The Misconception: Audits Are About Passing the Test
You think the point of your quality audit is to prove compliance and keep your ISO 9001 certificate. That's wrong. If you're auditing just to pass, you're already failing. The real purpose of an audit is to find out whether your quality management system is actually working—whether it's preventing defects, reducing waste, and driving improvement. If you treat the audit as a test, you'll get what you prepare for: a system that looks good on paper but doesn't perform when it counts.
My Thesis: Audits Are a Leadership Tool, Not a Compliance Ritual
Here's the blunt truth: an audit is one of the most underused management tools you have. It's not a policing exercise; it's a diagnostic. I'm not telling you to abandon compliance—certification still matters. But the organizations that get real value from their QMS are the ones that use audits to drive change, not just to verify paperwork.
Take ISO 9001, the world's most widely used QMS standard, with over 1.2 million valid certificates as of the end of 2022 (ISO Survey 2022). That's a lot of certificates. But how many of those certified organizations are actually using their QMS to improve? Probably not as many as you'd think. Because when you audit to satisfy the registrar, you're not auditing for your customer. You're auditing for a piece of paper.
What the Standard Actually Requires—and What You're Missing
ISO 9001 is built on the Plan-Do-Check-Act (PDCA) cycle, a process approach, and risk-based thinking (ASQ). That's not just a nice framework; it's the core of the standard. And the audit is where you check whether your 'Check' phase is real. The standard also emphasizes seven quality management principles: customer focus, leadership, engagement of people, process approach, improvement, evidence-based decision making, and relationship management (ASQ).
The problem is that most audits focus on the process approach and evidence-based decision making, but completely ignore the 'improvement' and 'engagement' parts. You can't audit your way to improvement if you're only checking for documentation. You have to ask: are we actually using this data to make decisions? Are our people engaged in fixing problems, or are they just filling out forms?
The Counter-Argument: 'We Don't Have Time for Deep Audits'
I know what you're thinking: 'We're too busy producing to spend days on a philosophical audit.' That's a fair point. You have deadlines, customers, and a bottom line. Deep audits take time, and time is money.
But consider this: the cost of poor quality includes internal and external failure costs—defects found before and after the customer receives the product (ASQ). External failures are the most expensive: warranty claims, recalls, lost customers. A single serious defect can wipe out the savings from a hundred superficial audits. So the question isn't 'Can we afford to audit deeply?' It's 'Can we afford not to?'
You don't need to audit for three weeks. You need to audit with the right questions. Instead of 'Show me the procedure,' ask 'Show me a recent problem and how you solved it.' Instead of 'Is this documented?', ask 'What did you learn from this?' That's not a huge time investment—it's a shift in mindset.
How to Make Your Next Audit Actually Useful
Here's a practical, no-nonsense approach to transforming your audit from a compliance ritual into a management tool:
- Focus on processes, not departments. Audit the flow of work from input to output, not just whether each department follows its own rules.
- Ask about failures, not just successes. Ask for examples of nonconformities, customer complaints, or near-misses—and how you responded.
- Involve top management. Leadership is one of the seven principles (ASQ). If your CEO doesn't care about the audit, why should anyone else?
- Use the audit to spot opportunities for improvement, not just problems. That's what the 'Act' phase of PDCA is for.
You can even apply the same thinking to your internal audits. Don't just have the quality department audit; have cross-functional teams audit each other. That builds engagement and gives you fresh eyes.
The 2026 Revisions: A Chance to Reboot Your Approach
The upcoming revisions to ISO 9001 and ISO 19011 are a perfect opportunity to rethink your audit program. ISO 9001:2026, expected to be published in September 2026, adds requirements for quality culture and ethical behavior, and strengthens management of change (ANSI Blog). That's a big deal: culture is not something you can audit with a checklist. You have to observe how people behave, what they prioritize, and what they're rewarded for.
ISO 19011:2026, the auditing guidelines, also expands guidance on remote auditing methods (CQI). That means you can audit remote sites and virtual processes more effectively. But don't use that as an excuse to become even more detached from the actual work. Remote auditing can be powerful, but it can't replace the insight you get from walking the floor and talking to the people doing the work.
The Bottom Line
If you take one thing from this, remember: your audit is not about the certificate. It's about whether you're actually managing quality—or just pretending to. The certificate is a byproduct of a well-run QMS, not the goal. So next time you plan an audit, ask yourself: 'What will we learn that will make us better?' If the answer is 'nothing,' you're doing it wrong.
Sources
- ASQ - https://asq.org/quality-resources/iso-9001
- ANSI Blog - https://blog.ansi.org/ansi/iso-9001-2026-qms-revision-updates/
- ISO Survey 2022 (AAA) - https://aaa-accreditation.org/iso-survey-results-of-certifications-to-management-system-standards/
- CQI (ISO 19011:2026) - https://www.quality.org/article/revision-iso-19011-what-you-need-know
- ASQ (Cost of Quality) - https://asq.org/quality-resources/cost-of-quality
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!