An audit by an external auditor is the final step your company will take to receive ISO 9001 certification. The auditor will assess your quality management system (QMS) to ensure it meets ISO 9001 requirements.
Audits can be daunting but if you know what to expect and you’ve done all your preparation, your company should be recommended for certification.
In this article, we look at the main steps of an external audit so you can be better prepared.
A positive approach to external ISO 9001 audits
By nature, an external audit is stressful. On the plus side, preparing for an audit, even if you don’t achieve certification on the first try, can result in valuable data about areas of improvement.
The process usually results in increased efficiency and improved quality management. So, even if you don’t get certified, your company will have more efficient and profitable procedures. These will make you better prepared for the next audit.
When does an external ISO 9001 audit take place?
An external ISO 9001 audit should be scheduled once you’ve completed an internal audit.
You will need at least two to three months of documentation and records from your ISO 9001 procedures.
The internal audit will act as a practice run to reveal any problems or non-compliances in your quality management system.
Who conducts an external ISO 9001 audit?
An external ISO 9001 audit is conducted by a third-party auditor (or auditor team). The auditor will be assigned to you by an ISO 9001 registrar, which is also known as a Certification Body (CB).
The registrar is an independent entity that will issue the ISO 9001 certificate once the third-party auditor has completed the audit and approved your certification.
The stages of a third-party audit
The third-party audit process is divided into two main sections, each with a series of steps.
Stage 1
Stage 1 of the audit is the document or readiness review. This stage determines if you’re ready for stage 2.
The audit focuses on your QMS documentation and the relevant policies that support the operation of the system.
The auditor will need information about your QMS processes, procedures, equipment used, the status of internal audits, and which sites are being audited.
Using all the reviewed information and documentation, the auditor will determine whether you’re ready for stage 2 of the audit.
Stage 2
Stage 2 is normally conducted in person but can be done remotely. Since the COVID-19 pandemic, remote audits have become more commonplace.
Stage 2 is broken up into three steps.
1. Opening meeting
In the opening meeting, the auditor will explain the process of the audit and what to expect. He or she will usually provide a schedule, so you’ll know how long the audit will take. The audit can take up to a week, depending on the size of your company.
2. In-depth evaluation
The in-depth evaluation is the main part of the audit. The auditor will inspect your documentation, assess the effectiveness of your QMS, look at your policies and procedures, and evaluate your internal audits.
The effectiveness of your corrective and preventative actions (CAPA) and your key performance objectives and targets will also be evaluated.
3. Closing meeting and report
In the closing meeting, the auditor will give you feedback, including any non-compliances that have been encountered.
He or she will generally supply a report that details these problems and provides corrective action that must be taken before receiving ISO 9001 accreditation.
Possible outcomes of an ISO 9001 audit
If the auditor is satisfied that a business is fully compliant with ISO 9001, the auditor will recommend it for certification.
However, if any issues are uncovered, they will be detailed in the report and must be addressed.
The three types of non-compliance issues that might be revealed are:
Major non-conformance
A major non-conformance means that there is one large or several minor non-conformities against one requirement that has caused the entire QMS to breakdown. Major non-conformances must be rectified to achieve certification.
Minor non-conformance
A minor non-conformance is a failure or a single observed lapse in some part of the management system. Minor non-conformances don’t affect the auditor’s recommendation for approval, but they must be rectified before you can be issued your certificate.
Opportunity for improvement (OFI)
These are areas that may warrant clarification or investigation to improve the effectiveness of the QMS. OFIs don’t affect the recommendation for certification.
What happens if you fail the audit?
If an auditor doesn’t recommend your business for certification, significant non-compliances will have been identified during the audit.
You must take the time to address these non-conformances before you can consider reapplying. Conducting one or more internal audits after you’ve made these changes is recommended.
Once this is done, you can reapply for certification and have another external ISO 9001 audit done.
How long does ISO 9001 certification last?
An external audit must be done every three years to maintain ISO 9001 certification.
Periodic “surveillance” audits may also be conducted. Typically, these are done annually.
How quality software can help you pass ISO 9001 audits
Quality management software allows businesses to manage their QMS, making compliance with ISO 9001 much easier.
Good QMS software like isoTracker’s includes the functionality to manage internal and external audits, so you can ensure your system meets regulatory requirements.
Use QMS software to streamline the auditing process by assigning tasks, monitoring progress, tracking issues and automating tasks.
At isoTracker, we offer QMS software that’s affordable, cloud-based and modular. Register for a free 60-day trial and get full access to all modules to see how QMS software can help you prepare for an external ISO 9001 audit.


