
ISO 9001 Audit Prep with ISO 27001 Overlap
50+ items. 60% clause overlap with ISO 27001. One check, not two.
- 7
- Sections
- 50
- Checkpoints
- A4 · Print
Checklist · 50 items
Get the checklist as PDF
Enter your email and we send you the full checklist as a printable PDF right away.
What's inside
- All 7 clauses of the standard covered, from scope to certificate
- 50 concrete checkpoints to tick off, each with a short explanation
- Stage 1 and Stage 2 audit clearly separated so nothing surfaces at the auditor
- A PDF to print, share with your team and check off
A Stage 1 and Stage 2 audit-prep checklist for organisations running ISO 9001 and ISO 27001 as an integrated management system (IMS). Uses the High Level Structure (HLS, formerly Annex SL) to avoid duplicate evidence collection.
Context & Scope (HLS Clause 4)
7 Checkpoints
Organisational context documented
Internal and external issues captured (SWOT, PESTEL, market environment). [IMS hint] ISO 9001 §4.1 and ISO 27001 §4.1 share this evidence: one document covers both audits.
Interested parties identified
Stakeholder landscape with expectations per group (customers, regulators, employees, suppliers). [IMS hint] §4.2 in both standards: one stakeholder matrix covers both.
Scope statement formally approved
What does the management system cover? Top management has signed the scope and recorded the approval date.
Scope boundaries documented
Which sites, processes, services, products are in scope, which are not. Exclusions with justification.
Management system interactions mapped
[IMS hint] An IMS matrix shows how ISO 9001 and ISO 27001 interlock. One diagram saves you explanation time during the audit.
External normative requirements captured
Which laws, regulations, customer requirements apply to you? A list with an owner per requirement.
Process landscape current
[IMS hint] §4.4 in both standards: process model as the foundation. One landscape, both audits.
Leadership & Policy (HLS Clause 5)
7 Checkpoints
Quality policy approved
ISO 9001 §5.2: quality policy signed by top management, communicated, accessible to all employees.
Information security policy approved
ISO 27001 §5.2: information security policy signed and published.
Integrated policy as one document possible
[IMS hint] In an IMS you can bundle quality and information security policy in a single document. Less maintenance and signals to the auditor: one coherent system.
Roles and responsibilities documented
[IMS hint] §5.3 in both standards: a role matrix with RACI for quality and security owners. One matrix is enough.
Management commitment evidenced
Top management meeting minutes with decisions on resources, budgets, audits.
Communication of policies documented
How were the quality and security policies rolled out internally? Awareness session, intranet, mailing with read confirmation.
Customer and stakeholder focus formally anchored
ISO 9001 §5.1.2 requires evidenced customer focus. Proof via customer surveys, complaint management, voice-of-customer reviews.
Planning & Risk (HLS Clause 6)
8 Checkpoints
Risk register exists
[IMS hint] ISO 9001 requires risk-based thinking, ISO 27001 a formal risk assessment. One register with a Risk Type column (Quality / Information Security / both) covers both.
Risk assessment methodology documented
Scale for likelihood and impact, evaluation criteria, acceptance thresholds. One methodology for both standards.
Opportunities documented
ISO 9001 core: opportunities tracked alongside risks. Which improvements, new markets, efficiency gains are on the radar?
Statement of Applicability prepared
ISO 27001 §6.1.3 d ONLY: SoA covering all 93 Annex A controls, each with justification for inclusion or exclusion.
Risk Treatment Plan documented
ISO 27001 §6.1.3: actions, owners, deadlines. [IMS hint] Can integrate quality actions, but flag them clearly.
Objectives defined per process
ISO 9001 §6.2: quality objectives measurable, time-bound, with owner. ISO 27001 §6.2 requires information security objectives. [IMS hint] Can be tracked in one objectives list with an Objective Type column.
Change management planned
ISO 9001 §6.3 requires planned changes to the QMS. How is it controlled that changes do not destabilise the system?
Risk treatment with residual-risk acceptance
Which risks are accepted, mitigated, avoided? Top management has explicitly approved residual risks.
Support & Documentation (HLS Clause 7)
7 Checkpoints
Resource planning documented
People, infrastructure, work environment, knowledge. [IMS hint] §7.1 in both: one resource overview is enough for both audits.
Competence matrix or competence records
[IMS hint] §7.2 in both standards: who has which skills, which trainings, which certifications. One matrix for QMS and ISMS.
Awareness programme documented
[IMS hint] §7.3 in both standards: employees know the policy, their contribution, the consequences. One awareness concept with modules for quality and security.
Communication plan established
What is communicated when, to whom, internally and externally. [IMS hint] §7.4 in both: one plan, two dimensions.
Document control established
[IMS hint] §7.5 in both standards: one document control process for both management systems. Versioning, approval, distribution, retention.
Records control documented
Which records are kept where for how long? One retention matrix covers both standards.
Versioning auditable
Every controlled document has a version, approval date, owner. Auditor sampling must run cleanly.
Operation (HLS Clause 8) — High Divergence
7 Checkpoints
[ISO 9001] Customer requirements captured
ISO 9001 §8.2: how are customer requirements identified, documented, reviewed, agreed? Contract management and quotation process.
[ISO 9001] Design & development documented
ISO 9001 §8.3: where applicable, design and development process with reviews, validation, verification. Often a focus area in Stage 2.
[ISO 9001] Service or product realisation controlled
ISO 9001 §8.5: production and service provision with process control, identification, traceability, customer property handling.
[ISO 27001] Operational planning
ISO 27001 §8.1: planned operational processes implementing the security requirements. Outsourced processes with controls.
[ISO 27001] Risk Treatment Plan executed
ISO 27001 §8.3: planned actions from the RTP are in progress or completed. At least one closed treatment cycle.
[ISO 27001] Annex A controls implemented
All controls flagged as applicable in the SoA are implemented or scheduled with an implementation plan.
[IMS hint] Clause 8 has the lowest overlap
This section requires separate evidence per standard. No shortcut. Plan twice the prep time for Clause 8 compared to Clauses 4 to 7.
Performance Evaluation (HLS Clause 9)
7 Checkpoints
Monitoring and measurement plan
[IMS hint] §9.1 in both standards: what is measured, how, when, by whom. One plan with columns for QMS KPIs and ISMS KPIs.
KPIs defined per process
Each core process has KPIs with target value, owner, reporting cadence. Trends visible.
Internal audits performed
[IMS hint] §9.2 in both standards: the audit programme can run as a combined IMS audit, one audit per site instead of two. Audit plan with owner and findings.
Management review at least annually
[IMS hint] §9.3 in both standards: a joint management review covering quality and security topics is explicitly allowed and reduces effort. Minutes with decisions.
Customer satisfaction measurement
ISO 9001 core: customer satisfaction systematically captured. NPS, surveys, complaint analysis, voice of the customer.
KPI trending visible
At least six months of data showing KPI evolution. Not just a snapshot.
Review minutes with decisions
Management reviews and audit reviews minuted with decisions, owners, deadlines. Follow-up traceable.
Improvement (HLS Clause 10)
7 Checkpoints
Nonconformity process documented
[IMS hint] §10.1 in both standards: one process for nonconformities, whether quality or security related. One platform, one process.
Corrective action process established
Root cause analysis, actions, effectiveness check. [IMS hint] CAPA for both management systems in a single tool.
Continual improvement plan
[IMS hint] §10.3 (9001) and §10.2 (27001): evidenced continual improvement activity. Lessons learned, improvement tickets, maturity roadmap.
Lessons learned from last audit cycle
What came up in the last internal or external audit? Which findings are closed, which still open?
CAPA tracking transparent
How many corrective actions are open, how many closed, what is the average cycle time? One overview covers both standards.
Maturity progression visible
Self-assessment or external maturity assessments show how the IMS evolves. Not strictly required, but a strong signal to the auditor.
Pre-audit walkthrough completed
[IMS hint] At least one internal pre-audit walkthrough with IMS focus evidenced: auditability of both standards verified in one pass, findings recorded.
Get the complete checklist as a PDF
All 50 checkpoints on A4 to print and check off. Free, all you need is your email address.