How do companies prepare for an ISO 9001 certification audit and maintain conformity across the surveillance audits?
We support both initial certification and recertification to ISO 9001:2015: from the gap analysis through building the process-oriented QM system to preparing for the certification body's stage 1 and stage 2 audit. The hurdle is rarely the standard itself, but the gap between the documented and the lived system: a QMS that is only activated at audit time gets flagged in the first surveillance audit, because the internal audit per clause 9.2 produces no genuine findings.
- Pharma
- Biotech
- MedTech
- IVD
Overview
What does ISO 9001:2015 require of the audit?
Support for initial certification and recertification · ISO 9001:2015, risk-based thinking per clause 6.1, internal audit per clause 9.2
Last updated: 2026-06-13
ISO 9001:2015 is the most widely adopted quality management standard and, across pharma, biotech, medtech and IVD, it is frequently the foundation on which industry-specific systems are built. The high-level structure of the 2015 revision shifted the emphasis: it is no longer the completeness of documents that is decisive, but the evidence that the system is effective. The points where preparation most often stalls:
- Risk-based thinking per clause 6.1 is required as a logic running throughout the system, not as a separate risk register; the certification body checks whether risks and opportunities feed into process control.
- The context of the organization and the interested parties per clause 4 must be determined and related to the scope of the QMS; this entry point of every audit is frequently treated superficially.
- The internal audit per clause 9.2 and the management review per clause 9.3 are evidence of effectiveness: without substantive findings and traceable management decisions, a gap forms that surfaces in the surveillance audit.
- Control of externally provided processes per clause 8.4 calls for the evaluation and monitoring of suppliers and contractors; a recurring finding area when outsourced activities are not captured.
Services
How we support you
ISO 9001 Gap Analysis
A structured target-versus-actual comparison of the existing QMS against all requirements of ISO 9001:2015. The result is a prioritized action plan that maps every gap to a clause of the standard and to a responsible function.
QMS Setup & Process Documentation
Building or reworking the process-oriented QM system to ISO 9001:2015: quality policy, quality objectives, a process map with interactions, and the documented information the standard requires. The deliverable is a system that matches lived practice.
Risk-Based Thinking & Context Analysis
Determining the context and the interested parties per clause 4 and embedding risk-based thinking per clause 6.1 into process control. The deliverable is the traceable linkage of risks, opportunities and actions for each process.
Internal Audit Program & Auditor Training
Building an effective internal audit program per clause 9.2 along the guidelines of ISO 19011: audit program, audit plan, process-specific checklists, and training of internal auditors. The deliverable is documented audit reports with actionable findings.
Audit Preparation & Mock Audit
Preparation for the two-stage certification audit: a mock audit under realistic audit conditions, coaching of key personnel, and a walkthrough of typical auditor questions. The deliverable is a mock audit findings report with corrective actions ahead of the stage 2 date.
Learn more →Corrective Actions & Continual Improvement
Addressing nonconformities per clause 10 and establishing an ongoing improvement process so that the QMS is maintained between audits. The deliverable is a traceable action status for the management review.
Learn more →How we work together
What it comes down to
The standard ISO 9001:2015, with its high-level structure, calls less for additional documents than for evidence that the system is effective. Three strands have to fit together, and in the right order: the context of the organization per clause 4 sets the scope. Risk-based thinking per clause 6.1 must, derived from that context, feed into the control of every process. And the internal audit per clause 9.2, together with the management review per clause 9.3, must demonstrate that this control actually takes hold. Set the internal audit up too late and without substantive findings, and you lose the evidence of effectiveness as your bottleneck, and that is exactly what the certification body examines first in the stage 2 audit.
This is precisely where we come in: at the outset, the gap analysis makes visible which strand is critical, before the QM system is documented and the audit date is booked. The mock audit moves the correction loops forward, to where findings are cheap and can be resolved without time pressure, rather than into the certification audit, where a single nonconformity puts the date at risk. The result is a system that reflects practice and holds up even in the first surveillance audit, instead of functioning only at the moment of certification.
Our approach
Our approach
Step
Result
Gap Analysis
Prioritized action list: where the QMS stands against ISO 9001:2015, what is critical, what is effort.
Context & Risk Logic
Context and interested parties determined per clause 4, risk-based thinking per clause 6.1 embedded in process control.
QMS Setup
Process-oriented system with quality policy, objectives, process map and documented information, aligned with lived practice.
Internal Audit & Management Review
Internal audit conducted per clause 9.2 with actionable findings and management review per clause 9.3.
Mock Audit & Correction
Mock audit findings report, corrective actions completed ahead of the certification date.
Stage 1 & Stage 2 Audit
Supported two-stage certification audit, structured handling of audit findings through to issuance of the certificate.
Common pitfalls
Where projects commonly fail
The QMS is only activated at audit time.
If the system is not maintained between audits, the annual surveillance audits expose gaps that have accumulated over months; this is the most common cause of nonconformities at recertification.
Risk-based thinking per clause 6.1 is filed away as a separate risk register instead of feeding into process control.
The certification body asks, for each process, about risks, opportunities and the actions derived from them; an isolated document does not satisfy this.
The internal audit per clause 9.2 is carried out as a box-ticking exercise without substantive findings.
An internal audit program that never finds a genuine nonconformity is itself a finding for the auditors and calls the effectiveness of the entire system into question.
Control of externally provided processes per clause 8.4 is underestimated.
Outsourced activities, suppliers and contractors are missing from the evaluation; the audit reveals that neither criteria nor monitoring are documented for these processes.
The process documentation describes an ideal state that is not lived.
At the stage 2 audit, the certification body checks implementation through on-site interviews and sampling; where practice diverges from the documentation, nonconformities arise that remain invisible in the document review.
FAQ
Frequently asked questions
Sources
- ISO 9001:2015: Quality management systems, Requirements (primary text, clauses 4, 6.1, 8.4, 9.2, 9.3, 10)
- ISO 19011: Guidelines for auditing management systems
- ISO 13485: Quality management systems for medical devices (distinction)
- https://theentourage.de/quality-management-operational-excellence/iso-9001-audit/ (existing page content, revised)
Life Science Journal
Regulatory updates, straight to your inbox.
New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.
Case Studies
What this looks like in practice
Related insights
All insights →Regulations & standards considered
- ISO 9001:2015 (Quality management systems: Requirements)
- ISO 9001:2015 clause 4 (Context of the organization, interested parties)
- ISO 9001:2015 clause 6.1 (Risk-based thinking)
- ISO 9001:2015 clause 8.4 (Control of externally provided processes, products and services)
- ISO 9001:2015 clause 9.2 (Internal audit)
- ISO 9001:2015 clause 9.3 (Management review)
- ISO 9001:2015 clause 10 (Improvement, corrective action)
- ISO 13485 (QM system for medical devices, distinction)
- ISO 19011 (Guidelines for auditing management systems)
Related topics
ISO Audit Consulting →
ISO 13485 specifically for medical devices as a counterpoint to the cross-industry ISO 9001
Quality Management →
QMS design and implementation as the foundation of certification
Mock Audits →
Audit simulation under realistic conditions ahead of the stage 2 date
Continuous Improvement Programs →
Ongoing QMS maintenance per clause 10 between the surveillance audits
Have a concrete project?
Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.
Prefer direct? +49 89 4161170-0
info@theentourage.de
- Reply usually within one working day
- 4 offices: DE · CH · IT · US
- 100% life sciences


