The paperwork isn't the hard part of an ISO 9001 audit - proving it on the spot is. Here's what auditors actually check, and why most contractors get caught scrambling.
By Cloudcon
4 minute read
If you've been through an ISO 9001 audit before, you know the feeling. Someone's coming in to check your quality management system, and the night before, you're digging through folders trying to find the current version of a SWMS, chasing down a sign-off that's sitting in a truck somewhere, or hoping the training records are actually up to date.
Here's the thing: an ISO 9001 audit isn't really testing whether you have a quality management system. It's testing whether you can prove it, on the spot, with real records. That's a different problem, and it's the one that actually catches people out.
So what do auditors actually look for? Here's the shortlist.
1. Document control (Clause 7.5) - is this actually the current version? Auditors want to see strict version control on SWMS, ITPs, and QA forms. Not "we think this is the latest one" - an actual, traceable history showing what changed, when, and who signed off on it. If your system is a shared folder full of files named "SWMS_final_v3_ACTUAL_final.docx," this is where it falls apart.
2. Non-conformance records (Clause 10.2) - and what you did about them Having a non-conformance isn't the problem. Auditors expect issues to come up - that's normal on any job. What they're checking is whether you caught it, logged it, and closed it out properly. A non-conformance report that was raised, actioned, and resolved with a timestamp is a good sign. A verbal "yeah we sorted that" with nothing written down is not.
3. Training and competency records (Clause 7.2) Can you show, for any given worker on any given day, that they were qualified and inducted for the work they were doing? Operator tickets, inductions, competency records - auditors will ask for a specific person and expect you to pull up their record in minutes, not go looking for a folder.
4. Risk-based thinking (Clause 6.1) - and the ISO 45001 overlap ISO 9001 requires risk-based thinking, which overlaps heavily for contractors also running ISO 45001 safety audits. Pre-starts, SWMS sign-offs, and incident reports all need to be there, timestamped, and consistent with what was actually happening on-site that day.
5. Whether your records match your actual process (Clause 9.2) This is the one that trips people up most. It's not enough to have the paperwork - the paperwork has to reflect what your business actually does. If your quality manual says inspections happen daily but your records show gaps, that's a bigger flag than a single missing form.
The real problem isn't the standard - it's the scramble
None of this is complicated in principle. The problem is logistics: paper forms decaying in a ute, a version of a document nobody can find, training records split across three spreadsheets. By the time the auditor's in the room, you're reconstructing history instead of just handing it over.
That's less about ISO 9001 itself and more about whether your day-to-day system produces evidence as a byproduct of doing the work - or whether "evidence" is something you have to go build after the fact.
Written by Cloudcon
