Skip to content

Evidence request lists

ISO 9001

Evidence request list. 43 controls, 43 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Audit

9001-9.2
Internal Audit

Conduct internal audits at planned intervals to determine QMS conformity and effectiveness.

Artefacts an auditor will ask for
  • Audit programme
  • Audit reports
  • Auditor competence records
Where this commonly fails
  • Programme covers only some clauses
  • Auditors not independent

Competence

9001-7.2
Competence

Determine required competence, ensure persons are competent, and take action to acquire competence where needed.

Artefacts an auditor will ask for
  • Competence matrix
  • Training records
  • Effectiveness evaluations
Where this commonly fails
  • Training delivered without effectiveness check
  • Competence gaps unaddressed

Context

9001-4.1
Understanding the Organization and its Context

Determine external and internal issues relevant to the purpose of the organisation and its strategic direction, and how they affect the QMS.

Artefacts an auditor will ask for
  • PESTLE or SWOT records
  • Strategic plan extracts
  • Context review minutes
Where this commonly fails
  • Context never refreshed
  • No link to risk register
9001-4.2
Needs and Expectations of Interested Parties

Identify interested parties relevant to the QMS, their requirements, and how these are monitored and reviewed.

Artefacts an auditor will ask for
  • Stakeholder register
  • Requirements log
  • Review records
Where this commonly fails
  • Regulators omitted
  • No periodic refresh

Corrective Action

9001-10.2
Nonconformity and Corrective Action

React to nonconformities, evaluate the need for action to eliminate causes, and review effectiveness of corrective actions.

Artefacts an auditor will ask for
  • CAPA records
  • Root cause analyses
  • Effectiveness reviews
Where this commonly fails
  • Symptoms fixed, causes not addressed
  • Effectiveness not verified

Customer

9001-8.2
Requirements for Products and Services

Determine, review, and communicate requirements for products and services with customers and other parties.

Artefacts an auditor will ask for
  • Contract reviews
  • Requirements records
  • Communication logs
Where this commonly fails
  • Verbal commitments not captured
  • Changes not re-reviewed

Design

9001-8.3
Design and Development

Establish, implement, and maintain a design and development process appropriate to the products and services.

Artefacts an auditor will ask for
  • Design plans
  • Verification and validation records
  • Design change records
Where this commonly fails
  • Verification skipped
  • Design changes uncontrolled

Documentation

9001-7.5
Documented Information

Maintain and retain documented information required by the standard and by the QMS, with proper control.

Artefacts an auditor will ask for
  • Document control procedure
  • Master document list
  • Retention schedule
Where this commonly fails
  • Uncontrolled copies in circulation
  • Retention not enforced

ISO 9001: Improvement

ISO9001-16
Cl. 10 Improvement - continual improvement methodology for the quality management system

Continual improvement methodology. Control from ISO 9001 framework, domain: ISO 9001: Improvement.

Artefacts an auditor will ask for
  • Improvement plan
  • CAPA register
  • Change control records
  • Lessons learned log
Where this commonly fails
  • Improvement reactive
  • Root cause shallow
  • Changes not validated
  • Lessons not shared
ISO9001-17
Corrective and preventive actions

Corrective and preventive actions. Control from ISO 9001 framework, domain: ISO 9001: Improvement.

Artefacts an auditor will ask for
  • Improvement plan
  • CAPA register
  • Change control records
  • Lessons learned log
Where this commonly fails
  • Improvement reactive
  • Root cause shallow
  • Changes not validated
  • Lessons not shared
ISO9001-18
Cl. 6.3 Planning of changes - innovation and change management for the quality management system

Innovation and change management. Control from ISO 9001 framework, domain: ISO 9001: Improvement.

Artefacts an auditor will ask for
  • Improvement plan
  • CAPA register
  • Change control records
  • Lessons learned log
Where this commonly fails
  • Improvement reactive
  • Root cause shallow
  • Changes not validated
  • Lessons not shared

ISO 9001: Leadership & Planning

ISO9001-01
Cl. 4.4 Quality management system and its processes - quality policy and objectives

Quality policy and objectives. Control from ISO 9001 framework, domain: ISO 9001: Leadership & Planning.

Artefacts an auditor will ask for
  • Quality policy
  • Quality objectives
  • Risk register
  • Resource plan
Where this commonly fails
  • Policy not communicated
  • Objectives not SMART
  • Risk not integrated
  • Resources misaligned
ISO9001-02
Leadership commitment to quality

Leadership commitment to quality. Control from ISO 9001 framework, domain: ISO 9001: Leadership & Planning.

Artefacts an auditor will ask for
  • Quality policy
  • Quality objectives
  • Risk register
  • Resource plan
Where this commonly fails
  • Policy not communicated
  • Objectives not SMART
  • Risk not integrated
  • Resources misaligned
ISO9001-03
Risk-based thinking and planning

Risk-based thinking and planning. Control from ISO 9001 framework, domain: ISO 9001: Leadership & Planning.

Artefacts an auditor will ask for
  • Quality policy
  • Quality objectives
  • Risk register
  • Resource plan
Where this commonly fails
  • Policy not communicated
  • Objectives not SMART
  • Risk not integrated
  • Resources misaligned
ISO9001-04
Cl. 7.1.1 Resources (general) - resource management for quality including people, infrastructure, and organizational knowledge

Resource management for quality. Control from ISO 9001 framework, domain: ISO 9001: Leadership & Planning.

Artefacts an auditor will ask for
  • Quality policy
  • Quality objectives
  • Risk register
  • Resource plan
Where this commonly fails
  • Policy not communicated
  • Objectives not SMART
  • Risk not integrated
  • Resources misaligned
ISO9001-05
Organizational roles and responsibilities

Organizational roles and responsibilities. Control from ISO 9001 framework, domain: ISO 9001: Leadership & Planning.

Artefacts an auditor will ask for
  • Quality policy
  • Quality objectives
  • Risk register
  • Resource plan
Where this commonly fails
  • Policy not communicated
  • Objectives not SMART
  • Risk not integrated
  • Resources misaligned

ISO 9001: Operational Controls

ISO9001-06
Cl. 8 Operation - operational planning and control for products and services

Operational planning and control. Control from ISO 9001 framework, domain: ISO 9001: Operational Controls.

Artefacts an auditor will ask for
  • Operating procedures
  • Design control records
  • Supplier evaluation
  • Production records
Where this commonly fails
  • Undocumented operations
  • Design changes uncontrolled
  • Weak supplier oversight
  • No traceability
ISO9001-07
Requirements for products and services

Requirements for products and services. Control from ISO 9001 framework, domain: ISO 9001: Operational Controls.

Artefacts an auditor will ask for
  • Operating procedures
  • Design control records
  • Supplier evaluation
  • Production records
Where this commonly fails
  • Undocumented operations
  • Design changes uncontrolled
  • Weak supplier oversight
  • No traceability
ISO9001-08
Design and development controls

Design and development controls. Control from ISO 9001 framework, domain: ISO 9001: Operational Controls.

Artefacts an auditor will ask for
  • Operating procedures
  • Design control records
  • Supplier evaluation
  • Production records
Where this commonly fails
  • Undocumented operations
  • Design changes uncontrolled
  • Weak supplier oversight
  • No traceability
ISO9001-09
Control of externally provided processes

Control of externally provided processes. Control from ISO 9001 framework, domain: ISO 9001: Operational Controls.

Artefacts an auditor will ask for
  • Operating procedures
  • Design control records
  • Supplier evaluation
  • Production records
Where this commonly fails
  • Undocumented operations
  • Design changes uncontrolled
  • Weak supplier oversight
  • No traceability
ISO9001-10
Production and service provision controls

Production and service provision controls. Control from ISO 9001 framework, domain: ISO 9001: Operational Controls.

Artefacts an auditor will ask for
  • Operating procedures
  • Design control records
  • Supplier evaluation
  • Production records
Where this commonly fails
  • Undocumented operations
  • Design changes uncontrolled
  • Weak supplier oversight
  • No traceability

ISO 9001: Performance Evaluation

ISO9001-11
Monitoring, measurement, and analysis

Monitoring, measurement, and analysis. Control from ISO 9001 framework, domain: ISO 9001: Performance Evaluation.

Artefacts an auditor will ask for
  • Audit program
  • Management review records
  • Customer satisfaction survey
  • NC report
Where this commonly fails
  • Audit gaps
  • Reviews not actioned
  • Survey results ignored
  • NC not analyzed
ISO9001-12
Internal audit program

Internal audit program. Control from ISO 9001 framework, domain: ISO 9001: Performance Evaluation.

Artefacts an auditor will ask for
  • Audit program
  • Management review records
  • Customer satisfaction survey
  • NC report
Where this commonly fails
  • Audit gaps
  • Reviews not actioned
  • Survey results ignored
  • NC not analyzed
ISO9001-13
Management review process

Management review process. Control from ISO 9001 framework, domain: ISO 9001: Performance Evaluation.

Artefacts an auditor will ask for
  • Audit program
  • Management review records
  • Customer satisfaction survey
  • NC report
Where this commonly fails
  • Audit gaps
  • Reviews not actioned
  • Survey results ignored
  • NC not analyzed
ISO9001-14
Customer satisfaction measurement

Customer satisfaction measurement. Control from ISO 9001 framework, domain: ISO 9001: Performance Evaluation.

Artefacts an auditor will ask for
  • Audit program
  • Management review records
  • Customer satisfaction survey
  • NC report
Where this commonly fails
  • Audit gaps
  • Reviews not actioned
  • Survey results ignored
  • NC not analyzed
ISO9001-15
Nonconformity and corrective action

Nonconformity and corrective action. Control from ISO 9001 framework, domain: ISO 9001: Performance Evaluation.

Artefacts an auditor will ask for
  • Audit program
  • Management review records
  • Customer satisfaction survey
  • NC report
Where this commonly fails
  • Audit gaps
  • Reviews not actioned
  • Survey results ignored
  • NC not analyzed

Improvement

9001-10.1
Improvement General

Determine and select opportunities for improvement and implement necessary actions to enhance customer satisfaction.

Artefacts an auditor will ask for
  • Improvement register
  • Project records
  • Benefit tracking
Where this commonly fails
  • No improvement pipeline
  • Benefits not tracked
9001-10.3
Continual Improvement

Continually improve the suitability, adequacy, and effectiveness of the QMS using analysis results and management review outputs.

Artefacts an auditor will ask for
  • Improvement plan
  • Trend analyses
  • Review outputs
Where this commonly fails
  • Improvement plan not data-driven
  • No trend over time

Leadership

9001-5.1
Leadership and Commitment

Top management demonstrates leadership and commitment to the QMS and to customer focus.

Artefacts an auditor will ask for
  • Management review minutes
  • Communications from top management
  • Customer focus statements
Where this commonly fails
  • Leadership invisible to staff
  • Customer focus reduced to slogans

Nonconformity

9001-8.7
Control of Nonconforming Outputs

Identify and control nonconforming outputs to prevent unintended use or delivery, and act on the nature of the nonconformity.

Artefacts an auditor will ask for
  • NC register
  • Disposition records
  • Customer notifications
Where this commonly fails
  • Customer not informed
  • Disposition not recorded

Objectives

9001-6.2
Quality Objectives and Planning

Establish measurable quality objectives at relevant functions and levels, with plans to achieve them.

Artefacts an auditor will ask for
  • Objective catalogue
  • KPI definitions
  • Action plans
Where this commonly fails
  • Objectives not measurable
  • No owners or due dates

Operations

9001-8.1
Operational Planning and Control

Plan, implement, and control processes needed to meet product and service requirements.

Artefacts an auditor will ask for
  • Operational plans
  • Process controls
  • Change records
Where this commonly fails
  • Outsourced processes not controlled
  • Plans not updated for changes
9001-8.5
Production and Service Provision

Implement controlled conditions for production and service provision including identification, traceability, and preservation.

Artefacts an auditor will ask for
  • Work instructions
  • Traceability records
  • Preservation procedures
Where this commonly fails
  • Traceability breaks at handover
  • Preservation not specified

Performance

9001-9.1
Monitoring, Measurement, Analysis, Evaluation

Monitor, measure, analyse, and evaluate the QMS, including customer satisfaction.

Artefacts an auditor will ask for
  • KPI dashboards
  • Customer satisfaction surveys
  • Analysis reports
Where this commonly fails
  • Data collected but not analysed
  • Customer voice missing

Policy

9001-5.2
Quality Policy

Establish, communicate, and maintain a quality policy appropriate to the purpose and context of the organisation.

Artefacts an auditor will ask for
  • Approved quality policy
  • Communication evidence
  • Awareness training records
Where this commonly fails
  • Policy unsigned or undated
  • Staff unaware of policy

Process

9001-4.4
QMS and its Processes

Establish, implement, maintain, and improve a QMS including the processes needed and their interactions.

Artefacts an auditor will ask for
  • Process landscape
  • Process descriptions
  • Interaction diagrams
Where this commonly fails
  • No interaction view
  • Process owners unnamed

Release

9001-8.6
Release of Products and Services

Implement planned arrangements to verify product and service requirements have been met before release.

Artefacts an auditor will ask for
  • Release records
  • Acceptance criteria
  • Authorisation signatures
Where this commonly fails
  • Release without verification
  • Authoriser not documented

Resources

9001-7.1
Resources

Determine and provide the resources needed for the QMS including people, infrastructure, environment, and monitoring resources.

Artefacts an auditor will ask for
  • Resource plans
  • Asset registers
  • Calibration records
Where this commonly fails
  • Calibration overdue
  • Resource gaps not escalated

Review

9001-9.3
Management Review

Top management reviews the QMS at planned intervals to ensure its continuing suitability, adequacy, effectiveness, and alignment with strategic direction.

Artefacts an auditor will ask for
  • Management review inputs
  • Minutes
  • Action register
Where this commonly fails
  • Reviews skipped
  • Required inputs missing

Risk

9001-6.1
Actions to Address Risks and Opportunities

Plan actions to address QMS risks and opportunities, integrate them into processes, and evaluate effectiveness.

Artefacts an auditor will ask for
  • Risk register
  • Action plans
  • Effectiveness reviews
Where this commonly fails
  • Risks listed but not actioned
  • No effectiveness evaluation

Roles

9001-5.3
Roles, Responsibilities, and Authorities

Assign and communicate responsibilities and authorities for relevant roles within the QMS.

Artefacts an auditor will ask for
  • Role descriptions
  • Org chart
  • RACI matrix
Where this commonly fails
  • No QMS process owners
  • Authority conflicts unresolved

Scope

9001-4.3
Scope of the QMS

Determine and document the boundaries and applicability of the QMS, including any non-applicable clauses with justification.

Artefacts an auditor will ask for
  • Scope statement
  • Exclusion justifications
  • Site list
Where this commonly fails
  • Scope too broad to be auditable
  • Exclusions without justification

Suppliers

9001-8.4
Control of Externally Provided Processes, Products, Services

Control external providers and the products, services, and processes they provide to ensure conformity.

Artefacts an auditor will ask for
  • Approved supplier list
  • Evaluation records
  • Incoming inspection records
Where this commonly fails
  • Approval lapses
  • No performance monitoring
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 9001 framework page.