What this is
What is an ISO 9001 readiness audit?
What is an ISO 9001 readiness audit?
An internal audit that scores your quality management system against ISO 9001:2015 clauses before a certification body arrives for a certification or surveillance visit. It combines a clause-by-clause conformance check with time on the production floor, because the two frequently disagree.
Who should carry it out?
A trained internal auditor who is independent of the process being audited, not the person who owns day-to-day management of the QMS. Independence matters because the audit exists to catch what the owning team has stopped seeing, and an auditor reviewing their own work tends to reproduce the same blind spots.
How does it differ from the certification audit itself?
The certification audit is performed by an accredited certification body against ISO/IEC 17021-1 requirements and results in a certificate or a nonconformance. The readiness audit is an internal rehearsal: it predicts the likely outcome and buys time to close gaps, but it carries no accreditation status and satisfies no external requirement on its own.
Scope
When is an iso 9001 readiness audit required?
This audit is one step in the Scheme Certification Readiness programme, sitting alongside the SQF and BRC readiness audits for the same certification cycle. Using it to cover a different scheme's requirements produces a record that satisfies neither auditor.
Use this template when
- Pre-certification, ahead of the initial ISO 9001 certification audit
- Ahead of an annual surveillance visit from the certification body
- After a finding elsewhere suggests a systemic QMS gap, as a gap analysis
- Following a nonconformance from a previous certification or surveillance visit
- On the fixed annual internal audit schedule, independent of any external visit
Do not use it for
- SQF Readiness Audit, which audits your site against the SQF code rather than ISO 9001 clauses.
- BRC Readiness Audit, which audits your site against the BRCGS standard ahead of certification.
- Annual Product Review, which reviews one product's yearly performance, not the management system as a whole.
- The certification audit itself, which only an accredited certification body can perform.
- A single process audit, which examines one process in depth rather than overall QMS readiness.
Compliance mapping
Which ISO 9001:2015 requirements does this satisfy?
ISO 9001 does not name a readiness audit by title; clause 9.2 requires an internal audit programme, and a readiness audit is how many organisations discharge part of that requirement in the run-up to a certification event.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 9001:2015 cl.4.1 | Determine internal and external issues relevant to the organisation's purpose and QMS direction | ISO 9001 specific |
| ISO 9001:2015 cl.6.1 | Actions to address risks and opportunities, applied with a real decision trail behind them | ISO 9001 specific |
| ISO 9001:2015 cl.6.2 | Quality objectives established, measurable, and monitored | ISO 9001 specific |
| ISO 9001:2015 cl.9.1 | Monitoring, measurement, analysis and evaluation, including customer satisfaction | ISO 9001 specific |
| ISO 9001:2015 cl.9.2 | Internal audit programme planned, implemented and maintained across the QMS | ISO 9001 specific |
| ISO 9001:2015 cl.9.3 | Management review conducted at planned intervals with defined inputs | ISO 9001 specific |
| ISO 9001:2015 cl.7.2 | Competence determined, and evidenced by what people can actually demonstrate | Practice versus paperwork |
| ISO 9001:2015 cl.7.5 | Documented information created, updated and controlled | ISO 9001 specific |
What it does not cover
- SQF Readiness Audit, which is the distinct instrument for the SQF code and its own certification cycle.
- BRC Readiness Audit, which is the distinct instrument for the BRCGS standard.
- Annual Product Review, which reviews one product's performance over a year rather than the management system.
- The certification audit, which only an accredited certification body performing to ISO/IEC 17021-1 can carry out.
- Corrective action itself, which belongs in the CAPA record raised from a finding, not in the audit that raised it.
Global
ISO 9001 Readiness Audit requirements by country
ISO 9001 is a voluntary international standard with no statutory force in most markets. What varies is who accredits the certification body, and how much weight a certificate without that accreditation carries.
ANAB accreditation (ANSI-ASQ National Accreditation Board) under ISO/IEC 17021-1
No federal requirement to hold ISO 9001, but defense, aerospace and automotive supply chains frequently require it, or a sector derivative, contractually.
A nonconformance found in a readiness audit is a contract-continuity risk to the supply chain relationship, not a regulatory citation.
UKAS accreditation under ISO/IEC 17021-1
Certification bodies are accredited by UKAS, and public sector procurement frequently specifies UKAS-accredited certification specifically.
A certificate from a non-UKAS-accredited body may not satisfy a public tender even though the underlying standard is identical.
ISO 9001:2015 and the IAF Multilateral Recognition Arrangement
Certification decisions from accreditation bodies that are IAF MLA signatories are recognised across signatory countries.
Consistency rests on accreditation body oversight rather than any single government, which is why the readiness audit tests against the standard's own clauses.
How to complete it
How to complete an iso 9001 readiness audit, step by step
The template captures a clause-by-clause score accurately enough. What decides whether that score means anything is whether the auditor scored what they saw, not what the documentation promised.
Weighted percent's value depends on the internal auditor resisting the temptation to grade the QMS as it's intended to work. Give Evidence Sighted and Conformance the same scepticism an accredited auditor would bring, or the score sits above the real audit result and the record teaches nothing.
Staff Could Explain Their Controls and Records Contemporaneous exist because a QMS that only lives in documents fails the moment an auditor asks an operator to describe it. Time in production should outweigh time in the document register when the two disagree.
Findings against internal audit programme adequacy or management review completeness are disproportionately likely to become certification nonconformances regardless of how well the rest of the system scores, because those two clauses are what prove the QMS manages itself rather than being managed from outside once a year.
Ready For Certification Audit should track Critical and Major Findings counts, not the headline score percent. A high weighted percent with one unresolved major finding is not ready, and recording it as such removes the only warning the schedule would have given.
What auditors find
Most common iso 9001 readiness audit findings
The readiness audit usually exists and is usually completed on schedule. What actually fails is the honesty of the scoring and the completeness of the clauses it tests.
| Finding | Clause | What fixes it |
|---|---|---|
| Context and interested parties documented as boilerplate, unchanged since the last certification cycle. | ISO 9001:2015 cl.4.1 | Interview top management and confirm the document reflects current issues, not last year's. |
| Management review inputs marked complete without the full input set: customer satisfaction, audit results, process performance and risk review. | ISO 9001:2015 cl.9.3 | Cross-check the review minutes against the full input list before marking the item complete. |
| Internal audit programme does not cover every clause or process within its own annual cycle. | ISO 9001:2015 cl.9.2 | Map the audit schedule against the full clause set and close any process left unaudited. |
| Staff interviewed on the floor could not explain the controls the documentation describes. | ISO 9001:2015 cl.7.2 | Retrain to the actual control and re-verify understanding before the certification date, not after. |
| Risk-based thinking evidenced only as a stated policy, with no risk register or decision trail behind it. | ISO 9001:2015 cl.6.1 | Show a decision that changed because of a documented risk assessment, not just a risk policy statement. |
| Ready For Certification Audit marked yes with open major findings still unresolved. | ISO 9001:2015 cl.10.2 | Gate the readiness decision on Critical and Major Findings counts, not on the overall score percent. |
Case in point
Case in point: the audit that scored the meeting, not the input
A mid-size fabricator ran its annual ISO 9001 readiness audit three weeks before a surveillance visit. The audit scored 91% weighted, every ISO 9001 specific item was marked Yes or Partly, Management Review Inputs Complete was ticked Yes because a meeting had been held and minuted, and Ready For Certification Audit was recorded as Yes.
The surveillance auditor asked to see the customer satisfaction data referenced in the management review minutes. It didn't exist as analysis, only a raw complaint count with no trend, no comparison to target, and no link to the corrective actions raised that year. The visit produced a major nonconformance against clause 9.3, on a system a readiness audit had scored at 91% three weeks earlier: the internal audit had tested whether the meeting happened, not whether the inputs it was supposed to review were actually present.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- QUA-079
- Archetype
- Audit
- Record ID
- AUD-2026-000
- Scoring
- Weighted percent
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 9001:2015
- Links
- Links Clause Register; feeds Finding
- Tags
- Certification, Quality
- Sections
- 5
- Fields
- 62
- Follow up fields
- 6
- Repeating sections
- 1
- Links out
- 5
Header
10 fieldsAudit ID*
Auto sequence. Format AUD-2026-00000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Audit Date*
Lead Auditor*
Auditor Trained And Independent*
- Yes3 pts
- No0 pts
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Standard Version*
Audit Scope*
Reason For Audit*
Pre-certification, surveillance preparation, gap analysis or post finding.
Modules audited
Repeats12 fieldsModule*
Clause Reference
Clause ID
Links to FDN-009 Clause ID
Requirement*
Requirement Type*
Evidence Sighted*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Evidence Type
Evidence Reference
Conformance*
- Conforms3 pts
- Partially conforms1 pt
- Does not conform0 pts
Finding Grade
- Critical0 pts
- Major1 pt
- Minor2 pts
- Observation3 pts
Finding ID
Links to FDN-015 Finding ID
Finding Detail
Practice versus paperwork
7 fieldsHalf The Audit Is On The Floor
Certification auditors spend most of their time in production, not in the office. Walk the site and talk to operators before you score anything.
Hours In Production Areas*
Staff Interviewed*
Staff Could Explain Their Controls*
- Most could3 pts
- Some could1 pt
- Few could0 pts
Practice Matches Documentation*
- Yes3 pts
- Partly1 pt
- No0 pts
Records Contemporaneous*
Records filled in at the time, not completed retrospectively before the audit.
- Yes3 pts
- Doubtful1 pt
- Clearly not0 pts
Gaps Detail
ISO 9001 specific
12 fieldsContext And Interested Parties Documented*
- Yes3 pts
- Partly1 pt
- No0 pts
Risk Based Thinking Evidenced*
Risk and opportunity thinking replaced preventive action in the 2015 revision.
- Yes3 pts
- Partly1 pt
- No0 pts
Quality Objectives Measurable*
- Yes3 pts
- Partly1 pt
- No0 pts
Process Approach Evident*
- Yes3 pts
- Partly1 pt
- No0 pts
Process Interactions Mapped*
- Yes3 pts
- Partly1 pt
- No0 pts
Performance Indicators In Use*
- Yes3 pts
- Partly1 pt
- No0 pts
Management Review Inputs Complete*
- Yes3 pts
- Partly1 pt
- No0 pts
Management Review ID
Links to CMP-014 Review ID
Internal Audit Programme Adequate*
- Yes3 pts
- Partly1 pt
- No0 pts
Documented Information Controlled*
- Yes3 pts
- Partly1 pt
- No0 pts
Competence Evidence Held*
- Yes3 pts
- Partly1 pt
- No0 pts
Customer Satisfaction Monitored*
- Yes3 pts
- Partly1 pt
- No0 pts
Result
21 fieldsItems Assessed*
Excludes anything marked N/A.
Items Failed*
Score Percent*
Calculated on submission. High is good. N/A items leave the denominator.
Result Band*
- Pass3 pts
- Caution1 pt
- Fail0 pts
Completeness Percent*
How much of the template was actually answered. A high score on a half completed form is not a high score.
Critical Findings*
Major Findings*
Minor Findings*
Predicted Grade*
- AA or A4 pts
- B3 pts
- C1 pt
- D or fail0 pts
Ready For Certification Audit*
- Yes3 pts
- With minor work2 pts
- No0 pts
Weeks Of Work Remaining
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Certification Audit Date
Next Readiness Audit
Lead Auditor*
Signature*
Site Manager*
Second Signature*
QUA-079 · record IDs look like AUD-2026-000 · Links Clause Register; feeds Finding
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The audit produces a score. What decides whether certification succeeds is whether the gaps it found actually close before the auditor arrives.
Holds the readiness audit library against the clause register, tracks the weighted percent across cycles, and flags a section whose score is drifting down.
Tracks the certification and surveillance schedule and links each finding's CAPA back to the clause it breaches.
Connects a competence finding, staff who couldn't explain their controls, to the training record that should close it.

Coordinates the crew, rolls open findings into one pre-certification view, and holds every write for your approval before it touches a record.
This template lives in KnowQuality — quality and food safety. HACCP, nonconformance, traceability, laboratory and customer complaints.
Meet KnowQuality→Glossary
ISO 9001 Readiness Audit definitions and key terms
- Certification body
- An accredited third party that audits an organisation against ISO 9001 and issues or withdraws the certificate, distinct from the internal readiness audit.
- Surveillance audit
- The periodic revisit a certification body performs between certification cycles to confirm the QMS is still being maintained, not just that it was compliant on the day of the original audit.
- Major nonconformance
- A finding indicating the QMS has failed to meet a requirement in a way that puts the whole system, or a customer requirement, at risk, and which typically must be closed before certification proceeds.
- Context of the organisation
- The clause 4.1 requirement to identify the internal and external issues that affect the QMS's ability to achieve its intended results.
- Risk-based thinking
- The clause 6.1 replacement for preventive action, requiring risks and opportunities to be identified and addressed through planning and decisions, not just documented as a policy.
FAQ
Frequently asked questions about iso 9001 readiness audit
What's the difference between the readiness audit and the certification audit itself?+
The readiness audit is internal and predictive; it exists to find gaps before an external party does. The certification audit is performed by an accredited certification body against ISO/IEC 17021-1 requirements, and its outcome is the certificate or a nonconformance that the readiness audit cannot substitute for.
Does a high readiness score guarantee we'll pass?+
No. A score built from document review alone can be high while the floor tells a different story, and management review inputs can be ticked complete without the actual analysis behind them existing. The score predicts the certification outcome only as well as the auditor scored what was actually there.
Who should do the readiness audit, internal or external?+
Internal, but independent of the process being audited. An external second opinion adds value close to certification, but the internal audit programme requirement in clause 9.2 exists precisely so the organisation can find its own gaps without paying for every check.
How often should we run it?+
Yearly at minimum, plus whenever a finding elsewhere suggests a systemic gap, ahead of a scheduled surveillance visit, or immediately after a prior nonconformance to confirm the fix held.
What happens if the readiness audit finds a critical gap close to the certification date?+
Ready For Certification Audit should be marked No or With minor work, and the certification date itself should be reviewed rather than proceeding on the hope the gap closes in time. A critical finding close to the date is a scheduling decision, not just a CAPA.
Does ISO 9001 require a formal readiness audit by name?+
No. Clause 9.2 requires an internal audit programme covering the QMS, and a readiness audit is one accepted way organisations discharge part of that requirement ahead of a certification event, not a named requirement in its own right.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Scheme Certification Readiness
External Audit Record
Records a certification body or customer audit, including findings and the response required
Customer Audit Record
Records a customer or second party audit, its findings and the response given
Unannounced Audit Readiness Check
Checks whether the site would pass an audit arriving today, covering records, standards and area condition
Certification Body Performance Review
Reviews the certification body on auditor consistency, technical competence, scheduling and value
SQF Readiness Audit
Audits your site against the SQF code before the certification body arrives
BRC Readiness Audit
Audits your site against the BRCGS standard ahead of certification

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 9001:2015 clauses 4.1, 6.1, 6.2, 7.2, 7.5, 9.1, 9.2 and 9.3
- ISO/IEC 17021-1:2015, requirements for bodies providing audit and certification of management systems
- IAF Mandatory Document MD 1, multilateral recognition arrangement
- UKAS accreditation criteria for management systems certification bodies
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.