ISO 9001
Evidence request list. 43 controls, 43 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Audit
Conduct internal audits at planned intervals to determine QMS conformity and effectiveness.
- Audit programme
- Audit reports
- Auditor competence records
- Programme covers only some clauses
- Auditors not independent
Competence
Determine required competence, ensure persons are competent, and take action to acquire competence where needed.
- Competence matrix
- Training records
- Effectiveness evaluations
- Training delivered without effectiveness check
- Competence gaps unaddressed
Context
Determine external and internal issues relevant to the purpose of the organisation and its strategic direction, and how they affect the QMS.
- PESTLE or SWOT records
- Strategic plan extracts
- Context review minutes
- Context never refreshed
- No link to risk register
Identify interested parties relevant to the QMS, their requirements, and how these are monitored and reviewed.
- Stakeholder register
- Requirements log
- Review records
- Regulators omitted
- No periodic refresh
Corrective Action
React to nonconformities, evaluate the need for action to eliminate causes, and review effectiveness of corrective actions.
- CAPA records
- Root cause analyses
- Effectiveness reviews
- Symptoms fixed, causes not addressed
- Effectiveness not verified
Customer
Determine, review, and communicate requirements for products and services with customers and other parties.
- Contract reviews
- Requirements records
- Communication logs
- Verbal commitments not captured
- Changes not re-reviewed
Design
Establish, implement, and maintain a design and development process appropriate to the products and services.
- Design plans
- Verification and validation records
- Design change records
- Verification skipped
- Design changes uncontrolled
Documentation
Maintain and retain documented information required by the standard and by the QMS, with proper control.
- Document control procedure
- Master document list
- Retention schedule
- Uncontrolled copies in circulation
- Retention not enforced
ISO 9001: Improvement
Continual improvement methodology. Control from ISO 9001 framework, domain: ISO 9001: Improvement.
- Improvement plan
- CAPA register
- Change control records
- Lessons learned log
- Improvement reactive
- Root cause shallow
- Changes not validated
- Lessons not shared
Corrective and preventive actions. Control from ISO 9001 framework, domain: ISO 9001: Improvement.
- Improvement plan
- CAPA register
- Change control records
- Lessons learned log
- Improvement reactive
- Root cause shallow
- Changes not validated
- Lessons not shared
Innovation and change management. Control from ISO 9001 framework, domain: ISO 9001: Improvement.
- Improvement plan
- CAPA register
- Change control records
- Lessons learned log
- Improvement reactive
- Root cause shallow
- Changes not validated
- Lessons not shared
ISO 9001: Leadership & Planning
Quality policy and objectives. Control from ISO 9001 framework, domain: ISO 9001: Leadership & Planning.
- Quality policy
- Quality objectives
- Risk register
- Resource plan
- Policy not communicated
- Objectives not SMART
- Risk not integrated
- Resources misaligned
Leadership commitment to quality. Control from ISO 9001 framework, domain: ISO 9001: Leadership & Planning.
- Quality policy
- Quality objectives
- Risk register
- Resource plan
- Policy not communicated
- Objectives not SMART
- Risk not integrated
- Resources misaligned
Risk-based thinking and planning. Control from ISO 9001 framework, domain: ISO 9001: Leadership & Planning.
- Quality policy
- Quality objectives
- Risk register
- Resource plan
- Policy not communicated
- Objectives not SMART
- Risk not integrated
- Resources misaligned
Resource management for quality. Control from ISO 9001 framework, domain: ISO 9001: Leadership & Planning.
- Quality policy
- Quality objectives
- Risk register
- Resource plan
- Policy not communicated
- Objectives not SMART
- Risk not integrated
- Resources misaligned
Organizational roles and responsibilities. Control from ISO 9001 framework, domain: ISO 9001: Leadership & Planning.
- Quality policy
- Quality objectives
- Risk register
- Resource plan
- Policy not communicated
- Objectives not SMART
- Risk not integrated
- Resources misaligned
ISO 9001: Operational Controls
Operational planning and control. Control from ISO 9001 framework, domain: ISO 9001: Operational Controls.
- Operating procedures
- Design control records
- Supplier evaluation
- Production records
- Undocumented operations
- Design changes uncontrolled
- Weak supplier oversight
- No traceability
Requirements for products and services. Control from ISO 9001 framework, domain: ISO 9001: Operational Controls.
- Operating procedures
- Design control records
- Supplier evaluation
- Production records
- Undocumented operations
- Design changes uncontrolled
- Weak supplier oversight
- No traceability
Design and development controls. Control from ISO 9001 framework, domain: ISO 9001: Operational Controls.
- Operating procedures
- Design control records
- Supplier evaluation
- Production records
- Undocumented operations
- Design changes uncontrolled
- Weak supplier oversight
- No traceability
Control of externally provided processes. Control from ISO 9001 framework, domain: ISO 9001: Operational Controls.
- Operating procedures
- Design control records
- Supplier evaluation
- Production records
- Undocumented operations
- Design changes uncontrolled
- Weak supplier oversight
- No traceability
Production and service provision controls. Control from ISO 9001 framework, domain: ISO 9001: Operational Controls.
- Operating procedures
- Design control records
- Supplier evaluation
- Production records
- Undocumented operations
- Design changes uncontrolled
- Weak supplier oversight
- No traceability
ISO 9001: Performance Evaluation
Monitoring, measurement, and analysis. Control from ISO 9001 framework, domain: ISO 9001: Performance Evaluation.
- Audit program
- Management review records
- Customer satisfaction survey
- NC report
- Audit gaps
- Reviews not actioned
- Survey results ignored
- NC not analyzed
Internal audit program. Control from ISO 9001 framework, domain: ISO 9001: Performance Evaluation.
- Audit program
- Management review records
- Customer satisfaction survey
- NC report
- Audit gaps
- Reviews not actioned
- Survey results ignored
- NC not analyzed
Management review process. Control from ISO 9001 framework, domain: ISO 9001: Performance Evaluation.
- Audit program
- Management review records
- Customer satisfaction survey
- NC report
- Audit gaps
- Reviews not actioned
- Survey results ignored
- NC not analyzed
Customer satisfaction measurement. Control from ISO 9001 framework, domain: ISO 9001: Performance Evaluation.
- Audit program
- Management review records
- Customer satisfaction survey
- NC report
- Audit gaps
- Reviews not actioned
- Survey results ignored
- NC not analyzed
Nonconformity and corrective action. Control from ISO 9001 framework, domain: ISO 9001: Performance Evaluation.
- Audit program
- Management review records
- Customer satisfaction survey
- NC report
- Audit gaps
- Reviews not actioned
- Survey results ignored
- NC not analyzed
Improvement
Determine and select opportunities for improvement and implement necessary actions to enhance customer satisfaction.
- Improvement register
- Project records
- Benefit tracking
- No improvement pipeline
- Benefits not tracked
Continually improve the suitability, adequacy, and effectiveness of the QMS using analysis results and management review outputs.
- Improvement plan
- Trend analyses
- Review outputs
- Improvement plan not data-driven
- No trend over time
Leadership
Top management demonstrates leadership and commitment to the QMS and to customer focus.
- Management review minutes
- Communications from top management
- Customer focus statements
- Leadership invisible to staff
- Customer focus reduced to slogans
Nonconformity
Identify and control nonconforming outputs to prevent unintended use or delivery, and act on the nature of the nonconformity.
- NC register
- Disposition records
- Customer notifications
- Customer not informed
- Disposition not recorded
Objectives
Establish measurable quality objectives at relevant functions and levels, with plans to achieve them.
- Objective catalogue
- KPI definitions
- Action plans
- Objectives not measurable
- No owners or due dates
Operations
Plan, implement, and control processes needed to meet product and service requirements.
- Operational plans
- Process controls
- Change records
- Outsourced processes not controlled
- Plans not updated for changes
Implement controlled conditions for production and service provision including identification, traceability, and preservation.
- Work instructions
- Traceability records
- Preservation procedures
- Traceability breaks at handover
- Preservation not specified
Performance
Monitor, measure, analyse, and evaluate the QMS, including customer satisfaction.
- KPI dashboards
- Customer satisfaction surveys
- Analysis reports
- Data collected but not analysed
- Customer voice missing
Policy
Establish, communicate, and maintain a quality policy appropriate to the purpose and context of the organisation.
- Approved quality policy
- Communication evidence
- Awareness training records
- Policy unsigned or undated
- Staff unaware of policy
Process
Establish, implement, maintain, and improve a QMS including the processes needed and their interactions.
- Process landscape
- Process descriptions
- Interaction diagrams
- No interaction view
- Process owners unnamed
Release
Implement planned arrangements to verify product and service requirements have been met before release.
- Release records
- Acceptance criteria
- Authorisation signatures
- Release without verification
- Authoriser not documented
Resources
Determine and provide the resources needed for the QMS including people, infrastructure, environment, and monitoring resources.
- Resource plans
- Asset registers
- Calibration records
- Calibration overdue
- Resource gaps not escalated
Review
Top management reviews the QMS at planned intervals to ensure its continuing suitability, adequacy, effectiveness, and alignment with strategic direction.
- Management review inputs
- Minutes
- Action register
- Reviews skipped
- Required inputs missing
Risk
Plan actions to address QMS risks and opportunities, integrate them into processes, and evaluate effectiveness.
- Risk register
- Action plans
- Effectiveness reviews
- Risks listed but not actioned
- No effectiveness evaluation
Roles
Assign and communicate responsibilities and authorities for relevant roles within the QMS.
- Role descriptions
- Org chart
- RACI matrix
- No QMS process owners
- Authority conflicts unresolved
Scope
Determine and document the boundaries and applicability of the QMS, including any non-applicable clauses with justification.
- Scope statement
- Exclusion justifications
- Site list
- Scope too broad to be auditable
- Exclusions without justification
Suppliers
Control external providers and the products, services, and processes they provide to ensure conformity.
- Approved supplier list
- Evaluation records
- Incoming inspection records
- Approval lapses
- No performance monitoring
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 9001 framework page.