Quality Management System
ISO 9001 Audit Checklist: Free Download
Preparing for an ISO 9001 internal audit, or just want to know where you are against the standard? Download our practical ISO 9001 Audit Checklist and assess your Quality Management System against the requirements of ISO 9001:2015.
Use the checklist to perform a gap analysis or internal audit against the standard and learn exactly where you stand.

Written By: Fiona Parker, a BSI-qualified Lead Auditor in ISO 9001. Built and ran a certified ISO 9001 quality management system for six years before moving into auditing, and previously led IT teams in high-performance engineering, including at McLaren
Last Update:
4 August 2026
An ISO 9001 audit checklist is a structured set of questions used during an internal audit to assess whether a Quality Management System conforms to the requirements of ISO 9001:2015 and is working as intended. It covers Clauses 4 to 10, prompts the auditor to gather objective evidence, and records what was found.
It’s important to state that any checklist is not a certification guarantee. Certification will depend on whether you can demonstrate that your management system is implemented, maintained and achieving its intended results, and that comes through an honest and in-depth review of the evidence. This checklist helps you find out whether that is true before a certification auditor does.
I have been on both sides of this. I spent six years building and running a certified ISO 9001 quality management system, which meant preparing for and sitting through a certification audit and then a surveillance audit every year. I now audit other organisations as a BSI-qualified Lead Auditor.
What I found running that system was that the checklist was never really the hard part. The hard part was everything around it: deciding what to audit and when, keeping the programme moving when the business got busy, writing findings that were useful rather than defensive, and proving afterwards that anything had actually changed. So the download below is not a single checklist. It is the full set of five documents I would want if I were starting again.
What ISO 9001 Actually Requires You to Check
Before looking at technique, it helps to be clear about what the standard requires. ISO 9001:2015 sets out its requirements across seven clauses (if you are wondering were clause 1 to 3 went, then they aren’t included as they are the references and introduction text, like the forward by Stephen Fry that accompanies every book).
Everything you audit sits somewhere in this table.
| Clause | Topic | What the standard requires | What auditors typically review |
|---|---|---|---|
| 4 | Context of the Organisation | Understand your context, interested parties, scope and processes | Scope statement, interested parties analysis, process map |
| 5 | Leadership | Top management accountability, quality policy, assigned responsibilities | Quality policy, evidence of leadership involvement, customer focus |
| 6 | Planning | Risks and opportunities, quality objectives, planning of changes | Risk records, measurable objectives, change control |
| 7 | Support | Resources, competence, awareness, communication, documented information | Training and competence records, communication routes, document control |
| 8 | Operation | Customer requirements, design, suppliers, production and service delivery | Contracts, requirement reviews, supplier records, delivery records |
| 9 | Performance Evaluation | Monitoring, measurement, internal audit, management review | KPIs, audit programme, management review minutes |
| 10 | Improvement | Nonconformity, corrective action, continual improvement | Corrective action records, effectiveness checks, improvement evidence |
This is why an ISO 9001 requirements checklist and an ISO 9001 audit checklist are related but not identical. A requirements checklist asks whether you have addressed each clause. An audit checklist asks whether the arrangements you put in place are being followed and are actually working. The second question is harder, and it is the one certification auditors care about.
The internationally recognised guidance on conducting management system audits is ISO 19011. It is not a certification requirement, but it is the reference point most competent auditors work from and it is worth reading if you are building an audit programme from scratch.
Readiness Review or Effectiveness Audit? Decide This First
This is the question that most often gets skipped, and getting it wrong wastes an audit.
A readiness review assesses whether the required elements of your QMS are defined, approved, published and communicated, and whether there is a plan to go live. You use it before certification, when the system exists on paper but has not been running long enough to generate much operational evidence.
or
An effectiveness audit assesses whether processes are implemented and working, supported by records and operational evidence. You use it once the system is genuinely running.
The distinction matters because the two produce completely different findings. Auditing a three-month-old QMS for effectiveness generates a long list of nonconformities that simply say “this has not happened yet”, which is demoralising and tells you nothing you did not already know.
Whereas, auditing an established system for readiness lets real operational problems slide by unexamined.
For a readiness review it is worth recording how far each element has actually got, rather than treating it as a binary pass or fail:
| Stage | What it means |
|---|---|
| Defined | A documented requirement or process exists |
| Approved | Formally approved by appropriate management |
| Published | Accessible to the people who need it |
| Communicated | Staff briefed or trained, with a record of it |
| Operational | In use, with records to prove it |
Most pre-certification gaps sit at Published or Communicated. The policy exists and has been approved, but nobody has told anyone about it. That is a very common and very fixable finding.
The audit procedure and programme templates in the pack both let you set the audit type up front, so this decision gets recorded rather than assumed.
What Is in the Free Internal Audit Pack
Five documents that work together. Use them in this order.
| Ref | Document | What it is for | When you use it |
|---|---|---|---|
| IA1 | Internal Audit Procedure | Defines how audits are planned, conducted, reported and followed up. This is the documented process a certification auditor will ask to see | Set up once, review annually |
| IA2 | Internal Audit Programme and Plan | The rolling schedule of what gets audited when and why, plus a per-audit plan covering scope, timetable and impartiality | Annually for the programme, then per audit |
| IA4 | Internal Audit Checklist (Clauses) | Clause-by-clause working paper across Clauses 4 to 10, with audit prompts, typical evidence and space to record results | During the audit |
| IA5 | Process Audit Checklist | A 17-stage process trail for following real orders end-to-end through the business | During the audit, alongside IA4 |
| IA3 | Internal Audit Findings Report | The report itself: overall conclusion, findings summary, detailed findings with evidence, and a closure log | After the audit |
All five are editable templates.
The document control blocks and classification markings are there for you to complete as the adopting organisation, in the same way as any other controlled document in your QMS. Where the templates reference codes like QPM1 or QCR1, those point to your own process map, order review log and similar records. Substitute your own equivalents.
Why Internal Audits Are Important
Firstly, they are a mandatory part of the standard under clause 9.2, so you have to conduct them on a regular basis, but internal audits are one of the most valuable requirements in ISO 9001, and one of the most commonly wasted.
Done properly, they help you identify issues before certification auditors do, confirm processes are being followed in practice rather than on paper, verify quality objectives are being achieved, improve consistency and customer satisfaction, demonstrate leadership oversight, and drive genuine improvement.
The best internal audits are not about ticking boxes. They are about understanding how the business works and whether the management system genuinely supports delivery of your products and services.
They are also an underrated training tool. For newer staff, taking part in an audit is one of the quickest ways to understand how the business fits together and why particular controls exist. And audits generate honest feedback on the management system from the people who have to use it. I certainly have used it as a tool for junior members of staff in the past to get up to speed with the standard and it’s requirements.
Some of the most useful audits I have run produced no major nonconformities at all. Instead they identified opportunities to simplify a process, reduce duplication, improve a handover, or make the system easier to live with.
I will admit I did not always see it that way. Running my first certified system myself, an internal audit felt like something to survive rather than something to use (we would bring in external auditor help), and for the first year or two we treated it as an annual box to tick ahead of the surveillance visit. What changed it was realising the audit was the only scheduled point in the year when anyone stopped to ask whether the system we had built was still the system we actually needed.
As a personal example of when I started out, we were onboarding our suppliers and undertaking due dillegence and review in a pretty robust manner, per our procedures, but what we weren’t doing so well was the periodic reviews that we should have been doing. Certainly we weren’t doing them as well as we could. The internal audit pulled that out and helped us avoid issues at the audit with the certification body. Crisis (and embarrassment) avoided…
How to Run the Audit
Step 1: Plan the programme, then the audit
An effective audit programme should be risk-based. It must consider the importance of each process, changes in the organisation, and findings from previous audits, rather than working through the same list in the same order every year.
Before each audit, you should define the objectives, scope, criteria, methods, team and sampling approach. The programme template (IA2) has a worked example showing three audits across a year: governance and planning in the first period, operations and core delivery in the second, performance and improvement in the third. It is a reasonably simple model for a small business, and it deliberately puts Clause 8 in the middle of the year so there is time to fix what it finds before the certification or surveillance visit.
Your programme should also trigger additional audits outside the schedule when something happens: a significant customer complaint or quality incident, a major organisational or process change, a material change of external provider, or repeated nonconformities.
One practical point that matters more than it looks at first glance. If an audit needs to be postponed, do not simply let it disappear. Record the reason, formally reschedule it, and keep the audit trail of that decision. The programme template has a status column for exactly this.
This does two things. It shows the audit programme is actively managed rather than quietly slipping. And it gives you real data. If audits are repeatedly delayed by resource pressure, customer commitments or reorganisation, that is a finding in its own right and belongs in your next management review. It’s actually quite a common occurance, and certainly something I’ve encountered in the past.
Step 2: Follow real work through the business
Rather than asking “do you have a procedure?”, I recommend you follow a real customer engagement from enquiry through to delivery and aftercare.
This process-based approach is the single most valuable audit technique available to you, because it tests whether the management system works rather than whether it has been written down. It’s easy enough to produce shelfware, but it’s a lot harder to run a functioning QMS.
The process audit checklist (IA5) is built for this. You select two or three recent orders of different types, ideally including one standard job, one bespoke, and one that went wrong, then trace each through seventeen stages from requirements capture to corrective action. Deliberately picking the awkward order is the point. A process that handles the routine case is not evidence of much.
When I audit, I am often less interested in the individual process steps than in what happens when responsibility moves from one person to another. Those handover points are where consistency, customer satisfaction and process effectiveness are most at risk, and they are where most worthwhile Opportunities for Improvement are found. A process can broadly work while information, responsibilities or expectations quietly degrade at the boundary between two teams.
This matters more as a business grows. In smaller organisations people wear several hats. Sales might also be delivery. Delivery might also be support. Because everyone knows each other and talks constantly, handovers happen through conversation rather than defined process. That works until it does not. Headcount rises, someone leaves, a second site opens, and the informal channel breaks without anyone noticing. Internal audits are how you find those transition points before a customer does.
Step 3: Gather evidence
Typical evidence includes proposals and contracts, customer requirements, training records, risk assessments, supplier records, management review minutes, customer feedback and corrective actions.
The clause checklist (IA4) lists typical evidence to sample against each requirement, which is the part people most often get stuck on. Knowing that Clause 7.2 requires competence is straightforward. Knowing what a certification auditor will actually ask to see is the useful bit.
One mistake I see repeatedly is organisations creating new forms purely because they assume ISO requires them. Before creating anything, look at what already exists. Emails, project records, helpdesk tickets, meeting notes and customer correspondence are usually perfectly acceptable evidence. Small businesses rarely need more paperwork. They usually need to make better use of what their operations already generate.
Validate potential findings with the process owner during the audit rather than saving them for the report. It confirms you have the facts right, and it avoids the closing meeting becoming an argument.
How to Grade What You Find
Findings should be evidence-led and written as factual statements. Each one should reference the applicable requirement, describe the observed condition, and cite the objective evidence.
| Category | Definition |
|---|---|
| Major nonconformity | A significant failure affecting the QMS’s ability to achieve its intended outcomes, or a pattern of minor issues indicating systemic weakness |
| Minor nonconformity | An isolated lapse that does not by itself indicate systemic failure |
| Opportunity for Improvement | A suggestion that would strengthen a process where the requirement is broadly met |
| Observation | Something seen during the audit that may become an issue if not addressed |
Two things worth knowing; A pattern of minor nonconformities can be graded as a major, which catches people out. And where one underlying issue affects several areas, record it once as a theme and cross-reference the affected clauses rather than raising the same finding six times.
A report with thirty findings that are really four problems is harder to act on than one with four.
Findings go into the findings report (IA3), which includes a closure log so you can evidence that corrective actions were completed and verified. Clause 10.2 requires you to review the effectiveness of corrective action, not just complete it, and “corrective actions not effectiveness checked” is one of the most common findings I raise.
Common ISO 9001 Audit Findings
Most findings are not major failures. Most organisations are already doing the right things. The problem is usually that they have not retained enough evidence to demonstrate those things happened consistently.
These are the ones I raise most often.
| Clause | Common finding |
|---|---|
| 6.2 | Quality objectives not measurable |
| 7.2 | Competence evidence missing |
| 8.2 | Customer requirements not formally reviewed |
| 8.3 | Design and development activities incorrectly excluded |
| 8.4 | Supplier evaluation and reviews missing |
| 9.2 | Internal audits overdue |
| 9.3 | Management review inputs incomplete |
| 10.2 | Corrective actions not effectiveness checked |
Clause 8.3 deserves particular mention. A great many organisations I see exclude design and development on the basis that they do not design products, when in practice they are designing services, configurations or bespoke solutions for customers. It is one of the most frequently misapplied exclusions in the standard, and the clause checklist prompts you to check whether any exclusion is actually justified.
So, recently I conducted an internal audit for a small company that had handed their QMS over to a new owner within the organisation. They’d misunderstood this and thought it was about designing software, which they didn’t do, so they effectively skipped it.
Are You Ready for an ISO 9001 Audit?
Answer honestly rather than optimistically.
| Question | Yes | No |
|---|---|---|
| Do you have defined, measurable quality objectives? | ☐ | ☐ |
| Are your internal audits up to date against your programme? | ☐ | ☐ |
| Can you demonstrate how you monitor customer satisfaction? | ☐ | ☐ |
| Are supplier evaluations documented? | ☐ | ☐ |
| Have corrective actions been effectiveness checked? | ☐ | ☐ |
| Is your management review current and complete? | ☐ | ☐ |
How to read your answers. Every “No” is an area a certification auditor will look at, and each maps to a clause in the table above. One or two are normal and straightforward to close. Three or more suggests the management system is not yet operating as a system, and you will want time to build evidence before booking an audit.
Whatever your score, the free pack walks you through each clause in detail.
Already Certified to ISO 27001?
If you operate both standards, you do not need two separate audit programmes. Clauses 4 to 7, 9 and 10 are substantially shared between ISO 9001 and ISO 27001, so those can be audited once, with standard-specific elements covered separately. The audit procedure in the pack is written to support this.
For most small businesses running both, a single integrated programme is significantly less work than two parallel ones. Read more: ISO 9001 vs ISO 27001
Why Many SMEs Use an Independent Internal Auditor
ISO 9001 requires internal audits to be conducted objectively and impartially. That does not mean you must use an external auditor. In smaller organisations it does mean it can be difficult in practice.
There is a section in the audit plan template asking you to state how objectivity is maintained. In a small business, that box is genuinely hard to fill in honestly, and it is worth pausing on rather than writing something plausible.
- Lack of independence – In many SMEs the person responsible for maintaining the quality management system is also the person expected to audit it. Which raises an obvious question: who audits the person running the system?
- No trained auditor available – Internal auditing is a specialist skill. Plenty of organisations have highly capable technical and operational staff but nobody experienced in audit planning, sampling, evidence gathering, writing findings, or interpreting the standard.
- Lack of time – Audits get postponed because customer delivery takes priority. Certification auditors do not generally accept “we were too busy” as a reason for a missed programme.
- Nobody wants to audit their colleagues – In a small team, people are understandably reluctant to raise findings against processes they helped design or colleagues they work with daily.
An independent auditor brings objectivity, but the more useful thing is often a fresh perspective. Because they are not involved in running the business day to day, they notice the assumptions, workarounds and accumulated habits that everyone inside has stopped seeing.
There is also a practical benefit that gets overlooked. Bringing someone in creates protected time to focus on the management system, which otherwise slides down the priority list. And the system owner gets to participate in the audit as a subject, rather than organising it, conducting it and being audited in it at the same time.
Ready to Assess Your Quality Management System?
Download the free Internal Audit Pack and work through your management system properly. Many SMEs are already meeting large parts of ISO 9001 without realising it. The challenge is usually not creating new processes, but understanding what is already in place, identifying the genuine gaps, and retaining evidence that things happen consistently.
If you would prefer an experienced auditor to carry out an independent review, we offer a fixed-fee ISO 9001 internal audit service for SMEs. It is designed for organisations that need independence, additional audit expertise, or simply extra capacity ahead of certification or a surveillance audit.
Download the Free ISO 9001 Internal Audit Pack
Learn more about our ISO 9001 Internal Audit Service
Frequently Asked Questions
Is an ISO 9001 audit checklist mandatory?
No. ISO 9001 requires you to plan and conduct internal audits at planned intervals, but does not specify that you must use a checklist. Most auditors use one because it supports consistency and gives you a record of what was examined.
How often do internal audits need to be carried out?
The standard requires audits at planned intervals and sets no fixed frequency. Most organisations audit every process at least once across a rolling twelve-month cycle, weighted so that higher-risk or recently changed processes are audited more often.
Do I need a documented internal audit procedure?
ISO 9001:2015 does not mandate a documented procedure for internal audit, but it does require you to retain documented information as evidence of the audit programme and results. In practice most organisations write one, because it makes the programme repeatable and gives the certification auditor something to assess.
What is the difference between a readiness review and an effectiveness audit?
A readiness review checks whether the required elements are defined, approved, published and communicated, and is used before certification. An effectiveness audit checks whether processes are implemented and working, supported by operational records.
What is the difference between a readiness review and an effectiveness audit?
A readiness review checks whether the required elements are defined, approved, published and communicated, and is used before certification. An effectiveness audit checks whether processes are implemented and working, supported by operational records.
What is the difference between a readiness review and an effectiveness audit?
A readiness review checks whether the required elements are defined, approved, published and communicated, and is used before certification. An effectiveness audit checks whether processes are implemented and working, supported by operational records.
What is the difference between an internal audit and a gap analysis?
A gap analysis assesses your current arrangements against the requirements of the standard, usually before you have a working management system. An internal audit assesses whether the system you have built is being followed and achieving its intended results.
How long should audit records be kept?
There is no fixed period in the standard. Three years is a common choice because it covers a full certification cycle, but set it in line with your own documented information control arrangements.
Does an internal audit have to be carried out by an external person?
No. It has to be objective and impartial. Where a small team makes genuine impartiality difficult, many organisations bring in an independent auditor for that reason.