Who is ISO 9001 certification for?
ISO 9001 suits organisations whose customers depend on consistent delivery and who need that consistency to be demonstrable. It is used most often by:
- Manufacturers and processors where consistency of output is a contractual expectation.
- Engineering, construction and trade contractors asked for certification as a condition of tender or prequalification.
- Professional and technical service firms formalising delivery so that it survives growth and staff turnover.
- Suppliers inside a certified customer's supply chain who are asked to demonstrate equivalent control.
ISO 9001 is the most widely held management system standard, and it is usually the first one an organisation is asked for. That familiarity works against it. The standard is often treated as a documentation exercise when it is really a test of whether an organisation understands and controls its own processes.
What does an ISO 9001 audit assess?
Our audit examines the management system against ISO 9001:2015 and against the arrangements you have stated for yourself. We look at:
- Context: the internal and external issues that affect the organisation, and the interested parties whose requirements matter.
- The scope, including any requirement determined not to be applicable and the justification recorded for that position.
- The processes needed for the management system, their sequence and interaction, their inputs and outputs, and how each is measured.
- Leadership, customer focus, the quality policy and the objectives set beneath it.
- Risk-based thinking: the risks and opportunities identified, the actions taken, and evidence of whether those actions worked.
- Operational planning and control, including design and development where that activity is within scope.
- Control of externally provided processes, products and services, and the criteria used to evaluate providers.
- Release of products and services, control of nonconforming output, and traceability where it is required.
- Monitoring and measuring resources, including calibration where measurement affects conformity.
- Customer satisfaction, internal audit, management review, nonconformity, corrective action and improvement.
Certification confirms that the management system meets the standard within the certified scope. It is not a statement that every product or service is free of defects, and it is not product certification.
How does ISO 9001 certification work?
Application and review
You describe your activities, sites, headcount, the processes within the requested scope, and any processes performed by others on your behalf. We determine the competence required, the audit time applicable under the scheme, and whether we can take the work impartially.
Stage 1
We examine readiness for Stage 2: how the scope is drawn and any requirement set aside as not applicable, how processes are defined and measured, internal audit and management review records, and your understanding of the standard.
Stage 2
We test implementation and effectiveness across the processes and sites in scope. Sampling follows the work as it is actually performed rather than the documents that describe it.
Correction and corrective action
Where nonconformities are raised, you analyse cause and act. We review the response and verify effectiveness as required before a decision can be made.
Independent certification decision
Competent personnel who were not members of the audit team review the audit information and make the certification decision.
Surveillance and recertification
Surveillance audits monitor continuing conformity through the cycle, with attention to customer complaints, changes to processes or sites, and the actions taken on previous findings.
Each stage is described in full on our certification process page.
What evidence should you prepare for an ISO 9001 audit?
Bring the records the business already generates in the course of doing the work. For ISO 9001 we normally expect to see:
- A scope statement naming activities and sites, and any requirement determined not to be applicable together with its justification.
- A process map or equivalent showing sequence and interaction.
- The quality policy and measurable quality objectives, with current performance against them.
- Records of risks and opportunities and the actions arising from them.
- Operational records for the work itself: planning, work instructions where they are needed, inspection and verification, and release records.
- Design and development records where design sits within the scope.
- Supplier evaluation criteria, evaluation records and ongoing performance monitoring.
- Calibration and verification records for measuring equipment that affects conformity.
- Records of nonconforming output, customer complaints and their resolution.
- Customer satisfaction information, and an explanation of how it was obtained.
- The internal audit programme and reports, and management review inputs and outputs.
- Competence, training and awareness records for roles that affect quality.
What are the most common ISO 9001 readiness gaps?
These are the issues that most often delay a Stage 2 audit or generate findings.
- Procedures describing another organisation. Template manuals bought or inherited, written in terminology nobody in the business actually uses.
- Objectives without measurement. Quality objectives stated as intentions, with no metric, no target and no record of performance.
- Requirements set aside without justification. Clauses treated as not applicable where the activity is in fact performed, most commonly design and development.
- Correction mistaken for corrective action. The immediate problem is fixed and the record closed, with no analysis of cause and no check that the fix held.
- Internal audit that is not risk-based. The same checklist applied each year to the same straightforward processes, leaving the areas carrying real risk untested.
- Supplier control resting on familiarity. Long-standing suppliers accepted without criteria, evaluation or performance monitoring.
- Customer satisfaction inferred from silence. An absence of complaints is not a measurement.
- Management review without decisions. The required inputs are listed, but no output can be produced.
ISO 9001 enquiries
Show us how the work is actually done.
Tell us your activities, sites and approximate headcount, and which processes you would place inside the scope. We will explain what an ISO 9001 engagement would involve and what evidence to prepare.
Start an enquiryRelated information
- What we certify — our full certification scope.
- Certification process — every stage from application to recertification.
- ISO/IEC 27001 certification — information security management systems.
- ISO/IEC 42001 certification — artificial intelligence management systems.
- Impartiality statement — how independence is protected.
- Complaints and appeals — how to raise a concern or challenge a decision.
- Contact — the scoping enquiry form.
General enquiries: info@acscert.com.au. Complaints and appeals: complaints@acscert.com.au.
