A practical path
to audit readiness.
Proprietary evidence-based readiness methodology. This is not the text of any ISO Standard and is not a certification decision. Prepare evidence against Grey Meta criteria for Grey Meta Management System Assessment Methodology 1.0.0. This is not a certification decision.
One system, a clear certification journey.
Scope & gap analysis
Confirm standards, activities, sites and ownership. Compare your existing evidence with the agreed criteria.
Implement & demonstrate
Close gaps, train the team, operate the system, and retain records. Complete internal audit and management review.
Independent audit
Arrange Stage 1 and Stage 2 with your chosen certification body. Address its findings and confirm its accredited scope.
Maintain & improve
Keep records current, track corrective actions, and agree surveillance and recertification dates with your certification body.
First-certification preparation
- Standard purchased
Licensed copy of the current edition under control.
- CB selected
JAS-ANZ register checked for standard + industry scope; impartiality confirmed.
- Scope frozen
Matches the application form the CB will print on the certificate.
- System operated
Retain enough live operating records for the agreed audit scope; confirm the period with your certification body.
- Internal audit done
Full system covered, findings closed or plan accepted.
- Management review done
Minutes exist; actions assigned.
- Legal register current
State-specific instruments, not a generic internet list.
- Staff briefed
People in sampled roles can describe their process without the manual in hand.
- Stage 1 closed
Stage 1 findings addressed before Stage 2.
- Logistics
Sites accessible; SME available; contractors on site if they are in scope.
A shared management system
For an integrated assessment, reuse evidence for context, leadership, document control, internal audit, management review and corrective action where it applies across your standards.
Keep specialist evidence distinct: environmental aspects, WHS hazards, information-security risk and Statement of Applicability, food safety, energy and business continuity.
Certification and accreditation
Management-system certification and laboratory accreditation are different pathways. For laboratory testing and calibration, discuss the ISO/IEC 17025 accreditation pathway with NATA. ISOCheck can help organise a gap analysis, but does not issue a certificate or accreditation.
Standard-specific preparation.
| Reference prompt | Evidence / practice to consider |
|---|---|
| 4.1 Business context and strategic conditions | Determine whether the management system reflects the internal and external conditions that can affect consistent delivery and quality outcomes. What internal conditions materially affect quality performance? What external conditions materially affect the organisation's ability to meet customer and applicable requirements? How are material changes reviewed? Look for: context review, strategic plan, SWOT/PESTLE or equivalent analysis, business risk register, management review records, evidence that context is revisited after significant change. |
| 4.2 Stakeholder and requirement awareness | Identify relevant parties and the requirements that can influence the quality management system. Who can affect or is affected by the organisation's ability to deliver conforming products/services? How are customer, regulator, supplier, owner and workforce expectations monitored? Look for: stakeholder register, contract requirements, customer specifications, regulatory register, supplier conditions, updates after new contracts, regulatory changes or stakeholder changes. |
| 4.3 Defined management-system scope | Confirm that the proposed QMS scope is clear, supportable and consistent with actual operations. Which entities, sites, services and processes are included? Are any activities excluded and is the rationale supportable? Does the proposed scope match what the organisation actually controls? Look for: scope statement, site list, service catalogue, organisation chart, process map. |
| 4.4 Managed process architecture | Verify that key processes, interactions, responsibilities, controls, measures and retained evidence are defined. What are the core and support processes? What inputs/outputs and responsibilities apply? How are process risks, measures and changes controlled? Look for: process map, procedures, RACI, KPIs, workflow diagrams, records, completed workflow records, process performance trends, process-change records. |
| 5.1 Leadership ownership of quality | Assess whether leadership actively directs, supports and reviews the QMS rather than delegating it as a documentation exercise. How does leadership demonstrate accountability? How are quality requirements integrated into normal business decisions? How are resources and improvement priorities decided? Look for: meeting minutes, leadership communications, resource decisions, QMS performance reviews, management decisions linked to quality data. |
| 5.1.2 Customer-focus controls | Assess how customer and applicable requirements are identified, protected and used to improve satisfaction. How are customer needs confirmed? How are delivery risks managed? How is satisfaction or dissatisfaction monitored? Look for: contracts, quote review records, customer feedback, complaint register, service KPIs, closed-loop complaint actions, customer trend analysis. |
| 5.2 Quality policy and direction | Verify that quality commitments and direction are established, communicated and relevant to the organisation. Is there a current quality policy? Does it support strategic direction and measurable objectives? Do relevant workers understand what it means for their work? Look for: approved policy, induction/training records, communications, acknowledgements. |
| 5.3 Roles, responsibilities and accountability | Confirm that QMS responsibilities and decision authorities are assigned and understood. Who owns key processes? Who can approve changes, release outputs and close corrective actions? How are responsibilities communicated? Look for: organisation chart, position descriptions, delegations, RACI, workflow permissions. |
| 6.1 Quality risks and opportunities | Evaluate whether risks and opportunities affecting intended QMS outcomes are identified, prioritised and acted upon. What could prevent consistent delivery? What opportunities could improve outcomes? How are actions integrated and later evaluated? Look for: risk register, opportunity register, project risk reviews, treatment plans, closed treatments, effectiveness reviews. |
| 6.2 Measurable quality objectives | Determine whether quality objectives are measurable, owned, monitored and linked to business needs. What quality outcomes are targeted? Who owns each target? How are results reviewed and actions taken when targets are missed? Look for: objective register, KPI dashboard, business plan, meeting minutes, trend data, actions for missed targets. |
| 6.3 Planned management-system change | Assess whether significant QMS changes are planned with attention to consequences, resources, responsibilities and system integrity. How are process/system changes approved? How are impacts assessed? How are users trained and records updated? Look for: change register, project plans, impact assessments, communications, training records. |
| 7.1 Resources and operational capability | Confirm that people, infrastructure, environment, monitoring resources and organisational knowledge are sufficient for intended outcomes. Are staffing, equipment, systems and work environment adequate? How are monitoring devices/resources controlled where relevant? How is critical organisational knowledge retained? Look for: resource plans, asset registers, maintenance/calibration records, knowledge base, capacity plans, resource reviews and corrective decisions. |
| 7.2 Competence assurance | Verify that competency requirements are defined and evidence shows people are capable of assigned work. What competencies are required by role? How is competence verified? What happens when a gap is identified? Look for: competency matrix, qualifications, training records, assessments, licence records, supervisor verification, refresher training, post-training evaluation. |
| 7.3 Awareness and controlled communication | Assess whether relevant people understand expectations and whether internal/external communications are managed. What must workers understand about quality and their contribution? Who communicates with customers, suppliers and regulators? How are critical changes communicated? Look for: inductions, toolbox/team meetings, communication matrix, customer correspondence. |
| 7.5 Controlled documented information | Assess creation, approval, access, revision, retention, protection and removal of obsolete documented information. How are documents approved and versioned? How are obsolete versions prevented from unintended use? How are records protected and retained? Look for: document register, revision history, approval workflow, retention schedule, access permissions, sample version trace, archived/superseded records. |
| 8.1 Operational planning and control | Verify that work is planned and controlled to meet requirements, including criteria, resources and retained evidence. How are jobs/orders/projects planned? What acceptance criteria apply? How are changes and outsourced activities controlled? Look for: job plans, work instructions, checklists, project plans, acceptance criteria, completed job records, change records. |
| 8.2 Customer requirement review and change control | Determine whether requirements are clarified before commitment and changes are communicated and controlled. How are requirements captured? Who reviews capability before accepting work? How are changed requirements controlled? Look for: quotes, contracts, scope reviews, purchase orders, variation records, customer approvals. |
| 8.3 Design and development control | Where design is within scope, assess planning, inputs, controls, outputs and changes. Does the organisation design products/services/solutions? How are design inputs validated? How are reviews, verification, validation and changes recorded? Look for: design plans, briefs, calculations, review records, test results, change logs. |
| 8.4 Supplier and outsourced-process control | Assess selection, monitoring and control of suppliers, subcontractors and outsourced processes according to risk. How are providers approved? What requirements are communicated? How is supplier performance monitored? Look for: approved supplier register, supplier assessments, purchase specifications, subcontractor records, performance reviews, supplier NCRs, re-evaluations, delivery/quality trends. |
| 8.5 Controlled service or production delivery | Verify controls for delivery, identification/traceability where relevant, customer property, preservation, post-delivery needs and operational changes. How is service/production performed consistently? What traceability is required? How is customer property protected? How are field changes controlled? Look for: work instructions, job packs, traceability records, custody records, change approvals, completed production/service records, site records. |
| 8.6 Release and nonconforming output control | Assess how outputs are accepted before release and how defective/nonconforming outputs are identified and controlled. Who authorises release? What evidence demonstrates acceptance criteria were met? How are defects, rework, concession and disposal controlled? Look for: inspection/test records, completion certificates, release approvals, NCR register, rework records, trace from NCR to disposition and verification. |
| 9.1 Monitoring, measurement and analysis | Determine whether useful performance data is defined, reliable, analysed and used to make decisions. What is measured and why? How is data reliability protected? What trends are reviewed? How is customer perception monitored? Look for: KPI register, dashboards, customer surveys, trend reports, analysis records, decisions/actions arising from analysis. |
| 9.2 Risk-based internal audit program | Verify that internal audits are planned, objective, appropriately scoped and followed through. Is there an audit program? Are auditors sufficiently independent/competent? Are findings tracked to closure? Look for: audit schedule, audit plans, checklists, reports, auditor competency, actions, follow-up verification. |
| 9.3 Management-system review | Assess whether leadership periodically reviews suitability, adequacy, effectiveness, changes, performance and improvement needs. When was the QMS last formally reviewed? What inputs were considered? What decisions/resources/actions resulted? Look for: management review agenda/minutes, performance pack, action register, closed management-review actions. |
| 10.2 Nonconformity and corrective action | Verify that problems are contained, causes are evaluated, actions are implemented and effectiveness is checked. How are nonconformities reported? How is root cause assessed? How is recurrence prevented and effectiveness verified? Look for: NCR/CAR register, root cause analysis, corrective actions, effectiveness checks, repeat-issue trend showing whether action worked. |
| 10.1 Continual improvement system | Assess whether performance information, lessons and opportunities lead to sustained improvement. How are improvement opportunities identified and prioritised? What evidence shows the QMS has improved over time? Look for: improvement register, lessons learned, projects, before/after KPI trends, verified benefit or performance change. |
| 2024 Climate-related relevance assessment | Confirm that the organisation has considered whether climate-related conditions are relevant to its QMS context and stakeholder requirements. Could climate-related conditions affect suppliers, sites, service continuity, customer requirements or product/service quality? Have relevant stakeholder expectations been considered? Look for: context review, business continuity/risk register, stakeholder review, supply chain assessment, actions where climate-related risks/opportunities were determined relevant. |
Common management-system preparation prompts
Clause numbers and applicability differ between standards and editions. Confirm these before using a prompt as an assessment criterion.
- 4.1 Context
Internal and external issues documented and reviewed; climate change considered where the 2024 HLS amendment applies.
- 4.2 Interested parties
Parties and their relevant needs/expectations identified; legal needs flagged.
- 4.3 Scope
Scope statement names products/services, sites, boundaries and justified exclusions.
- 4.4 System processes
Processes, interactions, owners, criteria, resources and risks determined; documented information sufficient to run and to prove they ran.
- 5.1 Leadership
Top management can explain the system, policy, objectives and performance without a consultant present.
- 5.2 Policy
Policy appropriate to the organisation, includes required commitments, available as documented information, communicated, available to parties as appropriate.
- 5.3 Roles
Responsibilities and authorities assigned and communicated; a person with authority to report on system performance to top management.
- 6.1 Risk and opportunity
Process exists; actions planned and taken; effectiveness reviewed. Not a one-page SWOT left in 2022.
- 6.2 Objectives
Measurable objectives at relevant levels; plans with actions, resources, owners, due dates, evaluation method.
- 6.3 Change
Changes to the management system planned.
- 7.1 Resources
People, infrastructure, environment for the operation of processes.
- 7.2 Competence
Competence determined, obtained, evaluated; evidence retained.
- 7.3 Awareness
People aware of policy, their contribution, implications of nonconformance (and, for 45001, incidents and hazards).
- 7.4 Communication
What, when, with whom, how, who — internal and external as required by the discipline.
- 7.5 Documented information
Creation, update, control, protection, retention and disposal. External documents (standards, licences, customer specs) controlled.
- 8 Operation
Controls implemented as planned; outsourced processes controlled.
- 9.1 Monitoring
What is monitored, methods, when, when analysed; results retained; performance against objectives.
- 9.2 Internal audit
Programme based on importance, changes and previous results; auditors independent; results reported; findings closed.
- 9.3 Management review
Scheduled; full input list from the standard; outputs include decisions, improvement, resource needs; records retained.
- 10.1 Improvement
Opportunities identified and acted on.
- 10.2 Nonconformity / CA
React, control, correct, deal with consequences, evaluate need for action to eliminate cause, implement, review effectiveness, update risks, retain records. No “retrain the operator” as the only cause every time.
- Certificate conditions
Scope still true; CB notified of significant change; logos used per rules; surveillance booked before anniversary.