After an ISO 9001 audit, most teams turn to the corrective action list and start closing nonconformities. The step they skip is testing whether the audit's findings depend on assumptions that neither the auditor nor the organisation has verified.

An ISO 9001 audit is a systematic examination of whether an organisation's quality management system conforms to the requirements of ISO 9001 and operates as documented.

The standard next step after an ISO 9001 audit

The audit report classifies findings into major nonconformities, minor nonconformities, and opportunities for improvement. Each nonconformity triggers a corrective action request (CAR). The responsible process owner identifies the root cause, proposes a fix, assigns a completion date, and records evidence of implementation. For a certification audit conducted by an accredited body, major nonconformities typically require resolution within 90 days before the certificate can be issued or maintained. Minor nonconformities are tracked to the next surveillance visit.

The corrective action request is the workhorse of post-audit activity. ISO 9001:2015 Clause 10.2 requires organisations to react to nonconformities, evaluate the need for action to eliminate root causes, implement that action, and review its effectiveness. ISO 19011:2018, the guidelines for auditing management systems, places responsibility for verifying corrective action completion on the audit programme manager. The certification body checks evidence of implementation, signs off the finding, and reports the result to the accreditation oversight process.

What to do after an ISO 9001 audit: test the assumptions behind each finding before closing corrective actions
The usual response after an ISO 9001 audit asks which nonconformities to close first. The better question asks which findings rest on assumptions the auditor did not test.Click to expand

Management review follows. Top management evaluates audit results alongside customer feedback, process performance data, and the status of previous actions. Decisions are made on resource allocation, system changes, and improvement priorities. Internal audit schedules are adjusted. Documents are updated. The cycle resets for the next surveillance or recertification audit, typically on a three-year cycle with annual surveillance visits in between. This sequence is well-documented across the organisational governance framework literature. Close the finding, verify the fix, report to management, prepare for the next audit.

For organisations whose quality management system feeds into broader board-level oversight, the audit results also inform strategic planning and resource decisions. The QMS becomes one input among several, alongside financial controls, regulatory compliance, and operational performance data.

What that step adds

Corrective action requests force specificity. A vague audit observation becomes a named problem with a named owner and a deadline. Without this mechanism, audit findings would accumulate in a report nobody acts on. The CAR converts a judgment into a task, and that conversion is a genuine contribution to organisational discipline.

Management review adds a second layer. It lifts audit results out of the quality department and places them in front of the people who control budgets, staffing, and strategic direction. A nonconformity in the purchasing process reads one way when the quality manager sees it. It reads differently when the board sees it alongside customer complaint trends and delivery performance. The standard's insistence on management review creates accountability that a departmental close-out alone does not.

The surveillance cycle matters too. A single audit captures a snapshot. Surveillance visits check whether corrective actions held, whether the system drifted, and whether new problems emerged. This is where ISO 9001 differs from frameworks that produce a single deliverable and move on. The recurring audit creates a feedback loop. Feedback loops are valuable. Process improvements need that loop between audits too: what to do after value stream mapping connects the redesigned process to a recurring service measure and a named owner. They are also, as the next section argues, insufficient when the loop itself runs on untested premises.

An ISO 9001 audit tests conformance against the standard. The Walk tests whether the corrective actions rest on assumptions that hold. Start the Walk →

Where the standard playbook breaks down

An ISO 9001 audit checks whether the quality management system conforms to the standard and whether the organisation follows its own documented procedures. It does not check whether the data the system produces is truthful. The auditor samples records, interviews staff, and traces processes from input to output. Each of those activities assumes that the records reflect what actually happened, that staff describe their real practice, and that the process observed matches the process performed when no auditor is present. These assumptions are reasonable in most settings. They are also the assumptions that fail most severely when they are wrong.

Standard audit response

  • Close nonconformities against documented procedures
  • Accept sampled records as representative evidence
  • Track corrective actions to the next surveillance visit
  • Treat a clean audit as confirmation the system works

With assumption testing

  • Ask what the auditor's sample was designed to detect and what it could not
  • Test whether records reflect actual practice or documented practice
  • Check whether root cause analysis reached the actual root
  • Distinguish system conformance from system honesty

Kobe Steel demonstrates the failure mode at scale. For at least a decade, employees across multiple factories falsified quality inspection certificates on aluminium, copper, and iron powder products. Certificates showed materials meeting customer specifications for tensile strength and dimensional tolerances when they did not. An independent investigation committee found data manipulation in over 70 product categories across plants in Japan, Thailand, China, and Malaysia. The practice was systematic, and managers at several plants were aware.

Kobe Steel's quality management system was certified. Audits were conducted on schedule. Documented procedures existed for inspection and testing. The audits checked whether the QMS operated as documented. They did not test whether the documented outputs were honest. The certification body saw records. The records were fabricated. The governance failure sat in a layer the audit was not designed to reach.

When the scandal surfaced in October 2017, roughly 500 customers were affected, including Boeing, Toyota, and JR Central. The CEO resigned. Kobe Steel lost its Japanese Industrial Standards certification. A compliance framework that had passed every audit for years was exposed as a shell over a culture of falsification.

The pattern recurs wherever audits treat records as evidence without asking what conditions make those records trustworthy. The audit cycle can verify that a system exists without ever testing whether the system tells the truth. That gap is not a flaw in ISO 9001 specifically. The environmental version shows up after an ISO 14001 audit, where a certified system can sit on an aspects register the site has already outgrown. It is a feature of any audit that checks conformance without surfacing the assumptions embedded in its own method.

The step to take first

Before acting on audit findings, surface the assumptions those findings depend on. This does not replace corrective actions or management review. It sits between the audit report and the response plan.

1
Receive the audit reportOutputs: nonconformities, observations, opportunities for improvement
2
Standard next step: assign CARs, identify root causes, set deadlines
Most teams skip straight to step 4
3
Test the assumptions behind each findingWhich nonconformities depend on conditions the auditor did not verify?
4
Act with sufficient certaintyImplement, monitor, adjust

A five-step decision method gives the check a structure. Frame the decision: what is the audit response trying to achieve, and for whom? Treat the findings, corrective actions, and priorities as tentative elements, provisional rather than settled. Surface the assumptions each one rests on: that the sample the auditor checked represents the full population of records, that the root cause analysis reached the actual root, that the corrective action will hold under normal operating conditions, that the data in the records is genuine.

Decide whether there is sufficient certainty to proceed, or whether a specific assumption needs testing before resources move. Then implement and monitor, with monitoring aimed at the assumptions most likely to be wrong, not only the nonconformities most recently closed.

An audit finding is a conclusion. Every conclusion rests on premises. Writing those premises next to the finding makes the quality of the conclusion visible. A major nonconformity supported by a representative sample across shifts and sites is actionable. The same finding supported by three records from one shift at one site is a different proposition. The governance value of the audit depends on which premises held and which were never examined.

The culture question matters here too. An organisation whose audit response starts with "close the CAR" is optimising for certification. One whose response starts with "what did the auditor assume" is optimising for the quality of the decision the audit is supposed to inform.

You could close this tab and carry that decision into another week.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.