ISO Certification Checklist: What Auditors Look For

Updated on: July 31, 2026

Published on: July 31, 2026 by Thai ISO Consultant Team

An ISO certification checklist covers seven areas: documentation, employee awareness, process implementation, records and evidence, internal audit history, management review, and corrective actions. Auditors check each area to confirm your system meets the ISO standard.

Getting ready for an ISO audit can feel stressful. Many Thai business owners ask the same question: what does the auditor actually check?

The answer is simple. ISO auditors follow a clear framework. They are not looking for perfection. They want proof that your system is real and working. Knowing what to expect puts your team in a much stronger position on audit day.

This ISO certification checklist covers every area the auditor will review. It lists the documents you need. It covers the questions your staff may be asked. It also explains the difference between a minor and major non-conformity. And it gives you a simple plan to get your team ready.

Thai ISO Certification works with Kingsmen Certification Services. Together, we support businesses across Thailand at every stage of the ISO certification process. This page supports our pillar guide on ISO Certification in Thailand.

What Is an ISO Auditor Actually Checking?

An ISO auditor has one job. They confirm that your management system meets the ISO standard.

To do that, auditors collect objective evidence. This is information that can be verified — records, data, or observations that show a process is working.

Auditors do not take your word for it. They check claims against audit evidence — documents, records, and interviews. Every finding must be backed by objective evidence before it is recorded.

The audit runs in two stages. Stage 1 is a document review. The auditor checks that your paperwork is complete. Stage 2 is the main audit. The auditor visits your site, talks to staff, and checks records.

In both stages, the auditor builds an audit trail. This links your policies to your procedures, and your procedures to your records. Gaps in that chain lead to auditor observations — or worse, non-conformities.

The Core ISO Certification Checklist

This ISO audit checklist covers every major area assessed during a certification audit. Use it as your readiness reference.

Area CheckedWhat the Auditor Looks For
DocumentationA quality policy, scope, objectives, and procedures that match your ISO standard. Documents must be current and easy for staff to access.
Employee AwarenessStaff must know the quality policy and their role. Auditors will ask them directly.
Process ImplementationProof that documented processes are followed in daily work. Auditors watch tasks and compare them to your written steps.
Records & EvidenceCompleted records showing processes have been done — training logs, checklists, and customer feedback.
Internal Audit HistoryA documented internal audit program with completed reports and findings for all key processes.
Management ReviewMeeting minutes showing leadership reviewed system performance, audit results, and improvement actions.
Corrective ActionsA log of issues and fixes, with proof that root causes were found and results were checked.

For a full breakdown of required documents, see our guide on Documents Required for ISO Certification.

Documents the Auditor Will Ask to See

The auditor will request documents at both Stage 1 and Stage 2. Missing documents can cause a non-conformity before the site visit even starts.

Have these ready for your ISO 9001 audit checklist review:

  • Quality Policy Statement — A signed policy showing your commitment to quality. It must be shared with all staff.
  • Procedures — Written steps for key processes like document control, internal auditing, and corrective action.
  • Training Records — Proof that staff have been trained. Include dates, topics, and attendance.
  • Internal Audit Reports — Completed reports covering all processes in your scope. Include findings and follow-up actions.
  • Management Review Minutes — Notes from leadership meetings. Show they reviewed system performance and improvement steps.
  • Corrective Action Log — A record of all issues, the actions taken, and checks that the fix worked.

Auditors may also ask for extra records based on your standard. For example, risk registers for ISO 9001 or hazard records for ISO 45001.

Questions Auditors Commonly Ask Employees

Employee interviews are a key part of what ISO auditors check. Auditors talk to staff at all levels — not just managers. Your team does not need to memorize documents. They just need to know their role.

Expect questions in these areas:

  • Policy awareness — “What is your quality policy?” or “What does it mean for your daily work?”
  • Role and responsibility — “What are your responsibilities?” or “Who do you report issues to?”
  • Process knowledge — “Walk me through how you do this task” or “What do you do if you find a problem?”
  • Nonconformity reporting — “Have you ever raised a non-conformity?” or “How would you report a failure?”
  • Improvement awareness — “Has anything changed in your process lately?” or “Do you know your team’s current goals?”

Uncertain answers create gaps in the audit trail. Brief your team before the audit. They need to know what they do, why they do it, and who to call if something goes wrong.

Minor vs Major Non-Conformity: What's the Difference?

Not every audit finding will stop your certification. It depends on the type of non-conformity found.

A minor non-conformity is a small, isolated gap. It does not mean a process has broken down. Examples: one missing training record or one outdated procedure. A minor non-conformity needs a corrective action plan. But certification can still move forward once the plan is accepted.

A major non-conformity is more serious. It means a required process is missing or not working. Examples: no internal audits done, or procedures that do not match what staff actually do. A major non-conformity means no certificate until the issue is fixed and verified.

An auditor observation is not a non-conformity. It is a note about something that could be improved.

The goal is simple. Remove all major non-conformities before the audit. Keep minor ones to a minimum. A mock audit is the best way to do this.

How to Prepare Your Team Before the Audit

Good preparation is not about writing new documents at the last minute. It is about checking that your system works — and fixing what does not.

Follow these steps before your certification audit:

  1. Run a mock audit
    Use your ISO certification checklist as the guide. Check every area the auditor will review. Write down all gaps — missing records, old procedures, or steps not being followed. This gives you a fix list before audit day.
  2. Brief employees on their roles
    Hold short briefings for all staff who may be interviewed. Cover the quality policy, their responsibilities, and how to report a non-conformity. Keep it simple.
  3. Review recent records
    Check that all records are complete, signed, and up to date. Focus on training logs and corrective action entries. Incomplete records are a top cause of minor non-conformities in an ISO 9001 audit checklist review.
  4. Close old corrective actions
    Auditors will check your corrective action log. Close all actions where the root cause has been fixed. Verify the fix worked before audit day.
  5. Walk the floor before audit day
    Do a walkthrough one or two days before the audit. Check that real work matches your written procedures. Gaps between documents and actual practice are a leading cause of non-conformities.

For help deciding which documents to prepare, see our guide on Documents Required for ISO Certification.

Frequently Asked Questions

What does an ISO auditor check during certification?

An ISO auditor checks seven areas: documentation, employee awareness, process implementation, records and evidence, internal audit history, management review, and corrective actions. In each area, the auditor looks for objective evidence — documents, records, and interviews — to confirm the system meets the ISO standard.

What is the difference between a minor and major non-conformity?

A minor non-conformity is a small gap — like one missing record or one outdated procedure. A major non-conformity is a serious failure — like no internal audits done or a process not in place. Minor issues allow certification to continue once a fix is agreed. Major issues must be resolved before a certificate can be issued.

Do employees need to be interviewed during an ISO audit?

Yes. Auditors talk to staff at all levels. They check that employees know the quality policy, understand their role, and follow the correct steps. Staff do not need to memorize documents. They just need to know what they do, why they do it, and how to report problems.

What happens if the auditor finds a non-conformity?

For a minor non-conformity, you submit a corrective action plan. Certification can proceed once the plan is accepted. For a major non-conformity, no certificate is issued until the issue is fixed and verified. Most certification bodies allow up to 90 days to resolve major findings.

How can a small business prepare for an ISO audit?

Run a mock internal audit. Brief staff on their roles and the quality policy. Check that all records are complete. Close any open corrective actions. Walk through your operations to confirm practice matches your documents. See our guide on How to Get ISO Certification in Thailand for the full process.

How long does an ISO certification audit take?

It depends on your business size, number of staff, and the ISO standard used. For small businesses with fewer than 50 employees, Stage 1 and Stage 2 may take one to two days combined. Larger businesses may need more time. Your certification body will confirm the exact length based on your scope.

Ready for Your Audit? Start With a Free Mock Audit

This ISO certification checklist shows you exactly what auditors expect. The next step is to apply it to your own business — before the external auditor does.

Thai ISO Certification works with Kingsmen Certification Services to offer free mock audits and consultations for businesses across Thailand. We review your documents, find the gaps, and guide you through the fixes. You go into your audit ready — not guessing.

Contact us via WhatsApp at +66 65 038 9262, Line Chat, or the contact form at thaiisocertification.com. To pick the right certification body, see our guide on How to Choose the Right ISO Certification Body.

Get Free Consultation

Share your requirements and our ISO experts will guide you through the certification process.

Thai ISO Consultant Team

The Thai ISO Consultant Team is a group of certified ISO professionals specialising in Quality, Environmental, Health & Safety, and Information Security Management Systems. Working in association with Kingsmen Certification Services and with hands-on experience supporting startups, manufacturers, and enterprises across Thailand, the team helps organisations achieve internationally recognised certification efficiently and confidently. All content is reviewed for technical accuracy against ISO standard requirements and recognised certification body audit criteria.

Scroll to Top

Please share your details. Our consultant will contact you at the earliest.