Retail audit checklist template
ISO Readiness Audit Checklist
Assess whether your management system is genuinely ready for an ISO certification audit by checking requirement mapping, implementation evidence, internal audits, corrective actions, management review, employee understanding, and unresolved gaps before the external audit begins.
Has the full management-system scope been internally audited using objective evidence, with findings assigned and verified?
Management System Owner | Complete audit coverage | Close findings | Verify evidence | Reassess go/no-go
Select an answer to preview the workflow.
About this checklist
What an ISO readiness audit should help you verify
Verify that the selected management-system requirements have been translated into working processes, records, responsibilities, internal audits, management review, corrective actions, and evidence that can withstand an external certification audit.
When
Before first certification, surveillance, recertification, major scope changes, or a new ISO standard rollout
Use it during implementation, before the certification audit, after major changes, when adding sites or scope, or when management needs a clear go or no-go view of readiness.
Who
Management-system owners, internal auditors, quality, EHS, process owners, and leadership
ISO programme leads, internal auditors, process owners, quality or EHS teams, HR, procurement, IT, facilities, operations, and top management can share evidence and closure ownership.
Outcome
A prioritized gap list with objective closure evidence before the external audit
Create one readiness view covering clause mapping, system implementation, performance evidence, audit findings, CAPA, management review, employee awareness, and certification logistics.
Complete ISO readiness audit checklist
Checks across ISO scope, context, leadership, planning, resources, operations, performance evaluation, internal audit, CAPA, management review, and certification readiness
Ten sections, sixty checks. First confirm the exact ISO standard, edition, amendments, and certification scope you are targeting. Then adapt the checklist to the clause structure and standard-specific requirements that apply to your organization.
Section 1Audit scope, target ISO standard, certification stage, and requirement mapping
- Confirm the target ISO management-system standard, edition, amendments, certification scope, sites, functions, products or services, and organizational boundaries included in the readiness review.
- Verify the organization has access to the current applicable requirements of the selected standard and has identified any sector, legal, customer, or certification-program requirements that also affect readiness.
- Map each applicable requirement or clause to the responsible process, owner, documented information, operating control, evidence source, and current readiness status.
- Confirm exclusions, non-applicable requirements, outsourced activities, shared services, remote functions, and multi-site arrangements are justified and reflected consistently in the management-system scope.
- Review previous certification audits, internal audits, customer audits, gap assessments, regulatory findings, complaints, incidents, and open corrective actions that may affect readiness.
- Assign ownership for gap closure, document updates, process implementation, internal audits, management review, evidence readiness, certification coordination, and final approval.
Section 3Risks, opportunities, objectives, planning, obligations, and management of change
- Verify risks and opportunities relevant to the management system are identified, evaluated, prioritized, and linked to planned controls or actions.
- Confirm applicable legal, regulatory, contractual, customer, environmental, safety, quality, information, or other obligations required by the selected standard are identified and kept current.
- Check measurable management-system objectives are established at relevant functions and levels with owners, targets, timelines, resources, and methods for evaluating results.
- Verify action plans explain how objectives will be achieved, who is responsible, what resources are needed, when actions will be completed, and how results will be evaluated.
- Confirm planned changes to processes, organization, technology, suppliers, facilities, products, services, or controls are reviewed for management-system impact before implementation.
- Verify the organization has considered current external issues required by the selected standard, including climate-related relevance where applicable to that standard and organizational context.
Section 5Operational planning, process controls, supplier controls, emergency or contingency readiness, and execution
- Verify operational processes needed to meet management-system requirements are defined with criteria, responsibilities, resources, controls, and records.
- Confirm process inputs, outputs, sequence, interactions, acceptance criteria, risks, quality or compliance gates, and required evidence are understood by process owners.
- Check externally provided processes, suppliers, contractors, service providers, and outsourced activities are selected, controlled, monitored, and evaluated according to their impact and risk.
- Verify operational changes, deviations, exceptions, temporary controls, rework, emergency conditions, and abnormal situations follow approved authorization and control methods.
- Confirm the organization has implemented standard-specific operational controls such as customer requirements, environmental aspects, OH&S hazards, information risks, food-safety controls, or other applicable requirements.
- Where the selected standard requires emergency, contingency, response, continuity, or preparedness arrangements, verify plans are practical, communicated, tested, reviewed, and supported by evidence.
Section 7Internal audit programme, auditor competence, audit evidence, and follow-up
- Verify an internal audit programme covers the full management-system scope, all applicable requirements, key processes, locations, shifts, outsourced activities, and prior problem areas over the planned cycle.
- Confirm audit frequency and priority consider process importance, risk, organizational change, previous audit results, complaints, incidents, nonconformities, and performance trends.
- Check internal auditors are competent and sufficiently independent or objective for the work being audited, with conflicts of interest appropriately managed.
- Verify audit plans define scope, criteria, methods, samples, timing, responsibilities, interview or observation needs, and evidence sources before the audit starts.
- Confirm audit findings are based on objective evidence, clearly linked to requirements, classified consistently, communicated to responsible management, and recorded.
- Check internal audit findings are assigned, corrected, investigated where needed, verified for closure, and used to improve the audit programme and management system.
Section 9Management review, leadership decisions, resources, strategic alignment, and system effectiveness
- Verify management review is completed at planned intervals and includes the inputs required by the selected standard and the organization's own management-system needs.
- Confirm management review considers previous actions, context changes, interested-party needs, performance results, objective status, audit findings, nonconformities, compliance, and improvement opportunities as applicable.
- Check management receives enough accurate information to evaluate whether the management system remains suitable, adequate, effective, and aligned with strategic direction.
- Verify management-review outputs include clear decisions and actions related to improvement, changes, resources, risks, objectives, process controls, and system priorities where needed.
- Confirm management-review actions have named owners, due dates, follow-up, evidence, and escalation rather than remaining as untracked meeting notes.
- Check leadership can explain major system risks, performance gaps, open critical actions, readiness status, and the evidence supporting the decision to proceed toward certification.
Section 2Organizational context, interested parties, system scope, leadership, and policy
- Verify the organization has identified relevant internal and external issues that can affect the intended outcomes of the management system.
- Confirm relevant interested parties, their applicable needs or expectations, and any resulting compliance, customer, contractual, employee, supplier, or stakeholder requirements are understood.
- Check the management-system scope is documented, appropriate to the organization's context, and aligned with actual activities, sites, products, services, and outsourced processes.
- Verify top management demonstrates accountability for the management system through direction, integration into business processes, resources, review, and support for continual improvement.
- Confirm the policy required by the selected ISO standard is approved, communicated, available where appropriate, and consistent with organizational purpose and management-system commitments.
- Check responsibilities, authorities, reporting lines, process ownership, escalation, and accountability for the management system are clear and understood.
Section 4Resources, competence, awareness, communication, infrastructure, and documented information
- Confirm the organization has identified and provided the people, infrastructure, work environment, technology, knowledge, monitoring resources, and support needed for effective system operation.
- Verify people performing work that affects management-system performance are competent based on appropriate education, training, skills, experience, or demonstrated capability.
- Check employees and relevant contractors understand the policy, objectives, their contribution, applicable requirements, significant risks, and consequences of not following the management system.
- Confirm internal and external communication requirements define what will be communicated, when, with whom, by whom, through which channels, and how records are retained where needed.
- Verify required documented information is approved, current, identifiable, accessible, protected, version-controlled, retained, and prevented from unintended use when obsolete.
- Check organizational knowledge, records, templates, forms, systems, instructions, and external documents needed to operate and demonstrate conformity are controlled and available.
Section 6Monitoring, measurement, evaluation, compliance, data integrity, and performance results
- Confirm the organization has defined what must be monitored or measured, the methods used, frequency, responsibilities, acceptance criteria, records, and evaluation of results.
- Verify monitoring and measuring equipment or systems are suitable, maintained, calibrated or verified where required, and protected from use when results may be unreliable.
- Check performance indicators and management-system results are analyzed for trends, target achievement, recurring gaps, process variation, incidents, complaints, defects, or other relevant outcomes.
- Confirm evaluation of applicable compliance or other obligations is completed at planned intervals where required by the selected standard.
- Verify customer, employee, supplier, environmental, safety, service, quality, security, or other relevant performance feedback is collected and evaluated as applicable.
- Check reported metrics can be traced to reliable source data and that calculation methods, assumptions, corrections, exceptions, and reporting periods are controlled.
Section 8Nonconformity, corrective action, root cause, effectiveness, and continual improvement
- Verify nonconformities from audits, complaints, incidents, process failures, monitoring, supplier issues, or other sources are recorded and controlled consistently.
- Confirm immediate correction and containment address the current issue and prevent further unintended use, release, impact, or recurrence while investigation continues.
- Check significant or recurring nonconformities receive evidence-based root-cause analysis rather than being closed only with correction, reminders, or retraining.
- Verify corrective actions address verified causes, have named owners and deadlines, consider similar risks elsewhere, and are supported by objective implementation evidence.
- Confirm effectiveness checks demonstrate that corrective actions reduced recurrence and did not create new management-system risks or unintended consequences.
- Review recurring findings, weak controls, missed objectives, audit trends, complaints, incidents, inefficiencies, and improvement opportunities for evidence of continual improvement.
Section 10Certification readiness, gap closure, evidence pack, audit logistics, and final sign-off
- Confirm all applicable requirements have been assessed and each identified gap has a clear owner, priority, due date, closure evidence, and verification status.
- Verify required processes are not only documented but have operated long enough to produce credible evidence of implementation, monitoring, internal audit, corrective action, and management review.
- Check the organization can quickly retrieve policies, scope, objectives, risk records, operational evidence, competence records, monitoring results, audit reports, management-review records, and corrective-action evidence.
- Confirm sampled employees and process owners can explain how the management system applies to their work, where relevant information is found, and how deviations or improvements are reported.
- Verify certification-audit logistics are ready, including audit scope, site list, key contacts, process schedule, access arrangements, evidence locations, language needs, remote-access needs, and responsible escorts or process owners.
- Record the final readiness status, unresolved major gaps, residual risks, go or no-go decision, target audit date, readiness reviewer, management-system owner, executive approver, date, time, and sign-off.
Take it with you
Use the complete checklist before your next ISO certification audit
Download the printable version, or continue below to see how the same readiness audit can run with evidence, scoring, gap ownership, deadlines, CAPA, verification, and multi-site reporting in Taqtics.How to use it
Treat readiness as evidence of implementation, not a documentation exercise
Map requirements to real processes, test evidence across the full scope, use internal audits as a rehearsal, close major gaps with objective proof, and make the certification decision based on what the system can demonstrate today.
Lock the target standard and scope
Confirm the current edition, amendments, certification boundaries, sites, processes, outsourced activities, and standard-specific requirements.
Audit implementation and evidence
Review leadership, planning, competence, documents, operational controls, monitoring, records, process performance, and employee awareness.
Run internal audit and close gaps
Audit the complete system, classify gaps, assign owners and deadlines, investigate significant failures, and verify corrective-action effectiveness.
Review management and go/no-go
Complete management review, confirm evidence retrieval and audit logistics, review residual risk, and decide whether the organization is ready to proceed.
Live interactive demo
See how an ISO readiness audit works in Taqtics
Complete representative readiness checks, record a major internal-audit gap, attach evidence, assign the management-system owner, and preview the gap-closure workflow.
Capture requirement, process, evidence, readiness status, finding, owner, deadline, verification, and audit history together.
Separate minor document issues from major implementation gaps, assign closure, and keep unresolved readiness risks visible.
Track clause coverage, open gaps, internal-audit findings, CAPA, management-review actions, closure speed, and site readiness.

Illustrative website demo. Responses are not stored or submitted.
Why digitize it
A clearer way to manage ISO readiness across sites, clauses, and process owners
Taqtics connects readiness audits, clause-level evidence, gap scoring, owners, deadlines, CAPA, internal-audit follow-up, management-review actions, approvals, and dashboards in one workflow.
Map requirements to real processes
Assign requirement groups to process owners and connect each check to the records, controls, locations, or teams that demonstrate implementation.
Capture readiness evidence
Attach live photos, records, comments, monitoring results, audit evidence, training proof, management-review actions, and closure evidence.
Turn gaps into tracked closure
Assign owners, deadlines, priorities, escalations, corrective actions, verification, and approval for every readiness gap.
Compare readiness across locations
Track coverage, major gaps, overdue actions, audit findings, CAPA, evidence status, and site-level readiness before certification.
Frequently asked questions
ISO readiness audit checklist FAQs
What should an ISO readiness audit checklist include?
It should cover the exact target standard and scope, context, interested parties, leadership, policy, risks and opportunities, objectives, resources, competence, documented information, operational controls, monitoring, internal audit, nonconformity, corrective action, management review, evidence retrieval, and final certification readiness.
Can this checklist be used for ISO 9001, ISO 14001, ISO 45001, or other management-system standards?
Yes, as a common readiness framework. The exact checklist must then be adapted to the current edition, amendments, clause requirements, terminology, and standard-specific operational controls of the management-system standard being implemented.
What is the difference between an ISO readiness audit and a certification audit?
A readiness audit is an internal gap assessment used to identify and close weaknesses before certification. A certification audit is performed by the selected certification body against the applicable certification scope and standard requirements.
What are common signs that an organization is not ready?
Common readiness gaps include incomplete scope or requirement mapping, newly written procedures with little operating evidence, missing internal-audit coverage, overdue corrective actions, weak objective or monitoring data, incomplete management review, poor employee awareness, and major gaps that have not been independently verified.
How much evidence should be available before certification?
There should be enough operating evidence to demonstrate that applicable management-system processes are implemented and functioning, including monitoring, records, internal audits, corrective-action follow-up, and management review. The exact evidence period depends on the standard, scope, organization, and certification programme.
Does this checklist replace the ISO standard or certification-body requirements?
No. It is a readiness template, not an official ISO document or certification decision tool. Always assess against the current applicable standard, amendments, certification scope, and requirements communicated by the selected certification body.
Map ISO requirements, audit implementation, capture evidence, assign readiness gaps, verify corrective actions, and compare certification readiness across every location.
Run ISO readiness audits with traceable evidence and accountable gap closure
Standardize certification preparation, identify major gaps early, assign closure to the right process owner, verify evidence, and give management a clearer go or no-go view before the external audit.
Printable PDF | Free Taqtics trial | No credit card required