NEWS

ISO Clauses Explained: What Do Auditors Look For?

What do ISO Clauses 4–10 actually mean? What evidence will an ISO auditor expect to see? How can you tell whether your organisation is properly prepared for its next audit?

These are questions we are hearing increasingly often from clients.

The terminology used in an ISO management system standard can initially seem complicated. However, Clauses 4–10 follow a logical sequence. Together, they describe how an organisation should understand its risks, plan its activities, control its work, evaluate its performance and continually improve.

This practical guide provides the main ISO clauses explained in straightforward business language.

Which ISO standards use Clauses 4–10?

The common management system structure is used across standards including:

Although the subject and detailed requirements differ between standards, their compatible structure makes it easier for organisations to develop an Integrated Management System.

Clause 4: Context of the Organisation

Clause 4 is the starting point for an effective ISO management system.

The organisation should understand what it does, the environment in which it operates and the internal and external issues that could affect its intended results.

It must also identify relevant interested parties. Depending on the organisation, these could include customers, employees, regulators, contractors, certification bodies, shareholders or members of the local community.

An ISO auditor may ask:

  • What are the main internal and external issues affecting the organisation?
  • Who are your relevant interested parties?
  • What do those interested parties require or expect?
  • How was the scope of the management system determined?
  • When was this information last reviewed?

The answers should reflect the organisation as it operates today. Context should be reviewed when there are significant changes to the business, its market, legislation, technology, workforce or activities.

Clause 5: Leadership

Clause 5 requires top management to demonstrate leadership and commitment.

An ISO management system should not be treated as the sole responsibility of the QHSE Manager or one nominated employee. Senior leaders must ensure that the system supports the organisation’s strategic direction and is integrated into normal business activities.

An auditor may look for:

  • A clear and appropriate policy
  • Defined responsibilities and authorities
  • Senior management involvement in objectives and management reviews
  • Evidence that resources are provided
  • Leadership awareness of significant risks and performance issues
  • Effective communication about the importance of the management system

Visible leadership is about involvement and decision-making—not simply signing a policy once a year.

Clause 6: Planning

Clause 6 asks the organisation to consider what could affect its intended results.

This includes identifying relevant risks and opportunities, deciding what action is required and establishing measurable objectives.

Depending on the standard, planning may also include environmental aspects, health and safety hazards, information security risks, compliance obligations or risks affecting product and service quality.

An ISO auditor may ask:

  • How are risks and opportunities identified and reviewed?
  • What actions have been taken to address them?
  • What objectives has the organisation established?
  • Who is responsible for achieving each objective?
  • How is progress measured?
  • How are changes to the management system planned?

Objectives should be meaningful to the organisation rather than created simply to satisfy an audit.

Clause 7: Support

Clause 7 covers the people, resources and information needed to make the management system work.

This includes competence, awareness, communication, infrastructure, organisational knowledge and controlled documented information.

Typical audit evidence may include:

  • Training and competence records
  • Qualifications and authorisations
  • Induction and awareness records
  • Maintenance or calibration records
  • Internal and external communications
  • Controlled procedures, forms and records
  • Evidence that employees understand relevant policies and objectives

Having attended a course does not automatically demonstrate competence. Organisations should also consider whether employees can apply their knowledge effectively in their role.

Clause 8: Operation

Clause 8 is where planning is converted into controlled day-to-day activity.

The exact requirements vary between ISO standards, but the general purpose is to ensure that operational activities are planned, implemented and controlled.

Evidence might include:

  • Project or service-delivery plans
  • Risk assessments and safe systems of work
  • Inspection and testing records
  • Supplier and contractor controls
  • Purchasing and procurement records
  • Change-management records
  • Emergency arrangements
  • Customer requirements and contract reviews
  • Information security or environmental operational controls

An auditor will often follow a process from beginning to end to establish whether requirements are understood and consistently applied.

Clause 9: Performance Evaluation

Clause 9 asks a fundamental question: how does the organisation know whether its management system is working?

The organisation should monitor relevant performance, evaluate compliance where applicable, conduct internal audits and complete management reviews.

An ISO auditor may examine:

  • Key performance indicators
  • Progress against objectives
  • Customer feedback and complaints
  • Environmental, safety, quality or security performance data
  • Internal audit reports
  • Corrective-action records
  • Management-review inputs and decisions
  • Evidence that previous actions have been completed

Internal audits should provide an honest assessment of the system. They should identify weaknesses and opportunities before they become larger problems or external-audit findings.

Clause 10: Improvement

Clause 10 focuses on responding to problems and continually improving the management system.

When a nonconformity or incident occurs, the organisation should correct the immediate issue, investigate why it happened and take proportionate action to prevent recurrence.

Auditors may ask:

  • What nonconformities or problems have recently been identified?
  • What immediate correction was completed?
  • How was the root cause determined?
  • What corrective action was taken?
  • Was the action checked for effectiveness?
  • What improvements have been made since the previous audit?

Continual improvement does not always require a major project. It can include simplifying a process, improving training, strengthening controls, reducing errors or acting on employee and customer feedback.

What evidence does an (Certification Body or Vendor) ISO auditor expect?

An ISO audit is not a memory test, and auditors should not be looking for paperwork purely for the sake of paperwork.

They are looking for objective evidence that the management system is understood, implemented and effective.

Useful evidence is often already generated through normal business activities, including:

  • Completed records and forms
  • Meeting minutes
  • Training and competence records
  • Inspections and audits
  • Performance data
  • Customer feedback
  • Risk assessments
  • Corrective actions
  • Discussions with employees and managers

The auditor may speak to employees in different roles to establish whether the arrangements described in procedures are reflected in everyday practice.

The ISO clauses form one connected system

A common mistake is to treat each ISO clause as a separate folder, procedure or audit subject.

In reality, the clauses should connect.

The organisation’s context influences its risks and objectives. Leadership provides direction and resources. Support arrangements enable people to perform the work. Operational controls manage service delivery. Audits and performance reviews establish whether the controls are effective. Corrective action and improvement then strengthen the system.

A well-designed management system should reflect how the organisation genuinely operates. It should help the business control risk, maintain consistency, meet requirements and improve performance—not create unnecessary paperwork.

Frequently asked questions about ISO audits

Do we need a separate procedure for every ISO clause?

No. ISO standards do not generally require a separate procedure for every clause. Your documented information should be appropriate to the size, complexity, risks and activities of your organisation.

Will an ISO auditor interview employees?

Yes. Auditors commonly speak to employees and managers to confirm that responsibilities, risks, controls and relevant procedures are understood and applied.

What happens if an auditor identifies a nonconformity?

The organisation will normally be required to correct the issue, investigate its cause and submit suitable corrective action. The timescale and follow-up process will depend on the type and significance of the finding.

How often should internal ISO audits be completed?

Internal audits must be completed at planned intervals. The audit programme should take account of the importance and risk of each process, organisational changes and the results of previous audits.

Can QHSE Aberdeen help us prepare for an ISO audit?

Yes. QHSE Aberdeen provides ISO consultancy, internal audits, gap analyses, management-system development and audit preparation support for organisations in Aberdeen, across Scotland and further afield.

Preparing for an ISO audit?

If you are unsure about a particular ISO clause, concerned about an upcoming audit or simply want reassurance that your management system remains effective, QHSE Aberdeen can help.

Our experienced Lead Auditors support organisations with:

  • ISO 9001 quality management systems
  • ISO 14001 environmental management systems
  • ISO 45001 health and safety management systems
  • ISO 27001 information security management systems
  • Integrated Management Systems
  • Internal audits and supplier audits
  • Gap analyses and certification preparation
  • Ongoing and fractional QHSE support

Contact QHSE Aberdeen to arrange an initial discussion about your management system and the support your organisation needs.

Share:

Archives

Recent Posts