ISO 9001 audit readiness: a step-by-step guide and checklist for regulated manufacturers

Preparing for an ISO 9001 audit comes down to four key things: 

  1. Keeping your documented information current and under control
  2. Showing that your processes run the way you say they do
  3. Closing out open nonconformities before the auditor arrives 
  4. Rehearsing the whole thing through an internal audit. 

Get those four right and the audit itself holds no surprises.

This guide works through each stage in the order a ISO 9001 certified manufacturer should tackle it, from first planning to the day itself.

The additional downloadable checklist turns it into something your team can work through clause by clause.

Download the full checklist

It is written for quality managers at manufacturers who are already certified and preparing for a surveillance or recertification audit, not for first-time certification. 

If you run a live ISO 9001:2015 system and want to walk into your next audit without the last-minute scramble, this is for you. We also cover what to expect under the new ISO9001: 2026 standard and handling the transition period. 

The effort pays back well beyond the certificate itself. According to BSI research, 66% of businesses that achieved ISO 9001 certification reported improved product or service quality, 60% experienced a reduction in errors and 65% noticed increased consumer trust.

What is an ISO 9001 audit?

An ISO 9001 audit is an independent check that your quality management system meets the requirements of the standard and works in practice, not only on paper (or even better, in a digital system).

For a company that is already certified, it is not a single event. It is a recurring cycle made up of three audit types, each with a different scope and a different level of risk attached.

Internal audits are your own check against your own system. They are a requirement of the standard, clause 9.2, not an optional extra and they are your best chance to find and fix problems before your certification body does.

Surveillance audits are carried out by your certification body, usually once a year. They sample part of the system rather than reviewing all of it and they confirm that your certification remains valid.

Recertification audits reassess the whole QMS end to end on a three-year cycle. This is the full review that renews your certificate for the next three years.

Across all three, the auditor is looking for objective evidence: records and demonstrable practice, not verbal assurance. If you cannot show it, in the auditor’s eyes it did not happen.

Internal vs surveillance vs recertification audit

Audit type Who runs it How often What it covers Typical length
Internal Your own team, or a contracted auditor At planned, risk-based intervals. ISO 9001 does not require one complete QMS audit every year; the audit programme should cover relevant processes and requirements over the planned cycle The organisation’s QMS processes and requirements, including implementation, effectiveness, risks, nonconformities, corrective actions and improvement opportunities Variable. Often several focused audits distributed across the year rather than one fixed whole-system audit. A rough planning allowance is 5–15 internal auditor-days annually, depending on complexity, shifts, sites and scope
Surveillance Your certification body or registrar Normally annually in years 1 and 2 of the three-year certification cycle. In the US, the annual time may instead be split into two visits roughly six months apart A representative sample of the QMS, relevant processes, performance data, internal audits, management review, corrective actions and follow-up of previous findings. It is not normally a complete re-audit of every requirement A representative sample of the QMS, relevant processes, performance data, internal audits, management review, corrective actions and follow-up of previous findings. It is not normally a complete re-audit of every requirement
Recertification Your certification body or registrar Every 3 years, before the certificate expires A broader reassessment of the QMS, including continuing suitability, effectiveness, performance, changes, risks, key processes and evidence from the previous certification cycle Usually around two-thirds of the audit time that a new initial certification audit would require at that point. Often approximately 3–6 audit days for a mid-size, single-site manufacturer

When should you start preparing for an ISO 9001 audit?

Start about 90 days out for a recertification audit and 30 to 60 days out for a surveillance visit. The earlier you begin, the more room you have to fix problems through your own internal audit rather than have the certification body raise them for you.

Two things can push that start date earlier. If you use an outsourced internal auditor, booking them can take weeks, so plan to begin at 100 to 120 days for a recertification. Also if you run multiple sites or carry a sector overlay such as IATF 16949 or AS9100, add time for the extra evidence those schemes require.

The roadmap to audit confidence

90 days out

Book and complete your internal audit, confirm the scope and date with your certification body and review the last audit report along with every finding it raised. If your internal auditor is external, arrange this first, as it usually has the longest lead time.

60 days out

Close out the nonconformities your internal audit raised, plus anything still open from last time. Check that calibration and training records are current.

30 days out

Confirm your scheduled management review has taken place within your normal cycle and that its actions are tracked. A review held purely to tick the box the month before an audit is easy for an auditor to spot. Confirm your quality objectives and KPI data are up to date and brief the process owners who will speak to the auditor.

7 days out

Run a final documented-information check, make sure any record can be retrieved in minutes and confirm who is available on the day.

If your next audit is a transition audit to ISO 9001:2026, add a gap analysis against the 2026 changes, update the documented information they affect and train staff on the new requirements before the audit.

Preparing for an audit under ISO 9001:2026 (the transition)

ISO 9001:2026 is expected to publish in September 2026, with a three-year transition period, so certified manufacturers have until around September 2029 to move across. The good news is that you will not need a separate audit. The transition is normally assessed as part of a scheduled surveillance or recertification visit, which is exactly why it belongs in your audit-readiness planning now.

What is expected to change in ISO9001:2026:

  • Climate and sustainability become an explicit part of your organizational context (clause 4), formalizing the 2024 amendment.
  • Risk and opportunity are separated more clearly in clause 6.1, so opportunities are pursued deliberately rather than treated as the flip side of risk.
  • Quality culture and ethical behavior become something you are expected to demonstrate, not just state.
  • The quality policy is tied more tightly to your strategic direction.
  • Change management gets sharper expectations, with a clearer trail from request through approval, communication and verification.
  • Supply-chain resilience is called out in its own right, with more expected from how you evaluate, monitor and can substitute critical external providers. 
  • A new guidance annex (Annex A) is included for the first time, giving standardized interpretation to reduce how much findings vary between auditors.

Where the 2026 changes will be easiest and hardest to evidence

In our experience, updating documents is the straightforward part. The two changes that give quality teams the most trouble are the ones that ask you to prove behavior rather than produce a record: quality culture and change management.

Quality culture is hard to evidence precisely because it is not a document. 

An auditor wants to see that good practice is embedded in how people work every day, not filed in a manual nobody opens. This is where a QMS that people genuinely use on the floor does the work for you. When everyone is working from the current instruction and the system captures what they actually do, quality culture stops being a claim and becomes something you can show.

Change management has been core to Singlepoint QMS for more than twenty years and it is an area few QMS platforms handle well. A controlled change in Singlepoint QMS, from request through approval, communication and verification, leaves exactly the trail the revised standard is looking for. 

Kasai, a tier 1 automotive supplier, replaced spreadsheet-and-email engineering change control with Singlepoint QMS and now keeps a complete, centralized change history. As their Quality Manager put it: 

“Now that everything’s in Singlepoint, we have one central repository and we can find the change history without having to chase around departments searching for paperwork.

Going paperless has also helped to save money and having a full history of changes means that when an audit falls, there’s no problem.”

The ISO 9001 audit readiness checklist 

An ISO 9001 audit checklist follows the structure of the standard, clauses 4 to 10. The best way to use it is as a set of questions: for each item, can you put your hand on the evidence an auditor would ask for? If the answer is “not quickly,” that is your prep list.

The key readiness points for each clause are below. The full checklist, including the pre-audit, on-the-day and manufacturing-specific sections, is available in our downloadable version.

Clause What an auditor wants to see
4 · Context QMS scope is current and the process map matches how the business actually runs
5 · Leadership Quality policy is live and understood on the floor, with recent evidence of management review
6 · Planning Risks and opportunities have been actioned and quality objectives are tracked with visible progress
7 · Support Competence and training records, calibration and controlled documents are all current
8 · Operation Production and inspection records, control of nonconforming product, supplier control and traceability are in place
9 · Performance evaluation Internal audit is complete and KPIs, customer feedback and management review are up to date
10 · Improvement Nonconformities are logged and corrective actions are closed with verified effectiveness

 

Download our audit readiness checklist

What auditors actually check on a manufacturing site

On the shop floor an auditor is looking for evidence that quality is controlled in practice, not just described in a manual. 

They gravitate toward the areas that are hardest to reconstruct after the fact, because that is where a system either holds up or frankly falls apart.

Expect them to start at the measuring equipment. Is it in calibration and can you produce the certificate at the point of use rather than after a trip to a central log? 

From there they tend to follow a single job through production, checking that the records match the work instructions and that nothing is missing. They will want to see how a rejected part is identified, segregated and dispositioned, so it cannot find its way back into the flow by accident. They will ask how you evaluate and monitor your suppliers and they will check that the people doing the work are trained for it, with the record to prove it.

Across all of these, the auditor is really testing two things: how well you have translated each clause into what your business actually does and how quickly you can produce the evidence. 

Much of that evidence, controlled SOPs, calibration records, training records, nonconformity records and supplier data, is exactly what a digital QMS keeps in one place and can retrieve at the workstation. 

The most common ISO 9001 non-conformities (and how to close them)

Most non-conformities raised in a manufacturing surveillance audit are not outliers. They cluster around the same handful of failures year after year and published audit findings back this up. In practice they come down to three things: documents that are not under control, records that are missing and corrective actions that were raised but never properly closed. All three are avoidable with a little discipline before the audit.

It helps to know what you are risking. A minor non-conformity is an isolated lapse. A major is a systemic failure or an absent process and it can put your certification at risk. Closing either one properly means identifying the root cause, taking a corrective action and showing evidence that the action worked, not just that it happened.

These are the five reported most often. 

  1. Document control — clause 7.5

People are using obsolete documents, or cannot access the current approved version. Use one controlled source, remove superseded copies and keep the shop floor aligned with the latest revision.

  1. Corrective action — clause 10.2

Actions are closed on paper, but the cause was not addressed and the problem returns. Link every finding to its cause, action, evidence and effectiveness review.

  1. Calibration — clause 7.1.5

Equipment is overdue, incorrectly labelled or missing supporting records. Maintain a live equipment register with owners, due dates, status and reminders.

  1. Internal audits — clause 9.2

Audits are late, too superficial, miss key processes or fail to follow up findings. Use a risk-based programme with clear ownership and verified closure.

  1. Competence — clause 7.2

Training records are incomplete, outdated or fail to show that people are competent. Link roles to required skills, qualifications and work instructions and assess whether document changes require retraining.

The common thread is that every one of these is a manual-process failure. Move the same task onto a system that manages it proactively and the finding never arises. 

That is the real shift a digital QMS delivers: instead of scrambling to become audit-ready in the weeks before a visit, you are audit-ready every single day.

How a digital or eQMS makes you audit-ready

A digital quality management system keeps your documents under control, links every non-conformity to its corrective action and evidence of closure and produces a complete, timestamped trail the moment an auditor asks for it.

Singlepoint QMS was built for exactly this, because four things matter most when an auditor is in the building:

  • Document control, so everyone works from the current version and obsolete copies are withdrawn rather than left to linger on a shared drive.
  • NCR-to-CAPA linkage, so a non-conformity, its root cause, the corrective action and the evidence of closure sit together and nothing is left half-finished.
  • A complete audit trail, a single timestamped record of who did what and when, which is exactly what an auditor asks to see.
  • Floor-level access people actually use. Concurrent-user licensing means you pay for active sessions, not headcount and the Fair Use Policy gives every employee unlimited view-only access with no license. Staff on shared terminals reach the current instruction the same day it changes.

Take the most common finding of all, document control. ZF, the global automotive technology group, runs around 4,000 manufacturing documents and CAD drawings for roughly 200 users on Singlepoint QMS, with shop-floor operators on controlled view-only access. As senior quality engineer Stella Wilkes put it: “With the old system there was the possibility of someone using the incorrect version, thus a potential for making scrap. That cannot happen anymore.” The version problem that sits behind most non-conformities simply stops being possible.

And when the audits themselves come around, the payoff shows up at scale. Amcor, a global packaging manufacturer operating across more than forty countries, has run its controlled documentation on Singlepoint QMS for over a decade. Quality systems manager Irene Garcia, who is responsible for internal and external audits, keeps every policy, SOP and record, with full version history, in one controlled system. 

“Singlepoint keeps everything together nicely with all the previous versions… Operators can only view and print, whilst line managers have access to change and obsolete documents.” 

Download our audit readiness checklist

ISO 9001 audit preparation FAQ

How long does an ISO 9001 audit take?
For a mid-size manufacturer of roughly 50 to 200 employees, a surveillance audit is usually one to two days on site. A recertification audit takes longer, often two to three days, because it reassesses the whole system. Your certification body sets the exact duration under IAF MD 5, based mainly on your headcount, number of sites and the complexity of your processes.

What is on an ISO 9001 audit checklist?
It follows clauses 4 to 10 of the standard: context, leadership, planning, support, operation, performance evaluation and improvement. For each clause, you should be able to produce the evidence an auditor would ask for. Our downloadable checklist works through every one.

What are the 5 C’s of audit findings?
Criteria, condition, cause, consequence and corrective action. These are the five elements a well-written audit finding should capture: the requirement, what was actually found, why it happened, its impact and what will be done about it.

What are the 7 principles of ISO 9001?
Customer focus, leadership, engagement of people, process approach, improvement, evidence-based decision making and relationship management. These are the quality management principles the whole standard is built on.

What is the difference between a surveillance and a recertification audit?
A surveillance audit is an annual check on part of your system, carried out between certification cycles. A recertification audit is a full reassessment of the entire QMS, carried out every three years to renew your certificate.

Does ISO 9001 require an internal audit?
Yes. Clause 9.2 requires you to run internal audits at planned intervals, to confirm your QMS conforms to the standard and is working effectively.

Do I need to recertify for ISO 9001:2026?

No separate recertification is required. You transition to the new edition during a scheduled surveillance or recertification audit within the three-year window, so plan the change into your normal audit cycle.

 

Download our ISO 9001 Audit Readiness Checklist

 

    View more case studies

    Horizons: From barely visible to ISO 9001 audit-ready

    Horizons: From barely visible to ISO 9001 audit-ready

    Horizons Incorporated had a document control system, but adoption never spread beyond the core quality team. At audit the answer was technically yes; in practice, most of the workforce did not know it existed. After evaluating six vendors, Horizons chose Singlepoint for its concurrent user licensing, visual navigation, and cross-module traceability. A back-end migration from Waypoint kept implementation to weeks, not months. The result: whole-workforce access without per-seat cost, a complete corrective action audit trail, and a first surveillance audit that impressed an examiner the team had never met. Adoption itself now serves as a live quality signal.

    read more
    Doncasters Trucast: Strengthening NPI & Audit Governance

    Doncasters Trucast: Strengthening NPI & Audit Governance

    Doncasters Trucast, a recognised leader in precision investment castings and turbine components, needed to strengthen governance and traceability within its New Product Introduction process. Operating in highly regulated mobility and aerospace-related markets, the business required a more structured, auditable and scalable approach to gated project management. By implementing Singlepoint’s configurable NPI module, Doncasters Trucast introduced electronic gate approvals aligned to regulatory standards, improving visibility, accountability and compliance. The result has been sustained zero audit findings related to NPI for over three years, alongside reduced administrative burden and improved real-time insight for engineering, quality and customer-facing teams.

    read more
    FMP: Delivering 4,000 Hours of Efficiency Gains

    FMP: Delivering 4,000 Hours of Efficiency Gains

    FMP, one of the UK’s leading manufacturers of medical devices and healthcare products, needed to replace its manual, paper-based processes with a more efficient, compliant system. After evaluating 15 platforms across two review cycles, Singlepoint stood out as the clear leader for its flexibility, scalability and ease of use. By implementing Singlepoint’s document management and training modules, FMP achieved measurable time savings of 4,000 hours per year and significantly improved audit readiness.

    read more
    Faltec: ERP Integration and Audit Efficiency

    Faltec: ERP Integration and Audit Efficiency

    Faltec Europe streamlined operations and enhanced compliance by replacing outdated systems with Singlepoint. Discover how seamless ERP integration and centralised document management transformed their digital workflow.

    read more
    UTAC: Driving Quality and Efficiency with Integrated Quality Management

    UTAC: Driving Quality and Efficiency with Integrated Quality Management

    UTAC UK, a leading provider of powertrain and engine testing services, faced challenges with outdated paper-based quality management processes. Senior Manager Peter Davies sought a modern, integrated solution to streamline operations across multiple sites. By implementing Singlepoint’s adaptable platform, UTAC UK digitised their entire quality management system, including document control, auditing and risk management

    read more
    Amcor: Document Management

    Amcor: Document Management

    “Singlepoint is a very good system for control of documentation. You have everything on the system and it’s user-friendly. Everybody in the company can use it.” – Irene, Quality Systems Manager

    read more
    Mentholatum: audit-ready under FDA scrutiny

    Mentholatum: audit-ready under FDA scrutiny

    The Mentholatum Company, a US OTC and consumer health manufacturer regulated under cGMP and 21 CFR Part 11, was managing quality documentation on local servers and network drives, with no single system of record, no reliable audit trail, and real exposure to ransomware. After a recommendation from its UK affiliate, Mentholatum deployed Singlepoint for document control across its Orchard Park and Horsham sites. A 2026 cloud migration removed dedicated server hosting and saved over $18,000 a year, while delivering 24/7 access for a three-shift operation. Every operator can now pull up a current, controlled SOP the moment an auditor asks.

    read more
    Hitachi Rail: Multi-site implementation

    Hitachi Rail: Multi-site implementation

    Hitachi Rail Europe, Ltd. is a wholly owned subsidiary of Hitachi, Ltd. and a total railway system supplier offering rolling stock, traction equipment, signalling, traffic management systems and maintenance centres.

    read more