In today’s environment where mature organizations often operate effectively with minimal formal documentation, many auditors’ kind of give up and wonder how they can document such a system. With my background in command and leadership at sea, I naturally appreciate the difference between real operational discipline and paper discipline. Expanding on this thought and my experience here in QMII I thought about how mature auditors could assess effectiveness of a management system without paper through the lens of ISO 9001 specifically and generally for any ISO standard in the harmonized structure.

In many audits, the reflex question still appears early for auditors as “where is the procedure?” It is a fair question but not necessarily always the right one. ISO 9001 does not require organizations to document every process. In fact, the 2015 edition deliberately moved away from mandatory procedures and toward the broader concept of “documented information”. Information where the organization determines what is necessary for the effectiveness of its quality management system (Clause 7.5). That shift was intentional. ISO 9001 is not a documentation standard. It is a management system standard. And management systems operate, not on paper. So how does a mature auditor assess effectiveness when a process is largely undocumented? The answer lies in understanding what ISO 9001 requires and what leadership is expected to ensure.

So, the question is what ISO 9001 really demands. ISO 9001 consistently emphasizes:

  • Process approach (Clause 4.4)
  • Risk-based thinking (Clause 6.1)
  • Operational control (Clause 8)
  • Monitoring and measurement (Clause 9)
  • Leadership accountability (Clause 5)

Nowhere does the standard state that every process must be written down in procedural form. Instead, organizations must, determine the processes needed, establish criteria and methods to ensure effective operation and control, maintain documented information “to the extent necessary” and retain documented information as evidence of results.

The phrase “to the extent necessary” is critical. Necessary for what? For effectiveness. That is the auditor’s focus. Understanding of process vs. procedure is necessary. A process is not a document. A process is a set of interrelated activities that transforms inputs into outputs under controlled conditions. Whereas a procedure may describe the process, but it is not the process itself. Therefore, in mature organizations, processes often operate through, competent personnel, clear roles and accountability, embedded system controls and established culture as also measurable outcomes. The absence of a written procedure does not automatically indicate nonconformity. What matters is whether the process:

  • Is understood,
  • Is consistently applied,
  • Achieves intended results, and
  • Manages risk appropriately.

If those elements are present, ISO 9001 may already be satisfied. Therefore, auditing without paper requires the mature auditor to follow the process, not the binder. Clause 4.4 requires organizations to determine and manage their processes. The auditor therefore audits the process in action. Instead of asking only for a document, the auditor:

  • Traces a real transaction.
  • Observes workflow.
  • Identifies inputs and outputs.
  • Verifies how responsibilities are assigned.
  • Looks for criteria used in decision-making.

The process must be visible in execution even if not in narrative form. If the organization can clearly explain:

  • What triggers the process,
  • Who does what,
  • How decisions are made,
  • What controls exist,
  • How performance is evaluated, then the process is defined. Whether or not it is formally documented is not the question.

Auditors must evaluate operational control (Clause 8). Clause 8 requires organizations to implement production and service provision under controlled conditions. Controlled does not mean documented. It means:

  • Clear specifications.
  • Defined acceptance criteria.
  • Availability of suitable resources.
  • Competence of personnel.
  • Monitoring and measurement.
  • Prevention of unintended outputs

The auditor must therefore ask questions as:

  • What prevents errors?
  • What detects errors?
  • What corrects errors?
  • What prevents recurrence?

Good auditors remember that controls may be embedded in:

  • ERP systems (Enterprise Resource Planning).
  • Workflow approvals.
  • Segregation of duties.
  • Automated validations.
  • Management reviews.
  • Cultural norms.

If controls are real, effective, and consistently applied, the absence of a written procedure may not constitute a gap. Next the auditors looking at undocumented systems must assess risk-based thinking (Clause 6.1). Undocumented processes raise one critical question has the organization assessed the risk of not documenting this process? If a process is, high risk, regulatory-sensitive, complex, dependent on one individual and perhaps prone to variability, then documentation may be necessary to mitigate risk.

However, if a process is, stable, low risk, performed by competent, experienced personnel, supported by system controls and is producing consistent results, then extensive documentation may add little value. The mature auditor connects documentation requirements to risk, not tradition.

The auditors should verify performance (Clause 9). Ultimately, effectiveness is proven in results. The auditor examines, key performance indicators, nonconformity trends, customer feedback, on-time delivery, rework rates and internal audit results. The check stage of the PDCA (plan, do, check & act) cycle must be effective and strong. If performance is stable and improving, this is strong evidence of process control. However, if outcomes are inconsistent, documentation alone will not fix the problem, the leadership must address process discipline.

The Leadership Dimension in clause 5 of ISO 9001 is where undocumented processes intersect directly with leadership. Clause 5 requires top management to:

  • Ensure integration of QMS requirements into business processes.
  • Promote the process approach and risk-based thinking.
  • Ensure resources are available.
  • Communicate the importance of effective quality management.

In organizations operating with lean documentation, leadership maturity becomes the control mechanism. Strong leadership creates, clarity of roles, culture of accountability, shared understanding of expectations, visible engagement with performance and discipline in execution. In such environments, people know what to do, not because it is written, but because it is reinforced through example and oversight. However, weak leadership cannot hide behind undocumented processes. If knowledge resides in one person, if decisions are inconsistent, if performance varies widely, the issue is not missing paperwork. It is missing leadership. Documentation cannot compensate for the absence of direction.

Then auditors must be able to distinguish maturity from informality. The auditor must differentiate between, operational maturity and operational informality. Therefore, the signs of maturity include consistent explanations across employees, clear understanding of objectives, measurable outputs, embedded controls, low dependence on individuals and leadership visibility. At the same time, signs of weakness include:

  • “We just know how it’s done.”
  • Inconsistent answers to the same question.
  • Frequent firefighting.
  • No defined acceptance criteria.
  • Lack of performance data.
  • Heavy reliance on tribal knowledge.

That ISO 9001 requires controlled processes; not necessarily written procedures need understanding. The difference is critical.

Yes, there are occasions when documentation becomes necessary. Even mature organizations eventually require documentation when, scaling operations, expanding geographically, introducing remote teams, experiencing turnover, facing regulatory scrutiny and increasing complexity.

Documentation then becomes a leadership tool, not a compliance artifact. It preserves knowledge, reduces variability, supports training, protects against organizational memory loss. The auditor’s recommendation should therefore be risk-based, not, “You must document this because ISO requires it.” But “given the risk profile and growth plans, documenting this process would strengthen control.” That advice reflects maturity, both in auditing and in leadership.

The auditor’s responsibility in auditing undocumented processes demands more skill than auditing documented ones. Checklist auditing is easy. Process auditing requires, systems thinking, observational skill, strong interviewing abilities, understanding of risk, ability to interpret performance data and good professional judgment. When documentation is minimal, the auditor must work harder, not default to nonconformity. ISO 9001 was intentionally written to encourage organizational maturity, not bureaucratic expansion. The competent auditor respects that intent.

In concluding I would say plan auditing for confidence, not compliance. At QMII we teach auditors that ISO 9001 does not demand paperwork. It demands confidence in consistent performance. When processes are undocumented, the central question becomes, is the organization in control? We ask auditors to remember, if the process is understood, controls are embedded, risks are addressed, results are measured and if leadership is engaged, then effectiveness can be demonstrated even without a formal procedure. However, if these elements are missing, no amount of documentation will create discipline. In the end, auditing undocumented processes is not about paper. It is about leadership, risk, control, and results. And that is precisely what ISO 9001 intended.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Recommended Posts