GREY META ASSESSMENT FRAMEWORK

A practical path
to audit readiness.

Proprietary evidence-based readiness methodology. This is not the text of any ISO Standard and is not a certification decision. Prepare evidence against Grey Meta criteria for Grey Meta Management System Assessment Methodology 1.0.0. This is not a certification decision.

Contains Grey Meta-authored assessment methodology only. It does not reproduce ISO Standards. Confirm the applicable edition, scope, legal obligations and certification-body requirements before relying on these prompts. ISOCheck does not issue certificates.

One system, a clear certification journey.

01

Scope & gap analysis

Confirm standards, activities, sites and ownership. Compare your existing evidence with the agreed criteria.

02

Implement & demonstrate

Close gaps, train the team, operate the system, and retain records. Complete internal audit and management review.

03

Independent audit

Arrange Stage 1 and Stage 2 with your chosen certification body. Address its findings and confirm its accredited scope.

04

Maintain & improve

Keep records current, track corrective actions, and agree surveillance and recertification dates with your certification body.

First-certification preparation

  • Standard purchased

    Licensed copy of the current edition under control.

  • CB selected

    JAS-ANZ register checked for standard + industry scope; impartiality confirmed.

  • Scope frozen

    Matches the application form the CB will print on the certificate.

  • System operated

    Retain enough live operating records for the agreed audit scope; confirm the period with your certification body.

  • Internal audit done

    Full system covered, findings closed or plan accepted.

  • Management review done

    Minutes exist; actions assigned.

  • Legal register current

    State-specific instruments, not a generic internet list.

  • Staff briefed

    People in sampled roles can describe their process without the manual in hand.

  • Stage 1 closed

    Stage 1 findings addressed before Stage 2.

  • Logistics

    Sites accessible; SME available; contractors on site if they are in scope.

A shared management system

For an integrated assessment, reuse evidence for context, leadership, document control, internal audit, management review and corrective action where it applies across your standards.

Keep specialist evidence distinct: environmental aspects, WHS hazards, information-security risk and Statement of Applicability, food safety, energy and business continuity.

Certification and accreditation

Management-system certification and laboratory accreditation are different pathways. For laboratory testing and calibration, discuss the ISO/IEC 17025 accreditation pathway with NATA. ISOCheck can help organise a gap analysis, but does not issue a certificate or accreditation.

EVIDENCE THAT SUPPORTS YOUR SYSTEM

Standard-specific preparation.

Reference promptEvidence / practice to consider
4.1 Business context and strategic conditionsDetermine whether the management system reflects the internal and external conditions that can affect consistent delivery and quality outcomes. What internal conditions materially affect quality performance? What external conditions materially affect the organisation's ability to meet customer and applicable requirements? How are material changes reviewed? Look for: context review, strategic plan, SWOT/PESTLE or equivalent analysis, business risk register, management review records, evidence that context is revisited after significant change.
4.2 Stakeholder and requirement awarenessIdentify relevant parties and the requirements that can influence the quality management system. Who can affect or is affected by the organisation's ability to deliver conforming products/services? How are customer, regulator, supplier, owner and workforce expectations monitored? Look for: stakeholder register, contract requirements, customer specifications, regulatory register, supplier conditions, updates after new contracts, regulatory changes or stakeholder changes.
4.3 Defined management-system scopeConfirm that the proposed QMS scope is clear, supportable and consistent with actual operations. Which entities, sites, services and processes are included? Are any activities excluded and is the rationale supportable? Does the proposed scope match what the organisation actually controls? Look for: scope statement, site list, service catalogue, organisation chart, process map.
4.4 Managed process architectureVerify that key processes, interactions, responsibilities, controls, measures and retained evidence are defined. What are the core and support processes? What inputs/outputs and responsibilities apply? How are process risks, measures and changes controlled? Look for: process map, procedures, RACI, KPIs, workflow diagrams, records, completed workflow records, process performance trends, process-change records.
5.1 Leadership ownership of qualityAssess whether leadership actively directs, supports and reviews the QMS rather than delegating it as a documentation exercise. How does leadership demonstrate accountability? How are quality requirements integrated into normal business decisions? How are resources and improvement priorities decided? Look for: meeting minutes, leadership communications, resource decisions, QMS performance reviews, management decisions linked to quality data.
5.1.2 Customer-focus controlsAssess how customer and applicable requirements are identified, protected and used to improve satisfaction. How are customer needs confirmed? How are delivery risks managed? How is satisfaction or dissatisfaction monitored? Look for: contracts, quote review records, customer feedback, complaint register, service KPIs, closed-loop complaint actions, customer trend analysis.
5.2 Quality policy and directionVerify that quality commitments and direction are established, communicated and relevant to the organisation. Is there a current quality policy? Does it support strategic direction and measurable objectives? Do relevant workers understand what it means for their work? Look for: approved policy, induction/training records, communications, acknowledgements.
5.3 Roles, responsibilities and accountabilityConfirm that QMS responsibilities and decision authorities are assigned and understood. Who owns key processes? Who can approve changes, release outputs and close corrective actions? How are responsibilities communicated? Look for: organisation chart, position descriptions, delegations, RACI, workflow permissions.
6.1 Quality risks and opportunitiesEvaluate whether risks and opportunities affecting intended QMS outcomes are identified, prioritised and acted upon. What could prevent consistent delivery? What opportunities could improve outcomes? How are actions integrated and later evaluated? Look for: risk register, opportunity register, project risk reviews, treatment plans, closed treatments, effectiveness reviews.
6.2 Measurable quality objectivesDetermine whether quality objectives are measurable, owned, monitored and linked to business needs. What quality outcomes are targeted? Who owns each target? How are results reviewed and actions taken when targets are missed? Look for: objective register, KPI dashboard, business plan, meeting minutes, trend data, actions for missed targets.
6.3 Planned management-system changeAssess whether significant QMS changes are planned with attention to consequences, resources, responsibilities and system integrity. How are process/system changes approved? How are impacts assessed? How are users trained and records updated? Look for: change register, project plans, impact assessments, communications, training records.
7.1 Resources and operational capabilityConfirm that people, infrastructure, environment, monitoring resources and organisational knowledge are sufficient for intended outcomes. Are staffing, equipment, systems and work environment adequate? How are monitoring devices/resources controlled where relevant? How is critical organisational knowledge retained? Look for: resource plans, asset registers, maintenance/calibration records, knowledge base, capacity plans, resource reviews and corrective decisions.
7.2 Competence assuranceVerify that competency requirements are defined and evidence shows people are capable of assigned work. What competencies are required by role? How is competence verified? What happens when a gap is identified? Look for: competency matrix, qualifications, training records, assessments, licence records, supervisor verification, refresher training, post-training evaluation.
7.3 Awareness and controlled communicationAssess whether relevant people understand expectations and whether internal/external communications are managed. What must workers understand about quality and their contribution? Who communicates with customers, suppliers and regulators? How are critical changes communicated? Look for: inductions, toolbox/team meetings, communication matrix, customer correspondence.
7.5 Controlled documented informationAssess creation, approval, access, revision, retention, protection and removal of obsolete documented information. How are documents approved and versioned? How are obsolete versions prevented from unintended use? How are records protected and retained? Look for: document register, revision history, approval workflow, retention schedule, access permissions, sample version trace, archived/superseded records.
8.1 Operational planning and controlVerify that work is planned and controlled to meet requirements, including criteria, resources and retained evidence. How are jobs/orders/projects planned? What acceptance criteria apply? How are changes and outsourced activities controlled? Look for: job plans, work instructions, checklists, project plans, acceptance criteria, completed job records, change records.
8.2 Customer requirement review and change controlDetermine whether requirements are clarified before commitment and changes are communicated and controlled. How are requirements captured? Who reviews capability before accepting work? How are changed requirements controlled? Look for: quotes, contracts, scope reviews, purchase orders, variation records, customer approvals.
8.3 Design and development controlWhere design is within scope, assess planning, inputs, controls, outputs and changes. Does the organisation design products/services/solutions? How are design inputs validated? How are reviews, verification, validation and changes recorded? Look for: design plans, briefs, calculations, review records, test results, change logs.
8.4 Supplier and outsourced-process controlAssess selection, monitoring and control of suppliers, subcontractors and outsourced processes according to risk. How are providers approved? What requirements are communicated? How is supplier performance monitored? Look for: approved supplier register, supplier assessments, purchase specifications, subcontractor records, performance reviews, supplier NCRs, re-evaluations, delivery/quality trends.
8.5 Controlled service or production deliveryVerify controls for delivery, identification/traceability where relevant, customer property, preservation, post-delivery needs and operational changes. How is service/production performed consistently? What traceability is required? How is customer property protected? How are field changes controlled? Look for: work instructions, job packs, traceability records, custody records, change approvals, completed production/service records, site records.
8.6 Release and nonconforming output controlAssess how outputs are accepted before release and how defective/nonconforming outputs are identified and controlled. Who authorises release? What evidence demonstrates acceptance criteria were met? How are defects, rework, concession and disposal controlled? Look for: inspection/test records, completion certificates, release approvals, NCR register, rework records, trace from NCR to disposition and verification.
9.1 Monitoring, measurement and analysisDetermine whether useful performance data is defined, reliable, analysed and used to make decisions. What is measured and why? How is data reliability protected? What trends are reviewed? How is customer perception monitored? Look for: KPI register, dashboards, customer surveys, trend reports, analysis records, decisions/actions arising from analysis.
9.2 Risk-based internal audit programVerify that internal audits are planned, objective, appropriately scoped and followed through. Is there an audit program? Are auditors sufficiently independent/competent? Are findings tracked to closure? Look for: audit schedule, audit plans, checklists, reports, auditor competency, actions, follow-up verification.
9.3 Management-system reviewAssess whether leadership periodically reviews suitability, adequacy, effectiveness, changes, performance and improvement needs. When was the QMS last formally reviewed? What inputs were considered? What decisions/resources/actions resulted? Look for: management review agenda/minutes, performance pack, action register, closed management-review actions.
10.2 Nonconformity and corrective actionVerify that problems are contained, causes are evaluated, actions are implemented and effectiveness is checked. How are nonconformities reported? How is root cause assessed? How is recurrence prevented and effectiveness verified? Look for: NCR/CAR register, root cause analysis, corrective actions, effectiveness checks, repeat-issue trend showing whether action worked.
10.1 Continual improvement systemAssess whether performance information, lessons and opportunities lead to sustained improvement. How are improvement opportunities identified and prioritised? What evidence shows the QMS has improved over time? Look for: improvement register, lessons learned, projects, before/after KPI trends, verified benefit or performance change.
2024 Climate-related relevance assessmentConfirm that the organisation has considered whether climate-related conditions are relevant to its QMS context and stakeholder requirements. Could climate-related conditions affect suppliers, sites, service continuity, customer requirements or product/service quality? Have relevant stakeholder expectations been considered? Look for: context review, business continuity/risk register, stakeholder review, supply chain assessment, actions where climate-related risks/opportunities were determined relevant.
Common management-system preparation prompts

Clause numbers and applicability differ between standards and editions. Confirm these before using a prompt as an assessment criterion.

  • 4.1 Context

    Internal and external issues documented and reviewed; climate change considered where the 2024 HLS amendment applies.

  • 4.2 Interested parties

    Parties and their relevant needs/expectations identified; legal needs flagged.

  • 4.3 Scope

    Scope statement names products/services, sites, boundaries and justified exclusions.

  • 4.4 System processes

    Processes, interactions, owners, criteria, resources and risks determined; documented information sufficient to run and to prove they ran.

  • 5.1 Leadership

    Top management can explain the system, policy, objectives and performance without a consultant present.

  • 5.2 Policy

    Policy appropriate to the organisation, includes required commitments, available as documented information, communicated, available to parties as appropriate.

  • 5.3 Roles

    Responsibilities and authorities assigned and communicated; a person with authority to report on system performance to top management.

  • 6.1 Risk and opportunity

    Process exists; actions planned and taken; effectiveness reviewed. Not a one-page SWOT left in 2022.

  • 6.2 Objectives

    Measurable objectives at relevant levels; plans with actions, resources, owners, due dates, evaluation method.

  • 6.3 Change

    Changes to the management system planned.

  • 7.1 Resources

    People, infrastructure, environment for the operation of processes.

  • 7.2 Competence

    Competence determined, obtained, evaluated; evidence retained.

  • 7.3 Awareness

    People aware of policy, their contribution, implications of nonconformance (and, for 45001, incidents and hazards).

  • 7.4 Communication

    What, when, with whom, how, who — internal and external as required by the discipline.

  • 7.5 Documented information

    Creation, update, control, protection, retention and disposal. External documents (standards, licences, customer specs) controlled.

  • 8 Operation

    Controls implemented as planned; outsourced processes controlled.

  • 9.1 Monitoring

    What is monitored, methods, when, when analysed; results retained; performance against objectives.

  • 9.2 Internal audit

    Programme based on importance, changes and previous results; auditors independent; results reported; findings closed.

  • 9.3 Management review

    Scheduled; full input list from the standard; outputs include decisions, improvement, resource needs; records retained.

  • 10.1 Improvement

    Opportunities identified and acted on.

  • 10.2 Nonconformity / CA

    React, control, correct, deal with consequences, evaluate need for action to eliminate cause, implement, review effectiveness, update risks, retain records. No “retrain the operator” as the only cause every time.

  • Certificate conditions

    Scope still true; CB notified of significant change; logos used per rules; surveillance booked before anniversary.