Guide

ISO 9001 Audit Checklist 2026

ISO 9001 audit checklist for 2026: clause-by-clause internal audit questions covering all requirements, updated for the three new ISO 9001:2026 changes.

Onega Ulanova
Onega Ulanova

Quality Management Systems Expert & Lead Auditor

August 10, 2026 13 min read
ISO 9001 Audit Checklist 2026

ISO 9001 Audit Checklist: How to Use This Guide

This ISO 9001 audit checklist provides clause-by-clause internal audit questions for ISO 9001:2026. Each question maps to a specific "shall" requirement. Auditors can use these questions verbatim during interviews, document reviews, and process observations. Questions marked [NEW 2026] target the three new requirements introduced in the 2026 revision.

Audit evidence types:

  • I = Interview (ask the question directly)
  • D = Document review (examine records, procedures, policies)
  • O = Observation (watch the process in operation)

ISO 9001 Audit Checklist: Clause 4 — Organizational Context

4.1 Understanding the Organization and Its Context

  • (D/I) How has the organization identified internal issues that affect the QMS? What are the current internal issues?
  • (D/I) How has the organization identified external issues? What external factors currently affect quality performance?
  • (D/I) [NEW 2026] Has the organization considered climate change as a relevant external issue? Where is this documented?
  • (D) Is the context analysis reviewed and updated? When was it last updated?

4.2 Understanding Interested Parties

  • (D/I) Who are the relevant interested parties? How were they identified?
  • (D/I) What are the requirements of each interested party? How are these monitored for changes?
  • (D) Is the interested parties register documented and current?

4.3 QMS Scope

  • (D) Is the QMS scope documented? Does it include all applicable products, services, and locations?
  • (D/I) Are any ISO 9001:2026 clauses excluded? Is the exclusion justified and documented?

4.4 QMS Processes

  • (D/I) What are the QMS processes? How are inputs, outputs, sequence, and interaction defined?
  • (D/I) Who is responsible for each process? Are process owners identified?
  • (D) Are process risks and opportunities addressed?

ISO 9001 Audit Checklist: Clause 5 — Leadership

Stay Current

ISO 9001:2026 publishes September 16, 2026. Get weekly briefings.

5.1 Leadership and Commitment

  • (I/O) How does top management demonstrate active involvement in the QMS — not just delegation?
  • (I) Can top management describe the quality policy and quality objectives from memory?
  • (I/O) [NEW 2026] How does top management promote a quality culture? What specific behaviours or actions demonstrate this?
  • (D/I) [NEW 2026] How does top management promote ethical behaviour? Is there a code of conduct or ethics policy?

5.2 Quality Policy

  • (D) Is the quality policy documented? Does it include commitment to satisfy requirements and continual improvement?
  • (I) Can employees at various levels explain the quality policy in their own words?
  • (D) Is the policy communicated to all relevant parties?

5.3 Roles, Responsibilities, and Authorities

  • (D/I) Are roles and responsibilities for QMS-relevant functions defined and documented?
  • (I) Do employees know their quality responsibilities? Can they describe them?

ISO 9001 Audit Checklist: Clause 6 — Planning

6.1 Actions to Address Risks and Opportunities

  • (D/I) How are risks and opportunities identified? What is the process?
  • (D) Is there a risk register? Does it link to the context analysis (Clauses 4.1 and 4.2)?
  • (D) What actions have been taken to address identified risks? Are they effective?
  • (D/I) [NEW 2026] Is there an opportunities register or equivalent? How are improvement opportunities identified and pursued?

6.2 Quality Objectives

  • (D) Are quality objectives documented? Are they measurable and monitored?
  • (D/I) Is there a plan for each objective — what, who, when, how evaluated?
  • (I) Can managers describe the quality objectives for their area?

6.3 Planning of Changes

  • (D/I) How are changes to the QMS planned and controlled? Can you show a recent example?

ISO 9001 Audit Checklist: Clause 7 — Support

7.1 Resources

  • (D/I) How are resource needs determined? Are adequate resources provided?
  • (D) Are monitoring and measuring devices calibrated? Is there a calibration register?
  • (D/I) How is organizational knowledge identified and maintained? What happens when a key person leaves?

7.2 Competence

  • (D/I) How are competence requirements determined for quality-affecting roles?
  • (D) Are competence records maintained? Do they include training, education, and experience?
  • (D/I) How is training effectiveness evaluated? Can you show evidence of evaluation?

7.3 Awareness

  • (I) Do employees know the quality policy? Can they explain their contribution to QMS effectiveness?
  • (I) Are employees aware of the implications of not conforming to QMS requirements?

7.4 Communication

  • (D/I) What are the internal and external communication requirements for the QMS? Are they defined?

7.5 Documented Information

  • (D) Is documented information controlled? Is there a document control procedure?
  • (D) Are records retained for the required periods? Is there a retention schedule?
  • (D) Is obsolete documentation prevented from unintended use?

ISO 9001 Audit Checklist: Clause 8 — Operations

8.1 Operational Planning and Control

  • (D/I) Are operational processes planned and controlled? Are acceptance criteria defined?
  • (D) Is documented information retained to demonstrate conformity?

8.2 Requirements for Products and Services

  • (D/I) How are customer requirements determined, including delivery and post-delivery?
  • (D) Is there a contract review process? Are reviews documented before commitment to supply?
  • (D/I) How are changes to requirements communicated and documented?

8.3 Design and Development (if applicable)

  • (D/I) Is design and development planning documented? Are inputs, outputs, reviews, and validation defined?
  • (D) Are design changes controlled and documented?

8.4 Control of External Providers

  • (D/I) How are external providers evaluated and selected? What are the criteria?
  • (D) Is there an approved supplier list? Is it current?
  • (D/I) How is external provider performance monitored?

8.5 Production and Service Provision

  • (D/O) Are controlled conditions in place? Are work instructions available and followed?
  • (D/I) How is product/service identification and traceability maintained?
  • (D) Is customer property identified, protected, and controlled?

8.6 Release of Products and Services

  • (D) Are release criteria defined? Is there evidence of conformity before release?
  • (D) Who has authority to release? Are release records retained?

8.7 Control of Nonconforming Outputs

  • (D/I) How are nonconforming outputs identified and controlled?
  • (D) Are nonconformity records maintained? Do they include disposition decisions?

ISO 9001 Audit Checklist: Clause 9 — Performance Evaluation

9.1 Monitoring, Measurement, Analysis, and Evaluation

  • (D/I) What is monitored and measured? How are methods and timing determined?
  • (D/I) How is customer satisfaction monitored? What data is collected and how is it analysed?
  • (D) Is data analysis performed? Does it evaluate QMS performance and identify improvement opportunities?

9.2 Internal Audit

  • (D) Is there an internal audit programme? Does it cover all QMS processes over a defined cycle?
  • (D/I) Are auditors selected for objectivity? Are they independent of the areas they audit?
  • (D) Are audit results reported to management? Are corrective actions taken for findings?

9.3 Management Review

  • (D) Are management reviews conducted at planned intervals? Are minutes retained?
  • (D/I) Does the review cover all required inputs: audit results, customer feedback, process performance, corrective actions, resource adequacy, risk and opportunity actions?
  • (D/I) [NEW 2026] Does the management review include an assessment of quality culture and ethical behaviour performance?
  • (D) Do review outputs include decisions and actions for improvement?

ISO 9001 Audit Checklist: Clause 10 — Improvement

10.1 General

  • (D/I) How are improvement opportunities identified? Is there a systematic process?

10.2 Nonconformity and Corrective Action

  • (D) Is there a corrective action process? Does it include root cause analysis?
  • (D) Are corrective actions implemented and their effectiveness evaluated?
  • (D) Are records of nonconformities and corrective actions retained?

10.3 Continual Improvement

  • (D/I) How is the QMS continually improved? Can you show evidence of improvement over time?
  • (D/I) How are improvement activities linked to quality culture and organizational learning?

How to Score Your Internal Audit

Use this scoring guide to assess each clause:

ScoreMeaning
C — ConformityRequirement fully met; evidence available
OFI — Opportunity for ImprovementRequirement met but improvement possible
Minor NCRequirement not fully met; isolated lapse
Major NCRequirement significantly not met; systemic failure

A major nonconformity in any clause must be resolved before certification or recertification can proceed. Minor nonconformities require a corrective action plan with a defined timeline.

Frequently Asked Questions

How often should an ISO 9001 internal audit be conducted?

ISO 9001:2026 requires internal audits at planned intervals. Most organizations audit all clauses at least once per year. High-risk processes or areas with previous nonconformities should be audited more frequently.

Can the same person audit their own work?

No. ISO 9001:2026 requires auditors to be objective and impartial — they must not audit their own work. In small organizations, this may require using external auditors or cross-functional audit teams.

What records must be retained from an internal audit?

ISO 9001:2026 requires retaining documented information as evidence of the audit programme and audit results. This includes the audit plan, audit report, findings, and corrective action records.

How is the ISO 9001:2026 audit checklist different from ISO 9001:2015?

The 2026 checklist adds three new question areas: quality culture promotion (Clause 5.1.1), opportunities register (Clause 6.1.3), and climate change consideration (Clause 4.1). All other questions remain the same.

Can I use this checklist for a Stage 2 certification audit?

This checklist is designed for internal audits. Certification body auditors use their own proprietary checklists. However, preparing your team with these questions will help them respond confidently during a Stage 2 audit.

ISO 9001 audit checklistinternal auditISO 9001:2026audit questionsQMS audit

Share this article

Was this article helpful?

Onega Ulanova
Onega UlanovaQuality Management Systems Expert & Lead Auditor
IRCA Certified Lead Auditor, ISO 9001Six Sigma Black BeltAPI Auditor (20+ specifications)MS Engineering & Technology ManagementExecutive MBA

Onega Ulanova is a quality management systems strategist with two decades of experience implementing ISO 9001 and API Spec Q1 across manufacturing, energy, and industrial sectors. She is an IRCA Certified Lead Auditor and former American Petroleum Institute auditor who has audited manufacturers including Schlumberger, Weatherford, GE Oil & Gas, and NOV.

Expertise:ISO 9001 auditing and implementationAPI Spec Q1 quality managementLead auditor practiceCorrective action and CAPASupplier evaluation and flow-downSix Sigma and process improvementManagement review and internal audits