🔍 ISO 9001:2015 Process Audit
Process Audit Checklist ISO 9001: A Fillable Template for Manufacturers
An internal audit checklist ISO 9001:2015 that names what the auditor actually verifies — pre-audit document prep, opening meeting, evidence collection, finding classification (Major / Minor / OFI), corrective-action ownership, and verification of effectiveness — copy-and-adapt for the mid-market process-quality lead.
If you are a process-quality or QMS lead at a mid-market manufacturer, a "process audit checklist ISO 9001" that names only clause numbers is not the document that survives a Stage 2 finding — let alone an OFI-to-Major escalation six months later. ISO 9001:2015 §9.2 and ISO 19011:2018 require the audit team to plan, evidence-sample, classify, and verify findings in a way that holds up at the closing meeting and again at the next surveillance audit. The checklist below is written for the auditor on the floor — it covers the six steps a process audit actually runs through, with the clause, the deliverable, and the auditor-side decision rule for each.
1. Pre-audit document prep — ISO 9001:2015 §7.5 + §9.2.1 + §4.4
Every process audit starts here. Per §7.5 the QMS must maintain documented information; per §9.2.1 the audit program must identify the criteria, scope, frequency, methods, and responsibilities; per §4.4 the organization must determine the processes needed and their interaction. The auditor's pre-audit read builds the clause-by-clause evidence map and the audit-program schedule before opening meeting.
- ✓ Build the clause-by-clause evidence map. For §4–§10 row, name the documented information that satisfies it — quality manual, process interaction map, turtle diagram for each process, control-of-documented-information register, training matrix, calibration list, customer-complaint log. A gap in this map is the first clue the audit will not go well.
- ✓ Verify the §4.3 QMS scope statement and clause-exclusion register. A scope that excludes design and development but produces engineered-to-order parts is a problem — the exclusion must be justified against §8.3 absent-process applicability, not asserted.
- ✓ Walk the process interaction map and turtle diagrams. Each process needs inputs, outputs, controls, KPIs, owners, and supporting documented information — without the turtle diagram the auditor cannot evidence-trace a nonconformity to its process.
- ✓ Pull the §9.2 audit program and the prior audit reports. Audit program must be risk-tied (production vs. calibration vs. training), not time-tied, and prior reports carry the closure status and effectiveness verification per §10.2.
- ✓ Review the §10.2 corrective-action log. CARs open, closed, and overdue with effectiveness-verification records — overdue CARs are an automatic Major under §10.2.1 when ignored across multiple cycles.
- ✓ Pull customer complaints and the non-conformance register for the audit window. Both feed evidence collection on the floor — a process audit that misses recurring customer complaints cannot check the §9.1.3 analysis-and-evaluation cycle.
Common failure: the audit plan names the scope and the criteria but skips the evidence map. Result — the opening meeting reads as prepared but closing meeting runs into findings the team did not see, and the CAR package is short on root-cause analysis.
2. Opening meeting agenda — ISO 19011:2018 §6.4.2 + §6.3
The opening meeting is not a courtesy call. Per ISO 19011:2018 §6.4.2 the auditor confirms the audit plan, scope, criteria, methods, and schedule with the auditee; per §6.3 the audit methods must be selected to ensure effective and reliable audit results. The opening meeting sets the daily standup cadence and communication rules used throughout the audit.
- ✓ Confirm scope, criteria, and method. State the process — production, calibration, training, document control — and the criteria (ISO 9001:2015 + the auditee's own procedures). Method: documented-information review, observation, interview per ISO 19011 §6.3.4.
- ✓ Walk the audit plan and the schedule. List the order — opening meeting, evidence collection, daily standup, closing meeting — and tie each step to the named process or clause so the auditee can escort and answer.
- ✓ Communication rules and standup cadence. Daily 15-minute standup at the same time/place — usually between the auditor and the lead auditee — to surface findings-in-progress, evidence clarifications, and reveal any sampling shifts before the closing meeting.
- ✓ Confirm escorts and access. Floor, document control, calibration room, training files, customer-complaint log — auditor's right to access per §6.4.4 must be stated, not assumed.
- ✓ Confirm reporting language and timing. Findings classification (Major / Minor / OFI per ISO 19011 §6.4.3), evidence trails, and the corrective-action ownership window — typically 30 / 60 / 90 days per §10.2.1 — are stated up-front, not at closing meeting.
- ✓ Confidentiality and impartiality. ISO 19011 §5 confirms auditor impartiality, objectivity, and confidentiality — stated at opening meeting so the auditee knows what is and is not reportable outside the QMS.
Common failure: opening meeting covers only the schedule. Result — daily standup cadence is missing, finding classification slips to closing meeting, and the auditee has no chance to provide evidence in real time.
3. Evidence collection — triangulation across records, observation, and interview — ISO 19011:2018 §6.3.4 + §6.4.4
Evidence collection is the audit step. Per ISO 19011 §6.3.4 evidence is gathered by documented-information review, observation, and interview — and the auditor's job is to triangulate the three sources, not take the first one at face value. ISO 19011 §6.4.4 governs evidence collection: the auditor continues sampling until sufficient, reliable evidence supports the finding.
- ✓ Sample-by-sample walkthrough of one process end-to-end. Pick a single order, calibration record, or training event — pull the documented information, watch the same process on the floor, interview the operator. Triangulate the three sources for the same record.
- ✓ Records-vs-observed-vs-interview triangulation. A training matrix that says an operator is trained on a press but an interview reveals they have never run it is a finding; a calibration record dated last week but an observation of the dirty instrument on the bench is a finding. Triangulation is the audit step, not optional flavor.
- ✓ Competency matrix sampling for §7.2 + §7.3. Pull the competency matrix for one role, pick three names, cross-check training records, observed skill, and interview — the cross-check is what closes the §7.2 competence gap and the §7.3 awareness requirement.
- ✓ Document version control sample. Pull a documented-information revision, check the controlled-copy register, observe the floor copy — a controlled-copy rev 03 on the shelf but an obsolete rev 02 at the workbench is the wrong-version-classification-of-nc finding.
- ✓ Customer-complaint and recall sampling. Pick a recent customer complaint — check the §10.2.1 CAR log, the root-cause analysis, the action-taken record, and the verification of effectiveness. A complaint with no root cause or no verification is a Major.
- ✓ End the evidence collection when sufficiency is met. Per §6.4.4 the auditor stops when sufficient, reliable evidence supports the finding — and not before. Stopping early on a "looks good" is the failure mode that haunts the next surveillance audit.
4. Finding classification — Major / Minor / OFI — ISO 19011:2018 §6.4.3 + ISO 9001:2015 §10.2.1
Classification is the audit step where the most misreporting happens. Per ISO 19011 §6.4.3 a Major nonconformity raises doubt about the QMS's ability to provide conforming product; a Minor is an observed lapse that does not materially affect QMS output; an OFI (Opportunity for Improvement) is a flag for improvement without a clause failure or product impact. Each classification comes with a standard one-line action and a closure window.
- ✓ Major nonconformity (e.g. clause failure, missing process control, systemic lapse): A clause-§ non-satisfaction that affects the QMS's ability to provide conforming product or service. Example: a missed process control across multiple cells (no first-piece inspection on the floor, no documented procedure, no training-record proof). Standard action: §10.2.1 corrective action, root cause identified, action within 30 days, formal verification of effectiveness.
- ✓ Minor nonconformity (single observed lapse without clause failure): An isolated observed lapse that does not affect QMS output. Example: a single missing record on one document, an isolated training-record gap on one name, a one-time deviation with no impact. Standard action: §10.2 corrective action, root cause, action within 60 days, verification of effectiveness at next surveillance audit.
- ✓ OFI — Opportunity for Improvement (process weakness, no clause failure): A flag for a process weakness or inefficiency that does not rise to a nonconformity. Example: slower sampling rate on the floor than needed for the risk-tied audit program, an opportunity to strengthen the §9.2 program-level review. No formal action; tracked in the audit program.
- ✓ Decision rule: would the same finding repeat tomorrow in a different area? If yes → Major (systemic, not isolated). If no → Minor (single observed lapse). If it is neither — no clause failure, no product impact, but an improvement opportunity — classify as OFI.
- ✓ The Major / Minor pair is mutually exclusive. A clause failure is a Major. A single observed lapse is a Minor. Do not classify a §10.2.1 root-cause failure as "minor" — that misclassification is the audit-team's failure, not a finding-by-degree problem.
- ✓ Classify before the closing meeting. Findings classification is verified at the daily standup and confirmed in the closing meeting — surfacing new reasoning in the closing meeting erodes auditee trust and audit-program integrity.
5. Corrective-action ownership & target dates — ISO 9001:2015 §10.2.1 + §10.2.2
Corrective action is the audit's downstream deliverable, not the audit itself. Per §10.2.1 the organization must react to the nonconformity, evaluate the need for action, implement action, review effectiveness, and update risk/opportunity as needed. Per §10.2.2 the corrective action must be appropriate to the magnitude of the nonconformity and its effects. The corrective-action ownership ladder is 30 / 60 / 90 days by Major / Minor / overdue — not by calendar target.
- ✓ Root-cause analysis on every Nonconformity (Major and Minor). §10.2.1 requires root cause — 5-Why, Fishbone, or fault-tree analysis. A CAR without root cause cannot be verified for effectiveness and is the audit-team's signal that the closure window is at risk.
- ✓ CAR owner named and accepted — not manager-of-record. The owner is the role accountable for executing the action, with named backup. The manager-of-record signs off but does not own the action — ownership and accountability are different.
- ✓ Target-date ladder: 30 / 60 / 90 days. Major → 30 days. Minor → 60 days. Overdue (CAR open past one cycle) → 90-day re-assessment. The ladder is the closed loop, not a "we'll get back to it" promise.
- ✓ Verification-in-place: an action that proves it closed the gap. A CAR that says "updated procedure" without a re-audit of the floor is not a verification. The verification is the next §10.2 sample evidence — training records, observed control, observed interview — that proves the gap is closed.
- ✓ Documented information for every CAR. §10.2 requires records of the nature of the nonconformity, action taken, results of action taken, and verification of effectiveness — in the right section of the corrective-action log, not in a separate workbook.
- ✓ Audit-team review at the daily standup. The auditor confirms progress, surfacing slipping CARs at the daily standup is the audit-program check; no finding is "discovered late" because the closure cadence is a daily-standup item.
6. Verification of effectiveness (VoE) — ISO 9001:2015 §10.2.1(d) + §9.2
Verification of effectiveness is the audit step that closes the loop — and is, in the audit-team's experience, the most-missed step in the corrective-action chain. Per §10.2.1(d) the organization must review the effectiveness of any action taken; per §9.2 the audit program must verify that the QMS remains effective. VoE happens before the next surveillance audit — not after — and operates on the same triangulation pattern as the audit itself.
- ✓ Auditor-side review cycle. The auditor's VoE cycle is a re-sample of the same §9.2 evidence sources — documented information review, observation, interview — at the next audit, with the same triangulation pattern as Step 3 above.
- ✓ Re-qualification of evidence (records, observed, interview). The next audit must pull the same records the prior CAR fix touched — a CAR proven on a spreadsheet but not at the workbench is not closed.
- ✓ Closing the loop before the next surveillance audit. VoE is verified at the next surveillance, not "later" — a CAR with no VoE at the next surveillance is a 10.2.1 non-satisfaction and a new finding types in the next audit report.
- ✓ VoE recorded in documented information. §10.2.1(d) requires documented information on the effectiveness of the action — a note in the corrective-action log columns: "VoE verified at next surveillance, [auditor], [date]" — not in a separate report.
- ✓ Risk and opportunity updated. §6.1 requires the organization to address risk and opportunity — a CAR that closes the gap but does not update the §6.1 risk register is a process-control gap that an OFI will catch at the next surveillance.
- ✓ Continuous improvement for §10.3. Findings and OFIs feed the §10.3 continual-improvement loop — a closed finding is not the end of the audit chain, it is the input to the next risk-based audit program.
The six-step checklist above is the audit-team framework — but it still needs to be keyed to the actual nonconformity log, the corrective-action ownership, and the §10.2 verification of effectiveness on a real floor. That is the work of an audit-finding workflow — and the practical layered tool is one that: