I once sat in a conference room while a plant manager held up a framed ISO 9001 certificate and said, "We're covered." Three weeks earlier, his line had shipped 4,200 brackets to an automotive customer. About 60 of them had the wrong thread pitch. Nobody caught it until the customer's torque driver started stripping heads on the assembly line.
The certificate didn't lie. The plant really did have a documented quality management system. It just wasn't doing what he thought it was doing.
That gap — between "we have a system" and "our product is good" — is where most quality problems live. And it's a gap that a lot of very smart people fall into, because the language around certification is genuinely confusing.
What an audit actually is (and isn't)
An audit is a sampling exercise. That's it. An auditor looks at evidence — records, interviews, observations — to decide whether your processes match your own procedures and the standard's requirements. They are not inspecting every unit. They cannot. A typical surveillance audit is two to five days. Your process runs 250 days a year.
So when a defect escapes, the audit didn't fail. The process did. The audit should have caught the weakness in the process that let the defect through — assuming it was scoped and executed with any real rigor. Which, honestly, is not always the case.
Auditing sits inside quality assurance. Its job is to give people confidence that requirements will be met — internally to management, externally to customers and regulators. That's a limited promise. It's not a warranty.
Does the certificate mean your product is good?
No. And I wish more sales teams understood this.
ISO 9001 is the only standard in the ISO 9000 family you can actually get certified against. ISO 9000 gives you vocabulary. ISO 9004 gives guidance for sustained success. You can't buy a certificate for either one. So when someone says "we're ISO 9001 certified," they're saying: our processes are defined, measured, and subject to improvement. They are not saying: your widget will never fail.
Customers conflate the two constantly. Vendors encourage the confusion. And then you get a credibility problem the first time something ships wrong — because you promised more than the certificate ever said.
Why so many audits feel like theater
Because they're treated as an event. A date on a calendar. A week of document cleanup and rehearsed answers.
The standard is built on Plan-Do-Check-Act, a process approach, and risk-based thinking. PDCA is simple: plan a change, do it, check the results, act on what you learned. It's supposed to loop forever. When your audit is just the Check box ticked once a year, you've cut the loop in half. The Act part — the part that actually changes things — never happens.
I've watched companies spend six weeks preparing for a three-day audit and zero weeks acting on the findings. That's not compliance. That's performance art.
A few things I'd call warning signs:
- Your findings are always minor and always the same three or four items. Nothing changes, which means your corrective action process isn't working.
- Only the quality department knows an audit is happening. If the rest of the building finds out on Monday, you've got a culture problem, not a documentation problem.
- You have never once changed a design, a supplier, or a process because of an audit finding. Then what are you auditing for? The certificate?
What's actually changing in the standards
Quite a bit, and sooner than people think.
ISO 19011 — the guidelines for auditing management systems — was revised and published in 2026. The Chartered Quality Institute called it "evolutionary not revolutionary," which is fair, but the changes matter. The biggest one: expanded guidance on remote auditing, driven by ISO/IEC TS 17012:2024. Annex A now covers remote auditing and virtual locations. Your next audit may be partly or entirely off-site. If you can't produce evidence on a screen — a scanned record, a screenshot with a timestamp, a live video walk-through — you're going to have a bad time.
Here's a concrete one. Under the old guidance, internal auditors were told to be independent of the function being audited "if practicable." That qualifier is gone. The new text says: when independence isn't possible, make every effort to remove bias and encourage objectivity. In plain English — you can audit your own area, but you have to actively fight your own blind spots. Anyone who's tried this knows it's much harder than it sounds.
And yes, ISO 9001 itself is getting revised. The Final Draft International Standard is expected around September 2026, replacing ISO 9001:2015. It adds requirements around quality culture and ethical behavior, separates risks and opportunities more clearly, and tightens up management of change. Not a teardown. Not a reason to panic. But if you're certified, your clock is already ticking.
"I'm not an auditor. Why should I care about ISO 19011?"
Because if you're a quality manager, you're either running an audit program or you're inside one. There is no third option.
ISO 19011 covers how to manage a program, how to conduct audits, and how to judge whether an auditor is actually competent. ASQ calls it the pre-eminent authority on auditing. Skipping it is like a chef skipping knife skills. You might survive service, but you'll be slow and you'll cut yourself.
Small detail worth noticing: the 2026 revision adds a term for "remote auditing method" and changes "outcome of an audit" to "result of an audit." Little language shifts like that usually signal a bigger shift in thinking. The emphasis is moving from what happened to what you're going to do about it.
What I'd actually do on Monday
Stop treating the certificate as a trophy. Treat it as a floor, not a ceiling.
Put risk thinking into daily work, not just audit prep. The standard has required risk-based thinking since 2015. Most companies dust it off the week before the auditor shows up. Use FMEA — Failure Mode and Effects Analysis — to look for failures in design and process before they happen. FMEA came out of the U.S. military in the 1940s and scores failures on severity, occurrence, and detection. It's not glamorous. It works.
Track the cost of poor quality, including the parts nobody likes to talk about. Scrap and rework are easy to count. Returns, recalls, warranty claims, and the customer who quietly stops ordering — those are the numbers that matter, and most companies don't have them in one place. If you can't produce a single figure for external failure cost, you're flying blind.
Train your internal auditors on the 2026 ISO 19011 guidance, remote auditing especially. One exercise that pays off: have each auditor run a mock remote audit of a department they don't know, using only electronic records. You'll find out fast where your evidence trail has holes.
Make one number a board metric: systemic improvements triggered by audit findings. Not total findings. Not findings closed. The number of changes — to a design, a supplier, a training module, a piece of equipment — that exist because of something an audit surfaced. If that number is zero, your audit program is a cost center wearing a compliance costume.
And keep this in mind. Quality assurance is about confidence — earned through consistent, evidence-based processes. A certificate is a piece of paper. The system is what keeps customers coming back. The 4,200 brackets with the wrong thread pitch? They came from a plant with a valid certificate, a clean audit, and a process nobody had actually looked at in two years.
Sources
- ASQ - https://asq.org/quality-resources/iso-9001
- ASQ (PDCA) - https://asq.org/quality-resources/pdca-cycle
- CQI (ISO 19011:2026) - https://www.quality.org/article/revision-iso-19011-what-you-need-know
- ANSI Blog (ISO 9001:2026) - https://blog.ansi.org/ansi/iso-9001-2026-qms-revision-updates/
- ASQ (FMEA) - https://asq.org/quality-resources/fmea
- ASQ (Cost of Quality) - https://asq.org/quality-resources/cost-of-quality
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!