How Will an Internal Audit Help Any Business?

An internal audit is often viewed as a compliance exercise, a scheduled activity designed to check whether an organization is following its procedures and meeting the requirements of a standard. However, a well-planned internal audit can provide much more value. It can help a business identify risks, improve processes, reduce costs, strengthen customer satisfaction, and support better management decisions.

Whether a company operates under ISO 9001, ISO 14001, ISO 45001, ISO 27001, or another management system, internal auditing can become an important business-improvement tool.

Identifying Problems Before They Become Serious

One of the greatest benefits of an internal audit is early problem detection, like they, if you have a headache for more than a day then it’s best to get it checked before it becomes something big and uncurable.

Every organization has weaknesses. Procedures may not be followed consistently, records may be incomplete, employees may misunderstand responsibilities, or processes may have gradually changed without the relevant documentation being updated.

An internal audit provides an opportunity to identify these issues before they develop into major problems.

For example, an audit may discover that equipment inspections are not being completed according to schedule. If this issue is identified early, management can take corrective action before equipment failure causes production delays, customer complaints, or safety incidents.

In this way, internal audits are preventive as well as corrective.

Improving Business Processes

Internal auditing should not simply ask, “Are we following the procedure?”

A stronger audit asks, “Is this process actually working?”

A procedure may technically meet requirements but still be inefficient. Employees may spend unnecessary time completing forms, approvals may take too long, information may be duplicated, or communication between departments may be poor.

An internal audit can identify these inefficiencies and provide evidence for process improvement.

For example, an organization may discover that a purchasing process requires three separate approvals for relatively low-risk purchases. The audit could identify unnecessary delays and encourage management to simplify the process while maintaining appropriate controls.

The result is a system that is not only compliant but also more efficient.

Reducing Costs and Waste

Businesses constantly look for ways to reduce unnecessary costs. Internal audits can contribute directly to this objective.

Auditors may identify:

  • Repeated errors and rework
  • Excessive material waste
  • Inefficient use of resources
  • Unnecessary administrative activities
  • Poor inventory controls
  • Equipment maintenance problems
  • Duplicate processes
  • Supplier-related problems

Consider a manufacturing organization experiencing a high level of product rework. An internal audit may trace the problem back to unclear work instructions or inconsistent inspection practices.

Addressing the underlying cause can reduce scrap, labor costs, production delays, and customer complaints.

Therefore, the financial value of an internal audit can be much greater than the cost of conducting the audit.

Strengthening Risk Management

Modern businesses operate in environments filled with risks. These may include operational, financial, environmental, cybersecurity, supply-chain, regulatory, and reputational risks.

Internal audits provide management with an independent examination of how effectively these risks are being controlled.

For example, an audit may determine that an organization has identified cybersecurity risks but has not adequately controlled access to sensitive information. Similarly, an environmental audit may identify inadequate controls over waste management.

The auditor does not necessarily solve the problem. Instead, the audit provides management with objective information so appropriate action can be taken.

This makes internal auditing an important component of risk-based management.

Supporting Compliance

Organizations are often required to meet laws, regulations, contractual requirements, industry standards, and internal policies.

Failure to comply can result in fines, legal problems, loss of customers, operational disruption, or damage to reputation.

Internal audits can provide an early warning system.

For organizations certified to an ISO standard, internal audits also help determine whether the management system continues to conform to applicable requirements and whether processes are effectively implemented.

Importantly, an internal audit should not be treated as preparation for “passing” an external audit. Its purpose is to determine whether the organization’s management system is genuinely effective.

Preparing for External Audits

A strong internal audit program can significantly improve an organization’s readiness for certification, surveillance, recertification, regulatory, or customer audits.

External auditors are likely to examine evidence showing how processes are controlled and whether the organization is meeting applicable requirements.

If internal audits are performed regularly, problems can be identified and corrected before an external auditor discovers them.

For example, an internal audit may identify an incomplete training record, an overdue calibration, or an ineffective corrective action. Management can address the issue before it becomes an external-audit finding.

The objective should not be to hide problems from external auditors. Instead, internal audits should help the organization discover and resolve its own problems first.

Improving Employee Awareness

Internal audits also create opportunities for employee engagement and learning.

During an audit, employees may be asked questions about their responsibilities, procedures, objectives, risks, and controls. This can reveal whether employees truly understand the management system or are simply completing tasks because they have been instructed to do so.

An auditor might discover that employees understand what they do but do not understand why they do it.

That distinction is important.

Employees who understand the purpose behind a process are generally better positioned to recognize problems, make appropriate decisions, and suggest improvements.

Internal auditing can therefore contribute to a stronger culture of quality, accountability, and continuous improvement.

Providing Management With Objective Information

Managers often make decisions based on reports, meetings, performance indicators, and employee feedback. While these sources are valuable, they may not always reveal what is happening within a process.

Internal auditors provide another perspective.

A good auditor collects objective evidence through interviews, observation, document review, and sampling. The resulting findings can help management understand the actual condition of a process.

For example, management may believe that customer complaints are being addressed effectively. An internal audit might reveal that complaints are being closed quickly but that root causes are not being properly investigated.

That information can lead to better management decisions.

Encouraging Continual Improvement

Continual improvement is a fundamental principle of many management systems, but improvement cannot occur effectively without knowing where improvement is needed.

Internal audits provide that information.

An audit can identify trends and recurring weaknesses. If the same type of finding appears repeatedly, management should consider whether the organization is addressing symptoms rather than underlying causes.

For example, repeated findings involving incomplete records may indicate a deeper problem with training, process design, workload, responsibilities, or management oversight.

Instead of repeatedly correcting individual records, the organization can investigate the systemic cause.

This is where internal auditing moves from simple compliance checking to genuine business improvement.

Increasing Customer Confidence

Customers want to know that a business can consistently deliver products or services that meet requirements.

A reliable internal audit program helps strengthen the systems supporting that consistency.

By identifying process weaknesses, controlling risks, improving corrective actions, and monitoring performance, internal auditing can contribute to improved product and service quality.

This can ultimately lead to fewer complaints, fewer returns, better delivery performance, and stronger customer relationships.

Conclusion

An internal audit should not be viewed as an exercise designed to find fault with employees. Its real purpose is to provide an objective assessment of how well the organization is operating and where it can improve.

A valuable internal audit identifies weaknesses before they become major problems, improves processes, reduces waste, supports compliance, strengthens risk management, prepares the organization for external audits, and provides management with reliable information for decision-making.

The most effective organizations do not ask, “How can we pass the audit?”

They ask, “What can this audit teach us about our business?”

When internal audits are approached in this way, they become much more than a requirement of an ISO management system. They become a practical management tool that helps businesses operate more efficiently, control risk, improve performance, and achieve sustainable growth.

Ultimately, the value of an internal audit is not measured by how many findings an auditor raises. It is measured by how effectively the organization uses those findings to become better.

__

About the Author:

Anjalika Singh is the President of QMII (Quality Management International, Inc.), a global management systems consulting firm headquartered in Ashburn, Virginia. Over the course of her career, she has developed a sharp intuitive sense combined with strong operational and training management skills, making her a key asset in QMII’s consulting and training initiatives. Her work focuses on practical lead-auditor training and helping organizations adopt ISO and industry-specific management systems in a way that delivers real business value. Anjalika also serves as President and CEO of iCertifications, LLC, where she leads efforts to make accredited ISO certification services accessible to small and medium-sized businesses.

ISO 22301 Business Continuity: Preparing for Disruptions Before They Happen

The 2015 revision of ISO 9001 introduced risk-based thinking into Clause 6.1, and sector-specific standards such as AS9100 went further by addressing operational risk in Clause 8.1.1. Once identified, a risk may be treated, accepted, or used as an opportunity for improvement. What these standards do not fully address, however, is how an organization will continue operating when a risk becomes a disruptive event.

That is the territory of business continuity. A cyberattack locks employees out of critical systems. A supplier failure halts production. A storm closes a facility. A key utility is lost, or a public-health emergency depletes the available workforce, as COVID-19 demonstrated on a global scale. The trigger may vary, but the leadership question remains the same, can the organization continue delivering its most important products and services at an acceptable, predefined capacity?

Resilience is not the ability to predict every disruption. It is the discipline of deciding—before pressure arrives—what must continue, how quickly it must recover, what resources it will require, and who has the authority to act.

ISO 22301 provides a structured approach. The international standard specifies requirements for a business continuity management system (BCMS): a management framework for understanding the organization and its disruption-related risks, establishing continuity priorities, preparing response and recovery arrangements, exercising those arrangements, evaluating performance, and continually improving capability.

Its value is not found in a binder on a shelf or a certificate on a wall. Its value lies in a practiced capability that helps people make sound decisions when normal assumptions no longer hold.

Continuity Begins Before the Incident. Many organizations begin with a plan template containing contact lists, emergency numbers, alternate locations, and recovery checklists. Those items may be useful, but beginning with the document reverses the logic.

A sound continuity program first establishes the organization’s context, the needs and expectations of relevant interested parties, the BCMS scope, leadership intent, responsibilities, and measurable continuity objectives. It then analyzes what the organization does, what its activities depend on, and what the consequences would be if those activities stopped. These foundations align with ISO 22301 Clauses 4.1–4.3, 5.1–5.3, and 6.2.

Organizations should also account for ISO 22301:2019/Amd 1:2024. The amendment adds an explicit requirement in Clause 4.1 to determine whether climate change is a relevant issue and adds a note to Clause 4.2 recognizing that interested parties may have climate-related requirements.

Business continuity is related to, but distinct from, other response disciplines:

  • Emergency response protects life, property, and the environment during the immediate event.
  • Crisis management coordinates strategic decisions, leadership, and communications.
  • IT disaster recovery restores technology and data.
  • Business continuity connects these disciplines to the continued delivery of prioritized products and services.

ISO 22301 helps align these elements within one managed system and, because it follows ISO’s harmonized management-system structure, it can be integrated with other management systems.

A Practical Path from Risk Assessment to Recovery. The following sequence turns business continuity from a broad aspiration into an operating capability.

Establish scope, governance, and decision rights

Define which sites, services, legal entities, technologies, and third parties fall within the BCMS scope. Appoint an accountable executive, assign process owners, and clarify who may declare an incident, activate a plan, authorize emergency expenditure, communicate with stakeholders, or accept temporary operating risk.

Ambiguity in these decisions consumes precious time during a disruption, and, in a severe event, may threaten the organization’s survival. Relevant requirements appear in Clauses 4.3, 5.1, 5.3, and 8.4.2.

Assess disruption risks

Identify plausible sources of interruption and evaluate their likelihood and consequences. These may include cyber events, utility loss, fire, severe weather, equipment failure, transportation interruption, labor shortages, civil disturbance, and the loss of critical suppliers or data.

The purpose is not to develop a separate plan for every imagined scenario. It is to understand vulnerabilities and select measures that reduce the likelihood or impact of disruption. ISO 22301 addresses the assessment of risks of disruption to prioritized activities in Clause 8.2.3. This should not be confused with Clause 6.1, which concerns risks and opportunities affecting whether the BCMS itself achieves its intended outcomes.

Conduct the business impact analysis

The risk assessment asks, “What could happen?” The business impact analysis (BIA) asks, “What happens to the organization as time passes after an activity stops?”

The BIA establishes recovery priorities and provides the evidence needed to define continuity strategies, resource requirements, and recovery objectives. ISO 22301 addresses the BIA in Clause 8.2.2.

Select continuity strategies and solutions 

Choose proportionate ways to protect, continue, or restore prioritized activities. Options may include cross-trained personnel, remote-working capability, alternate facilities, redundant utilities, backup communications, diversified suppliers, emergency inventory, manual workarounds, resilient cloud architecture, and tested data recovery.

A strategy is credible only when its people, capacity, cost, and activation time are consistent with the BIA. ISO 22301 addresses business continuity strategies and solutions, associated resource requirements, and implementation in Clauses 8.3.1–8.3.5.

Develop response and recovery plans

Translate strategy into action. Plans should define activation criteria, initial actions, roles, escalation paths, communications, dependencies, workarounds, resource requirements, recovery steps, and stand-down arrangements.

Make plans usable under stress: concise, role-based, accessible when primary systems are unavailable, and clear about what must occur during the first hour, the first day, and the subsequent recovery period. These matters are addressed principally in Clauses 8.4.1–8.4.5.

The BIA: Identifying What Cannot Be Allowed to Fail. Not every process is equally urgent. Labeling everything “critical” leaves leaders with no meaningful priority. The BIA creates a time-based view of impact. It examines how disruption may affect life and safety, customers, revenue, contractual obligations, regulatory compliance, reputation, cash flow, and other operations. It also reveals the chain of dependencies supporting each activity: people, information, applications, facilities, equipment, utilities, logistics, and external providers.

A useful BIA produces decisions, not merely scores. For each prioritized activity, the organization should determine the time within which impacts would become unacceptable, the prioritized time frame for resuming the activity, the minimum acceptable capacity during recovery, and the resources and dependencies required over time. Where information and communications technology are involved, data-loss and restoration targets should also be aligned with business needs.

The following table summarizes the decisions a BIA should support:

Decision areaQuestion for the organizationWhat it drives
PriorityWhich activities must resume first?Recovery sequence
Time objectiveWhen would the impacts of interruption become unacceptable, and by when must the activity resume?Recovery design and investment
Minimum capacityWhat level of service is acceptable initially?Staffing, sites, systems, and workarounds
DependenciesWhat must be available for the activity to operate?Supplier, technology, facility, utility, and data controls

These targets must be reconciled across departments. One function’s recovery may depend on another function that has assigned itself a lower priority. The BIA should be challenged, approved, and reviewed when products, technologies, suppliers, locations, or operating models change. It is not a one-time questionnaire owned by the continuity coordinator; it is a management decision about what the organization is prepared to sustain. Clause 8.6 requires the organization to evaluate the suitability, adequacy, and effectiveness of its business impact analysis, risk assessment, strategies, solutions, plans, and procedures.

Designing a Response People Can Actually Use. A continuity plan must work amid incomplete information, unavailable colleagues, and competing priorities. Effective plans therefore emphasize decisions and interfaces. They identify the incident leadership structure, primary and alternate role holders, communication channels, escalation criteria, and the point at which a local response becomes an enterprise-level crisis.

Plans must also address stakeholder communication. Employees need instructions. Customers need honest service expectations. Regulators may require notification. Suppliers need revised priorities, and leadership needs a consistent operating picture. Preapproved message frameworks can save time, but facts must be verified before release. Speed matters; credibility matters more. ISO 22301 addresses warning and communication in Clause 8.4.3, supported by the broader communication requirements in Clause 7.4.

Continuity arrangements must account for their weakest dependencies. An alternate site is ineffective if access credentials, specialized equipment, or key records remain at the affected location. Remote work is not a recovery strategy if the identity platform is the failed system. A backup is not a recovery capability until data have been restored within the required time and shown to be usable. Plans also require appropriate control as documented information under Clause 7.5. Accessibility, protection, version control, distribution, retention, and availability during a disruption all matter.

Exercising the Plan and Proving the Capability. Documentation creates potential capability; exercises provide evidence. ISO 22301 Clause 8.5 requires an exercise program to validate business continuity strategies and solutions over time. Clause 8.6 requires evaluation of the continuing suitability, adequacy, and effectiveness of the organization’s continuity arrangements.

A mature exercise program progresses from simple checks to realistic, cross-functional tests:

  • Walkthroughs and checklist reviews confirm that roles, contact information, resources, and procedures remain accurate.
  • Tabletop exercises present an evolving scenario and require leaders to make decisions, communicate, and resolve competing priorities.
  • Functional exercises activate selected capabilities, such as emergency notification, remote operations, supplier substitution, or restoration from backup.
  • Full or integrated exercises test multiple teams and dependencies together under realistic time pressure while controlling safety and operational risk.

An exercise is not successful merely because participants completed the script. It succeeds when the organization learns. Observers should record decisions, elapsed times, assumptions, bottlenecks, communication failures, and gaps between stated and actual capability. Corrective actions need owners, due dates, and verification of effectiveness. Repeating the same unresolved finding in the next exercise signals a weakness in the management system, not merely in the plan. Corrective action and continual improvement are addressed in Clauses 10.1 and 10.2.

The exercise schedule should be risk-based. High-impact activities and fragile dependencies deserve greater frequency and realism. Exercises should also follow material changes, significant incidents, major technology migrations, acquisitions, facility moves, or supplier changes. Where a live test would create unacceptable risk, controlled simulations and component tests can provide evidence without exposing the organization unnecessarily.

Keeping the BCMS Alive. People change roles. Suppliers consolidate. Applications migrate. Inventories shrink. Workarounds become obsolete. Sustained readiness therefore depends on monitoring and measurement, internal audit, management review, corrective action, and continual improvement—the disciplines covered by Clauses 9.1–9.3 and 10.1–10.2.

Useful performance measures may include:

  • completion of scheduled exercises;
  • achievement of recovery objectives;
  • overdue corrective actions;
  • supplier continuity assurance;
  • currency of plans and contact information;
  • training and awareness coverage; and
  • trends identified through incidents, exercises, and near misses.

Leadership review should go beyond asking whether documents are current. It should examine whether continuity objectives remain aligned with organizational strategy, whether resources match exposure, whether risk acceptance is explicit, and whether exercises demonstrate the promised capability. Internal audits should likewise evaluate effectiveness—not simply whether a procedure exists, but whether it is understood, implemented, exercised, and improved.

The Role of Lead Auditor Training. Sustained conformity with ISO 22301 requires long-term ownership by people who can see the BCMS as a connected system. A capable lead auditor follows the evidence from leadership commitments to the BIA, from recovery objectives to continuity solutions, from exercise results to corrective action, and from management review back to investment decisions. This line of sight helps distinguish polished documentation from genuine resilience.

QMII’s ISO 22301 Lead Auditor Training is designed to develop the competence to assess a BCMS against ISO 22301, identify vulnerabilities and improvement opportunities, evaluate the effectiveness of plans and controls, and support continual improvement.

For organizations building internal capability, lead auditor training can strengthen three essential forms of ownership:

  1. Independent assurance: Auditors can test whether practice matches policy and whether recovery claims are supported by evidence.
  2. Cross-functional understanding: Trained personnel can examine the links among operations, technology, facilities, suppliers, communications, and leadership decisions.
  3. Improvement discipline: Audit findings can be framed around systemic causes and followed through to effective corrective action, rather than treated as a documentation clean-up exercise.

Training alone does not own the BCMS. Leadership and process owners do. Trained auditors, however, provide the challenge, structure, and feedback that help keep continuity integrated with everyday management. They enable the organization to ask uncomfortable questions before a real incident asks them under pressure.

Preparedness Is a Management Habit. No continuity program can eliminate uncertainty. What ISO 22301 can do is replace improvisation with informed priorities, rehearsed responsibilities, viable recovery options, and a repeatable cycle of learning.

The objective is not uninterrupted perfection. It is the ability to absorb disruption, protect essential commitments, recover within acceptable limits, and emerge better prepared for the next test. The best time to discover that a recovery objective is unrealistic, a supplier has no viable alternative, or a contact list is obsolete is before operations are at risk. Begin with the BIA. Build strategies from evidence. Turn them into usable plans. Exercise those plans honestly. Audit the system for effectiveness. Then improve it-again and again.

About the Author:

Inderjit (IJ) Arora, Ph.D., is the Chairman of QMII. He serves as a team leader for consulting, advising, auditing, and training regarding management systems. He has conducted many courses for the United States Coast Guard and is a popular speaker at several universities and forums on management systems. Arora is a Master Mariner who holds a Ph.D., a master’s degree, an MBA, and has a 35-year record of achievement in the military, mercantile marine, and civilian industry.

AS9100 Certification: What Aerospace Suppliers Need to Know Before Bidding

So much is happening in the quality and related world. ISO 9001:2026 is on the way, and the mid-September update this year changes look superficial but go deeper than a checklist update. The implementation is being more closely looked at then just cosmetic lip service. Leadership accountability, use of risk inputs to drive opportunity, and then the emphasis on effective root cause analysis is all being redefined.  This will be then followed with updates to other standards in the harmonized structure (HS) and the aerospace standards.

In this article against this changing background, I want to look at the focus of aerospace suppliers. For commercial or defense suppliers preparing to bid on tier-1 or prime contractor awards, technical capability and competitive pricing are only half the equation. Prime contractors operate under stringent regulatory oversight, where a single non-conforming part or untraced engineering change can ground an aircraft, void a defense contract, or jeopardize mission safety. Therefore, before submitting a bid, suppliers must understand that a Quality Management System (QMS) built to AS9100 Rev D is not just an operational advantage—it is a mandatory license to compete. Then why AS9100 is a prerequisite, and not a differentiator, in Aerospace, is a valid question.

In commercial manufacturing, ISO 9001 certification often serves as a competitive differentiator that signals product reliability. In aerospace, defense, and space supply chains, AS9100 certification is table stakes.  Prime contractors (such as Boeing, Lockheed Martin, Northrop Grumman, and Airbus) maintain strict, approved vendor lists (AVLs). To gain initial consideration for a request for proposal (RFP), suppliers must show evidence of AS9100 compliance and maintain an active profile in the online aerospace supplier information system (OASIS) database.  Having AS9100 does not win you the bid, it simply earns you a place at the table. Lacking it automatically disqualifies your bid during pre-qualification screening, regardless of your technical prowess or low-cost structure.

Therefore, it is important to consider how prime contractors vet supplier quality systems. Achieving AS9100 certification gets a company listed on the AVL, but prime contractors conduct their own rigorous supplier evaluation before awarding contracts. Tier-1 buyers do not rely solely on third-party audit certificates. They perform deep-dive supplier quality assessments to evaluate operational capability including checking OASIS database audit history.  Primes inspect past third-party audit results, minor/major Non-Conformance Reports (NCRs), and corrective action (CA) performance recorded in OASIS.

Primes conduct on-site pre-award audits. Quality engineers evaluate physical shop-floor controls, calibration records, tool storage, material handling, and overall culture. Then there is the sub-tier supplier control.  OEM auditors inspect how effectively you flow down technical and quality requirements to your sub-tier suppliers.   On-time delivery (OTD) and quality metrics are looked at including historical performance data on parts per million (PPM) defect rates and delivery performance. Looking at the AS9100 (IA9100) and ISO 9001 changes for aerospace suppliers we see that the AS9100 Rev D encompasses the full text of ISO 9001:2015, layering over 100 aerospace-specific additions. Transitioning from ISO 9001 to AS9100 requires shifting from general process controls to strict risk prevention and traceability.  

Area ISO 9001:2015 AS9100 Rev D (Aerospace Addition)
Risk ManagementHigh-level consideration of organizational risks and opportunities.Formal operational risk assessment integrated into production planning and design.
Product SafetyImplicit within customer satisfaction and product quality.Explicit mandatory requirements to identify safety-critical characteristics and lifecycle risks.
Counterfeit PartsBasic vendor oversight and purchasing controls.Strict policies for counterfeit part prevention, source verification, and segregation.
ConfigurationBasic control of documented changes and revisions.Formal Configuration Management across design, manufacturing baselines, and engineering changes.
Supplier ControlGeneral evaluation and selection of external providers.Mandatory requirement flow-down (e.g., test reports, NADCAP ((National Aerospace and Defense Contractors Accreditation Program)) requirements, retention periods).

For organizations building or upgrading an aerospace QMS prior to bidding on contracts, implementation should follow a structured approach including perform a gap analysis. Benchmark existing processes against AS9100 Rev D clauses to pinpoint missing controls (e.g., risk matrices, counterfeit mitigation, or design verification tools). Formalize Operational Risk Management by establishing systematic methods (such as FMEA or risk registers) to assess operational risks prior to taking on new job orders. Additionally, to establish requirement flow-down mechanics by building controls ensuring customer purchase order requirements, engineering drawings, and quality clauses are automatically flowed down to sub-tier suppliers and shop-floor traveler routes.  Then there is the need to train key personnel by educating leadership, process owners, and shop-floor staff on aerospace quality imperatives, emphasizing individual contributions to product safety and ethical behavior. Finally, to execute internal audits & management reviews by conducting full internal audit cycles to verify process effectiveness before inviting an accredited registrar / certification Body (CB).

There are of course the configuration management and traceability requirements. The aerospace documentation burden is significantly higher than in general manufacturing, largely centered around configuration management and full material/process traceability.  For configuration management (AS 9100 clause 8.1.2) organizations must control the design and manufacturing baseline. Every engineering change order (ECO) must evaluate impact on form, fit, function, and test procedures before implementation. Traceability & identification (AS 9100 clause 8.5.2): Suppliers must maintain bidirectional traceability from raw material heat numbers and special process certs to individual batch or serial numbers. Acceptance media control requires use of physical inspection stamps, electronic signatures, or system authorizations must be strictly controlled to prevent unauthorized signoffs.

Looking ahead auditing as emphasized in the revised ISO 19011:2026 and anticipated changes in ISO 9001:2026 (coming in September) the lead auditor and internal auditor training will require the team needs of the audit team to build internal competency as an essential for both initial certification and ongoing audit survival. When for example evaluating QMII training tracks for staff, matching the course depth to internal roles ensures both compliance and resource efficiency.

  • Internal Auditor Training (2 to 3 Days):
    • Target Audience: Quality managers, process owners, manufacturing engineers, and internal audit team members.
    • Focus: Understanding AS9100 Rev D requirements, ISO 19011 auditing principles, preparing checklists, gathering evidence, and writing clear non-conformance reports.
    • Objective: Conduct periodic internal audits to keep the QMS healthy and compliant.
  • Lead Auditor Training (4 to 5 Days):
    • Target Audience: Quality Directors, Chief Auditors, lead consultants, or staff managing complex multi-site QMS programs.
    • Focus: Deep mastery of standard intent, lead-auditor protocols, managing audit teams, lead-closing meetings, and assessing root-cause corrective actions (RCCA).
    • Objective: Drive strategic management system improvement and interface effectively with third-party certification bodies and prime contractor oversight teams.

Certification must be maintained through supplier audits. Achieving your initial certificate is only the baseline; maintaining it requires continuous readiness. Prime contractors and certification bodies conduct recurring surveillance audits to ensure systems do not degrade over time.  

  1. Maintain Robust Root Cause Corrective Action (RCCA): Move beyond surface-level fixes. Utilize structured methodologies like 5-Why Analysis or Fishbone (Ishikawa) Diagrams to resolve internal and customer-reported issues permanently.
  2. Monitor Key Performance Indicators (KPIs): Track metrics continuously across process effectiveness, product conformity, and on-time delivery.
  3. Conduct Continuous Process Audits: Audit high-risk shop floor operations, special processes, and sub-tier supplier handling throughout the year, rather than rushing preparation right before the third-party surveillance audit.

About the Author:

Inderjit (IJ) Arora, Ph.D., is the Chairman of QMII. He serves as a team leader for consulting, advising, auditing, and training regarding management systems. He has conducted many courses for the United States Coast Guard and is a popular speaker at several universities and forums on management systems. Arora is a Master Mariner who holds a Ph.D., a master’s degree, an MBA, and has a 35-year record of achievement in the military, mercantile marine, and civilian industry.

ISO 9001 Certification: A Business Leader’s Roadmap

ISO 9001 certification is more than a certificate displayed on a wall. For business leaders, it represents an opportunity to build a disciplined management system that consistently delivers quality, satisfies customers, manages risks, and supports continuous improvement. Yet organizations sometimes approach ISO 9001 as a compliance exercise rather than as a continual improvement tool. The difference in approach can determine whether certification becomes a valuable strategic asset or simply another administrative burden.

For leaders considering ISO 9001 certification, the journey should begin with understanding what the standard is designed to accomplish and how it can support organizational objectives.

Understanding ISO 9001

ISO 9001 is an internationally recognized standard for quality management systems (QMS). It provides a framework for organizations to establish processes that consistently meet customer requirements, applicable regulatory requirements, and the organization’s own objectives.

Importantly, ISO 9001 does not prescribe exactly how a business must operate. A manufacturing company, consulting firm, software provider, construction company, or service organization can all implement the standard. The organization determines the processes, controls, resources, and methods appropriate to its size, complexity, products, services, and risks.

For business leaders, this flexibility is important. Certification should not mean copying another organization’s procedures. The management system should reflect how the organization operates.

Step 1: Establish Leadership Commitment

Successful ISO 9001 implementation starts with the Top Management/ Leadership.

Senior leadership must understand why the organization wants certification and what business outcomes it expects. Possible objectives include improving customer satisfaction, reducing defects, standardizing processes, strengthening supplier management, improving operational efficiency, entering new markets, or satisfying customer requirements.

Leadership should communicate that quality is an organizational responsibility rather than the sole responsibility of a quality manager.

A strong leadership commitment includes providing appropriate resources, establishing quality objectives, assigning responsibilities, participating in management reviews, and ensuring that employees understand the importance of effective processes.

If employees believe ISO 9001 is simply “the quality department’s project,” implementation is likely to struggle.

Step 2: Define the Business Context and Scope

The organization should next determine the context in which it operates. Leaders need to consider internal and external issues that can affect the organization’s ability to achieve its intended quality outcomes. These may include market conditions, technology, competition, customer expectations, regulatory requirements, organizational capabilities, supply-chain issues, and changes in the business environment.

The organization must also determine the scope of its quality management system. The scope should clearly identify the products, services, locations, and organizational activities covered by the QMS. It should be realistic and accurately represent the organization’s operations. A clearly defined scope prevents confusion later in the certification process.

Step 3: Identify and Manage Risks and Opportunities

Modern quality management is not simply about detecting problems after they occur. ISO 9001 encourages organizations to think about risks and opportunities before problems affect customers or business performance.

Leaders should ask questions such as:

  • What could prevent us from meeting customer requirements?
  • Which processes are most critical to our success?
  • Where are errors most likely to occur?
  • Which suppliers create significant operational risk?
  • What opportunities could improve efficiency or customer satisfaction?
  • What changes could affect our ability to deliver consistent products or services?

Risk-based thinking should become part of everyday decision-making rather than a standalone exercise performed only for an audit.

Step 4: Map and Standardize Key Processes

A quality management system is fundamentally a system of processes. Organizations should identify their major processes and understand how they interact. Depending on the business, these may include sales, contract review, purchasing, design and development, production, service delivery, inspection, testing, customer support, human resources, maintenance, and supplier management.

Process mapping can reveal duplication, unclear responsibilities, bottlenecks, missing controls, and opportunities for improvement.

The goal is not to create excessive paperwork. The goal is to make important processes predictable and effective.

Step 5: Build Competence and Employee Awareness

Even the best designed QMS will fail if employees do not understand their responsibilities.

ISO 9001 places significant importance on competence and awareness. Organizations should determine the competencies required for people performing work that affects quality, provide appropriate training or other actions, and evaluate whether competence has been achieved.

Training should be practical.

Employees should understand not only what procedure they are expected to follow but also why it matters. For example, a purchasing employee should understand how supplier selection affects product quality, delivery performance, customer satisfaction, and organizational risk.

This creates ownership rather than simple procedural compliance.

Step 6: Establish Performance Measures

Business leaders cannot effectively manage what they do not measure.

Organizations should establish meaningful quality objectives and appropriate performance indicators. Depending on the organization, these might include customer complaints, on-time delivery, defect rates, rework, process efficiency, supplier performance, warranty claims, service response times, or customer satisfaction.

The key is to avoid measuring everything simply because data is available.

Good metrics help leaders answer important questions:

Are our processes working? Are customers satisfied? Are objectives being achieved? Where should management focus its attention?

Performance information should be reviewed regularly and used to make decisions.

Step 7: Implement Internal Audits

Internal audits are one of the most valuable tools in the ISO 9001 system.

An internal audit should not be treated as a rehearsal for the certification audit. Its purpose is to determine whether the QMS conforms to requirements and whether it is effectively implemented and maintained.

Effective auditors look beyond documentation. They follow processes, interview employees, examine records, observe activities, and evaluate objective evidence.

A strong internal audit program can identify weaknesses before they become customer complaints or external audit findings.

Leaders should encourage employees to view internal audits as improvement opportunities rather than investigations designed to assign blame.

Step 8: Use Corrective Action for Real Improvement

Problems will occur in every organization. ISO 9001 does not require perfection; it requires organizations to respond appropriately when nonconformities occur.

The critical question is whether the organization addresses the underlying cause.

For example, if an employee repeatedly completes a form incorrectly, simply retraining that employee may not solve the problem. The organization should investigate why the error occurred. Was the form confusing? Was the procedure unclear? Was the employee adequately trained? Was the process poorly designed? Was there insufficient supervision?

Effective corrective action addresses causes rather than symptoms.

Step 9: Conduct Management Review

Management review gives senior leaders an opportunity to evaluate whether the QMS remains suitable, adequate, effective, and aligned with organizational direction.

Management should review relevant performance information, audit results, customer feedback, process performance, nonconformities, corrective actions, risks and opportunities, supplier performance, and changes that could affect the QMS.

The output should be decisions and actions, not merely meeting minutes.

Leadership should use management review to determine where resources, priorities, or processes need to change.

Step 10: Prepare for the Certification Audit

Once the QMS has been implemented and has generated sufficient evidence of operation, the organization can engage an accredited certification body for the certification process. Certification generally involves an initial assessment conducted in stages. The certification auditors evaluate whether the management system meets ISO 9001 requirements and whether it is effectively implemented.

Organizations should not attempt to hide weaknesses from auditors. A mature QMS recognizes that problems are opportunities to improve. Preparation should include reviewing internal audit results, closing appropriate corrective actions, confirming employee awareness, ensuring required documented information is controlled, and verifying that processes are actually being followed.

The Business Leader’s Role After Certification

Certification is not the destination. One of the most common mistakes organizations make is treating certification as the end of the project. Once the certificate is issued, attention may decline and the QMS can gradually become disconnected from daily operations.

Business leaders should instead treat ISO 9001 as an ongoing management framework. The organization should continue monitoring performance, conducting internal audits, addressing customer feedback, managing risks, improving processes, reviewing objectives, and preparing for surveillance audits.

The real value of ISO 9001 becomes apparent when the QMS becomes part of how the organization is managed, not something maintained only because an auditor is coming.

Conclusion

ISO 9001 certification provides business leaders with a structured approach to improving quality, consistency, customer satisfaction, and organizational performance. However, the certificate itself is not the objective. The objective is to create a management system that helps the organization understand its processes, manage risks, make informed decisions, and continually improve.

The roadmap is straightforward: establish leadership commitment, understand the business context, identify risks and opportunities, manage processes, develop competent employees, measure performance, conduct effective internal audits, implement meaningful corrective actions, perform management reviews, and undergo certification with confidence.

When leadership treats ISO 9001 as a business management tool rather than a compliance exercise, certification can become much more than an external recognition of conformity. It can provide the foundation for a more disciplined, customer-focused, resilient, and continuously improving organization.

About the Author:

Anjalika Singh is the President of QMII (Quality Management International, Inc.), a global management systems consulting firm headquartered in Ashburn, Virginia. Over the course of her career, she has developed a sharp intuitive sense combined with strong operational and training management skills, making her a key asset in QMII’s consulting and training initiatives. Her work focuses on practical lead-auditor training and helping organizations adopt ISO and industry-specific management systems in a way that delivers real business value. Anjalika also serves as President and CEO of iCertifications, LLC, where she leads efforts to make accredited ISO certification services accessible to small and medium-sized businesses.

ISO 14001 vs ISO 9001: Can Your Organization Implement Both at the Same Time?

Organizations today face increasing pressure to deliver consistent quality while also managing their environmental responsibilities. Customers, regulators, investors, and other stakeholders increasingly expect organizations to demonstrate not only that their products and services meet requirements, but also that their operations minimize environmental impacts.

ISO 9001 focuses on quality management, customer satisfaction, and consistent processes, while ISO 14001 focuses on environmental management and the organization’s interaction with the environment. Although they have different purposes, the two standards share a significant amount of common management-system structure. As an add on, adding ISO 45001 will greatly add value to the organization with respect to Health and Safety along with Quality and Environmental Management Systems. As an option, an organization can also integrate ISO 9001 with ISO 27001 for integrated Cybersecurity management system. Perhaps, ISO 22301, for Business Continuity Management System. There are various ways why Integrated Management Systems works wonders for an organization. For a Maritime Company, organization can integrate ISO 9001 with ISM Code, or maybe add ISO 27001 to integrate and meet the objective of Maritime Cybersecurity. For the Aviation Industry, AS9100 or AS9110 can be integrated with ISO 9001.

Here’s a link to another article on the emphasis and benefits of having an integrated management system: https://www.qmii.com/integrated-management-systems-aka-a-balanced-lifestyle/

In this article, we will discuss the value behind implementing ISO 9001 with ISO 14001.

Understanding ISO 9001 and ISO 14001

ISO 9001 is the internationally recognized standard for Quality Management Systems (QMS). Its primary objective is to help organizations consistently provide products and services that meet customer and applicable statutory and regulatory requirements.

Key areas include:

  • Customer focus
  • Leadership
  • Planning
  • Risk and opportunity management
  • Competence and awareness
  • Operational control
  • Performance evaluation
  • Continual improvement
  • Corrective action

ISO 14001, on the other hand, specifies requirements for an Environmental Management System (EMS). It helps organizations manage their environmental responsibilities systematically and improve environmental performance.

Important areas include:

  • Environmental aspects and impacts
  • Compliance obligations
  • Environmental objectives
  • Operational controls
  • Emergency preparedness and response
  • Environmental monitoring
  • Risk and opportunity management
  • Continual improvement

The standards therefore address different organizational objectives, but they use many similar management principles.

Why Implement Both Standards?

One of the biggest advantages of implementing ISO 9001 and ISO 14001 together is that organizations do not necessarily need two separate management systems.

Many of the underlying processes can be shared. For example, an organization can establish one system for:

  • Document and record control
  • Internal audits
  • Management reviews
  • Corrective action
  • Employee competence
  • Training and awareness
  • Risk management
  • Supplier evaluation
  • Organizational context
  • Leadership responsibilities
  • Performance monitoring

The organization can then incorporate quality-specific and environmental-specific requirements into these common processes.

Instead of creating two independent systems, the organization can develop an Integrated Management System (IMS). A major reason ISO 9001 and ISO 14001 can work well together is their use of a common high-level structure.

Both standards address areas such as:

  1. Context of the organization
  2. Leadership
  3. Planning
  4. Support
  5. Operation
  6. Performance evaluation
  7. Improvement

This common structure allows organizations to integrate requirements without unnecessarily duplicating procedures.

For example, an organization may conduct one internal audit covering both quality and environmental requirements. Similarly, one management review meeting can evaluate quality performance and environmental performance.

This approach can reduce duplication and make the management system easier for employees to understand.

What Should Remain Separate?

Although integration is beneficial, organizations should not assume that ISO 9001 and ISO 14001 are identical. Some requirements are specific to each discipline.

ISO 9001 places considerable emphasis on issues such as customer requirements, product and service conformity, customer satisfaction, design and development, and process performance; whereas, ISO 14001 places greater emphasis on environmental aspects and impacts, environmental compliance obligations, environmental objectives, life-cycle considerations, and environmental performance.

For example, a manufacturing organization may need to consider:

Quality perspective:

  • Are products manufactured according to specifications?
  • Are customer requirements being met?
  • Are defects being controlled?
  • Are processes producing consistent results?

Environmental perspective:

  • What emissions are generated?
  • How are wastes managed?
  • What resources and energy are consumed?
  • What environmental impacts are associated with operations?
  • What legal environmental requirements apply?

These requirements should remain clearly identifiable even when they are managed through common processes.

An Integrated Risk-Based Approach

Another advantage of combining the standards is the ability to consider quality and environmental risks together. Suppose an organization changes a production process to reduce manufacturing costs. From a quality perspective, the organization should consider whether the change could affect product conformity.

From an environmental perspective, it should consider whether the change could increase waste, energy consumption, emissions, or other environmental impacts. Considering both perspectives during planning can lead to better business decisions.

An integrated risk-management process can therefore help management understand the broader consequences of operational decisions.

Internal Auditing Can Also Be Integrated

Internal auditing is another area where organizations can achieve significant efficiencies.

Rather than conducting two separate audits for ISO 9001 and ISO 14001, an organization can develop an integrated audit program.

For example, an auditor reviewing a production process could examine:

  • Process controls
  • Product conformity
  • Customer requirements
  • Competence of personnel
  • Equipment and infrastructure
  • Waste management
  • Chemical handling
  • Energy consumption
  • Environmental controls
  • Emergency preparedness
  • Applicable compliance obligations

This provides a more complete picture of process performance. However, auditors must still understand the specific requirements of each standard. An integrated audit should not become a superficial checklist exercise.

Management Review Can Cover Both Systems

Management review is another area where integration provides significant value. Instead of holding separate meetings, top management can review quality and environmental performance during the same management review process.

The agenda might include:

  • Customer feedback
  • Quality objectives
  • Environmental objectives
  • Nonconformities
  • Corrective actions
  • Audit results
  • Process performance
  • Environmental performance
  • Compliance status
  • Risks and opportunities
  • Resource requirements
  • Improvement opportunities

This gives leadership a broader understanding of organizational performance.

What Are the Challenges?

Implementing both standards simultaneously is not without challenges.

The first challenge is Scope. The organization must clearly define which activities, locations, products, services, and processes are included.

The second challenge is Competence. Personnel responsible for quality management may not automatically understand environmental requirements, and environmental personnel may not have sufficient knowledge of quality-management principles. Training is therefore important. Click here to view some of the training services that QMII provides including ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22301 and many others: https://www.qmii.com/training-services-qmii/

Another challenge is avoiding unnecessary documentation. Organizations sometimes respond to two standards by creating excessive procedures, forms, and records. Integration should achieve the opposite: a streamlined system that provides effective control without unnecessary bureaucracy.

Leadership commitment is also essential. ISO 9001 and ISO 14001 should not be treated as separate certification projects owned by different departments. They should support the organization’s overall strategic direction to meet its measurable objectives and scope.

Should You Implement Them Simultaneously?

For organizations that are starting from scratch, implementing both standards simultaneously can make considerable sense when quality and environmental management are both strategically important. However, the organization should consider its resources, size, complexity, regulatory environment, and existing management-system maturity. A practical implementation approach could be:

Step 1: Define the organizational context and scope

Identify internal and external issues, interested parties, organizational processes, and the boundaries of the management system.

Step 2: Identify common processes

Determine which processes can support both ISO 9001 and ISO 14001 requirements.

Step 3: Identify standard-specific requirements

Clearly identify quality-specific and environmental-specific requirements that need dedicated controls.

Step 4: Establish integrated objectives

Develop measurable quality and environmental objectives that support business strategy.

Step 5: Train employees

Ensure employees understand both the quality and environmental responsibilities relevant to their work.

Step 6: Implement operational controls

Integrate quality and environmental considerations into everyday processes rather than treating them as separate administrative activities.

Step 7: Conduct integrated internal audits

Evaluate both standards systematically while ensuring that each requirement is adequately addressed.

Step 8: Conduct management review

Use management review to evaluate the effectiveness and performance of the integrated system.

Step 9: Prepare for certification

If certification is required, the organization can work with a certification body to determine the appropriate audit and certification arrangements.

The Bigger Picture

The real value of implementing ISO 9001 and ISO 14001 together is not simply obtaining two certificates. The objective should be to create a management system that helps the organization produce consistent results while controlling environmental impacts and improving overall performance.

Quality and environmental performance are often interconnected. Poor process control can generate defects, rework, waste, and additional resource consumption. Better process control can therefore improve both quality and environmental performance.

An integrated management system can help organizations recognize these connections.

Conclusion

The two standards have different purposes, but their common management-system structure makes integration practical. Organizations can combine processes such as internal auditing, management review, corrective action, competence, document control, risk management, and continual improvement while maintaining separate controls for quality-specific and environmental-specific requirements.

The key is to avoid treating the standards as two independent compliance exercises.

Instead, organizations should build one coherent management system that supports quality, environmental performance, regulatory compliance, customer satisfaction, risk management, and continual improvement.

When implemented effectively, ISO 9001 and ISO 14001 can complement rather than compete—helping an organization become not only more consistent and customer-focused, but also more environmentally responsible and sustainable.

If you have any questions, contact QMII and our panel of expertise and solution providers can help you and guide you with your requirement of an integrated management system.

About the Author

Anjalika Singh is the President of QMII (Quality Management International, Inc.), a global management systems consulting firm headquartered in Ashburn, Virginia. Over the course of her career, she has developed a sharp intuitive sense combined with strong operational and training management skills, making her a key asset in QMII’s consulting and training initiatives. Her work focuses on practical lead-auditor training and helping organizations adopt ISO and industry-specific management systems in a way that delivers real business value. Anjalika also serves as President and CEO of iCertifications, LLC, where she leads efforts to make accredited ISO certification services accessible to small and medium-sized businesses.

Subchapter M and TSMS Certification: What U.S. Towing Vessel Operators Must Know

Subchapter M ushered in a new era for safety on US inland waters. It outlined requirement for towing vessels to improve the overall safety of marine transportation on inland water. Subchapter M compliance began with the publishing of the rule in July 2016 with a phased implementation approach and a requirement for all vessels to hold a valid Certificate of Inspection (COI) by July 2022.

These United States Coast Guard, USCG towing vessel regulations outlined requirements for crew competence, better office oversight of vessel management, equipment standards and requirements for emergency preparedness. Subchapter M requirements 2026 have not changed since inception, however, there has been much additional guidance on interpretation of requirements published by the USCG.

In the 90s and 2000’s, there was an increase in major incidents on inland waterways including collision of towboats & barges with other boats and allisions with shore infrastructure such as bridges resulting in fatalities and impact to the local economy. Studies cite 60–80%+ of incidents owe to human-system interface failure.

With the requirement in force the grace period is now over. These towing vessel safety regulations are now law via US Code and US CFR as outlined in 46 CFR Subchapter M.

TSMS vs. Coast Guard Inspection: Choosing Your Compliance Path

Vessel owners have two options to ensure compliance with the regulations. The two options include a TSMS option and Inspections by the USCG. There are pros to each and below is outlined the TSMS vs Coast Guard inspection options:

Option 1 (Coast Guard inspection): This consists of an annual inspection by the USCG within 3 months of COI anniversary. These are scheduled directly with the USCG and incur a fixed fee as outlined by the USCG. In this option each boat must get inspected each year. For owners with large fleets this cost can be high. These Coast Guard annual inspections are also dependent on USCG personnel availability.

Option 2 (TSMS): Using this option the vessel owner contracts with a USCG approved third-party organization (TPO) who must assess office and vessel operations and issue a TSMS certificate of conformity six months before the COI date. Under this option all vessels under the TSMS must be audited at least once in a 5-year period. Under TSMS costs can be lower and there is more predictable scheduling, but it requires the building of internal systems.

Penalties and Operational Risk of Non-Compliance

With the subchapter M rule in force, towing vessels cannot legally operate without a valid COI. Without a COI or a TSMS Certificate of conformity (on the basis on which a COI is effective), vessel owners can take a direct hit to their revenue because of Subchapter M penalties and downtime.

There is also the potential for marine insurance coverage and liability protection costs to be impacted because of the towing vessel compliance risk. More importantly though non-compliance bears an underlying risk of a vessel not operating to standards. This can lead to major onetime costs for an owner as a result of a major incident/accident on the waterway.

A system approach allows the owners to be aware of potential risks before they impact business and to proactively address them. There are also the intangible risks associated with impact to company reputation.

Lastly substandard vessels not complying with the 46 CFR subchapter M requirements can be detained by the USCG and prevented from operating until all issues have been resolved.

Building a Towing Safety Management System (TSMS)

A compliant TSMS does not start with the TPO showing up to audit, it starts with a gap analysis. TSMS development begins with comparing an operator’s existing procedures against what Subchapter M actually requires, which shows the office and vessels where they stand and what policy and procedure development still needs to happen before an auditor is ever involved.

From there owners build out the actual safety management system for towing vessels — policies covering navigation, mechanical and electrical systems, and towing operations, plus procedures for reporting near misses and hazardous conditions. Crew training has to follow, and it needs to be real familiarization on these procedures rather than a manual handed out and never opened, since Subchapter M puts a lot of weight on crew competence as part of the TSMS certification process.

Documentation and recordkeeping is really the backbone of a defensible TSMS. Auditors and the USCG want objective evidence — training records, maintenance logs, drill records, internal audit findings — that shows the system is being followed day to day, not just written down and filed away.

Once policies, training and documentation are in place, the operator runs its own internal audit before the TPO conducts the external certification audit. That relationship with the TPO does not end at certification — TSMS audit requirements call for periodic external audits going forward, with a full vessel audit at least once every five years and a management audit twice in that same five-year period.

Building a Towing Safety Management System from a blank page can take months, which is why most operators lean on ready-made templates over using a consultant to reduce costs. However, a poorly built foundation can kill a system over time. It results in too much documentation, additional burden for the crew and a system that only lives on paper.

This is where a partner like QMII fits in to help build a strong foundation with a system documented to fit the operational need, to reduce the compliance burden on the crew/office, and to provide valuable insights with their extensive maritime expertise. QMII helps to shorten the runway from initial gap analysis to a certified, audit-ready TSMS.

Designated Person Ashore: Roles and Certification Requirements

One of the key factors for success of a safety management system is the role the company management play in it. This includes the provision of resources needed for the system to be implemented well by the vessel crew. To enable this support the TSMS requires a Designated Person Ashore (DPA). This person is to be nominated by the company and must have a access to the highest level of management ashore.

The DPA has their own TSMS management responsibilities, acting as a shoreside link between vessel operations and management. They are responsible for monitoring safety and compliance of vessel operations across the fleet. The DPA is the person a captain or crew member can approach to escalate a safety concern, knowing it will not just get overridden by production pressure.

This is a role companies often underestimate until an audit finds gaps in how it actually functions day to day. DPA certification and TSMS management responsibilities training give the person in this seat a working knowledge of what the USCG and TPO expect to see documented, not just a title on an org chart.

For owners setting up a TSMS for the first time, or replacing a DPA who has moved on, QMII’s Designated Person training for this role is a natural next step. It helps provide those without prior DPA experience with the knowledge needed to execute in the role.

Auditor Training for Internal TSMS Oversight

Audits play a crucial role in assessing the state of conformity and the effectiveness of the system. Internal auditors conduct audits to provide insight to the leadership on potential risks that may catch them blindsided. While inspections and maintenance checks are regular occurrences, they do not assess the interaction of the processes and the interaction of the shore and the vessel TSMS.

Subchapter M outlines requirements for internal audits to be conducted once annually at a minimum and also identifies the criteria for internal auditors. TSMS auditor training for internal auditors includes them completing an ISO 9001 lead auditor course or equivalent. This maritime compliance auditor course helps auditors prepare for planning, conducting and reporting of audit results. Auditors must objectively assess the evidence they are given and draw conclusions based on factual evidence and not on opinions.

With over 40 years of experience in teaching auditor courses this is key distinction of QMII’s auditor training. QMII’s ISO 9001 auditor training meets the requirements of Subchapter M and teaching auditors to go beyond merely seeking conformity. Trained internal auditors can through internal audit towing vessel better assess the system effectiveness.

Maintaining Certification Through Ongoing Audits and Renewals

Getting the TSMS certificate is not the finish line, it’s the starting point for an ongoing compliance cycle. Once certified, operators must conduct annual internal audits plus the undergo the external audit cycle run by the TPO. A full vessel audit at least once in five years for each vessel and a management audit twice within that five-year window. Missing either side of that cadence puts the certificate, and by extension the COI, at risk.

Most compliance failures at this stage are not drastic, they’re just neglect. Documentation lapses, an internal audit that gets pushed back a quarter and then forgotten, a missed audit window because nobody was tracking the anniversary date. Crew turnover is another common one; a new captain or engineer who was never properly familiarized with the TSMS procedures.

The operators who stay ahead of this treat certification maintenance as a standing responsibility, not a once-a-year scramble before the TPO shows up. That usually means someone managing the audit calendar, keeping training records current as crew changes, and catching small gaps before they become findings. The Master should ensure this on behalf of the company.

This is also where ongoing training and consulting support earns its keep. Rather than relearning TSMS renewal requirements every time an audit window approaches, operators working with a partner like QMII can keep certification active on a predictable schedule instead of managing it as a recurring emergency.

About the Author

Julius DeSilva is CEO of QMII (Quality Management International, Inc.), with more than 25 years of experience in quality management systems, maritime safety and security, and information security. A former seagoing officer and Exemplar Global Certified Lead Auditor (ISO 9001, ISO 27001, ISO 50001, RC14001), he has trained over 1,500 professionals as lead auditors and led consulting and auditing engagements across manufacturing, government, maritime, and aerospace sectors. He holds an MBA from the Darden School of Business, University of Virginia, and is an Associate Fellow of the Nautical Institute.

What to Expect from an ISO 9001 Consultant: A Plain-English Buyer’s Guide

Hiring an ISO 9001 consultant should not be treated as purchasing a collection of procedures or hiring someone to just get the certificate. A capable consultant should help your organization develop a management system that improves how work is controlled, how risks are managed, how customers are served, and how leadership makes decisions. It is of course a generic compilation of thoughts to assist all organizations who work with consultants to refine, retune and improve their management systems. With the ISO 9001 almost on the eve of being updated in September 2026, this is a pertinent question: how to select consultants. QMII has forty plus years of experience. I have been in the lead role at QMII for two decades now and share some of my thoughts to enable managements make good decisions on this.

The certificate matters, but it should be the result of an effective management system and not the sole purpose of the engagement.

Organization’s As-Is System.

QMII has worked with organizations and management systems for four decades. During that time, we have learned that successful consulting is not about imposing a generic ISO template. It is about understanding how an organization operates, identifying what already works, strengthening what does not, and helping its people develop a system they can use and improve long after the consultant has left. I think beginning with the “as-is” of the system is the best start. Basing a system design on a template or a fictional system is never a good idea.

For organizations considering ISO 9001 certification or trying to obtain more value from an existing system, this guide explains what a competent consultant should provide, what the client should contribute, and what warning signs to watch for.

Build on What Already Exists

The consultant should begin by understanding the organization. Please don’t throw the baby with the bath water. Start with the “as-is” of the system. A good consultant does not arrive with a finished quality manual and begin changing the company to fit it. The consultant first learns how the organization works. This includes understanding, what the organization provides (products and services), who its customers and other relevant interested parties (ISO 9001 clause 4.1 and 4.2) are. Then look at how customer requirements are determined and fulfilled and connect these to which processes create value (ISO 9001 clause 4.4). A good consultant should systematically look at what can prevent those processes from achieving their intended results (ISO 9001 risks clause 6.1 and maintaining customer focus clause 5.1.2). No consultant can forget which regulatory, statutory, contractual, and industry requirements apply to the organization and its deliverables. Study how performance is currently measured and what leadership wants the management system to accomplish (policy 5.2 flowing to measurable objectives 6.2 considering the risks 6.1 to doing the work 8.5 and releasing the product and or service 8.6).

Use the Process Approach

This approach reflects ISO 9001 Clauses 4.1 and 4.2, which require an organization to understand its context and the needs and expectations of relevant interested parties. Clause 4.4 then requires the organization to determine and manage the processes needed for its quality management system.

These requirements cannot be addressed properly with a generic questionnaire alone. The consultant must talk with leadership, process owners, supervisors, and employees. They should observe work where it occurs and then follows the flow of actual orders, information, materials, decisions, and records. At QMII, we regard this discovery process as essential. Four decades of experience have reinforced a simple lesson, before recommending a solution, we must understand the client’s organization, its culture, its risks, and its intended results.

Emphasize the “as-is” of the system as a consultant. It is more and committed work as a consultant to start with what they already do as compared to a template.  The consultant should be willing to build on what the organization already Has. Most established organizations already have a management system, whether they call it one or not. I often use a practical rule of thumb: if an organization has operated successfully for eighteen months, much of its management system, perhaps 85 percent is already present, even if it has not been formally defined in ISO language.

After all they receive customer inquiries, review contracts, purchase materials, train employees, produce goods or deliver services, inspect work, resolve problems, and monitor financial and operational performance. These activities may not be organized around ISO terminology, but the underlying processes already exist.

A capable consultant identifies and builds upon these existing practices. The objective is not to replace sound business methods with ISO methods. The objective is to ensure that the organization’s processes are adequately defined, controlled, measured, and improved. This may require, clarifying responsibilities and authorities, improving the interaction between departments as also establishing missing controls, simplifying duplicated or ineffective controls and identifying meaningful performance measures. There may be a need to strengthening corrective action, addressing risks before failures occur and lead risks as input to create OFI (opportunities for improvement) and finally retaining documented information where it adds value or provides necessary evidence. The system from a reactive where NC (non-conformity) drives correction and corrective action must be changed to a proactive system where data drives risk and trends. The consultant should help the organization close genuine gaps without creating unnecessary bureaucracy.

ISO 9001 does not require a procedure for every activity. It requires the organization to maintain and retain documented information to the extent necessary to support process operation and provide confidence that work is being performed as planned (clause 4.4 of ISO 9001). An experienced consultant understands this distinction.

The consultant should use a process-based methodology. ISO 9001 is based on the process approach. Consequently, the consultant’s methodology should also be process based. A process is more than a department or a procedure. It is a set of related activities that converts inputs into intended outputs. Each process should have a purpose, responsible ownership, appropriate resources, operating controls, performance criteria, and methods for addressing risk and improvement. For example, sales should not be examined only as an organizational department. The consultant should consider the full customer-related process which should include how are customer needs identified, how are quotations prepared, how are requirements reviewed before commitments are made and how are changes communicated? Then there should be clarity on how are operational departments informed, how is customer feedback is obtained and how does the organization determine whether the process is effective?

This thinking connects several ISO 9001 requirements instead of treating each clause separately. It can link the process requirements of Clause 4.4 with operational planning under Clause 8.1, the review of customer requirements under Clause 8.2, performance evaluation under Clause 9.1, and improvement under Clause 10.

QMII’s methodology has been developed and refined through four decades of consulting, training, auditing, and practical management-system experience. Our consultants look beyond individual clauses to understand how processes interact and whether the system is achieving its intended results.

Engage Leadership

Then in selecting consultants consider how the consultant will engage the leadership. ISO 9001 cannot be implemented successfully as a quality department project. Clause 5.1 places clear responsibility on top management for the effectiveness of the quality management system. Leadership is expected to establish direction, integrate quality requirements into business processes, provide resources, promote the process approach and risk-based thinking, and support continual improvement.

A competent consultant should therefore work directly with senior leadership. This does not mean occupying executives with the wording of every procedure. It means helping them understand and fulfill their responsibilities. The consultant should help leadership answer practical questions such as what results do we expect from this management system, what quality objectives support the organization’s business strategy, which risks could prevent us from fulfilling customer requirements and do the process owners have sufficient authority and resources? Without information leading to risks and trends the top management (TM) cannot make objective decisions. The consultant should bring to their understanding if the organization is receiving useful performance information, are management reviews resulting in decisions and action and is the system helping improvement or merely preparing us for audits?

The consultant should also be willing to challenge leadership respectfully. If managers want ISO 9001 certification but are unwilling to provide time, resources, accountability, or visible support, the consultant should explain the consequences honestly. Commitment cannot be delegated to the consultant.

Transfer Knowledge and Build Independence

Another important duty of the consultant is to transfer knowledge (ISO 9001 clause 7.1.6). A consultant’s responsibility to transfer knowledge also supports the intent of ISO 9001 Clause 7.1.6 concerning organizational knowledge. One of the most important tests of a consulting engagement is what happens after the consultant leaves. The organization should understand and own its management system. Employees should know how their work contributes to quality. Process owners should be able to monitor and improve their processes. Internal auditors should be capable of evaluating effectiveness, and leadership should be able to use management review as a genuine decision-making process.

The consultant should therefore act as an adviser, facilitator, coach, and educator and not as the permanent owner of the system. Consultants who intentionally make clients dependent on continuing support are not serving the client’s long-term interests. Prospective clients should therefore examine how the consultant intends to transfer knowledge and build internal capability. That is unethical and organizations should therefore be wise in selecting consultants. Knowledge transfer may include awareness sessions for employees (often called familiarization and or orientation), leadership briefings, process-owner workshops, risk-based thinking exercises, internal auditor training, corrective-action and root-cause training, guidance for management review and perhaps coaching during implementation and readiness activities. Training should be relevant to the participant’s role. Senior leaders, internal auditors, process owners, and frontline employees do not all need the same level or type of instruction.

QMII is both a consulting, auditing and a training organization. This enables us to combine subject-matter expertise with a strong emphasis on developing the client’s internal capability. Our measure of success is not client dependence; it is the client’s ability to sustain and improve the system.

Prepare for Certification, Without Becoming the Auditor

The consultant should prepare the organization for certification without becoming the auditor. A consultant may help an organization prepare for certification, but the consultant should not promise or guarantee certification. Certification decisions belong to an independent, accredited certification body. The consultant should explain the certification process, help the organization select a suitable certification body, and prepare the organization for the Stage 1 and Stage 2 audits. However, the certification body must remain independent of the consulting work. Before the certification audit, the consultant should help confirm that the quality management system has been implemented, processes are operating under planned conditions and required documented information is available. Then there is the need for employees to understand their responsibilities, for quality objectives being monitored, internal audits should have been completed, and management review has taken place. Then there are the NCs (Nonconformities) which should have been corrected. Basically, that there is evidence that the system is producing results.

A readiness review should not be a rehearsal in which employees memorize answers. It should determine whether the system is genuinely ready to be evaluated. The best preparation for an external audit is an effective system used routinely, not a last-minute cleanup exercise. The consultant should focus on results, not just documents. This results-oriented emphasis is also consistent with ISO 19011:2026, published in May 2026, which places increased attention on risk, technology, digitization, and evolving audit practices. ISO 9001:2026 which should be available in September 2026 also emphasizes this.

Focus on Results, Not Documents

Remember that a management system may be fully documented and still fail to deliver. A skilled consultant looks beyond whether a procedure exists. The more important questions are is the process achieving its intended result, are customer requirements consistently fulfilled, are errors and delays decreasing, are employees competent to perform their work and are risks being addressed? This should be followed by addressing if recurring problems are being eliminated, are decisions based on reliable evidence, is customer satisfaction improving and is the organization learning from experience?

This results-based approach is consistent with ISO 9001 Clause 9.1, which requires organizations to determine what should be monitored and measured, and Clause 10, which focuses on nonconformity, corrective action, and continual improvement. The consultant selected should help establish measures that support decisions, not measurements collected only because they look impressive on a dashboard.

Match the Consultants to the Industry

Further the consultant should tailor the system to your industry. This is true for ISO 9001 and particularly true for industry specific standards. ISO 9001 can be applied across many industries, but implementation should never ignore industry context. An aerospace supplier, maritime organization, engineering company, training provider, nuclear supply-chain organization, and general manufacturer may all use ISO 9001, but their risks, contractual requirements, operational controls, and stakeholder expectations will differ substantially. Therefore, ask prospective consultants whether they understand the industry and operating environment, the applicable legal and regulatory requirements, customer-specific requirements, the industry terminology, product or service risks and the relevant sector-specific standards. This all affects the practical realities faced by the employees. The system is for the employees and not for auditors.

QMII’s subject-matter expertise extends beyond the text of ISO 9001. Our experience includes maritime safety and the ISM Code, aerospace standards such as AS9100 and IA9100, nuclear quality assurance, environmental and occupational health and safety management systems, supply-chain security, and auditor development. This breadth allows us to recognize where ISO 9001 must operate as part of a larger business and regulatory framework.

Warning Signs When Selecting a Consultant

The organization should consciously include study of promises of guaranteed certification, offers of a complete generic documentation package before understanding the organization, when consultants focus almost entirely on procedures and forms and treats ISO 9001 as the responsibility of the quality manager. Further when the consultant cannot explain requirements in plain English, has little relevant industry or auditing experience, discourages direct contact with employees or leadership, creates unnecessary documentation and or prepares people to say the right things to an auditor and specially makes the organization dependent on continued consulting support. Another warning sign is when the consultant shows little interest in business performance or customer satisfaction.

Questions to Ask Before Signing

A consultant’s credentials matter, but so do judgment, communication skills, integrity, practical experience, and the ability to gain the confidence of people at every level of the organization. Therefore, consider the questions to ask before signing a consulting agreement:

  1. How will you learn about our organization and its processes?
  2. What experience do you have in our industry?
  3. Who will perform the consulting work?
  4. What will you expect from our leadership team?
  5. How will you avoid unnecessary documentation?
  6. How will you help our employees understand and own the system?
  7. What training is included?
  8. How will progress and effectiveness be measured?
  9. How will you prepare us for internal and certification audits?
  10. What support will be available after certification?
  11. Can you provide relevant references or examples?
  12. How will the completed system support our business objectives?

The proposal should clearly define scope, responsibilities, deliverables, estimated timing, training, expenses, and assumptions. The least expensive proposal may not provide the best value, particularly if it results in a burdensome system that later must be redesigned. Remember the summary of ISO 9001 clause 8.4.1 on selecting vendors. Selecting a consultant solely on the lowest price can be costly if the resulting system is bureaucratic, ineffective, or must later be redesigned.

What QMII Brings to the Engagement

From QMII experience of 40 years and with satisfied clients I can say consultants should bring to the engagement value. For forty years, QMII has helped organizations understand, implement, audit, and improve management systems. That history has enabled us to perfect a practical methodology grounded in the process approach, systems thinking, risk-based thinking, and continual improvement. Amongst many qualities, I would say good consultants should at least bring these three qualities to every engagement.

First, bring subject-matter expertise. Consultants and instructors understand both management-system requirements and the operational environments in which those requirements must be applied. Second, the consultant must bring a proven methodology. For this begin by understanding the organization, map and evaluate its processes, identify meaningful gaps, work with its people to develop appropriate controls, and transfer the knowledge needed to sustain the system. Third, bring commitment to the client’s success. Do not measure success merely by the award of a certificate. Good consultants like QMII want the client to have a management system that employees understand, leadership uses, customers trust, and the organization continually improves.

The Final Test of a Successful Engagement

The final test of a successful ISO 9001 consulting engagement should leave an organization with more than a certificate and a set of documents. It should leave the organization with better-understood processes, clearer responsibilities, more engaged leadership, stronger control of operational risks, more capable employees and internal auditors, better information for decision-making, a more effective corrective action, greater confidence in meeting customer requirements and a s sustainable foundation for continual improvement. The real question is not simply, “Did we achieve ISO 9001 certification?” The better question is, “Has our management system made us a more capable, consistent, and successful organization?”

That is what a client should expect from an ISO 9001 consultant—and it is the standard to which QMII has committed itself for four decades.

About the Author:

Inderjit (IJ) Arora, Ph.D., is the Chairman of QMII. He serves as a team leader for consulting, advising, auditing, and training regarding management systems. He has conducted many courses for the United States Coast Guard and is a popular speaker at several universities and forums on management systems. Arora is a Master Mariner who holds a Ph.D., a master’s degree, an MBA, and has a 35-year record of achievement in the military, mercantile marine, and civilian industry.

ISO 9001 Gap Analysis: How to Do It Before Your First Certification Audit

What Is a Gap Analysis and Why It Matters Before Certification

When first looking to conform to ISO 9001, seeking certification or perhaps looking to upgrade your system to a new revision of the standard an ISO 9001 gap analysis comes up in conversations. This article outlines what a gap analysis is, what goes into it and why it matters.

Defined plainly, it is a structured comparison of your current Management System (MS) against ISO 9001 requirements, clause by clause. Think of it as a practice exam before the main exam that gives you insights into where your weaknesses are so you can improve on them. It is not a full audit of your system. More a diagnostic check. In a gap analysis no nonconformities are “issued,” just gaps identified.

Not knowing where your weaknesses in the management system lie can impact your operations by letting risks go unnoticed and unaddressed. Further it may result in certification delays especially if any non-conformities identified are major. In a few cases the major non-conformities may require a secondary onsite visit, that is an additional cost. If your business contracts and contingent upon certification being achieved, then an ISO 9001 gap analysis helps. It doesn’t guarantee a clean audit, but it de-risks it significantly.

It is a small cost to incur to avoid a failed external audit and certification delay. Other intangible costs are also incurred such as a hit to team morale and loss of faith in the system approach.

The 10-Clause Framework: Walking Through ISO 9001 Section by Section

With the harmonization to a uniform structure ISO 9001 and its 10 clauses are not aligned to the Plan-Do-Check-Act cycle. This allows for easier implementation and integration with other management systems. As a note, clauses 1-3 (scope, normative references, terms) are non-auditable but set context for the standard and its why.

Perhaps the best approach to the gap analysis is to use the clause structure of the standard as a starting point. The challenge often lies in assessing processes and connecting internal requirements to the language of ISO. Clauses 4 through 10 are the real “meat” of the standard.

  • Clause 4 — Context of the organization – Evidence for this clause is often found with the leadership and requires their involvement and engagement.
  • Clause 5 — Leadership – The clauses under 5 require leadership awareness of what the system needs from them as also the assignment of a clear vision via the policy and clear responsibilities and authorities.
  • Clause 6 — Planning – This clause requires the organization to assess the risks to meeting its goals (including customer satisfaction and continual improvement) and identify controls that will enable mitigation of these risks.
  • Clause 7 — Support (resources, competence, documented info) – While perhaps the easiest clause of the standard, documentation control is often the biggest weakness in systems and in audits.
  • Clause 8 — Operation – Clause 8 is the “meat” of any organizations operations and will perhaps take the longest time during the gap analysis.
  • Clause 9 — Performance evaluation – Here is where the organizations determine what they are going to monitor and how they monitor it.
  • Clause 10 — Improvement – Check whether your system has avenues for identifying and acting on improvement opportunities including identifying and taking action on non-conformities.

A simple was to look at each requirement is to ask, “What does this clause require? Do we have evidence? Is it followed consistently?”. If you struggle to identify a suitable checklist for the gap you can simply use the clause structure as a gap analysis checklist itself. Reach out to [email protected] should you want a checklist you can use.

 

Context of the organization: what most SMBs overlook in clause 4

SMBs often treat 4.1 (internal/external issues) as a one-time exercise, and not a living document. For micro business with only a few employees there may be no need to document the context. I say no need as the ISO 9001 standard does not require the context to be documented. It is best practice though as the company grows in locations, personnel and/or operations. Contextual issues are really business 101. An organization must determine what is going to impact them and what actions they should be planning to mitigate any negative impact while building on the positive ones. Penning them down helps keep track of them and review them later.

While leadership may know who the interested parties are what their needs are often internal parties get overlooked such as employees, and certain external parties such as suppliers and insurers. Interested parties are often thought of as customers and perhaps rightly so as they are probably the largest for a business. When reviewing the scope statement make sure it covers what you are seeking to get certified. While generally the limit of the actual site/process boundaries is common don’t use it as a means to exclude areas/processes that must be included.

Clause 4.4 is often a weakness in systems QMII has worked on. The clause requires the organization to determine the sequence and interaction of the processes. SMBs often have documented procedures but no process interaction map. QMII often captures this as a core process for its clients.

Pro tip: tie context review to a real business planning input (e.g., strategic planning meeting) so it doesn’t feel like a paperwork exercise

How to Score Your Gaps: A Simple Red/Amber/Green Method

A simple was to score your gap analysis is using the RAG logic:

  • Red = requirement not met at all, no evidence
  • Amber = partially met, inconsistent, or undocumented but practiced
  • Green = fully met with objective evidence

While it is easy to score the entire clause, QMII recommends scoring each requirement at the sub-clause level, for accuracy. In addition to the requirement in one column, additional columns may include current state evidence, RAG, actions needed to conform, action owner and target date.

Remember it is a system and you are identifying risks. As such even though an area/requirement may be conforming and green your ISO 9001 gap analysis should identify process risks such as when reliant on one person or no document exists, only tribal knowledge. This gives the leadership visibility on the risk and they can make a decision to accept it or not.

Pro Tip on prioritization: fix all Reds first, especially in clauses tied to product/service conformity (clause 8) since those tend to trigger major NCs

Common Gaps Found in US Manufacturing Plants (and How to Close Them Fast)

Below is a list of common gaps found across systems that QMII has helped implement and get through first time certification:

  • Calibration records incomplete or gauges past due date – Create/update the calibration log and set up a recall/alert system for upcoming due dates.
  • Supplier evaluation not risk-based (approved vendor list exists but no criteria/re-evaluation cycle) – For each supplier determine the evaluation, selection and re-evaluation criteria. Apply them to existing suppliers.
  • Nonconformance and corrective action process exists but isn’t tied back to root cause analysis (people fix symptoms, not causes) – preferably get a few personnel training in problem solving/root cause analysis (RCA) and these will then champion this RCA process.
  • Training records not linked to competency requirements for specific roles – Determine the competency requirements for each role, determine the records needed to prove competency is met, identify where and who will retain the records.
  • Management review meetings happen but don’t cover all required inputs/outputs from clause 9.3 – Review the existing review template against the requirements of Clause 9.3. In addition to the inputs remember to document the decision and actions of leadership.
  • Document control: multiple “current” versions floating on shop floor vs. controlled system – Ask personnel to identify all out-of-date documents either on the desktop or in print and to control them. The primary repository whether in print or electronic should be used each time a document is needed.
  • No core process mapped – map the sequence and interaction of processes.

Each of these while easily fixed are often looked over when a gap analysis is done by someone with little experience of the standard.

Clause 8 operations: where most manufacturers find the most gaps

Below is a list of common items identified during ISO 9001 gap analysis done by QMII:

  • Design and development controls (8.3) often skipped by manufacturers who think they don’t “design” anything, but engineering changes count
  • Control of externally provided processes/products (8.4) inadequate
  • Production and service provision (8.5), where work instructions as documented do not relfect actual practice
  • Control of nonconforming outputs (8.7), disposition process (use-as-is, rework, scrap) not always documented with authority sign-off and often missing a designated area for storage

Pro Tip: walk the actual production floor with the clause 8 checklist in hand rather than reviewing documents at a desk — gaps surface fastest this way

Gap Analysis vs Internal Audit: What’s the Difference and When to Use Each

Below is a handy reference on the difference between an ISO 9001 gap analysis and an internal audit.

  • Gap analysis = readiness check, usually done once before initial certification or major transition
  • Internal audit = ongoing, cyclical, required by clause 9.2 as part of maintaining certification. While the standard does not specify a frequency, mature organization do internal audits at least twice a year and sometimes more often.
  • Gap analysis can be broad-brush; internal audits require formal audit plans, trained auditors, and documented findings/CAPAs
  • Use gap analysis when: preparing for first certification, after a major QMS overhaul, after failed audit findings elsewhere or a major customer quality issue.
  • Use internal audit when: maintaining ongoing compliance, meeting the annual audit program requirement, preparing for surveillance audits

Key point: A gap analysis finding should feed into your first internal audit program, not replace it.

How to build a gap closure action plan with owners and deadlines

While the gap analysis is a good starting point failing to take actions timely can leave you too close to the project deadline with important issues unaddressed. Keep in mind that while the ISO project is important, the show must go on. As such personnel in an organization are being pulled in all directions to meet operational needs of getting the products and/or service out the door.

It is therefore imperative to get leadership involvement from the start of the project. For other personnel in the organization to know how important this is to leadership. To agree to deadlines mutually and identify verification methods to know actions items have been closed out effectively. Assign realistic deadlines based on complexity of the issue identified. For example, process redesign may take longer than a documentation fix.

For good measure the verifier must be someone other than the person who “fixed” it should confirm closure. Tie closure plan directly to the certification body’s audit date so there’s a hard deadline forcing prioritization.

Pro Tip: Recommend a weekly stand-up or tracker review cadence leading up to the audit date

FAQs

How long does a gap analysis take?

Typically, 2 days for a single-site SMB, depending on number of processes and whether it’s desk review only or includes floor walks. Larger or multi-site operations can take 1 week or more depending on the size of the sample chosen for the gap.

Who should conduct a gap analysis — internal team or external consultant?

  • Internal team: cheaper, deeper operational knowledge, but risk of blind spots/bias toward “we already do this”
  • External consultant: objective, benchmarked against many other clients, but costs money and takes time to onboard to your processes
  • Hybrid approach often works best: consultant-led framework, internal team fills in evidence

Can a gap analysis replace an internal audit?

No. A gap analysis is a one-time readiness check; internal audit is a mandatory recurring clause 9.2 requirement. Certification bodies will ask for internal audit records, not gap analysis reports, as objective evidence

What does a gap analysis report look like?

Typically, a spreadsheet or short report that includes clause-by-clause RAG score (or another methodology), evidence notes, gap descriptions, recommended actions, and an overall readiness percentage. Some consultants supplement it with an executive summary for leadership

How close do you need to be before scheduling a certification audit?

Rule of thumb: all Red-rated items closed, Amber items with an active action plan and target dates, before booking Stage 1.

About the Author:

Julius DeSilva is CEO of QMII (Quality Management International, Inc.), with more than 25 years of experience in quality management systems, maritime safety and security, and information security. A former seagoing officer and Exemplar Global Certified Lead Auditor (ISO 9001, ISO 27001, ISO 50001, RC14001), he has trained over 1,500 professionals as lead auditors and led consulting and auditing engagements across manufacturing, government, maritime, and aerospace sectors. He holds an MBA from the Darden School of Business, University of Virginia, and is an Associate Fellow of the Nautical Institute.

Understanding Nonconformance Reports (NCRs) in ISO Audits: What to Do When You Get One

A Nonconformance Report (NCR) is one of the most important outcomes of an ISO audit. While many organizations initially view an NCR as a sign of failure, it is a valuable management tool that identifies opportunities for improvement. Whether an organization is certified to ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22000, or another ISO management system standard, receiving an NCR is a normal part of the auditing process. The true measure of an organization’s management system is not whether it receives nonconformities, but how effectively it responds to them, and the corrective action and root cause analysis that follows. Understanding what an NCR means and knowing how to address it systematically can help organizations strengthen their management systems, reduce risks, improve compliance, and enhance overall business performance.

What Is a Nonconformance Report?

A Nonconformance Report is a formal record issued by an auditor when objective evidence demonstrates that an organization’s management system does not meet one or more requirements of the applicable ISO standard, its own documented procedures, or relevant legal and regulatory obligations.

An NCR is always based on objective evidence rather than opinion. Auditors collect evidence through interviews, observation of activities, examination of documents, and review of records.

If the evidence shows that a requirement has not been fulfilled, the auditor documents the finding in an NCR. The purpose of an NCR is not to assign blame or criticize employees. Instead, it highlights gaps that need to be corrected so that the management system remains effective and continues to improve.

Types of Nonconformities:

Although certification bodies may use slightly different terminology, nonconformities generally fall into two categories.

Major Nonconformity

A major nonconformity indicates a significant failure of the management system. It may involve:

  • Complete absence of a required process.
  • Failure to comply with a key ISO requirement.
  • Repeated occurrence of the same issue.
  • A situation that creates serious risk to product quality, environmental protection, occupational health and safety, or information security.
  • Failure to implement corrective actions from previous audits.

Major nonconformities often require prompt corrective action and may affect certification if not resolved within the specified timeframe.

Minor Nonconformity

A minor nonconformity represents an isolated lapse or limited breakdown in the management system that does not seriously compromise its overall effectiveness.

Examples include:

  • An incomplete training record.
  • Missing signatures on inspection forms.
  • An outdated document remaining in circulation.
  • A calibration label missing from one piece of equipment.

Minor nonconformities are more common and usually indicate areas requiring better process control rather than system failure.

Common Reasons Organizations Receive NCRs

Many NCRs arise from recurring management system weaknesses rather than complex technical issues. Common causes include:

  • Poor document control.
  • Inadequate employee training.
  • Failure to follow established procedures.
  • Missing or incomplete records.
  • Ineffective internal audits.
  • Lack of management review.
  • Failure to identify and evaluate risks.
  • Inadequate corrective action implementation.
  • Poor supplier monitoring.
  • Non-compliance with legal or regulatory requirements.

Most NCRs result from inconsistent implementation rather than poorly written procedures.

How Should an Organization Respond?

Receiving an NCR should trigger a structured corrective action process rather than a rushed attempt to “fix the paperwork.” ISO standards emphasize addressing both the immediate problem and its underlying cause.

Step 1: Read the NCR Carefully

The first step is to fully understand what the auditor has identified.

Review:

  • The requirement that was not met.
  • The objective evidence recorded.
  • The process involved.
  • The scope of the nonconformity.

If any wording is unclear, seek clarification from the auditor before the audit closes.

Step 2: Correct the Immediate Problem

Immediate correction addresses the specific issue identified during the audit.

Examples include:

  • Updating an incomplete record.
  • Calibrating overdue equipment.
  • Providing missing employee training.
  • Replacing obsolete documents.
  • Completing required inspections.

These actions eliminate the immediate nonconformity but do not necessarily prevent recurrence.

Step 3: Conduct Root Cause Analysis

Corrective action should always focus on why the nonconformity occurred.

Effective root cause analysis tools include:

  • The 5 Whys.
  • Fishbone (Ishikawa) Diagram.
  • Process Mapping.
  • Pareto Analysis.

For example:

Problem: Employee training records were incomplete.

Why? Training was conducted but not documented.

Why? Supervisors were unaware documentation was required.

Why? The training procedure did not clearly assign responsibility.

Root Cause: The documented process lacked defined accountability for maintaining training records.

Without identifying the true root cause, organizations often experience repeat NCRs.

Step 4: Develop Corrective Actions

Corrective actions should eliminate the root cause rather than simply correcting the symptom.

Examples include:

  • Revising procedures.
  • Assigning process ownership.
  • Improving employee training.
  • Introducing automated reminders.
  • Updating document control systems.
  • Strengthening internal audits.
  • Improving management oversight.

Corrective actions should include:

  • Responsibilities.
  • Deadlines.
  • Required resources.
  • Expected outcomes.

Step 5: Verify Effectiveness

ISO standards require organizations to determine whether corrective actions actually worked.

Verification may include:

  • Follow-up audits.
  • Review of performance indicators.
  • Process monitoring.
  • Interviews with personnel.
  • Examination of updated records.

If the same issue occurs again, the corrective action was not fully effective and further investigation is needed.

What Auditors Expect to See

During follow-up or surveillance audits, auditors typically review whether the organization:

  • Understood the nonconformity.
  • Identified the real root cause.
  • Implemented appropriate corrective actions.
  • Updated documented information where necessary.
  • Trained affected employees.
  • Verified effectiveness.
  • Prevented recurrence.

Auditors are generally more interested in the quality of the organization’s corrective action process than in the existence of the original nonconformity.

Mistakes to Avoid

Organizations sometimes weaken their corrective action process by making common mistakes, including:

  • Treating symptoms instead of root causes.
  • Blaming individual employees without examining system failures.
  • Closing NCRs before verifying effectiveness.
  • Implementing corrective actions without updating procedures.
  • Failing to communicate changes across departments.
  • Delaying corrective actions until the next audit.

These mistakes increase the likelihood of recurring findings and may lead to more serious nonconformities in future audits.

Preventing Future NCRs

The most successful organizations treat every NCR as an opportunity to improve their management systems. Preventive measures include:

  • Conducting thorough internal audits.
  • Reviewing risks regularly.
  • Monitoring process performance through key performance indicators (KPIs).
  • Keeping documentation current.
  • Providing ongoing employee competence and awareness training.
  • Performing effective management reviews.
  • Encouraging employees to report problems before audits.
  • Reviewing trends in previous NCRs to identify recurring weaknesses.

A culture of continual improvement helps organizations identify and resolve issues before external auditors discover them.

The Role of Leadership

Top management plays a critical role in responding to NCRs. Leaders should provide adequate resources, encourage open communication, avoid creating a blame culture, and ensure that corrective actions receive appropriate attention. When leadership demonstrates commitment to continual improvement, employees are more likely to engage positively in resolving nonconformities and strengthening the management system.

Conclusion

Receiving a Nonconformance Report during an ISO audit should not be viewed as a setback but as an opportunity to enhance organizational performance. NCRs provide objective evidence of areas where the management system can be strengthened, helping organizations improve compliance, reduce operational risks, and increase customer confidence.

The most effective response involves understanding the finding, correcting the immediate issue, identifying the root cause, implementing meaningful corrective actions, and verifying their effectiveness. Organizations that embrace NCRs as part of a continual improvement process often emerge with stronger, more resilient management systems and greater readiness for future audits. Rather than aiming for an audit with no findings, organizations should strive for a culture that learns from every NCR and uses it to drive sustainable improvement.

About the Author:

Anjalika Singh is the President of QMII (Quality Management International, Inc.), a global management systems consulting firm headquartered in Ashburn, Virginia. Over the course of her career, she has developed a sharp intuitive sense combined with strong operational and training management skills, making her a key asset in QMII’s consulting and training initiatives. Her work focuses on practical lead-auditor training and helping organizations adopt ISO and industry-specific management systems in a way that delivers real business value. Anjalika also serves as President and CEO of iCertifications, LLC, where she leads efforts to make accredited ISO certification services accessible to small and medium-sized businesses.

Living the System: How to Maintain ISO 9001 Certification Between Surveillance Audits

Every year, thousands of organizations undergo the intense experience of an ISO 9001 audit. Measurable Objectives (ISO 9001 clause 6.2) as key performance indicators are gathered, internal audit reports are polished, conference rooms are booked, and top management gathers to present a united front to the external auditor. When the registrar signs off with zero major non-conformities, a collective sigh of relief echoes through the hallways. One customer organizes a barbecue! QMII in its forty years in providing solutions for effective management systems has seen what follows. In many organizations, then something dangerous happens. The ISO standard goes back onto the shelf until next year.

This phenomenon is often dubbed ISO fatigue or audit-season sprint and is the single biggest vulnerability in quality management. Treating ISO 9001 as an annual event rather than an everyday operational engine guarantees stress, lost productivity, and, worse, a system that serves the auditor instead of the business.

Maintaining certification between surveillance audits should never feel like holding your breath under water until the external auditor resurfaces. Instead, it should be the natural byproduct of running a sound, value-adding Quality Management System (QMS). In QMII we have worked with our customers to do just that, so their system effectively meets requirements, produces confirming products and services and continually improves by reducing waste and giving the organization ROI (return on investment).

The trap of audit driven quality occurs when an organization operates in the audit-driven mode, the standard becomes a burden. Documentation is updated retrospectively, non-conformity reports (NCRs) are rushed through closing phases weeks before the registrar’s visit, and management reviews turn into mere tick-box exercises. The question is why does this happen? There are many reasons primary one has its genesis in not interpreting ISO 9001 clause 4.4.1 correctly where in there is a lack of process ownership. Process owners view ISO 9001 as the Quality Manager’s job rather than their operational responsibility. Over-engineered documentation is another flaw in an ineffective system.  Standard operating procedures (SOPs) were written by the organization for the auditor rather than for the people executing the processes. Additionally, disconnection from strategy makes it worst. ISO 9001 clause 5.1 requires the business and quality to be effectively merged. The QMS is treated as a compliance shadow running parallel to, rather than inside the company’s actual strategic direction. To break this cycle, the focus must shift from preparing for an audit to governing through the QMS. The updated ISO 9001 expected soon, in September 2026 is a step in the correct direction.

There are many actions to maintain an effective QMS but as a brief summarized aid I would classify them as five pillars for maintaining an active QMS. To maintain continuous audit-readiness and drive real organizational value between surveillance visits, organizations can focus on these five foundational practices as a start. Pillar one is to have distributed internal audits wherein instead of compressing your internal audits into a high-stress audit month right before the registrar arrives, distribute the internal audits evenly across the 12-month cycle. Some organizations prefer a six-monthly cycle. These audits can be theme-based or process-based. Auditing can be planned so the organization rotates the audits by department or core process for example quarterly or monthly. Audit for effectiveness, not just compliance. Maybe a good idea to shift the internal audit question from are we following the clauses to: is this process achieving its intended operational outcome? Then finally involve operational leads by training cross-functional staff to audit peer departments. This breaks down silos and builds deep organizational awareness.

The second pillar would be the real-time CA (Corrective Action) and risk appreciation and where applicable OFI (opportunity for improvement). A healthy QMS welcomes non-conformities because they signal an opportunity to prevent business leakage. As Dr. IJ’s original quote goes “the only bad NC is the one you do not know about.” Address root causes immediately (ISO 9001 clause 9.2.2 e).  Don’t let open NCs sit dormant for months. An open non-conformity addressed promptly with robust root-cause analysis (RCA) is a mark of a mature management system. Also be sure to focus on systemic causes by avoiding assigning human error as the primary root cause. Look at process design, training, resource allocation, and tool suitability.

The third and an important pillar is conducting dynamic management reviews (ISO 9001 clause 9.3 as also in other standards in the harmonized structure). If your management Rrview meeting occurs only once a year right before the surveillance audit, it cannot effectively direct the system. It is best to integrate into existing executive business reviews by incorporating the QMS performance metrics (customer satisfaction, supplier evaluation, process yields, risk registers) into routine monthly or quarterly executive meetings. The focus should be on action and decision-making. Ensure top management uses QMS outputs to allocate resources and adjust strategic goals, keeping leadership engagement genuine and ongoing.

The fourth pillar I would say is the continuous document control & simplicity. Documented information should reflect how work is actually performed today. The “as-is” of the system is fundamental to continual improvement. Fictional systems are hard to improve without an honest baseline. It is important to keep it visual and accessible. Lean workflows, quick reference flowcharts, and short video work instructions are far easier to maintain and follow than 20-page text manuals. Also empower frontline feedback by creating a simple channel for operators and team members to flag outdated procedures or suggest process improvements in real time.

The fifth and last pillar is active risk & opportunity management. ISO 9001 clause 6.1 requires organizations to address risks and opportunities, but too many treat the risk register as a static document created during initial certification. The organization must review risks at process changes. The context of the organization (ISO 9001 clause 4.1 and 4.2) changes. Whenever a new customer requirement, equipment change, software deployment, or supply chain shift occurs, review and update the relevant process risk profile.

These five at the least and many such along the same lines, led by the leadership can ensure the management system remains relevant and a tool for continual improvement instead of becoming an expensive investment to keep auditors in business. This is all the more important as we look ahead and start preparing for expected changes with updated of ISO 9001:2026. As organizations maintain the current ISO 9001:2015 system, it is vital to keep an eye on the horizon. The International Organization for Standardization (ISO) is finalizing the next revision, ISO 9001:2026, scheduled for publication in September 2026. The good news? ISO 9001:2026 is an evolutionary refinement, not a revolutionary rewrite. The core harmonized structure and foundational requirements remain intact. However, the revision introduces key targeted enhancements that you can begin embedding into your interim maintenance routine today itself.

To that end the focus areas would be first the quality culture and ethics per ISO 9001:2026 clauses 5 & 7. Second group head if I may call it that, would be climate and context considerations per clauses 4.1 and the risk clarification and objectives as per clause 6.1.

Explicit focus on quality culture and ethical behavior (clauses 5.1 & 7.3) is a slight change in that the 2026 revision elevates Quality Culture and Ethical Behavior from implicit assumptions to explicit leadership and awareness expectations. Top management will be expected to demonstrate how shared organizational values, ethical standards, and communication foster quality. Maintenance action would require evaluation of how the organization’s corporate values, ethics policies, and employee recognition programs intersect with quality outcomes.

Integration of climate change considerations (Clause 4.1) came up as a note tweak for the 2015 version. Now it is being formally integrated with the early 2024 climate change amendment (ISO 9001:2015/Amd. 1:2024). The 2026 standard explicitly requires organizations to assess whether climate change factors impact their business context and customer satisfaction. Maintenance action would require that during routine context reviews (Clause 4.1), evaluate whether climate-related factors (e.g., supply chain disruptions, energy transition, regulatory shifts) affect operational resilience.

Clearer distinction of risk vs. opportunity (Clause 6.1) was needed. OFI was not fully amplified in the 2015 version of the standard. The revised ISO 9001:2026 clause 6.1 provides clearer structure to ensure organizations do not treat risk mitigation and opportunity pursuit as the same exercise. Looking at the maintenance action, the organizations will have to ensure their risk matrix clearly separates risk mitigation actions from strategic growth opportunities.

Let us see what details matter for the organization’s transition planning. We know the standard 3-Year transition window following the publication of the new standard in September 2026, wherein the certified organizations will have a standard 3-year transition period (until approximately September 2029) to update their QMS. There is no need to wait or pause the current ISO 9001:2015. The certifications remain valid throughout the transition. Maintaining a strong ISO 9001:2015 baseline today will make your transition seamless during regular surveillance cycles in 2027 or 2028.

A summary health checklist to cover the period between-audits will ensure your system stays vibrant and audit-ready month after month, measure your progress against a quick operational checklist with key indicators of success such as for internal audits: a focus on process efficiency and value and not just tick-boxes. CA and risk appreciation should look at RCA to ensure zero stale/ overdue action items. About the management review ensure decisions are recorded and resources allocated based on QMS data. For the process and risk review ensure the risk-register is updated with operational changes that may have occurred. And finally for 2026 standard’s alignment ensure that ethical, cultural and climate context factors are monitored.

In conclusion I thin an ISO 9001 Quality Management System should be the steering wheel of your operations, not an extra luggage rack strapped to the roof. When top management embeds QMS activities into the routine tempo of business decisions, surveillance audits cease to be nerve-wracking exams. Instead, they become valuable third-party health checks that validate a culture of continual improvement keeping your organization strong today and effortlessly prepared for the 2026 standard tomorrow.

About the Author:

Inderjit (IJ) Arora, Ph.D., is the Chairman of QMII. He serves as a team leader for consulting, advising, auditing, and training regarding management systems. He has conducted many courses for the United States Coast Guard and is a popular speaker at several universities and forums on management systems. Arora is a Master Mariner who holds a Ph.D., a master’s degree, an MBA, and has a 35-year record of achievement in the military, mercantile marine, and civilian industry.