|
Internal audits can easily become a compliance exercise.
The auditor checks that a procedure exists, confirms that a form has been completed and verifies that a record has been filed. Everything appears to be in place — yet the same production problems, customer complaints or process failures continue to occur. A useful internal audit should do more than confirm that documentation exists. It should help you understand whether a process is working as intended. Start With the Process, Not the Clause When preparing an audit, it is tempting to work through the ISO standard clause by clause. A more useful starting point is the process itself. Before the audit, establish:
That question usually produces much more useful evidence. Follow a Real Transaction Through the Process One of the simplest ways to test a process is to select an actual example and follow it from beginning to end. For a purchasing process, for example, you might select a recent purchase and examine:
For a customer-complaint process, follow an actual complaint from receipt through investigation, corrective action and closure. This approach makes it easier to identify where the documented process and the actual process differ. Ask for Evidence of Effectiveness Compliance and effectiveness are not always the same thing. A calibration may have been completed on time, but are measurement problems still occurring? Employees may have attended training, but can they perform the required task competently? A corrective action may have been closed, but has the problem occurred again? Look beyond evidence that an activity happened. Ask what happened as a result. Useful questions include:
These questions turn the audit into a source of management information rather than simply an inspection. Spend More Time Where the Risk Is Not every process deserves the same level of audit attention. Processes with a strong history of performance may require less frequent or less intensive auditing than areas experiencing:
Use what you already know about the organisation to shape the audit programme. If the same area has produced three customer complaints and two corrective actions during the year, that is probably a better place to spend audit time than a stable process that has produced no significant issues. Turn Findings Into Action An audit only creates value if something happens with what it uncovers. Where an issue is identified, record clearly:
Then follow the issue through to closure. For significant findings, do not stop when the corrective action has been completed. Verify that the action was effective. Use Audits to Understand the Business A strong internal audit programme should give management a better view of how the organisation is operating. Over time, your audit results should help answer questions such as:
That is when internal auditing becomes more than preparation for an external audit. It becomes part of continual improvement.
0 Comments
ISO 9001 is changing. At the time of writing, ISO/FDIS 9001 is the Final Draft International Standard and is expected to replace ISO 9001:2015 in September 2026. (ISO) That does not mean organisations should rush to rewrite every procedure before the final standard is published. Quality managers should instead use this time to strengthen the foundations of their existing Quality Management System. A well-maintained, actively used QMS will always be easier to transition than one that is updated only before an external audit. Start by examining the system you already have The forthcoming edition provides an opportunity for organisations to review and refine their management systems in response to changing business needs, technologies and stakeholder expectations. The sensible response is not to speculate about final clause wording. It is to ask whether your existing system works as intended.
1. Review your process ownership Every key process should have a clearly identified owner who understands:
Meet with process owners and ask them to explain how their processes operate in practice. Where the documented process and the real process differ, determine whether the documentation or the operation needs to change. 2. Clean up your controlled documents Document-control problems often accumulate quietly. Old templates remain in shared folders. Employees save local copies of procedures. Approvals are recorded inconsistently. Review dates pass without action. Superseded documents remain accessible. Begin with a structured document review. Identify documents that are:
A controlled document system should make the correct way of working easier to follow. It should not create an administrative obstacle. 3. Address overdue corrective actions An open corrective action is not automatically a sign of a weak system. An action that remains open indefinitely, has no accountable owner or is closed without checking its effectiveness is a more serious concern. Review your current non-conformances and corrective actions. For each one, confirm that:
Avoid closing an action simply because a task was performed. The real question is whether the action prevented the problem from recurring or reduced the identified risk. 4. Revisit risks and opportunities A risk register should not be a document that is updated once a year for an audit. Review whether your risks still reflect current business conditions. Consider changes involving:
Where possible, integrate risk discussions into normal management meetings rather than treating risk management as a separate compliance exercise. 5. Strengthen your quality objectives Objectives such as “improve quality” or “increase customer satisfaction” are too broad to guide meaningful action. A useful quality objective should establish:
6. Check the integrity of your training records A list of employees who attended a course does not necessarily prove competence. Review whether your training system connects:
When procedures change, determine whether affected employees need communication, retraining or formal reassessment. 7. Improve your internal audit programme Internal audits should help the organisation understand whether its processes are effective. They should not be limited to checking whether a document exists. Plan audits according to process importance, business risk, previous findings and recent changes. A stronger audit programme asks questions such as:
8. Create a formal transition plan Once ISO 9001:2026 is published, conduct a structured gap analysis rather than making disconnected changes. Your transition plan should include:
Do not wait for the external auditor The greatest risk is not that the new standard will introduce an unexpected clause. It is that existing weaknesses will make every change more difficult. Organisations with controlled documents, accountable process owners, current risks, meaningful objectives and effective corrective actions will be in a much stronger position. The transition should be used to improve how the business operates—not simply to update the year printed on a certificate. How IsoRight can help IsoRight provides a central environment for managing controlled documents, risks, objectives, audits, non-conformances, corrective actions, training records, management reviews and assigned tasks. By strengthening these processes now, organisations can create a more reliable foundation for the transition to ISO 9001:2026 while improving their current quality-management performance. ISO 9001 is entering a new chapter. The revised edition of the world’s best-known quality management standard is expected to be published in September 2026, replacing ISO 9001:2015. The revision has reached the Final Draft International Standard stage, which is the final approval phase before publication. Organisations certified to ISO 9001:2015 will receive a transition period in which to update their quality management systems. Although the final standard has not yet been published, organisations should not wait until their next external audit before thinking about the transition. The months ahead provide an opportunity to review the health of your existing quality management system, correct longstanding weaknesses and prepare your team for the transition in a controlled way. What Does the ISO 9001 Revision Mean for Certified Organisations?ISO periodically reviews its standards to ensure that they remain relevant to changing business conditions and stakeholder expectations. ISO is the International Organization for Standardization. It is an independent, non-governmental organisation that brings together experts from national standards bodies to develop internationally agreed standards. These standards cover areas such as quality management, environmental management, occupational health and safety, information security and AI governance. ISO develops the standards, but it does not certify companies itself; certification is performed by independent certification bodies. Official website: www.iso.org ISO 9001:2015 has now been in use for more than a decade. Since its publication, organisations have experienced major changes in areas such as technology, supply chains, remote work, customer expectations, organisational knowledge and the availability of data. The revised standard is intended to ensure that ISO 9001 remains aligned with the needs of modern organisations. ISO has described the publication as an opportunity for certified organisations to review and refine their quality management systems so that they continue to meet organisational, customer and stakeholder needs. Once the final edition is published, organisations will need to understand the changes, assess their current systems and implement the necessary updates within the transition period. Do You Need to Act Immediately?There is no need to rewrite your quality management system before the final standard is available. Draft editions can still change during the standards-development process. Organisations should therefore avoid making significant changes based only on preliminary interpretations. However, there is a great deal of useful preparation that can begin now. A strong, well-maintained quality management system will be considerably easier to transition than one that is only updated immediately before an audit. This is a good time to ask:
A Practical ISO 9001 Transition ProcessOnce ISO 9001:2026 is published, organisations should approach the transition as a managed improvement project. 1. Understand the final changes Obtain an authorised copy of the new standard and review reliable guidance from ISO, your certification body or an experienced ISO consultant. Avoid relying entirely on informal summaries. Your organisation needs to understand how the final requirements apply to its own context and processes. 2. Conduct a structured gap assessment Compare your existing quality management system with the requirements of the new edition. The assessment should identify:
3. Assign responsibilities and deadlinesEvery transition action should have:
4. Update your controlled information Policies, procedures, process maps, forms and other controlled information may need to be revised. Changes should follow an appropriate document-control process that records:
5. Train employees and process owners Employees need to understand how changes affect their work. Training should be proportionate to each person’s role. A process owner may need detailed training, while other employees may only require awareness of an updated procedure or responsibility. Training records should demonstrate that the organisation did more than circulate a document by email. 6. Implement and test the changes Updated processes should be used for a sufficient period to generate evidence that they are working. Organisations should not wait until the transition audit to discover that a revised process has not been properly implemented. 7. Conduct an internal transition audit Your internal audit programme should assess whether the updated system conforms to the new edition and whether the changes are effective in practice. Any findings should be addressed before the certification transition audit. 8. Complete a management review Senior management should review the transition process, including:
9. Coordinate with your certification body Your certification body will advise you how and when the transition audit will be incorporated into your certification cycle. Confirm the arrangements early so that your transition plan aligns with your surveillance or recertification schedule. Why Manual Transition Management Becomes DifficultMany organisations still maintain their quality management systems through a combination of spreadsheets, shared folders, email reminders and Word documents. This creates challenges during a standards transition. It can become difficult to determine:
How IsoRight Supports the ISO 9001 TransitionIsoRight provides a central online platform for implementing, maintaining and improving a quality management system. Organisations can use IsoRight to:
Use the Transition to Improve the BusinessA standards transition should not be treated as an exercise in changing clause numbers or updating document headings. It is an opportunity to ask whether your quality management system is genuinely helping your organisation:
Begin Preparing for ISO 9001:2026The final requirements and formal transition arrangements will become clearer following publication of ISO 9001:2026. Organisations that begin reviewing their existing systems now will be better positioned to respond. They will have fewer outdated documents, fewer unresolved corrective actions and a clearer understanding of the weaknesses in their current QMS. IsoRight can help your organisation centralise its quality information, manage transition actions and prepare reliable evidence for internal and external audits. Speak to the IsoRight team about preparing your quality management system for the ISO 9001:2026 transition. |
ISO Quality Management News & Insights
Categories
All
Posts
August 2026
|
RSS Feed