The ISO 9001 Audit Checklist, Explained

Last updated 24 August 2026.

An ISO 9001 audit checklist is a working list of everything the standard expects, turned into practical questions you can check your business against before a real audit. You go through it area by area, confirm you can show evidence for each point, and note anything missing so you can fix it in good time. Used properly it does one thing above all: it removes surprises, so that when an assessor looks at your system, you already know what they will find.

This page explains what the checklist covers, how to use one, and how to run your own internal audit with it. If you would rather not build a checklist from scratch, there is a ready-made one you can download, linked further down.

Why a checklist is the thing that calms the nerves

The fear before an audit is almost always the fear of the unknown, of being asked something you had not thought about and being caught short in front of a professional.

A checklist removes that, because it lets you ask yourself every question the auditor will ask, first, in private, with time to put things right. There is a world of difference between discovering a gap at your own kitchen table three weeks out and discovering it while an assessor waits for an answer. By the time of the real audit, nothing on it is new. That is the entire value of working through one honestly.

I built the actual audit machinery ISO Guidance uses, the checklists, the criteria, the forms, after years of running companies at director level. So the checklist you are being taught to use here is not academic. It is the same practical tool used to assess real systems, translated into something you can run yourself.

What an ISO 9001 audit checklist covers

A good checklist follows the structure of the standard, so nothing is missed. Here is each area as a set of practical things to verify, in plain terms.

Your business and its context

Check you can clearly state what your business does, who your customers and key parties are, what they need from you, and what your quality system covers. In practice: can you describe your scope in a sentence, and does it match what you actually do? An auditor will start here, so you should too.

Leadership

Check that whoever runs the business visibly stands behind the quality system. Is there a clear quality policy, does it fit how you really work, and would your team say leadership actually cares about doing the work properly? This is verified as much by talking to people as by reading documents, so a checklist prompts you to test it, not just file it.

Planning

Check you have thought about what could go wrong and what could go better, and that you have a few clear quality objectives you are actually working towards. Can you show that risks and opportunities were considered and acted on, rather than just listed once and forgotten? The checklist turns this from a vague idea into a yes or no you can answer.

Support

Check the work has what it needs: competent people, suitable equipment, current information, and records to prove it. Are people trained for what they do, is important information controlled so everyone uses the current version, and can you find the records when asked? This is one of the most common areas for easy gaps, which is exactly why it is on the list.

Operation

Check that the actual work is controlled from order to delivery. Are customer requirements confirmed before you commit, are suppliers and bought-in goods controlled, and when something does not meet requirements, is it caught and dealt with? This is the largest area, because it is the real work of the business, so a checklist keeps you honest about whether the controls you designed are actually being followed.

Performance evaluation

Check you are measuring whether the system works. Do you gather customer feedback, monitor how you are doing, carry out internal audits, and hold a management review where the evidence is actually looked at? This area is, in effect, the checklist checking that you check. It is where an auditor confirms the system is alive rather than dormant.

Improvement

Check that when things go wrong you fix the cause, not just the symptom, and that you can show the business getting better over time. Are corrective actions recorded and closed, and can you point to changes you made because the system told you to? This is the area that proves the whole thing is working as intended.

How to use an ISO 9001 internal audit checklist to audit yourself

An internal audit sounds formal, but for a small business it is simply you, or someone in the business, working through the checklist honestly and writing down what you find. Here is how to do it well.

Set aside the time and treat it seriously, because a rushed internal audit that finds nothing is worse than none at all. Go through each area of the checklist and, for every point, look for the actual evidence rather than assuming it exists. Talk to the people who do the work, not just the person who wrote the procedure, because the gap between the two is exactly what a real auditor probes. Write down what you find, both what is working and what is not. Where you find a gap, record it, decide what you will do, and follow it through to done.

One point that surprises people: finding problems in your internal audit is success, not failure. An internal audit that finds nothing tells an assessor you did not really look. Finding and fixing issues is the entire purpose, and it is what turns the real audit into a formality.

A checklist is a tool, not a trophy

It is tempting to treat the checklist as a one-off hurdle: fill it in, pass the audit, file it away. That wastes most of its value.

The same checklist run every few months is one of the simplest ways to keep your business running well between audits. It catches drift before it becomes a problem, keeps the system honest, and means every future audit is easy because you never let things slide. Live the checklist and it quietly improves the business. File it away and you are back to cramming before each audit, which is the very thing it was meant to end.

Get a ready-made checklist

You can build a checklist yourself from the areas above. Most people would rather start from one that is already complete and correctly structured.

Our internal audit checklist is ready to use, covering every requirement in the order an auditor works through them. Get the ready-made internal audit checklist and you can run your first internal audit this week.

And when your internal audits are clean and your system is running well, you can have it independently assessed and certified.

Frequently asked questions

What is an ISO 9001 audit checklist?

An ISO 9001 audit checklist is a structured list of the standard’s requirements turned into practical questions you check your business against. It follows the areas of the standard, from context and leadership through to operation, performance evaluation and improvement, and for each point it prompts you to confirm you have the evidence an auditor would want to see. It is used both to prepare for certification and to run regular internal audits that keep the system healthy between assessments.

What are the mandatory procedures for ISO 9001?

ISO 9001 does not mandate a fixed list of procedures, which surprises many people. Instead of naming specific procedures you must write, it requires that certain activities are controlled and certain records kept, and leaves the exact documents to you. In practice most businesses maintain documented information covering things like control of documents and records, internal audit, dealing with work that does not meet requirements, and corrective action, because these are the simplest way to show the requirements are met. The test is always whether the activity is controlled and evidenced, not whether a particular document exists.

What do auditors look for in an ISO 9001 audit?

Auditors look for evidence that your system is real and is being used, not just written down. They check that what your documents say actually happens, by examining records and talking to the people who do the work. They look for consistency between your policy, your procedures and your day-to-day practice, for evidence that you find and fix problems, and for signs that leadership genuinely supports the system. The single thing they are testing throughout is whether you do what you say you do and can show it.

How do you conduct an ISO 9001 internal audit?

You conduct an internal audit by working through a checklist of the standard’s requirements and honestly gathering evidence for each one. Plan which areas you are auditing, set aside proper time, then examine records and talk to the people doing the work rather than assuming the documented process is followed. Record what you find, both strengths and gaps, raise corrective actions for anything missing, and follow them through to completion. Finding issues is the goal, because fixing them before the external assessment is exactly what an internal audit is for.

How often are ISO 9001 audits required?

Internal audits should be carried out at planned intervals, which for most small businesses means at least once a year, and often more usefully every few months across different areas. External certification audits follow a three-year cycle: the initial certification assessment, a lighter surveillance audit in each of years one and two, and a fuller recertification at year three. The internal audits are yours to schedule; the external cycle is set by how certification works.

About the author

Written by Mike Armstrong, founder of ISO Guidance. Mike ran companies at director level before building management systems, so the systems ISO Guidance writes are built to work in the real world, not just on paper. ISO Guidance helps small and medium sized businesses get ISO certified without a consultant.