Skip to main content
Free tool · Excel

ISO 9001 internal audit checklist

64 audit questions covering every sub-clause of ISO 9001, from context to continual improvement, each with the evidence to look for. Every question is shown below. The Excel version adds a rating drop-down, the same questions grouped by department, a findings log and an audit plan.

The checklist

Audit questions by clause

This is a generalised checklist. It does not set out your organisation's specific requirements. It is a sound starting point, and we recommend tailoring it to your organisation's context, processes, risks and legal obligations. For support on your ISO journey, contact us at [email protected].

Written against ISO 9001:2015 with Amendment 1:2024 (climate action), the edition certification bodies audit to today. ISO 9001:2026 was published in September 2026; see the note at the end of the checklist.

Clause 4 Context of the organisation

  1. 4.1 Internal and external issues

    Has the organisation identified the internal and external issues that affect its purpose, strategy and ability to deliver conforming products and services, and does it monitor and review them?

    Evidence: Context analysis (SWOT, PESTLE or similar) with a review date; management review minutes showing the issues were revisited

  2. 4.1 Climate change

    Has the organisation decided whether climate change is a relevant issue for its quality management system, and recorded the reasoning either way?

    Evidence: Context analysis naming climate change and the conclusion reached; link to risks and opportunities where it is relevant

  3. 4.2 Interested parties

    Are the interested parties relevant to the quality management system identified, with their requirements, including any climate-related requirements, and are these kept under review?

    Evidence: Interested parties register with requirements and review date; customer and regulator requirements traced into the system

  4. 4.3 Scope

    Is the scope documented, stating the products, services and sites covered, and is every requirement treated as not applicable justified on the basis that it does not affect conformity or customer satisfaction?

    Evidence: Scope statement; justification for any exclusion (for example design and development); certificate scope matches

  5. 4.4.1 Processes and interactions

    Are the processes of the quality management system defined, with their inputs, outputs, sequence, criteria, resources, responsibilities, risks and performance measures?

    Evidence: Process map or turtle diagrams; process owners named; KPIs for each process

  6. 4.4.2 Documented information for processes

    Does the organisation keep the documented information needed to support the operation of its processes, and retain enough to be confident they run as planned?

    Evidence: Procedures and work instructions for key processes; sample of records showing the processes run as described

Clause 5 Leadership

  1. 5.1.1 Leadership and commitment

    Can top management show that they take accountability for the effectiveness of the system, integrate it into business processes and promote the process approach and risk-based thinking?

    Evidence: Interview with top management; business plans and budgets that reference quality objectives; management review attendance

  2. 5.1.1 Resources and engagement

    Does top management make the resources available, communicate why effective quality management matters, and support other managers and staff to contribute?

    Evidence: Resourcing decisions; town halls, briefings or messages on quality; staff interviews

  3. 5.1.2 Customer focus

    Does top management make sure customer and applicable legal requirements are determined and met, that risks to conformity and customer satisfaction are addressed, and that customer satisfaction stays a focus?

    Evidence: Customer satisfaction results reviewed by top management; complaint trends; decisions taken on them

  4. 5.2.1 Quality policy

    Is there a quality policy appropriate to the organisation's purpose and context that provides a framework for objectives and commits to meeting requirements and to continual improvement?

    Evidence: Signed, dated quality policy; comparison with strategy and context

  5. 5.2.2 Communicating the policy

    Is the policy available as documented information, communicated and understood within the organisation, and available to interested parties where appropriate?

    Evidence: Policy on notice boards, intranet or website; staff can explain what it means for their job

  6. 5.3 Roles, responsibilities and authorities

    Are roles, responsibilities and authorities for the system assigned and communicated, including who reports on system performance to top management and who keeps the system intact when changes are made?

    Evidence: Organisation chart; job descriptions; appointment letters; RACI matrix

Clause 6 Planning

  1. 6.1.1 Risks and opportunities

    Has the organisation determined the risks and opportunities arising from its context and interested parties that need to be addressed to achieve the intended results and prevent undesired effects?

    Evidence: Risk and opportunity register linked to 4.1 and 4.2; ratings and owners

  2. 6.1.2 Actions on risks and opportunities

    Are actions planned for the risks and opportunities, proportionate to their potential effect on conformity, built into the processes, and is their effectiveness evaluated?

    Evidence: Action plans with owners and dates; evidence actions were completed and reviewed

  3. 6.2.1 Quality objectives

    Are quality objectives set at relevant functions and levels, measurable, consistent with the policy, monitored, communicated and updated?

    Evidence: Objectives register with targets and current results; departmental objectives

  4. 6.2.2 Planning to achieve objectives

    For each objective, is it clear what will be done, with what resources, by whom, by when, and how results will be evaluated?

    Evidence: Objective action plans; progress reports; management review minutes

  5. 6.3 Planning of changes

    When changes to the system are needed, are they carried out in a planned way, considering their purpose and consequences, the integrity of the system, resources and the reallocation of responsibilities?

    Evidence: Change records for recent restructures, new sites or new processes; change plans approved before implementation

Clause 7 Support

  1. 7.1.1 Resources

    Has the organisation determined and provided the resources needed for the system, considering what its existing internal resources can do and what has to be obtained from external providers?

    Evidence: Budget; resource planning; management review outputs on resources

  2. 7.1.2 People

    Are enough people available to run the system and its processes effectively?

    Evidence: Manpower plans; vacancy records; overtime levels in key processes

  3. 7.1.3 Infrastructure

    Is the infrastructure needed for conforming products and services (buildings, equipment, software, transport, IT) determined, provided and maintained?

    Evidence: Asset list; planned maintenance schedule and completion records; breakdown log

  4. 7.1.4 Environment for operation of processes

    Are the working conditions needed for conforming outputs (physical, social and psychological factors such as temperature, cleanliness, workload and stress) determined and maintained?

    Evidence: Site observation; environmental monitoring records where relevant; housekeeping inspections

  5. 7.1.5.1 Monitoring and measuring resources

    Where monitoring or measurement is used to verify conformity, are the resources suitable for the purpose and maintained, with records kept as evidence of fitness for purpose?

    Evidence: Register of measuring equipment; checks and verification records

  6. 7.1.5.2 Measurement traceability

    Where traceability is required, is measuring equipment calibrated or verified against traceable standards, identified with its status, and protected from adjustments that would invalidate results? Is the validity of previous results assessed when equipment is found out of tolerance?

    Evidence: Calibration certificates traceable to national standards; status labels; out-of-tolerance investigations

  7. 7.1.6 Organisational knowledge

    Has the organisation determined the knowledge needed to operate its processes, kept it available, and considered how to acquire additional knowledge when needs and trends change?

    Evidence: Lessons learned records; technical libraries; handover and succession arrangements

  8. 7.2 Competence

    Are competence requirements defined for roles that affect quality, are people competent on the basis of education, training or experience, and is the effectiveness of training or other actions evaluated?

    Evidence: Competence matrix; training records; training effectiveness evaluations; certificates

  9. 7.3 Awareness

    Are people aware of the quality policy, relevant objectives, their contribution to the system and the consequences of not following its requirements?

    Evidence: Staff interviews at several levels; induction content; toolbox talks

  10. 7.4 Communication

    Are internal and external communications relevant to the system planned, stating what is communicated, when, with whom, how and by whom?

    Evidence: Communication plan or matrix; meeting minutes; customer communication records

  11. 7.5.1 Documented information

    Does the system include the documented information the standard requires and the documented information the organisation has decided it needs?

    Evidence: Master list of documents and records; mapping to clause requirements

  12. 7.5.2 Creating and updating

    Are documents identified (title, date, author or reference), in an appropriate format, and reviewed and approved for suitability before issue?

    Evidence: Document control procedure; approval signatures or workflow history; revision status

  13. 7.5.3 Control of documented information

    Is documented information available where needed, protected, controlled for distribution, access, storage, changes and retention, and are obsolete versions prevented from use? Are documents of external origin identified and controlled?

    Evidence: Spot checks of documents at point of use; access rights; retention schedule; external documents register

Clause 8 Operation

  1. 8.1 Operational planning and control

    Are the processes needed to provide products and services planned, with requirements, acceptance criteria, resources and controls defined, and are outsourced processes controlled?

    Evidence: Quality plans; production or service plans; control plans; records of planned changes

  2. 8.2.1 Customer communication

    Are there arrangements for communicating with customers on product and service information, enquiries, contracts, orders and changes, feedback and complaints, handling of customer property, and contingency actions?

    Evidence: Enquiry and order records; complaint log; customer correspondence

  3. 8.2.2 Determining requirements

    When determining the requirements for products and services, does the organisation include applicable legal and regulatory requirements and those it considers necessary, and can it meet the claims it makes?

    Evidence: Product specifications; legal requirements for products; marketing claims checked against capability

  4. 8.2.3 Review of requirements

    Before committing to supply, are customer requirements reviewed, including delivery and post-delivery, implied requirements, legal requirements and differences from earlier quotes, with the review result retained?

    Evidence: Contract or order review records; signed-off tenders; resolved differences

  5. 8.2.4 Changes to requirements

    When requirements change, is the documented information amended and are the relevant people made aware of the change?

    Evidence: Contract amendments; change notices circulated to operations

  6. 8.3.1 Design and development process

    Where design and development applies, is there a process for it that suits the products and services? If design is excluded, is the exclusion still valid?

    Evidence: Design procedure; scope justification if excluded

  7. 8.3.2 Design planning

    Does design planning define stages, reviews, verification and validation activities, responsibilities, resources, interfaces, customer and user involvement, and the records needed?

    Evidence: Design plans; project schedules; design team lists

  8. 8.3.3 Design inputs

    Are design inputs complete and unambiguous, covering functional and performance requirements, previous similar designs, legal requirements, standards and potential consequences of failure?

    Evidence: Design input documents; resolution of conflicting inputs

  9. 8.3.4 Design controls

    Are design reviews, verification and validation carried out as planned, with problems identified and actions taken and recorded?

    Evidence: Design review minutes; verification test reports; validation records

  10. 8.3.5 Design outputs

    Do design outputs meet the input requirements, cover the needs of later processes, include monitoring and acceptance criteria, and specify what is essential for safe and proper use?

    Evidence: Drawings, specifications and acceptance criteria; output approval

  11. 8.3.6 Design changes

    Are changes made during or after design identified, reviewed and controlled, with records of the change, the reviews, the authorisation and the action taken to prevent adverse effects?

    Evidence: Design change requests and approvals; impact assessments

  12. 8.4.1 Externally provided processes, products and services

    Are criteria set for evaluating, selecting, monitoring and re-evaluating external providers based on their ability to supply as required, and are the results and any actions recorded?

    Evidence: Approved supplier list; supplier evaluation and re-evaluation records; performance scorecards

  13. 8.4.2 Type and extent of control

    Are the controls applied to external providers and their outputs defined according to the potential effect on conformity, including outsourced processes that remain within the system?

    Evidence: Incoming inspection records; supplier audits; service level agreements for outsourced processes

  14. 8.4.3 Information for external providers

    Do purchase orders and contracts tell external providers what is required: the products and services, approval and release, competence, interactions, control and monitoring, and any verification at their premises?

    Evidence: Sample purchase orders and subcontracts; specifications attached

  15. 8.5.1 Control of production and service provision

    Is production and service provision carried out under controlled conditions: available specifications, suitable equipment and monitoring, competent people, validated special processes, and actions to prevent human error?

    Evidence: Site observation; work instructions at point of use; process validation records; inspection records

  16. 8.5.2 Identification and traceability

    Are outputs identified with their inspection and test status throughout, and is unique identification controlled where traceability is required?

    Evidence: Labels and status tags on site; batch or serial records; a traceability test from finished item back to raw material

  17. 8.5.3 Customer or provider property

    Is property belonging to customers or external providers (materials, tools, premises, data, intellectual property) identified, protected and safeguarded, and is loss or damage reported to the owner?

    Evidence: Register of customer property; records of reported loss or damage

  18. 8.5.4 Preservation

    Are outputs preserved during production and service provision so they still conform, covering handling, packaging, storage, transport and protection?

    Evidence: Warehouse and storage observation; shelf-life control; packaging specifications

  19. 8.5.5 Post-delivery activities

    Are post-delivery requirements (warranty, maintenance, support, recycling or disposal) determined and met, considering legal requirements, risks, product life and customer feedback?

    Evidence: Warranty records; service reports; maintenance contracts

  20. 8.5.6 Control of changes

    Are unplanned changes to production or service provision reviewed and controlled, with records of the review, who authorised the change and the actions taken?

    Evidence: Production change records; deviation approvals

  21. 8.6 Release of products and services

    Are products and services released only after planned checks show requirements are met, or with approval from a relevant authority or the customer, and is the person authorising release traceable?

    Evidence: Final inspection records with acceptance criteria and signature; concessions approved by the customer

  22. 8.7 Nonconforming outputs

    Are nonconforming outputs identified and controlled to prevent unintended use or delivery, dealt with by correction, segregation, return, informing the customer or concession, and is conformity re-verified after correction?

    Evidence: Nonconformance reports; quarantine area; concession records; rework re-inspection

Clause 9 Performance evaluation

  1. 9.1.1 Monitoring and measurement

    Has the organisation decided what needs to be monitored and measured, the methods, when it is done and when results are analysed, and does it retain the results?

    Evidence: KPI list per process; monitoring schedule; performance reports

  2. 9.1.2 Customer satisfaction

    Does the organisation monitor how customers perceive the degree to which their needs and expectations are met, and act on the results?

    Evidence: Customer surveys; feedback analysis; complaint trends; meeting notes with key accounts

  3. 9.1.3 Analysis and evaluation

    Are monitoring data analysed to evaluate conformity, customer satisfaction, system performance, the effectiveness of planning and of actions on risks, external provider performance, and the need for improvement?

    Evidence: Trend analyses; dashboards; data packs prepared for management review

  4. 9.2.1 Internal audit

    Are internal audits carried out at planned intervals to check that the system conforms to the organisation's own requirements and the standard, and is effectively implemented and maintained?

    Evidence: Audit reports covering the full scope over the cycle

  5. 9.2.2 Audit programme

    Does the audit programme take account of process importance, changes and previous results; are criteria and scope defined for each audit; are auditors objective and impartial; and are results reported and acted on without undue delay?

    Evidence: Audit programme; auditor competence and independence; audit plans; follow-up of findings

  6. 9.3.1 Management review

    Does top management review the system at planned intervals for its continuing suitability, adequacy, effectiveness and alignment with strategy?

    Evidence: Management review schedule and minutes; attendance

  7. 9.3.2 Management review inputs

    Does the review consider previous actions, changes in issues, customer satisfaction, objectives, process performance, nonconformities, monitoring results, audit results, external provider performance, resources, risk actions and improvement opportunities?

    Evidence: Management review agenda and data pack checked against each required input

  8. 9.3.3 Management review outputs

    Do the outputs record decisions on improvement opportunities, changes to the system and resource needs, and is evidence of the results retained?

    Evidence: Minutes with decisions, owners and dates; follow-up at the next review

Clause 10 Improvement

  1. 10.1 Improvement

    Does the organisation select and act on opportunities to improve products, services, results and customer satisfaction, including correcting, preventing or reducing undesired effects?

    Evidence: Improvement projects; suggestion schemes; before and after results

  2. 10.2.1 Nonconformity and corrective action

    When a nonconformity occurs, including from complaints, does the organisation react, find the root cause, check whether similar nonconformities exist or could occur, take action, review its effectiveness and update risks and the system where needed?

    Evidence: Corrective action records with root cause analysis (5 Whys, fishbone); effectiveness checks; risk register updates

  3. 10.2.2 Records of nonconformity

    Is documented information retained on the nature of each nonconformity, the actions taken and the results of corrective action?

    Evidence: Nonconformity and corrective action log; closed reports

  4. 10.3 Continual improvement

    Does the organisation continually improve the suitability, adequacy and effectiveness of the system, using analysis results and management review outputs to find needs and opportunities?

    Evidence: Improvement trends year on year; management review decisions implemented

Written against ISO 9001:2015 with Amendment 1:2024 (climate action changes to clauses 4.1 and 4.2), the edition certification bodies audit to as of October 2026. ISO published ISO 9001:2026 on 16 September 2026. Certificates to the 2015 edition stay valid during a transition that certification bodies expect to run about three years, to around September 2029; confirm the dates with your certification body. The clause structure and process approach carry over, and the reported changes include quality culture and ethical behaviour, risks and opportunities treated separately, and stronger change management. Once your system moves to the 2026 edition, check each clause reference against it.

The questions paraphrase the requirements of each clause. They are a working aid, not a substitute for the standard, which is published by ISO and national standards bodies. Add questions for your own legal requirements, procedures and sites.

Free download

Get the Excel version

Enter your work email. We'll send the workbook to your inbox and unlock the direct download here.

Work or organisation email required. No spam.

  • Five sheets: legend, checklist, by department, findings log, audit plan
  • Questions for sales, design, procurement, operations and HR interviews
  • Editable, in Calibri, works in Excel and Google Sheets
Questions

Using an internal audit checklist

Should an ISO 9001 internal audit use the 2015 or the 2026 edition?

Audit against the edition your certificate is issued to. ISO published ISO 9001:2026 on 16 September 2026, and certificates to ISO 9001:2015 stay valid during a transition that certification bodies expect to run about three years, to around September 2029. Until your certification body audits you to the 2026 edition, this checklist, written against ISO 9001:2015 with its 2024 climate amendment, matches what you will be audited on. Confirm the transition dates with your certification body.

What does an ISO 9001 internal audit cover?

Every clause from 4 to 10: context and interested parties, leadership and customer focus, risks and opportunities, quality objectives, resources and competence, documented information, operation (customer requirements, design and development, externally provided processes, production, release and nonconforming outputs), monitoring and customer satisfaction, internal audit, management review and corrective action. This checklist has 64 questions across those clauses.

Can we leave out design and development?

Only if it genuinely does not apply and does not affect your ability to deliver conforming products and services or customer satisfaction. The justification has to be in your scope statement. If you adapt designs for customers or develop new services, clause 8.3 usually applies, and an auditor will test the exclusion.

How often should we run an ISO 9001 internal audit?

At planned intervals that reflect how important each process is and what previous audits found. Most organisations audit every process at least once a year in a rolling programme, with weaker or higher-risk processes more often, and finish the cycle before the certification body's surveillance visit.

Related: ISO 9001 certification in the UAE, ISO internal audit services, managed ISO systems and ISO internal auditor training.

Other free checklists: ISO 14001 (environment), ISO 45001 (health and safety), ISO 50001 (energy), ISO 27001 (information security), ISO 14001 and ISO 45001 combined.