Skip to content

Evidence request lists

ISO 30401

Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Audit

ISO30401-9.2
Internal audit

Conduct internal audits of the KMS at planned intervals.

Artefacts an auditor will ask for
  • Audit programme
  • Reports
  • CAPA
Where this commonly fails
  • Auditors not independent

Awareness

ISO30401-7.3
Awareness

Ensure persons under control are aware of the KM policy and their contribution.

Artefacts an auditor will ask for
  • Awareness campaigns
  • Intranet content
  • Quiz results
Where this commonly fails
  • Awareness limited to launch

CAPA

ISO30401-10.1
Nonconformity and corrective action

React to nonconformities, evaluate causes, and take corrective action.

Artefacts an auditor will ask for
  • NCR register
  • RCA reports
  • Effectiveness checks
Where this commonly fails
  • Recurring NCRs

Communication

ISO30401-7.4
Communication

Determine internal and external communications relevant to the KMS.

Artefacts an auditor will ask for
  • Comms plan
  • Channels list
  • Feedback log
Where this commonly fails
  • One way communication only

Competence

ISO30401-7.2
Competence

Ensure persons doing KM work are competent through education, training, or experience.

Artefacts an auditor will ask for
  • Competence matrix
  • Training records
  • Certifications
Where this commonly fails
  • No KM competencies defined

Context

ISO30401-4.1
Understanding organisation and context

Determine internal and external issues relevant to the knowledge management system.

Artefacts an auditor will ask for
  • PESTLE analysis
  • SWOT
  • Stakeholder map
Where this commonly fails
  • Context not refreshed
  • No link to strategy

Culture

ISO30401-4.8
Knowledge management culture

Cultivate a culture that values learning, sharing, collaboration, and innovation.

Artefacts an auditor will ask for
  • Values statement
  • Recognition program
  • Engagement scores
Where this commonly fails
  • No recognition for sharing

Documentation

ISO30401-7.5
Documented information

Create, control, and retain documented information for the KMS.

Artefacts an auditor will ask for
  • Document control SOP
  • Version log
  • Retention schedule
Where this commonly fails
  • Versioning not enforced

Enablers

ISO30401-4.7
Knowledge enablers

Address human capital, processes, technology, governance, and KM culture as enablers.

Artefacts an auditor will ask for
  • Enabler matrix
  • Culture survey
  • Tech inventory
Where this commonly fails
  • Technology heavy, culture light

Governance

ISO30401-9.3
Management review

Top management reviews the KMS for suitability, adequacy, and effectiveness.

Artefacts an auditor will ask for
  • Review minutes
  • Input pack
  • Action log
Where this commonly fails
  • Review tokenistic

ISO 30401: Improvement

ISO30401-16
Continual improvement methodology

Continual improvement methodology. Control from ISO 30401 framework, domain: ISO 30401: Improvement.

Artefacts an auditor will ask for
  • Continual improvement plan
  • Corrective action register
  • Innovation pipeline
  • Change management plan
Where this commonly fails
  • Improvement not data-driven
  • Corrective actions reactive
  • Innovation pipeline empty
ISO30401-17
Corrective and preventive actions

Corrective and preventive actions. Control from ISO 30401 framework, domain: ISO 30401: Improvement.

Artefacts an auditor will ask for
  • Continual improvement plan
  • Corrective action register
  • Innovation pipeline
  • Change management plan
Where this commonly fails
  • Improvement not data-driven
  • Corrective actions reactive
  • Innovation pipeline empty
ISO30401-18
Innovation and change management

Innovation and change management. Control from ISO 30401 framework, domain: ISO 30401: Improvement.

Artefacts an auditor will ask for
  • Continual improvement plan
  • Corrective action register
  • Innovation pipeline
  • Change management plan
Where this commonly fails
  • Improvement not data-driven
  • Corrective actions reactive
  • Innovation pipeline empty

ISO 30401: Leadership & Planning

ISO30401-01
Knowledge management systems - policy and objectives for organizational knowledge management

Quality policy and objectives. Control from ISO 30401 framework, domain: ISO 30401: Leadership & Planning.

Artefacts an auditor will ask for
  • KM policy
  • KM objectives matrix
  • Resource allocation plan
  • Risk-based KM plan
Where this commonly fails
  • KM objectives not measurable
  • Leadership commitment not visible
  • Roles not staffed
ISO30401-02
Leadership commitment to quality

Leadership commitment to quality. Control from ISO 30401 framework, domain: ISO 30401: Leadership & Planning.

Artefacts an auditor will ask for
  • KM policy
  • KM objectives matrix
  • Resource allocation plan
  • Risk-based KM plan
Where this commonly fails
  • KM objectives not measurable
  • Leadership commitment not visible
  • Roles not staffed
ISO30401-03
Risk-based thinking and planning

Risk-based thinking and planning. Control from ISO 30401 framework, domain: ISO 30401: Leadership & Planning.

Artefacts an auditor will ask for
  • KM policy
  • KM objectives matrix
  • Resource allocation plan
  • Risk-based KM plan
Where this commonly fails
  • KM objectives not measurable
  • Leadership commitment not visible
  • Roles not staffed
ISO30401-04
Resource management for quality

Resource management for quality. Control from ISO 30401 framework, domain: ISO 30401: Leadership & Planning.

Artefacts an auditor will ask for
  • KM policy
  • KM objectives matrix
  • Resource allocation plan
  • Risk-based KM plan
Where this commonly fails
  • KM objectives not measurable
  • Leadership commitment not visible
  • Roles not staffed
ISO30401-05
Organizational roles and responsibilities

Organizational roles and responsibilities. Control from ISO 30401 framework, domain: ISO 30401: Leadership & Planning.

Artefacts an auditor will ask for
  • KM policy
  • KM objectives matrix
  • Resource allocation plan
  • Risk-based KM plan
Where this commonly fails
  • KM objectives not measurable
  • Leadership commitment not visible
  • Roles not staffed

ISO 30401: Operational Controls

ISO30401-06
Operational planning and control

Operational planning and control. Control from ISO 30401 framework, domain: ISO 30401: Operational Controls.

Artefacts an auditor will ask for
  • Operational KM plan
  • Knowledge content lifecycle
  • External provider register
  • Service delivery log
Where this commonly fails
  • Lifecycle stages not enforced
  • Provider oversight light
  • Service delivery metrics missing
ISO30401-07
Requirements for products and services

Requirements for products and services. Control from ISO 30401 framework, domain: ISO 30401: Operational Controls.

Artefacts an auditor will ask for
  • Operational KM plan
  • Knowledge content lifecycle
  • External provider register
  • Service delivery log
Where this commonly fails
  • Lifecycle stages not enforced
  • Provider oversight light
  • Service delivery metrics missing
ISO30401-08
Design and development controls

Design and development controls. Control from ISO 30401 framework, domain: ISO 30401: Operational Controls.

Artefacts an auditor will ask for
  • Operational KM plan
  • Knowledge content lifecycle
  • External provider register
  • Service delivery log
Where this commonly fails
  • Lifecycle stages not enforced
  • Provider oversight light
  • Service delivery metrics missing
ISO30401-09
Control of externally provided processes

Control of externally provided processes. Control from ISO 30401 framework, domain: ISO 30401: Operational Controls.

Artefacts an auditor will ask for
  • Operational KM plan
  • Knowledge content lifecycle
  • External provider register
  • Service delivery log
Where this commonly fails
  • Lifecycle stages not enforced
  • Provider oversight light
  • Service delivery metrics missing
ISO30401-10
Production and service provision controls

Production and service provision controls. Control from ISO 30401 framework, domain: ISO 30401: Operational Controls.

Artefacts an auditor will ask for
  • Operational KM plan
  • Knowledge content lifecycle
  • External provider register
  • Service delivery log
Where this commonly fails
  • Lifecycle stages not enforced
  • Provider oversight light
  • Service delivery metrics missing

ISO 30401: Performance Evaluation

ISO30401-11
Monitoring, measurement, and analysis

Monitoring, measurement, and analysis. Control from ISO 30401 framework, domain: ISO 30401: Performance Evaluation.

Artefacts an auditor will ask for
  • KM metrics dashboard
  • Internal audit plan
  • Management review minutes
  • Nonconformity log
Where this commonly fails
  • Metrics not tied to outcomes
  • Audits skip KM scope
  • Nonconformities not closed
ISO30401-12
Internal audit program

Internal audit program. Control from ISO 30401 framework, domain: ISO 30401: Performance Evaluation.

Artefacts an auditor will ask for
  • KM metrics dashboard
  • Internal audit plan
  • Management review minutes
  • Nonconformity log
Where this commonly fails
  • Metrics not tied to outcomes
  • Audits skip KM scope
  • Nonconformities not closed
ISO30401-13
Management review process

Management review process. Control from ISO 30401 framework, domain: ISO 30401: Performance Evaluation.

Artefacts an auditor will ask for
  • KM metrics dashboard
  • Internal audit plan
  • Management review minutes
  • Nonconformity log
Where this commonly fails
  • Metrics not tied to outcomes
  • Audits skip KM scope
  • Nonconformities not closed
ISO30401-14
Customer satisfaction measurement

Customer satisfaction measurement. Control from ISO 30401 framework, domain: ISO 30401: Performance Evaluation.

Artefacts an auditor will ask for
  • KM metrics dashboard
  • Internal audit plan
  • Management review minutes
  • Nonconformity log
Where this commonly fails
  • Metrics not tied to outcomes
  • Audits skip KM scope
  • Nonconformities not closed
ISO30401-15
Nonconformity and corrective action

Nonconformity and corrective action. Control from ISO 30401 framework, domain: ISO 30401: Performance Evaluation.

Artefacts an auditor will ask for
  • KM metrics dashboard
  • Internal audit plan
  • Management review minutes
  • Nonconformity log
Where this commonly fails
  • Metrics not tied to outcomes
  • Audits skip KM scope
  • Nonconformities not closed

Improvement

ISO30401-10.2
Continual improvement

Continually improve suitability, adequacy, and effectiveness of the KMS.

Artefacts an auditor will ask for
  • Improvement backlog
  • Lessons learned register
  • Trend analysis
Where this commonly fails
  • Lessons not actioned

Knowledge lifecycle

ISO30401-4.5
Knowledge development

Address acquiring, applying, retaining, handling outdated, and developing new knowledge.

Artefacts an auditor will ask for
  • Knowledge lifecycle SOP
  • Capture templates
  • Retirement log
Where this commonly fails
  • No retirement step
  • Hoarding

Leadership

ISO30401-5.1
Leadership and commitment

Top management demonstrates leadership and commitment to the KMS.

Artefacts an auditor will ask for
  • Leadership communications
  • KM sponsor charter
  • Board minutes
Where this commonly fails
  • Sponsor in name only

Monitoring

ISO30401-9.1
Monitoring, measurement, analysis, evaluation

Monitor and evaluate KM performance and effectiveness.

Artefacts an auditor will ask for
  • KPI dashboard
  • Evaluation reports
Where this commonly fails
  • Outcome metrics absent

Objectives

ISO30401-6.2
Knowledge management objectives

Establish measurable KM objectives at relevant functions and levels.

Artefacts an auditor will ask for
  • Objectives register
  • KPI scorecard
  • Review minutes
Where this commonly fails
  • Vanity metrics only

Operations

ISO30401-8.1
Operational planning and control

Plan, implement, and control processes needed to meet KM requirements.

Artefacts an auditor will ask for
  • KM process docs
  • Operational plans
  • Change records
Where this commonly fails
  • Ad hoc execution

Planning

ISO30401-6.1
Actions to address risks and opportunities

Identify and address risks and opportunities for the KMS.

Artefacts an auditor will ask for
  • Risk register
  • Opportunity log
  • Treatment plan
Where this commonly fails
  • No KM specific risks

Policy

ISO30401-5.2
Knowledge management policy

Establish and communicate a knowledge management policy.

Artefacts an auditor will ask for
  • KM policy
  • Communication evidence
  • Review record
Where this commonly fails
  • Policy not communicated

Resources

ISO30401-7.1
Resources

Determine and provide resources for the KMS.

Artefacts an auditor will ask for
  • Budget
  • Headcount plan
  • Tool licences
Where this commonly fails
  • Underfunded KM program

Roles

ISO30401-5.3
Roles, responsibilities, authorities

Assign and communicate KM roles, responsibilities, and authorities.

Artefacts an auditor will ask for
  • RACI
  • Role descriptions
  • Org chart
Where this commonly fails
  • No KM lead

Scope

ISO30401-4.3
Scope of KMS

Define the boundaries and applicability of the knowledge management system.

Artefacts an auditor will ask for
  • Scope statement
  • Exclusions register
Where this commonly fails
  • Subsidiaries excluded without rationale

Stakeholders

ISO30401-4.2
Needs and expectations of stakeholders

Identify stakeholders and their knowledge needs and expectations.

Artefacts an auditor will ask for
  • Stakeholder register
  • Needs analysis
  • Survey results
Where this commonly fails
  • Field staff omitted

System

ISO30401-4.4
Knowledge management system

Establish, implement, maintain, and improve the knowledge management system.

Artefacts an auditor will ask for
  • KMS framework
  • Process map
  • Governance charter
Where this commonly fails
  • No process owner

Transfer

ISO30401-4.6
Knowledge conveyance and transformation

Enable interactions, representations, and integrations that transform knowledge.

Artefacts an auditor will ask for
  • Communities of practice charter
  • Mentoring program
  • Repository taxonomy
Where this commonly fails
  • Tacit knowledge not captured
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 30401 framework page.