Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

The Ultimate Guide to ISO 9001 Audits

Achieving a good result at an ISO 9001 Audit should be a walk in the park for a well designed, developed and implemented Quality Management System. During the audit, the Certification Auditor will sight objective evidence to support conformity with each of the sub-clauses (clause numbers 4-10) of ISO 9001. This will mean an ISO 9001 audit result of either:

What is an ISO 9001 audit?

An ISO 9001 audit is a structured check that your quality management system meets the requirements of ISO 9001:2015 and is working in practice. There are two main types: an internal audit, which you must carry out yourself under ISO clause 9.2, and an external certification audit, conducted in two stages by a JAS-ANZ accredited certification body. This guide explains the audit codes you will encounter, from Satisfactory through to Major non-conformity, and how to pass first time.

Many organisations engage Streamline to run an independent internal audit before their certification audit, so issues are found and fixed before the external auditor sees them. We can also mentor your team to run audits well in-house.

  1. Satisfactory: all is well
  2. Improvement Opportunity: the auditor is recommending improvements (take them or leave them)
  3. Observation: things may be going off the tracks
  4. Minor Non-conformity: isolated minor deficiency identified
  5. Major Non-conformity: major deficiency identified

Note: If you have received a dreaded ISO 9001 Quality Management System major non-conformity it means there has been a significant deficiency identified in the structure and/or the implementation of the quality management system but don’t panic! Read on. 

What is the difference between a non-conformity and a non-compliance?

Before we go into the details of the various audit codes it is worth reflecting on the terminology used (incorrectly at times) around ISO Audits.

  • A Non-compliance is typically used when there is a breach of externally imposed requirements, for example, when you have not complied with the law (Acts, Regulations, etc). That is a Noncompliance.
  • A Non-conformity (also known as a Non-conformance) is normally used in situations where there has been a failure or non-fulfillment to conform with internally imposed requirements such as ISO Standards (eg ISO 9001 Quality Management Systems).

So when talking about ISO Audits you would normally say audit Non-conformity as opposed to audit Non-compliance. On the flip side (where you want to be), you would conform with ISO standards and comply with legal requirements.

Government funding for ISO certification

Grants may be available to help with the cost of ISO certification. See our guide to Government Grants & Funding for ISO Certification (AU).

ISO 9001 Audit Codes

A note about ISO Audit codes: Under JAS-ANZ, Certification Bodies are not obliged to use specific Audit Codes so these may vary somewhat depending upon which Certification Body conducts the audit. For example (with reference to the definitions below), some Certification Bodies will raise an Improvement Opportunity as their Observation, a Minor Non-conformity as an Improvement Request, and a Major Non-conformity as a Non-conformity. So much for standardisation! That said the following definitions will largely apply.

Satisfactory

Satisfactory (SAT) objective evidence was sighted to demonstrate conformance with ISO 9001:2015 Quality Management Systems. No further action required here. Keep up the good work and well done!

Improvement opportunity

If the ISO Certification auditor identifies an Improvement Opportunity (IO) then it means they think things could be done better and they are making a recommendation to try and add value to your Quality Management System through their audit service. Bear in mind that there are many ways to skin a cat and some ISO 9001 Certification auditors may be used to seeing systems set up in a way that may not necessarily be the best solution for your business. You aren’t required to action IO recommendations made in the audit report however it is a good idea to address them in either the Improvement Register or QMS Management Review Minutes, even if it is just to say that you have reviewed the recommendations and aren’t going to proceed with them.

Observation

If the Auditor gives you an Observation (OBS) it means that things aren’t going to plan and there are some issues that need addressing before they escalate to a Minor or Major Nonconformity. Observations should be registered in your improvement framework and action taken to address the recommendations made prior to the next surveillance audit from the Certification Body.

Minor nonconformity

An isolated failure to conform with the requirements of the ISO standard or implement the Quality Management System is generally classified as a minor nonconformity and as a minimum should be addressed within the next 12 months prior to the next surveillance audit.

A Corrective Action Plan is not usually required as long as the non-conformity is registered into the improvement framework and addressed in a timely manner (maximum of 12 months). Corrective action taken to address a Minor Non-conformity will be reviewed at the following surveillance audit and if appropriate action has not been taken then the Minor will likely escalate into a major Non-conformity.

Major nonconformity

A Major Non-conformity means the auditor has determined that there is a complete or significant absence of any objective evidence to support conformance to the clause, or a complete failure to implement the Quality Management System to requirements.

If you receive a Major Nonconformity then you will not receive certification (if it is your initial audit) until the Non-conformity has been closed out, and if you are already certified then the Certification Body will not renew your certification if the Non-conformity has not been actioned within three months (ie certification suspended). But again, don’t panic!

When a Major Nonconformity is raised, simply complete the following five steps:

  1. Complete a Corrective Action Plan (including Root Cause Analysis).
  2. Submit the Corrective Action Plan to the Certification Body for review and approval within one month of the audit date.
  3. Action the items detailed in the Corrective Action Plan within three months.
  4. Update the Corrective Action Plan when the action items have been completed to indicate they have been closed out.
  5. Send the completed CAP to the Certification Body, along with any other evidence required to support the completion of the action items.

Based on the information provided the Certification Body may decide a follow-up audit is required to verify the effectiveness of action taken.

Note: CLICK HERE for an example Corrective Action Plan  

Auditor reviewing records with a client
For a Major Nonconformity, the Corrective Action Plan must go to the Certification Body for review within one month of the audit and be actioned within three months.

ISO 9001 internal audit checklist

Use this checklist to plan and run an effective ISO 9001 internal audit, from preparation through to closing out findings.

Before the audit

  • Define the audit scope, criteria and objectives: which clauses and processes you’ll cover.
  • Confirm the audit schedule with the relevant process owners.
  • Select a competent, impartial auditor (no one audits their own work).
  • Review previous audit results, nonconformities and corrective actions.
  • Prepare an audit plan/checklist mapped to the relevant ISO 9001:2015 clauses.

During the audit

  • Hold a short opening meeting to confirm scope and logistics.
  • Gather objective evidence through interviews, records and observation.
  • Check conformance to both ISO 9001 requirements and your own documented processes.
  • Record each finding as satisfactory, an observation, an opportunity, or a nonconformity.
  • Verify that previous corrective actions were actually effective.

After the audit

  • Hold a closing meeting and present the findings.
  • Issue a clear audit report.
  • Raise corrective actions for any nonconformities, including root-cause analysis.
  • Track every action to closure and verify effectiveness.
  • Feed the results into your management review.

How to Avoid ISO 9001 Audit Non-conformity

Consider engaging an ISO 9001 Consultant to undertake a comprehensive internal audit prior to certification, surveillance or recertification audit from a Certification Body. A thorough Internal Audit will ensure any deficiencies are identified and an action plan established before non-conformities are picked up by the ISO 9001 Certification Auditor.

Outsourcing your internal auditing to Streamline provides independence, objectivity and eliminates the requirement for employee training and diversion from normal work activities, both of which cost time and money. You work directly with an experienced ISO auditor who provides the professionalism and high level of diplomacy required to facilitate effective internal audits.

Your business will receive highly objective and impartial audits that will add real value to your management system and ensure any problems with the QMS are identified and actioned before you receive a Non-conformity at the external audit.

Benefits of ISO 9001 Internal Auditing

ISO 9001 internal auditor reviewing audit records and process documents at a desk in a modern office
ISO 9001 requires internal audits to cover every clause and process at least once a year, ahead of each certification surveillance audit.
  • Receive highly objective and impartial audits that will add real value to your management system,
  • Reduced requirements for internal auditor training and logistical costs,
  • Allow your employees to focus on their core jobs so there is minimal disruption to normal business operations,
  • Avoid internal political issues that may arise due to internal departments cross-auditing,
  • Meet the requirements of management system standards,
  • Ensure your management system is effectively implemented,
  • Identify opportunities for improvement, and
  • Reduced non-conformance findings from certification bodies.

Remember to take into account the ISO 9001 Certification Costs and understand the risks of cheap ISO 9001 Certification.

ISO 9001 audit FAQs

How often should you do an ISO 9001 internal audit?

At least once a year, with the entire quality management system (every clause and process) covered across your audit programme before each certification surveillance audit.

Who can carry out an internal audit?

Any competent, objective person who does not audit their own work. Many small and medium businesses bring in an independent internal auditor to keep the process impartial and add fresh perspective.

What’s the difference between an internal audit and a certification audit?

An internal audit is run by you (or on your behalf) to check and improve the QMS. A certification, or external, audit is run by a JAS-ANZ accredited certification body to grant and maintain your certificate.

What happens if an audit finds a nonconformity?

You raise a corrective action: contain the immediate issue, find the root cause, fix it, and verify it doesn’t recur. Minor nonconformities are usually closed out with an action plan; major nonconformities must be resolved before certification can proceed. See our full guide to nonconformance and corrective action.

You might also like

  • ISO 31000 risk management explained
  • Interested parties in ISO 9001 (clause 4.2)

Speak with an experienced ISO auditor

Email hello@streamline.business or call us. You’ll deal directly with an experienced ISO auditor who’ll tailor a practical approach to your business. You’re also welcome to get in touch via our contact page.

  • Brisbane 07 3667 8280
  • Sydney 02 8315 7780
  • Melbourne 03 9034 3990
General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • Quality inspector in an Australian machining workshop checking a machined aluminium component against a tablet record, with CNC machines and Australian flags behind
    How Much Does ISO 9001 Certification Cost in…
  • ISO 9001 quality management inspection
    ISO 9001 Quality Management Consulting, Audits & Mentoring
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • Tilt-shift miniature naval shipyard inspection bay with a submarine hull section on keel blocks and workers in hi-vis checking tagged components in a parts quarantine area
    ISO 19443: The Nuclear Supply Chain Standard, and…
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • Manager reviewing a budget spreadsheet
    ISO 27001 Certification Cost & Timeline in Australia…
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring

Filed Under: Articles, Featured, Ultimate Tagged With: #auditing, #certification, #iso9001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire