
ISO 9001 Explained.
The Standard, The Process, And What Auditors Actually Check
ISO 9001:2015 is the international standard for a Quality Management System. This guide covers how certification works, the clauses an auditor will test, and the evidence they expect behind every process you claim to run.
the certification journey
Stage 1 To Recertification.
Certification runs on a three-year cycle. It begins with two audits, continues with annual surveillance, and ends with a full recertification in year three.
Stage 1 — Readiness Review
Is the QMS documented?
The auditor reviews your scope, quality policy, process map, risk and opportunity register, quality objectives and internal audit records. Findings raised here must be closed before Stage 2.
Stage 2 — Certification Audit
Is it actually working?
Typically 2–8 weeks after Stage 1. The auditor traces real jobs end to end — order through to delivery — sampling records, interviewing staff and testing whether your processes run as documented.
Surveillance — Years 1 & 2
Has it stayed alive?
Shorter annual audits. Internal audit, management review, customer complaints, corrective actions and any change to scope, processes or suppliers are always in scope.
Recertification — Year 3
Does it still hold up?
A full audit of the entire QMS, similar in depth to Stage 2, before a new three-year certificate is issued.
clauses 4 to 10
The Processes Auditors Audit.
Clauses 4–10 are the mandatory requirements. ISO 9001 is built on the process approach — the auditor follows your processes, not your org chart.
Clauses 4 & 5 — Context & Leadership
Scope, processes and accountability.
Defining scope and interested parties, identifying your processes and how they interact under Clause 4.4, a quality policy, and demonstrable top-management commitment including customer focus.
Clause 6 — Planning & Risk
Risk-based thinking, applied.
Risks and opportunities identified and addressed, measurable quality objectives with plans to achieve them, and planning of changes so they do not break the system.
Clauses 7 & 8 — Support & Operation
Resources and delivery.
Competence and awareness, calibrated monitoring and measuring resources, documented information — plus operational control: customer requirements, design and development, supplier control and service provision.
Clauses 9 & 10 — Evaluation & Improvement
Measure, correct, improve.
Monitoring including customer satisfaction, analysis of data, internal audit, management review, control of nonconforming outputs, corrective action and continual improvement.
the process approach
Processes, Not Departments.
Clause 4.4 is what makes ISO 9001 different. You must determine your processes, their sequence and interaction, and how you control them. Auditors audit the process end to end.
Determine Your Processes
What actually happens here?
Identify the processes needed for the QMS — sales, design, purchasing, production, delivery, support — and what each needs as inputs and produces as outputs.
Sequence & Interaction
How they hand over.
Map how processes connect. Most nonconformities live at the handovers, where one process assumes another has already done something.
Criteria & Methods
How you know it worked.
Define the criteria, methods, measures and indicators needed to make sure each process is both operating and being controlled effectively.
Risk-Based Thinking
What could go wrong.
Risks and opportunities considered for each process, with actions proportionate to their potential impact on conformity and customer satisfaction.
quality in daily practice
Where Findings Come From.
These four areas generate a disproportionate share of ISO 9001 nonconformities — usually because the process exists but the records do not.
Nonconforming Output
Clause 8.7.
When something is wrong you must identify it, control it so it cannot be used by mistake, decide what to do, and keep records of the decision and who authorised it.
Calibration
Clause 7.1.5.
Any equipment used to prove conformity must be calibrated or verified against traceable standards, identified, safeguarded, and reviewed if later found out of calibration.
Supplier Control
Clause 8.4.
Criteria for selecting and evaluating external providers, records of that evaluation, and controls proportionate to the impact the supplier has on your product or service.
Customer Satisfaction
Clause 9.1.2.
You must monitor customer perception, not just count complaints. Surveys, feedback, delivery performance and returns all count — provided you analyse them.
audit evidence
Evidence, Not Intentions.
Auditors sample. They pick a process, ask to see it working, and follow the trail. These four areas account for most findings.
A Complete Internal Audit
The most common gap.
Your internal audit programme must cover the whole QMS across the cycle, be run by someone independent of the area audited, and have findings closed out with evidence.
A Real Management Review
Not a diary entry.
Minutes covering the required inputs — audit results, customer feedback, process performance, nonconformities, supplier performance, risks and improvement — with decisions and actions recorded.
Corrective Action That Sticks
Root cause, not a patch.
Nonconformities investigated to root cause, action taken, and the effectiveness of that action reviewed afterwards under Clause 10.2.
Documented Information
Current, controlled, available.
Documents and records must be identifiable, version-controlled, available where needed and protected — including how you control documents of external origin.
Need Help Getting ISO 9001 Certified?
We build and run ISO 9001 quality management systems for businesses across the UK, Ireland and the Isle of Man — and we stand with you at Stage 1 and Stage 2.













