ISO 9001 Expert · a Certify Consulting service

ISO 9001:2015 Readiness Checklist

A 40-item self-assessment across all seven auditable clauses

Prepared by Jared Clark, CPGP, PMP, CMQ-OE

How to score this

Work through it with the person who would actually be answering an auditor's questions — not alone at a desk. For each item score 2 if it is fully in place and you could show evidence today, 1 if it partially exists or exists without evidence, and 0 if it does not. Maximum score is 80.

The single most useful output is not the total — it is which clause scores lowest. That is where your certification timeline is actually set.

Clause 4 — Context of the Organization

5 items · max 10 pts

Why your QMS exists and what it covers

# Requirement Yes
2
Part
1
No
0
1
You have identified the external and internal issues relevant to your purpose and strategic direction — and you revisit them, rather than having written them once at certification.
Clause 4.1
2
You have identified your interested parties (customers, regulators, owners, suppliers, employees) and determined which of their requirements are relevant to the QMS.
Clause 4.2
3
The scope of your QMS is documented and available, states the products and services covered, and justifies any requirement you have determined is not applicable.
Clause 4.3
4
Your QMS processes are identified, including their inputs, outputs, sequence, and interactions — typically as a process map or turtle diagrams.
Clause 4.4.1
5
For each process you have determined the criteria, methods, and performance indicators needed to ensure it operates effectively, and assigned responsibilities for it.
Clause 4.4.1
Section score / 10

Clause 5 — Leadership

5 items · max 10 pts

What top management must own personally

# Requirement Yes
2
Part
1
No
0
6
Top management can personally demonstrate accountability for the effectiveness of the QMS — it is not wholly delegated to a quality manager or consultant.
Clause 5.1.1
7
QMS requirements are integrated into your business processes rather than running as a parallel 'quality system' that only appears at audit time.
Clause 5.1.1
8
Customer requirements and applicable statutory and regulatory requirements are determined, understood, and consistently met, with risks to conformity addressed.
Clause 5.1.2
9
A quality policy exists that is appropriate to your context, includes commitments to satisfy applicable requirements and continually improve, and is communicated and understood.
Clause 5.2
10
Roles, responsibilities, and authorities relevant to the QMS are assigned, documented, communicated, and understood by the people who actually hold them.
Clause 5.3
Section score / 10

Clause 6 — Planning

5 items · max 10 pts

Risk, objectives, and managing change

# Requirement Yes
2
Part
1
No
0
11
You have determined the risks and opportunities that could affect conformity of products and services and the ability to enhance customer satisfaction.
Clause 6.1.1
12
Actions to address those risks and opportunities are planned, integrated into your QMS processes, and evaluated afterwards for effectiveness.
Clause 6.1.2
13
Quality objectives are established at relevant functions and levels, are measurable, consistent with the quality policy, monitored, and updated as needed.
Clause 6.2.1
14
For each objective you have documented what will be done, what resources are required, who is responsible, when it will be complete, and how results will be evaluated.
Clause 6.2.2
15
Changes to the QMS are carried out in a planned manner — considering purpose and consequences, integrity of the system, resource availability, and reallocation of authority.
Clause 6.3
Section score / 10

Clause 7 — Support

7 items · max 14 pts

People, infrastructure, knowledge, and documents

# Requirement Yes
2
Part
1
No
0
16
The people necessary for effective operation of the QMS and control of its processes are determined and provided.
Clause 7.1.2
17
The infrastructure and the process environment (physical, social, psychological) needed to achieve conformity are determined, provided, and maintained.
Clause 7.1.3–4
18
Monitoring and measuring resources are suitable, verified or calibrated against traceable standards at defined intervals, safeguarded, and records are retained.
Clause 7.1.5
19
The organizational knowledge necessary to operate your processes is determined, maintained, and made available — including how you will acquire knowledge you lack.
Clause 7.1.6
20
Competence requirements are defined for roles affecting QMS performance, people are competent on the basis of education, training, or experience, and evidence is retained.
Clause 7.2
21
People are aware of the quality policy, relevant objectives, their contribution, and the implications of not conforming; internal and external communications are determined.
Clause 7.3–7.4
22
Documented information required by the standard and by your QMS is controlled — identified, reviewed and approved, version-controlled, available where needed, and protected.
Clause 7.5
Section score / 14

Clause 8 — Operation

9 items · max 18 pts

The work itself — the largest clause, and the most audited

# Requirement Yes
2
Part
1
No
0
23
Operational processes are planned and controlled with defined acceptance criteria, and documented information is retained sufficient to show the processes ran as planned.
Clause 8.1
24
Customer communication covers product and service information, enquiries and order changes, feedback and complaints, customer property, and contingency requirements.
Clause 8.2.1
25
Requirements for products and services are determined and reviewed before you commit to supply, and you can demonstrably meet the claims you make.
Clause 8.2.2–3
26
When requirements for products and services change, relevant documented information is amended and relevant people are made aware of the changed requirements.
Clause 8.2.4
27
Design and development is controlled across planning, inputs, controls, outputs, and changes — or is formally excluded and justified in your documented scope.
Clause 8.3
28
Externally provided processes, products, and services are controlled: suppliers are evaluated and selected against defined criteria, and re-evaluated on performance.
Clause 8.4
29
Production and service provision is carried out under controlled conditions, with identification and traceability applied where it is a requirement.
Clause 8.5.1–2
30
Customer and external-provider property is safeguarded, outputs are preserved, post-delivery obligations are met, and changes are reviewed and controlled with records.
Clause 8.5.3–6
31
Products and services are released only after planned arrangements are satisfactorily completed; nonconforming outputs are identified, controlled, and dispositioned with records.
Clause 8.6–8.7
Section score / 18

Clause 9 — Performance Evaluation

5 items · max 10 pts

Proving the system works

# Requirement Yes
2
Part
1
No
0
32
You have determined what needs to be monitored and measured, the methods used, when it is performed, and when the results are analysed and evaluated.
Clause 9.1.1
33
Customer satisfaction — their perception of whether needs and expectations are met — is monitored, with defined methods for obtaining, monitoring, and reviewing it.
Clause 9.1.2
34
Data is analysed and evaluated to assess conformity, customer satisfaction, QMS performance, effectiveness of actions on risk, and external provider performance.
Clause 9.1.3
35
An internal audit programme runs at planned intervals, covers all QMS requirements and ISO 9001 itself, uses impartial auditors, and retains results as evidence.
Clause 9.2
36
Management review is conducted at planned intervals against the full required agenda, and produces documented decisions on improvement, change needs, and resources.
Clause 9.3
Section score / 10

Clause 10 — Improvement

4 items · max 8 pts

Closing the loop

# Requirement Yes
2
Part
1
No
0
37
Opportunities for improvement are determined and selected, including improving products and services to meet requirements and to address future needs and expectations.
Clause 10.1
38
Nonconformities are reacted to and corrected, evaluated for underlying cause, and reviewed for whether similar nonconformities exist or could potentially occur elsewhere.
Clause 10.2.1
39
Documented information is retained on the nature of nonconformities, any subsequent actions taken, and the results of every corrective action.
Clause 10.2.2
40
The suitability, adequacy, and effectiveness of the QMS is continually improved using analysis results, evaluation outputs, and management review outputs.
Clause 10.3
Section score / 8

Interpreting your score

Total score / 80
68–80 Certification-ready Your system is materially complete. The gap to certification is usually evidence depth, not system design. Schedule your Stage 1 audit and spend the interval building the records that prove the system has been running.
52–67 Close — targeted gap closure The architecture is there and most processes are defined. Expect 2–4 months of focused work, concentrated in whichever clause scored lowest. Do not schedule a registrar until your first full internal audit and management review are complete.
32–51 Foundations exist, gaps are systematic You have real processes but the QMS layer is partial — usually strong operations (Clause 8) with thin planning and evaluation (Clauses 6 and 9). Expect 4–8 months. Start with the process map and internal audit programme.
0–31 Early — build before you book Certification is 8–12 months out. Booking a registrar now spends money to be told what this checklist already told you. Build the system first; the audit should confirm what you already know.

Where certification audits actually go wrong

Across the systems I have taken through certification, findings cluster in the same five places. If you scored 1 or 0 on any of these, treat it as a priority regardless of your total.

  • Item 35 — internal audit — Audits that check paperwork exists rather than whether the process works, or auditors auditing their own area.
  • Item 36 — management review — Held, but missing required agenda inputs, or producing minutes with no decisions attached.
  • Item 12 — risk actions — Risks identified in a register that is never revisited, with no evaluation of whether the actions worked.
  • Item 28 — supplier control — Approved supplier list exists; the evaluation criteria behind it and the re-evaluation on performance do not.
  • Item 20 — competence — Training attendance records mistaken for competence evidence — attendance is not demonstrated capability.

Want a second opinion on your score?

Send me your section scores and I will tell you — free — which gap is actually on your critical path and roughly how long closing it takes. No pitch deck.

Send me your scores

This checklist paraphrases the requirements of ISO 9001:2015 for self-assessment purposes and is not a substitute for the standard itself, which must be purchased from ISO or your national standards body. Clause references are provided so you can read the source text alongside it.