Cover of the ISO 9001 Audit Prep with ISO 27001 Overlap
Free checklist

ISO 9001 Audit Prep with ISO 27001 Overlap

50+ items. 60% clause overlap with ISO 27001. One check, not two.

7
Sections
50
Checkpoints
PDF
A4 · Print

Checklist · 50 items

Get the checklist as PDF

Enter your email and we send you the full checklist as a printable PDF right away.

7 categories50 checkpointsPDF · A4

What's inside

  • All 7 clauses of the standard covered, from scope to certificate
  • 50 concrete checkpoints to tick off, each with a short explanation
  • Stage 1 and Stage 2 audit clearly separated so nothing surfaces at the auditor
  • A PDF to print, share with your team and check off

A Stage 1 and Stage 2 audit-prep checklist for organisations running ISO 9001 and ISO 27001 as an integrated management system (IMS). Uses the High Level Structure (HLS, formerly Annex SL) to avoid duplicate evidence collection.

01

Context & Scope (HLS Clause 4)

7 Checkpoints

  • Organisational context documented

    Internal and external issues captured (SWOT, PESTEL, market environment). [IMS hint] ISO 9001 §4.1 and ISO 27001 §4.1 share this evidence: one document covers both audits.

  • Interested parties identified

    Stakeholder landscape with expectations per group (customers, regulators, employees, suppliers). [IMS hint] §4.2 in both standards: one stakeholder matrix covers both.

  • Scope statement formally approved

    What does the management system cover? Top management has signed the scope and recorded the approval date.

  • Scope boundaries documented

    Which sites, processes, services, products are in scope, which are not. Exclusions with justification.

  • Management system interactions mapped

    [IMS hint] An IMS matrix shows how ISO 9001 and ISO 27001 interlock. One diagram saves you explanation time during the audit.

  • External normative requirements captured

    Which laws, regulations, customer requirements apply to you? A list with an owner per requirement.

  • Process landscape current

    [IMS hint] §4.4 in both standards: process model as the foundation. One landscape, both audits.

02

Leadership & Policy (HLS Clause 5)

7 Checkpoints

  • Quality policy approved

    ISO 9001 §5.2: quality policy signed by top management, communicated, accessible to all employees.

  • Information security policy approved

    ISO 27001 §5.2: information security policy signed and published.

  • Integrated policy as one document possible

    [IMS hint] In an IMS you can bundle quality and information security policy in a single document. Less maintenance and signals to the auditor: one coherent system.

  • Roles and responsibilities documented

    [IMS hint] §5.3 in both standards: a role matrix with RACI for quality and security owners. One matrix is enough.

  • Management commitment evidenced

    Top management meeting minutes with decisions on resources, budgets, audits.

  • Communication of policies documented

    How were the quality and security policies rolled out internally? Awareness session, intranet, mailing with read confirmation.

  • Customer and stakeholder focus formally anchored

    ISO 9001 §5.1.2 requires evidenced customer focus. Proof via customer surveys, complaint management, voice-of-customer reviews.

03

Planning & Risk (HLS Clause 6)

8 Checkpoints

  • Risk register exists

    [IMS hint] ISO 9001 requires risk-based thinking, ISO 27001 a formal risk assessment. One register with a Risk Type column (Quality / Information Security / both) covers both.

  • Risk assessment methodology documented

    Scale for likelihood and impact, evaluation criteria, acceptance thresholds. One methodology for both standards.

  • Opportunities documented

    ISO 9001 core: opportunities tracked alongside risks. Which improvements, new markets, efficiency gains are on the radar?

  • Statement of Applicability prepared

    ISO 27001 §6.1.3 d ONLY: SoA covering all 93 Annex A controls, each with justification for inclusion or exclusion.

  • Risk Treatment Plan documented

    ISO 27001 §6.1.3: actions, owners, deadlines. [IMS hint] Can integrate quality actions, but flag them clearly.

  • Objectives defined per process

    ISO 9001 §6.2: quality objectives measurable, time-bound, with owner. ISO 27001 §6.2 requires information security objectives. [IMS hint] Can be tracked in one objectives list with an Objective Type column.

  • Change management planned

    ISO 9001 §6.3 requires planned changes to the QMS. How is it controlled that changes do not destabilise the system?

  • Risk treatment with residual-risk acceptance

    Which risks are accepted, mitigated, avoided? Top management has explicitly approved residual risks.

04

Support & Documentation (HLS Clause 7)

7 Checkpoints

  • Resource planning documented

    People, infrastructure, work environment, knowledge. [IMS hint] §7.1 in both: one resource overview is enough for both audits.

  • Competence matrix or competence records

    [IMS hint] §7.2 in both standards: who has which skills, which trainings, which certifications. One matrix for QMS and ISMS.

  • Awareness programme documented

    [IMS hint] §7.3 in both standards: employees know the policy, their contribution, the consequences. One awareness concept with modules for quality and security.

  • Communication plan established

    What is communicated when, to whom, internally and externally. [IMS hint] §7.4 in both: one plan, two dimensions.

  • Document control established

    [IMS hint] §7.5 in both standards: one document control process for both management systems. Versioning, approval, distribution, retention.

  • Records control documented

    Which records are kept where for how long? One retention matrix covers both standards.

  • Versioning auditable

    Every controlled document has a version, approval date, owner. Auditor sampling must run cleanly.

05

Operation (HLS Clause 8) — High Divergence

7 Checkpoints

  • [ISO 9001] Customer requirements captured

    ISO 9001 §8.2: how are customer requirements identified, documented, reviewed, agreed? Contract management and quotation process.

  • [ISO 9001] Design & development documented

    ISO 9001 §8.3: where applicable, design and development process with reviews, validation, verification. Often a focus area in Stage 2.

  • [ISO 9001] Service or product realisation controlled

    ISO 9001 §8.5: production and service provision with process control, identification, traceability, customer property handling.

  • [ISO 27001] Operational planning

    ISO 27001 §8.1: planned operational processes implementing the security requirements. Outsourced processes with controls.

  • [ISO 27001] Risk Treatment Plan executed

    ISO 27001 §8.3: planned actions from the RTP are in progress or completed. At least one closed treatment cycle.

  • [ISO 27001] Annex A controls implemented

    All controls flagged as applicable in the SoA are implemented or scheduled with an implementation plan.

  • [IMS hint] Clause 8 has the lowest overlap

    This section requires separate evidence per standard. No shortcut. Plan twice the prep time for Clause 8 compared to Clauses 4 to 7.

06

Performance Evaluation (HLS Clause 9)

7 Checkpoints

  • Monitoring and measurement plan

    [IMS hint] §9.1 in both standards: what is measured, how, when, by whom. One plan with columns for QMS KPIs and ISMS KPIs.

  • KPIs defined per process

    Each core process has KPIs with target value, owner, reporting cadence. Trends visible.

  • Internal audits performed

    [IMS hint] §9.2 in both standards: the audit programme can run as a combined IMS audit, one audit per site instead of two. Audit plan with owner and findings.

  • Management review at least annually

    [IMS hint] §9.3 in both standards: a joint management review covering quality and security topics is explicitly allowed and reduces effort. Minutes with decisions.

  • Customer satisfaction measurement

    ISO 9001 core: customer satisfaction systematically captured. NPS, surveys, complaint analysis, voice of the customer.

  • KPI trending visible

    At least six months of data showing KPI evolution. Not just a snapshot.

  • Review minutes with decisions

    Management reviews and audit reviews minuted with decisions, owners, deadlines. Follow-up traceable.

07

Improvement (HLS Clause 10)

7 Checkpoints

  • Nonconformity process documented

    [IMS hint] §10.1 in both standards: one process for nonconformities, whether quality or security related. One platform, one process.

  • Corrective action process established

    Root cause analysis, actions, effectiveness check. [IMS hint] CAPA for both management systems in a single tool.

  • Continual improvement plan

    [IMS hint] §10.3 (9001) and §10.2 (27001): evidenced continual improvement activity. Lessons learned, improvement tickets, maturity roadmap.

  • Lessons learned from last audit cycle

    What came up in the last internal or external audit? Which findings are closed, which still open?

  • CAPA tracking transparent

    How many corrective actions are open, how many closed, what is the average cycle time? One overview covers both standards.

  • Maturity progression visible

    Self-assessment or external maturity assessments show how the IMS evolves. Not strictly required, but a strong signal to the auditor.

  • Pre-audit walkthrough completed

    [IMS hint] At least one internal pre-audit walkthrough with IMS focus evidenced: auditability of both standards verified in one pass, findings recorded.

Get the complete checklist as a PDF

All 50 checkpoints on A4 to print and check off. Free, all you need is your email address.

Get the download