Auditing Undocumented Processes: How Mature Auditors Assess Effectiveness Without Paper

In today’s environment where mature organizations often operate effectively with minimal formal documentation, many auditors’ kind of give up and wonder how they can document such a system. With my background in command and leadership at sea, I naturally appreciate the difference between real operational discipline and paper discipline. Expanding on this thought and my experience here in QMII I thought about how mature auditors could assess effectiveness of a management system without paper through the lens of ISO 9001 specifically and generally for any ISO standard in the harmonized structure.

In many audits, the reflex question still appears early for auditors as “where is the procedure?” It is a fair question but not necessarily always the right one. ISO 9001 does not require organizations to document every process. In fact, the 2015 edition deliberately moved away from mandatory procedures and toward the broader concept of “documented information”. Information where the organization determines what is necessary for the effectiveness of its quality management system (Clause 7.5). That shift was intentional. ISO 9001 is not a documentation standard. It is a management system standard. And management systems operate, not on paper. So how does a mature auditor assess effectiveness when a process is largely undocumented? The answer lies in understanding what ISO 9001 requires and what leadership is expected to ensure.

So, the question is what ISO 9001 really demands. ISO 9001 consistently emphasizes:

  • Process approach (Clause 4.4)
  • Risk-based thinking (Clause 6.1)
  • Operational control (Clause 8)
  • Monitoring and measurement (Clause 9)
  • Leadership accountability (Clause 5)

Nowhere does the standard state that every process must be written down in procedural form. Instead, organizations must, determine the processes needed, establish criteria and methods to ensure effective operation and control, maintain documented information “to the extent necessary” and retain documented information as evidence of results.

The phrase “to the extent necessary” is critical. Necessary for what? For effectiveness. That is the auditor’s focus. Understanding of process vs. procedure is necessary. A process is not a document. A process is a set of interrelated activities that transforms inputs into outputs under controlled conditions. Whereas a procedure may describe the process, but it is not the process itself. Therefore, in mature organizations, processes often operate through, competent personnel, clear roles and accountability, embedded system controls and established culture as also measurable outcomes. The absence of a written procedure does not automatically indicate nonconformity. What matters is whether the process:

  • Is understood,
  • Is consistently applied,
  • Achieves intended results, and
  • Manages risk appropriately.

If those elements are present, ISO 9001 may already be satisfied. Therefore, auditing without paper requires the mature auditor to follow the process, not the binder. Clause 4.4 requires organizations to determine and manage their processes. The auditor therefore audits the process in action. Instead of asking only for a document, the auditor:

  • Traces a real transaction.
  • Observes workflow.
  • Identifies inputs and outputs.
  • Verifies how responsibilities are assigned.
  • Looks for criteria used in decision-making.

The process must be visible in execution even if not in narrative form. If the organization can clearly explain:

  • What triggers the process,
  • Who does what,
  • How decisions are made,
  • What controls exist,
  • How performance is evaluated, then the process is defined. Whether or not it is formally documented is not the question.

Auditors must evaluate operational control (Clause 8). Clause 8 requires organizations to implement production and service provision under controlled conditions. Controlled does not mean documented. It means:

  • Clear specifications.
  • Defined acceptance criteria.
  • Availability of suitable resources.
  • Competence of personnel.
  • Monitoring and measurement.
  • Prevention of unintended outputs

The auditor must therefore ask questions as:

  • What prevents errors?
  • What detects errors?
  • What corrects errors?
  • What prevents recurrence?

Good auditors remember that controls may be embedded in:

  • ERP systems (Enterprise Resource Planning).
  • Workflow approvals.
  • Segregation of duties.
  • Automated validations.
  • Management reviews.
  • Cultural norms.

If controls are real, effective, and consistently applied, the absence of a written procedure may not constitute a gap. Next the auditors looking at undocumented systems must assess risk-based thinking (Clause 6.1). Undocumented processes raise one critical question has the organization assessed the risk of not documenting this process? If a process is, high risk, regulatory-sensitive, complex, dependent on one individual and perhaps prone to variability, then documentation may be necessary to mitigate risk.

However, if a process is, stable, low risk, performed by competent, experienced personnel, supported by system controls and is producing consistent results, then extensive documentation may add little value. The mature auditor connects documentation requirements to risk, not tradition.

The auditors should verify performance (Clause 9). Ultimately, effectiveness is proven in results. The auditor examines, key performance indicators, nonconformity trends, customer feedback, on-time delivery, rework rates and internal audit results. The check stage of the PDCA (plan, do, check & act) cycle must be effective and strong. If performance is stable and improving, this is strong evidence of process control. However, if outcomes are inconsistent, documentation alone will not fix the problem, the leadership must address process discipline.

The Leadership Dimension in clause 5 of ISO 9001 is where undocumented processes intersect directly with leadership. Clause 5 requires top management to:

  • Ensure integration of QMS requirements into business processes.
  • Promote the process approach and risk-based thinking.
  • Ensure resources are available.
  • Communicate the importance of effective quality management.

In organizations operating with lean documentation, leadership maturity becomes the control mechanism. Strong leadership creates, clarity of roles, culture of accountability, shared understanding of expectations, visible engagement with performance and discipline in execution. In such environments, people know what to do, not because it is written, but because it is reinforced through example and oversight. However, weak leadership cannot hide behind undocumented processes. If knowledge resides in one person, if decisions are inconsistent, if performance varies widely, the issue is not missing paperwork. It is missing leadership. Documentation cannot compensate for the absence of direction.

Then auditors must be able to distinguish maturity from informality. The auditor must differentiate between, operational maturity and operational informality. Therefore, the signs of maturity include consistent explanations across employees, clear understanding of objectives, measurable outputs, embedded controls, low dependence on individuals and leadership visibility. At the same time, signs of weakness include:

  • “We just know how it’s done.”
  • Inconsistent answers to the same question.
  • Frequent firefighting.
  • No defined acceptance criteria.
  • Lack of performance data.
  • Heavy reliance on tribal knowledge.

That ISO 9001 requires controlled processes; not necessarily written procedures need understanding. The difference is critical.

Yes, there are occasions when documentation becomes necessary. Even mature organizations eventually require documentation when, scaling operations, expanding geographically, introducing remote teams, experiencing turnover, facing regulatory scrutiny and increasing complexity.

Documentation then becomes a leadership tool, not a compliance artifact. It preserves knowledge, reduces variability, supports training, protects against organizational memory loss. The auditor’s recommendation should therefore be risk-based, not, “You must document this because ISO requires it.” But “given the risk profile and growth plans, documenting this process would strengthen control.” That advice reflects maturity, both in auditing and in leadership.

The auditor’s responsibility in auditing undocumented processes demands more skill than auditing documented ones. Checklist auditing is easy. Process auditing requires, systems thinking, observational skill, strong interviewing abilities, understanding of risk, ability to interpret performance data and good professional judgment. When documentation is minimal, the auditor must work harder, not default to nonconformity. ISO 9001 was intentionally written to encourage organizational maturity, not bureaucratic expansion. The competent auditor respects that intent.

In concluding I would say plan auditing for confidence, not compliance. At QMII we teach auditors that ISO 9001 does not demand paperwork. It demands confidence in consistent performance. When processes are undocumented, the central question becomes, is the organization in control? We ask auditors to remember, if the process is understood, controls are embedded, risks are addressed, results are measured and if leadership is engaged, then effectiveness can be demonstrated even without a formal procedure. However, if these elements are missing, no amount of documentation will create discipline. In the end, auditing undocumented processes is not about paper. It is about leadership, risk, control, and results. And that is precisely what ISO 9001 intended.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

How to Audit Culture Without Turning It Into a Soft Conversation

Culture (noun): the set of shared attitudes, values, goals, and practices that characterizes an institution or organization

If you think culture is too “soft” to audit, you’re probably looking in the wrong places. Culture has always been integral to management systems. It is what your auditor instinct notices as you start reviewing system documentation and begin your opening meeting. It’s not tangible and yet it’s there slowly forming an image in your mind’s eye. When you conclude that the organization is committed to quality, safety or whatever standard you may be auditing against. 

Culture cannot be found in documented procedures, necessarily. Culture is in how personnel embrace the “What’s in it for me?” and contribute to the overall objective of the system. It’s where the vision is clearly shared and understood. It’s the way work is done. 

The undocumented and intangible cause auditors to push back on these topics. They question how it can be audited and perhaps rightly so. After all should an audit not be based on objective evidence without the introduction of feelings and opinions? Yes and not everything in a system is documented. For example the person’s knowledge of their process, of what constitutes a potential risk, and more.

In this article I address how auditors can assess the culture of an organization

Why Culture Matters to Management System Performance

Culture is what people do even when there is no oversight, when no one is looking. Culture shapes decisions long before procedures are referenced. It must be driven by leadership who must ‘walk the talk’. It’s in the silent messaging based on what leadership prioritizes. 

The organization may plaster the walls with quality and safety posters, but if the senior managers bypass safety and quality requirements to meet deadlines and commercial pressures then that is what everyone does. When objectives are not aligned with the vision of the organization it does not drive the right actions. Think about if you prioritize product quantity over quality. You may still get both however there may be a cost of added scrap. 

Culture drives people to take the right actions. The cornerstone of any good management system is the culture of the organization. The shared attitudes, values, goals, and practices. I said shared! It may be championed by one person but the load must be shared, if not equally then proportionately. 

The Mistake Auditors Make When “Auditing Culture”

Just like auditors and organizations think of customer surveys when assessing customer satisfaction, similarly auditors may think of employee surveys or opinions, when it comes to assessing an organization’s culture. However, culture is more than that. While there may be no documented procedure on it, It is in how well the forms have been completed and the procedure been followed.

Perhaps the biggest mistake auditors make when auditing culture is this: they ask people how they feel instead of examining how the system behaves.Culture is not a mood or a slogan. Culture is the pattern of decisions the organization consistently makes, even when under pressure. When vague questions are asked such as “How would you describe the culture here?” or “Do you feel empowered?” you will always get an answer. But is this answer the truth?

If raising issues in the past led to being labeled negative, empowerment will be described cautiously. If reporting risks slowed promotions, communication will be described as “generally good.” If audits have historically led to blame, then even the most open-ended question will be filtered through self-protection.

The real culture however shows up when production is behind, when a shipment is at risk, when a major client is on the phone, when a safety incident threatens reputation. In those moments, priorities become visible. Do not treat culture as separate from the management system. It is the management system that shapes culture.

Culture as a System Output, Not a Personality Trait

We sometimes perceive culture as a reflection of personalities. And maybe they do play a role in it. As a result when morale is low we may draw a conclusion that it must be a difficult manager. Perhaps when accountability is weak, it must be “those people.” But all this does is give us someone to praise or someone to blame. But culture is not a personality trait. 

What you experience as “culture” is the predictable result of how the management system is designed, reinforced, and lived. It is shaped by objectives, incentives, consequences, communication pathways, and leadership behavior over time. Systems condition behaviour over time.

If an organization consistently closes corrective actions late, perhaps objectives prioritize output over systemic improvement. Perhaps root cause analysis is seen as administrative work instead of strategic work. Perhaps management review does not meaningfully challenge overdue actions. If employees hesitate to escalate risk, that is not a lack of courage. It may be a system that historically punished disruption. If internal audits surface only minor issues year after year, that may not reflect perfection. It may reflect a system that subtly discourages surfacing uncomfortable truths.

Auditing culture, then, is not about assessing personalities. It is about examining whether the system is producing the behaviors leadership claims to value.In the end, culture is evidence. Not of who people are, but of what the system repeatedly produces.

Observable Evidence That Reflects Culture

Every organization has operational realities: nonconformities, customer complaints, missed targets, near misses. How organizations react to these is culture. When a problem surfaces, is the first question, “Who did this?” or “What allowed this?” That single distinction tells you whether the system leans toward blame or learning. 

Look at how objectives cascade from the policy (vision) of the organization. Do KPIs drive short-term output at the expense of long-term system health? Culture leaves fingerprints in escalation pathways, in how quickly risks are reported, in how leaders react when challenged.

Culture is reinforced by incentives, metrics, leadership behavior, and how the management system is actually used. The harmonized ISO structure was designed to drive alignment. Context shapes strategy. Leadership sets direction. Planning addresses risk. Performance evaluation feeds improvement. If those elements are functioning as an integrated system, culture stabilizes around accountability and learning. If they are fragmented, culture drifts toward silos and survival.

Questions Experienced Auditors Ask to Reveal Culture

What reveals culture are questions that trace cause and effect. Questions that explore decisions under pressure. Questions that connect behavior to consequences. Below are a few questions that auditors may consider in assessing culture:

  1. How do you decide which corrective actions deserve deeper root cause analysis and which are “quick fixes”?
  2. How are conflicting objectives resolved between production, quality, and safety?
  3. If I looked at your last five corrective actions, what patterns would I see?
  4. How are lessons learned from one department shared across others?
  5. What does “risk-based thinking” look like in day-to-day decisions here?
  6. If I asked frontline employees what leadership truly cares about, what would they say?
  7. When production is behind schedule, how do you ensure operational controls are still followed?
  8. How do you verify that outsourced or externally provided processes meet your requirements?

I hope the above will give you adequate insight into framing your own questions as you set to auditing to the various ISO 

Integrating Cultural Findings Into Audit Conclusions

Auditing culture does not require abandoning objectivity. The same discipline you apply to reviewing documented information, sampling records, and verifying implementation can be applied to observing patterns of behavior. Culture becomes visible when you connect what people say to what the system consistently produces. When you trace objectives to outcomes. It is evidence-based.

As auditors, we must resist the temptation to reduce culture to sentiment. Equally, we must resist ignoring it because it feels intangible. Culture links leadership to planning, planning to operations, operations to performance evaluation, and evaluation to improvement. If those links are weak, culture will fragment. If they are aligned, culture will reinforce the very outcomes the standard intends. Your audit conclusion should reflect this, not just the presence or absence of documentation.

In the end, auditing culture is about integrity of the system. Does the organization do what it says it values, especially under pressure? Are behaviors aligned with policy and objectives? When you can answer those questions with observable evidence, you audit culture without turning it into a soft conversation.

From Findings to Failure Prevention: How Advanced Organizations Link Nonconformities to System Design

Closing nonconformities does not prevent recurrence – it restores compliance temporarily.

In many organizations, nonconformities are viewed negatively, especially when identified during regulatory or customer audits. Audits are often perceived as tests to pass. Any finding feels like a deduction from a perfect score rather than a signal of system vulnerability.

This perception creates unintended consequences:

  • Findings become tied to performance metrics or bonuses
  • Root cause analysis turns into subtle blame
  • Quick fixes replace systemic improvement

When the cause is attributed to an individual, it provides emotional closure and an easy fix – retraining, reminders, revised SOPs. But these actions rarely address the deeper issue: the system allowed failure to occur.

High-performing organizations take a different view. They recognize that humans are fallible and design systems that anticipate error and make success easier than failure. Corrective action, therefore, is not about fixing people – it is about strengthening system design.

Why Most Corrective Actions Don’t Prevent Failure

One of the most common weaknesses in management systems is the confusion between correction and corrective action

  • Correction addresses the immediate issue.
  • Corrective action eliminates the cause to prevent recurrence.

Under pressure to close findings quickly, organizations often stop at correction. They implement:

  • Additional training
  • Updated procedures
  • Email reminders

These are administrative controls – the weakest level in the hierarchy of controls.

Another major weakness is poor problem definition. When the problem is vaguely described, the solution will inevitably be weak. Effective corrective action begins with clearly defining:

  • What failed
  • Where it failed
  • Under what conditions
  • How often it has occurred

Without clarity at this stage, prevention is unlikely.

Direct Cause vs. System Cause

When something goes wrong, advanced organizations ask two essential questions:

  • How did the system fail the individual?
  • Why did the system fail the individual?

Tools like the 5 Whys can help move beyond direct causes toward systemic causes.

Direct causes may include:

  • Missed inspection
  • Incorrect data entry
  • Procedure not followed

System causes often involve:

  • Inadequate communication pathways
  • Poor documentation design
  • Resource constraints
  • Conflicting priorities
  • Ineffective controls

It may feel excessive to redesign a system for what appears to be a small issue. However, small systemic weaknesses accumulate. Over time, they produce larger failures.

Organizations that consistently pursue systemic causes build stronger safety, quality, and compliance cultures.

How Advanced Organizations Analyze Nonconformities

Mature organizations approach nonconformities using structured methodologies and strong cultural foundations.

In high-performing systems:

  • Employees feel safe reporting issues
  • Findings are treated as early warning signals
  • Prevention is prioritized over closure speed

Within the hierarchy of controls, they evaluate whether they can:

  1. Eliminate the risk entirely
  2. Substitute or automate the activity
  3. Engineer safeguards into the process
  4. Strengthen administrative controls

They also examine:

  • Design weaknesses
  • Feedback loops
  • Resource adequacy
  • Process interactions

A practical and powerful technique is conducting a GEMBA walk. Observing work where it actually happens often reveals system constraints invisible in documented procedures.

Using Audit Findings as Design Input

Audit findings should be treated as design input – not simply compliance gaps.

A process audit helps determine:

  • The true extent of a problem
  • Whether similar vulnerabilities exist elsewhere
  • Weaknesses in process interaction

Experienced auditors create psychological safety. When personnel feel comfortable speaking openly, they often provide the most practical improvement ideas.

Audits should evaluate the suitability, adequacy, and effectiveness of the entire system – not just clause-by-clause conformity.

Linking Nonconformities to Management Review

In some organizations, personnel hesitate to report nonconformities out of concern for leadership exposure. This is a cultural red flag.

Management review should not merely confirm that corrective actions were “closed.” It should evaluate system health and emerging risks.

Leadership should be asking:

  • Are similar failures recurring across departments?
  • Are corrective actions overly focused on training?
  • Are people routinely working around broken processes?
  • Are resource constraints contributing to errors?
  • Are responsibilities unclear?
  • Is leadership unintentionally creating risk conditions?

When nonconformities are analyzed at the management level as indicators of system design strength, risk-based thinking becomes operational rather than theoretical.

The Auditor’s Role in Failure Prevention

Auditing is not about catching mistakes. When auditing becomes adversarial, fear enters the system. Fear suppresses reporting, learning, and improvement.

Strong auditors act as diagnosticians. They look beyond symptoms to identify structural vulnerabilities.

Their tone and questioning style shape culture. When auditors create psychological safety:

  • Employees speak up
  • Organizations learn
  • Systems improve

The goal of auditing is not to “pass.”
The goal is to build resilient systems that produce reliable outcomes even when people are tired, distracted, or under pressure.

Closing a nonconformity is administrative.
Preventing recurrence is strategic.

Mature organizations understand that findings are not blemishes. They are feedback. They are data. They are early warning signals.

That is the shift from compliance to resilience – and from findings to failure prevention.

AS9100 Revision Trends: What Aerospace Auditors Need to Know in 2026

Aerospace auditors are walking into 2026 with an unusual mix of certainty and ambiguity: certainty that the 9100-series will change, and ambiguity about how fast and how big the first wave will be. The International Aerospace Quality Group (IAQG) has been coordinating the next revision to align with the ISO 9001 update cycle, and industry communications increasingly describe a staged approach, with smaller, earlier adjustments followed by a more comprehensive alignment once ISO 9001’s revision is finalized.

QMII opines the practical question isn’t “What will the clause numbers be?” It is, what will organizations struggle to implement, what will certification bodies emphasize, and where will audit trails be weakest during transition? This article focuses on those revision trends—the direction of travel, so our clients, alumni and friends of QMII can sharpen their planning for changes in 2026 without waiting for every last editorial detail.

IAQG’s publicly shared planning materials describe a multi-year schedule that includes coordination drafts, dispositioning of comments, and balloting leading into publication aligned with ISO 9001’s release timing. In parallel, multiple industry briefings and consultants’ summaries describe two update tracks (a narrower-scope update followed by a larger revision tied closely to ISO 9001). ISO 9001 timing matters because it drives the backbone of the expected changes.

The ISO 9001 revision process reached a major milestone with the Draft International Standard (DIS) released on 27 August 2025, and several reputable sources project publication in late 2026 (often cited around September–October 2026 depending on the process steps).
That timing is important because AS9100 (and its next iteration being discussed in industry as “IA9100”) typically layers sector-specific requirements onto the ISO 9001 structure.

A consistent signal from ISO 9001 revision commentary is stronger emphasis on quality culture and ethical conduct, with leadership expected to do more than sign a policy statement. Even where the ISO changes are described as “editorial clarifications,” the interpretation by auditors and customers tends to be that culture and ethics must be demonstrated through governance and day-to-day decisions.

What this looks like in aerospace audits where organizations already operate under intense safety, airworthiness, and customer oversight is that “ethics” often shows up as:

  • escalation pathways for quality/safety concerns.
  • protections against retaliation.
  • independence of quality from production pressure.
  • decision records when delivery commitments conflict with conformity risk.

Therefore, the organizational emphasis and audit requirements for 2026 include and must consider:

  • Leadership interviews become evidence-seeking, not conversational. Ask for examples where leadership chose quality over schedule/cost and how that decision was communicated and verified.
  • Look for “quality culture instrumentation.” Are there measurable indicators beyond NCR counts (e.g., recurrence rates, escape metrics, employee reporting trends, first pass yield vs. risk hotspots)?
  • Test the management review inputs. Culture/ethics themes should show up as risks, objectives, corrective action effectiveness, and resource decisions and not just as a slide with no follow-through.

Supply chain resilience becomes a first-class audit theme and an organizational need for aerospace organizations. Even before formal revisions, the market reality is pushing standards interpretation toward resilience, second sourcing, supplier continuity, counterfeit avoidance, and rapid response to disruptions. ISO 9001 revision commentary increasingly calls out supply chain disruptions and resilience as a clearer focus area.

In AS9100 Rev D, many organizations already struggle with “supplier control” as an administrative exercise (scorecards, approvals) rather than a risk-driven system. And AS9100’s established focus areas as counterfeit parts prevention, product safety, and configuration management tend to intensify supply chain expectations. Changes for 2026 include:

  • Audit the supplier-control process as risk management. If a supplier is “high risk,” you should see enhanced controls: incoming verification strategy, escape mitigation, alternate routing, tighter change notification, and defined containment plans.
  • Trace a disruption scenario. Pick one realistic event (material shortage, special process capacity loss, cyber incident at a supplier) and ask, what is the organization’s playbook? Who triggers it? What evidence exists that it’s been tested?
  • Counterfeit prevention isn’t just training. Look for authenticated sourcing, traceability depth, suspect/unapproved parts handling, and supplier flow-down effectiveness (especially in distribution channels).

Risk-based thinking matures with this update and organizations as also auditors will be expected to distinguish “lists of risks” from risk-managed processes. AS9100 Rev D embedded risk-based thinking broadly, but many implementations still look like static risk registers that don’t change decisions. The direction of travel reinforced by ISO’s revision commentary is toward more explicit proactive risk management, including resilience and continuity. Therefore, the expected changes for 2026 include:

  • Follow risk into planning and controls. Pick a top operational risk and verify it changed something tangible: inspection plans, process capability targets, staffing plans, supplier strategy, buffer stocks, verification methods, or design reviews.
  • Verify risk competence. Who owns risk evaluation? Do they understand likelihood vs. detectability vs. severity? Are criteria consistent across functions?
  • Test the corrective action loop. When a failure occurs, do they update risk controls to prevent recurrence, or just close an 8D?

Human factors and “work environment” evidence becomes more specific. The changes look at aerospace quality failures which are often human-system failures, fatigue, confusing work instructions, poor tool control, inadequate lighting/layout, rushed handoffs. AS9100 Rev D already signaled movement in this direction by requiring consideration of human and physical factors when planning the work environment. The changes for 2026 now include:

  • Observe, then verify. Start on the floor. If you see error-likely conditions (visual clutter, ambiguous labeling, interrupted work, rework loops), then ask what the system does to prevent escapes.
  • Training effectiveness over training completion. Ask operators to demonstrate critical steps and show how competence is maintained when changes occur (new revision levels, tooling changes, new materials).
  • Shift handover is auditable. For critical processes, assess how information continuity is protected between shifts and between internal/supplier handoffs.

World is more and more into digitalization and data integrity becomes audit-critical, not “nice to have”. ISO revision discussions frequently highlight digital transformation and data-driven quality practices. In aerospace, that will collide with:

  • eQMS workflows.
  • digital inspection records.
  • automated test systems.
  • MES/ERP traceability.
  • remote collaboration across the supply chain.

Therefore, the changes for 2026 will trend toward:

  • Data integrity checks. Can the organization show controls for access, versioning, audit trails, backups, and cybersecurity-related risks for quality records?
  • Software-enabled processes. If an app enforces a step (e-signature, validation gate), test whether it can be bypassed, and whether exceptions are controlled and reviewed.
  • Analytics that drive decisions. If they claim, “we use dashboards,” audit one dashboard end-to-end, data source to transformation to interpretation to action and the result.

Climate and sustainability considerations creep into QMS context and risk. ISO 9001 gained climate change considerations via an amendment in 2024, and the 2026 revision discourse continues to treat climate as part of organizational context and risk. This doesn’t automatically mean “environmental management system” requirements but it does mean auditors may increasingly ask how climate-related disruptions affect:

  • continuity of operations.
  • supplier viability.
  • infrastructure risks.
  • regulatory/customer expectations.
  • product conformity risks (materials, storage, transport).

So, in 2026 changes the organizations consider:

  • Keeping it QMS-relevant. Organizations and the auditors are not just looking at ISO 14001 instead the focus is on how climate-related issues are captured in context, risks/opportunities, and planning.
  • Look for materiality. For a site in a storm-prone region, do contingency plans and infrastructure maintenance reflect that reality? For temperature-sensitive materials, are storage/transport controls robust?

Therefore, what aerospace organizations and the auditors should do differently in 2026 is:

  1. Treat transition readiness as an auditable system. Even before formal adoption dates, organizations will be working on readiness. Audit their change management discipline:
  • gap assessment method and assumptions.
  • controlled interpretation of drafts/briefings.
  • documented transition plan with owners and milestones.
  • internal communication and competence-building.
  • “No surprises” engagement with customers and certification bodies.

Just having a plan without governance, will not work. With the updated standard governance is emphasized.

  1. Increase the depth of process-based auditing. The more standards emphasize culture, resilience, and risk, the less value there is in document conformance audits. Go process-first:
  • pick a critical product line or program.
  • follow it from contract/design planning through purchasing, production, verification, shipment, and post-delivery feedback.
  • sample change events (engineering changes, supplier changes, escapes).
  1. Recalibrate “effectiveness” tests. The emerging expectations reward organizations that can show:
  • fewer escapes and less recurrence.
  • faster detection and containment.
  • decisions that reflect risk prioritization.
  • leadership actions that protect product safety and conformity under pressure.

A practical closing view on what will be hardest for organizations with the 2026 changes is that the most common weak points are likely to be:

  1. Culture/ethics presented as slogans rather than measurable behaviors and governance.
  2. Risk registers that don’t change controls, especially in supplier management and production planning.
  3. Resilience talked about abstractly, with no tested scenarios or defined triggers/ authorities.
  4. Digital records without strong integrity controls, especially across multiple systems and suppliers.
  5. Human factors addressed implicitly (“our operators are experienced”) rather than through designed error-proofing and competency evidence.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

AS9100 Revision to IA9100: The Changes to Clauses in the 2026 Version

Aerospace will see a change in 2026 when AS 9100 comes as the revised and renamed standard IA9100 in 2026.  The International Aerospace Quality Group (IAQG) has been coordinating the next revision to align with the ISO 9001 update cycle, and industry communications increasingly describe a staged approach.

The updated ISO 9001 version is expected to be published this year (2026), toward September–October. That timing is important because AS9100 updated as IA9100 is expected toward the same time. This is because IA 9100 will continue to be typically providing sector-specific requirements latched to the ISO 9001 structure. And a consistent signal from ISO 9001 revision commentary is stronger emphasis on quality culture and ethical conduct, with greater expectations from leadership and their involvement. Even where the ISO changes are described as editorial clarifications, the interpretation by organizations, auditors and customers tends to be that culture and ethics must be demonstrated through governance and day-to-day decisions.

Looking at the 2026 version some of the changes on a clause-by-clause basis that organizations, auditors can expect are toward effective implementation proved by actual actions and results:

  • 5.1 Leadership and commitment (especially how leadership drives culture and accountability).
  • 5.2 Policy (is it lived or framed?).
  • 9.3 Management review (outputs that change the system, not just minutes).

Supply chain resilience becomes a priority and a first-class audit theme. The ISO 9001 revision discourse also highlights supply chain disruption and resilience more directly. In aerospace, resilience is inseparable from product safety, counterfeit avoidance, special process control, and traceability. Therefore, what auditors should look for is, risk-tiered supplier controls that change inspection strategy, verification depth, and containment plans. Disruption playbooks, realistic scenario drills (material shortage, special process capacity collapse, cyber event at a supplier, geopolitical shipping impact). And the flow down effectiveness to see if customer/statutory requirements and key characteristics are properly transmitted and verified? These clauses are relevant:

  • 8.4 Control of externally provided processes, products and services (supplier selection, monitoring, re-evaluation).
  • 6.1 Actions to address risks and opportunities (supplier and continuity risks).
  • 8.1 Operational planning and control (contingency thinking in operational control).

Counterfeit part prevention stays central for organizations and auditors will probe end-to-end traceability. Counterfeit prevention is already explicit in AS9100 Rev D operational controls, including planning and control for prevention of counterfeit or suspect counterfeit part use. In practice, many systems still over-rely on training and “approved supplier” lists while leaving gaps in distribution channels and returns/repairs. The changes relate to what auditors should look for (beyond training records) are authenticated sourcing and purchasing controls, traceability depth sufficient for risk and part criticality. Also, controls for suspect parts (segregation, reporting, disposition, customer notification where needed) and receiving verification strategy linked to supplier risk and history. This would mean looking at these clauses:

  • 8.1 Operational planning and control (where counterfeit prevention is implemented in practice).
  • 8.4 Supplier control (distribution risk, broker controls).
  • 8.7 Control of nonconforming outputs (suspect parts containment and disposition).

The risk-based thinking matures in the revised standard and auditors must separate “risk lists” from risk-managed operations. A common failure mode today is a static risk register that doesn’t change controls. The ISO revision commentary continues to reinforce clearer expectations around risk, resilience, and communication of contingency-related topics. This would see risk changing the plan in terms of inspection, verification, staffing, supplier strategy, buffers, first-article strategy, special process oversight. Also, risk competence in terms of consistent criteria and decision rights. Corrective action feedback would be checked to see if major issues trigger updated controls and re-assessed risk? Therefore:

  • 6.1 Actions to address risks and opportunities.
  • 8.1 Operational planning and control.
  • 10.2 Nonconformity and corrective action.

For human factors and “work environment” evidence becomes more specific (and more observable). Aerospace escapes are frequently human-system failures. AS9100 already expects organizations to determine and manage the work environment, including human/physical factors. In a revision climate emphasizing culture and effectiveness organizations will be expected to implement reality and link it to control design. Auditors will be required to observe these and audit them. This would mean looking for error-likely conditions (interrupt-driven work, ambiguous WI’s (work instructions), rework loops, poor 5S/tooling discipline) and competence effectiveness (can the operator explain critical steps and acceptance criteria?) as also, shift handover integrity for critical operations. The clauses applicable would be:

  • 7.1.4 Environment for the operation of processes.
  • 7.2 Competence / 7.3 Awareness.
  • 8.5 Production and service provision (work instruction use, verification, tooling)

Another trend likely to be seen in IA9100 would be digitalization and data integrity becoming audit-critical, not “nice to have”. ISO 9001 revision commentary highlights digitalization and modern data-driven management. Aerospace auditors should therefore elevate scrutiny of digital records, e-signatures, MES/ERP traceability, (Manufacturing Execution System and ERP – Enterprise Resource Planning, traceability refers to the integrated digital record that tracks a part, from its raw material origin through every production step to final delivery) and automated test systems, and data transformations used for decision-making. Therefore, aerospace organizations should look for data integrity controls, access, versioning, audit trails, backups, retention and bypass risk to see can the required workflow steps be overridden without controlled authorization. Dashboard traceability to see from source system to transformation to metric  to decision to action and finally to the result:

  • 7.5 Documented information (control of digital records).
  • 9.1 Monitoring, measurement, analysis and evaluation (validity of metrics).
  • 8.1 / 8.5 Operational control (system-enforced steps, automated verification).

Aerospace auditors in 2026 would therefore see an audit approach that fits the revision trends to audit “transition readiness” as a controlled process. Even before formal adoption dates, many organizations may consider starting aligning language and practices to see if they have a controlled gap assessment method, a revision/transition plan with owners and milestones, controlled internal communications and competence updates and disciplined change control over procedures and process controls. The clause anchors for this are:

  • 3 Planning of changes.
  • 5 documented information.
  • 2 internal audit.
  • 3 management review.

For the go process-first organizations will follow each product and follow the risk. The auditors will check this by picking one high-impact product line or program and trace it from contract/design planning to purchasing leading to production then verification and release as also post-delivery feedback. Sample at least one change event (supplier change, drawing revision, special process change, escape). The relevant clauses to do this would be:

  • 4 process approach.
  • 1–8.7 operations.
  • 2 corrective action.

Elevation of effectiveness tests in 2026 would require audit conclusions to increasingly hinge on whether the system produces fewer escapes and less recurrence, faster detection and containment and pinpoints decisions that visibly reflect risk and culture commitments. Clause anchors for these would be,  9.1 performance evaluation and 10.2 improvement.

Based on the revisions expected in IA9100 2026 I could sum up for aerospace auditors a clause-based checklist (field-ready) with grounded evidence to perhaps be:

  • 5.1 / 9.3: Show me a leadership decision where quality/product safety won over schedule—what changed afterward?
  • 6.1 / 8.4: How do supplier risks change receiving inspection, verification, and contingency planning?
  • 8.1 / 8.7: Walk me through your counterfeit/suspect part prevention and containment from PO to disposition.
  • 7.1.4 / 7.2: What human-factor risks exist in this process, and what controls reduce error-likelihood?
  • 7.5 / 9.1: Prove this KPI: data source, transformations, access control, and how it drove action.

Summing up I would guess the hardest for organizations would be to consider the most common weak points they will likely see are:

  • Culture/ethics presented as statements, not governance and measurable behaviors.
  • Risk registers that don’t change controls, especially in supplier management and production planning.
  • Counterfeit prevention that’s not end-to-end, particularly in distribution and returns/repairs.
  • Digital records without strong integrity controls, especially across multiple systems.
  • Human factors handled informally, without designed controls and competence verification.

If auditors hold the line on evidence—governance, traceability, effectiveness—the transition to IA9100 can strengthen aerospace quality rather than just reshuffle terminology. IA9100 clause numbering and wording may evolve until formal publication. This article intentionally anchors to the stable ISO 9001 / AS9100 structure (Clauses 4–10) to remain usable throughout the transition.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

How to Audit Undocumented Processes: Practical Tools for Internal Auditors

Undocumented processes are ubiquitous. They emerge when people invent expedient workarounds, when systems lag behind evolving operations, or when tacit knowledge simply lives in employees’ heads. While these informal processes can be efficient, they also create risk: inconsistent outcomes, poor control, hidden single points of failure, compliance gaps, and difficulty demonstrating due diligence to auditors or regulators.

Auditing undocumented processes requires a different skill set than checking documented procedures: you must be a careful investigator, an evidence‑first interviewer, a data sleuth, and a pragmatic synthesizer who delivers usable outputs (not just findings).

This guide provides a practical, step‑by‑step toolkit and templates internal auditors can use to surface, assess and help formalize undocumented processes.

Clarify objective, scope and value

Start by defining why the audit is needed. Objectives might include assessing control effectiveness, verifying compliance, validating corrective action, identifying business continuity risks, or preparing the process for formalization. Limit scope to one process or a narrowly defined subprocess so you can dig deep rather than skim many shadows. Articulate the value for stakeholders up front-demonstrate you’re there to reduce risk, not to police personalities or on an inspection round.

Identify the de-facto owners and stakeholders

Undocumented processes usually have a “de facto” owner—someone who runs the work daily but may not appear on org charts. Use interviews with supervisors, system logs, or simple triangulation (“who signs off on X?”) to find them. Brief stakeholders on the purpose, scope and expected outcomes of the audit; getting buy‑in reduces defensive behavior and improves access to evidence.

Use structured discovery frameworks

Adopt a concise process discovery tool such as SIPOC (Suppliers, Inputs, Process, Outputs, Customers) or PIPS (People, Inputs, Process, Systems). These one‑page frameworks help quickly establish boundaries, expected outputs and interfaces even without formal procedures. Create an initial draft map during the kickoff meeting—doing this collaboratively both gathers knowledge and signals your methodical approach.

Evidencefirst interviewing

When interviewing staff, ask for artifacts, not assertions. Use these techniques:

“Show me” requests: ask to see the last 3–5 completed cases, tickets, orders, change requests or emails that represent normal workflow.

Scenario probing: “Walk me through how you handled ticket #123 last Wednesday from start to finish.”

Document chase: request logs, timestamps, approvals, system entries, reconciliation files and any physical evidence (tags, manifests). Avoid leading questions. Record factual timelines and capture exact phrases when people describe exceptions or informal rules.

Transaction tracing: purposive sampling and end‑to‑end follow

Select a purposive sample of recent transactions—choose items that are typical, borderline, and exceptional. For each, trace the lifecycle: initiation, validation, approvals, handoffs, controls, exceptions, completion, and post‑action reconciliation. Use a transaction tracing worksheet (fields: ID, date/time, initiator, systems used, handoffs, controls observed, evidence located, anomalies). Tracing multiple items uncovers patterns: recurring workarounds, undocumented checkpoints, or missing reconciliations.

Silent observation and shadowing

Observe work in situ-silent shadowing during normal operations reveals deviations and shortcuts that people may not report. Rotate observations across shifts and workload peaks to see variability. Use time‑motion notes to capture durations, handoffs and informal controls. Observation is powerful for processes with a physical element (warehouse picking, handover logs, machine operator routines) and for revealing tacit knowledge.

Data analytics and system interrogation

Systems often hold the documentary evidence even when procedures do not exist. Extract logs, check non conformity logs and check it’s trends especially those non conformities that have been repeating, transactions, user access records, change histories, reconciliation files, and exception reports.

Simple analytics-pivot tables, sequence checks, duplicate detection, out‑of‑hours activity flags, and time‑to‑completion distributions—can corroborate interview findings or surface anomalies you didn’t see on the floor. Where permitted, use filters to find outliers and then trace those back to the people and steps that produced them.

Identify implicit controls and grade effectiveness

Not every control is written. List implicit controls you discover (segregation via separate systems, verbal supervisory checks, reconciliations, dual entry by different roles). For each control, evaluate:

Existence: is it consistently applied?

Evidence: is there a recorded trail?

Owner: who is responsible?

Frequency: how often is it performed?

Effectiveness: does it detect/prevent the related risk? Use a simple scoring matrix (Effective / Partially Effective / Ineffective) tied to risk impact and likelihood.

Map risks to controls and prioritize findings

Translate process gaps into risk statements (fraud, error, data integrity, regulatory noncompliance, single‑point‑of‑failure). Prioritize findings by risk severity and exploitability. For critical risks require immediate mitigation (temporary controls, access restrictions, segregation of duties) and escalate to management if necessary.

Produce a validated onepage process map and Quick SOP

One of the highest‑value audit deliverables is a validated one‑page process map and a Quick SOP (3–8 steps). Draft these from your traces and observations, then review them with the de facto owner and SMEs in a validation meeting. The Quick SOP should include: purpose, scope, steps, responsible roles, key controls, evidence to retain, and critical timelines. This turns tribal knowledge into a usable artifact and accelerates formal documentation.

Report with practical, prioritized recommendations

Structure findings as: condition → criteria (what should be) → cause → effect/risk → recommendation → owner/timeframe. Prioritize quick wins (retain evidence, simple reconciliations, temporary segregation changes) and medium/long‑term fixes (formal SOPs, automation, redesign). Provide sample corrective actions and, where helpful, a template Quick SOP and transaction trace annexes so the process owner doesn’t start from scratch.

Ensure rootcause focus and verification

Insist on root‑cause analysis for any significant nonconformity and require corrective actions with measurable success criteria. Avoid administrative closures—verification should be evidence‑based (data, subsequent traces, or direct observation). Schedule focused follow‑up audits or data checks to confirm effectiveness.

  • Tools and templates (practical, lightweight)
  • Keep tools simple and shareable:
  • SIPOC/PIPS one‑page template
  • Transaction tracing worksheet
  • Observation/time‑motion log
  • Quick SOP template (purpose, steps, owner, controls, records)
  • Control effectiveness scoring matrix
  • Data extraction checklist with suggested flags (duplicates, out‑of‑hours, missing reconciliations)
  • Sample management reporting slide: heatmap of risks and status of actions
  • Cultural and ethical considerations

Approach audits as collaborative improvement, not blame. Undocumented processes often evolved to solve real operational problems; acknowledge this and highlight where formalization will reduce risk without adding unnecessary bureaucracy. Protect confidential and personal data when handling records; comply with privacy rules and get consent from data owners where required. Use unannounced checks judiciously to reduce rehearsed responses but balance with respect for staff.

From audit to durable change

Audits of undocumented processes should not stop at reporting. Drive transition from Quick SOPs to formalized procedures by linking findings to training, process redesign, automation projects, and management review. Measure success with KPIs tied to the process (exceptions per 100 transactions, time to complete, number of post‑transaction corrections) and track trends post‑implementation.

Conclusion

Auditing undocumented processes demands investigative rigor and practical empathy. By combining structured discovery (SIPOC), evidence‑first interviewing, transaction tracing, observation, data analytics and lightweight deliverables (one‑page maps and Quick SOPs), internal auditors can convert tribal knowledge into auditable controls, reduce risk, and add immediate operational value. The result is a process that’s safer, more consistent, and ready for formal quality, compliance or continuity governance.

Integrated Audit Strategies for ISO 9001, ISO 14001 & ISO 45001

I recently completed an integrated audit that addressed multiple standards (RC14001, ISO 9001, FSSC 22000, RSPO, and HALAL). Auditing this way is especially valuable for organizations that operate under more than one framework, because it helps reduce duplicated effort, save resources, and create better alignment across business goals, without making the management system feel like a burden to the people using it 

In a recent webinar, I discussed how to run a more effective management review, and why an integrated approach can give leadership the kind of insights and decision-ready information they actually value. In this article, I’ll build on that theme by sharing practical strategies for integrated audits and how organizations can use them to stay compliant, improve performance, and keep multiple standards working together as one system.

Why Organizations Integrate Management System Audits

Management systems are a great way to bring structure to how a business operates. Without that structure, it can often feel like the organization is constantly fighting multiple fires. A process-based approach helps bring order to the chaos by making it easier to understand the context the business operates in, set clear goals, identify risks, and put plans in place that can be implemented, monitored, and reviewed.

For many organizations, the push to implement multiple management systems is mainly market-driven. Customers, regulators, or industry schemes may require certification as a condition of doing business. A smaller number of companies adopt management systems simply because they recognize the value, even when certification isn’t required. The problem is that management systems are often implemented in a piecemeal way, as new requirements arise. For example, a company may already have ISO 9001 in place, then a new requirement for ISO 45001 comes along. Instead of integrating the new standard into the existing system, a separate ISO 45001 “system” gets built alongside it.

When integrated management systems are implemented well, the benefits are significant. They reduce duplication, improve alignment, and make the system easier for people to use. And when the system is easier to implement and maintain, it naturally improves buy-in and strengthens commitment across the organization.

Common Structures Across ISO 9001, 14001 & 45001

What makes the ISO standard easier to implement is the harmonized structure used by ISO in developing the standards. This approach starting in 2013 has made it easier to integrate owing to the similar unified clause structure. The standards now also follow the flow of the PDCA cycle with the standards laid out in the plan – implement – performance evaluation and improvement approach. 

The common clause structure allows for a better integrated manual without the need for a cross-reference matrix. Additionally organizations can now maintain a common risk register, conduct integrated audits, plan a common management review, have one policy (ensures no conflicts with other policies) and a common documentation approach. 

Planning an Integrated Audit Program

Planning an integrated audit program may at first seem challenging especially with finding resources that can audit to the multiple standards in one audit. Let us first look at the approach to a good audit program. 

A good audit program goes beyond meeting the minimum requirements. Often I come across organizations that do audits just once a year. The justification is that there is QC in place, site walk-throughs by safety, operational inspections and regulatory/customer audits. Organizations must keep in mind that the scope of each of these may be different from that of an internal audit. While it may appear that various inspections and audits are being performed, the lens through which the system is being looked at may be very different. 

For example in an inspection the focus is only on the output of a process and whether the output is conforming or not. In regulatory audits the focus is on regulatory requirements and compliance not necessarily on the process performance. Internal audits focus on process effectiveness and move beyond conformity. Based on the risks associated with a process the leadership must determine the interval at which they want to audit each process. 

For internal audits it is best to audit a few processes every month or every other month and then to conduct a system audit once a year.

Process-Based vs Clause-Based Integration

The ISO standards promote a process-based and risk-based approach to internal audits. While it may seem easier, or even more logical at first, to conduct a clause-based audit, it is often not very effective. The main reason is simple: it doesn’t paint the whole picture.

When we audit a process, we can assess conformity to multiple clauses at the same time, within the real flow of work. That is where integration becomes practical. There are a few situations where a clause-based approach may still make sense, such as when auditing leadership commitment to the system, or when reviewing how documented information is created, updated, and controlled across the organization.

A process-based approach allows the auditor to connect the dots between contextual risks, the planning done to address those risks, the controls and actions implemented, and the evaluation of effectiveness. Building on this, auditors can also assess how well the process is actually working in practice, not just whether the organization can point to a procedure that says it exists.

Risks of Poorly Integrated Audits

As stated at the start of this article, one of the biggest challenges in conducting integrated audits is having the internal resources who are competent across multiple standards. Many of our clients, especially those working with smaller budgets, find themselves trying to hire that one person who understands everything, and can audit everything. In reality, that’s a unicorn find.

Organizations generally have two options to address this.

The first is to outsource internal audits to an auditing organization or auditor who already has experience across multiple standards. In many cases, the provider will assign a team of auditors with the competence to cover the relevant requirements. Depending on the scope, this could be a team of two, or even four. Of course, the more auditors involved, the higher the cost.

The second option is to build internal capability by training the organization’s own audit team across the required standards. This does involve investment in the individuals selected, but it also creates long-term value. QMII typically recommends training a minimum of 10% of the workforce as internal auditors, up to a total of 10 auditors. This creates a strong pool to choose from and also supports more objective and impartial auditing.

QMII’s modular training approach helps organizations build audit capability quickly, without needing to put people through a full 4–5 day lead auditor course for every standard. Running an in-house auditor course can also create economies of scale and allows the training to be more customized to the organization’s own processes and risks.

Building Integrated Audit Capability

Integrated audits don’t fail because the standards are difficult. They fail because the organization does not have enough people who can confidently audit across the scope. The key to building integrated audit capability is to stop thinking of auditors as “ISO 9001 auditors” or “ISO 14001 auditors” or “ISO 45001 auditors” and start developing auditors who understand process performance, risk-based thinking, and system effectiveness. Once that foundation is strong, adding additional standards becomes far easier.

The goal is not to create a team of “super auditors.” The goal is to build a pool of competent internal auditors who can look at a process and understand how it supports quality outcomes, environmental controls, and worker safety all at the same time. When an organization can do that, integrated auditing becomes practical, consistent, and sustainable.

A good way to start is by building capability around the process approach. This means training auditors to follow the workflow, understand inputs and outputs, ask the right questions, and confirm that controls are working as intended. In many organizations, this is where the biggest value is gained, because audit conversations move beyond “show me a procedure” and into “show me how the process is managed.” This is exactly where QMII adds value. Our training is designed to build real audit skill, not just theoretical knowledge of clauses. 

Ultimately, when audit capability is built the right way, integrated audits stop being a burden and start becoming a value adding tool. They provide leadership with better insight, stronger confidence in controls, and a clearer view of where the system needs to improve before problems grow into incidents, complaints, or nonconformities.

How to Quantify Audit Value: KPI Models for Internal Audit Functions in 2026

In some organizations QHSE functions and the associated management system are seen merely as compliance requirements and not as a value add to the system. As such, budgets allocated to QHSE programs are viewed as an overhead. Since they are viewed as not directly contributing to the bottom line.

Mature organizations realize the impact QHSE programs have on a system. A conforming service or product means lesser returns, greater customer satisfaction, better employee morale, lower operating costs and better governance. The cost of not having an effective QHSE program is much higher. 

However often it is left up to the QHSE program managers to justify their budgets and in some cases the program itself. In an organization I was supporting, the QC function tried to get rid of the QA program completely, citing it was redundant. Here is where having good metrics can justify the value add the QHSE and Internal Audit Functions provide.

Why “Audit Value” Is Under Scrutiny in 2026

When perceived as merely a compliance check box the internal audit can seem an expensive proposition. There are many other means of oversight within the organization including leadership ‘GEMBA’ walks, inspections, supervisor oversight and a plethora of other audits including customer audits. 

Attempting to go beyond the bare minimum to merely meet a requirement, increases internal audit budgets. Justifying high overhead costs to an investor or stakeholder that is taking away from the profit margins may be challenging for leadership. 

Internal audits are meant to sample the system to assess its continuing effectiveness. Note sample. Not to guarantee its effectiveness. When a regulatory audit identifies an issue that was missed by an internal auditor the board and others may question the effectiveness of such programs. They may fail to recognize that the scope and objective of the two audits may have been different. 

The Shift from Compliance Audits to Performance Audits

Internal Audit functions began in the financial world in the 16th century. They expanded to focus on quality outputs during the World Wars. At the time the focus was merely on ensuring a quality output with little focus on the process. Ever since system thinkers have been trying to change the mindset about audits with little progress.

Traditional Compliance-Driven Audit Models

Traditionally, as stated above, audits were about ensuring compliance and conformity. Little importance was given to the amount of scrap, waste or rework. Customer satisfaction was the goal and many a time with impact on the efficiency of the process. During the wars it did not matter how many products were non-conforming so long as they were identified and segregated.

Audits were merely about ensuring the requirement was met. This has since changed.

Modern Performance-Driven Audit Models

Internal audits now focus on the continuing adequacy, suitability and effectiveness of the system. The goal of management systems has changed from being a reactive tool to being a proactive approach to identifying and managing risks to the system. Standards now ask organizations to assess the context of operations, risks to meeting objectives and action taken to ensure that the objective can be met.

Audits thus use a risk based approach to this planning to ensure that the the system is performing as expected and will continue to do so.

Defining “Value” in an Internal Audit Context

So what is meant by a value-added audit? It is one that uses a risk based approach to sample the controls and resources in the system. Based on this sample, the auditor is assessing the effectiveness of the system (think people, processes and their interaction) to manage risks. 

Auditors accept that non-conformities and new risks may arise. They assess if the system will catch it timely and address it to ensure that the possibility of it impacting the system now and in the future is minimal.

Value is added by assessing process efficiency in meeting process and system objectives. In eliminating process waste. Finally audit outputs must provide insights to leadership on the state of the system. How is my system working? What are the risks? Where is it robust and where is it fragile? 

KPI Categories for Internal Audit Functions

Effective internal audit KPIs should reflect more than activity counts, grouping measures into categories that show how audits manage risk, improve processes, support compliance, and contribute to business performance.

Risk Management KPIs

Risk management KPIs evaluate how well internal audits identify, assess, and help reduce significant organizational risks before they escalate into issues.
Example: Cost of impact of high-risk audit findings if not timely identified.

Process Effectiveness KPIs

These KPIs focus on whether audit activities lead to measurable improvements in process performance, consistency, and control effectiveness over time.
Example: Reduction in repeat findings for the same process across successive audits.

Compliance Stability KPIs

Compliance stability KPIs track trends in regulatory findings and external audit results to indicate whether controls are becoming more reliable and sustainable, not just temporarily fixed.

Example: Year-over-year decrease in major nonconformities raised during external audits.

Business Impact KPIs

Business impact KPIs translate audit outcomes into tangible value, such as cost avoidance, downtime reduction, or improved decision-making, helping leadership see audits as a business enabler rather than a compliance exercise.
Example: Estimated cost savings from audit-driven corrective actions that prevent production delays or rework.

Linking Audit KPIs to Management System Performance

Organizations may find it challenging to find appropriate KPIs since you may not know the exact cost of the non-conformity unless it occurs. A general approximation can be made with assumptions outlined.

ISO 9001 – Quality Performance Indicators

Audit KPIs under ISO 9001 should demonstrate how audits contribute to consistent product and service quality, process control, and customer satisfaction.

Example: Reduction in customer complaints linked to corrective actions arising from internal audit findings.

ISO 14001 – Environmental Performance Indicators

For ISO 14001, audit KPIs should reflect how effectively audits identify environmental risks, compliance gaps, and opportunities to reduce environmental impact.

Example: Decrease in environmental incidents or permit deviations following audit-driven improvements.

ISO 45001 – Safety Performance Indicators

ISO 45001 audit KPIs should show how audits support hazard identification, risk reduction, and safer working conditions.

Example: Reduction in near-miss recurrence after audit findings addressing unsafe conditions or behaviors.

Why Most Audit Functions Fail to Demonstrate Value

As with all other processes, the internal audit function too should have a process objective that can be made measurable and should be based on the framework set in the policy. Read clause 6.2 read in conjunction with clause 5.2 of the ISO management system standards.
Often this KPI is merely the performance on an annual audit. Not even the outcome of the audit. Just that the audit was completed. This is because the audit is merely seen as an annual ritual that must be completed.
Without effective KPIs the value of the internal audit function cannot be highlighted to leadership and they cannot perceive the cost savings or rather the low investment costs for the high returns!

Building KPI-Driven Audit Programs – A System Approach

Defining Audit Objectives

Organizations must outline what it is that they want the audit program to achieve. Think beyond just compliance. An example of this may be “To provide timely insight to leadership on system risks and opportunities”

Mapping Processes

Based on this objective, now map the audit program to the processes within the system based on contextual issues impacting the system (example high turnover, supply chain issues, etc.). Use this as a basis to develop a risk based approach to performing internal audits. This would include the frequency of audits (some processes would get audited more than once a year based on risk), the selection of the audit team, the sample size and the duration of the audit.

Selecting Meaningful Indicators

With the audit objective achieved the program manager can now begin to select meaningful indicators of how the audit program has added value to the system. How it goes beyond checking for compliance and now identifies risk proactively

The Role of Auditor Competence in Measuring Value

As stated in the paragraph above the selection of the audit team is a critical step in the internal audit function. The organization must consider the competence of the auditor and select them based on the criteria outlined in ISO 19011. The auditor must then be assessed at some interval to determine their continuing competence.
Auditors must be impartial and objective and use a processes based approach to auditing. They must have the ability to perform analytical thinking, keeping their biases and prejudices at bay. Further the auditor must have the ability to frame good audit questions that seek to dive deeper and get a true picture of the functioning of the system.

How QMII Trains Auditors to Deliver Measurable Value

QMII’s auditor training focuses on developing professionals who can evaluate system effectiveness, identify real risk, and communicate insights that drive meaningful management action.

Process effectiveness auditing – Auditors are trained to assess how processes actually perform in practice, not just whether procedures exist, using evidence that links controls to outcomes.

Risk-based audit training – QMII emphasizes risk-based thinking so auditors prioritize what matters most to the organization, aligning audit focus with strategic, operational, and compliance risks.

Real-world audit case analysis – QMII training includes real audit scenarios and failures, helping auditors recognize systemic issues, weak signals, and unintended consequences that checklists often miss.

Executive-level reporting skills – Auditors learn how to translate audit findings into clear, focused insights that leadership can act on, rather than just a completed check-off list.

2026 and Beyond – The End of “Tick-Box” Auditing

Internal auditing can no longer survive as a compliance ritual measured by audit completion alone. As this article shows, audit functions that fail to quantify risk reduction, process effectiveness, compliance stability, and business impact will continue to be viewed as overhead, despite the very real cost of unmanaged risk, waste, incidents, and poor governance.

The future belongs to performance-driven, risk-based audits that provide leadership with clear insight into how well the management system is working, where it is fragile, and where it creates value. When supported by meaningful KPIs, competent auditors, and systems-aware training, internal audits move decisively beyond tick-box conformity and become a strategic tool for resilience, improvement, and sustained organizational performance.

Right-Sizing TSMS Under Subchapter M: Cutting COI Deficiencies with Data-Driven Internal Audits

Right-Sizing TSMS Under Subchapter M

The onset of regulatory requirements causes organizations to rush their efforts to ensure compliance within the deadline issued. Management systems while enabling compliance are not intended solely for compliance. Their primary purpose is to provide a framework for the organization to meet leadership objectives using a systemized approach. Additionally it is meant to act as a preventive tool so that organization can proactively manage risks. 

The requirements for Towing Safety Management Systems or TSMS were similarly met with organizations rushing to document (perhaps over-document) everything! Many implemented the TSMS just to pass an audit and keep records of “compliance”. The management system failed to reflect actual practices and thus created a burden of paperwork for those on board. Especially with small tow boats with limited crew this has created more problems. Further the system does nothing to improve safety in any way. 

The documentation (TSMS) now leads to further problems during audits because the written TSMS does not reflect the TSMS actually lived on board. Despite good intentions inconsistencies arise and COI deficiencies are identified. Management systems designed around the “as-is” enable organizations to develop an operationally realistic TSMS that matches how the company actually works and makes it easier to maintain. 

The Compliance Trap in Subchapter M Auditing

Subchapter M was intended to usher in a new era of safety within the towing vessel industry. This followed many years of regulatory development and was the result of an increase in accidents and incidents involving tow boats. However as with many regulatory requirements the focus has been merely compliance while work continues as normal. When a view of the management system equating compliance is taken then leadership ashore and on board tend to merely “fix” or “prepare” the system for internal and external audits.

Personnel forget that audits are merely a sampling of the system and not a comprehensive review. In some cases auditors tend to conduct the audits more like inspections than audits. They become merely a review of the paperwork then an assessment of actual practices on board. Auditors must verify the crew’s understanding of the system. However, in an effort to pass audits records are updated the day before, only the most well-versed crew members are presented to the audit team and practices are limited to the minimum so the auditors do not have much evidence.

Compliance focused audits therefore may fail to uncover the systemic causes of repeated deficiencies. 

Understanding the Audit Requirements in $138.315

One of the biggest misconceptions I see among operators is their understanding of what $138.315 actually expects during an internal audit. Many assume the regulation is asking for a paperwork confirmation exercise of “show me the TSMS manual, show me the forms,” and that’s enough to satisfy Subchapter M. But $138.315 is far more purposeful than a documentation review. It requires an internal evaluation that verifies two things: that the TSMS is implemented and that it is effective. This distinction is where operators fall short.

The regulation expects internal evaluations to be evidence-based, meaning the auditor must look beyond the binder and confirm that what is written actually reflects what happens on the vessel and in day-to-day operations. Operators often assume that if the forms are filled out and the policies exist, they are compliant. But $138.315 is explicitly tied to the idea of system performance, not paperwork completion. A beautifully formatted SMS means nothing if the crew doesn’t understand it or if the vessels operate differently from what the manual describes. This is why TSMS audits under Subchapter M must go deeper than document checks. 

Subchapter M is not trying to make life harder for operators. It is designed to ensure the TSMS reflects reality and results in safer, more reliable operations. When internal audits focus on objective evidence rather than documentation alone, they fulfill the intent of the regulation and help operators find the issues before the Coast Guard or TPO does.

Using Data to Drive Audit Priorities

As a preventive tool the management system must provide the leadership with the evidence needed to make data driven decisions. This is where well set KPIs provide the leadership with inputs needed to determine if the system is being implemented effectively as planned and to identify trends for timely action. The KPIs including near-miss trends, machinery downtime, and incident reports enable the organization to target audit areas. Not to solely focus on the problem areas but to take a deeper dive into these areas.

Internal auditors may use statistical based sampling to develop their audit plan. Such an audit plan is then a risk based plan that allows for a deeper dive in certain areas. Additionally the company may determine the need for special audits outside of the normal periodic timeframe. Operators however do not need to wait for an audit to take action on data trends. “Repeat offenders” (tasks, equipment, vessels, crew behaviors) when identified through trend analysis can be acted upon immediately. 

A key role is played here in the checklists that auditors use. Audit checklists should primarily consist of open ended questions that begin the conversation. Auditors then build on these based on the answers they receive. If auditors do not have follow on questions but merely stick to their documented checklist then the audit becomes more of an inspection. Further auditees know what to expect and prepare the system accordingly. 

The Designated Person’s Role in Effective Oversight

In a maritime management system the designated person or DP plays a critical role in the success of the system. The DP is the key interface between the shore management and the vessel management. Subchapter M requires the DP to effectively manage the TSMS on board beyond signing forms or attending audits. 

The DP has a responsibility for the safety on board and for the implementation of the TSMS. To this effect they have to monitor the safety on board. To achieve this they may get insights from  audit reports, NCRs, and trend data to inform management decisions. The DP plays a critical role in ensuring corrective actions address root causes, not generic retraining or re-documentation. Effective and timely communication can help alleviate the issues on board in a timely manner and ensure that leadership is aware of the risks on board as also those ashore. A strong DP presence is instrumental in strengthening TSMS integrity.

Common Pitfalls and How QMII Helps Fix Them

One of the most consistent problems we see across the industry is the use of overly complex, copy-paste TSMS manuals that don’t reflect how the company actually works. Templates look impressive, but they create confusion, inconsistencies, and ironically, more COI deficiencies. Add to that audits performed by untrained personnel who rely on generic compliance checklists, and the result is a system that appears documented but is barely implemented. Corrective actions often close the immediate symptom but never address the underlying cause, which is why the same issues show up year after year. Weak closeout documentation and thin evidence trails only compound the problem when a TPO or Coast Guard officer asks for proof.

QMII’s approach built on over 39 years of experience enables our team to create and deliver customized solutions to our clients. Our training equips auditors to verify systems, not just paperwork, and to ask the kinds of questions that reveal true implementation and effectiveness. We help operators right-size their TSMS so it matches their operations. This includes leaner manuals, clearer processes, and forms that crews can actually use. Through gap assessments and coaching, we strengthen corrective action practices, reinforce the importance of objective evidence, and help organizations build a TSMS they can sustain. The end result is a system that reduces COI deficiencies because it’s built on operational reality, not borrowed documentation.

Conclusion & Next Steps

Internal audits remain a critical tool for leadership to use in determining the state of their system. It further must also help reduce COI deficiencies. However, this is only possible when the audit team is skilled, people aware of the audit, the audit objective and checklists enable to auditor to determine the focus areas of the audit. Right-sizing the TSMS leads to better crew engagement and safer operations.

Operators must formally train their internal auditors and QMIIs auditor training course has been specially designed for maritime clients. The instructors too come with a varied background in the maritime industry. In conclusion operators must consider shifting from a mindset of “audit for compliance” to “audit to improve the system.

About the Author

Dr. Julius is a Senior Consultant at QMII with over 25 years of experience in ISO and aerospace quality systems. He has trained and guided hundreds of U.S. defense contractors on AS9100 and compliance, turning certification into a competitive advantage.

ISO 9001 Internal Audits that Improve Performance

ISO 9001 internal audits are most valuable when they move beyond compliance checking to actively drive performance improvement. Properly designed and executed, internal audits validate that the quality management system (QMS) is effective, reveal systemic weaknesses, surface opportunities, and provide input for management decisions that raise process outcomes and customer value.

It is best to start with purpose and planning. Audits should be risk‑based and aligned to business objectives and scope: critical processes, high‑risk activities, recent changes, customer complaints, and past nonconformities merit higher audit frequency. Define clear objectives for each audit (e.g., verify effectiveness of corrective actions, assess process performance against KPIs, confirm readiness for certification). Use a rolling schedule that balances coverage with depth rather than mechanical clause ticking.

Adopt a process‑and‑evidence mindset. Auditors trace the process flow from inputs through controls to outputs and outcomes. Instead of focusing on whether a procedure exists for the organization, an auditor must ask whether the process delivers the intended result and how that is measured. Review objective evidence — records, performance data, trend charts, work observations and interviews — to test effectiveness. Ask probing questions such as “How do you know this control is working?” and “What evidence shows improvement over time?”

Make auditor competence and approach central. Auditors require process knowledge, risk awareness, data‑analysis skills and good interviewing techniques. Internal auditors should act as impartial investigators and constructive consultants: identifying root causes and suggesting practical corrective or improvement actions rather than assigning blame. Cross‑functional auditing helps expose interdependencies and spreads good practices across the organization.

Emphasize root‑cause analysis and corrective action effectiveness. When nonconformities are found, require structured root‑cause methods (5 Whys, fishbone) and corrective actions that target systemic causes with measurable success criteria and timelines. Verification of effectiveness is essential — closures should be evidence‑based (data, subsequent audits, or implemented controls), not merely administrative sign‑offs.

Link audit findings to performance metrics and management review. Audits should feed quantifiable insights into management review: trends in KPI performance, recurring issues, risk exposures, and results of corrective actions. Management should use this input to prioritize resources, approve improvement projects, and adjust objectives. Tracking audit‑driven improvements against business outcomes (reduced defects, faster delivery, higher customer satisfaction) demonstrates audit ROI and motivates continued engagement.

It is imperative to use data and tools to enhance impact. Data analytics, control charts, exception reporting, and audit management software increase audit efficiency and enable evidence‑based conclusions. A well-prepared checklist focuses on performance indicators—not just mere clause compliance; this is to ensure consistency while preserving investigative flexibility.

Cultivate a culture that views audits as opportunities and not as a factor to intimidate. Communicate that audits are aimed at learning and strengthening processes. Celebrate instances where audits uncover improvements or where process owners implement effective corrective actions. A no‑blame, improvement‑oriented culture increases transparency and cooperation.

Measure audit program effectiveness. Useful indicators include the decline in recurring nonconformities, the percentage of corrective actions verified effective, time to close actions, and improvement in audited process KPIs. Regularly review and refine the audit program itself based on these metrics.

To sum up, ISO 9001 internal audits that improve performance are planned around risk and business impact, executed with process focus and competent auditors, emphasize root‑cause, corrective action and measurable verification, leading to effective management decision‑making process. When integrated with data analysis and a culture of continual improvement, the internal audit becomes a strategic tool that drives sustained and measurable enhancement of quality and organizational performance.

 

About the Author

This article was written by Anjalika Singh, President at QMII. Over the years she has developed a sharp intuitive sense combined with strong operational and training management skills, making her a key asset in QMII’s consulting and training initiatives. Her work focuses on practical lead-auditor training and helping organisations adopt ISO and industry-specific management systems in a way that delivers business value.