Compliance

ISO 9001:2015 — what auditors actually look for

ISO 9001:2015 — what auditors actually look for

Preparing for a certification audit becomes far less stressful the moment you understand what the auditor is genuinely trying to confirm. Here is the reassuring truth that transforms the whole experience: it is not to catch you out.

Many teams approach the audit the way a nervous student approaches an exam they are convinced they will fail — with dread, over-preparation, and a temptation to hide anything imperfect. It is a far more accurate, and far more useful, frame to see the audit as an independent second opinion on whether your quality system actually works. The auditor is not hunting for reasons to reject you. They are verifying one deceptively simple thing: that what you say you do is what you really do, and that it reliably produces good results for your customers.

Once you internalise that, everything changes. You stop performing and start showing. You stop hiding gaps and start demonstrating how you manage them. And you begin to get real value from an expert who is spending a day or more studying your business closely — something few outsiders ever do.

What ISO 9001:2015 is really about

At its heart, ISO 9001 asks a handful of honest questions. Does your organisation consistently deliver what it promises? Do you understand your risks? Do you listen to your customers? Do you get better over time? It is not, despite its reputation, about drowning in paperwork. The 2015 revision deliberately reduced the emphasis on rigid, mandatory documentation and increased the emphasis on outcomes, leadership and risk-based thinking. An auditor steeped in that philosophy cares less about the beauty of your manuals and far more about whether your system genuinely functions in the real world.

Stage 1 and Stage 2

Certification usually happens in two stages, and understanding the difference removes a great deal of anxiety.

Stage 1 is a readiness review. The auditor checks that your management system is documented and in place, that you understand the standard, and that you are genuinely ready to be assessed in depth. It often surfaces gaps while there is still comfortable time to fix them before the decision-making assessment. Treat Stage 1 as a gift and an early-warning system, not a hurdle to resent.

Stage 2 is the main assessment: an on-site (or partly remote) evaluation of how your system actually works in practice, across your processes and your people. This is where evidence, not intention, carries the day — where the auditor talks to the people doing the work and looks at the records they produce.

The things auditors focus on

  • Context and leadership. Do the leaders genuinely own the system, or has it been delegated to one person and quietly forgotten? Are roles, responsibilities and authorities clear to the people actually doing the work?
  • Risk-based thinking. Have you identified what could realistically go wrong in your key processes, and planned sensibly for it — rather than only reacting after problems occur?
  • Process evidence. Can you show, with records, that your processes actually run the way your documents describe? Consistency between the two is central to everything.
  • Customer focus. Are you measuring customer satisfaction, capturing complaints, and demonstrably acting on both?
  • Competence. Are the people performing important work trained and competent, with evidence to support it?
  • Improvement. When something goes wrong, do you fix the root cause — or just the visible symptom, so the same problem returns next month?

How to prepare your team

You do not need theatrical, last-minute preparation or a scramble to invent records. You need three straightforward things. First, records that are easy to find, because an auditor’s confidence grows every single time you can produce evidence quickly and calmly. Second, staff who can describe their part of the process in their own words — not recite a memorised script, but genuinely explain what they do and why it matters. Third, honesty about the gaps you already know about. An experienced auditor respects a team that understands its own weaknesses and is visibly working on them far more than one pretending to be flawless, because the pretence never survives contact with the evidence.

During the audit

  • Answer the question that was actually asked — concisely, without volunteering unrelated problems.
  • Show evidence rather than offering opinions or assurances.
  • If you do not know something, say so and offer to find out, rather than guessing.
  • Stay calm and professional; a composed team signals a controlled, well-run system.
  • Take notes on what the auditor observes — it is valuable feedback, not just judgement.

After the audit: findings are a gift

Non-conformities and observations are not punishments. They are, in effect, free consulting from an expert who has just studied your business closely and objectively. A minor non-conformity is a small gap to close; a major one is a signal that part of the system is not yet working as intended. In both cases the right response is identical: investigate the root cause, implement a genuine corrective action that addresses that cause, and verify that it actually worked. Resist the temptation to apply a quick cosmetic fix that makes the finding disappear on paper but leaves the underlying problem alive. Do this properly and your next audit becomes noticeably smoother, because the system is genuinely stronger.

A well-run audit should leave your organisation stronger than it found it.

Common myths

“We need a document for everything.”

You need documented information where it adds value and where the standard specifically requires it — not for its own sake. Excess documentation can actually harm a system by making it too rigid to follow.

“The auditor wants to fail us.”

A reputable auditor wants an accurate result. Passing an organisation that is not ready helps no one, misleads its customers, and ultimately undermines the value of the certificate for everyone who holds it.

“Certification is a one-time event.”

It is a cycle. Surveillance audits keep the system honest between the big assessments, and re-certification renews the whole thing, typically every three years.

The bottom line

Approach the audit as a partnership in improvement rather than a test to survive, and it quietly becomes one of the most useful external checks your organisation receives all year — an honest, expert look at whether you really do what you say you do.

← Back to all insights