Skip to main content

Certification you can stand behind.

ISO 9001:2015

ISO 9001 Quality Management Systems

Deliver consistently, reduce rework and win contracts that demand proof of quality.

Quality
  1. Customer

    Requirements in

  2. Leadership

    Clause 5

  3. Plan

    Clause 6

  4. Operate

    Clause 8

  5. Check

    Clause 9

  6. Act

    Clause 10

    Improve returns to Plan

  7. Customer confidence

    Verified outcome

    Feedback returns to Customer

SYS/01 · Quality loop

Customer requirements drive a governed Plan, Operate, Check, Act cycle; verified output builds confidence.

What ISO 9001 is

ISO 9001 is the most widely adopted management-system standard in the world. It defines how an organization plans, controls and improves the work that affects customer satisfaction: from understanding requirements and managing risk to controlling suppliers, competence and change.

CORE audits ISO 9001 by following the work rather than the manual. Your auditor traces orders and contracts from requirement through delivery, samples the records the process actually produced, and tests whether internal audit, management review and corrective action have changed anything. The evidence that carries weight is operational: nonconformity records with root causes that hold, objectives measured against real data, competence that can be shown at the workstation. The findings raised most often concern corrective action that treats symptoms, internal audits that never sample the difficult processes, and a scope that does not match what the organization sells.

Who it is for

  • Organizations whose tenders require a certificate of registration to ISO 9001 from a third-party body
  • Suppliers whose customers have set certification as a condition of continuing to trade
  • Manufacturers and service providers whose regulator or scheme expects an audited quality system
  • Certified organizations transferring an active certificate from another certification body
  • Groups seeking one combined audit covering quality alongside environment, safety or security

Business outcomes

What leadership should expect the system to change, in operational terms.

Predictable delivery

Defined processes, ownership and acceptance criteria reduce variation between teams, shifts and sites.

Lower cost of poor quality

Nonconformity and root-cause discipline turns repeat failures into permanent fixes.

Tender eligibility

A certificate of registration satisfies the management-system requirements that appear in public and enterprise procurement.

Decisions from data

Objectives, KPIs and management review give leadership a factual view of performance.

Benefits beyond the certificate

  • Customer confidence

    Documented control of requirements, changes and complaints shows customers exactly how their work is protected.

  • Onboarding speed

    New starters inherit defined processes instead of tribal knowledge.

  • Supplier control

    Evaluation and monitoring criteria stop supplier problems from becoming your problems.

  • Risk-based focus

    Effort concentrates on the risks and opportunities that actually affect outcomes.

  • A platform to integrate

    The Annex SL structure lets ISO 14001, ISO 45001 and ISO 27001 share one management system later.

Micrometer measuring a machined steel ring
ISO 9001 in the field

The main requirements

The themes your auditor will examine, in plain language. The full clause detail is worked through at Stage 2.

01

Context and interested parties (Clause 4)

Identify internal and external issues, the parties that matter and the scope of the system.

02

Leadership and policy (Clause 5)

Top management owns the quality policy, assigns roles and keeps customer focus visible.

03

Risk-based planning (Clause 6)

Address risks and opportunities, set measurable quality objectives and plan changes deliberately.

04

Support and competence (Clause 7)

Resources, competence, awareness, communication and controlled documented information.

05

Operational control (Clause 8)

Control design, production and service provision, external providers, releases and nonconforming outputs.

06

Evaluation and improvement (Clauses 9 and 10)

Monitor performance, run internal audits and management review, and correct problems at root cause.

What each requirement buys you

Select a requirement theme to see the business outcomes it chiefly drives. The mapping reflects where audit sampling concentrates, not a normative ISO table.

Requirement themes

Context and interested parties (Clause 4) chiefly drives 2 of 4 ISO 9001 outcomes.

Outcomes it drives

Predictable delivery

Defined processes, ownership and acceptance criteria reduce variation between teams, shifts and sites.

Lower cost of poor quality

Nonconformity and root-cause discipline turns repeat failures into permanent fixes.

Tender eligibility

A certificate of registration satisfies the management-system requirements that appear in public and enterprise procurement.

Decisions from data

Objectives, KPIs and management review give leadership a factual view of performance.

How CORE audits ISO 9001

Step 1

Stage 1 reviews the scope and the documented system

Your auditor confirms the quality scope matches the products and services you supply, reads the documented information the standard requires, and checks that at least one internal audit and one management review have taken place. Findings here are raised as improvement requests, not nonconformities.

Step 2

Stage 2 examines the process in practice

The audit traces work end to end: requirement review, planning, design where applicable, purchasing and external providers, production or service delivery, release, and the handling of nonconforming output. Records are sampled at the point they are created rather than accepted from a summary.

Step 3

Surveillance samples where quality moves

Year 1 and Year 2 audits sample customer complaints, corrective actions raised since the last visit, changes of process, product or personnel, internal audit coverage, and progress against the quality objectives. Previous findings are verified as closed in practice, not on paper.

Step 4

Recertification revisits the whole system

In Year 3 the audit reviews effectiveness across the full three-year cycle: whether objectives moved, whether root-cause analysis stopped failures recurring, whether the scope is still accurate, and whether leadership engagement has held. A renewed three-year certificate follows the decision.

What your auditor expects to see

Before Stage 2 can proceed, the system needs to have run long enough to have produced its own evidence.

  1. 01Internal audit completed

    A full internal audit of the quality system against ISO 9001:2015, run by auditors independent of the work they audit, with reports and findings available to your auditor.

  2. 02Management review held

    A minuted management review covering the inputs Clause 9.3 lists, with decisions and actions recorded and owners named.

  3. 03Records covering a meaningful period

    The system needs to have been running long enough to have produced evidence: complaints, supplier evaluations, calibration or verification records, release records and change control.

  4. 04Corrective actions closed

    Nonconformities you raised yourself should show root-cause analysis, action taken and verification of effect. Open actions with no evidence of progress attract findings.

  5. 05Competence demonstrable

    Training, qualification and authorization records that connect named people to the work the standard says they must be competent to do.

  6. 06Scope defined

    A written scope statement naming the products, services and sites to be certified, with any clause exclusion justified.

  7. Certification decision

    With that evidence in place, Stage 1 and Stage 2 can run. The decision that follows is taken by a reviewer who was not on your audit team.

CORE is the certification body. We assess and certify management systems. We do not build them — that separation is what makes the certificate worth holding. We do not design, document or implement the systems we audit, and we do not run your internal audits. If you need that work done, our directory of independent consultants is a starting point, and engaging one has no bearing on the decision. More on how we keep the audit and the decision separate.

The optional pre-assessment

Before Stage 1 you can ask for an optional pre-assessment: an audit-style review of your quality management system against ISO 9001:2015 that reports where the evidence would not yet satisfy an auditor. It uses the same sampling method as a certification audit and returns a written report of findings clause by clause.

A pre-assessment reports gaps; it does not prescribe how to close them. Designing or documenting your system would make CORE the author of work it later has to audit, which ISO/IEC 17021-1 prohibits. If you want help acting on the report, our directory of independent consultants at /resources/find-a-consultant is a starting point, and engaging one has no bearing on the certification decision.

What you receive

  • Findings against each clause of the standard
  • Where the evidence is missing or incomplete
  • Whether Stage 2 could proceed on today's records
  • The same sampling method a certification audit uses
How the pre-assessment works

Training for ISO 9001

Courses that teach how the standard is written and how it is audited.

All courses

ISO 9001 questions, answered straight

Ready to certify to ISO 9001?

Tell us your standards, scope, effective headcount and sites. You will get a scope statement and a fixed quotation, with audit duration calculated from the accreditation body's mandatory formula.