IsoRight - Quality & Compliance Management Software
  • About
  • Features
    • Document Control
    • Audits & Inspections
    • Non-Conformances
    • Risk Management
    • Training & Competence
    • Calendar & Tasks
    • Supplier Management
    • Management & Objectives
    • Dashboards & Reporting
    • Customer Complaints
  • Solutions
    • ISO 9001 Software
    • ISO 14001 Software
  • Pricing
  • Demo
  • Free Trial
  • News
  • Contact
  • SIGN IN

Stop Auditing Documents: How to Make Internal Audits Find Real Process Problems

8/21/2026

0 Comments

 
Picture
Internal audits can easily become a compliance exercise.

The auditor checks that a procedure exists, confirms that a form has been completed and verifies that a record has been filed. Everything appears to be in place — yet the same production problems, customer complaints or process failures continue to occur.

A useful internal audit should do more than confirm that documentation exists. It should help you understand whether a process is working as intended.

Start With the Process, Not the Clause

When preparing an audit, it is tempting to work through the ISO standard clause by clause.
A more useful starting point is the process itself.
​
Before the audit, establish:
  • What is the process intended to achieve?
  • Who owns it?
  • What are its important inputs and outputs?
  • What could prevent it from achieving the intended result?
  • How is performance measured?
  • Which other processes does it depend on?
This changes the audit conversation. Instead of asking, “Do you have a procedure for this?” you can ask, “How do you know this process is working?”

That question usually produces much more useful evidence.

Follow a Real Transaction Through the Process

One of the simplest ways to test a process is to select an actual example and follow it from beginning to end.

For a purchasing process, for example, you might select a recent purchase and examine:
  1. How the supplier was selected and approved.
  2. Whether the purchasing requirements were clear.
  3. What happened when the goods were received.
  4. Whether any defects were identified.
  5. How the supplier's performance was recorded.
  6. Whether poor performance resulted in further action.

For a customer-complaint process, follow an actual complaint from receipt through investigation, corrective action and closure. This approach makes it easier to identify where the documented process and the actual process differ.

Ask for Evidence of Effectiveness

Compliance and effectiveness are not always the same thing.

A calibration may have been completed on time, but are measurement problems still occurring?

Employees may have attended training, but can they perform the required task competently?

A corrective action may have been closed, but has the problem occurred again?

Look beyond evidence that an activity happened. Ask what happened as a result.

Useful questions include:
  • What performance measure tells you whether this process is working?
  • What problems have occurred during the past six months?
  • What trends are you seeing?
  • What actions were taken?
  • Did those actions improve the result?
  • What risks have changed since the last audit?

These questions turn the audit into a source of management information rather than simply an inspection.

Spend More Time Where the Risk Is

Not every process deserves the same level of audit attention.

Processes with a strong history of performance may require less frequent or less intensive auditing than areas experiencing:
  • Repeated non-conformances
  • Customer complaints
  • Supplier failures
  • High reject or rework costs
  • Employee turnover
  • Process or equipment changes
  • New regulatory requirements
  • Previous audit findings

Use what you already know about the organisation to shape the audit programme.

If the same area has produced three customer complaints and two corrective actions during the year, that is probably a better place to spend audit time than a stable process that has produced no significant issues.

Turn Findings Into Action

An audit only creates value if something happens with what it uncovers.

Where an issue is identified, record clearly:
  • What was observed
  • What requirement or expected process was not met
  • What evidence supports the finding
  • Who is responsible for addressing it
  • When action is due

Then follow the issue through to closure.

For significant findings, do not stop when the corrective action has been completed. Verify that the action was effective.

Use Audits to Understand the Business

A strong internal audit programme should give management a better view of how the organisation is operating.

Over time, your audit results should help answer questions such as:
  • Where are our processes weakest?
  • Which problems keep recurring?
  • Where are controls not being followed consistently?
  • Which risks are increasing?
  • Where are improvement actions producing results?

That is when internal auditing becomes more than preparation for an external audit. It becomes part of continual improvement.
0 Comments

ISO 9001:2026 is coming: Eight practical steps Quality Managers should take now

7/10/2026

0 Comments

 
Picture
ISO 9001 is changing.

At the time of writing, ISO/FDIS 9001 is the Final Draft International Standard and is expected to replace ISO 9001:2015 in September 2026. (ISO)

That does not mean organisations should rush to rewrite every procedure before the final standard is published.

Quality managers should instead use this time to strengthen the foundations of their existing Quality Management System. A well-maintained, actively used QMS will always be easier to transition than one that is updated only before an external audit.

Start by examining the system you already have
The forthcoming edition provides an opportunity for organisations to review and refine their management systems in response to changing business needs, technologies and stakeholder expectations.

The sensible response is not to speculate about final clause wording. It is to ask whether your existing system works as intended.
  • Can employees find the correct procedures?
  • Are risks reviewed when business conditions change?
  • Do managers understand which quality objectives they own?
  • Are corrective actions completed and checked for effectiveness?
  • Can you demonstrate that decisions are based on reliable information?
These questions matter under the current standard and will remain important under the revised edition.

1. Review your process ownership
Every key process should have a clearly identified owner who understands:
  • The purpose of the process
  • Its required inputs and intended outputs
  • The associated risks and opportunities
  • How performance is measured
  • Which documents and records must be maintained
  • Who is responsible for improvement actions
Do not rely on an organisational chart alone. A job title does not necessarily establish meaningful process ownership.

Meet with process owners and ask them to explain how their processes operate in practice. Where the documented process and the real process differ, determine whether the documentation or the operation needs to change.

2. Clean up your controlled documents
Document-control problems often accumulate quietly.

Old templates remain in shared folders. Employees save local copies of procedures. Approvals are recorded inconsistently. Review dates pass without action. Superseded documents remain accessible.

Begin with a structured document review. Identify documents that are:
  • Outdated
  • Duplicated
  • Awaiting approval
  • Assigned to people who have left the organisation
  • No longer relevant to current operations
  • Inconsistent with how the work is actually performed
Confirm that the current approved version of every important document is clearly identifiable and accessible to the people who need it.

A controlled document system should make the correct way of working easier to follow. It should not create an administrative obstacle.

3. Address overdue corrective actions
An open corrective action is not automatically a sign of a weak system.

An action that remains open indefinitely, has no accountable owner or is closed without checking its effectiveness is a more serious concern. Review your current non-conformances and corrective actions.

For each one, confirm that:
  1. The problem was clearly defined.
  2. The immediate issue was contained.
  3. The underlying cause was investigated.
  4. Responsibility and a due date were assigned.
  5. The agreed action was completed.
  6. The outcome was checked for effectiveness.

Avoid closing an action simply because a task was performed. The real question is whether the action prevented the problem from recurring or reduced the identified risk.

4. Revisit risks and opportunities
A risk register should not be a document that is updated once a year for an audit.

Review whether your risks still reflect current business conditions. Consider changes involving:
  • Customers and contracts
  • Suppliers and logistics
  • Technology and cybersecurity
  • Skills and employee turnover
  • Infrastructure and equipment
  • Regulatory obligations
  • Climate and environmental conditions
  • New products, services or markets
  • Artificial intelligence and automation
Connect important risks to actions, owners and review dates.

Where possible, integrate risk discussions into normal management meetings rather than treating risk management as a separate compliance exercise.

5. Strengthen your quality objectives
Objectives such as “improve quality” or “increase customer satisfaction” are too broad to guide meaningful action.

A useful quality objective should establish:
  • What will be improved
  • How it will be measured
  • The current baseline
  • The intended target
  • The responsible owner
  • The required actions
  • The review frequency
  • The completion date
Quality objectives should also support the organisation’s strategic direction. For example, if customer complaints are concentrated around late deliveries, an objective focused only on product defects may overlook a significant customer concern.

6. Check the integrity of your training records
A list of employees who attended a course does not necessarily prove competence.

Review whether your training system connects:
  • Roles
  • Required skills
  • Qualifications and certifications
  • Completed training
  • Training expiry dates
  • Competency assessments
  • Identified skills gaps
  • Planned development activities
Pay particular attention to employees performing work that can affect product quality, safety, compliance or customer outcomes.

When procedures change, determine whether affected employees need communication, retraining or formal reassessment.

7. Improve your internal audit programme
Internal audits should help the organisation understand whether its processes are effective. They should not be limited to checking whether a document exists.
Plan audits according to process importance, business risk, previous findings and recent changes.

A stronger audit programme asks questions such as:
  • Is the process achieving its intended result?
  • Are responsibilities understood?
  • Are controls being applied consistently?
  • Is the information used to manage the process reliable?
  • Were previous problems addressed effectively?
  • What new risks or improvement opportunities have emerged?
ISO 19011:2026 is the current international guidance standard for auditing management systems. It covers audit principles, audit programme management and the conduct of management-system audits. (ISO)

8. Create a formal transition plan
Once ISO 9001:2026 is published, conduct a structured gap analysis rather than making disconnected changes.
​
Your transition plan should include:
  • Obtaining and reviewing the final standard
  • Identifying changed or clarified requirements
  • Assigning responsibility for each gap
  • Updating relevant documents and processes
  • Communicating changes to employees
  • Providing training where necessary
  • Updating the internal audit programme
  • Reviewing the transition through management review
  • Coordinating the timing with your certification body
Keep evidence showing how each transition action was addressed.

Do not wait for the external auditor
The greatest risk is not that the new standard will introduce an unexpected clause. It is that existing weaknesses will make every change more difficult.

Organisations with controlled documents, accountable process owners, current risks, meaningful objectives and effective corrective actions will be in a much stronger position.

The transition should be used to improve how the business operates—not simply to update the year printed on a certificate.
How IsoRight can help

IsoRight provides a central environment for managing controlled documents, risks, objectives, audits, non-conformances, corrective actions, training records, management reviews and assigned tasks.

By strengthening these processes now, organisations can create a more reliable foundation for the transition to ISO 9001:2026 while improving their current quality-management performance.
0 Comments

ISO 9001:2026 Is Coming: How to Prepare Your Quality Management System for the Transition

7/5/2026

0 Comments

 
Picture
ISO 9001 is entering a new chapter. The revised edition of the world’s best-known quality management standard is expected to be published in September 2026, replacing ISO 9001:2015. The revision has reached the Final Draft International Standard stage, which is the final approval phase before publication. Organisations certified to ISO 9001:2015 will receive a transition period in which to update their quality management systems.

Although the final standard has not yet been published, organisations should not wait until their next external audit before thinking about the transition.
​
The months ahead provide an opportunity to review the health of your existing quality management system, correct longstanding weaknesses and prepare your team for the transition in a controlled way.

What Does the ISO 9001 Revision Mean for Certified Organisations?

​ISO periodically reviews its standards to ensure that they remain relevant to changing business conditions and stakeholder expectations.
ISO is the International Organization for Standardization. It is an independent, non-governmental organisation that brings together experts from national standards bodies to develop internationally agreed standards.
These standards cover areas such as quality management, environmental management, occupational health and safety, information security and AI governance. ISO develops the standards, but it does not certify companies itself; certification is performed by independent certification bodies.
Official website: www.iso.org
ISO 9001:2015 has now been in use for more than a decade. Since its publication, organisations have experienced major changes in areas such as technology, supply chains, remote work, customer expectations, organisational knowledge and the availability of data.
The revised standard is intended to ensure that ISO 9001 remains aligned with the needs of modern organisations. ISO has described the publication as an opportunity for certified organisations to review and refine their quality management systems so that they continue to meet organisational, customer and stakeholder needs.
Once the final edition is published, organisations will need to understand the changes, assess their current systems and implement the necessary updates within the transition period.

Do You Need to Act Immediately?

There is no need to rewrite your quality management system before the final standard is available. Draft editions can still change during the standards-development process. Organisations should therefore avoid making significant changes based only on preliminary interpretations.

However, there is a great deal of useful preparation that can begin now. A strong, well-maintained quality management system will be considerably easier to transition than one that is only updated immediately before an audit.
​

This is a good time to ask:
  • Are our policies, procedures and process documents current?
  • Are responsibilities clearly allocated?
  • Are risks and opportunities reviewed regularly?
  • Are internal audits identifying meaningful opportunities for improvement?
  • Are non-conformances and corrective actions properly closed?
  • Are quality objectives measurable and actively monitored?
  • Are management reviews producing clear decisions and actions?
  • Can we retrieve reliable evidence quickly during an audit?
  • Are employees participating in the quality management system?
  • Is our QMS helping the business improve, or has it become an administrative exercise?
Addressing these questions now will reduce the pressure when the new requirements are confirmed.

A Practical ISO 9001 Transition Process

Once ISO 9001:2026 is published, organisations should approach the transition as a managed improvement project.
​
1. Understand the final changes
​
Obtain an authorised copy of the new standard and review reliable guidance from ISO, your certification body or an experienced ISO consultant.

Avoid relying entirely on informal summaries. Your organisation needs to understand how the final requirements apply to its own context and processes.

2. Conduct a structured gap assessment

Compare your existing quality management system with the requirements of the new edition.

The assessment should identify:
  • Requirements already adequately addressed
  • Existing processes that require minor changes
  • New or revised requirements requiring further action
  • Documents and records that may need updating
  • Training and communication requirements
  • Potential changes to internal audits and management reviews
The result should be a practical transition action plan rather than simply a lengthy report.

3. Assign responsibilities and deadlinesEvery transition action should have:
  • A responsible person
  • A target date
  • A clear expected outcome
  • Supporting evidence
  • A review or approval process
A transition should not become the sole responsibility of the quality manager. Process owners and senior management should be involved wherever changes affect their areas.

4. Update your controlled information

Policies, procedures, process maps, forms and other controlled information may need to be revised. 
Changes should follow an appropriate document-control process that records:
  • What changed
  • Why it changed
  • Who reviewed it
  • Who approved it
  • When the new version became effective
  • Whether affected employees were informed
This ensures that outdated documents are not accidentally used after the transition.

5. Train employees and process owners

Employees need to understand how changes affect their work. 
Training should be proportionate to each person’s role. A process owner may need detailed training, while other employees may only require awareness of an updated procedure or responsibility. Training records should demonstrate that the organisation did more than circulate a document by email.

6. Implement and test the changes

Updated processes should be used for a sufficient period to generate evidence that they are working. 
Organisations should not wait until the transition audit to discover that a revised process has not been properly implemented.

7. Conduct an internal transition audit

Your internal audit programme should assess whether the updated system conforms to the new edition and whether the changes are effective in practice. 
Any findings should be addressed before the certification transition audit.

8. Complete a management review

Senior management should review the transition process, including:
  • The status of the gap-assessment actions
  • Internal audit findings
  • Remaining risks
  • Resource requirements
  • Training progress
  • Changes to objectives or processes
  • Readiness for the transition audit
This provides evidence that the transition is being directed and supported by leadership.

9. Coordinate with your certification body

Your certification body will advise you how and when the transition audit will be incorporated into your certification cycle. 
Confirm the arrangements early so that your transition plan aligns with your surveillance or recertification schedule.

Why Manual Transition Management Becomes Difficult

Many organisations still maintain their quality management systems through a combination of spreadsheets, shared folders, email reminders and Word documents.
This creates challenges during a standards transition.
It can become difficult to determine:
  • Which documents still need to be reviewed
  • Whether the latest version has been approved
  • Which transition actions are overdue
  • Whether employees have received the required training
  • Which internal audit findings remain unresolved
  • Whether sufficient evidence exists for the transition audit
A transition involving dozens of documents, processes and responsible people can quickly become difficult to coordinate manually.​

How IsoRight Supports the ISO 9001 Transition

IsoRight provides a central online platform for implementing, maintaining and improving a quality management system.
Organisations can use IsoRight to:
  • Manage controlled policies, procedures and process documents
  • Maintain document versions and approval histories
  • Record risks and opportunities
  • Set and monitor quality objectives
  • Assign and track transition actions
  • Schedule and conduct internal audits
  • Capture non-conformances
  • Perform root-cause analysis
  • Manage corrective actions
  • Record training and competence
  • Conduct management reviews
  • Maintain supporting audit evidence
  • Monitor progress through central reports and dashboards
These capabilities allow the transition to be managed as part of the organisation’s live quality management system rather than through a separate collection of transition spreadsheets. IsoRight already brings document control, management responsibility, risk, tasks, training, audits and corrective actions together in one environment.

Use the Transition to Improve the Business

A standards transition should not be treated as an exercise in changing clause numbers or updating document headings. It is an opportunity to ask whether your quality management system is genuinely helping your organisation:
  • Improve customer satisfaction
  • ​Prevent recurring problems
  • Strengthen process ownership
  • Make better decisions
  • Reduce rejects and rework
  • Manage risks more effectively
  • Improve employee participation
  • ​Respond faster when quality issues arise
The best outcome is not simply a successful transition audit. It is a more useful, current and effective management system.

Begin Preparing for ISO 9001:2026

The final requirements and formal transition arrangements will become clearer following publication of ISO 9001:2026.
Organisations that begin reviewing their existing systems now will be better positioned to respond. They will have fewer outdated documents, fewer unresolved corrective actions and a clearer understanding of the weaknesses in their current QMS.
IsoRight can help your organisation centralise its quality information, manage transition actions and prepare reliable evidence for internal and external audits.
Speak to the IsoRight team about preparing your quality management system for the ISO 9001:2026 transition.
0 Comments
<<Previous

    ISO Quality Management News & Insights


    ​​Stay up to date with the latest ISO standards, compliance insights and practical guidance to help your  quality and continual improvement.

    Categories

    All
    ISO 14001
    ISO 9001
    Reseller

    Posts

    August 2026
    July 2026
    June 2026
    May 2026
    March 2026
    November 2025

    RSS Feed

IsoRight

About
Reseller
​
News
Request a Demo
​
​Free Trial
Pricing

Features

> Features Overview
> ​Document Control

> Audits & Inspections
> ​Non-Conformances
> ​Risk Management
> ​Training
> ​
Calendar & Tasks
> Supplier Management
> Management Review
> Dashboards & Reports
> Customer Complaints

​Solutions

ISO 9001 Software
ISO 14001 Software


Legal

Website Disclaimer
Privacy Policy 
PAIA
Cookie Policy

Contact Us

​[email protected]
+27 (0)31 303 2299
Get in touch

Picture
Picture
Picture
Find us on Capterra
Isoright Pty Ltd. © Copyright 2026. All rights reserved.
  • About
  • Features
    • Document Control
    • Audits & Inspections
    • Non-Conformances
    • Risk Management
    • Training & Competence
    • Calendar & Tasks
    • Supplier Management
    • Management & Objectives
    • Dashboards & Reporting
    • Customer Complaints
  • Solutions
    • ISO 9001 Software
    • ISO 14001 Software
  • Pricing
  • Demo
  • Free Trial
  • News
  • Contact
  • SIGN IN