Audit Workshop
banner
auditworkshop.bsky.social
Audit Workshop
@auditworkshop.bsky.social
ISO standards auditor training courses, certified by Exemplar Global, are delivered by practising auditors.
A word in the standard reads vaguely. Where do you go to settle it? Clause 2 lists the one document needed beside it.
ISO 9001:2026 2 Normative references
Watch the full clause explained in plain words on YouTube.
youtu.be
October 2, 2026 at 9:35 AM
How to Become an ISO 27001 Information Security Auditor
How to Become an ISO 27001 Information Security Auditor
Information security auditing is one of the fastest growing career paths in compliance right now. With data breaches making headlines every week, organisations are under real pressure to demonstrate their ISO 27001 controls actually work. That means demand for qualified ISO 27001 auditors is climbing. But where do you actually start? The path typically looks like this: First, build your foundation in ISO 27001 concepts and the structure of an information security management system. Then develop your auditing skills through a recognised Internal Auditor or Lead Auditor course. From there, you log audit experience and earn your formal credentials. The Lead Auditor qualification is the one that opens doors to external certification audits and consulting work. It is also the credential employers and certification bodies look for. The key thing most people miss is this. Knowing the standard is not enough. You need to understand how to gather evidence, write findings, and run an audit from opening meeting to closing meeting. We have put together a full breakdown of the career path, the qualifications worth getting, and what the role actually involves day to day. Read the full guide here: https://auditworkshop.com/blog/become-iso-27001-auditor #ISO27001 #InformationSecurity #ISOAuditor #CyberSecurityCareers #AuditCareer
auditworkshop.com
October 2, 2026 at 6:12 AM
Before a construction crew pours concrete, someone checks the weather, the mix and the crew.
October 2, 2026 at 4:13 AM
Who is ISO 9001 actually written for? Clause 1 answers that before anything else.
ISO 9001:2026 1 Scope
Watch the full clause explained in plain words on YouTube.
youtu.be
October 2, 2026 at 1:35 AM
Audit Interviewing Techniques Every Auditor Should Master
Audit Interviewing Techniques Every Auditor Should Master
Most audit findings do not come from documents. They come from conversations. Yet interviewing is the skill auditors practice the least. We spend hours reviewing procedures and checklists, then walk into an interview and wing it. Here are a few things that actually make a difference in audit interviews. Ask open questions first. 'Walk me through what happens when...' gets you far more than 'Do you follow this procedure?' Listen for hesitation. When someone pauses or qualifies their answer, that is often where the real story is. Avoid leading. If you hint at the answer you expect, you will get exactly that answer, and nothing useful. Build rapport early. A relaxed auditee gives you accurate information. A nervous one gives you rehearsed answers. Take notes on what is said, not just what you planned to ask. Interviewing well is a craft. It takes practice, awareness, and a genuine curiosity about how things actually work. We have written a full breakdown of audit interviewing techniques on the Audit Workshop blog. Worth a read before your next audit. https://auditworkshop.com/blog/audit-interviewing-techniques #ISOAuditing #AuditSkills #LeadAuditor #InternalAuditor #AuditTraining
auditworkshop.com
October 2, 2026 at 12:37 AM
A bakery. A software team. A hospital ward. Nothing in common, except the need to get it right every time.
ISO 9001:2026 Overview
Watch the full clause explained in plain words on YouTube.
youtu.be
October 1, 2026 at 11:16 PM
A batch ships with the wrong label.
October 1, 2026 at 10:38 PM
ISO 17100 Clause 6 Post Production: Feedback, Archiving and Data Protection
ISO 17100 Clause 6 Post Production: Feedback, Archiving and Data Protection
Most translation providers focus heavily on the translation and revision stages of ISO 17100. But Clause 6, the post production phase, is where many fall short during audits. Clause 6 covers three areas that auditors look at closely. First, feedback handling. Does the TSP have a documented process for receiving, reviewing, and acting on client feedback? Auditors want to see evidence that feedback actually influences service improvement, not just a complaint log that goes nowhere. Second, archiving. ISO 17100 requires translation project records to be retained in a way that supports retrievability and confidentiality. Auditors will check whether your retention periods are defined and whether archived files are actually protected. Third, data protection. This is increasingly important. Client source materials, translated content, and translator agreements can all contain sensitive information. Your documented controls need to reflect this. Post production is often treated as an afterthought, but it is a genuine audit risk area if processes are undocumented or inconsistently applied. We have published a detailed breakdown of Clause 6 on the Audit Workshop blog. Worth reading if you are involved in translation quality management or preparing for ISO 17100 certification. https://auditworkshop.com/blog/iso-17100-clause-6-post-production #ISO17100 #TranslationQuality #ISOAuditing #QualityManagement #ISOCompliance
auditworkshop.com
October 1, 2026 at 6:12 AM
An auditor asks a forklift driver about the quality policy.
October 1, 2026 at 4:13 AM
The AI Policy Explained: Inside Clause 5.2 of ISO 42001
The AI Policy Explained: Inside Clause 5.2 of ISO 42001
Most organisations rushing into AI governance skip the one clause that sets the tone for everything else. Clause 5.2 of ISO 42001 requires top management to establish an AI policy. Not a general tech policy. Not a data policy. A specific commitment to responsible AI development and use. What makes a strong AI policy under this clause? It needs to align with the organisation's AI objectives, commit to satisfying applicable requirements, and support continual improvement of the AI management system. It also needs to be communicated internally and made available to relevant interested parties. The tricky part is that many organisations either write something too vague to be useful or copy a generic template that does not reflect how they actually use AI. Auditors look for evidence that the policy is genuinely understood by the people responsible for AI systems, not just sitting in a shared drive. We have broken down exactly what Clause 5.2 requires, common gaps we see in practice, and what good looks like in our latest article. Worth a read if you are preparing for ISO 42001 certification or building out your AI governance framework. https://auditworkshop.com/blog/iso-42001-clause-5-2-ai-policy #ISO42001 #AIGovernance #AIManagement #ISOAuditor #ArtificialIntelligence
auditworkshop.com
October 1, 2026 at 12:37 AM
Leadership and Commitment in ISO 27001: Inside Clause 5.1
Leadership and Commitment in ISO 27001: Inside Clause 5.1
Most information security failures are not technical failures. They are leadership failures. Clause 5.1 of ISO 27001 makes this explicit. Top management cannot delegate accountability for the information security management system. They must demonstrate commitment through action, not just policy sign-off. What does that actually look like in practice? It means ensuring the ISMS has the resources it needs. It means integrating information security into the way the business operates, not treating it as a separate IT function. It means communicating why information security matters and reinforcing that message consistently. When auditors assess Clause 5.1, they are not looking for a signed policy document. They are looking for evidence that leadership is genuinely engaged. That means interviews, meeting minutes, strategic decisions, and resource allocation records all come into scope. If leadership sees the ISMS as a compliance checkbox, that attitude will show up in the audit. We have published a detailed breakdown of Clause 5.1 on the Audit Workshop blog, covering what the clause requires, how auditors evaluate it, and what good leadership commitment looks like in real organisations. Worth a read if you are preparing for an ISO 27001 audit or building out your ISMS. https://auditworkshop.com/blog/iso-27001-leadership-commitment-5-1 #ISO27001 #InformationSecurity #ISOAuditor #ISMS #LeadershipAndCommitment
auditworkshop.com
September 30, 2026 at 6:12 AM
Managing an Audit Programme Under Clause 5 of ISO 19011:2026
Managing an Audit Programme Under Clause 5 of ISO 19011:2026
Most organisations run audits. Far fewer actually manage an audit programme. There is a difference, and Clause 5 of ISO 19011:2026 is where that difference lives. Clause 5 covers how to establish, plan, implement, monitor, review, and improve an audit programme at the organisational level. It is not about individual audits. It is about the system that governs all of them. A few things Clause 5 expects you to think through: What are the objectives of your audit programme, and are they tied to actual organisational risk? Who has authority over the programme, and are they genuinely competent to manage it? How are audit scope, frequency, and methods being adjusted based on results and changing context? How is the programme itself being reviewed for effectiveness? These are strategic questions, not administrative ones. Getting them right is what separates a mature audit function from a box-ticking exercise. We have published a detailed breakdown of how Clause 5 works in practice, including what auditors and audit programme managers need to understand heading into 2026. Worth a read if you manage or oversee an audit programme. https://auditworkshop.com/blog/iso-19011-clause-5-audit-programme #ISOAuditing #ISO19011 #AuditProgramme #LeadAuditor #ISOCompliance
auditworkshop.com
September 30, 2026 at 12:37 AM
Could a policy copied from another company's website pass an audit?
September 29, 2026 at 10:38 PM
Defining the Scope of Your OH&S Management System: Clause 4.3
Defining the Scope of Your OH&S Management System: Clause 4.3
Getting your OH&S scope wrong is one of the most common issues we see in ISO 45001 certification audits. Clause 4.3 requires your organisation to determine the boundaries and applicability of your OH&S management system. But many organisations either write a scope that is too vague or one that accidentally excludes workers, sites, or activities that clearly fall within their control. A well defined scope needs to consider a few things: The external and internal issues identified in Clause 4.1 The requirements of workers and other interested parties from Clause 4.2 The work activities your organisation performs and the locations where they happen One practical tip we share in our ISO 45001 training is to think about your scope from the perspective of a worker on the ground. If they are performing work under your direction, they probably need to be covered. Auditors will test your scope against reality. If your documented scope says one thing but your actual operations tell a different story, that gap becomes a nonconformance. We have written a full breakdown of Clause 4.3 on the Audit Workshop blog. Worth a read if you are building or reviewing your OH&S management system. https://auditworkshop.com/blog/ohs-management-system-scope-clause-4-3 #ISO45001 #OHSManagement #InternalAuditor #ISOAuditor #WorkplaceSafety
auditworkshop.com
September 29, 2026 at 6:12 AM
A new starter sees the quality policy framed in reception.
September 29, 2026 at 4:14 AM
A customer rings to complain for the third time this month.
September 28, 2026 at 10:38 PM
ISO 9001 Clause 4.3: Determining the Scope of Your QMS
ISO 9001 Clause 4.3: Determining the Scope of Your QMS
One of the most overlooked steps in building a QMS is also one of the most important. Clause 4.3 of ISO 9001 requires you to define the scope of your Quality Management System. Not just write a sentence for a document, but genuinely think through what is included, what is excluded, and why. Get this wrong and everything downstream becomes harder. Auditors will test your scope against your context, your interested parties, and your actual operations. A few things worth knowing before you write your scope statement: Exclusions are allowed, but they must be justified. You cannot simply exclude a clause because it is inconvenient. Your scope should reflect reality, not aspiration. If a site or process is not covered, say so clearly. The scope must be available as documented information. It is not optional. We have put together a detailed breakdown of Clause 4.3 on the Audit Workshop blog, covering what the standard actually requires, common mistakes organisations make, and how auditors assess scope during a certification audit. Worth a read if you are preparing for certification or just want to tighten up your QMS foundations. https://auditworkshop.com/blog/iso-9001-clause-4-3-qms-scope #ISO9001 #QualityManagement #ISOAuditor #QMS #ISOCertification
auditworkshop.com
September 28, 2026 at 6:12 AM
A software company has a lovely quality policy on the wall. But deadlines always beat testing.
September 28, 2026 at 4:13 AM
ISO 9001 for Transport and Logistics Operators
ISO 9001 for Transport and Logistics Operators
Transport and logistics operations run on tight margins and even tighter timelines. When things go wrong, the cost is not just a delayed shipment. It is lost contracts, damaged goods, compliance breaches, and reputation hits that take months to recover from. ISO 9001 gives logistics operators a framework to get ahead of those problems rather than react to them. Here is what that looks like in practice: Clear process controls for dispatch, warehousing, and subcontractor management. Documented procedures that reduce reliance on individual knowledge. Nonconformance tracking that actually drives improvement. Customer feedback loops built into operations, not just collected and filed away. The standard is not about adding paperwork. It is about making your operation more reliable and easier to audit when customers or regulators come knocking. We have put together a practical guide covering how ISO 9001 applies specifically to transport and logistics, including the clauses that matter most and the common gaps auditors find in this sector. Worth a read if you work in or audit this industry. https://auditworkshop.com/blog/iso-9001-transport-logistics #ISO9001 #TransportAndLogistics #QualityManagement #ISOAuditor #SupplyChain
auditworkshop.com
September 28, 2026 at 12:37 AM
A plant manager skips the quality meeting again.
September 27, 2026 at 10:38 PM
What Is a Surveillance Audit
What Is a Surveillance Audit
You passed your ISO certification audit. Congratulations. But that is not the end of the journey. It is actually the beginning. Once certified, your organisation enters a three year certification cycle. During years one and two, your certification body sends auditors back to check that your management system is still working. These visits are called surveillance audits. Surveillance audits are shorter than your initial certification audit, but do not underestimate them. Auditors are looking for evidence that your system is alive and improving, not just sitting in a folder somewhere. Common focus areas include internal audit results, management review records, corrective actions, and any changes to your organisation since the last visit. The biggest mistake organisations make is treating certification as a finish line and then scrambling before each surveillance visit. The organisations that sail through are the ones maintaining their systems consistently year round. If you want to understand exactly what happens in a surveillance audit and how to stay ready, we have written a full breakdown on the blog. https://auditworkshop.com/blog/what-is-a-surveillance-audit #ISO9001 #ISOAuditing #SurveillanceAudit #ISOCertification #QualityManagement
auditworkshop.com
September 27, 2026 at 6:12 AM
The quality manager runs the system. The chief executive just signs the policy.
September 27, 2026 at 4:13 AM
How to Become an ISO 45001 OH&S Auditor
How to Become an ISO 45001 OH&S Auditor
Thinking about becoming an ISO 45001 auditor? It is one of the most in-demand credentials for anyone working in health and safety. Organisations across every industry need people who can audit their OH&S management systems with confidence, not just tick boxes. Here is what the path generally looks like. First, you need a solid understanding of ISO 45001 requirements. Then you build practical auditing skills including planning, conducting interviews, writing findings, and reporting. From there, formal training at the Internal Auditor or Lead Auditor level gives you a recognised credential that employers and certification bodies take seriously. Exemplar Global recognised training adds even more weight to your qualification, with a digital badge you can share on LinkedIn and a Certificate of Attainment as proof of competency. The good news is you do not need to already work in safety to start. Many quality and environmental professionals make the move across, and the auditing skills transfer well. We put together a full guide on exactly how to get there, what to study, and what certification options are available. Read it here: https://auditworkshop.com/blog/become-iso-45001-ohs-auditor #ISO45001 #OHSAuditor #HealthAndSafety #ISOAuditor #AuditorTraining
auditworkshop.com
September 27, 2026 at 12:37 AM
An order leaves sales, but production never gets the special packing note.
September 26, 2026 at 10:38 PM