Six weeks before your ISO 9001 surveillance audit, the email arrives. And if you’re like most quality managers at small and mid-sized manufacturers, your first feeling isn’t confidence — it’s dread. Not because your products are bad or your team is careless, but because proving compliance means a frantic hunt through shared drives, email threads, and a spreadsheet named QMS_Master_FINAL_v3_ACTUAL.xlsx.
Here’s the truth: audit preparation doesn’t have to be a fire drill. With a methodical approach, you can walk into audit day calm, organized, and ready. Let’s break down exactly how.
Why spreadsheets make audits harder than they need to be #
Let’s be honest about the spreadsheet problem. Spreadsheets aren’t a quality management system — they’re a patchwork that holds together until an auditor starts pulling threads:
- No real version control. When three people maintain “the master list,” nobody knows which one is master.
- Evidence lives everywhere. Procedures in a shared drive, training records in HR’s inbox, calibration dates on a whiteboard in maintenance.
- No audit trail. Who changed that corrective action’s due date, and when? A spreadsheet can’t tell you.
- Disconnected records. Your non-conformance log doesn’t talk to your CAPA tracker, which doesn’t talk to your document revisions.
Auditors rarely fail companies for using spreadsheets. They fail them when the evidence is incomplete, uncontrolled, or impossible to retrieve on the spot. The chaos isn’t a discipline problem — it’s a tooling problem.
A practical 7-step audit preparation plan #
Step 1: Confirm your audit scope and criteria #
Before you organize anything, know exactly what you’re being audited against. Review:
- Which ISO 9001 clauses are in scope for this audit cycle
- Findings and observations from your last audit — auditors will check whether previous non-conformances were actually resolved
- Any changes since the last audit: new processes, equipment, suppliers, or personnel
Write the scope down in one place and share it with process owners. Half of audit chaos comes from different departments preparing for different audits.
Step 2: Demonstrate risk-based thinking #
ISO 9001:2015 doesn’t demand a formal risk management procedure — but auditors will look for evidence that you’ve identified risks and opportunities (Clause 6.1) and that your processes actually reflect them. “We think about risks” isn’t evidence; a living risk register is.
- Keep a risk register covering operational, quality, and compliance risks, each with likelihood, impact, an owner, and mitigation actions
- Show the link between risks and controls — e.g., a supplier risk that led to tighter incoming inspection
- Review and update risks on a schedule; a register untouched since your last certification audit is a red flag
- Don’t forget opportunities — auditors notice when they’re missing, and they’re often where the best improvement stories live
In Artintech, risks are tracked centrally and linked to the processes, documents, and actions they affect — so when an auditor asks how a risk was addressed, the answer is one click away instead of a slide deck from last year.
Step 3: Get document control in order #
Document control is where spreadsheet-based systems bleed the most. An auditor will ask for your quality manual, procedures, and work instructions — and then check that people are actually using the current versions.
- Retire outdated versions so they can’t be mistaken for current ones
- Confirm approval signatures and revision histories are complete
- Check that documents reference the correct ISO 9001 clauses
- Make sure controlled documents are accessible where the work happens — not just in a folder nobody opens
If finding “the current version” takes more than a minute, your document control needs attention before the auditor arrives.
Step 4: Close the loop on non-conformances and CAPAs #
Open corrective actions are an auditor’s favorite hunting ground. For every non-conformance and CAPA:
- Verify the root cause analysis is documented — not just the fix
- Confirm corrective actions were implemented and verified effective
- Check that due dates were met, or that extensions were formally approved
- Make sure related documents or training were updated as part of the action
A CAPA that says “retrain operator” with no training record to back it up is worse than no CAPA at all — it tells the auditor your system doesn’t follow through.
Step 5: Verify training and competency records #
Clause 7.2 (competence) trips up more companies than almost any other. Auditors will sample employees and ask: is this person competent for this task, and where’s the proof?
- Match training records against current job roles — people change roles; records often don’t
- Confirm training was completed before the employee performed the task, not after
- Check that training content links back to the current version of the relevant procedure
- Don’t forget temporary and contract workers
Step 6: Run an internal audit first #
Never let the certification auditor be the first person to audit you. A proper internal audit — conducted by someone independent of the area being audited — surfaces gaps while there’s still time to fix them.
Treat it seriously: use the same sampling approach a certification auditor would, document findings formally, and raise corrective actions for anything you find. An internal audit with zero findings isn’t a success — it usually means it wasn’t thorough enough.
Step 7: Organize your objective evidence #
In the final two weeks, assemble evidence the way an auditor will ask for it: by process, not by department. For each key process, you should be able to quickly produce:
- The current procedure or work instruction
- Records showing the process was followed (inspection reports, production records, etc.)
- Related non-conformances, CAPAs, and their closure evidence
- Training records for the people involved
- Calibration or maintenance records for equipment used
Do a dry run: pick a recent production lot or customer order and trace it end to end. If you can follow that thread without friction, you’re ready.
What changes when it’s all in one QMS #
Notice how every step above is really about the same thing: connected, controlled, retrievable evidence. That’s exactly what a quality management system does that spreadsheets can’t.
With a QMS like Artintech’s, document control, non-conformances, CAPAs, audits, training records, and calibration live in one system — linked to each other. When an auditor asks about a corrective action, you don’t open four files; you open one record that shows the non-conformance, the root cause, the action taken, the updated document, and the training that followed. Version control, approval workflows, and audit trails are built in, not bolted on.
Companies that make the switch consistently report the same thing: audit preparation shrinks from weeks of scrambling to a few days of review. The audit itself becomes almost boring — which is exactly what you want.
Your pre-audit checklist #
- Audit scope confirmed and communicated
- Risk register current, with risks linked to actions and controls
- All documents current, approved, and accessible
- Previous findings verified as resolved
- Non-conformances and CAPAs closed with evidence of effectiveness
- Training records complete and matched to current roles
- Internal audit completed with findings addressed
- Objective evidence organized by process
- Dry-run trace completed on a recent lot or order
Stop dreading audit season #
Audit preparation is painful because disconnected tools make it painful — not because the standard is unreasonable. Get the preparation right, and the audit becomes what it should be: a routine confirmation that your system works.
If you’re tired of the spreadsheet scramble, start a free trial of Artintech and see what audit preparation feels like when everything is connected.