Skip to content

Evidence request lists

ISO 55001

Evidence request list. 40 controls, 40 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Context

ISO55001-4.1
Understanding the organization and its context

Determine external and internal issues relevant to purpose and that affect ability to achieve intended outcomes of asset management system.

Artefacts an auditor will ask for
  • Context analysis
  • Stakeholder pressure map
  • Strategic asset issues
Where this commonly fails
  • Engineering-only view
  • No regulator/customer context
ISO55001-4.2
Understanding the needs and expectations of stakeholders

Determine stakeholders relevant to asset management and their requirements including financial and non-financial criteria.

Artefacts an auditor will ask for
  • Stakeholder register
  • Service level requirements
  • Customer LoS commitments
Where this commonly fails
  • No documented LoS
  • Stakeholder list outdated
ISO55001-4.3
Determining scope of asset management system

Determine boundaries and applicability of AMS including portfolio of assets to be managed.

Artefacts an auditor will ask for
  • AMS scope statement
  • Asset portfolio inventory
  • Class/category structure
Where this commonly fails
  • Mobile assets excluded
  • No IT/SCADA inclusion
ISO55001-4.4
Asset management system

Establish, implement, maintain and continually improve AMS including processes and their interactions.

Artefacts an auditor will ask for
  • AMS process map
  • Process interaction matrix
  • AMS manual
Where this commonly fails
  • Silos between OT/IT
  • No process owners

ISO 55001: Improvement

ISO55001-16
Continual improvement methodology

Continual improvement methodology. Control from ISO 55001 framework, domain: ISO 55001: Improvement.

Artefacts an auditor will ask for
  • Improvement register
  • Corrective action log
  • Change request record
  • Lessons learned database
Where this commonly fails
  • Recurring issues
  • No preventive actions
  • Change without impact review
  • Lessons not applied
ISO55001-17
Corrective and preventive actions

Corrective and preventive actions. Control from ISO 55001 framework, domain: ISO 55001: Improvement.

Artefacts an auditor will ask for
  • Improvement register
  • Corrective action log
  • Change request record
  • Lessons learned database
Where this commonly fails
  • Recurring issues
  • No preventive actions
  • Change without impact review
  • Lessons not applied
ISO55001-18
Innovation and change management

Innovation and change management. Control from ISO 55001 framework, domain: ISO 55001: Improvement.

Artefacts an auditor will ask for
  • Improvement register
  • Corrective action log
  • Change request record
  • Lessons learned database
Where this commonly fails
  • Recurring issues
  • No preventive actions
  • Change without impact review
  • Lessons not applied

ISO 55001: Leadership & Planning

ISO55001-01
Cl. 6.2 Asset management objectives - policy, objectives, and planning for asset management system operation

Quality policy and objectives. Control from ISO 55001 framework, domain: ISO 55001: Leadership & Planning.

Artefacts an auditor will ask for
  • Asset management policy
  • Strategic asset plan
  • Roles and responsibility chart
  • Resource plan
Where this commonly fails
  • Policy not endorsed
  • No line of sight to objectives
  • Unclear asset ownership
  • Resource shortfalls
ISO55001-02
Leadership commitment to quality

Leadership commitment to quality. Control from ISO 55001 framework, domain: ISO 55001: Leadership & Planning.

Artefacts an auditor will ask for
  • Asset management policy
  • Strategic asset plan
  • Roles and responsibility chart
  • Resource plan
Where this commonly fails
  • Policy not endorsed
  • No line of sight to objectives
  • Unclear asset ownership
  • Resource shortfalls
ISO55001-03
Risk-based thinking and planning

Risk-based thinking and planning. Control from ISO 55001 framework, domain: ISO 55001: Leadership & Planning.

Artefacts an auditor will ask for
  • Asset management policy
  • Strategic asset plan
  • Roles and responsibility chart
  • Resource plan
Where this commonly fails
  • Policy not endorsed
  • No line of sight to objectives
  • Unclear asset ownership
  • Resource shortfalls
ISO55001-04
Resource management for quality

Resource management for quality. Control from ISO 55001 framework, domain: ISO 55001: Leadership & Planning.

Artefacts an auditor will ask for
  • Asset management policy
  • Strategic asset plan
  • Roles and responsibility chart
  • Resource plan
Where this commonly fails
  • Policy not endorsed
  • No line of sight to objectives
  • Unclear asset ownership
  • Resource shortfalls
ISO55001-05
Organizational roles and responsibilities

Organizational roles and responsibilities. Control from ISO 55001 framework, domain: ISO 55001: Leadership & Planning.

Artefacts an auditor will ask for
  • Asset management policy
  • Strategic asset plan
  • Roles and responsibility chart
  • Resource plan
Where this commonly fails
  • Policy not endorsed
  • No line of sight to objectives
  • Unclear asset ownership
  • Resource shortfalls

ISO 55001: Operational Controls

ISO55001-06
Operational planning and control

Operational planning and control. Control from ISO 55001 framework, domain: ISO 55001: Operational Controls.

Artefacts an auditor will ask for
  • Operating procedures
  • Design control record
  • Supplier evaluation
  • Production records
Where this commonly fails
  • Undocumented operations
  • Weak supplier oversight
  • Change control gaps
  • No service spec
ISO55001-07
Requirements for products and services

Requirements for products and services. Control from ISO 55001 framework, domain: ISO 55001: Operational Controls.

Artefacts an auditor will ask for
  • Operating procedures
  • Design control record
  • Supplier evaluation
  • Production records
Where this commonly fails
  • Undocumented operations
  • Weak supplier oversight
  • Change control gaps
  • No service spec
ISO55001-08
Design and development controls

Design and development controls. Control from ISO 55001 framework, domain: ISO 55001: Operational Controls.

Artefacts an auditor will ask for
  • Operating procedures
  • Design control record
  • Supplier evaluation
  • Production records
Where this commonly fails
  • Undocumented operations
  • Weak supplier oversight
  • Change control gaps
  • No service spec
ISO55001-09
Control of externally provided processes

Control of externally provided processes. Control from ISO 55001 framework, domain: ISO 55001: Operational Controls.

Artefacts an auditor will ask for
  • Operating procedures
  • Design control record
  • Supplier evaluation
  • Production records
Where this commonly fails
  • Undocumented operations
  • Weak supplier oversight
  • Change control gaps
  • No service spec
ISO55001-10
Production and service provision controls

Production and service provision controls. Control from ISO 55001 framework, domain: ISO 55001: Operational Controls.

Artefacts an auditor will ask for
  • Operating procedures
  • Design control record
  • Supplier evaluation
  • Production records
Where this commonly fails
  • Undocumented operations
  • Weak supplier oversight
  • Change control gaps
  • No service spec

ISO 55001: Performance Evaluation

ISO55001-11
Monitoring, measurement, and analysis

Monitoring, measurement, and analysis. Control from ISO 55001 framework, domain: ISO 55001: Performance Evaluation.

Artefacts an auditor will ask for
  • Performance dashboard
  • Internal audit schedule
  • Management review minutes
  • Customer satisfaction survey
Where this commonly fails
  • Lagging indicators only
  • Audit scope gaps
  • No survey follow-through
  • NC not closed
ISO55001-12
Internal audit program

Internal audit program. Control from ISO 55001 framework, domain: ISO 55001: Performance Evaluation.

Artefacts an auditor will ask for
  • Performance dashboard
  • Internal audit schedule
  • Management review minutes
  • Customer satisfaction survey
Where this commonly fails
  • Lagging indicators only
  • Audit scope gaps
  • No survey follow-through
  • NC not closed
ISO55001-13
Management review process

Management review process. Control from ISO 55001 framework, domain: ISO 55001: Performance Evaluation.

Artefacts an auditor will ask for
  • Performance dashboard
  • Internal audit schedule
  • Management review minutes
  • Customer satisfaction survey
Where this commonly fails
  • Lagging indicators only
  • Audit scope gaps
  • No survey follow-through
  • NC not closed
ISO55001-14
Customer satisfaction measurement

Customer satisfaction measurement. Control from ISO 55001 framework, domain: ISO 55001: Performance Evaluation.

Artefacts an auditor will ask for
  • Performance dashboard
  • Internal audit schedule
  • Management review minutes
  • Customer satisfaction survey
Where this commonly fails
  • Lagging indicators only
  • Audit scope gaps
  • No survey follow-through
  • NC not closed
ISO55001-15
Nonconformity and corrective action

Nonconformity and corrective action. Control from ISO 55001 framework, domain: ISO 55001: Performance Evaluation.

Artefacts an auditor will ask for
  • Performance dashboard
  • Internal audit schedule
  • Management review minutes
  • Customer satisfaction survey
Where this commonly fails
  • Lagging indicators only
  • Audit scope gaps
  • No survey follow-through
  • NC not closed

Improvement

ISO55001-10.1
Nonconformity and corrective action

React to asset-related failures and AMS nonconformities, evaluate need for action and implement corrective action including reviewing effectiveness.

Artefacts an auditor will ask for
  • Failure investigations
  • Root cause register
  • CAPA tracker
Where this commonly fails
  • Repeat failures
  • No RCA culture
ISO55001-10.2
Preventive action

Establish processes to proactively identify potential failures in asset performance and evaluate need for preventive action.

Artefacts an auditor will ask for
  • FMEA studies
  • Predictive maintenance program
  • Risk-based inspection plans
Where this commonly fails
  • No predictive maintenance
  • FMEA outdated
ISO55001-10.3
Continual improvement

Continually improve suitability, adequacy and effectiveness of asset management and AMS.

Artefacts an auditor will ask for
  • Improvement initiatives register
  • Maturity assessments
  • Benchmarking studies
Where this commonly fails
  • No maturity baseline
  • No benchmarking

Leadership

ISO55001-5.1
Leadership and commitment

Top management demonstrates leadership for asset management including ensuring SAMP and asset management policy alignment with organizational objectives.

Artefacts an auditor will ask for
  • Board AM mandate
  • Resource commitments
  • Management review chair record
Where this commonly fails
  • Asset manager isolated
  • No board-level KPI
ISO55001-5.2
Policy

Establish asset management policy aligned with organizational objectives and providing framework for setting asset management objectives.

Artefacts an auditor will ask for
  • Signed AM policy
  • Communication evidence
  • Periodic review log
Where this commonly fails
  • Policy not linked to org strategy
  • No public version

Operation

ISO55001-8.1
Operational planning and control

Plan, implement and control processes needed to meet requirements and implement actions determined in planning including operations, maintenance and renewal.

Artefacts an auditor will ask for
  • Maintenance strategy (RCM/FMEA)
  • Work management process
  • Spares management
Where this commonly fails
  • Reactive maintenance dominant
  • No RCM
ISO55001-8.2
Management of change

Assess risks associated with planned change to AMS or assets and control changes that could affect achievement of asset management objectives.

Artefacts an auditor will ask for
  • MOC procedure
  • Change impact assessments
  • Pre/post-change reviews
Where this commonly fails
  • Operational changes bypass MOC
  • No impact assessment
ISO55001-8.3
Outsourcing

When outsourcing activities affecting achievement of asset management objectives, control and integrate these activities into AMS.

Artefacts an auditor will ask for
  • Contractor management framework
  • Service level agreements
  • KPI reporting from contractors
Where this commonly fails
  • No data handback
  • Contractor risk uncontrolled

Performance evaluation

ISO55001-9.1
Monitoring, measurement, analysis and evaluation

Determine what needs monitoring including asset performance, asset management performance and AMS effectiveness and analyse data.

Artefacts an auditor will ask for
  • KPI dashboards (asset/AM/AMS)
  • Condition monitoring records
  • Lifecycle cost reports
Where this commonly fails
  • Lagging KPIs only
  • No condition monitoring
ISO55001-9.2
Internal audit

Conduct internal audits at planned intervals to evaluate AMS conformity and effective implementation.

Artefacts an auditor will ask for
  • Audit programme
  • Audit reports
  • Auditor competence on AM
Where this commonly fails
  • Generic auditors
  • No technical specialists
ISO55001-9.3
Management review

Top management reviews AMS at planned intervals to ensure continuing suitability, adequacy and effectiveness.

Artefacts an auditor will ask for
  • Management review minutes
  • SAMP review record
  • Decision log
Where this commonly fails
  • No SAMP review
  • Skipped inputs

Planning

ISO55001-6.1
Actions to address risks and opportunities

Determine risks and opportunities affecting achievement of asset management objectives and plan actions.

Artefacts an auditor will ask for
  • Asset risk register
  • Criticality analysis
  • Opportunity log
Where this commonly fails
  • No criticality ranking
  • Risks not asset-specific
ISO55001-6.2.1
Asset management objectives

Establish asset management objectives consistent with policy at relevant functions and levels considering stakeholder requirements and financial criteria.

Artefacts an auditor will ask for
  • AM objectives register
  • LoS targets
  • Cost/risk/performance balance
Where this commonly fails
  • Performance only
  • No cost-risk tradeoff
ISO55001-6.2.2
Planning to achieve asset management objectives

Develop strategic asset management plan (SAMP) and asset management plans including activities, resources, responsibilities and timeframes over relevant horizons.

Artefacts an auditor will ask for
  • Strategic Asset Management Plan
  • Asset Management Plans by class
  • Long-term capital forecast
  • Lifecycle cost models
Where this commonly fails
  • No SAMP
  • 5-year horizon only
  • Capex/opex disconnected

Support

ISO55001-7.1
Resources

Determine and provide resources needed for establishment, implementation, maintenance and continual improvement of AMS.

Artefacts an auditor will ask for
  • Resource plan
  • Budget allocations
  • Headcount plan
Where this commonly fails
  • Reactive maintenance budget only
  • No improvement budget
ISO55001-7.2
Competence

Determine necessary competence of persons whose work affects asset performance and ensure competence through training, education or experience.

Artefacts an auditor will ask for
  • AM competency framework
  • Training matrix
  • IAM/AMCL certifications register
Where this commonly fails
  • Tribal knowledge
  • No succession plan
ISO55001-7.5
Information requirements

Determine information requirements supporting assets, asset management, AMS and achievement of organizational objectives including data quality.

Artefacts an auditor will ask for
  • Asset information strategy
  • Data quality framework
  • EAM/CMMS structure
  • Asset hierarchy
Where this commonly fails
  • Multiple disconnected registers
  • Poor data quality
ISO55001-7.6
Documented information

AMS includes documented information required by this standard and determined as necessary for effectiveness of AMS.

Artefacts an auditor will ask for
  • Document register
  • Procedure library
  • Version control
Where this commonly fails
  • Inconsistent format
  • Outdated procedures
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 55001 framework page.