References and track record DOCUMENTED INFORMATION: - Evaluation and selection criteria - Supplier evaluations and assessments - Approved supplier list - Performance monitoring records - Re-evaluation records - Actions taken on poor performance

What to sample

Review the approved supplier list and evaluation records for 3-5 suppliers. Verify initial evaluation and ongoing monitoring.

Follow-up questions
  • How do you evaluate, select, and monitor external providers?
  • What criteria distinguish an approved supplier from a non-approved one?
  • How often do you re-evaluate supplier performance?
8.4.1 a Are controls determined for external products and services that get incorporated into the organization's own output (raw materials, components, sub-assemblies)?
Objective evidence
  • Approved supplier list for incorporated items
  • Incoming inspection procedures
  • Component specifications
  • Supplier quality data
Common nonconformities
  • Incorporated materials not from approved suppliers
  • No incoming verification of critical components
  • Supplier quality not monitored
Auditor tip

Controls needed when external products/services become part of your output: - Raw materials - Components and parts - Sub-assemblies - Services incorporated into product - Software components Examples: - Steel for manufacturing - Electronic components - Packaging materials - Subcontracted assembly work

What to sample

Review controls for 1-2 outsourced processes. Verify they are defined, implemented, and monitored.

Follow-up questions
  • How do you control externally provided processes that are performed under your control (e.g., on-site contractors)?
  • What oversight do you maintain over outsourced processes?
8.4.1 b Are controls determined for external products and services provided directly to the organization's customers on its behalf (for example drop-ship, installation, outsourced support)?
Objective evidence
  • Service level agreements with providers
  • Customer feedback on provider performance
  • Provider performance monitoring
  • Quality requirements for direct-to-customer services
Common nonconformities
  • No oversight of direct-to-customer providers
  • Customer complaints about external providers unaddressed
  • Provider performance not monitored
Auditor tip

Controls needed when suppliers deliver/provide directly to your customers: - Distribution services - Installation services - Customer support outsourced - Products drop-shipped - Maintenance services Examples: - Third-party logistics - Contracted installation teams - Outsourced customer service - Field service providers Organization remains responsible for customer experience!

What to sample

Review incoming inspection records for 3-5 recent deliveries. Verify acceptance criteria and inspection results are recorded.

Follow-up questions
  • How do you ensure purchased products and services meet your requirements before use?
  • What incoming inspection or verification is performed?
8.4.1 c Are controls determined where the organization outsources a process (or part of one), recognizing it still owns responsibility for the result?
Objective evidence
  • Outsourced process agreements
  • Process specifications provided to outsource provider
  • Verification of outsourced process outputs
  • Outsource provider audits or assessments
Common nonconformities
  • Outsourced processes not controlled
  • No specifications provided to outsource provider
  • Outputs not verified
  • Organization unaware of outsourced process quality
Auditor tip

Controls needed for outsourced processes: - Processes organization chooses to outsource - Organization retains responsibility - Must be controlled as if done internally Examples: - Heat treatment - Calibration services - Testing and inspection services - Manufacturing steps outsourced - Design services - IT services

What to sample

If applicable, review how customer-directed suppliers are managed. Verify quality controls are maintained.

Follow-up questions
  • When a customer specifies a particular external provider, how do you ensure quality requirements are still met?
  • What controls apply to customer-directed suppliers?
8.4.2 Is the type and extent of control over external providers proportionate to the impact of what they provide and to the provider's own capability (higher risk, tighter control)?
Objective evidence
  • Evidence the level of control is risk-based - a documented basis (supplier risk tiering, criticality of the item) showing critical/high-impact supplies get tighter control than low-risk commodities.
  • For critical external provision, the specific controls defined - on the PROVIDER (audits, certification, quality agreements) AND on the OUTPUT (incoming inspection, source inspection, certificates of conformity, first-article).
  • Incoming-verification records for critical items - showing the defined verification is actually performed, not waived under schedule pressure.
  • Consideration of the provider's own capability and controls when setting the level of verification - e.g. reduced inspection justified by a proven, certified supplier.
  • Evidence the controls are reviewed when a supplier's performance or the item's risk changes.
Common nonconformities
  • Major NC: A critical externally provided item with direct product or safety impact receives no verification, relying entirely on the supplier.
  • Minor NC: All suppliers are controlled identically regardless of risk, so effort is wasted on trivial supplies and critical ones are under-controlled.
  • Minor NC: Controls on the provider are defined (e.g. must be certified) but no controls on the resulting output (no incoming check), or the reverse.
  • Observation: The basis for the chosen level of control is not documented, so verification intensity appears arbitrary.
Auditor tip

The level of control must be proportionate to the risk and impact on quality. Higher risk suppliers need tighter controls. RISK-BASED APPROACH: a) OUTSOURCED PROCESSES WITHIN QMS CONTROL: - Organization retains ultimate responsibility - Process must be monitored and controlled - Cannot abdicate quality responsibility b) DEFINE CONTROLS: - Controls on external provider (audits, assessments, certification) - Controls on outputs (inspection, testing, verification) c) CONSIDERATIONS FOR CONTROL LEVEL: 1) IMPACT ASSESSMENT: - Critical vs. non-critical supplies - Direct customer impact - Safety implications - Regulatory requirements - Complexity and risk 2) EFFECTIVENESS OF SUPPLIER CONTROLS: - Does supplier have QMS (e.g., ISO 9001)? - Supplier's quality history - Capability and maturity d) VERIFICATION ACTIVITIES: - Incoming inspection - Testing and analysis - Source inspection at supplier - Certificate of conformity review - Audits of supplier - Sample testing EXAMPLES OF CONTROL LEVELS: HIGH CONTROL (Critical items): - Supplier audits - Source inspection - 100% incoming inspection - Certificates of analysis required - Frequent performance reviews MEDIUM CONTROL (Important items): - Sample incoming inspection - Performance monitoring - Annual supplier review - Quality agreements LOW CONTROL (Low risk items): - Approved supplier required - Complaint-based monitoring - Periodic re-evaluation

What to sample

Compare controls applied to critical vs. non-critical suppliers. Verify the level of control is risk-based.

Follow-up questions
  • What type and extent of controls do you apply to external providers?
  • How do you determine the appropriate level of control for different types of suppliers?
8.4.2 a Does the organization make sure outsourced processes stay within the control of its QMS, rather than treating outsourcing as handing off responsibility?
Objective evidence
  • Outsourced processes included in QMS
  • Process controls defined for outsourced work
  • Monitoring of outsourced process performance
  • Integration of outsourced work in process maps
Common nonconformities
  • Outsourced processes excluded from QMS
  • No accountability for outsourced work quality
  • Outsourced processes uncontrolled
Auditor tip

Outsourced processes must be controlled as part of the QMS: - Organization retains ultimate responsibility - Process must be monitored and controlled - Cannot abdicate quality responsibility - Outsourcing does not remove accountability - Include outsourced processes in QMS scope

What to sample

Review supplier quality agreements or contracts for 2-3 key suppliers. Verify QMS requirements are defined.

Follow-up questions
  • How do you ensure externally provided processes remain under the control of your QMS?
  • What contractual requirements ensure supplier processes meet your standards?
8.4.2 b Are the controls defined both for the external provider and for the resulting output (for example supplier assessment plus incoming verification)?
Objective evidence
  • Supplier control requirements documented
  • Incoming inspection procedures
  • Supplier audit program
  • Quality agreements
  • Verification plans
Common nonconformities
  • No controls defined for suppliers
  • No verification of supplier outputs
  • Controls not documented
Auditor tip

Two types of controls must be defined: CONTROLS ON EXTERNAL PROVIDER: - Supplier audits or assessments - Quality system certification requirements - Quality agreements - Periodic reviews - Supplier development activities CONTROLS ON RESULTING OUTPUT: - Incoming inspection - Testing and analysis - Certificate of conformity/analysis review - Sample verification - First article inspection

What to sample

Review purchase orders and supplier agreements for clarity of requirements and controls specified.

Follow-up questions
  • How do you define and communicate the controls you apply to external providers and those applied to outputs?
  • How do suppliers know what you expect from them?
8.4.2 c In deciding controls, does the organization weigh the potential impact of the external provision on its ability to consistently meet requirements, and the effectiveness of the provider's own controls?
Objective evidence
  • Risk assessment of suppliers/supplies
  • Supplier criticality classification
  • Supplier certification status
  • Quality history with supplier
  • Impact analysis documentation
Common nonconformities
  • All suppliers treated same regardless of risk
  • No consideration of impact
  • Supplier capability not assessed
  • Critical items not identified
Auditor tip

Risk-based approach to determining control level: 1) POTENTIAL IMPACT: - Critical vs. non-critical supplies - Direct customer impact - Safety implications - Regulatory requirements - Complexity and risk - Higher impact = more control needed 2) EFFECTIVENESS OF SUPPLIER CONTROLS: - Does supplier have QMS (e.g., ISO 9001)? - Supplier's quality history and track record - Supplier capability and maturity - Effective supplier = less verification needed

What to sample

Review supplier risk assessments. Verify that higher-risk suppliers receive more stringent controls.

Follow-up questions
  • How do you consider the potential impact of externally provided items on your ability to meet customer and regulatory requirements?
  • How does supplier risk feed into your control decisions?
8.4.2 d Are the verification (or other) activities needed to ensure externally provided processes, products, and services meet requirements determined (for example incoming inspection, source inspection, certificate review)?
Objective evidence
  • Incoming inspection procedures
  • Verification plans by item/supplier
  • Test procedures for incoming items
  • Source inspection records
  • Sample inspection plans
Common nonconformities
  • No verification of externally provided items
  • Critical items not inspected
  • Verification activities undefined
  • Non-conforming items not detected
Auditor tip

Define how externally provided items will be verified: VERIFICATION ACTIVITIES: - Incoming inspection - Testing and analysis - Source inspection at supplier - Certificate of conformity/analysis review - Audits of supplier - Sample testing - First article inspection Level of verification should match risk: - Critical items: More rigorous verification - Low-risk items: Reduced verification acceptable

What to sample

Review supplier performance data (delivery, quality, nonconformances). Verify corrective actions are taken for underperformance.

Follow-up questions
  • How do you determine the effectiveness of controls applied to external providers?
  • What metrics or KPIs do you track for supplier performance?
8.4.3 Does the organization make sure requirements are adequate before they go to the external provider, and communicate them clearly?
Objective evidence
  • A sample of purchase orders/agreements - verify they communicate the requirements clearly and completely: the product/service/process to be provided, with specifications, drawings, revisions, and quantities.
  • Communication of approval requirements (product/service approval, methods, processes, equipment) and of personnel competence/qualification where relevant.
  • Evidence requirements were confirmed ADEQUATE before being sent to the provider (reviewed for completeness), not issued with gaps the supplier must guess at.
  • Communication of how the organization (or its customer) will verify or validate at the provider's premises, and of the provider's required interactions (reporting, change notification, escalation).
  • Communication of how the provider's performance will be controlled and monitored (metrics, audit rights, scorecards).
Common nonconformities
  • Minor NC: Purchase orders lack specifications, revisions, or quality requirements, so the supplier is left to interpret what is needed.
  • Minor NC: Verbal orders are placed without documented requirements, creating disputes over what was agreed.
  • Minor NC: Approval or competence requirements (e.g. for special processes or qualified personnel) are not communicated to the provider.
  • Observation: Requirements are sent to suppliers without first confirming they are adequate and complete.
Auditor tip

Clear communication of requirements to suppliers is essential. Purchase orders and contracts must contain all necessary information. ADEQUACY OF REQUIREMENTS: - Requirements must be clear and complete before ordering - Review requirements before communicating to supplier INFORMATION TO COMMUNICATE (a-f): a) PRODUCT/SERVICE/PROCESS REQUIREMENTS: - Specifications and drawings - Standards and codes to be met - Quality requirements - Packaging and labeling - Delivery requirements b) APPROVAL REQUIREMENTS: 1) Product/service approval (samples, first article inspection) 2) Methods/processes/equipment approval (process validation, equipment qualification) 3) Release approval (certificate of conformity, sign-off) c) COMPETENCE AND QUALIFICATION: - Certification requirements (e.g., welders, auditors) - Training requirements - Experience requirements - Personnel qualifications needed d) INTERACTIONS WITH ORGANIZATION: - Communication protocols - Contact points - Reporting requirements - Problem notification - Change management process e) CONTROL AND MONITORING: - Performance metrics required - Reporting frequency - Quality data to be provided - Right to audit f) VERIFICATION/VALIDATION ACTIVITIES: - Incoming inspection by organization - Source inspection at supplier - Third-party testing - Customer verification rights - Witness/hold points COMMUNICATION METHODS: - Purchase orders - Contracts - Quality agreements - Specifications and drawings - Supplier portals - Technical data packages

What to sample

Review 3-5 recent purchase orders. Verify they specify product requirements, approval methods, and competence requirements as applicable.

Follow-up questions
  • What information do you communicate to external providers regarding your requirements?
  • How do you ensure purchase orders contain complete and accurate requirements?
8.4.3 a Are the organization's requirements for the processes, products, and services to be provided communicated to the external provider?
Objective evidence
  • Purchase orders with specifications
  • Drawings and technical documents provided
  • Quality requirements in orders
  • Delivery schedules communicated
Common nonconformities
  • Purchase orders lack specifications
  • Requirements not communicated
  • Supplier unclear on requirements
Auditor tip

Communicate what is required from the supplier: - Specifications and drawings - Standards and codes to be met - Quality requirements - Packaging and labeling requirements - Delivery requirements and schedules - Quantities required

What to sample

Check purchase orders for clear product/service descriptions including specifications, drawings, and standards referenced.

Follow-up questions
  • How do you communicate the processes, products, and services to be provided?
  • How do you ensure suppliers understand what is being ordered?
8.4.3 b Are the organization's requirements for approval of products and services, methods, processes, and equipment communicated to the external provider?
Objective evidence
  • First article inspection requirements
  • Sample approval procedures
  • Process approval requirements in contracts
  • Release documentation requirements
Common nonconformities
  • No approval requirements specified
  • Supplier releases without approval
  • Process changes not approved
Auditor tip

Communicate approval requirements to suppliers: 1) PRODUCT/SERVICE APPROVAL: - Sample approval requirements - First article inspection - Prototype approval 2) METHODS/PROCESSES/EQUIPMENT APPROVAL: - Process validation requirements - Equipment qualification - Method approval procedures 3) RELEASE APPROVAL: - Certificate of conformity requirements - Release authorization procedures - Sign-off requirements

What to sample

Review purchase orders for approval requirements. Verify first-article or qualification requirements are specified where appropriate.

Follow-up questions
  • What approval requirements do you specify for supplier products, methods, or equipment?
  • Are first-article inspections or process approvals required?
8.4.3 c Are competence requirements, including any required qualification of persons, communicated to the external provider?
Objective evidence
  • Personnel qualification requirements in contracts
  • Certification requirements specified
  • Training requirements communicated
  • Supplier personnel records reviewed
Common nonconformities
  • Competence requirements not specified
  • Unqualified personnel doing critical work
  • Required certifications not verified
Auditor tip

Communicate personnel competence requirements: - Certification requirements (e.g., welders, auditors) - Training requirements - Experience requirements - Professional qualifications needed - Specific skills required

What to sample

Check contracts for competence requirements (e.g., certified welders, trained inspectors). Verify compliance evidence.

Follow-up questions
  • What competence requirements do you specify for supplier personnel?
  • Do you require suppliers to use qualified personnel for critical operations?
8.4.3 d Are the organization's expectations for how the external provider interacts with it communicated (contacts, reporting, escalation, change notification)?
Objective evidence
  • Communication protocols defined
  • Contact information provided
  • Escalation procedures in place
  • Problem reporting requirements
Common nonconformities
  • No communication protocols established
  • Supplier doesn't know who to contact
  • Problems not reported timely
Auditor tip

Communicate how supplier should interact with organization: - Communication protocols and contacts - Contact points and escalation paths - Reporting requirements - Problem notification procedures - Change management process - Meeting and review schedules

What to sample

Review supplier agreements for audit rights, access provisions, and communication requirements.

Follow-up questions
  • How do you communicate your supplier interaction and control requirements?
  • What access do your personnel have to supplier facilities for monitoring?
8.4.3 e Are the organization's requirements for controlling and monitoring the external provider's performance communicated (metrics, reporting, audit rights)?
Objective evidence
  • Performance monitoring requirements in contracts
  • Metrics and KPIs defined
  • Right to audit clauses
  • Reporting requirements communicated
Common nonconformities
  • Supplier unaware of performance monitoring
  • No metrics or KPIs defined
  • Right to audit not established
Auditor tip

Communicate how supplier performance will be monitored: - Performance metrics to be tracked - Reporting frequency and format - Quality data to be provided - Right to audit - Scorecard or rating systems used - Consequences of poor performance

What to sample

If applicable, review source inspection records. Verify planned verification activities were conducted at supplier premises.

Follow-up questions
  • What verification or validation activities do you perform at the supplier's premises?
  • How do you decide whether source inspection is needed?
8.4.3 f Are the verification or validation activities the organization (or its customer) intends to perform at the provider's premises communicated to the external provider?
Objective evidence
  • Source inspection requirements communicated
  • Customer verification rights in contracts
  • Witness point requirements
  • Audit scheduling arrangements
Common nonconformities
  • Verification activities not communicated
  • Supplier not expecting inspections
  • Access denied at supplier premises
Auditor tip

Communicate verification activities at supplier: - Incoming inspection that will be performed - Source inspection at supplier premises - Third-party testing requirements - Customer verification rights - Witness/hold points - Right to conduct audits on-site

What to sample

Review receiving inspection procedures and records for 3-5 recent deliveries. Verify appropriate checks were performed.

Follow-up questions
  • What verification activities do you perform on receipt of externally provided products/services?
  • How do you handle materials received without certificates of conformity?
8.5.1 Is production and service provision carried out under controlled conditions, with documented information, suitable equipment, monitoring, competent people, and release and delivery controls as applicable?
Objective evidence
  • For a sample of operations, the documented information that defines what to do and the results to achieve - work instructions, specs, drawings, parameters - available and current AT the point of use, not buried in a system.
  • Suitable, calibrated monitoring and measuring resources in use, and competent, authorized people performing the work (tie to 7.1.5 and 7.2).
  • In-process and final monitoring/measurement records at the defined stages, showing acceptance criteria are checked during production, not only at the end.
  • For special processes (where output cannot be fully verified later - welding, heat-treat, sterilization, coating), the validation/revalidation records and controlled parameters.
  • Evidence of actions to prevent human error (mistake-proofing, checklists, visual controls) and of release, delivery, and post-delivery controls as applicable.
Common nonconformities
  • Major NC: A special process whose output cannot be verified afterward is run without validation, so conformity cannot be assured.
  • Minor NC: Work instructions for complex operations are missing or not available at the point of use, so the work depends on individual memory.
  • Minor NC: In-process monitoring at defined stages is not performed or not recorded, so nonconformities are only caught (if at all) at final inspection.
  • Observation: No actions to prevent human error on operations where a single mistake produces nonconforming output.
Auditor tip

Production and service provision must be controlled to ensure consistent quality. CONTROLLED CONDITIONS (a-h): a) DOCUMENTED INFORMATION: - Work instructions - Process specifications - Drawings and specifications - Standard operating procedures (SOPs) - Quality plans b) MONITORING AND MEASURING RESOURCES: - Equipment available and suitable - Calibrated and maintained (see 7.1.5) - Inspection tools and gauges - Test equipment c) MONITORING AND MEASUREMENT AT APPROPRIATE STAGES: - In-process inspection - Final inspection - Monitoring of process parameters - Verification at key stages d) SUITABLE INFRASTRUCTURE AND ENVIRONMENT: - Appropriate facilities (see 7.1.3) - Controlled environment (see 7.1.4) - Proper equipment and tools - Safe working conditions e) COMPETENT PERSONS: - Trained and qualified personnel (see 7.2) - Certifications where required - Skill verification - Authorization to perform work f) VALIDATION OF SPECIAL PROCESSES: - Where output cannot be verified after the fact - Examples: Welding, heat treatment, sterilization, software - Process validation before production - Periodic revalidation - Equipment and personnel qualification g) PREVENT HUMAN ERROR: - Error-proofing (poka-yoke) - Clear work instructions - Training - Standard work - Checks and verifications - Ergonomic design h) RELEASE, DELIVERY, POST-DELIVERY: - Release criteria and approval (see 8.6) - Delivery controls - Post-delivery activities (warranty, support, etc.) (see 8.5.5)

What to sample

Observe a key production or service delivery process. Verify controlled conditions (a-i) are implemented as documented.

Follow-up questions
  • How do you ensure production and service provision occurs under controlled conditions?
  • What controls are in place to prevent errors during production or service delivery?
  • How do you handle special processes where output cannot be verified by inspection alone?
8.5.1.a Under controlled conditions, is documented information available that defines the characteristics of the products and services (or the activities) and the results to be achieved?
Objective evidence
  • Work instructions at point of use
  • Process specifications
  • Product/service specifications
  • Standard operating procedures (SOPs)
Common nonconformities
  • No documented work instructions
  • Outdated specifications
  • Instructions not accessible to workers
Auditor tip

Work instructions and specifications must be available: - Product specifications - Service procedures - Work instructions - Process parameters - Quality requirements

What to sample

Check 2-3 workstations for availability of current work instructions. Verify they describe both characteristics and activities.

Follow-up questions
  • What documented information defines product/service characteristics and activities to be performed?
  • Are work instructions available at point of use for critical operations?
8.5.1.b Under controlled conditions, is documented information available that defines the results to be achieved?
Objective evidence
  • Quality objectives for production
  • Output requirements documentation
  • Target specifications
  • Acceptance criteria
Common nonconformities
  • Unclear quality targets
  • No defined acceptance criteria
  • Ambiguous output requirements
Auditor tip

Clear definition of expected outcomes: - Quality targets - Output specifications - Performance criteria - Acceptance standards

What to sample

Verify monitoring equipment at 2-3 workstations is identified, calibrated (current sticker/record), and appropriate for the measurement.

Follow-up questions
  • What monitoring and measurement resources are available and used during production?
  • How do you ensure monitoring equipment is suitable and calibrated?
8.5.1.c Under controlled conditions, are suitable monitoring and measuring resources available and actually used?
Objective evidence
  • Monitoring and measuring equipment list
  • Calibration records
  • Equipment availability at workstations
  • Equipment suitability verification
Common nonconformities
  • Missing measurement equipment
  • Out-of-calibration equipment in use
  • Equipment unsuitable for task
Auditor tip

Proper measurement equipment: - Gauges and instruments available - Calibrated and maintained - Suitable for the measurement task - Properly used by trained personnel

What to sample

Review in-process and final inspection records for 2-3 products. Verify checks were performed at defined stages per the control plan.

Follow-up questions
  • At what stages are monitoring and measurement activities performed?
  • How do you verify that acceptance criteria are met before releasing product?
8.5.1.d Under controlled conditions, is monitoring and measurement implemented at appropriate stages to verify acceptance criteria are met?
Objective evidence
  • Inspection and test plans
  • In-process inspection records
  • Final inspection records
  • Quality control checkpoints
Common nonconformities
  • No inspection points defined
  • Skipping required inspections
  • No verification before release
Auditor tip

In-process and final inspection: - Inspection points defined - Process monitoring performed - Acceptance verification before release - Records of measurement results

What to sample

Check environmental monitoring records for controlled areas. Verify conditions are within specified limits.

Follow-up questions
  • How do you ensure the infrastructure and environment are suitable for production?
  • What environmental conditions are monitored (temperature, humidity, cleanliness)?
8.5.1.e Under controlled conditions, is suitable infrastructure and environment used for operating the processes?
Objective evidence
  • Facility suitability assessments
  • Environmental monitoring records
  • Workspace organization (5S)
  • Infrastructure maintenance records
Common nonconformities
  • Inadequate facilities for work
  • Environmental conditions affecting quality
  • Poor workspace organization
Auditor tip

Appropriate facilities and conditions: - Adequate workspace and equipment - Proper environmental controls - Clean and organized work areas - Safety considerations addressed

What to sample

Verify operator qualifications for 2-3 workers in critical processes. Check training records against competence requirements.

Follow-up questions
  • How do you ensure personnel performing production or service delivery are competent?
  • What qualification requirements exist for special process operators?
8.5.1.f Under controlled conditions, are competent persons appointed, including any required qualifications?
Objective evidence
  • Training records for production personnel
  • Competency assessments
  • Certifications and qualifications
  • Personnel authorization records
Common nonconformities
  • Untrained personnel performing work
  • Missing required certifications
  • No competency verification
Auditor tip

Qualified personnel for operations: - Training and competency verified - Certifications where required - Skills appropriate for assigned tasks - Authorization to perform work

What to sample

Identify special processes (e.g., welding, heat treatment, sterilization). Review validation records and revalidation schedules.

Follow-up questions
  • How do you validate special processes where outputs cannot be verified by subsequent inspection?
  • What revalidation criteria apply to validated processes?
8.5.1.g Where output cannot be fully verified afterward (special processes such as welding, heat treatment, or sterilization), is the process's ability to achieve planned results validated and periodically revalidated?
Objective evidence
  • Special process validation protocols
  • Process validation reports
  • Revalidation schedule and records
  • Equipment and personnel qualification for special processes
Common nonconformities
  • Special processes not identified
  • No validation performed
  • Revalidation not scheduled or performed
Auditor tip

Special process validation: - Processes where output cannot be verified after the fact - Examples: welding, heat treatment, sterilization, coating - Initial validation before production use - Periodic revalidation to confirm continued capability

What to sample

Review error-proofing measures in 2-3 processes. Ask operators what safeguards prevent mistakes.

Follow-up questions
  • What actions are implemented to prevent human error in production?
  • How have you applied error-proofing (poka-yoke) principles?
8.5.1.h Under controlled conditions, are actions taken to prevent human error (mistake-proofing, checklists, clear instructions)?
Objective evidence
  • Error-proofing implementations
  • Poka-yoke devices
  • Verification checklists
  • Standard work documentation
Common nonconformities
  • Recurring human errors
  • No error prevention measures
  • Confusing work instructions
Auditor tip

Error-proofing measures: - Poka-yoke (mistake-proofing) devices - Clear work instructions - Verification steps and checklists - Ergonomic workplace design - Standard work procedures

What to sample

Review release authorization records for 2-3 recent shipments. Verify authorized personnel signed off before release.

Follow-up questions
  • What release, delivery, and post-delivery activities are defined?
  • How do you authorize product release, and who has this authority?
8.5.1.i Under controlled conditions, are release, delivery, and post-delivery activities implemented?
Objective evidence
  • Release procedures
  • Delivery verification records
  • Post-delivery activity procedures
  • Customer handover documentation
Common nonconformities
  • No formal release process
  • Delivery issues not controlled
  • Post-delivery activities neglected
Auditor tip

End-of-process controls: - Release approval process (see 8.6) - Delivery controls and verification - Post-delivery support activities (see 8.5.5) - Customer handover procedures

What to sample

Review error/rework data trends. Verify error prevention actions are implemented and effective.

Follow-up questions
  • What actions are in place to prevent human error during production and service provision?
  • How effective have your error prevention measures been?
8.5.2 Where it matters for conformity, are outputs identified by suitable means, is the status with respect to monitoring and measurement identified, and is traceability maintained where required?
Objective evidence
  • The identification and traceability procedure and its use on the floor - verify outputs (materials, components, product) are identified by suitable means where conformity depends on it, so the right item is used and mix-ups are prevented.
  • Status identification - tags, stamps, color codes, or system status showing the monitoring/measurement (inspection/test) status of product, so unverified or rejected product cannot be mistaken for accepted.
  • Traceability records where required (by contract, regulation, or risk) - serial/lot/batch systems that allow product to be traced back to production conditions and forward to customers (essential for recall).
  • For a sampled item, an actual traceability exercise - trace a finished item back through its records to materials and process data, and confirm the chain is unbroken.
  • Segregation/identification keeping conforming and nonconforming product distinct (link to 8.7).
Common nonconformities
  • Major NC: Traceability is required (regulatory/contractual) but is not maintained, so affected product cannot be identified in a recall or containment.
  • Minor NC: Inspection/test status is not identified, so unverified or rejected product can be (or has been) mixed with accepted product.
  • Minor NC: Product/material identification is missing where conformity depends on it, risking the wrong item being used.
  • Observation: A traceability exercise reveals broken links (e.g. lot records that do not reconcile), so the system would not perform in an actual recall.
Auditor tip

Identification ensures correct product/material is used. Traceability enables tracking through production and to customers. IDENTIFICATION: - Identify outputs (products, services, materials, components) - Ensure correct items used in production - Prevent mix-ups and errors - Methods: Labels, tags, serial numbers, batch codes, location STATUS IDENTIFICATION: - Inspection and test status - Examples: "Inspected - OK", "Awaiting Inspection", "Rejected", "Quarantine" - Prevents use of uninspected or nonconforming product - Methods: Tags, stamps, labels, color coding, location TRACEABILITY (when required): - Unique identification (serial numbers, lot codes) - Ability to trace from raw material through production to customer - Ability to trace back from customer to production conditions - Required for: Safety-critical products, regulated industries, customer requirements - Documented information: Traceability records, lot/serial number logs, genealogy records

What to sample

Select a finished product and trace backwards through production stages to raw material receipt. Verify identification is maintained throughout.

Follow-up questions
  • How do you identify products and their status throughout production?
  • How far back can you trace a product — to raw materials, process parameters, and operators?
  • Is traceability required by contract or regulation?
8.5.3 Is property belonging to customers or external providers cared for while under the organization's control, with any loss, damage, or unsuitability reported to the owner?
Objective evidence
  • The customer/supplier-property register and procedure - verify property under the organization's control is identified, verified on receipt, and protected.
  • Receipt/verification records showing property is checked when it arrives, so problems are caught early.
  • Storage/handling controls keeping customer property distinct from the organization's own stock and protected from damage.
  • Evidence that loss, damage, or unsuitability of customer property is REPORTED to the owner and recorded.
  • Protection of intangible property too - intellectual property, designs, and personal data provided by customers.
Common nonconformities
  • Minor NC: Customer/external-provider property is not controlled - not identified, verified, or protected while in the organization's care.
  • Minor NC: Loss, damage, or unsuitability of customer property is not reported to the owner.
  • Minor NC: Customer property is mixed with the organization's own stock, risking misuse.
  • Observation: Intangible customer property (IP, data) is not recognized or protected.
Auditor tip

Customer/supplier property must be protected and any problems reported. TYPES OF PROPERTY: - Materials for processing - Components for assembly - Tooling owned by customer - Equipment loaned to organization - Intellectual property (designs, data, trade secrets) - Personal data (GDPR considerations) - Customer premises (for service work) REQUIREMENTS: - IDENTIFY: Record receipt and identify as customer property - VERIFY: Check condition and suitability upon receipt - PROTECT: Store, handle, use properly - SAFEGUARD: Prevent damage, loss, degradation - REPORT: Notify customer/provider if damaged, lost, or unsuitable - RETAIN RECORDS: Document property handling and any issues

What to sample

Review the customer/external provider property register. Inspect storage conditions for 2-3 items. Verify reporting process for damage/loss.

Follow-up questions
  • What types of customer or external provider property do you handle?
  • How do you identify, protect, and safeguard such property?
  • What do you do when customer property is lost, damaged, or found to be unsuitable?
8.5.4 Are outputs preserved during production and service provision to the extent needed for conformity (identification, handling, contamination control, packaging, storage)?
Objective evidence
  • Evidence outputs are preserved during production and service provision to the extent needed for conformity - identification, handling, packaging, storage, and protection.
  • Storage conditions and controls appropriate to the product (environment, contamination control, segregation).
  • Handling and packaging methods that prevent damage in process and transit.
  • Where relevant, shelf-life/expiration and FIFO controls so product is not used past its usable life.
  • A floor check that product is actually preserved as specified, not just in the procedure.
Common nonconformities
  • Minor NC: Product is damaged or deteriorating in storage or handling because preservation controls are inadequate.
  • Minor NC: No defined storage conditions for product that needs them (environment, contamination control).
  • Observation: Shelf-life/expiration controls are absent for product that has a usable-life limit.
  • Observation: Packaging or handling methods do not prevent in-transit damage.
Auditor tip

Products must be preserved to prevent damage, degradation, or deterioration. PRESERVATION ACTIVITIES: - IDENTIFICATION: Maintain labels and markings - HANDLING: Proper handling methods to prevent damage - CONTAMINATION CONTROL: Prevent contamination or cross-contamination - PACKAGING: Appropriate packaging for protection - STORAGE: Proper storage conditions (temperature, humidity, light) - TRANSMISSION/TRANSPORTATION: Protect during movement - PROTECTION: General protection from damage, deterioration, theft APPLIES TO: - Finished products - Work-in-process - Component parts - Materials - Service elements (e.g., software, data)

What to sample

Inspect storage areas for proper identification, FIFO, environmental conditions, and protection. Check for expired or deteriorated materials.

Follow-up questions
  • How do you ensure products are preserved during internal processing and delivery?
  • What preservation methods are used (packaging, handling, storage, protection)?
  • How do you manage shelf life or expiration dates?
8.5.5 Are post-delivery activities met to the extent required, taking account of statutory/regulatory obligations, potential undesired consequences, product life, customer feedback, and contractual commitments (warranty, servicing, recall)?
Objective evidence
  • The defined post-delivery activities (warranty, servicing, support, recall) and evidence they are delivered to the extent required by contract, regulation, and the product's risk.
  • Evidence the EXTENT of post-delivery activity was determined considering statutory/regulatory obligations, potential undesired consequences, product nature/use/lifetime, customer requirements, and customer feedback - not set arbitrarily.
  • A functioning recall/field-action capability where the product's risk warrants it - procedure plus evidence it could be executed (traceability, contacts, mock or actual recall).
  • Service/maintenance and warranty records showing obligations are actually met and tracked, not just promised.
  • Post-delivery feedback fed back into the QMS - field issues informing improvement, design, or risk (link to 9.1.2/10).
Common nonconformities
  • Major NC: A product whose risk warrants a recall/field-action capability has none, so the organization could not act on a serious post-market issue.
  • Minor NC: The extent of post-delivery activity was not determined against the required considerations (statutory, consequences, lifetime, customer needs).
  • Minor NC: Warranty or servicing obligations are not consistently met, with customer complaints about after-sales support.
  • Observation: Post-delivery/field feedback is not fed back into the QMS, so recurring field issues do not drive improvement.
Auditor tip

Post-delivery activities support products/services after delivery to customer. CONSIDERATIONS (a-e): a) STATUTORY/REGULATORY: Product liability laws, warranty laws, safety recalls b) UNDESIRED CONSEQUENCES: Safety issues, failures, environmental impact c) NATURE AND LIFETIME: Durability, maintenance needs, expected life d) CUSTOMER REQUIREMENTS: Support, training, maintenance contracts e) CUSTOMER FEEDBACK: Issues reported, improvement opportunities POST-DELIVERY ACTIVITIES: - Warranty service and repair - Technical support and helpdesk - Maintenance and servicing - Training and user support - Software updates and patches - Spare parts supply - Installation and commissioning - Field service - Product recalls - End-of-life disposal or recycling

What to sample

Review post-delivery obligations (warranty, maintenance, support). Verify activities are defined and records maintained.

Follow-up questions
  • What post-delivery activities are applicable to your products/services?
  • How do you determine the extent of post-delivery activities needed?
8.5.5.a Do post-delivery activities take account of the applicable statutory and regulatory requirements?
Objective evidence
  • Regulatory requirements analysis for post-delivery
  • Compliance with product liability laws
  • Recall procedures where required
  • Legal post-delivery requirements documentation
Common nonconformities
  • Regulatory post-delivery requirements not identified
  • Non-compliance with legal obligations
  • No recall process when required by law
Auditor tip

Legal requirements for after-sales: - Product liability laws - Warranty obligations under law - Safety recall requirements - Environmental disposal requirements

What to sample

Check regulatory requirements for post-market activities (e.g., safety reporting, recalls). Verify compliance processes exist.

Follow-up questions
  • What statutory and regulatory requirements apply to post-delivery activities?
  • How do you ensure compliance with product safety and reporting requirements after delivery?
8.5.5.b Do post-delivery activities take account of the potential undesired consequences of the products and services?
Objective evidence
  • Risk assessment for product use
  • Safety monitoring procedures
  • Incident tracking and response
  • Post-market surveillance
Common nonconformities
  • Safety risks not considered
  • No monitoring for product issues
  • Incidents not tracked
Auditor tip

Risk-based post-delivery considerations: - Safety risks in use - Potential for misuse - Environmental impact - Failure consequences

What to sample

Review risk assessments for post-delivery scenarios. Verify mitigations are in place for identified risks.

Follow-up questions
  • What potential undesired consequences have been identified for your products after delivery?
  • How are known risks communicated to customers?
8.5.5.c Do post-delivery activities take account of the nature, use, and intended lifetime of the products and services?
Objective evidence
  • Product lifetime documentation
  • Maintenance requirements
  • Spare parts strategy
  • End-of-life planning
Common nonconformities
  • Product life not considered
  • No maintenance support for durable goods
  • Spare parts unavailable prematurely
Auditor tip

Product lifecycle considerations: - Durability and expected life - Maintenance requirements - Spare parts availability needs - End-of-life disposal

What to sample

Verify product lifetime specifications. Check that warranty periods and spare parts availability align with intended lifetime.

Follow-up questions
  • What is the nature, use, and intended lifetime of your products?
  • How do these factors influence your post-delivery support?
8.5.5.d Do post-delivery activities take account of customer requirements (warranty, support, training)?
Objective evidence
  • Customer warranty agreements
  • Service level agreements
  • Training delivery records
  • Customer support procedures
Common nonconformities
  • Customer requirements not met
  • SLAs not honored
  • Customer complaints about support
Auditor tip

Customer expectations for after-sales: - Warranty terms agreed with customer - Support and service level agreements - Training requirements - Installation and commissioning

What to sample

Review contracts for post-delivery requirements (SLAs, maintenance, training). Verify fulfillment records.

Follow-up questions
  • What specific customer requirements exist for post-delivery activities?
  • How do you track and fulfill contractual post-delivery obligations?
8.5.5.e Do post-delivery activities take account of customer feedback?
Objective evidence
  • Customer feedback on post-delivery services
  • Satisfaction surveys for support
  • Analysis of field issues
  • Improvements based on feedback
Common nonconformities
  • Customer feedback ignored
  • No systematic feedback collection
  • Field issues not analyzed
Auditor tip

Using feedback to inform support: - Customer satisfaction surveys - Complaint analysis - Field issue trends - Improvement opportunities from feedback

What to sample

Review customer feedback on service/support activities. Verify it is analyzed and improvement actions taken.

Follow-up questions
  • How is customer feedback on post-delivery activities collected and used?
  • What improvements have been made based on post-delivery experience?
8.5.6 Are changes to production or service provision reviewed and controlled to the extent needed to keep conformity, with the results and authorizing person(s) recorded?
Objective evidence
  • Change-control records for production/service changes - verify changes are reviewed and controlled to the extent needed to keep conformity, with the change authorized.
  • Impact assessment before the change, so the effect on product/service conformity is understood.
  • Records identifying the person(s) who authorized the change and the results of the review.
  • Verification that conformity is maintained after the change.
  • Updated documentation reflecting the changed process/parameters.
Common nonconformities
  • Minor NC: Production/service changes are made without review or control, causing conformity issues.
  • Minor NC: No impact assessment before changing a process, so consequences are discovered in the product.
  • Minor NC: The authorizing person and the review results are not recorded.
  • Observation: Documentation is not updated after a production change, so people work to the old method.
Auditor tip

Changes to production/service provision must be controlled to maintain quality. TYPES OF CHANGES: - Process changes - Equipment changes - Material or supplier changes - Method changes - Temporary changes or deviations - Product/service changes (see also 8.3.6 for design changes) REQUIREMENTS: - REVIEW: Assess impact of change on conformity - CONTROL: Implement change in controlled manner - AUTHORIZE: Approval by authorized person - DOCUMENT: Record review, authorization, actions - VERIFY: Ensure change maintains conformity RELATIONSHIP TO OTHER CLAUSES: - 6.3: Planning of QMS changes (strategic/system level) - 8.3.6: Design changes - 8.5.6: Production/operational changes (this clause)

What to sample

Review 3-5 recent production/process change records. Verify review, authorization, and post-change verification were conducted.

Follow-up questions
  • How do you control changes to production or service provision?
  • What review and authorization is required before implementing a change?
  • How do you verify that changes do not adversely affect conformity?
8.6 Are planned verification activities carried out at the right stages to confirm product and service requirements are met before release, with release withheld until those checks are satisfactorily completed?
Objective evidence
  • The planned verification arrangements (from 8.1) and final-inspection/test records - confirm product/service requirements are verified at the right stages before release, against defined acceptance criteria.
  • Release records that include evidence of conformity to acceptance criteria AND traceability to the person(s) who authorized release.
  • Evidence that release is WITHHELD until the planned checks are satisfactorily completed - check for any product shipped before inspection was finished.
  • Where release proceeds before verification is complete, the documented customer or relevant-authority approval (concession) for doing so.
  • For a delivered sample, traceability from the shipment back through the release record to the inspection/test data.
Common nonconformities
  • Major NC: Product/service is released and delivered without the planned verification being completed, so conformity is not demonstrated at the point of release.
  • Minor NC: Release records do not identify who authorized release, so accountability for the release decision is missing.
  • Minor NC: Release records confirm shipment but not conformity to acceptance criteria.
  • Observation: Early release ahead of full verification occurs without a recorded concession/authorization.
Auditor tip

Products/services must be verified against requirements before release to customers. This is the final gate before delivery. PLANNED ARRANGEMENTS FOR VERIFICATION: - Defined inspection and test activities - Acceptance criteria (from 8.1) - Verification at appropriate stages - Final inspection before release VERIFICATION ACTIVITIES: - Inspection (visual, dimensional, functional) - Testing (performance, safety, durability) - Review of records and data - Verification of customer requirements - Compliance verification (regulatory, standards) - Review of deviations or nonconformities RELEASE AUTHORIZATION: - Formal approval to ship/deliver - By authorized person - Only after verification complete - Exception: Customer or authority approval for early release DOCUMENTED INFORMATION (a-b): a) EVIDENCE OF CONFORMITY: - Inspection records - Test results - Certificates of conformity/analysis - Verification checklists - Quality release documents - Proof that acceptance criteria were met b) TRACEABILITY TO AUTHORIZING PERSON: - Signature or electronic approval - Identity of person releasing product - Date of release - Accountability for release decision EXCEPTIONS TO NORMAL RELEASE: - Customer concession (customer accepts known nonconformity) - Authority approval (e.g., regulatory deviation) - Must be documented and approved STAGES OF RELEASE: - Receiving inspection (incoming materials) - In-process verification (work-in-process) - Final inspection (finished product) - Delivery release (shipment approval) LINK TO NONCONFORMITY: - Nonconforming product must not be released (see 8.7) - Unless authorized concession/deviation

What to sample

Review final inspection/test records for 3-5 recent releases. Verify all planned checks were completed and authorized personnel approved release.

Follow-up questions
  • At what stages do you verify that product/service requirements have been met?
  • Who has authority to release products, and under what conditions?
  • How do you handle release when planned arrangements have not been satisfactorily completed?
8.6 a Do the release records include evidence that the products and services meet the acceptance criteria?
Objective evidence
  • Final inspection records
  • Test reports and certificates
  • Verification checklists
  • Certificates of conformity
  • Measurement and test data
  • Quality release documentation
Common nonconformities
  • No evidence of conformity documented
  • Inspection records missing or incomplete
  • Products released without test results
  • Acceptance criteria not clearly met
Auditor tip

Release documentation must show products/services met acceptance criteria: - Inspection records showing results - Test results and reports - Certificates of conformity or analysis - Verification checklists completed - Quality release documents - Proof that acceptance criteria were met - Measurement data if applicable

What to sample

Review certificates of conformity or test reports for 3-5 released products. Verify they reference specific acceptance criteria.

Follow-up questions
  • What evidence do you retain to demonstrate conformity with acceptance criteria?
  • Are inspection and test results recorded with traceability to the product?
8.6 b Do the release records provide traceability to the person(s) who authorized release?
Objective evidence
  • Signed release documents
  • Electronic approval records
  • Release authorization with names/dates
  • Signature log for release approvals
  • Quality release sign-offs
Common nonconformities
  • Unclear who authorized release
  • No signatures on release documents
  • Release by unauthorized personnel
  • No traceability to release authority
Auditor tip

Release documentation must identify who authorized release: - Signature or electronic approval - Identity of person releasing product - Date of release authorization - Accountability for release decision - Authorization level appropriate to risk - Clear trail showing who approved release

What to sample

For 3-5 released products, verify the authorizing person(s) can be identified from records.

Follow-up questions
  • How is traceability maintained to the person(s) authorizing release?
  • Can you identify who released each batch or lot of product?
8.7.1 Are outputs that do not conform to requirements identified and controlled to stop their unintended use or delivery?
Objective evidence
  • The nonconforming-output procedure and a sample of nonconformance records - verify nonconforming outputs (in-process, at receipt, at final, and after delivery) are IDENTIFIED and CONTROLLED to prevent unintended use or delivery.
  • Physical/system evidence of control - segregation or quarantine areas, status tagging/labelling, or system holds - confirming nonconforming and conforming product cannot be mixed.
  • Disposition records (rework, scrap, use-as-is/concession, return) showing each nonconformity was dispositioned by an appropriate authority, with concessions properly authorized.
  • Re-verification records after correction/rework - confirming corrected output was re-checked against requirements before release.
  • Evidence that significant or recurring nonconforming outputs trigger the corrective-action process (link to 10.2), and that customers were informed where nonconforming product was delivered.
Common nonconformities
  • Major NC: Nonconforming output is not segregated or marked and can be (or has been) shipped or used unintentionally alongside conforming product.
  • Minor NC: Nonconforming product is accepted under concession without proper authorization (or without customer approval where required).
  • Minor NC: Reworked/corrected product is not re-verified against the original requirements before release.
  • Observation: Nonconforming outputs are dispositioned individually but never analyzed for systemic causes, so the same nonconformity recurs (link to 10.2).
Auditor tip

Nonconforming product/service must be identified, controlled, and dispositioned to prevent delivery to customers and ensure appropriate action. IDENTIFICATION AND CONTROL: - Identify nonconforming outputs (products, services, materials, components) - Mark or segregate to prevent unintended use - Control to prevent release or delivery - Methods: Physical segregation, tagging, quarantine areas, status marking SCOPE: - During production/service provision - At incoming inspection - At final inspection - After delivery to customer (field failures, complaints) - At any stage where nonconformity is detected DISPOSITION ACTIONS (a-d): a) CORRECTION: - Repair or rework to meet requirements - Re-inspection after correction - Verification of conformity b) SEGREGATION, CONTAINMENT, RETURN, SUSPENSION: - Segregate from conforming product - Contain to prevent use - Return to supplier (if supplier-caused) - Suspend service provision until resolved - Scrap or dispose if cannot be corrected c) INFORM CUSTOMER: - Notify customer of nonconformity - Required if already delivered - Coordinate resolution with customer - May lead to recall or field correction d) CONCESSION (DEVIATION/WAIVER): - Accept nonconforming product "as-is" - Requires authorization by relevant authority - May require customer approval - Only if acceptable for use despite nonconformity - Document justification VERIFICATION AFTER CORRECTION: - Re-inspect or re-test after rework/repair - Verify conformity to requirements - Same rigor as original verification NONCONFORMITY AFTER DELIVERY: - Customer complaints - Field failures - Warranty returns - Product recalls - Must be controlled same as internal nonconformities - Link to corrective action (10.2) PREVENTION OF UNINTENDED USE: - Critical requirement to prevent shipping bad product - Physical separation from good product - Clear identification - Controlled access to nonconforming area - Release only after proper disposition

What to sample

Review 5-10 recent nonconformance records. Verify segregation, disposition decisions, and closure. Check for repeat nonconformances.

Follow-up questions
  • How do you identify and control nonconforming outputs to prevent unintended use or delivery?
  • Walk me through what happens when a nonconformance is detected during production.
  • How do you handle nonconformances detected after delivery?
8.7.1 a Where nonconforming output is handled by correction, is the corrected output re-verified against the original requirements?
Objective evidence
  • Rework procedures
  • Rework records
  • Re-inspection records after correction
  • Verification of corrected product
Common nonconformities
  • Rework not properly documented
  • Corrected product not re-verified
  • Repeated rework indicating systemic issues
Auditor tip

Correction involves fixing the nonconformity: - Repair or rework to meet requirements - Re-processing the product - Adjustment or correction of defect - Must be re-verified after correction - Verify conformity to original requirements - Same verification rigor as original inspection

What to sample

Review 2-3 corrected nonconformances. Verify re-verification was performed and results documented.

Follow-up questions
  • How are nonconforming products corrected and re-verified?
  • What re-inspection or re-test is performed after correction?
8.7.1 b Where nonconforming output is handled by segregation, containment, return, or suspension of provision, are those actions actually carried out and recorded?
Objective evidence
  • Segregation/quarantine areas
  • Nonconforming material tags or labels
  • Return to vendor records
  • Service suspension records
  • Scrap records and authorization
Common nonconformities
  • Nonconforming product not segregated
  • Mixed with conforming product
  • No quarantine area or process
Auditor tip

Various options to control nonconforming output: SEGREGATION: - Physically separate from conforming product - Use quarantine areas or designated locations - Clear identification/tagging CONTAINMENT: - Prevent further use or processing - Stop propagation of nonconformity - Identify all affected material/products RETURN: - Return to supplier (if supplier-caused) - Return for credit or replacement - Document return and reasons SUSPENSION: - Suspend service provision until resolved - Stop delivery until issue addressed - Halt production if needed SCRAP: - Dispose if cannot be corrected - Make unusable to prevent inadvertent use

What to sample

Inspect quarantine/hold areas. Verify nonconforming materials are clearly identified and physically segregated.

Follow-up questions
  • How do you segregate, contain, or suspend nonconforming products?
  • What physical or system controls prevent nonconforming items from being used?
8.7.1 c Where appropriate, is the customer informed when nonconforming output is involved (especially after delivery or for safety-related issues)?
Objective evidence
  • Customer notification records
  • Communication with customer about nonconformity
  • Customer response and agreement
  • Field correction or recall records
Common nonconformities
  • Customer not informed of delivered nonconformities
  • No process for customer notification
  • Safety issues not communicated
Auditor tip

Customer must be informed when appropriate: - Required if product already delivered - Required for safety-related nonconformities - Coordinate resolution with customer - May lead to recall or field correction - Document customer communication - Obtain customer decision on disposition when needed

What to sample

Review recent customer notifications for nonconformances. Verify timeliness and completeness of communication.

Follow-up questions
  • Under what circumstances would you notify the customer of a nonconformance?
  • How do you handle customer notification for nonconformances detected after delivery?
8.7.1 d Where nonconforming output is accepted under concession, is proper authorization obtained (and customer approval where needed), with justification recorded?
Objective evidence
  • Concession or deviation authorizations
  • Customer approval for concessions (if required)
  • Justification documentation
  • Material Review Board (MRB) records
  • Risk assessment for concessions
Common nonconformities
  • Concessions granted without proper authorization
  • Customer not consulted when required
  • No justification documented
  • Excessive concessions indicating quality issues
Auditor tip

Concession (deviation/waiver) process: - Accept nonconforming product "as-is" - Requires authorization by relevant authority - May require customer approval - Only if acceptable for use despite nonconformity - Document justification and risk assessment - Define any limitations or conditions - Track and trend concessions

What to sample

Review 2-3 concession/deviation records. Verify proper authorization and customer approval where required.

Follow-up questions
  • Who has authority to accept nonconforming product under concession?
  • What conditions must be met for a concession, and is customer approval required?
8.7.2 Does the organization keep records of nonconforming output that describe the nonconformity, the actions taken, any concessions, and who decided the disposition?
Objective evidence
  • The nonconformity records - verify each describes the nonconformity, the actions taken, any concessions obtained, and identifies the authority that decided the disposition (the 8.7.2 a-d elements).
  • Evidence the records are complete and retrievable (link to 7.5), not scattered or missing fields.
  • Authorization evidence - the decision-maker for each disposition is identified, with concessions properly authorized.
  • Trend analysis of nonconformity data, so recurring issues are visible (link to 9.3/10.2).
  • A sample check that the records reconcile with the physical/disposition actions actually taken.
Common nonconformities
  • Minor NC: Nonconformity records are incomplete - missing the nature, the actions, the concession, or the deciding authority.
  • Minor NC: The authority that decided the disposition is not identified, so accountability is missing.
  • Minor NC: Nonconformity records cannot be retrieved when requested.
  • Observation: Nonconformity data is recorded but never analyzed for trends.
Auditor tip

All nonconformities must be documented with description, actions, concessions, and responsible authority. This creates accountability and enables analysis. DOCUMENTED INFORMATION REQUIREMENTS (a-d): a) DESCRIPTION OF NONCONFORMITY: - What is nonconforming? - What requirement was not met? - Quantity or extent of nonconformity - Where/when detected - Lot or serial numbers affected - Severity or impact b) ACTIONS TAKEN: - Disposition decision (rework, scrap, use-as-is, return) - Corrective actions taken - Containment actions - Customer notification (if applicable) - Re-verification results c) CONCESSIONS OBTAINED: - Deviation or waiver granted - Terms and conditions of concession - Customer approval (if required) - Expiration or limits of concession d) AUTHORITY DECIDING ACTION: - Who made disposition decision - Signature or electronic approval - Date of decision - Accountability and traceability PURPOSE OF DOCUMENTATION: - Accountability for decisions - Traceability of nonconformities - Analysis of trends - Input to corrective action - Input to management review - Evidence for audits - Learning and improvement FORMS OF DOCUMENTATION: - Nonconformance reports (NCRs) - Corrective action requests (CARs) - Material review board (MRB) reports - Deviation notices - Rejection tags with follow-up documentation - Digital quality management system records

What to sample

Review 5 nonconformance records for completeness — they should describe the NC, actions taken, concessions obtained, and authority who decided.

Follow-up questions
  • What documented information do you retain on nonconforming outputs?
  • How complete are your nonconformance records?
8.7.2 a Do the nonconformity records describe the nonconformity itself (what failed, where, how much)?
Objective evidence
  • Nonconformance reports (NCRs)
  • Rejection tags with descriptions
  • Inspection reports noting nonconformities
  • Test failure reports
Common nonconformities
  • Nonconformity description vague or missing
  • Cannot understand what was wrong
  • No details on extent or impact
Auditor tip

Documentation must describe what was wrong: - What is nonconforming? - What requirement was not met? - Quantity or extent of nonconformity - Where/when detected - Lot or serial numbers affected - Severity or impact - Detection method or stage

What to sample

Check 3-5 nonconformance forms. Verify descriptions are specific enough to identify the product, defect, and quantity.

Follow-up questions
  • How do you document the description of nonconformities?
  • Is there a standard format for recording nonconformances?
8.7.2 b Do the nonconformity records describe the actions taken (disposition, corrections, re-verification)?
Objective evidence
  • Disposition recorded on NCRs
  • Rework or scrap documentation
  • Re-inspection records
  • Containment action records
Common nonconformities
  • Actions not documented
  • Unclear what was done
  • No record of disposition
Auditor tip

Documentation must describe disposition and actions: - Disposition decision (rework, scrap, use-as-is, return) - Corrective actions taken - Containment actions - Customer notification (if applicable) - Re-verification results - Root cause investigation (if performed)

What to sample

Review disposition records (rework, scrap, use-as-is, return). Verify actions were documented and completed.

Follow-up questions
  • How are actions taken on nonconforming outputs documented?
  • Are disposition decisions recorded with rationale?
8.7.2 c Do the nonconformity records describe any concessions obtained?
Objective evidence
  • Concession/deviation requests and approvals
  • Customer concession approvals
  • MRB meeting records
  • Justification documentation
Common nonconformities
  • Concessions not documented
  • No justification for use-as-is decisions
  • Customer approval not obtained when required
Auditor tip

Documentation must include concession details: - Deviation or waiver granted - Terms and conditions of concession - Customer approval (if required) - Justification for acceptance - Expiration or limits of concession - Risk assessment if applicable

What to sample

Review concession records. Verify written approval from appropriate authority (and customer where required).

Follow-up questions
  • How are concessions documented and tracked?
  • What records show customer or relevant authority approval for concessions?
8.7.2 d Do the nonconformity records identify the authority that decided the action on the nonconformity?
Objective evidence
  • Signed NCRs or disposition records
  • Electronic approval records
  • MRB attendee lists and signatures
  • Authorization matrix for decisions
Common nonconformities
  • Decision authority not identified
  • No signatures on disposition decisions
  • Decisions made by unauthorized personnel
Auditor tip

Documentation must show who made decisions: - Who made disposition decision - Signature or electronic approval - Date of decision - Title/role of decision-maker - Accountability and traceability - Authorization level appropriate to decision

What to sample

Check 3-5 nonconformance records for clear identification of the person who authorized the disposition.

Follow-up questions
  • How is the identity of the person authorizing the disposition decision recorded?
  • Can you trace every nonconformance disposition to an authorized individual?

Each item shows its evidence, common nonconformities and auditor tips. The clause index has the PDF of all 251 items, formatted for a clipboard.