Checklist · QSM / IMS lead
ISO 9001 / IMS audit-readiness checklist
A pre-audit self-check against the ISO 9001 clauses an internal or certification audit actually samples. Each item names the clause it evidences and the record an auditor will ask to see.
Quality objectives & planning (§6.1, §6.2)
- [ ] Every quality objective has an owner, a target value, and a review date — not a narrative goal.
- [ ] Risk-and-opportunity assessment exists per objective and is dated within the current review cycle.
- [ ] Objective status is reviewable on demand, not reconstructed from memory before the audit.
Non-conformance management (§10.2)
- [ ] Every open non-conformance has a registration number, an activity-type source, an assigned process owner, and a due date — not an email thread.
- [ ] Root-cause analysis is recorded before closure, not filled in retroactively for the auditor.
- [ ] Corrective-action effectiveness is verified by someone other than who executed it (verify ≠ approve) and that verification is dated.
- [ ] Ageing statistics (open / closed, days-to-closure) can be pulled without a manual count.
Internal audit program (§9.2)
- [ ] The audit schedule covers every process at its defined frequency — gaps are visible, not discovered when a process goes unaudited for a cycle.
- [ ] Every finding traces to a non-conformance record or a closed corrective action, not a standalone note.
Management review (§9.3)
- [ ] Review inputs (audit results, NC status, objective performance, risk register) are pulled from source records, not re-typed from memory.
- [ ] Minutes are a documented output, not informal notes — reviewable as evidence, not recalled verbally in the next audit.
Document & normative control (feeds §7.5, §8.1)
- [ ] Every referenced standard/normative document shows a current validity status — a superseded standard cannot be released against without a visible flag.
- [ ] A change to a controlled process document is routed through Management of Change with a responsible-person sign-off, not applied silently.
Why this matters
Structured, continuously-current evidence for these six areas is what separates an audit that takes days from one that takes weeks: organizations with a mature internal-audit and non-conformance program report meaningfully fewer major findings than those without one — 0.6 vs. 2.7 major findings per audit cycle, a 43% reduction (BSI Global Audit Benchmarking Data, 2025).
Mechanism reference
Every item above corresponds to a real e-QMS mechanism: quality objectives and the risk catalog
(Risk Management), the routed NCR lifecycle with source-prefix numbering and SLA timers
(Non-conformance Management), the internal-audit and management-review record set, and
color-coded standard validity (Normative-Technical Documents DB) — see 02_Products_and_SaaS/e_qms.md.
Sources
- BSI Global Audit Benchmarking Data, 2025 — internal-audit-program impact on major-finding rate.
- Clause structure: ISO 9001:2015 §6.1, §6.2, §9.2, §9.3, §10.2.