When Procedures Look Perfect but Performance Doesn’t: Auditing the Effectiveness of Process Design

In a quality management system, the way processes are designed reveals whether a system is built for execution or merely for compliance. Organizations often establish well-documented systems with structured procedures, templates, and controls, yet continue to struggle to meet operational objectives. The contradiction reflects a deeper issue where the presence of documentation creates an illusion of control, while actual performance tells a different story.

A system can appear complete, structured, and aligned with standards, but if outcomes remain inconsistent, delayed, or dependent on workarounds, the problem is not documentation. It is more of a process design issue. What makes this particularly dangerous is that organizations often interpret poor performance as an execution issue rather than a design failure.

Employees are retrained, monitored more closely, or reminded to “follow the procedure,” while the underlying process remains unchanged. Over time, this creates frustration at the operational level and reinforces a culture where compliance is expected but not realistically achievable. When procedures look perfect but performance continues to decline, the organization is not facing a compliance gap. It is facing a design problem that has been masked by documentation.

Why Well-Documented Processes Still Fail

Well-documented processes fail for reasons that are often overlooked because the focus remains on the quality of documentation rather than the practicality of execution.

One of the most common reasons is that procedures are overly theoretical. In many cases, procedures are written by external consultants or internal teams removed from day-to-day operations. The result is documentation that reflects how work should happen in an ideal environment, not how it actually happens under operational pressure. This is particularly evident in specialized industries such as maritime operations, where procedures written without real operational exposure fail to account for onboard realities.

When procedures are written without operational context, they tend to assume stable conditions, uninterrupted systems, and full resource availability. In reality, operations are rarely that controlled. Systems go down, deadlines compress, and competing priorities emerge. A procedure that cannot accommodate these conditions becomes irrelevant the moment pressure is introduced.

Another reason is the lack of operational practicality. A procedure may be technically correct but practically unworkable. For instance, requiring crewing managers to verify certifications exclusively through a Flag State portal may appear compliant, but if that portal is unavailable due to maintenance, the process becomes ineffective. In such cases, employees are forced to choose between compliance and continuity, and continuity usually wins.

These situations reveal an important truth. Employees do not deliberately ignore procedures. They adapt to keep operations moving. When adaptation becomes routine, it signals that the process design is not aligned with operational reality.

Process complexity further compounds the problem. When procedures involve excessive steps, multiple approvals, or unclear pathways, they increase the likelihood of deviation. Employees do not reject processes because they are unwilling to comply. They bypass them because the process does not support the reality of their work.

Complexity also introduces variability. The more steps and dependencies a process has, the more opportunities there are for inconsistency. Over time, different employees develop different ways of navigating the same process, leading to uneven outcomes and loss of standardization. What emerges from these conditions is not failure of individuals, but failure of design.

Procedure Quality vs Process Effectiveness

A critical distinction must be made between procedure quality and process effectiveness.

Procedure quality reflects how well a document is written. It includes clarity, structure, completeness, and compliance with documentation requirements such as approvals and version control. It answers the question of whether the procedure meets formal expectations.

Process effectiveness, on the other hand, reflects how well the process performs in practice. It is measured through outcomes such as timeliness, accuracy, consistency, and the ability to meet operational objectives. It answers the question of whether the process works. Organizations often confuse the two.

A procedure may be clear, approved, and properly controlled, yet the process it describes may still fail to deliver consistent results. When outputs are delayed, inconsistent, or dependent on informal adjustments, the issue is not documentation quality. It is process effectiveness.

This confusion is reinforced by audit preparation practices that prioritize documentation review over performance analysis. Organizations invest time ensuring procedures are complete and controlled but spend far less time examining whether those procedures consistently produce the intended results.

A mature audit evaluates both. It does not stop at confirming that procedures exist or are well written. It examines whether those procedures translate into reliable and repeatable outcomes. When there is a gap between documented intent and operational performance, the conclusion is unavoidable. The process design is flawed.

At this point, accountability must shift. It is no longer sufficient to expect employees to comply. Leadership must question whether the system they designed can realistically be executed.

How Auditors Evaluate Process Design

Auditors do not rely solely on documentation to assess process design. They use practical techniques to understand how processes function in real conditions.

One such method is the process walkthrough. The auditor follows a single transaction, such as a claim or a seafarer’s file, from initiation to completion. This allows the auditor to observe where delays occur, where controls are bypassed, and where dependencies create bottlenecks. It reveals whether the process operates as designed or whether it relies on informal adjustments.

Process walkthroughs are particularly revealing because they expose the difference between prescribed flow and actual flow. Where the procedure shows a linear sequence, the walkthrough often reveals loops, delays, and decision points that were never formally defined.

Employee interviews provide another layer of insight. Instead of asking whether procedures are followed, experienced auditors ask where the process becomes difficult. Questions such as “Which part of this procedure is hardest to implement?” expose areas where design does not align with operational reality. Employees tend to reveal process weaknesses not through noncompliance, but through the challenges they face in execution.

These conversations often uncover informal practices that have become normalized. Employees may describe alternative steps, shortcuts, or workarounds without recognizing that these indicate systemic issues. For an auditor, these are not minor deviations. They are indicators of design failure.

Output evaluation is equally important. Auditors examine whether the results of a process are consistent and reliable. Patterns of rework, delays, or nonconforming outputs indicate that the process is not functioning effectively, regardless of how well it is documented.

Through these methods, auditors are not testing compliance alone. They are testing whether the process design can withstand real-world conditions.

Common Process Design Problems

Certain design problems appear consistently across organizations, regardless of industry.

Excessive approval layers are a common issue. When simple decisions require multiple levels of authorization, the process slows down, increasing the likelihood of delays and noncompliance. In an insurance claims environment, requiring multiple signatures for low-value claims may appear as a control, but in practice, it creates bottlenecks that undermine performance and regulatory expectations.

What begins as a control often becomes a constraint. Instead of reducing risk, excessive approvals redistribute it by introducing delays, frustration, and eventual bypassing of controls.

Unclear ownership is another recurring problem. When responsibilities are not clearly defined, tasks become shared in theory but neglected in practice. In a crewing department, if certificate verification is described as a shared responsibility, it often results in no one taking full accountability.

Lack of ownership also weakens accountability mechanisms. When outcomes are poor, there is no clear point of responsibility, making corrective action superficial and ineffective.

Disconnected processes across departments further weaken system design. When different teams interpret or apply procedures differently, the system loses consistency. What appears as a single process on paper becomes fragmented in execution.

Unrealistic controls also contribute to failure. Requiring physical signatures in environments where they are not feasible, such as vessels at sea, demonstrates a disconnect between control design and operational context.

These problems are rarely isolated. They interact and reinforce each other, creating systems that are increasingly difficult to execute and even harder to improve.

The impact of these problems is cumulative. They do not just slow processes down. They force employees to create workarounds, and those workarounds gradually become the real system.

Improving Process Design Instead of Adding Procedures

Effective improvement requires a different approach. Instead of increasing documentation, organizations need to simplify processes. Simplification does not mean removing controls. It means aligning processes with how work actually happens, reducing unnecessary steps, and ensuring that controls are practical.

Simplification requires discipline. It involves questioning existing steps, eliminating redundant approvals, and redesigning workflows based on actual usage rather than historical assumptions.

Aligning procedures with workflows is equally critical. Procedures should reflect real operational sequences, not theoretical models. When documentation mirrors actual workflows, compliance becomes a natural outcome rather than an enforced requirement.

Clarifying accountability is another essential step. Each process should have clearly defined ownership, ensuring that responsibilities are understood and executed consistently.

Improvement also requires feedback loops. Organizations must create mechanisms for employees to report process difficulties without resistance. Without this feedback, process design remains disconnected from operational reality.

Improving process design requires organizations to shift focus from documenting intent to enabling execution. When processes are designed with execution in mind, documentation becomes a reflection of reality rather than an aspiration.

Conclusion: Effective Systems Are Designed for Execution

In quality management systems, the effectiveness of a process is not determined by how well it is documented, but by how reliably it performs. Procedures that cannot be executed under real conditions do not strengthen a system. They weaken it by creating gaps between expectation and reality.

An effective system is one where processes are designed to function under pressure, adapt to constraints, and deliver consistent outcomes. Documentation supports this, but it does not replace it. The real test of a system is not whether it can pass an audit, but whether it can sustain performance without constant intervention. Systems that depend on effort rather than design will always struggle.

Ultimately, systems are not tested by how they look during an audit. They are tested by how they perform when conditions are less than ideal.

About the Author:

Liyuwork (Liyu) Shiferaw is a Compliance Officer with QMII with expertise in maritime law and regulatory systems. She is a former maritime director and has supported international maritime administration improvements, including IMO missions in Africa. Her experience spans safety, labor, environmental protection, audits, and management systems. She holds advanced maritime law credentials and international fellowships

Can the PBMS Approach Prepare the Mercantile Marine for Conflict Zones?

This conflict in the middle east and economic and human loss in the Straits of Hormuz has brought the merchant mariner in focus. The mercantile marine since times gone has played such an important role. These are sailors sailing the oceans, perhaps for their livelihood, perhaps for adventure and many such reasons, however this is certain the Columbuses, and the likes of Captain Cook changed the world. Affected the economies. In dangerous times like sailing through a war zone to meet the basic needs of the world, brings challenges. We realize this with the Iran war as we see merchant ships, tankers, bulk carriers, container vessels and the rest in the war zone. Without them the global supply chain stops. Yet how safe are they. Does the world owe them safety, security. Can they themselves as mariner, Masters and ship owners exercise some due diligence?

 For me personally as an ex sea farer who commanded submarines in the  Indian navy and then sailed as a merchant mariner in the mercantile marine as Master and now as a SME (subject matter expert) in maritime safety, security and related issues I felt compelled this morning to see if I could analyze what I hear, read and provide a  mantra whereby maritime industry could better prepare themselves. Does the ISM Code and STCW convention and ISO 9001 with the process-based management system approach as primary standards be used to plan better.

Most of us do not have to deal with such life-and-death decisions as whether to risk transiting the Strait of Hormuz. However, for those who must traverse these waters, are there guidelines they can use.  The ISM Code can provide some lessons into anticipating the unexpected and planning for these risks in a systematic manner. In this article I touch how portions of the Code might connect to elements of ISO 9001 and provide inputs that might be useful to maritime leadership in ensuring quality assurance and conformity assessment based on risk and in the context of the organization.

Let me start with the sinking of the IRIS Dena. I start with this recent incident to convey that warships or mercantile marine, the maritime environment can be best prepared for fast developing circumstances by keeping the process-based management system (PBMS) approach as the basis for all planning. On 4 March 2026, the Iranian Navy frigate IRIS Dena was torpedoed and sunk by a U.S. Navy submarine in the Indian Ocean near the southern coast of Sri Lanka. The vessel sank within minutes after being struck, leaving at least 87 sailors dead and dozens missing, while 32 survivors were rescued by the Sri Lankan Navy. The attack was particularly notable for naval historians. It was reportedly the first time since the second world war that a U.S. submarine had sunk an enemy surface warship with a torpedo[1].

What makes the incident significant for our discussion is not the geopolitics, but the reminder of how quickly circumstances can change at sea. The Dena had recently taken part in multinational naval exercises hosted by India and was sailing in international waters near Sri Lanka when the strike occurred. For professional mariners, the lesson is familiar, conditions that appear routine can change without warning. The ISM Code is not applicable to navy, but is there a harm in understanding the principles? After all this is precisely why the ISM Code emphasizes preparedness for emergencies and abnormal situations.

Clause 8.1 of the ISM Code requires that the company should establish procedures to identify, describe and respond to potential emergency shipboard situations. The Navies have their own doctrine. Yes, one wonders if risks are systematically appreciated can better decisions be made. In other words, the Code requires organizations to plan not only for technical failures or weather hazards, but also for security risks and unexpected external threats. Sure, a navy may call it an operational assessment, or by any name. Yet (in Shakespearean language) a risk would remain a risk if called by another name. ISO 9001 expresses a comparable idea through the requirement for risk-based thinking. The organization shall determine the risks and opportunities that need to be addressed to give assurance that the quality management system can achieve its intended results as emphasized in ISO 9001:2015, Clause 6.1.1.

From a management systems perspective, the broader lesson is clear. Organizations must plan for situations that may appear unlikely until they occur. For a ship’s captain, that planning may involve security drills, contingency routing, and coordination with naval authorities. For a quality manager or organizational leader, it may involve supply chain disruption, cybersecurity incidents, or geopolitical shocks. Finally, the decision on sailing should be based on the risk assessment. Events at sea sometimes remind us, in stark terms, why disciplined safety and command systems matter. What makes the incident significant for our discussion is not the geopolitics, but the reminder of how quickly circumstances can change at sea as they did for Dena.  

For professional mariners, the lesson is similar and familiar. Conditions that appear routine can change without warning. The context of the organization (ISO 9001 clause 4.1 & 4.2) leading to risk appreciation clause 6.1, must be an integral part of the maritime management system, at sea or ashore. This is precisely why the ISM Code emphasizes preparedness for emergencies and abnormal situations. The company should establish procedures to identify, describe and respond to potential emergency shipboard situations per ISM Code, Section 8.1. From a management systems perspective, the broader lesson is clear. Organizations must plan for situations that may appear unlikely until they occur. Good organizations connect real maritime events with risk-based thinking, understand that commercial interests apart they must see why emergency planning clauses in ISM are not theoretical and are reinforced by ISO 9001 Clause 6 (Planning) and clause 8 (Operational control).

 My own appreciation for disciplined systems thinking was shaped long before the ISM Code was widely implemented in commercial shipping. During my years in the Indian Navy, I had the privilege of commanding submarines, first F-class boats and later service on a Charlie II submarine. Submarines operate in an environment where uncertainty is not theoretical. The margin for error is extremely small. A failure in equipment, communication, or procedure can quickly become critical. What keeps submarines safe is not individual brilliance on the part of a captain or crew. That too, but most importantly the relentless adherence to procedures and constant preparation for contingencies. Before every patrol, the crew rehearses emergency actions repeatedly as flooding drills, fire drills, loss of propulsion, loss of power. Each crew member knows precisely where to go, what valve to operate, and what sequence of actions must follow. These procedures are not simply written manuals. They are practiced until they become instinctive.

At the time, we did not describe this discipline in terms of “process-based management systems,” but that is exactly what it was. The system existed to ensure that when the unexpected occurred, as it inevitably does at sea. The crew would not rely on improvisation alone. The response would already be embedded in the system. Years later, when I sailed as Master in the merchant marine and later worked with ISO management systems, I recognized the same principle expressed in a different language. ISO 9001 requires organizations to establish, implement and maintain the processes needed for the quality management system and their interactions. Refer ISO 9001 clause 4.4. The ISM Code similarly requires companies to ensure safe practices in ship operation and a safe working environment (ISM Code, clause 1.2). Different industries. Different terminology. But the underlying idea is identical. Safety, quality, and reliability are not the result of reacting well to emergencies.

These thoughts are the result of preparing for them long before they occur. I can confirm with my experience that this reflection is not merely theoretical. It comes from my first-hand experience wherein I  led teams where preparation truly mattered. My background, commanding submarines and later sailing as Master in the merchant marine gives me a clear perspective on risk, command responsibility, and disciplined procedures under uncertainty. This perspective can make a very compelling bridge between maritime safety management (ISM/STCW) and organizational quality systems (ISO 9001).

The connection as we look at the dangerous situations at sea particularly in the Hormuz Staits is to see what the ISM Code and ISO 9001 (as also other maritime and ISO standards) can teach maritime leaders about risk in uncertain times. In today’s volatile world, commercial shipping once again finds itself navigating geopolitical tension. News headlines remind us that vessels may need to transit waters such as the Red Sea or the Strait of Hormuz where the risks are not merely commercial, but they can become matters of safety and survival. For those who have spent a career at sea, such circumstances are not entirely unfamiliar. The maritime profession has long recognized that uncertainty is inherent to operations. Ships sail through storms, equipment failures, and occasionally conflict zones. Yet despite these uncertainties, shipping remains one of the safest and most reliable global industries. This is not an accident. Much of that safety culture comes from the International Safety Management (ISM) Code, supported by training standards such as the STCW Convention. These frameworks provide structured guidance on how organizations anticipate risk, prepare crews, and maintain operational control.

Most professionals in quality assurance or conformity assessment will never face the life-and-death decisions that a ship’s master may face when deciding whether to transit a dangerous waterway. However, the principles embedded in the ISM Code offer valuable lessons for organizations operating in any uncertain environment. Many of these principles also resonate strongly with ISO 9001, the international standard for quality management systems. Let us examine a few of those connections.

The ISM Code brings a framework for safety through systematic management. The ISM Code was introduced by the International Maritime Organization (IMO) after several major maritime accidents revealed a common problem: the failures were rarely technical alone. They were failures of management systems. The Code therefore established a simple but powerful requirement, wherein shipping companies must implement a documented Safety Management System (SMS) to ensure safe operation of ships and protection of the environment. This requirement may sound familiar to anyone working with ISO management systems. Like ISO 9001 and other standards in the harmonized structure (HS). The ISM Code is not a technical manual for operating ships. Instead, it requires organizations to establish structured processes addressing, leadership responsibility, risk assessment, operational control, training and competence, incident reporting and corrective action and Continual improvement. In essence, the Code recognizes a fundamental truth in that safe operations are the result of disciplined management systems, not individual heroics.

The use of the SMS based on the ISM code and principles of ISO 9001 ensures planning for the unexpected. One of the most relevant principles in the ISM Code is the requirement to identify potential emergency situations and establish procedures to respond to them. Ships are required to plan for events such as fire, collision, grounding, machinery failure, man overboard and or security threats or piracy (maritime security is covered by the ISPS Code and ISO 28001). These procedures are not theoretical. Crews regularly conduct drills so that when an emergency occurs, the response is not improvised. In essence, the Code recognizes a fundamental truth that the safe operations are the result of disciplined management systems, not individual heroics.

Planning for the unexpected is one of the most relevant principles in the ISM Code. There is the requirement to identify potential emergency situations and establish procedures to respond to them. Crews regularly conduct drills so that when an emergency occurs, the response is not improvised. Organizations often interpret risk narrowly, focusing only on operational or financial risks. The ISM Code reminds us that effective management systems anticipate the unexpected and low-probability events that can disrupt operations. In quality management terms, this is the discipline of asking what could go wrong, how prepared are we, do people know their roles if it does?

Leadership and responsibility are important in maritime life. Another core principle of the ISM Code is clear authority and responsibility. ISM Code clause 5.1 and 5.2 seen with ISO 9001 Clause 5.1 and 5.3, require that on board a ship, there is no ambiguity about who is responsible for the safety of the vessel. The Master has the overriding authority. At the same time, the Code requires the company ashore to support the Master through a defined role known as the Designated Person Ashore (DPA) clause 4 of the ISM code. This individual provides a direct link between shipboard operations and top management. This structure reflects two key leadership principles, authority must match responsibility and top management must remain connected to operational realities. ISO 9001 expresses the same idea in a different context. Leadership is required to ensure that the quality management system is integrated into the organization’s processes and that responsibilities and authorities are clearly assigned. Without this alignment, procedures quickly become paperwork rather than operational guidance.

Competence and training in case of the mariners are systematized. The STCW Convention (Standards of Training, Certification and Watchkeeping) ensures that seafarers are properly trained and certified for their duties. But beyond certification, maritime safety culture emphasizes something equally important continuous drills and practice. Crew members rehearse emergency responses repeatedly. Fire drills, abandon ship drills, and damage control exercises are conducted not because emergencies are frequent, but precisely because they are rare and high consequence. This principle translates directly into quality management, competence is not merely about qualifications, it is about preparedness to perform under pressure. Organizations that rely solely on written procedures without practical rehearsal often discover gaps only when a crisis occurs.

Learning lessons from Incidents (ISO 9001 clause 7.1.6) is integral to the SMS, making it a critical requirement of the ISM Code requiring the reporting and investigation of non-conformities, accidents, and hazardous occurrences. The purpose is not blame, but learning. Each incident becomes an opportunity to ask, what failed in the system, what corrective action is needed, how do we prevent recurrence? Again, this is entirely consistent with ISO 9001’s approach to corrective action and continual improvement. The difference in the maritime world is that the consequences of failure can be immediate and severe. As a result, the discipline around incident learning is deeply embedded in the culture.

Risk decisions at sea and in maritime organizations need consideration about the decision a shipping company might face today whether to transit a high-risk region such as the Strait of Hormuz. The decision is rarely simple. It requires balancing safety risks, commercial pressures, regulatory requirements including daily changing statutory requirements of various contracting governments specially those controlling the war zone. This must be seen with the operational capability and the need to ensure crew welfare. The ISM Code does not dictate the decision. Instead, it ensures that the process for making the decision is structured and informed. This is perhaps the most valuable lesson for quality professionals. Management systems do not eliminate risk. They provide a framework for making better decisions about risk.

A war zone has much to be learnt from. Nevertheless, quality professionals can use their learning based on their use of the system approach by considering risks. For those working in quality assurance, auditing, or conformity assessment, the maritime experience offers several enduring lessons. Systems matter more than individuals and therefore, competent people are essential, but reliable operations depend on structured systems. Leadership must remain engaged in safety or quality, and this accountability cannot be delegated away from top management. The leaders must prepare for rare but high-impact events risk management is not only about what happens frequently.  Practice builds readiness. Training and drills ensure procedures work under real conditions. Therefore, the need to learn relentlessly from failure, use nonconformities as opportunities to strengthen the system. Management systems do not eliminate risk. They provide a framework for making better decisions about risk.

Navigating uncertainty strengthens the need to see what the ISM Code can teach leaders about risk and process management. These geopolitical tensions bring to maritime organizations the need to reassess risks faced by commercial shipping. Headlines remind us that vessels may transit waters such as the Red Sea or the Strait of Hormuz under heightened threat conditions. For ship owners and masters, such decisions require a complete and quick update of risks and other factors. For those who have spent a lifetime at sea, uncertainty is part of the profession. Mariners routinely navigate storms, mechanical failures, and complex navigational environments. Occasionally they must also consider security threats or conflict zones. Yet despite these uncertainties, global shipping remains remarkably reliable. Over 80 percent of world trade moves by sea, and the system functions with a level of safety and predictability that most industries take for granted.

These small but essential thoughts from the ISM Code are the philosophy to success in challenging times, “Every company should develop, implement and maintain a Safety Management System (SMS).”  Refer ISM Code, clause 1.4 and the definition of the SMS as a, structured and documented system enabling company personnel to effectively implement the company safety and environmental protection policy, as per ISM Code, clause 1.4. Both standards recognize that outcomes, whether safety or quality depend on well-defined processes and leadership oversight.

To the mariners in the straits or those intending to cross the war zone, relook at your management system. Strengthen it. Maritime leadership ashore should stay involved in assessing risks to give the best shot at safety.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

 

Clause vs. Capability: Why Mature Auditors Evaluate Organizational Capability, Not Just ISO Clauses

What really is the purpose of a management system (MS)? As its basic expectation, the organization would like to produce confirming products and services. Yes, it would like to see continual improvement and by the repeated use of the PDCA (plan, do, check, act) cycle reduce the waste, improve ROI (return on investment), have less product returns, less dissatisfied customers and growth in its product sale. Toward this end a management system is created. So that the wheel does not have to be reinvented the ISO standards provide the clauses to enable create that MS. Sounds all great, but the question is with time auditors settle down checking that requirements of clauses are met by seeking proof in terms of backup paperwork. The MS soon becomes audit driven and auditors who lack this maturity become slaves of the clauses. They lose the maturity to audit if the MS is actually meeting the objectives based on the policy. For example, let us say, as an auditor you are auditing a world-class manufacturing facility. You walk in, and everything is immaculate. The quality manual is a meticulously detailed work of art, referencing every relevant ISO standard. You randomly pull a procedure, and it’s perfectly aligned with the corresponding clause. You ask for competency records and a training record appears instantly. It seems perfect. But is this organization truly capable of achieving its objectives consistently and improving over time, is a question not asked.

For years, audits (especially for certification) have often been focused heavily on clause compliance. An auditor arrives with a checklist. “Does your procedure meet Clause 8.6?” Check. “Have you addressed 9.1.2?” Check. It’s a binary system, a binary “yes” or “no” for conformance. The auditors often don’t even make the effort to see if as per ISO 9001 clause 8.6 the release of the product was carried out correctly. How many product returns took place. While ensuring conformance to standards it is important, mature auditors are increasingly recognizing that this approach alone is insufficient. A perfect checklist can sometimes mask a struggling, fragile organization. This is where the distinction between auditing to a standard (clause-based) and auditing for performance (capability-based) becomes crucial. The forthcoming ISO 9001 revision expected in September 2026 is not changing the fundamental requirements but is now insisting on better functioning of the management system. The limits of clause-based auditing without proof of the system actually producing a confirming product and or service are now clear.

The standards are well thought of, and these ISO standards are valuable tools. They provide a structured framework of best practices. Auditing against them is necessary, particularly for demonstrating minimum adherence and achieving certification. However, a clause-based audit often provides a limited view:

  • By focusing only on documentation and not seeking proof of Implementation is a pitfall into which auditors fall. The organization might have a procedure (the “clause” says you need one), but is anyone actually using it? Is it effective? A compliant procedure that’s ignored yields zero real-world value.
  • Clause based auditing makes auditing easy for auditors. However, it does not systematically give continual improvement. It encourages a check-box mentality where organizations might view auditing solely as an exercise in getting through the checklist without focusing on why these processes exist and how they contribute to results.
  • This auditing to clauses gives a snapshot in time and misses out on resiliency. A compliance audit assesses the system “at the moment” of the audit. It doesn’t tell you if the organization can maintain that level of performance during periods of growth, stress, or market shifts.
  • The clause-based auditing can often inadvertently reinforce silos. Clause-by-clause auditing can strengthen a departmental focus rather than a process-oriented one. You might audit the QA department’s compliance perfectly, but how do they interact with Engineering? With Purchasing? Do the departments work together as teams to achieve the organizational policy?

This cluses-based auditing is particularly the drawback of the certifying bodies. They need the proof to each clause and so need those check lists as evidence of what they audited for giving a certificate. Organizations using ISO 19011 for internal auditing should be focused on the true performance of their management system. The clauses should not become the masters. The clauses are the servants of the organization which help it meet objectives in a systematic manner.  There is therefore a need for auditing to move toward capability assessment.

Mature auditors both internal and external (second and third party) recognize these limitations. They seek to understand not just if a standard is being met, but how capable the organization is of delivering value and achieving its strategic objectives. Assessing organizational capability involves a shift from asking, “Do you have a process for xxx?” to asking, “How effective is your capability for xxx?” This change in attitude is essential for auditors if the organizations are to use the audit inputs to drive their systems to conformity. A capability assessment looks beyond mere existence and focuses on factors like integration and context, the need to understanding the ‘why’.

Instead of just verifying that process descriptions exist (ISO 9001 clause 4.4), mature auditors ask how these processes are integrated to support the organization’s unique context (ISO 9001 clause 4.1) and the strategic direction. Does everyone in the organization understand how their role connects to the high-level goals and the external landscape? The need is to go from clause which asks show me your ‘context of the organization’ document to capability. Mature auditors would perhaps ask the process owner to walk the auditor through how the analysis of the business context directly influences organizations risk planning and, consequently, the operational processes.

There is need for future auditing to look at process effectiveness and performance. Just checking for the existence of monitoring and measurement (ISO 9001 clause 9.1) isn’t enough. A capability approach evaluates what is measured, how it’s analyzed, and most importantly, what action is taken. The maturity in an auditor needs him/ her to move from clause questions as do you have key performance Indicators (KPIs) per ISO 9001 clause 6.2 to seeking evidence by moving to questions and evidence indicating capability.  Ask the organization to show the auditor how these specific KPIs (which are linked to your objectives) have helped you identify a problem area, leading to an improvement that resulted in measurable cost savings/quality increase.

Mature auditors look to ISO 9001 clause 7.2 competence and clause 7.1.6 organizational knowledge and should instead of reviewing training records (clause 7.2) which would be compliance should instead be assessing capability which involves understanding if the staff actually have the competence to perform their tasks and if that knowledge is shared and retained by the organization (clause 7.1.6). Therefore, from clause attitude of asking show me the training records for your machine operators the auditors would move to assessing capability by interviewing an operator and asking, can you explain the why behind this step? What would happen if this critical process parameter was out of tolerance? How do you ensure this critical operating knowledge isn’t lost when someone retires or leaves?

Mature auditors would need to look at leadership and organizational culture with a fresh look. This is perhaps the biggest differentiator. Compliance can often be achieved with minimal leadership engagement. Assessing capability requires evaluating the commitment of top management (clause 5.1). Do they promote a culture of quality, safety, and continuous improvement? Is “management commitment” tangible and felt throughout the organization? Here moving from clause wherein auditors asked to see minutes of the last management review meeting need to move to the capability assessment by asking to be shown the evidence where leadership has allocated resources specifically to address an identified strategic risk, resulting in a quantifiable change to operational capability. Perhaps asking leadership to provide evidence of how they encourage and process employee suggestions for improvement?

For mature auditing this shift matters. Mature auditors are pushing these boundaries because it delivers far greater value to the organization being audited and to its stakeholders. This change will drive real-world improvement. Compliance-based audits can identify deficiencies, but capability assessments identify opportunities for significant performance gains, cost reduction, and quality enhancement. The need is to enhances Business Resilience. A capable organization can adapt and respond to change more effectively than a merely compliant one. Evaluating capability helps identify potential weaknesses that compliance-based audits might miss, making the organization more robust.

Moreover, mature auditing elevates the audit function. Instead of an auditor focused only on clauses being a cost center, an auditor who can assess and provide insights into organizational capability becomes a strategic partner to management, adding real value to the business. Greater stakeholder confidence is the desirable outcome. Customers, regulators, and investors are increasingly looking for more than a certification certificate. They want assurance that the organization is robust, reliable, and capable of delivering on its promises. A mature audit providing an assessment of capability provides this greater assurance. That then is the path forward. Making this shift isn’t simple. It requires auditors to have not only deep knowledge of the standards but also a high level of business acumen, system thinking, and strong interviewing skills. It also requires the auditee organization to be open to a more holistic, collaborative, and potentially challenging audit process. The rewards to the organization are a more effective, efficient, and resilient organization and are well worth the effort. By focusing on capability rather than just compliance, auditors can transform the audit process from a bureaucratic exercise into a vital driver of organizational excellence.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Auditing Undocumented Processes: How Mature Auditors Assess Effectiveness Without Paper

In today’s environment where mature organizations often operate effectively with minimal formal documentation, many auditors’ kind of give up and wonder how they can document such a system. With my background in command and leadership at sea, I naturally appreciate the difference between real operational discipline and paper discipline. Expanding on this thought and my experience here in QMII I thought about how mature auditors could assess effectiveness of a management system without paper through the lens of ISO 9001 specifically and generally for any ISO standard in the harmonized structure.

In many audits, the reflex question still appears early for auditors as “where is the procedure?” It is a fair question but not necessarily always the right one. ISO 9001 does not require organizations to document every process. In fact, the 2015 edition deliberately moved away from mandatory procedures and toward the broader concept of “documented information”. Information where the organization determines what is necessary for the effectiveness of its quality management system (Clause 7.5). That shift was intentional. ISO 9001 is not a documentation standard. It is a management system standard. And management systems operate, not on paper. So how does a mature auditor assess effectiveness when a process is largely undocumented? The answer lies in understanding what ISO 9001 requires and what leadership is expected to ensure.

So, the question is what ISO 9001 really demands. ISO 9001 consistently emphasizes:

  • Process approach (Clause 4.4)
  • Risk-based thinking (Clause 6.1)
  • Operational control (Clause 8)
  • Monitoring and measurement (Clause 9)
  • Leadership accountability (Clause 5)

Nowhere does the standard state that every process must be written down in procedural form. Instead, organizations must, determine the processes needed, establish criteria and methods to ensure effective operation and control, maintain documented information “to the extent necessary” and retain documented information as evidence of results.

The phrase “to the extent necessary” is critical. Necessary for what? For effectiveness. That is the auditor’s focus. Understanding of process vs. procedure is necessary. A process is not a document. A process is a set of interrelated activities that transforms inputs into outputs under controlled conditions. Whereas a procedure may describe the process, but it is not the process itself. Therefore, in mature organizations, processes often operate through, competent personnel, clear roles and accountability, embedded system controls and established culture as also measurable outcomes. The absence of a written procedure does not automatically indicate nonconformity. What matters is whether the process:

  • Is understood,
  • Is consistently applied,
  • Achieves intended results, and
  • Manages risk appropriately.

If those elements are present, ISO 9001 may already be satisfied. Therefore, auditing without paper requires the mature auditor to follow the process, not the binder. Clause 4.4 requires organizations to determine and manage their processes. The auditor therefore audits the process in action. Instead of asking only for a document, the auditor:

  • Traces a real transaction.
  • Observes workflow.
  • Identifies inputs and outputs.
  • Verifies how responsibilities are assigned.
  • Looks for criteria used in decision-making.

The process must be visible in execution even if not in narrative form. If the organization can clearly explain:

  • What triggers the process,
  • Who does what,
  • How decisions are made,
  • What controls exist,
  • How performance is evaluated, then the process is defined. Whether or not it is formally documented is not the question.

Auditors must evaluate operational control (Clause 8). Clause 8 requires organizations to implement production and service provision under controlled conditions. Controlled does not mean documented. It means:

  • Clear specifications.
  • Defined acceptance criteria.
  • Availability of suitable resources.
  • Competence of personnel.
  • Monitoring and measurement.
  • Prevention of unintended outputs

The auditor must therefore ask questions as:

  • What prevents errors?
  • What detects errors?
  • What corrects errors?
  • What prevents recurrence?

Good auditors remember that controls may be embedded in:

  • ERP systems (Enterprise Resource Planning).
  • Workflow approvals.
  • Segregation of duties.
  • Automated validations.
  • Management reviews.
  • Cultural norms.

If controls are real, effective, and consistently applied, the absence of a written procedure may not constitute a gap. Next the auditors looking at undocumented systems must assess risk-based thinking (Clause 6.1). Undocumented processes raise one critical question has the organization assessed the risk of not documenting this process? If a process is, high risk, regulatory-sensitive, complex, dependent on one individual and perhaps prone to variability, then documentation may be necessary to mitigate risk.

However, if a process is, stable, low risk, performed by competent, experienced personnel, supported by system controls and is producing consistent results, then extensive documentation may add little value. The mature auditor connects documentation requirements to risk, not tradition.

The auditors should verify performance (Clause 9). Ultimately, effectiveness is proven in results. The auditor examines, key performance indicators, nonconformity trends, customer feedback, on-time delivery, rework rates and internal audit results. The check stage of the PDCA (plan, do, check & act) cycle must be effective and strong. If performance is stable and improving, this is strong evidence of process control. However, if outcomes are inconsistent, documentation alone will not fix the problem, the leadership must address process discipline.

The Leadership Dimension in clause 5 of ISO 9001 is where undocumented processes intersect directly with leadership. Clause 5 requires top management to:

  • Ensure integration of QMS requirements into business processes.
  • Promote the process approach and risk-based thinking.
  • Ensure resources are available.
  • Communicate the importance of effective quality management.

In organizations operating with lean documentation, leadership maturity becomes the control mechanism. Strong leadership creates, clarity of roles, culture of accountability, shared understanding of expectations, visible engagement with performance and discipline in execution. In such environments, people know what to do, not because it is written, but because it is reinforced through example and oversight. However, weak leadership cannot hide behind undocumented processes. If knowledge resides in one person, if decisions are inconsistent, if performance varies widely, the issue is not missing paperwork. It is missing leadership. Documentation cannot compensate for the absence of direction.

Then auditors must be able to distinguish maturity from informality. The auditor must differentiate between, operational maturity and operational informality. Therefore, the signs of maturity include consistent explanations across employees, clear understanding of objectives, measurable outputs, embedded controls, low dependence on individuals and leadership visibility. At the same time, signs of weakness include:

  • “We just know how it’s done.”
  • Inconsistent answers to the same question.
  • Frequent firefighting.
  • No defined acceptance criteria.
  • Lack of performance data.
  • Heavy reliance on tribal knowledge.

That ISO 9001 requires controlled processes; not necessarily written procedures need understanding. The difference is critical.

Yes, there are occasions when documentation becomes necessary. Even mature organizations eventually require documentation when, scaling operations, expanding geographically, introducing remote teams, experiencing turnover, facing regulatory scrutiny and increasing complexity.

Documentation then becomes a leadership tool, not a compliance artifact. It preserves knowledge, reduces variability, supports training, protects against organizational memory loss. The auditor’s recommendation should therefore be risk-based, not, “You must document this because ISO requires it.” But “given the risk profile and growth plans, documenting this process would strengthen control.” That advice reflects maturity, both in auditing and in leadership.

The auditor’s responsibility in auditing undocumented processes demands more skill than auditing documented ones. Checklist auditing is easy. Process auditing requires, systems thinking, observational skill, strong interviewing abilities, understanding of risk, ability to interpret performance data and good professional judgment. When documentation is minimal, the auditor must work harder, not default to nonconformity. ISO 9001 was intentionally written to encourage organizational maturity, not bureaucratic expansion. The competent auditor respects that intent.

In concluding I would say plan auditing for confidence, not compliance. At QMII we teach auditors that ISO 9001 does not demand paperwork. It demands confidence in consistent performance. When processes are undocumented, the central question becomes, is the organization in control? We ask auditors to remember, if the process is understood, controls are embedded, risks are addressed, results are measured and if leadership is engaged, then effectiveness can be demonstrated even without a formal procedure. However, if these elements are missing, no amount of documentation will create discipline. In the end, auditing undocumented processes is not about paper. It is about leadership, risk, control, and results. And that is precisely what ISO 9001 intended.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

How to Audit Culture Without Turning It Into a Soft Conversation

Culture (noun): the set of shared attitudes, values, goals, and practices that characterizes an institution or organization

If you think culture is too “soft” to audit, you’re probably looking in the wrong places. Culture has always been integral to management systems. It is what your auditor instinct notices as you start reviewing system documentation and begin your opening meeting. It’s not tangible and yet it’s there slowly forming an image in your mind’s eye. When you conclude that the organization is committed to quality, safety or whatever standard you may be auditing against. 

Culture cannot be found in documented procedures, necessarily. Culture is in how personnel embrace the “What’s in it for me?” and contribute to the overall objective of the system. It’s where the vision is clearly shared and understood. It’s the way work is done. 

The undocumented and intangible cause auditors to push back on these topics. They question how it can be audited and perhaps rightly so. After all should an audit not be based on objective evidence without the introduction of feelings and opinions? Yes and not everything in a system is documented. For example the person’s knowledge of their process, of what constitutes a potential risk, and more.

In this article I address how auditors can assess the culture of an organization

Why Culture Matters to Management System Performance

Culture is what people do even when there is no oversight, when no one is looking. Culture shapes decisions long before procedures are referenced. It must be driven by leadership who must ‘walk the talk’. It’s in the silent messaging based on what leadership prioritizes. 

The organization may plaster the walls with quality and safety posters, but if the senior managers bypass safety and quality requirements to meet deadlines and commercial pressures then that is what everyone does. When objectives are not aligned with the vision of the organization it does not drive the right actions. Think about if you prioritize product quantity over quality. You may still get both however there may be a cost of added scrap. 

Culture drives people to take the right actions. The cornerstone of any good management system is the culture of the organization. The shared attitudes, values, goals, and practices. I said shared! It may be championed by one person but the load must be shared, if not equally then proportionately. 

The Mistake Auditors Make When “Auditing Culture”

Just like auditors and organizations think of customer surveys when assessing customer satisfaction, similarly auditors may think of employee surveys or opinions, when it comes to assessing an organization’s culture. However, culture is more than that. While there may be no documented procedure on it, It is in how well the forms have been completed and the procedure been followed.

Perhaps the biggest mistake auditors make when auditing culture is this: they ask people how they feel instead of examining how the system behaves.Culture is not a mood or a slogan. Culture is the pattern of decisions the organization consistently makes, even when under pressure. When vague questions are asked such as “How would you describe the culture here?” or “Do you feel empowered?” you will always get an answer. But is this answer the truth?

If raising issues in the past led to being labeled negative, empowerment will be described cautiously. If reporting risks slowed promotions, communication will be described as “generally good.” If audits have historically led to blame, then even the most open-ended question will be filtered through self-protection.

The real culture however shows up when production is behind, when a shipment is at risk, when a major client is on the phone, when a safety incident threatens reputation. In those moments, priorities become visible. Do not treat culture as separate from the management system. It is the management system that shapes culture.

Culture as a System Output, Not a Personality Trait

We sometimes perceive culture as a reflection of personalities. And maybe they do play a role in it. As a result when morale is low we may draw a conclusion that it must be a difficult manager. Perhaps when accountability is weak, it must be “those people.” But all this does is give us someone to praise or someone to blame. But culture is not a personality trait. 

What you experience as “culture” is the predictable result of how the management system is designed, reinforced, and lived. It is shaped by objectives, incentives, consequences, communication pathways, and leadership behavior over time. Systems condition behaviour over time.

If an organization consistently closes corrective actions late, perhaps objectives prioritize output over systemic improvement. Perhaps root cause analysis is seen as administrative work instead of strategic work. Perhaps management review does not meaningfully challenge overdue actions. If employees hesitate to escalate risk, that is not a lack of courage. It may be a system that historically punished disruption. If internal audits surface only minor issues year after year, that may not reflect perfection. It may reflect a system that subtly discourages surfacing uncomfortable truths.

Auditing culture, then, is not about assessing personalities. It is about examining whether the system is producing the behaviors leadership claims to value.In the end, culture is evidence. Not of who people are, but of what the system repeatedly produces.

Observable Evidence That Reflects Culture

Every organization has operational realities: nonconformities, customer complaints, missed targets, near misses. How organizations react to these is culture. When a problem surfaces, is the first question, “Who did this?” or “What allowed this?” That single distinction tells you whether the system leans toward blame or learning. 

Look at how objectives cascade from the policy (vision) of the organization. Do KPIs drive short-term output at the expense of long-term system health? Culture leaves fingerprints in escalation pathways, in how quickly risks are reported, in how leaders react when challenged.

Culture is reinforced by incentives, metrics, leadership behavior, and how the management system is actually used. The harmonized ISO structure was designed to drive alignment. Context shapes strategy. Leadership sets direction. Planning addresses risk. Performance evaluation feeds improvement. If those elements are functioning as an integrated system, culture stabilizes around accountability and learning. If they are fragmented, culture drifts toward silos and survival.

Questions Experienced Auditors Ask to Reveal Culture

What reveals culture are questions that trace cause and effect. Questions that explore decisions under pressure. Questions that connect behavior to consequences. Below are a few questions that auditors may consider in assessing culture:

  1. How do you decide which corrective actions deserve deeper root cause analysis and which are “quick fixes”?
  2. How are conflicting objectives resolved between production, quality, and safety?
  3. If I looked at your last five corrective actions, what patterns would I see?
  4. How are lessons learned from one department shared across others?
  5. What does “risk-based thinking” look like in day-to-day decisions here?
  6. If I asked frontline employees what leadership truly cares about, what would they say?
  7. When production is behind schedule, how do you ensure operational controls are still followed?
  8. How do you verify that outsourced or externally provided processes meet your requirements?

I hope the above will give you adequate insight into framing your own questions as you set to auditing to the various ISO 

Integrating Cultural Findings Into Audit Conclusions

Auditing culture does not require abandoning objectivity. The same discipline you apply to reviewing documented information, sampling records, and verifying implementation can be applied to observing patterns of behavior. Culture becomes visible when you connect what people say to what the system consistently produces. When you trace objectives to outcomes. It is evidence-based.

As auditors, we must resist the temptation to reduce culture to sentiment. Equally, we must resist ignoring it because it feels intangible. Culture links leadership to planning, planning to operations, operations to performance evaluation, and evaluation to improvement. If those links are weak, culture will fragment. If they are aligned, culture will reinforce the very outcomes the standard intends. Your audit conclusion should reflect this, not just the presence or absence of documentation.

In the end, auditing culture is about integrity of the system. Does the organization do what it says it values, especially under pressure? Are behaviors aligned with policy and objectives? When you can answer those questions with observable evidence, you audit culture without turning it into a soft conversation.

From Findings to Failure Prevention: How Advanced Organizations Link Nonconformities to System Design

Closing nonconformities does not prevent recurrence – it restores compliance temporarily.

In many organizations, nonconformities are viewed negatively, especially when identified during regulatory or customer audits. Audits are often perceived as tests to pass. Any finding feels like a deduction from a perfect score rather than a signal of system vulnerability.

This perception creates unintended consequences:

  • Findings become tied to performance metrics or bonuses
  • Root cause analysis turns into subtle blame
  • Quick fixes replace systemic improvement

When the cause is attributed to an individual, it provides emotional closure and an easy fix – retraining, reminders, revised SOPs. But these actions rarely address the deeper issue: the system allowed failure to occur.

High-performing organizations take a different view. They recognize that humans are fallible and design systems that anticipate error and make success easier than failure. Corrective action, therefore, is not about fixing people – it is about strengthening system design.

Why Most Corrective Actions Don’t Prevent Failure

One of the most common weaknesses in management systems is the confusion between correction and corrective action

  • Correction addresses the immediate issue.
  • Corrective action eliminates the cause to prevent recurrence.

Under pressure to close findings quickly, organizations often stop at correction. They implement:

  • Additional training
  • Updated procedures
  • Email reminders

These are administrative controls – the weakest level in the hierarchy of controls.

Another major weakness is poor problem definition. When the problem is vaguely described, the solution will inevitably be weak. Effective corrective action begins with clearly defining:

  • What failed
  • Where it failed
  • Under what conditions
  • How often it has occurred

Without clarity at this stage, prevention is unlikely.

Direct Cause vs. System Cause

When something goes wrong, advanced organizations ask two essential questions:

  • How did the system fail the individual?
  • Why did the system fail the individual?

Tools like the 5 Whys can help move beyond direct causes toward systemic causes.

Direct causes may include:

  • Missed inspection
  • Incorrect data entry
  • Procedure not followed

System causes often involve:

  • Inadequate communication pathways
  • Poor documentation design
  • Resource constraints
  • Conflicting priorities
  • Ineffective controls

It may feel excessive to redesign a system for what appears to be a small issue. However, small systemic weaknesses accumulate. Over time, they produce larger failures.

Organizations that consistently pursue systemic causes build stronger safety, quality, and compliance cultures.

How Advanced Organizations Analyze Nonconformities

Mature organizations approach nonconformities using structured methodologies and strong cultural foundations.

In high-performing systems:

  • Employees feel safe reporting issues
  • Findings are treated as early warning signals
  • Prevention is prioritized over closure speed

Within the hierarchy of controls, they evaluate whether they can:

  1. Eliminate the risk entirely
  2. Substitute or automate the activity
  3. Engineer safeguards into the process
  4. Strengthen administrative controls

They also examine:

  • Design weaknesses
  • Feedback loops
  • Resource adequacy
  • Process interactions

A practical and powerful technique is conducting a GEMBA walk. Observing work where it actually happens often reveals system constraints invisible in documented procedures.

Using Audit Findings as Design Input

Audit findings should be treated as design input – not simply compliance gaps.

A process audit helps determine:

  • The true extent of a problem
  • Whether similar vulnerabilities exist elsewhere
  • Weaknesses in process interaction

Experienced auditors create psychological safety. When personnel feel comfortable speaking openly, they often provide the most practical improvement ideas.

Audits should evaluate the suitability, adequacy, and effectiveness of the entire system – not just clause-by-clause conformity.

Linking Nonconformities to Management Review

In some organizations, personnel hesitate to report nonconformities out of concern for leadership exposure. This is a cultural red flag.

Management review should not merely confirm that corrective actions were “closed.” It should evaluate system health and emerging risks.

Leadership should be asking:

  • Are similar failures recurring across departments?
  • Are corrective actions overly focused on training?
  • Are people routinely working around broken processes?
  • Are resource constraints contributing to errors?
  • Are responsibilities unclear?
  • Is leadership unintentionally creating risk conditions?

When nonconformities are analyzed at the management level as indicators of system design strength, risk-based thinking becomes operational rather than theoretical.

The Auditor’s Role in Failure Prevention

Auditing is not about catching mistakes. When auditing becomes adversarial, fear enters the system. Fear suppresses reporting, learning, and improvement.

Strong auditors act as diagnosticians. They look beyond symptoms to identify structural vulnerabilities.

Their tone and questioning style shape culture. When auditors create psychological safety:

  • Employees speak up
  • Organizations learn
  • Systems improve

The goal of auditing is not to “pass.”
The goal is to build resilient systems that produce reliable outcomes even when people are tired, distracted, or under pressure.

Closing a nonconformity is administrative.
Preventing recurrence is strategic.

Mature organizations understand that findings are not blemishes. They are feedback. They are data. They are early warning signals.

That is the shift from compliance to resilience – and from findings to failure prevention.

AS9100 Revision Trends: What Aerospace Auditors Need to Know in 2026

Aerospace auditors are walking into 2026 with an unusual mix of certainty and ambiguity: certainty that the 9100-series will change, and ambiguity about how fast and how big the first wave will be. The International Aerospace Quality Group (IAQG) has been coordinating the next revision to align with the ISO 9001 update cycle, and industry communications increasingly describe a staged approach, with smaller, earlier adjustments followed by a more comprehensive alignment once ISO 9001’s revision is finalized.

QMII opines the practical question isn’t “What will the clause numbers be?” It is, what will organizations struggle to implement, what will certification bodies emphasize, and where will audit trails be weakest during transition? This article focuses on those revision trends—the direction of travel, so our clients, alumni and friends of QMII can sharpen their planning for changes in 2026 without waiting for every last editorial detail.

IAQG’s publicly shared planning materials describe a multi-year schedule that includes coordination drafts, dispositioning of comments, and balloting leading into publication aligned with ISO 9001’s release timing. In parallel, multiple industry briefings and consultants’ summaries describe two update tracks (a narrower-scope update followed by a larger revision tied closely to ISO 9001). ISO 9001 timing matters because it drives the backbone of the expected changes.

The ISO 9001 revision process reached a major milestone with the Draft International Standard (DIS) released on 27 August 2025, and several reputable sources project publication in late 2026 (often cited around September–October 2026 depending on the process steps).
That timing is important because AS9100 (and its next iteration being discussed in industry as “IA9100”) typically layers sector-specific requirements onto the ISO 9001 structure.

A consistent signal from ISO 9001 revision commentary is stronger emphasis on quality culture and ethical conduct, with leadership expected to do more than sign a policy statement. Even where the ISO changes are described as “editorial clarifications,” the interpretation by auditors and customers tends to be that culture and ethics must be demonstrated through governance and day-to-day decisions.

What this looks like in aerospace audits where organizations already operate under intense safety, airworthiness, and customer oversight is that “ethics” often shows up as:

  • escalation pathways for quality/safety concerns.
  • protections against retaliation.
  • independence of quality from production pressure.
  • decision records when delivery commitments conflict with conformity risk.

Therefore, the organizational emphasis and audit requirements for 2026 include and must consider:

  • Leadership interviews become evidence-seeking, not conversational. Ask for examples where leadership chose quality over schedule/cost and how that decision was communicated and verified.
  • Look for “quality culture instrumentation.” Are there measurable indicators beyond NCR counts (e.g., recurrence rates, escape metrics, employee reporting trends, first pass yield vs. risk hotspots)?
  • Test the management review inputs. Culture/ethics themes should show up as risks, objectives, corrective action effectiveness, and resource decisions and not just as a slide with no follow-through.

Supply chain resilience becomes a first-class audit theme and an organizational need for aerospace organizations. Even before formal revisions, the market reality is pushing standards interpretation toward resilience, second sourcing, supplier continuity, counterfeit avoidance, and rapid response to disruptions. ISO 9001 revision commentary increasingly calls out supply chain disruptions and resilience as a clearer focus area.

In AS9100 Rev D, many organizations already struggle with “supplier control” as an administrative exercise (scorecards, approvals) rather than a risk-driven system. And AS9100’s established focus areas as counterfeit parts prevention, product safety, and configuration management tend to intensify supply chain expectations. Changes for 2026 include:

  • Audit the supplier-control process as risk management. If a supplier is “high risk,” you should see enhanced controls: incoming verification strategy, escape mitigation, alternate routing, tighter change notification, and defined containment plans.
  • Trace a disruption scenario. Pick one realistic event (material shortage, special process capacity loss, cyber incident at a supplier) and ask, what is the organization’s playbook? Who triggers it? What evidence exists that it’s been tested?
  • Counterfeit prevention isn’t just training. Look for authenticated sourcing, traceability depth, suspect/unapproved parts handling, and supplier flow-down effectiveness (especially in distribution channels).

Risk-based thinking matures with this update and organizations as also auditors will be expected to distinguish “lists of risks” from risk-managed processes. AS9100 Rev D embedded risk-based thinking broadly, but many implementations still look like static risk registers that don’t change decisions. The direction of travel reinforced by ISO’s revision commentary is toward more explicit proactive risk management, including resilience and continuity. Therefore, the expected changes for 2026 include:

  • Follow risk into planning and controls. Pick a top operational risk and verify it changed something tangible: inspection plans, process capability targets, staffing plans, supplier strategy, buffer stocks, verification methods, or design reviews.
  • Verify risk competence. Who owns risk evaluation? Do they understand likelihood vs. detectability vs. severity? Are criteria consistent across functions?
  • Test the corrective action loop. When a failure occurs, do they update risk controls to prevent recurrence, or just close an 8D?

Human factors and “work environment” evidence becomes more specific. The changes look at aerospace quality failures which are often human-system failures, fatigue, confusing work instructions, poor tool control, inadequate lighting/layout, rushed handoffs. AS9100 Rev D already signaled movement in this direction by requiring consideration of human and physical factors when planning the work environment. The changes for 2026 now include:

  • Observe, then verify. Start on the floor. If you see error-likely conditions (visual clutter, ambiguous labeling, interrupted work, rework loops), then ask what the system does to prevent escapes.
  • Training effectiveness over training completion. Ask operators to demonstrate critical steps and show how competence is maintained when changes occur (new revision levels, tooling changes, new materials).
  • Shift handover is auditable. For critical processes, assess how information continuity is protected between shifts and between internal/supplier handoffs.

World is more and more into digitalization and data integrity becomes audit-critical, not “nice to have”. ISO revision discussions frequently highlight digital transformation and data-driven quality practices. In aerospace, that will collide with:

  • eQMS workflows.
  • digital inspection records.
  • automated test systems.
  • MES/ERP traceability.
  • remote collaboration across the supply chain.

Therefore, the changes for 2026 will trend toward:

  • Data integrity checks. Can the organization show controls for access, versioning, audit trails, backups, and cybersecurity-related risks for quality records?
  • Software-enabled processes. If an app enforces a step (e-signature, validation gate), test whether it can be bypassed, and whether exceptions are controlled and reviewed.
  • Analytics that drive decisions. If they claim, “we use dashboards,” audit one dashboard end-to-end, data source to transformation to interpretation to action and the result.

Climate and sustainability considerations creep into QMS context and risk. ISO 9001 gained climate change considerations via an amendment in 2024, and the 2026 revision discourse continues to treat climate as part of organizational context and risk. This doesn’t automatically mean “environmental management system” requirements but it does mean auditors may increasingly ask how climate-related disruptions affect:

  • continuity of operations.
  • supplier viability.
  • infrastructure risks.
  • regulatory/customer expectations.
  • product conformity risks (materials, storage, transport).

So, in 2026 changes the organizations consider:

  • Keeping it QMS-relevant. Organizations and the auditors are not just looking at ISO 14001 instead the focus is on how climate-related issues are captured in context, risks/opportunities, and planning.
  • Look for materiality. For a site in a storm-prone region, do contingency plans and infrastructure maintenance reflect that reality? For temperature-sensitive materials, are storage/transport controls robust?

Therefore, what aerospace organizations and the auditors should do differently in 2026 is:

  1. Treat transition readiness as an auditable system. Even before formal adoption dates, organizations will be working on readiness. Audit their change management discipline:
  • gap assessment method and assumptions.
  • controlled interpretation of drafts/briefings.
  • documented transition plan with owners and milestones.
  • internal communication and competence-building.
  • “No surprises” engagement with customers and certification bodies.

Just having a plan without governance, will not work. With the updated standard governance is emphasized.

  1. Increase the depth of process-based auditing. The more standards emphasize culture, resilience, and risk, the less value there is in document conformance audits. Go process-first:
  • pick a critical product line or program.
  • follow it from contract/design planning through purchasing, production, verification, shipment, and post-delivery feedback.
  • sample change events (engineering changes, supplier changes, escapes).
  1. Recalibrate “effectiveness” tests. The emerging expectations reward organizations that can show:
  • fewer escapes and less recurrence.
  • faster detection and containment.
  • decisions that reflect risk prioritization.
  • leadership actions that protect product safety and conformity under pressure.

A practical closing view on what will be hardest for organizations with the 2026 changes is that the most common weak points are likely to be:

  1. Culture/ethics presented as slogans rather than measurable behaviors and governance.
  2. Risk registers that don’t change controls, especially in supplier management and production planning.
  3. Resilience talked about abstractly, with no tested scenarios or defined triggers/ authorities.
  4. Digital records without strong integrity controls, especially across multiple systems and suppliers.
  5. Human factors addressed implicitly (“our operators are experienced”) rather than through designed error-proofing and competency evidence.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

AS9100 Revision to IA9100: The Changes to Clauses in the 2026 Version

Aerospace will see a change in 2026 when AS 9100 comes as the revised and renamed standard IA9100 in 2026.  The International Aerospace Quality Group (IAQG) has been coordinating the next revision to align with the ISO 9001 update cycle, and industry communications increasingly describe a staged approach.

The updated ISO 9001 version is expected to be published this year (2026), toward September–October. That timing is important because AS9100 updated as IA9100 is expected toward the same time. This is because IA 9100 will continue to be typically providing sector-specific requirements latched to the ISO 9001 structure. And a consistent signal from ISO 9001 revision commentary is stronger emphasis on quality culture and ethical conduct, with greater expectations from leadership and their involvement. Even where the ISO changes are described as editorial clarifications, the interpretation by organizations, auditors and customers tends to be that culture and ethics must be demonstrated through governance and day-to-day decisions.

Looking at the 2026 version some of the changes on a clause-by-clause basis that organizations, auditors can expect are toward effective implementation proved by actual actions and results:

  • 5.1 Leadership and commitment (especially how leadership drives culture and accountability).
  • 5.2 Policy (is it lived or framed?).
  • 9.3 Management review (outputs that change the system, not just minutes).

Supply chain resilience becomes a priority and a first-class audit theme. The ISO 9001 revision discourse also highlights supply chain disruption and resilience more directly. In aerospace, resilience is inseparable from product safety, counterfeit avoidance, special process control, and traceability. Therefore, what auditors should look for is, risk-tiered supplier controls that change inspection strategy, verification depth, and containment plans. Disruption playbooks, realistic scenario drills (material shortage, special process capacity collapse, cyber event at a supplier, geopolitical shipping impact). And the flow down effectiveness to see if customer/statutory requirements and key characteristics are properly transmitted and verified? These clauses are relevant:

  • 8.4 Control of externally provided processes, products and services (supplier selection, monitoring, re-evaluation).
  • 6.1 Actions to address risks and opportunities (supplier and continuity risks).
  • 8.1 Operational planning and control (contingency thinking in operational control).

Counterfeit part prevention stays central for organizations and auditors will probe end-to-end traceability. Counterfeit prevention is already explicit in AS9100 Rev D operational controls, including planning and control for prevention of counterfeit or suspect counterfeit part use. In practice, many systems still over-rely on training and “approved supplier” lists while leaving gaps in distribution channels and returns/repairs. The changes relate to what auditors should look for (beyond training records) are authenticated sourcing and purchasing controls, traceability depth sufficient for risk and part criticality. Also, controls for suspect parts (segregation, reporting, disposition, customer notification where needed) and receiving verification strategy linked to supplier risk and history. This would mean looking at these clauses:

  • 8.1 Operational planning and control (where counterfeit prevention is implemented in practice).
  • 8.4 Supplier control (distribution risk, broker controls).
  • 8.7 Control of nonconforming outputs (suspect parts containment and disposition).

The risk-based thinking matures in the revised standard and auditors must separate “risk lists” from risk-managed operations. A common failure mode today is a static risk register that doesn’t change controls. The ISO revision commentary continues to reinforce clearer expectations around risk, resilience, and communication of contingency-related topics. This would see risk changing the plan in terms of inspection, verification, staffing, supplier strategy, buffers, first-article strategy, special process oversight. Also, risk competence in terms of consistent criteria and decision rights. Corrective action feedback would be checked to see if major issues trigger updated controls and re-assessed risk? Therefore:

  • 6.1 Actions to address risks and opportunities.
  • 8.1 Operational planning and control.
  • 10.2 Nonconformity and corrective action.

For human factors and “work environment” evidence becomes more specific (and more observable). Aerospace escapes are frequently human-system failures. AS9100 already expects organizations to determine and manage the work environment, including human/physical factors. In a revision climate emphasizing culture and effectiveness organizations will be expected to implement reality and link it to control design. Auditors will be required to observe these and audit them. This would mean looking for error-likely conditions (interrupt-driven work, ambiguous WI’s (work instructions), rework loops, poor 5S/tooling discipline) and competence effectiveness (can the operator explain critical steps and acceptance criteria?) as also, shift handover integrity for critical operations. The clauses applicable would be:

  • 7.1.4 Environment for the operation of processes.
  • 7.2 Competence / 7.3 Awareness.
  • 8.5 Production and service provision (work instruction use, verification, tooling)

Another trend likely to be seen in IA9100 would be digitalization and data integrity becoming audit-critical, not “nice to have”. ISO 9001 revision commentary highlights digitalization and modern data-driven management. Aerospace auditors should therefore elevate scrutiny of digital records, e-signatures, MES/ERP traceability, (Manufacturing Execution System and ERP – Enterprise Resource Planning, traceability refers to the integrated digital record that tracks a part, from its raw material origin through every production step to final delivery) and automated test systems, and data transformations used for decision-making. Therefore, aerospace organizations should look for data integrity controls, access, versioning, audit trails, backups, retention and bypass risk to see can the required workflow steps be overridden without controlled authorization. Dashboard traceability to see from source system to transformation to metric  to decision to action and finally to the result:

  • 7.5 Documented information (control of digital records).
  • 9.1 Monitoring, measurement, analysis and evaluation (validity of metrics).
  • 8.1 / 8.5 Operational control (system-enforced steps, automated verification).

Aerospace auditors in 2026 would therefore see an audit approach that fits the revision trends to audit “transition readiness” as a controlled process. Even before formal adoption dates, many organizations may consider starting aligning language and practices to see if they have a controlled gap assessment method, a revision/transition plan with owners and milestones, controlled internal communications and competence updates and disciplined change control over procedures and process controls. The clause anchors for this are:

  • 3 Planning of changes.
  • 5 documented information.
  • 2 internal audit.
  • 3 management review.

For the go process-first organizations will follow each product and follow the risk. The auditors will check this by picking one high-impact product line or program and trace it from contract/design planning to purchasing leading to production then verification and release as also post-delivery feedback. Sample at least one change event (supplier change, drawing revision, special process change, escape). The relevant clauses to do this would be:

  • 4 process approach.
  • 1–8.7 operations.
  • 2 corrective action.

Elevation of effectiveness tests in 2026 would require audit conclusions to increasingly hinge on whether the system produces fewer escapes and less recurrence, faster detection and containment and pinpoints decisions that visibly reflect risk and culture commitments. Clause anchors for these would be,  9.1 performance evaluation and 10.2 improvement.

Based on the revisions expected in IA9100 2026 I could sum up for aerospace auditors a clause-based checklist (field-ready) with grounded evidence to perhaps be:

  • 5.1 / 9.3: Show me a leadership decision where quality/product safety won over schedule—what changed afterward?
  • 6.1 / 8.4: How do supplier risks change receiving inspection, verification, and contingency planning?
  • 8.1 / 8.7: Walk me through your counterfeit/suspect part prevention and containment from PO to disposition.
  • 7.1.4 / 7.2: What human-factor risks exist in this process, and what controls reduce error-likelihood?
  • 7.5 / 9.1: Prove this KPI: data source, transformations, access control, and how it drove action.

Summing up I would guess the hardest for organizations would be to consider the most common weak points they will likely see are:

  • Culture/ethics presented as statements, not governance and measurable behaviors.
  • Risk registers that don’t change controls, especially in supplier management and production planning.
  • Counterfeit prevention that’s not end-to-end, particularly in distribution and returns/repairs.
  • Digital records without strong integrity controls, especially across multiple systems.
  • Human factors handled informally, without designed controls and competence verification.

If auditors hold the line on evidence—governance, traceability, effectiveness—the transition to IA9100 can strengthen aerospace quality rather than just reshuffle terminology. IA9100 clause numbering and wording may evolve until formal publication. This article intentionally anchors to the stable ISO 9001 / AS9100 structure (Clauses 4–10) to remain usable throughout the transition.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

How to Audit Undocumented Processes: Practical Tools for Internal Auditors

Undocumented processes are ubiquitous. They emerge when people invent expedient workarounds, when systems lag behind evolving operations, or when tacit knowledge simply lives in employees’ heads. While these informal processes can be efficient, they also create risk: inconsistent outcomes, poor control, hidden single points of failure, compliance gaps, and difficulty demonstrating due diligence to auditors or regulators.

Auditing undocumented processes requires a different skill set than checking documented procedures: you must be a careful investigator, an evidence‑first interviewer, a data sleuth, and a pragmatic synthesizer who delivers usable outputs (not just findings).

This guide provides a practical, step‑by‑step toolkit and templates internal auditors can use to surface, assess and help formalize undocumented processes.

Clarify objective, scope and value

Start by defining why the audit is needed. Objectives might include assessing control effectiveness, verifying compliance, validating corrective action, identifying business continuity risks, or preparing the process for formalization. Limit scope to one process or a narrowly defined subprocess so you can dig deep rather than skim many shadows. Articulate the value for stakeholders up front-demonstrate you’re there to reduce risk, not to police personalities or on an inspection round.

Identify the de-facto owners and stakeholders

Undocumented processes usually have a “de facto” owner—someone who runs the work daily but may not appear on org charts. Use interviews with supervisors, system logs, or simple triangulation (“who signs off on X?”) to find them. Brief stakeholders on the purpose, scope and expected outcomes of the audit; getting buy‑in reduces defensive behavior and improves access to evidence.

Use structured discovery frameworks

Adopt a concise process discovery tool such as SIPOC (Suppliers, Inputs, Process, Outputs, Customers) or PIPS (People, Inputs, Process, Systems). These one‑page frameworks help quickly establish boundaries, expected outputs and interfaces even without formal procedures. Create an initial draft map during the kickoff meeting—doing this collaboratively both gathers knowledge and signals your methodical approach.

Evidencefirst interviewing

When interviewing staff, ask for artifacts, not assertions. Use these techniques:

“Show me” requests: ask to see the last 3–5 completed cases, tickets, orders, change requests or emails that represent normal workflow.

Scenario probing: “Walk me through how you handled ticket #123 last Wednesday from start to finish.”

Document chase: request logs, timestamps, approvals, system entries, reconciliation files and any physical evidence (tags, manifests). Avoid leading questions. Record factual timelines and capture exact phrases when people describe exceptions or informal rules.

Transaction tracing: purposive sampling and end‑to‑end follow

Select a purposive sample of recent transactions—choose items that are typical, borderline, and exceptional. For each, trace the lifecycle: initiation, validation, approvals, handoffs, controls, exceptions, completion, and post‑action reconciliation. Use a transaction tracing worksheet (fields: ID, date/time, initiator, systems used, handoffs, controls observed, evidence located, anomalies). Tracing multiple items uncovers patterns: recurring workarounds, undocumented checkpoints, or missing reconciliations.

Silent observation and shadowing

Observe work in situ-silent shadowing during normal operations reveals deviations and shortcuts that people may not report. Rotate observations across shifts and workload peaks to see variability. Use time‑motion notes to capture durations, handoffs and informal controls. Observation is powerful for processes with a physical element (warehouse picking, handover logs, machine operator routines) and for revealing tacit knowledge.

Data analytics and system interrogation

Systems often hold the documentary evidence even when procedures do not exist. Extract logs, check non conformity logs and check it’s trends especially those non conformities that have been repeating, transactions, user access records, change histories, reconciliation files, and exception reports.

Simple analytics-pivot tables, sequence checks, duplicate detection, out‑of‑hours activity flags, and time‑to‑completion distributions—can corroborate interview findings or surface anomalies you didn’t see on the floor. Where permitted, use filters to find outliers and then trace those back to the people and steps that produced them.

Identify implicit controls and grade effectiveness

Not every control is written. List implicit controls you discover (segregation via separate systems, verbal supervisory checks, reconciliations, dual entry by different roles). For each control, evaluate:

Existence: is it consistently applied?

Evidence: is there a recorded trail?

Owner: who is responsible?

Frequency: how often is it performed?

Effectiveness: does it detect/prevent the related risk? Use a simple scoring matrix (Effective / Partially Effective / Ineffective) tied to risk impact and likelihood.

Map risks to controls and prioritize findings

Translate process gaps into risk statements (fraud, error, data integrity, regulatory noncompliance, single‑point‑of‑failure). Prioritize findings by risk severity and exploitability. For critical risks require immediate mitigation (temporary controls, access restrictions, segregation of duties) and escalate to management if necessary.

Produce a validated onepage process map and Quick SOP

One of the highest‑value audit deliverables is a validated one‑page process map and a Quick SOP (3–8 steps). Draft these from your traces and observations, then review them with the de facto owner and SMEs in a validation meeting. The Quick SOP should include: purpose, scope, steps, responsible roles, key controls, evidence to retain, and critical timelines. This turns tribal knowledge into a usable artifact and accelerates formal documentation.

Report with practical, prioritized recommendations

Structure findings as: condition → criteria (what should be) → cause → effect/risk → recommendation → owner/timeframe. Prioritize quick wins (retain evidence, simple reconciliations, temporary segregation changes) and medium/long‑term fixes (formal SOPs, automation, redesign). Provide sample corrective actions and, where helpful, a template Quick SOP and transaction trace annexes so the process owner doesn’t start from scratch.

Ensure rootcause focus and verification

Insist on root‑cause analysis for any significant nonconformity and require corrective actions with measurable success criteria. Avoid administrative closures—verification should be evidence‑based (data, subsequent traces, or direct observation). Schedule focused follow‑up audits or data checks to confirm effectiveness.

  • Tools and templates (practical, lightweight)
  • Keep tools simple and shareable:
  • SIPOC/PIPS one‑page template
  • Transaction tracing worksheet
  • Observation/time‑motion log
  • Quick SOP template (purpose, steps, owner, controls, records)
  • Control effectiveness scoring matrix
  • Data extraction checklist with suggested flags (duplicates, out‑of‑hours, missing reconciliations)
  • Sample management reporting slide: heatmap of risks and status of actions
  • Cultural and ethical considerations

Approach audits as collaborative improvement, not blame. Undocumented processes often evolved to solve real operational problems; acknowledge this and highlight where formalization will reduce risk without adding unnecessary bureaucracy. Protect confidential and personal data when handling records; comply with privacy rules and get consent from data owners where required. Use unannounced checks judiciously to reduce rehearsed responses but balance with respect for staff.

From audit to durable change

Audits of undocumented processes should not stop at reporting. Drive transition from Quick SOPs to formalized procedures by linking findings to training, process redesign, automation projects, and management review. Measure success with KPIs tied to the process (exceptions per 100 transactions, time to complete, number of post‑transaction corrections) and track trends post‑implementation.

Conclusion

Auditing undocumented processes demands investigative rigor and practical empathy. By combining structured discovery (SIPOC), evidence‑first interviewing, transaction tracing, observation, data analytics and lightweight deliverables (one‑page maps and Quick SOPs), internal auditors can convert tribal knowledge into auditable controls, reduce risk, and add immediate operational value. The result is a process that’s safer, more consistent, and ready for formal quality, compliance or continuity governance.

Integrated Audit Strategies for ISO 9001, ISO 14001 & ISO 45001

I recently completed an integrated audit that addressed multiple standards (RC14001, ISO 9001, FSSC 22000, RSPO, and HALAL). Auditing this way is especially valuable for organizations that operate under more than one framework, because it helps reduce duplicated effort, save resources, and create better alignment across business goals, without making the management system feel like a burden to the people using it 

In a recent webinar, I discussed how to run a more effective management review, and why an integrated approach can give leadership the kind of insights and decision-ready information they actually value. In this article, I’ll build on that theme by sharing practical strategies for integrated audits and how organizations can use them to stay compliant, improve performance, and keep multiple standards working together as one system.

Why Organizations Integrate Management System Audits

Management systems are a great way to bring structure to how a business operates. Without that structure, it can often feel like the organization is constantly fighting multiple fires. A process-based approach helps bring order to the chaos by making it easier to understand the context the business operates in, set clear goals, identify risks, and put plans in place that can be implemented, monitored, and reviewed.

For many organizations, the push to implement multiple management systems is mainly market-driven. Customers, regulators, or industry schemes may require certification as a condition of doing business. A smaller number of companies adopt management systems simply because they recognize the value, even when certification isn’t required. The problem is that management systems are often implemented in a piecemeal way, as new requirements arise. For example, a company may already have ISO 9001 in place, then a new requirement for ISO 45001 comes along. Instead of integrating the new standard into the existing system, a separate ISO 45001 “system” gets built alongside it.

When integrated management systems are implemented well, the benefits are significant. They reduce duplication, improve alignment, and make the system easier for people to use. And when the system is easier to implement and maintain, it naturally improves buy-in and strengthens commitment across the organization.

Common Structures Across ISO 9001, 14001 & 45001

What makes the ISO standard easier to implement is the harmonized structure used by ISO in developing the standards. This approach starting in 2013 has made it easier to integrate owing to the similar unified clause structure. The standards now also follow the flow of the PDCA cycle with the standards laid out in the plan – implement – performance evaluation and improvement approach. 

The common clause structure allows for a better integrated manual without the need for a cross-reference matrix. Additionally organizations can now maintain a common risk register, conduct integrated audits, plan a common management review, have one policy (ensures no conflicts with other policies) and a common documentation approach. 

Planning an Integrated Audit Program

Planning an integrated audit program may at first seem challenging especially with finding resources that can audit to the multiple standards in one audit. Let us first look at the approach to a good audit program. 

A good audit program goes beyond meeting the minimum requirements. Often I come across organizations that do audits just once a year. The justification is that there is QC in place, site walk-throughs by safety, operational inspections and regulatory/customer audits. Organizations must keep in mind that the scope of each of these may be different from that of an internal audit. While it may appear that various inspections and audits are being performed, the lens through which the system is being looked at may be very different. 

For example in an inspection the focus is only on the output of a process and whether the output is conforming or not. In regulatory audits the focus is on regulatory requirements and compliance not necessarily on the process performance. Internal audits focus on process effectiveness and move beyond conformity. Based on the risks associated with a process the leadership must determine the interval at which they want to audit each process. 

For internal audits it is best to audit a few processes every month or every other month and then to conduct a system audit once a year.

Process-Based vs Clause-Based Integration

The ISO standards promote a process-based and risk-based approach to internal audits. While it may seem easier, or even more logical at first, to conduct a clause-based audit, it is often not very effective. The main reason is simple: it doesn’t paint the whole picture.

When we audit a process, we can assess conformity to multiple clauses at the same time, within the real flow of work. That is where integration becomes practical. There are a few situations where a clause-based approach may still make sense, such as when auditing leadership commitment to the system, or when reviewing how documented information is created, updated, and controlled across the organization.

A process-based approach allows the auditor to connect the dots between contextual risks, the planning done to address those risks, the controls and actions implemented, and the evaluation of effectiveness. Building on this, auditors can also assess how well the process is actually working in practice, not just whether the organization can point to a procedure that says it exists.

Risks of Poorly Integrated Audits

As stated at the start of this article, one of the biggest challenges in conducting integrated audits is having the internal resources who are competent across multiple standards. Many of our clients, especially those working with smaller budgets, find themselves trying to hire that one person who understands everything, and can audit everything. In reality, that’s a unicorn find.

Organizations generally have two options to address this.

The first is to outsource internal audits to an auditing organization or auditor who already has experience across multiple standards. In many cases, the provider will assign a team of auditors with the competence to cover the relevant requirements. Depending on the scope, this could be a team of two, or even four. Of course, the more auditors involved, the higher the cost.

The second option is to build internal capability by training the organization’s own audit team across the required standards. This does involve investment in the individuals selected, but it also creates long-term value. QMII typically recommends training a minimum of 10% of the workforce as internal auditors, up to a total of 10 auditors. This creates a strong pool to choose from and also supports more objective and impartial auditing.

QMII’s modular training approach helps organizations build audit capability quickly, without needing to put people through a full 4–5 day lead auditor course for every standard. Running an in-house auditor course can also create economies of scale and allows the training to be more customized to the organization’s own processes and risks.

Building Integrated Audit Capability

Integrated audits don’t fail because the standards are difficult. They fail because the organization does not have enough people who can confidently audit across the scope. The key to building integrated audit capability is to stop thinking of auditors as “ISO 9001 auditors” or “ISO 14001 auditors” or “ISO 45001 auditors” and start developing auditors who understand process performance, risk-based thinking, and system effectiveness. Once that foundation is strong, adding additional standards becomes far easier.

The goal is not to create a team of “super auditors.” The goal is to build a pool of competent internal auditors who can look at a process and understand how it supports quality outcomes, environmental controls, and worker safety all at the same time. When an organization can do that, integrated auditing becomes practical, consistent, and sustainable.

A good way to start is by building capability around the process approach. This means training auditors to follow the workflow, understand inputs and outputs, ask the right questions, and confirm that controls are working as intended. In many organizations, this is where the biggest value is gained, because audit conversations move beyond “show me a procedure” and into “show me how the process is managed.” This is exactly where QMII adds value. Our training is designed to build real audit skill, not just theoretical knowledge of clauses. 

Ultimately, when audit capability is built the right way, integrated audits stop being a burden and start becoming a value adding tool. They provide leadership with better insight, stronger confidence in controls, and a clearer view of where the system needs to improve before problems grow into incidents, complaints, or nonconformities.