Here's a dirty secret the certification industry doesn't want you to hear: your ISO 9001 certificate is a lie. Not because your auditor is corrupt—though that happens—but because you've been trained to treat the audit as the finish line. You polish the paperwork, rehearse the employee answers, and pray the auditor doesn't wander into the warehouse. Then you celebrate with a plaque on the wall. And that's precisely why your quality system is stagnant.
Audits are not compliance exams. They are your best window into whether your processes actually work. But only if you stop gaming them. The 2026 revisions to ISO 9001 and ISO 19011 are coming—and they're going to make that painfully clear. So before you schedule another internal audit, let's walk through what a real audit looks like when you use it as the improvement tool it's meant to be.
Imagine you're the quality manager at a mid-sized electronics manufacturer. You've been certified to ISO 9001:2015 for three years. Your external audit is in six weeks, and your internal auditor—a well-meaning engineer who took a two-day course—just submitted his report. It's full of minor nonconformities: a missing signature here, an outdated work instruction there. He's already drafting the corrective action forms.
Stop. Tear up that report. Because if you let that pattern continue, you're not auditing—you're tidying up for the inspector. Here's what you need to do instead.
Audit the Process, Not the Paperwork
Your internal auditor's report is a symptom of a fundamental misunderstanding. He's treating quality control (QC) as if it were quality assurance (QA). You need both, but they serve different purposes. QA is proactive—it ensures the process is designed to prevent defects. QC is reactive—it catches defects after they've happened (ASQ, QA vs QC). Audits are part of QA; they're supposed to verify that the process is actually being followed, not just that the records are filled in.
So when you audit, don't start with the documents. Start with the people on the line. Ask them what they do, and then watch them do it. Compare that to the work instruction. Where are the gaps? That's where your audit findings should live. If the instruction says operators must wear grounding straps, and you see three people not wearing them, you've found a real issue—not a paperwork nitpick. That's a process failure, and it's the kind of thing that leads to defects downstream.
Use the PDCA Cycle to Make It Stick
Here's where most audits fall apart: they identify problems, write corrective actions, and then never verify that those actions actually solved the problem. You're missing the 'Check' and 'Act' steps of the PDCA cycle. The Plan-Do-Check-Act cycle is the engine of ISO 9001—it's built into the standard's DNA (ASQ). And it's not a one-time loop. It's meant to be repeated continuously, like a circle with no end (ASQ, PDCA).
So after your internal auditor finds that missing grounding strap issue, don't just retrain the operator and close the finding. Plan a root-cause analysis. What's causing operators to skip the strap? Maybe the straps are uncomfortable, or they're stored too far away. Do a small test—try a different strap model. Check the results—are operators wearing them now? Then act on what you learned, and standardize the fix. That's how you use an audit to drive improvement, not just compliance.
Risk-Based Thinking Is Your Friend, Not a Buzzword
ISO 9001:2015 introduced risk-based thinking, and it's not just a box to tick. It's a way to prioritize audit findings based on their potential impact. The 2026 revision goes further, separating risks and opportunities more clearly (ANSI Blog, ISO 9001:2026). So when you audit, don't list every minor deviation equally. Ask: which findings could actually cause a customer complaint, a product recall, or a safety issue? Those are the ones that deserve your attention first.
Use a simple risk matrix. For each finding, estimate the likelihood and severity. A missing signature on a batch record for a non-critical component is low risk. A deviation in the calibration of a test instrument that checks safety-critical products is high risk. Focus your corrective actions there. That's the kind of thinking that will make your audit meaningful—and it's the kind of thinking the 2026 auditors will be looking for.
Look Beyond Your Own Walls
Here's a place where most internal audits are blind: your suppliers. If you're certified to ISO 9001, your quality management system includes your relationship with suppliers. The standard's principles include relationship management (ASQ). But how often do you audit your suppliers' performance beyond just checking their delivery dates? If a key component has a high defect rate, that's a quality problem that will hit you downstream.
Don't just rely on their certificates. Ask for their internal audit results. If they're ISO 9001 certified, they should have them. (ASQ notes that ISO 9001 is the world's most widely used QMS standard, with over 1 million certifications (ASQ). But certification doesn't guarantee performance—it's a snapshot of their system, not proof of quality.) If their audit reveals recurring issues in their process, that's a risk to your product. Work with them to address it, or consider a second source. That's proactive quality assurance.
Prepare for the 2026 Revisions Now
The ISO 9001:2026 revision is expected to be published in September 2026 (ANSI Blog, ISO 9001:2026). And while the core principles remain intact, there are changes you need to start preparing for now—especially around quality culture and ethical behavior (ANSI Blog, ISO 9001:2026). That means your audits will need to assess not just whether people follow procedures, but whether they're engaged and committed to quality. That's a cultural shift, and it won't happen overnight.
Similarly, ISO 19011:2026—the guidelines for auditing—have been updated, with expanded guidance on remote auditing methods (CQI, ISO 19011:2026). If you're still doing everything on-site, start thinking about how remote audits might change your approach. And note the change to the independence principle: when independence isn't possible, auditors should make every effort to remove bias and encourage objectivity (CQI, ISO 19011:2026). That's a subtle but important shift—it acknowledges that perfect independence is often unrealistic, but bias reduction is still mandatory.
So here's your action plan:
- Stop treating audits as a paperwork exercise. Go to the floor and watch the work.
- Use the PDCA cycle to close the loop on every significant finding.
- Prioritize findings using risk-based thinking—high risk first.
- Extend your audits to your key suppliers.
- Start building a culture where people care about quality, not just compliance.
And if you do all that, your next audit might actually uncover something worth fixing. The certificate will still be a lie—it always is—but at least it'll be a lie you can live with.
The most important thing to remember: An audit is not a verdict on your quality—it's a tool for improvement. Use it that way, and the certificate becomes irrelevant.
Sources
- ASQ - https://asq.org/quality-resources/iso-9001
- ASQ (PDCA) - https://asq.org/quality-resources/pdca-cycle
- ANSI Blog (ISO 9001:2026) - https://blog.ansi.org/ansi/iso-9001-2026-qms-revision-updates/
- CQI (ISO 19011:2026) - https://www.quality.org/article/revision-iso-19011-what-you-need-know
- ASQ (QA vs QC) - https://asq.org/quality-resources/quality-assurance-vs-control
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!