TrustCloud launches native ServiceNow application to deliver enterprise-grade continuous control monitoring. Read more →

ISO 9001 FAQ

Estimated reading: 2 minutes 2297 views

The standard requires an Internal Audit to be carried out before an external audit is performed.

The Internal Audit must be carried out by a competent and objective auditor.

The auditor can be in-house (from the organization’s own staff) or an external consultant. If in house, it is important that the auditor is independent and has no prior or current involvement in the development and implementation of the QMS.

The Internal Audit review includes:

  1. A documentation review of policies and procedures to confirm they adhere to the requirements of the standards
  2. An evidence review through sampling and analysis to determine that the policies are being adhered to

Any findings from the Internal Audit must be tracked to resolution.

The internal audit is meant to be continuous throughout the certification period (3 years).

An external audit is essentially the same as an internal audit, except that the outcome is the acquisition of certification. 

The external audit starts with stages 1 and 2.

Stage 1: This consists of an extensive documentation review of your QMS program. This typically lasts a couple of hours to a day.

The outcome of Stage 1 is a list of findings (non-conformities) that need to be remediated before moving on to Stage 2.

Stage 2: Consists of an extensive review of evidence that supports the documentation provided during Stage 1 to confirm that the controls operate according to the ISO 9001 requirements. This takes a bit more time than Stage 1 and can last a couple of days to a week.

The outcome of stage 2 is a list of findings (non-conformities) that would need to be remediated before being recommended for certification.

An ISO 9001 certification is valid for three years.

ISO requires surveillance audits to be performed each year to ensure the QMS program and controls continue to operate effectively.

Join the conversation

You might also be interested in

Strengthen security with smart data breach response practices

Learn proactive data breach response strategies to protect your business. Boost cybersecurity, reduce risk,...

Digital transformation in governance: strategies for success in 2026

Digital transformation in governance is driven by the increasing demand for improved government services...

Access control policies for strong data security in 2026

Learn how ideal access control policies protect sensitive data, enforce user roles, and ensure...

Powerful benefits of decentralized governance in 2026

Explore how blockchain powers decentralized governance. Learn its impact on control, trust, and compliance...

NIST password guidelines 2026: what you need to know to stay secure

With a proactive and comprehensive approach, you can unlock the future of cybersecurity and...

How to implement a data classification policy in 2026

Learn how to implement a data classification policy to protect sensitive information, ensure compliance,...

ISO 27001 toolkit: Essential tools and templates to simplify compliance in 2026

Looking to achieve ISO 27001 compliance faster? Explore this curated ISO 27001 compliance toolkit...

Transforming healthcare compliance: Top benefits of automation in 2026

Discover how automation enhances healthcare compliance by reducing errors, saving time, and ensuring data...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue