ISO 9001 Implementation Packages: Best Options for Small Manufacturers in 2026

Small manufacturers choosing an ISO 9001 implementation package face three real paths — full consulting, a DIY documentation kit, or a hybrid approach. This guide breaks down real costs, hidden internal labor, and what ISO 9001 actually requires versus what a package sells you, ahead of the ISO 9001:2026 transition.

How Small Shops Choose the Right Path to a Certified QMS

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


You’ve Committed to ISO 9001. Now You Have to Pick a Path.

Deciding to pursue ISO 9001 certification is the easy part. The harder decision comes next: how do you actually build the quality management system a registrar will audit against?

Most small manufacturers hit this fork in the road within the first week of research. A consultant quotes a number that makes the owner’s stomach drop. A documentation toolkit promises the same result for a fraction of the price — but someone still has to do the work. A hybrid option sits in between, and nobody explains clearly what it includes.

This isn’t a question of whether ISO 9001 is worth it — if you’re reading this, you’ve already answered that. This is about which ISO 9001 implementation package gets you to a certified QMS without wasting six figures or six months you don’t have.

From the Floor: After 25+ years in heavy industrial manufacturing and operations leadership, I’ve watched the same failure pattern repeat across shops of very different sizes: companies buy documentation before deciding who’s actually going to own the system. I’ve sat across the table from operations managers three weeks out from a Stage 1 audit, watching them realize their “documentation” was a folder of half-finished Word files nobody had touched since the project kicked off. The templates were never the problem — the missing ownership, process integration, and follow-through were. The shops that made it through cleanly picked an implementation path that matched their actual internal bandwidth, not the one that looked cheapest on a sales page.

Before your next audit, run this gap check → The ISO 9001 Roadmap walks you through exactly what a certified QMS needs, phase by phase, so you’re picking a package based on what you’re missing — not guessing.


In This Guide

  • The three real paths to a certified QMS — and what each actually costs
  • What’s inside a documentation package vs. what a consultant delivers
  • The hidden cost most owners forget to budget for
  • How to match a package to your shop’s size and timeline
  • Why the ISO 9001:2026 transition changes the calculation right now
  • A pre-purchase readiness checklist


👉 Start Here (Top Resources)


The Three Ways Small Manufacturers Actually Get to a Certified QMS

Strip away the marketing language and every ISO 9001 implementation package on the market falls into one of three categories.

PathTypical Planning RangeTimelineInternal EffortBest For
Full Consulting$15,000–$75,000+~2 months in highly prepared organizationsLowTight deadlines, limited internal capacity, or little QMS implementation experience
DIY Documentation Kit$1,500–$10,0003–6 monthsHighA quality-minded employee with time to own the project
Hybrid (Kit + Training)$3,000–$15,0003–4 monthsModerateMost small-to-midsize manufacturers

Ranges are planning estimates, not standardized market prices — actual cost depends on company size, QMS scope, existing processes, consultant involvement, training requirements, and certification-body fees. As one current example: 9001Simplified publishes starting prices of $2,490 for its DIY toolkit, $3,930 for its hybrid path, and $13,530 for full-service — a useful reference point, not an industry benchmark.

Full Consulting: A consultant runs the entire project — process mapping, documentation, gap closure, audit prep. 9001Simplified currently advertises a certification guarantee and claims its full-service approach — priced from $13,530 — can reduce internal team time by about 90%. You’re buying speed and certainty, not savings.

DIY Documentation Kit: You get editable templates — procedures, forms, records, and audit tools — and your team builds the QMS around them. Lowest cost, but it requires real internal time. 9001Simplified’s documentation toolkit, priced from $2,490, is built specifically for manufacturers rather than generic service businesses, which matters once you start adapting templates to a shop floor.

Hybrid — Kit Plus Training: You buy the documentation kit and pair it with lead implementer or internal auditor training for whoever runs the project. This is often a practical fit for shops in the 20–150 employee range: enough internal capability to execute, enough outside structure to avoid the false starts that eat months.

ISO 9001 implementation package options showing full consulting, DIY documentation kit, and hybrid kit with training for manufacturers
Three ISO 9001 implementation approaches, full consulting, DIY documentation, and hybrid support, leading to a certified quality management system.

What’s Actually Inside an Implementation Package

ISO 9001 tells you what your QMS needs to accomplish. An implementation package gives you tools for building and managing it.

The standard doesn’t prescribe a single document set or require every organization to use the same templates. A quality manual, for example, isn’t specifically mandated by ISO 9001, and neither is a standalone CAPA procedure or a particular calibration-log format. What a legitimate implementation package should give you is practical tools for addressing the standard’s documented-information requirements and managing the processes that matter to your QMS: procedures, forms, records, internal audit tools, and training materials, adapted to your operation rather than issued as a fixed checklist.

For a manufacturer, that means checking whether the package includes practical tools for the areas that matter most on a shop floor: supplier controls, nonconformity and corrective action, internal auditing, equipment and measurement controls, and production-related processes. A kit built primarily for generic service businesses may require substantial rework before it’s genuinely useful in a manufacturing environment. That rework is the hidden cost below.

Most teams miss this step — checking whether a documentation kit was actually built for manufacturers before buying it. Run the Manufacturing Compliance Checklist against any kit you’re evaluating before you commit budget to it.


What This Really Costs — Beyond the Sticker Price

ISO 9001 implementation package cost breakdown showing package price, internal labor, training, process changes, corrective actions, and certification audit
The cost of an ISO 9001 implementation package is only part of the investment. Internal labor, training, process changes, corrective actions, and certification also affect the total cost.

We broke down the full cost structure of ISO 9001 certification elsewhere, but the number that trips up most owners comparing packages isn’t on any sales page: internal labor.

Someone in your organization has to actually do the work — mapping processes, writing procedures, training the floor, running mock audits. For example, at a loaded internal labor rate of $35/hour, roughly 150–250 hours of implementation work represents $5,250–$8,750 in internal labor — a planning estimate, not a fixed number, but real cost that doesn’t show up in the package price you’re comparing.

That’s the actual difference between the three paths above. Full consulting can substantially reduce internal implementation labor, but it doesn’t eliminate the organization’s responsibility for building and operating the QMS — a DIY kit shifts that balance the other direction, trading cash cost for internal time. The hybrid path is where most shops land once they price both sides honestly.

⚠️ If a documentation kit’s price looks dramatically lower than everything else on the market, ask what’s excluded — training, support, or manufacturing-specific templates are the usual gaps.

If you’re not 100% certain your current documentation would survive an internal audit today → Run the Manufacturing Compliance Checklist against your own operation first. Most gaps show up there before they show up in a registrar’s finding.


The Objection Every Owner Raises: “We Don’t Have Time for This”

This is the real reason shops overpay for full consulting when a hybrid path would work — not because consulting is a bad option, but because the time objection gets resolved by writing a bigger check instead of scoping the project honestly.

The practical answer: a documentation kit doesn’t require your best people to disappear for six months. For a small manufacturer using a reasonably complete toolkit, a practical planning assumption is one project owner spending roughly 8–12 hours a week over 12–16 weeks, with additional participation from process owners as needed — a materially different commitment than building a QMS from scratch. If your operation genuinely doesn’t have that kind of time available anywhere internally, that’s real information — it tells you full consulting is probably the right call, not a fallback.


Which Package Fits Your Shop

  • If you are a fabrication or machine shop under 25 employees with no dedicated quality role → the hybrid path is often a strong fit. You need the structure a kit provides, but also someone trained to interpret it correctly the first time.
  • If you are already ISO 9001 experienced but building your first formal QMS at a new facility → a documentation kit alone is usually enough. You have the internal knowledge; you just need the template scaffolding.
  • If you are under customer or contract pressure to certify within 90–120 days → full consulting is worth the premium. Speed is the product you’re buying, and a guaranteed timeline has real value against a contract deadline.
  • If you are still deciding whether to build in-house or hire out entirely → read our full comparison of implementation packages versus hiring a consultant before committing budget either direction.

Why the ISO 9001:2026 Transition Changes the Math Right Now

ISO has scheduled publication of ISO 9001:2026 for September 16, 2026 — the sixth edition, replacing ISO 9001:2015. Certified organizations will receive a transition period to migrate to the new edition once it’s published; the final transition arrangements and deadlines will be confirmed through the accreditation and certification community rather than fixed in advance.

This matters for anyone choosing a package right now. Before you buy a kit or start a consulting engagement, ask directly whether the 2015-based deliverables include a path to the 2026 revision at no extra cost — several providers, 9001Simplified among them, are positioning free upgrade paths for exactly this reason. As of publication of this article, ISO 9001:2015 remains the current published edition and can still be used for certification; once ISO 9001:2026 is published, certification-body transition arrangements will determine how organizations move to the new edition.

Full transition timeline: ISO 9001:2026 Is Coming — What Manufacturers Should Do Right Now.

If you’re purchasing the current standard while you evaluate packages, ANSI’s bundle pricing is typically more cost-effective than buying individual standards separately if your certification plans include more than one document.


Before You Buy: Readiness Checklist

✅ You’ve mapped roughly how much internal time your team can realistically commit weekly
✅ You know whether your customer or contract deadline requires a guaranteed timeline
✅ You’ve confirmed any documentation kit includes manufacturing-specific templates — calibration logs, NCR/CAPA forms — not generic service-business content
✅ You’ve asked whether the package includes a no-cost path to ISO 9001:2026 once published
✅ You’ve budgeted internal labor hours, not just the package price, into your real cost comparison
✅ You’ve identified who internally will own the project day-to-day, regardless of which path you choose

ISO 9001 implementation package readiness checklist showing internal time, deadline, package contents, transition planning, labor cost, and project ownership
Before choosing an ISO 9001 implementation package, manufacturers should evaluate available time, project ownership, internal labor, package contents, and certification deadlines.

Looking past certification → Every path above gets you to a certified QMS — none of them are built to manage it afterward. Once you’re certified, refer your company to QualityWeb 360 for day-to-day document control, internal audit tracking, and CAPA management. Worth bookmarking now, not something to evaluate mid-implementation.


FAQ

Is a DIY documentation kit actually enough to pass a registrar audit?

Yes, provided the kit is built for manufacturing environments and someone internally has the time and authority to implement it fully — not just fill in templates. Registrars don’t certify you because the paperwork looks complete; they evaluate whether your QMS is implemented and operating effectively, using documented information and records as evidence where required.

How much should I budget for the whole implementation, not just the package?

As a planning range, total spend — documentation, training, internal labor, and the certification audit — typically lands between $8,000 and $30,000 for a facility under 100 employees choosing a hybrid path, though full consulting engagements can run considerably higher. See our complete cost breakdown for the component-by-component numbers.

Can I switch from a DIY kit to a consultant partway through if I fall behind?

In most cases, yes — several providers, including 9001Simplified, offer both toolkit and full-service consulting under the same umbrella, which makes switching paths less disruptive than starting over with a new vendor. Confirm this before you buy if it’s a realistic possibility.

Does an implementation package include the ISO 9001 standard document itself?

No. Packages help you build a QMS that meets the standard’s requirements, but the standard itself is a separate purchase from ANSI Webstore or another authorized source.

Does a documentation kit help with ongoing QMS management after certification?

Most one-time kits are built for the implementation phase, not day-to-day management. Once you’re certified, tracking document revisions, CAPA status, and audit schedules on an ongoing basis is a different problem than building the system was. Tools like QualityWeb 360 are built specifically for that post-certification stage — worth evaluating once your registrar audit is behind you, not before.

Is it cheaper to build documentation entirely from scratch, with no kit or consultant?

Almost never, once internal labor is priced honestly. Building a full set of QMS documentation from a blank page typically takes far longer than adapting a purpose-built kit, and the risk of missing a documented-information requirement is higher without a template mapped to the standard.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts

Not Sure What to Do Next?

🔹 Still researching? Start with the ISO 9001 Certification Guide for the full picture of what certification requires before committing to a package.

🔹 Ready to compare specific packages? Read the 9001Simplified Review for an honest look at toolkit and consulting pricing, or go directly to 9001Simplified’s implementation packages.

🔹 Need to buy the standard itself first? Get ISO 9001:2015 from ANSI Webstore — code CC2026 takes 5% off through December 31, 2026.

🔹 Not sure you even need to purchase the standard separately? Do You Need to Buy ISO 9001 to Get Certified? answers that directly.

🔹 Already thinking past certification? Refer your company to QualityWeb 360 to manage document control, internal audits, and CAPA once your QMS is certified.

The right implementation package isn’t the cheapest one or the fastest one — it’s the one that matches how much internal time your shop actually has to give it. Get that match wrong, and you pay for it twice: once in the package price, and again in the rework when the first path stalls out. The Standards Navigator breaks down every implementation option we can verify, so you’re choosing based on what fits your operation, not a sales page.


Stay Ahead of the Next Implementation Decision

Picking the wrong ISO 9001 implementation package doesn’t usually fail loudly — it fails quietly, six weeks in, when the documentation stalls and nobody on the floor has touched the toolkit in a month.

Shops that struggle here picked a path based on price alone. Shops that succeed matched the package to their actual internal bandwidth before they signed anything.

The Standards Navigator covers ISO 9001 implementation, documentation, and certification decisions for manufacturers who need practical answers, not sales pitches.

👉 Get updates on ISO 9001 implementation and documentation
👉 Be first to access new gap assessment and readiness checklists

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISO 14001:2026 Clauses Explained: A Complete Clause-by-Clause Breakdown

ISO 14001:2026 replaces the 2015 edition, but most of the standard is unchanged. This guide breaks down every clause — the five named environmental conditions in 4.1, the strengthened scope requirements in 4.3, the new Clause 6.3 on change management, the restructured audit and management-review requirements in Clause 9, and the 10.1/10.3 merge — so manufacturers know exactly what needs updating before their certification body’s April 30, 2029 transition deadline.

What Changed in Every Clause — And What Your EMS Actually Needs to Do About It

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your EMS Isn’t Broken. But Several Clauses Just Changed Underneath It.

This ISO 14001:2026 clauses explained guide breaks down every clause so you know exactly what changed and what to leave alone.

If you’re certified to ISO 14001:2015, here’s the uncomfortable truth: your certificate has an expiration date now, and it’s not the one on the wall.

ISO 14001:2026 was published April 15, 2026. It cancels and replaces the 2015 edition. Every organization holding an ISO 14001:2015 certificate now has until April 30, 2029 — confirmed directly in UKAS’s published technical bulletin for accredited certification bodies — to move to the new edition or lose certified status entirely.

The good news: this is not a rebuild. The Plan-Do-Check-Act structure is untouched. The ten-clause Harmonized Structure you already know from ISO 9001 and ISO 45001 is still there. What changed is narrower and more specific than most transition guides make it sound — and that’s exactly why a clause-by-clause read matters more than a high-level summary. You need to know which clauses to touch and which ones to leave alone.

I’ve spent 25+ years in heavy industrial operations, and I hold ISO 9001 Internal Auditor certification and a Six Sigma Green Belt — which means I’ve been the one standing in front of an auditor when a clause got reinterpreted mid-cycle. When ISO 9001:2015 rolled out its own risk-based thinking language, I watched two “equivalent” fabrication shops get very different audit outcomes — one had mapped the new requirement into an existing procedure six months ahead, the other tried to bolt it on during the transition audit itself. The shops that treat a standard revision as a documentation exercise get surprised. The ones that treat it as a system update don’t.

EMS teams generally fall into one of two postures over the transition window: reactive gap-closing right before a transition audit, or a planned, clause-mapped update that folds into a normal surveillance cycle. Before your next audit window closes, run a structured gap check against the 2026 requirements

Get the Manufacturing Compliance Checklist — a practical reference for closing gaps before an auditor finds them for you.


In This Guide

  • What actually changed between ISO 14001:2015 and ISO 14001:2026, clause by clause
  • The one genuinely new clause (6.3) and why it exists
  • Which requirements are genuinely new, which are reorganized, and which are primarily clarified
  • How the 2024 Climate Change Amendment folds into the 2026 edition
  • Transition timeline and what your certification body will expect
  • Where to buy the standard and where to get training
  • A quick-reference audit checklist for your next internal audit


ISO 14001:2026 Clauses Explained: Quick Answer

ClauseWhat ChangedAction Needed
4.1Five named environmental conditions: climate change, biodiversity, pollution, resource availability, ecosystem healthUpdate context analysis
4.3Life-cycle perspective now required at the EMS scoping stageExtend scope justification upstream/downstream
6.1.4New sub-clause dedicated to risks and opportunitiesMake risks/opportunities traceable — register optional
6.3Entirely new clause — Planning of ChangesBuild or extend a change-management procedure
8.1“Externally provided processes, products and services” replaces “outsourced processes”Broaden supplier and flow-down controls
9.2.2Audit objectives now required for every internal auditAdd defined objectives to your audit programme
9.3Restructured into 9.3.1 / 9.3.2 / 9.3.3Update management review agenda and minutes template
10.1Merged with former 10.3 (Continual improvement)Update internal cross-references

👉 Start Here (Top Resources)


Why This Revision Happened

ISO doesn’t revise a management system standard every few years for the sake of it. ISO 14001:2015 has been in place over a decade, and in that time three things happened that the standard didn’t fully account for: climate reporting became a business expectation rather than a voluntary add-on, supply chain environmental accountability moved from “nice to have” to contractual requirement in many industries, and the 2024 Climate Change Amendment (Amendment 1) was issued as a stopgap that needed to be formally folded into the core text rather than living as a bolt-on.

ISO.org confirms the core structure of ISO 14001 remains the internationally recognized environmental management system framework it has always been — this revision sharpens the requirements, it doesn’t replace the model.

If you are already ISO 9001 or ISO 45001 certified → you’ll recognize most of what changed here immediately, because the 2026 revision closes gaps that made ISO 14001 feel slightly out of step with its Harmonized Structure siblings. Clause 6.3 is the clearest example — ISO 9001 has had it since 2015.


Clause 4: Context of the Organization

This is where the most-cited substantive change sits, spread across three sub-clauses.

Clause 4.1 (Understanding the organization and its context) now names five specific environmental conditions that organizations must explicitly consider: climate change, biodiversity, pollution levels, natural resource availability, and ecosystem health. Under the 2015 edition, these lived as Annex A examples rather than requirement text. The 2026 edition writes them into the “shall” statement itself — auditors will expect to see these named factors addressed in your context analysis, not filed under a generic catch-all.

Clause 4.2 (Understanding the needs and expectations of interested parties) carries the same tightening, with a new note clarifying the types of interested parties in language that aligns more closely with ISO 9001. If your organization already addressed the 2024 Climate Change Amendment, you’re largely ahead of this change — it’s been formally absorbed into the core text rather than treated as a standalone add-on.

Clause 4.3 (Determining the scope of the EMS) picks up a genuine substantive change of its own: the life-cycle perspective is now explicitly required at the scoping stage, not just when identifying environmental aspects later in Clause 6. In practice, this means your scope statement needs to reflect where you have control or influence across upstream and downstream activities — not just what happens inside your fence line. A manufacturing site that already controls emissions and waste on-site may still need to account for supplier and product-use impacts when justifying its scope boundary.

⚠️ A gap worth closing before an audit tests it: a documented statement that a factor (say, biodiversity) was considered and found not material is defensible. Silence on it is not. Auditors are trained to look for evidence of consideration, not necessarily a full formal assessment for every factor.

If you are updating your context analysis for the first time under 2026 → don’t treat this as a rewrite. Add the five named factors to your existing context documentation, extend your scope justification to address life-cycle control and influence under 4.3, and note your rationale where a factor doesn’t apply to your operation.


Clause 5: Leadership

No new sub-clauses were added to Clause 5, and the changes here are clarifications and strengthened emphasis rather than a wholesale redesign — but it isn’t purely a matter of tone, either. The policy note under 5.2 has been expanded to explicitly reference commitment to the preservation or conservation of natural resources, and the documented-information language shifts from “fulfil” to “meet” for compliance obligations. If your environmental policy is due for review during the transition window, this is a natural point to incorporate the expanded commitment language.

Beyond that wording update, certification bodies are signaling that auditors will expect more visible evidence of personal top-management engagement — not just a signed environmental policy and calendar attendance at the annual management review. Accountability, integration of environmental objectives into business planning, and alignment with strategic direction were always required; the 2026 revision keeps the pressure on without adding new formal sub-clause requirements.

A common finding going into transition audits: leadership commitment that exists on paper (signed policy, meeting minutes) but isn’t traceable to an actual business decision — a capital allocation, a supplier contract clause, a product design change. That traceability is what auditors are being trained to probe for.


Clause 6: Planning

Clause 6 sees the most structural change of any section in the revised standard, split across three areas.

6.1 Actions to Address Risks and Opportunities

The core planning clause — environmental aspects, compliance obligations, risk-based thinking — isn’t redesigned, but it’s restructured for clarity. Most of the general content that lived in 2015’s Clause 6.1.1 has been moved into a new dedicated sub-clause, and the former “planning actions” content is renumbered to 6.1.5.

New Clause 6.1.4 (Risks and opportunities) gives risks and opportunities their own dedicated sub-clause for the first time. It requires the organization to determine which risks and opportunities — arising from its 4.1 context, 4.2 interested-party needs, and 4.3 scope — need to be addressed, and to make that determination available as documented information. Important nuance: the standard does not prescribe a specific document format called a “risks-and-opportunities register.” If your current system scatters this information across aspect registers, compliance logs, and planning documents, 6.1.4 is a good opportunity to make the connection more explicit and traceable — but a register isn’t a mandatory artifact, just a common and defensible way to demonstrate it.

6.1.2 (Environmental aspects) strengthens the life-cycle perspective that already existed in 2015, with a new note clarifying that environmental risk planning — including identification, assessment, and emergency-situation determination — must consider the life-cycle perspective. This is the clause connecting most directly to Clause 8.1 below — if your supplier flow-down documentation is thin, both clauses will surface it.

6.3 Planning of Changes — The One Genuinely New Clause

ISO 14001:2026 clauses explained with a practical Clause 6.3 planning of changes workflow for an environmental management system
ISO 14001:2026 clauses explained through a practical Clause 6.3 workflow for identifying, planning, implementing, and verifying EMS changes.

This is the headline change in the entire revision. Clause 6.3 did not exist in ISO 14001:2015. It requires organizations to determine, plan, and manage changes that affect — or could affect — the intended outcomes of the EMS, and to carry those changes out in a planned, controlled manner.

If you’re also certified to ISO 9001, this will look immediately familiar — ISO 9001:2015 has had a change management clause since its last revision. ISO 14001 is catching up, and for integrated management systems this closes one of the more persistent structural mismatches between the two standards. In the 2015 edition, environmental change management lived piecemeal across multiple clauses with no single anchor point. The 2026 edition gives it one.

If you are running an integrated management system (ISO 9001 + ISO 14001) → extend your existing ISO 9001 clause 6.3 change-management procedure rather than building a parallel one from scratch. Keep the risks-and-opportunities information clearly identifiable and traceable under 6.1.4, even if the underlying process is shared.


Clause 7: Support

Structurally unchanged. The documented-information terminology is refreshed to match the vocabulary used across the rest of the 2026 edition, but the substantive requirements — competence, awareness, communication, control of documented information — carry over from 2015 without new “shall” statements.

Objection worth naming here: “Do we need to rebuild our entire document control system for this?” No. If your EMS documentation was compliant under 2015, the structure doesn’t need rebuilding. What needs review is whether the terminology and cross-references in your procedures still match the clause numbering and vocabulary used in the 2026 text — a find-and-replace exercise, not a redesign.


Clause 8: Operation

Clause 8.1 (Operational planning and control) is broadened, and this is the second most consequential change in the revision after Clause 6.3. The 2026 edition replaces the 2015 term “outsourced processes” with “externally provided processes, products and services” — a deliberately wider scope that extends environmental accountability further into your supply chain, not just the processes you’ve formally outsourced.

This connects directly back to Clause 6.1.2’s strengthened life-cycle perspective and Clause 4.3’s scope requirements. Together, these clauses are where auditors will spend more time in a transition audit than anywhere else in the standard.

ISO 14001:2026 clauses explained through the life-cycle perspective connecting Clause 6.1.2 environmental aspects with Clause 8.1 external controls
ISO 14001:2026 clauses explained through the life-cycle perspective from raw materials and suppliers through manufacturing, distribution, product use, and end of life.

If you are under customer pressure to demonstrate supply chain environmental controls → this is the clause pairing to get ahead of first. Supplier questionnaires, flow-down clauses in purchase orders, and documented supplier evaluation criteria all become more defensible evidence under the 2026 text than a general “we expect suppliers to comply” statement.


Clause 9: Performance Evaluation

This clause carries two real structural changes and deserves the same depth as Clause 7.

Clause 9.2.2 (Internal audit programme) now explicitly requires audit objectives, alongside the existing scope and criteria elements, as part of every internal audit. This is a small addition in word count but a real one in practice: “verify we’re ready for the certification audit” doesn’t meet the intent. A defensible objective looks more like “verify conformance of the updated EMS to the 2026 requirements, with particular focus on Clauses 4.1, 6.1.4, 6.3, and 8.1” — specific, testable, and tied to what actually changed.

Clause 9.3 (Management review) is restructured from a single clause into three sub-clauses: 9.3.1 General, 9.3.2 Management review inputs, and 9.3.3 Management review results. The required inputs and results are substantially preserved from 2015 — this is a structural reorganization more than a content rewrite — but your management review agenda and meeting-minutes template should be updated to reflect the new sub-clause structure so your documented information maps cleanly to what an auditor will be checking against.

Monitoring, measurement, analysis, and evaluation requirements outside these two areas carry over largely intact. What auditors are being trained to check more closely is whether performance evaluation data actually feeds into the Clause 6.3 change-planning process — in other words, whether your monitoring results are driving documented EMS changes, not just sitting in a report.


Clause 10: Improvement

The 2015 and 2026 structures line up like this:

2015 Edition2026 Edition
10.1 General10.1 Continual improvement
10.2 Nonconformity and corrective action10.2 Nonconformity and corrective action
10.3 Continual improvement

Clause 10.1 and 10.3 from the 2015 edition are merged into a single renumbered Clause 10.1, “Continual improvement.” This is a structural consolidation with two accompanying wording updates rather than a new requirement — nonconformity and corrective action content stays at 10.2 and is unaffected in substance, only in how the surrounding clauses are numbered and referenced.

If your procedures cross-reference clause numbers directly (a common practice in older EMS documentation) → this is the one place a pure numbering change can create a real nonconformity if your document control doesn’t catch it. Update cross-references before your transition audit, not during it.


Transition Timeline: What Happens and By When

MilestoneDateWhat It Means
ISO 14001:2026 publishedApril 15, 2026The 2015 edition is formally superseded
New certifications to 2015 edition stopOctober 31, 2027Certification bodies stop issuing fresh 2015 certificates — 18 months after publication
Recertification audits incorporate transition activitiesOctober 1, 2027Under published certification-body schedules (e.g., Amtivo) — not a universal UKAS date; confirm with your own registrar
Final transition deadlineApril 30, 2029ISO 14001:2015 certificates are no longer valid after this date
ISO 14001:2026 clauses explained with a transition timeline from publication through the 2029 certification deadline
ISO 14001:2026 clauses explained with key publication, certification transition, and final deadline milestones.

A three-year transition window is standard practice for a major ISO management system revision under IAF rules — it mirrors the timelines used for ISO 9001:2015 and ISO 45001:2018. UKAS’s published technical bulletin confirms both dates directly: certification bodies must transition their certified customers by April 30, 2029, and stop issuing new ISO 14001:2015 certificates after 18 months from publication. Many organizations fold the transition into a scheduled surveillance or recertification audit rather than scheduling a standalone transition audit, which reduces duplicated audit activity — though additional audit time, training, or documentation work should still be budgeted for depending on your certification body’s approach.

⚠️ Certification bodies are still finalizing their own auditor training and accreditation updates for the 2026 edition. If you’re scheduling a transition audit in the next few months, confirm directly with your certification body which clauses their auditors are currently trained to assess — you can verify a certification body’s accredited scope through ANAB if you want independent confirmation beyond what the registrar tells you — since availability and readiness vary by registrar.

A common transition failure isn’t that the work is hard — it’s assuming a scheduled recertification audit will automatically cover the new edition. Confirm with your registrar now whether your next audit is scoped for the 2026 transition →

Get the ISO 9001 Roadmap — a step-by-step framework for sequencing management system implementation and updates without missing a deadline.


Where to Buy ISO 14001:2026 and Get Trained

The ANSI Webstore remains the preferred source for the official current edition — it serves international buyers and offers standards in multiple languages, which matters if you’re managing EMS documentation across more than one country. ISO 14001:2026 — ANSI Webstore. Use code CC2026 for 5% off any standard purchase through December 31, 2026.

If you’re building out a broader environmental documentation set, the ISO 14001 Collection bundles related standards at a lower combined cost than buying individually.

For internal auditor training on the revised clauses, both ISOQAR and BSI Group offer current courses covering the 2026 changes — worth comparing both since training format and pacing differ between the two providers. For a fuller side-by-side, see our BSI vs ISOQAR comparison.

If you are ready to buy the standard today → go with ANSI Webstore for the official edition. If you are still evaluating training providers → compare ISOQAR and BSI directly before committing budget. If you are building documentation from scratch → start with the ISO Documentation Kits for Manufacturers page rather than a generic template search.


Quick Audit Checklist

Use this as a fast pre-transition scan — not a substitute for a full gap assessment.

  • ✅ Context analysis (4.1/4.2) explicitly names all five environmental conditions: climate change, biodiversity, pollution, resource availability, and ecosystem health
  • ✅ A documented rationale exists for any named factor deemed not material
  • ✅ EMS scope statement (4.3) addresses control and influence across upstream and downstream life-cycle stages
  • ✅ Risks and opportunities (6.1.4) are identified, traceable, and available as documented information — register format optional
  • ✅ Life-cycle perspective (6.1.2) documentation addresses upstream supplier and downstream product impact
  • ✅ A change-management procedure exists and is mapped to Clause 6.3 — shared with ISO 9001 if integrated
  • ✅ Supplier and externally-provided-process flow-down and evaluation criteria (8.1) go beyond a general compliance statement
  • ✅ Internal audit programme documentation includes defined audit objectives (9.2.2)
  • ✅ Management review agenda and minutes template reflect the 9.3.1/9.3.2/9.3.3 structure
  • ✅ Internal procedures cross-referencing old clause numbers (especially 10.1–10.3) have been updated

FAQ

Is ISO 14001:2026 a completely new standard?

No. The revision keeps the ten-clause Harmonized Structure and PDCA model, but reorganizes several sub-clauses, clarifies requirements, and adds the new 6.3 Planning of Changes.

What is the actual deadline to transition my certificate?

April 30, 2029, per UKAS’s published technical bulletin for accredited certification bodies. Certification bodies must also stop issuing new ISO 14001:2015 certificates by October 31, 2027. Confirm both dates with your own certification body, since national accreditation bodies outside the UK may communicate on slightly different timelines.

Do I need to rebuild my entire EMS documentation?

Generally, no. Organizations with a mature, well-run EMS under the 2015 edition should not need to start from scratch. The clarified expectations concentrate in specific clauses — primarily 4.1, 4.2, 4.3, 6.1.4, 6.3, 8.1, 9.2.2, and 9.3 — not the full documentation set.

What is the one genuinely new requirement in ISO 14001:2026?

Clause 6.3, Planning of Changes. It requires a formal, planned approach to managing changes affecting the EMS. It did not exist in any form in the 2015 edition.

Does the 2024 Climate Change Amendment still apply separately?

No. Amendment 1:2024, which introduced climate change considerations into clauses 4.1 and 4.2, has been formally integrated into the 2026 edition. If you already addressed the amendment, you’re ahead of most of this revision.

Will my certification body’s auditors already know the new requirements?

Not universally yet. Certification bodies are still completing their own auditor training and accreditation updates for the 2026 edition. Confirm directly with your registrar which clauses their auditors are currently trained and accredited to assess before scheduling a transition audit.

Does this revision affect integration with ISO 9001 or ISO 45001?

It improves it. Clause 6.3 closes a structural gap that previously existed between ISO 14001 and its Harmonized Structure siblings — ISO 9001 has had a change-management clause since 2015. Integrated management systems should find alignment easier, not harder, under the 2026 edition.

Should I certify directly to ISO 14001:2026 if I’m not yet certified to any edition?

If you’re implementing an EMS for the first time, there’s little reason to build to the 2015 edition and then transition. Go directly to the 2026 requirements.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts

Not Sure What to Do Next?

🔹 Still researching what changed? Start with our ISO 14001:2026 vs 2015: What’s New at a Glance for the condensed version, then bookmark this clause-by-clause breakdown as your reference.

🔹 Ready to start closing gaps? Run the Manufacturing Compliance Checklist against Clauses 4.1, 4.3, 6.1.4, 6.3, 8.1, and 9.2–9.3 first — that’s where the substantive changes concentrate.

🔹 Need to buy the standard or get your team trained? ISO 14001:2026 — ANSI Webstore for the standard itself, or compare ISOQAR and BSI Group for internal auditor training on the revised clauses.

The revision cycle rewards the organizations that mapped their EMS to the new clauses early — not the ones that waited for the deadline to force the issue. That’s the difference between a transition audit that folds into your normal surveillance cycle and one that turns into a scramble.

The Standards Navigator will keep tracking this transition as certification bodies finalize their auditor guidance.


Every Revision Cycle Produces the Same Split

Some EMS teams treat a standard revision as a scramble that starts the month before their transition audit. Others map the changed clauses the week the new edition publishes and fold the update into their next scheduled surveillance visit. The difference isn’t resources — it’s whether someone read the clause-by-clause changes before the deadline was the only thing driving the timeline.

The Standards Navigator covers ISO 14001, ISO 9001, and ISO 45001 clause-by-clause — not just certification overviews — because the clause level is where audit findings actually happen.

👉 Get updates on ISO 14001:2026 transition guidance as certification bodies finalize their timelines
👉 Be first to access new EMS gap-assessment resources as they’re built

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISO 13485 Clauses Explained: A Complete Clause-by-Clause Breakdown (2026)

ISO 13485:2016 has eight clauses, but only five carry auditable requirements. This ISO 13485 clauses explained guide breaks down Clauses 4 through 8 in practical terms, corrects the common DHF-to-Medical-Device-File mapping error, and explains how FDA’s Compliance Program 7382.850 — which replaced QSIT on February 2, 2026 — reorganizes inspections around six QMS Areas and four Other Applicable FDA Requirements.

What every section of ISO 13485:2016 actually requires — and where auditors dig deepest

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Standard Reads Like a Checklist. It Isn’t One.

ISO 13485:2016 has eight clauses. Five of them carry actual requirements. That structure looks simple on the page — and it’s exactly why so many quality teams underestimate how much interpretation each clause demands once an auditor starts asking “show me.” This ISO 13485 clauses explained guide breaks down what each section requires, where the requirements overlap, and what auditors and FDA investigators may look for.

The FDA’s Quality Management System Regulation (QMSR) took effect February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. That changes what this clause structure means in practice. FDA also replaced its inspection methodology the same day — the Quality System Inspection Technique (QSIT) is gone, replaced by Compliance Program 7382.850. Getting the clause boundaries right now has a direct line to how an FDA investigator scopes an inspection, not just how a certification body audits.

Regulatory affairs and quality professionals reading this already know ISO 13485 exists. What’s harder to find is a breakdown that goes past the clause titles and into what each section demands in practice — where the audit findings cluster, where risk management threads through clauses that don’t mention risk in their title, and where the standard’s lack of an Annex SL high-level structure changes how it should be read compared to ISO 9001.

My perspective on this comes from 25+ years in operations leadership, an ISO 9001 Internal Auditor certification, and a Six Sigma Green Belt — a lot of that time spent on both sides of the table, building QMS documentation and sitting in CAPA reviews when a gap in that documentation turned into a finding. The pattern holds across every regulated QMS I’ve worked with: teams don’t fail because they misread a clause. They fail because they treated clause boundaries as more rigid than the standard actually intends, and missed how much cross-referencing an auditor expects between clauses 4 through 8.

If you haven’t run a structured gap check against the current clause set, that’s the place to start — not a full documentation rewrite.

👉 Run the ISO 13485 Gap Assessment Checklist before you touch your quality manual — a free, structured way to see exactly which clauses your QMS already satisfies and which ones need real work before an auditor finds the gap for you.


In This Guide

  • How ISO 13485:2016 is structured, and why it doesn’t follow ISO’s Annex SL format
  • A clause-by-clause breakdown of Clauses 4 through 8
  • How FDA’s current inspection program, Compliance Program 7382.850, reorganizes inspections around six QMS Areas
  • The most common audit findings tied to specific sub-clauses
  • Where risk management actually appears throughout the standard
  • How ISO 13485 clause numbering compares to ISO 9001
  • FAQs on structure, exclusions, and transition timing


👉 Start Here (Top Resources)


ISO 13485 Clauses Explained: How the Standard Is Structured

ISO 13485 clauses explained with an eight-clause map covering the standard’s foundational and QMS requirement clauses
ISO 13485 clauses explained through an eight-clause map showing the foundational clauses and the five clauses containing QMS requirements.

ISO 13485:2016 is built around eight clauses. The first three are introductory — they define scope, point to normative references, and set terminology. They carry no auditable requirements on their own, but skipping them is a mistake most teams make once and then correct the hard way.

Clauses 4 through 8 are where the requirements live. This is the part of the standard your certification body actually audits against, clause by clause, sub-clause by sub-clause.

Here’s something worth knowing before you go further: ISO 13485 does not follow the Annex SL high-level structure that ISO 9001:2015, ISO 14001, and ISO 45001 all share. Those three standards align clause-for-clause at the top level, which is why integrated management systems work so cleanly across them. ISO 13485 kept its own structure when it was revised in 2016, specifically so it could stay independent of ISO 9001 revision cycles — a deliberate choice by the technical committee to protect regulatory stability for device manufacturers. If you’re coming from an ISO 9001 background, this is the first adjustment to make: don’t assume clause 7 means the same thing in both standards. It doesn’t.


Clauses 1 Through 3: No Requirements, But Don’t Skip Them

Clause 1 (Scope) defines what the standard covers and, critically, how exclusion and non-application work. ISO 13485 doesn’t let an organization simply skip a requirement that seems inconvenient — where a clause is excluded or considered non-applicable (say, you don’t perform installation), the scope and justification have to be documented in the quality manual under Clause 4.2.2, and be prepared to defend that justification during an audit.

Clause 2 (Normative References) points to ISO 9000:2015 for terms and definitions. You don’t need to buy ISO 9000 to comply, but auditors do expect your team to be using its vocabulary consistently — “nonconformity,” “corrective action,” and “verification” all carry specific meanings your documentation should match.

Clause 3 (Terms and Definitions) establishes the vocabulary used throughout the standard, including specific definitions for concepts like medical device, complaint, risk, and post-market surveillance. Getting comfortable with this terminology matters more than it looks like it should — auditors expect your documentation to use these terms precisely, not colloquially.

📥 Before diving into clauses 4-8: if your QMS documentation predates 2020, run it against the current ISO 13485 Documentation Requirements breakdown first. Most gaps trace back to documentation structure, not missing procedures.


Clause 4: Quality Management System

Clause 4 sets the general requirements for the QMS itself — and it’s where most audit programs start, because everything downstream depends on it.

4.1 General Requirements requires you to identify your QMS processes, map their sequence and interaction, and — this is the part that trips up contract manufacturers — maintain control over any process you outsource. Most common finding: outsourced processes (contract sterilization, contract testing, third-party calibration) that exist operationally but were never formally brought into QMS scope. If a supplier touches your product or your data, your QMS has to account for it.

4.2 Documentation Requirements covers the quality manual, the Medical Device File (Clause 4.2.3), document control, and record control. This requirement is specific to this standard — it’s not something ISO 9001 asks for. It’s a defined set of documents and references demonstrating a device meets its requirements throughout its lifecycle, and auditors will ask to see it assembled, not scattered across a dozen disconnected folders.

If your documentation still uses FDA’s old terminology, this is worth getting precise about. As of February 2, 2026, the terms Device Master Record, Device History Record, and Design History File no longer appear in 21 CFR Part 820. Those legacy record concepts weren’t simply eliminated; their applicable requirements are now addressed through the QMSR framework and ISO 13485’s own structure. Most of what a Device Master Record covered lives in the Medical Device File at Clause 4.2.3, while the Design History File corresponds to the Design and Development File at Clause 7.3.10. These aren’t simple one-for-one renamings: the Medical Device File in particular is a broader requirement than the DMR it replaced, so a straight terminology swap in your documentation will likely leave gaps a crosswalk exercise would catch.

Sub-clause 4.2.4 (control of documentation) and 4.2.5 (control of records) get their own scrutiny. Auditors typically check three things here: are documents reviewed and approved before use, is there a mechanism to prevent use of outdated versions, and are records retained for a defined, justified period. If you’re preparing for your first audit under this clause → build your document control procedure before you build anything else. Everything else in the QMS references it.


Clause 5: Management Responsibility

Clause 5 puts specific, named accountability on top management — not “the quality department,” but leadership itself.

This clause requires a documented quality policy, measurable quality objectives, evidence of planning for QMS changes, and a sub-clause I’ve seen come up repeatedly in audit findings — management review. Clause 5.6.2 is unusually prescriptive for an ISO standard: it names twelve required inputs, and a compliant management review record has to address all of them or document why one doesn’t apply — feedback, complaint handling, reporting to regulatory authorities, audits, monitoring and measurement of processes, monitoring and measurement of product, corrective action, preventive action, follow-up actions from previous reviews, changes that could affect the QMS, recommendations for improvement, and applicable new or revised regulatory requirements. A management review that skips several of these, or that doesn’t produce documented outputs and action items, is a finding waiting to happen — and under the current FDA inspection framework, it’s no longer just a certification-audit concern (more on that below).

If you are already ISO 9001 certified, this clause will feel familiar structurally — but ISO 13485 expects a tighter link between management review and regulatory requirements specifically, not just general business objectives.


Clause 6: Resource Management

Clause 6 covers human resources, infrastructure, and work environment — including contamination-control requirements under 6.4.2 that go considerably further than ISO 9001’s general treatment of work environment.

6.2 Human Resources requires documented competence for anyone whose work affects product quality — not just “trained,” but competence tied to education, skills, and experience, with evidence. 6.3 Infrastructure requires maintenance records for equipment critical to product conformity. 6.4 Work Environment and Contamination Control is where device manufacturers doing anything sterile, implantable, or otherwise contamination-sensitive get the most detailed scrutiny — cleanroom classifications, gowning procedures, and environmental monitoring data all trace back here.


Clause 7: Product Realization

Clause 7 is the largest clause in the standard, and it’s where design controls, purchasing, production, and servicing all live.

7.1 Planning of Product Realization is where ISO 13485 explicitly requires documented risk management processes within product realization, with records maintained throughout. The clause’s note points readers to ISO 14971 for further guidance on structuring that risk management activity — it’s a reference, not a formal incorporation, though in practice most organizations end up using ISO 14971’s framework to satisfy this requirement.

7.3 Design and Development is one of the sub-clauses most commonly identified as non-applicable by contract manufacturers who don’t design product — but where it applies, it can’t be excluded lightly, and the justification has to hold up to the same Clause 4.2.2 scrutiny as any other exclusion. If it applies to you, this is the densest technical section of the standard: design inputs, outputs, review, verification, validation, transfer, and change control, each with its own documented evidence trail. Most common finding: design changes made without running them back through the full verification/validation cycle, especially late in development when schedule pressure is highest.

7.4 Purchasing requires supplier evaluation criteria proportionate to risk, and re-evaluation triggers when supplier performance changes. 7.5 Production and Service Provision covers process validation for anything that can’t be fully verified by downstream inspection — sterilization is the textbook example, which is why it gets its own dedicated body of standards. 7.6 Control of Monitoring and Measuring Equipment ties directly into your calibration program.

If you are under customer or FDA pressure to show design control maturity quickly → prioritize closing out 7.3 documentation gaps before anything else in this clause. In my experience, it’s one of the first sections a regulatory reviewer or auditor asks to see in depth.


Clause 8: Measurement, Analysis and Improvement

Clause 8 is where the QMS proves it’s actually working — and where CAPA lives.

8.2 Monitoring and Measurement covers feedback, complaint handling, and internal audit. Complaint handling under this clause has to interface with FDA’s separate adverse-event reporting requirements — a complaint that may represent a reportable event under Medical Device Reporting (21 CFR Part 803) can’t remain solely an internal QMS record; it has to be evaluated independently against those reporting obligations.

8.3 Control of Nonconforming Product requires documented procedures for identifying, segregating, and dispositioning nonconforming product, including for product discovered nonconforming after delivery — which is where recall-adjacent procedures connect back into the standard.

8.5 Improvement is where corrective and preventive action requirements sit. CAPA under ISO 13485 requires root cause investigation, verification that the action taken was effective, and — a detail I’ve seen auditors check for specifically — evidence that you evaluated whether the same nonconformity could exist elsewhere in the organization before closing the CAPA. A CAPA record that fixes one instance without documenting that broader check is incomplete by this clause’s own standard, regardless of whether the immediate fix worked.

For a deeper breakdown of this clause specifically, see our full guide to CAPA requirements in ISO 13485.


Where ISO 13485 and FDA’s QMSR Overlap by Clause

FDA’s Quality Management System Regulation took effect February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. That’s the headline most coverage stopped at. What matters more for how you prepare is what happened on the inspection side the same day: FDA retired the Quality System Inspection Technique (QSIT), the inspection methodology it had used since 1999, and replaced it with a new compliance program manual — CP 7382.850, Inspection of Medical Device Manufacturers.

ISO 13485 clauses explained through the 2026 FDA QMSR inspection framework, including six QMS Areas and four OAFRs
ISO 13485 clauses explained in the context of the FDA QMSR and CP 7382.850 inspection framework effective February 2, 2026.

QSIT organized inspections around four subsystems. CP 7382.850 reorganizes them around six QMS Areas, each mapped to ISO 13485 clauses with FDA-specific requirements layered in:

  • Management Oversight — the QMS itself, management review, the medical device file, and product realization planning
  • Design and Development — design inputs, outputs, review, verification, validation, software validation, and transfer
  • Production and Service Provision — production planning, process validation, and servicing
  • Measurement, Analysis, and Improvement — complaint handling, feedback, internal audits, corrective and preventive action, and control of nonconforming product
  • Outsourcing and Purchasing — supplier evaluation and control
  • Change Control — how changes to product or process are managed and documented

Alongside the six QMS Areas, inspections also evaluate four Other Applicable FDA Requirements (OAFRs) that sit outside ISO 13485’s text entirely: Medical Device Reporting (21 CFR Part 803), Corrections and Removals reporting (21 CFR Part 806), Medical Device Tracking (21 CFR Part 821), and Unique Device Identification (21 CFR Part 830). This is where the clause structure above stops covering everything — these four areas are FDA-specific regulatory obligations, not ISO 13485 requirements. They’re evaluated during routine surveillance, compliance follow-up, and PMA postmarket inspections; a narrow exception can apply to certain PMA preapproval inspections when the manufacturer hasn’t yet introduced the device to the U.S. market.

The change that affects Clause 5 most directly: under the prior QSR, management review records were categorically exempt from FDA review under §820.180(c). Under CP 7382.850, that exemption is gone. Management review now sits squarely inside the Management Oversight QMS Area, and an investigator can ask to see it — which means the twelve required Clause 5.6.2 inputs covered above aren’t just a certification-audit concern anymore.

One caution worth stating plainly: ISO 13485 certification and FDA QMSR compliance are related but not identical. A QMS built cleanly against Clauses 4 through 8 covers the ISO 13485 core that QMSR incorporates, but it doesn’t automatically satisfy the four OAFRs — those require their own documented processes regardless of how strong your clause-by-clause QMS is.

If you’re not sure whether your current documentation satisfies both frameworks → our FDA QSR vs ISO 13485 comparison and MDSAP vs ISO 13485 breakdown both walk through this in more detail than fits here.

ISO 13485 vs ISO 9001: Same Numbers, Different Weight

ElementISO 13485:2016ISO 9001:2015
Structure8 clauses, own structure (not Annex SL)10 clauses, Annex SL high-level structure
Risk managementDocumented risk management required in product realization (7.1); note references ISO 14971Risk-based thinking, less prescriptive
Customer satisfaction monitoringNo direct ISO 9001-style requirement; feedback/complaints addressed via Clause 8.2Explicit requirement (Clause 9.1.2)
DocumentationMedical device file required (Clause 4.2)No equivalent requirement
Design controlsDetailed, mandatory unless justified exclusionLess detailed by comparison
Regulatory linkDirectly referenced in FDA QMSR (21 CFR 820)Not tied to a specific regulation

The clause numbers look similar enough to cause real confusion — both standards use “Clause 7” for a large operational section, but the content underneath diverges substantially. If your organization holds both certifications, don’t assume a clause 7 audit finding under one standard tells you anything about your standing under the other. For the full comparison, see ISO 9001 vs ISO 13485.

The objection I hear most on this topic: “We’re already ISO 9001 certified — how much of this is actually new work?” Realistically, expect Clauses 5 and 6 to require the least rework, since management responsibility and resource management overlap heavily in intent. Clauses 4, 7, and 8 are where the medical device-specific requirements add real documentation and process work — the medical device file, design control rigor, and CAPA’s broader-impact evaluation aren’t things a general ISO 9001 QMS already has built in.


Most teams don’t fail an ISO 13485 audit because they misunderstood a clause. They fail because they assumed a documented procedure was enough without checking whether it actually produces the evidence an auditor will ask to see.

👉 Run a structured check before that assumption gets tested in front of an auditor → ISO 13485 Gap Assessment Checklist


Quick Clause Reference Checklist

A clause tells you what’s required. It doesn’t tell you what to hand an auditor when they ask for proof. Below is a quick translation — clause by clause, requirement to evidence.

ISO 13485 clauses explained through an audit evidence checklist showing objective evidence for Clauses 4, 5, 7, and 8
ISO 13485 clauses explained through the objective evidence auditors may review for Clauses 4, 5, 7, and 8.

✅ Clause 4 — QMS scope defined, outsourced processes controlled, medical device file assembled
✅ Clause 5 — Quality policy documented, management review covering all required inputs
✅ Clause 6 — Competence records current, contamination controls documented where applicable
✅ Clause 7 — Risk management documented within product realization; ISO 14971 provides further guidance; design control records complete, supplier evaluation criteria defined
✅ Clause 8 — Complaint handling tied to regulatory reporting, CAPA records show broader-impact evaluation

⚠️ Clauses 1–3 — Exclusions and non-applicability justified in the quality manual, not just left blank

For implementation sequencing beyond the checklist above, our ISO 13485 Implementation Roadmap and ISO 13485 Gap Assessment: Step-by-Step Guide walk through the order to tackle these in.


FAQ

How many clauses does ISO 13485:2016 have?

Eight. Clauses 1 through 3 are introductory and carry no auditable requirements. Clauses 4 through 8 contain the substantive quality management system requirements that certification bodies audit against — and since February 2026, FDA investigators evaluate the same core requirements under Compliance Program 7382.850.

Does ISO 13485 follow the same structure as ISO 9001?

No. ISO 13485 does not use ISO’s Annex SL high-level structure, which ISO 9001, ISO 14001, and ISO 45001 all share. The technical committee kept ISO 13485 independent specifically to protect regulatory stability for device manufacturers, so clause numbers that look similar between the two standards often cover different scope.

Can I exclude clauses from ISO 13485?

Only with documented justification. Under Clause 4.2.2, the scope and justification for any exclusion or non-application have to be recorded in the quality manual, and you need to be prepared to defend that justification during an audit.

Which ISO 13485 clause covers risk management?

Clause 7.1 (Planning of Product Realization) is where documented risk management is explicitly required, and its note points to ISO 14971 for further guidance. But risk-related requirements aren’t confined to one clause — they surface throughout Clauses 4 through 8 rather than sitting in a single isolated section.

What’s the difference between ISO 13485 and the FDA’s QMSR?

As of February 2, 2026, FDA’s QMSR incorporates ISO 13485:2016 by reference into 21 CFR Part 820, and FDA’s inspection methodology changed to match — Compliance Program 7382.850 replaced QSIT the same day. The two frameworks are far more tightly aligned than before, but they’re not identical: four Other Applicable FDA Requirements (Medical Device Reporting, Corrections and Removals, Medical Device Tracking, and UDI) sit outside ISO 13485’s text and are evaluated in applicable inspection types, with a limited exception for certain PMA preapproval inspections when the device has not yet been introduced to the U.S. market.

What is CP 7382.850?

CP 7382.850 (Inspection of Medical Device Manufacturers) is FDA’s current compliance program manual for device inspections, effective February 2, 2026 alongside the QMSR. It replaced the Quality System Inspection Technique (QSIT) and reorganizes inspections around six QMS Areas — Management Oversight, Design and Development, Production and Service Provision, Measurement/Analysis/Improvement, Outsourcing and Purchasing, and Change Control — plus four Other Applicable FDA Requirements evaluated in most inspection types.

Do I need to buy ISO 9001 to understand ISO 13485’s terminology?

You don’t need to purchase it, but ISO 13485 does reference ISO 9000:2015 for its terms and definitions, and auditors expect consistent use of that vocabulary in your documentation.

Which clauses deserve the closest audit preparation?

In practice, Clause 4.2 (documentation control), Clause 7.3 where applicable (design and development), and Clause 8.5 (CAPA effectiveness) tend to draw sustained attention, largely because each requires ongoing documented evidence rather than a one-time procedure. The exact focus varies by organization, device type, and regulatory scope — under the current FDA inspection framework, Management Oversight and Measurement, Analysis, and Improvement are evaluated on every inspection regardless of device type.

Is a documentation kit enough to get ISO 13485 clause requirements right?

A kit gives you a starting structure, but clause-by-clause compliance depends on evidence specific to your processes — training records, design and development records, CAPA effectiveness checks. Our ISO Documentation Kits for Manufacturers page breaks down what a kit does and doesn’t cover.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching how the clauses fit together? Start with What Is ISO 13485? for the foundational overview before working through this clause breakdown a second time.

🔹 Ready to assess where your QMS actually stands? Run the ISO 13485 Gap Assessment Checklist against the clause list above — it’s built to map directly to Clauses 4 through 8.

🔹 Need the official standard text to cite exact clause language? Purchase ISO 13485:2016 through ANSI Webstore — use code CC2026 for 5% off through December 31, 2026. International-language editions are available for teams managing documentation across multiple regulatory regions.

🔹 Need your internal auditors trained on this clause structure before your next surveillance audit? ISO 13485 training through BSI Group covers the structure clause by clause with a certification body’s own instructors.

The Standards Navigator breaks down what these clauses actually demand — not just what they’re titled — so your team can walk into an audit knowing which sub-clause the finding will land on before it does.


Stay Ahead of Clause-Level Changes

Most QMS documentation doesn’t fail because a team ignored ISO 13485. It fails because someone mapped a procedure to the wrong clause once, early on, and every review since has confirmed the wrong thing.

Organizations that treat the clause structure above as a living reference — checked against actual audit findings, updated as FDA’s QMSR enforcement approach becomes clearer — walk into surveillance audits with far fewer surprises than organizations treating their quality manual as a document they wrote once and filed away.

The Standards Navigator tracks ISO 13485, QMSR, and the surrounding medical device standards landscape as they develop, not just at certification time.

👉 Get updates on ISO 13485 and medical device QMS requirements
👉 Be first to access new gap assessment tools and clause-mapping resources

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

AS9100 Rev D Clauses Explained: A Complete Clause-by-Clause Breakdown (2026)

AS9100 Rev D shares its ten-clause structure with ISO 9001, but aerospace-specific additions are layered inside it — from counterfeit parts prevention to configuration management. This guide breaks down every clause, maps it to ISO 9001, and shows exactly where auditors focus.

Every AS9100 Rev D clause, mapped to ISO 9001 and explained in plain shop-floor language

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Most AS9100 Nonconformances Trace Back to One Thing: Not Knowing What the Clause Actually Requires

Auditors don’t fail organizations for not trying. They fail them for gaps between what a procedure says and what a clause actually demands — and with AS9100 Rev D clauses, those gaps concentrate in the aerospace-specific additions layered inside the ISO 9001 structure.

AS9100 Rev D is built on the ISO 9001:2015 core structure — ten clauses, the same high-level framework shared across ISO 14001 and ISO 45001. The standard doesn’t present its aerospace requirements as a separate numbered list — its own foreword states that additional aviation, space, and defense requirements are shown in bold, italic text directly inside the ISO 9001 clause structure. Organizations that already run a certified ISO 9001 QMS often assume AS9100 is “the same thing with extra paperwork.” It isn’t. Those embedded additions carry real audit weight, and Clause 8 (Operation) carries the heaviest concentration of them.

This guide walks through all ten AS9100 Rev D clauses, what each one requires, and exactly where the aerospace-specific language sits inside the ISO 9001 framework — being careful throughout to separate what the standard actually requires from what auditors commonly emphasize in practice. Those aren’t always the same thing, and conflating them is one of the more common ways organizations misjudge their own audit readiness.

As an ISO 9001 Internal Auditor, I’ve sat in enough audit rooms to know the pattern: a work instruction gets followed to the letter, but the calibration record behind the measurement it relies on has already lapsed. The paperwork says compliant. The process says otherwise. That’s clause 7.1.5 in real life, not on paper — and it’s the kind of gap AS9100 auditors can uncover when they trace a documented process back to the evidence supporting it.

Before your next audit, run a clause-by-clause gap check against the full standard → Get the free AS9100 Rev D Gap Assessment Checklist and find out exactly which clauses your QMS is weakest on before an auditor does.

In This Guide:

  • What AS9100 Rev D actually adds to the ISO 9001 clause structure
  • A clause-by-clause breakdown of all ten sections
  • The aerospace-specific sub-clauses that deserve the closest audit attention
  • Where AS9100 and ISO 9001 requirements diverge — and where they’re identical
  • FAQ on AS9100 clause numbering, scope, and audit focus areas


Start Here — Top Resources

If you’re working from the standard itself while you read this breakdown, get the official text directly rather than a summary. AS9100 Rev D — ANSI Webstore is the authorized source for the current edition, available in print and PDF, with worldwide shipping and multi-language options for suppliers outside the U.S. Use code CC2026 for 5% off through December 31, 2026.

If your team needs to understand how auditors actually interpret these clauses in practice — not just what they say — BSI Group’s AS9100 Training Courses cover clause-level interpretation and internal auditor certification specific to the aerospace series.


How AS9100 Rev D Clauses Are Structured

AS9100 Rev D uses the same ten-clause Annex SL structure as ISO 9001:2015 — Context, Leadership, Planning, Support, Operation, Performance Evaluation, and Improvement. If you’ve already worked through our ISO 9001 clause breakdown, the numbering will look familiar.

What’s different is what’s been inserted inside that structure. AS9100 doesn’t renumber clauses — it adds sub-clauses at the points where aerospace risk is highest: configuration management, counterfeit parts prevention, product safety, first article inspection, and control of production equipment and tooling. Those additions are catalogued in the standard’s own comparison annex, and they’re the reason a shop that’s ISO 9001 certified still has real implementation work to do before an AS9100 Stage 1 audit.

If you’re not yet sure how the two standards differ at a strategic level, our AS9100 vs ISO 9001 comparison covers the bigger picture. This article goes clause by clause.

AS9100 Rev D clauses structure map showing the 10-clause ISO 9001 framework and aerospace-specific requirements
AS9100 Rev D clauses follow the ISO 9001:2015 10-clause structure with aerospace-specific requirements embedded throughout.

Clause 1–3: Scope, Normative References, Terms and Definitions

These three clauses establish the scope, references, and terminology that auditors use to frame everything that follows. They don’t contain the operational QMS requirements that make up the bulk of an AS9100 audit, but they still matter when determining your certification scope and how requirements are interpreted.

Clause 1 — Scope defines AS9100 as applicable to organizations that design, develop, and/or produce aviation, space, and defense products, and to organizations providing post-delivery activities including maintenance, spares, or repair. Scope statements get checked against your actual certificate scope more often than new clients expect.

Clause 2 — Normative References points to ISO 9000:2015 for foundational terms and definitions.

Clause 3 — Terms and Definitions adds aerospace-specific vocabulary on top of the ISO 9000 base: counterfeit part, critical items, key characteristic, product safety, and special requirements. Auditors expect these terms used correctly and consistently across your documentation — not interchangeably with generic quality language.


Clause 4: Context of the Organization

Clause 4.1 through 4.4 require you to identify internal and external issues affecting your QMS, determine interested parties and their requirements, define QMS scope, and document your processes and their interactions.

AS9100 doesn’t add new sub-clauses here, but auditors interpret “interested parties” more broadly than in general manufacturing — regulatory authorities, certifying agencies, and customer flow-down requirements all count, and your QMS scope statement needs to reflect the specific product lines and processes your certificate covers.


Clause 5: Leadership

Clause 5.1 covers leadership commitment, 5.2 covers the quality policy, and 5.3 covers organizational roles, responsibilities, and authorities.

The concrete AS9100 addition sits in 5.3, and it’s a narrow one: ISO 9001:2015 dropped the requirement for a single named “management representative,” but AS9100 explicitly retained it. Top management must appoint a specific person with the organizational freedom and unrestricted access to top management needed to oversee the QMS. If your quality function is spread across several roles with no one holding this explicit authority and access, that’s a real gap against the standard’s text — not just an auditor preference.


Clause 6: Planning

Clause 6.1 (actions to address risks and opportunities), 6.2 (quality objectives and planning), and 6.3 (planning of changes) are essentially unchanged from the ISO 9001 baseline — there’s no AS9100-specific addition inserted directly into Clause 6 itself. The standard’s own informative annex is explicit about where the aerospace risk emphasis actually lives: a formal operational risk management process is required under Clause 8.1.1, not Clause 6. If you’re looking for where AS9100 gets more demanding about risk, that’s the clause to focus on — Clause 6 planning should still look familiar if you’re coming from ISO 9001.


Clause 7: Support — Where the First Major Additions Appear

Sub-ClauseSource of the DifferenceWhat Actually ChangesWhy It Matters in Practice
7.1.3 InfrastructureSame as ISO 9001 baseline — no AS9100-specific textual addition hereNothing added at this clauseEquipment and tooling validation requirements do show up in AS9100 — but at 8.5.1.1, under Production, not here. Don’t confuse the two when building your clause cross-reference.
7.1.5 Monitoring & Measuring ResourcesAS9100 textual addition (7.1.5.2)Explicit calibration/verification against national or international measurement standards, a documented recall process for equipment due for calibration, and a maintained register (equipment type, unique ID, location, method, frequency, acceptance criteria)This is one of the most detailed sub-clauses in the entire standard. Shops tracking calibration informally, without a maintained register, are working against explicit standard text — not just an auditor’s preference.
7.1.6 Organizational KnowledgeSame as ISO 9001 baseline — no AS9100-specific textual additionNothing added at this clauseThe practical risk (tribal knowledge lost to turnover) is real and worth managing, but it’s not a distinct AS9100 requirement beyond what ISO 9001 already asks for.
7.2 CompetenceSame as ISO 9001 baseline — no AS9100-specific textual additionNothing added at this clauseDon’t confuse this with 7.3 below — product safety and ethics awareness live there, not in the competence clause itself.
7.3 AwarenessAS9100 textual additionTwo items added to the awareness list that don’t appear in the ISO 9001 baseline clause: personnel must be aware of their contribution to product safety and the importance of ethical behaviorTraining records built only around technical/skill competence, with no documented safety or ethics awareness element, are a common and genuine gap against this specific text.
7.5 Documented InformationAS9100 textual addition (narrow)An explicit requirement that when documented information is managed electronically, the organization defines data protection processes covering loss, unauthorized changes, unintended alteration, corruption, and physical damageElectronic document-control systems get checked specifically for this language — general version control isn’t automatically the same thing.

For a full breakdown of what documentation auditors expect to see at each stage, see our guide to AS9100 Documentation Requirements.


Clause 8: Operation — Where Most of the Standard’s Weight Lives

AS9100 Rev D clauses showing Clause 8 operational controls for aerospace manufacturing
AS9100 Rev D Clause 8 connects aerospace-specific controls from operational risk and configuration management through production verification and product release.

Clause 8 is where AS9100 diverges most sharply from the ISO 9001 baseline, with the greatest concentration of aerospace-specific operational requirements.

8.1 Operational Planning and Control gains four aerospace-specific sub-clauses:

  • 8.1.1 Operational Risk Management — requires a documented process for managing risk in operations, including risk of nonconformity affecting product safety
  • 8.1.2 Configuration Management — required for organizations where product configuration must be controlled and traceable through its lifecycle
  • 8.1.3 Product Safety — requires planning, implementation, and control of processes for product safety across the product lifecycle
  • 8.1.4 Prevention of Counterfeit Parts — requires a documented approach to preventing counterfeit or suspect counterfeit parts from entering the supply chain

If you haven’t yet mapped your counterfeit parts controls against clause 8.1.4 specifically, our AS9100 Counterfeit Parts Standards guide covers what auditors expect to see documented.

8.3 Design and Development carries three specific AS9100 additions worth knowing by number: 8.3.4.1 requires detailed test planning for verification and validation activities (test plans identifying the item, resources, objectives, conditions, and acceptance criteria); 8.3.5(e) requires design outputs to specify critical items, including key characteristics, and the specific actions to be taken for them; and 8.3.6 requires customer notification before implementing design changes that affect customer requirements, plus control of those changes in accordance with your configuration management process. Organizations that design as well as build have real implementation work here beyond the ISO 9001 baseline.

8.4 Control of Externally Provided Processes, Products, and Services requires flow-down of applicable requirements (including customer and regulatory requirements, and the duty to prevent counterfeit parts) to sub-tier suppliers, and requires verification that purchased product conforms before use in production or delivery. AS9100 also explicitly requires a maintained register of external providers that includes their approval status (approved, conditional, or disapproved) and the scope of the approval — a specific recordkeeping requirement, not just a general expectation. Supplier evaluation and monitoring get audited far more closely under AS9100 than under a standard ISO 9001 certificate.

8.5 Production and Service Provision is where the bulk of aerospace-specific sub-clauses sit — and where getting the exact sub-clause numbers right matters, because they’re easy to mix up:

  • 8.5.1.1 Control of Equipment, Tools, and Software Programs — equipment, tools, and software used to automate, control, monitor, or measure production processes must be validated prior to final release for production and maintained — a common audit gap on CNC-heavy shop floors
  • 8.5.1.2 Validation and Control of Special Processes — for processes where the output can’t be verified by subsequent inspection, requires defined approval criteria, facility/equipment approval, and personnel qualification
  • 8.5.1.3 Production Process Verification — this is the clause that requires production process verification, including first article inspection where applicable: a representative item from the first production run of a new or changed part must verify that production processes, documentation, and tooling meet requirements, repeated when changes invalidate the original results. Covered in detail in our First Article Inspection guide
  • 8.5.2 Identification and Traceability — extended traceability and configuration-identification requirements covered in our AS9100 Traceability Requirements breakdown
  • 8.5.4 Preservation — includes explicit requirements around foreign object debris (FOD) prevention, detailed in our FOD Control Standards guide
  • 8.5.5 Post-Delivery Activities — support and servicing requirements after product leaves your facility, including in-service data collection and technical documentation control

8.6 Release of Products and Services requires verifying that product and service requirements have been met before release proceeds, retaining documented evidence of conformity and traceability to the person authorizing release, and ensuring all documentation required to accompany the product is present at delivery. It’s a closely related idea to first article inspection, but it’s a separate requirement, not a restatement of 8.5.1.3.

8.7 Control of Nonconforming Outputs goes considerably further than the general ISO 9001 requirement. AS9100 requires that dispositions of “use-as-is” or repair be approved by an authorized representative of the design organization (or someone with delegated design authority) — and by the customer, if the nonconformity departs from contract requirements. Product dispositioned for scrap must be conspicuously and permanently marked, or positively controlled, until it’s physically rendered unusable. Counterfeit or suspect counterfeit parts must be controlled to prevent reentry into the supply chain. And nonconformities affecting delivered product require timely reporting to the customer and other relevant interested parties.


Clause 9: Performance Evaluation

Clause 9.1 (monitoring, measurement, analysis, evaluation), 9.2 (internal audit), and 9.3 (management review) follow the ISO 9001 structure without major aerospace-specific insertions — but auditors expect internal audit programs to demonstrate coverage of the AS9100-specific clauses above, not just the ISO 9001 baseline. A shop running internal audits against a generic ISO 9001 checklist and calling it AS9100-compliant can leave significant aerospace-specific requirements untested before Stage 2.

For a full walkthrough of building an internal audit program that actually covers these clauses, see our AS9100 Internal Audit Process guide.


Clause 10: Improvement

Clause 10.1 (general), 10.2 (nonconformity and corrective action), and 10.3 (continual improvement) mirror ISO 9001 directly. The practical difference is scale and documentation rigor: corrective action records tied to product safety or counterfeit parts findings tend to get far closer scrutiny during surveillance audits than a routine process nonconformance.


Objection: “Isn’t This Just ISO 9001 With More Paperwork?”

This is the single most common misconception I run into with shops transitioning from ISO 9001 to AS9100. It’s not more paperwork — it’s more scope. Requirements like 8.1.4 (counterfeit parts prevention), 5.3’s retained management representative, and 7.3’s product safety and ethics awareness items don’t appear in ISO 9001 in this form. They require new processes, not just new forms. Organizations that treat AS9100 as an ISO 9001 add-on typically underestimate the implementation timeline by months — see our AS9100 Implementation Timeline guide for a realistic planning window.

AS9100 Rev D clauses audit evidence trail showing the connection between requirements, procedures, implementation, and objective records
AS9100 Rev D clauses are verified through the complete audit evidence trail from requirements and procedures to shop-floor implementation and objective records.

Quick Clause Audit Checklist — AS9100-Specific Additions

[ ] Documented counterfeit parts prevention process (8.1.4)
[ ] Configuration management process, if applicable to your product line (8.1.2)
[ ] Product safety planning documented across the product lifecycle (8.1.3)
[ ] A named management representative with unrestricted access to topmanagement (5.3)
[ ] Calibration register maintained per 7.1.5.2 — equipment type, ID, location, method, frequency, acceptance criteria
[ ] First article inspection records for new or changed part numbers (8.5.1.3)
[ ] Equipment, tooling, and software validated before release to production (8.5.1.1)
[ ] FOD prevention program documented and implemented (8.5.4)
[ ] Ethics and product safety awareness included in training records (7.3)


FAQ

Does AS9100 Rev D use the same clause numbers as ISO 9001:2015?

Yes. AS9100 Rev D uses the identical ten-clause Annex SL structure as ISO 9001:2015, with aerospace-specific sub-clauses inserted at relevant points rather than renumbered separately.

How many additional requirements does AS9100 add to ISO 9001?

The standard itself doesn’t present the additions as a numbered list — AS9100’s own foreword states that aerospace-specific requirements, definitions, and notes are shown in bold, italic text directly inside the ISO 9001:2015 clause structure. They’re concentrated most heavily in Clause 8 (Operation), which carries more distinct aerospace sub-clauses than any other section of the standard.

Which clauses generate the most AS9100 audit findings?

We don’t have access to statistically representative registrar-wide nonconformance data, so we won’t put a ranking on this. What we can say from direct clause-level audit experience is that 7.1.5 (calibration and measurement traceability), 8.1.4 (counterfeit parts prevention), and 8.5.1.1 (control of production equipment, tools, and software) are recurring finding areas in practice — worth checking closely even if you can’t quantify exactly how common each one is industry-wide.

Do I need a separate quality manual for AS9100 versus ISO 9001?

No — most organizations integrate AS9100-specific requirements into a single QMS manual structured around the same ten clauses, rather than maintaining two parallel systems.

Is clause 8.1.2 (Configuration Management) mandatory for every AS9100 organization?

It applies where product configuration control is relevant to your scope — typically design-and-build organizations and complex assemblies. A pure build-to-print machine shop may have limited applicability, though this should be confirmed with your registrar, not assumed.

Does AS9100 replace ISO 9001 certification?

No. AS9100 certification incorporates and is audited alongside ISO 9001 requirements — it is not a separate parallel certificate. Organizations certified to AS9100 do not need a separate ISO 9001 certificate for the same scope.

Will IA9100 change this clause structure?

AS9100 Rev D remains the current, active standard as of this writing, and everything in this breakdown reflects it. The IAQG has published a roadmap targeting IA9100 for 2026, and its current public material confirms the revision is still in progress rather than finalized. At least one industry newsletter has separately reported a possible slip to mid-2027 — we’re noting that as a secondary, less-authoritative data point rather than treating it as equally confirmed. What’s consistently reported across sources is that IA9100 is expected to preserve the core clause structure while adding requirements in areas like information security, digital assurance, and supplier controls — not a ground-up rebuild. We’ll update this breakdown once a publication date and the actual clause text are confirmed, rather than guess at either now.

here can I verify a supplier’s AS9100 certification status by clause scope?

The IAQG OASIS Database is the authoritative source for verifying a supplier’s certification status, scope, and certifying body.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching how AS9100 differs from what you already know? Start with AS9100 vs ISO 9001 for the strategic-level comparison before diving deeper into clause specifics.

🔹 Ready to start closing clause gaps before your next audit? Run the free AS9100 Rev D Gap Assessment Checklist against your current QMS this week.

🔹 Need the official standard to reference clause language directly? Get the current edition from ANSI Webstore — code CC2026 takes 5% off through the end of 2026.

🔹 Want your team trained on how auditors actually interpret these clauses? BSI Group’s AS9100 training courses cover clause-level interpretation for internal teams.

The Standards Navigator will update this breakdown when IA9100 is formally published and its transition requirements are established. Until then, this guide reflects the current AS9100 Rev D requirements.


Get Ahead of the Clause Gaps Auditors Actually Find

Shops can miss AS9100 audit gaps on the clauses they assumed were “basically the same as ISO 9001” — counterfeit parts prevention, production equipment control, FOD, ethics awareness — requirements that don’t appear in ISO 9001 in this form.

Organizations that treat these as genuinely new requirements build the process controls early and walk into Stage 2 with evidence already in hand. Organizations that treat AS9100 as an ISO 9001 add-on end up building those same controls under audit pressure, on a clock they don’t control.

The Standards Navigator tracks every AS9100 clause, sub-clause, and upcoming IA9100 change so you don’t have to reverse-engineer them from a nonconformance report.

👉 Get updates on AS9100 and the IA9100 transition
👉 Be first to access new aerospace gap assessment tools and clause references

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISOQAR Academy Training Review: Is It Worth It for Manufacturers in 2026?

ISOQAR Academy is the training division of certification body ISOQAR, offering CQI/IRCA-certified courses across ISO 9001, 14001, and 45001. This review breaks down course levels from foundation through lead auditor, distinguishes the IMS route from the auditor-conversion route, and covers what training costs and how to decide which level actually fits a given shop.

ISOQAR doesn’t just certify manufacturers — it trains them through ISOQAR Academy. Here’s what the courses actually cover, what they cost, and whether formal training is worth the investment for your shop

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you. The Standards Navigator is an authorized affiliate of ISOQAR.


Your Auditors Don’t Need a Certificate. They Need to Actually Be Competent.

Every ISO standard requires competent internal auditors. None of them requires you to buy a specific training course to get there.

That distinction matters, because training providers — ISOQAR included — will always make the case that their course is the fastest path to that competence. Sometimes it is. Sometimes your shop already has the in-house experience to get there a cheaper way. The question worth answering before you book anything is which path actually fits where your operation stands right now.

ISOQAR Academy is the training arm of ISOQAR, the UKAS-accredited certification body. It offers CQI/IRCA-certified auditor training alongside foundation and other ISO courses across ISO 9001, ISO 14001, ISO 45001, and ISO 27001, delivered both in person at UK training venues and through live virtual classrooms. This review breaks down what ISOQAR Academy training actually covers, what it costs, and how to decide whether it’s the most efficient way to build your team’s competence.

From the Floor: I’ve watched auditors who were genuinely sharp on ISO 9001 fundamentals still miss things once the audit crossed into AS9100-only territory — a configuration management record that didn’t tie back cleanly, a counterfeit-parts control that existed on paper but nobody on the floor could actually explain. That’s not a competence gap in the general sense. It’s a knowledge gap in the aerospace-specific clauses that ISO 9001 experience alone doesn’t cover. Training earns its cost closing that specific gap — it doesn’t replace the auditing fundamentals your team should already have walking in.

Before you book a course, know where your QMS actually stands. A gap assessment tells you which clauses need work before you decide who needs training and at what level.

📥 Download the ISO 9001 Roadmap — a step-by-step implementation guide that walks you from gap assessment through Stage 2 audit clearance, so you know exactly what training gap you’re actually closing.


In This Guide

  • What ISOQAR Academy is and how it fits alongside ISOQAR’s certification business
  • What each course level actually covers — foundation, internal auditor, integrated auditor, and lead auditor
  • The honest pros and cons of training through ISOQAR Academy
  • What it costs, and how the pricing model works
  • A decision framework: which course level fits your shop right now
  • How ISOQAR Academy compares to BSI Group’s training catalog
  • FAQ: CQI/IRCA accreditation, in-house delivery, and what training does and doesn’t guarantee


👉 Start Here: Where to Look Into ISOQAR Academy Training

If your shop is evaluating formal ISO training, ISOQAR Academy’s course catalog spans foundation, internal auditor, and lead auditor levels across ISO 9001, ISO 14001, and ISO 45001. Review ISOQAR Academy’s current ISO 9001 training courses.

If you haven’t purchased a current copy of the standard yet, budget for it separately — course fees don’t always include it. Buy the current standard through the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.


What Is ISOQAR Academy?

ISOQAR Academy is the training division of ISOQAR, part of the Alcumus Group. While ISOQAR’s certification arm audits organizations against ISO standards, the Academy is a separate function that teaches teams how to understand and audit against those same standards — ISOQAR reports delivering over 8,000 hours of training to 10,000 participants each year.

Courses run through two delivery formats: classroom-based training at UK venues, and live virtual classroom sessions for teams who want to avoid travel cost and time away from the floor. In-house delivery is also available for shops training multiple employees at once, built around your own facility’s documentation rather than a generic case study.

A meaningful share of ISOQAR Academy’s auditor-level courses are CQI/IRCA-certified — accredited through the Chartered Quality Institute’s International Register of Certificated Auditors. That certification provides a formally recognized training credential, which can be useful when an individual’s training record needs to be demonstrated beyond their current employer, not just a course completion certificate.

A 2026 note on ISO 14001: ISOQAR Academy’s catalog is already transitioning ISO 14001 courses to the 2026 edition of the standard. If you’re booking ISO 14001 training, confirm which edition the specific course covers before enrolling — you don’t want your team trained against a superseded version while your certification body is auditing against the current one.


What ISOQAR Academy Courses Actually Cover

ISOQAR Academy training course levels for ISO auditors
ISOQAR Academy training ranges from foundation and internal auditor courses to IMS, CQI/IRCA conversion, and lead auditor training.

ISOQAR Academy’s course catalog isn’t one course — it’s a track, and most manufacturers only need the first one or two levels.

Course LevelWhat It CoversTypical LengthBest For
Foundation (single standard)Standard requirements clause by clause1 dayTeams new to a standard needing working familiarity before anything else
IMS FoundationIntroduces ISO 9001, ISO 14001, and ISO 45001 together, focused on the synergies between them1 dayTeams building familiarity across multiple standards from scratch
Internal Auditor (single standard)Planning, conducting, and reporting internal audits against one standard1 day (standard track) or 2 days (CQI/IRCA-certified)Teams ready to run their own audit program for a single standard
IMS Internal AuditorAuditing across ISO 9001, ISO 14001, and ISO 45001 in one course2 daysTeams already familiar with quality, environmental, or safety systems who need to audit all three together
Auditor Conversion (CQI/IRCA)Extends an existing single-standard auditor’s skills to add ISO 14001 and ISO 450013 daysAuditors already qualified in one standard who need to add EMS/OHS scope
Lead AuditorFull auditor competence for leading external or supplier audits5 daysDeveloping a professional auditing credential, not typical for a single shop’s internal program

A note on terminology: ISOQAR Academy doesn’t sell one generic “integrated auditor” course — it separates a from-scratch IMS Internal Auditor course (for teams building multi-standard audit capability together) from a CQI/IRCA conversion course (for auditors who already hold a single-standard credential and want to extend it). Confirm which one actually fits your team’s starting point before booking, since they assume different prior knowledge.

Most common finding: manufacturers default to booking internal auditor training as the first step, even when their team has never worked through the standard’s requirements in a structured setting. The foundation course exists for a reason — you can’t audit effectively against clauses your team doesn’t understand yet.

If you are new to a standard and still building your QMS → start with the foundation course, not internal auditor training.

If your team already understands the standard and just needs to run audits → the internal auditor course is the right entry point. CQI/IRCA-certified tracks provide a formally recognized training credential, which is useful if the individual’s training record ever needs to be demonstrated beyond this employer — a generic in-house version doesn’t carry that same portability.

If you’re pursuing certification across ISO 9001, 14001, and 45001 together and your team is starting from scratch → the IMS Internal Auditor course is built specifically for that, rather than sending your team through three separate single-standard courses.

If someone on your team is already a qualified auditor for one standard and you’re adding scope → the CQI/IRCA conversion course extends that existing credential to ISO 14001 and 45001, rather than starting them over with a from-scratch integrated course.


Pros and Cons of ISOQAR Academy Training

What ISOQAR Academy Does Well

  • CQI/IRCA-certified course tracks for internal and integrated auditor levels, providing a formally recognized training credential rather than just a generic completion certificate
  • Full course ladder from foundation through lead auditor, so you’re not stuck choosing between “too basic” and “too advanced”
  • Both classroom and live virtual delivery, with in-house options for training multiple employees at once
  • Courses cover ISO 9001, ISO 14001, ISO 45001, and ISO 27001 under one training provider
  • High course volume — ISOQAR reports delivering over 8,000 hours of training to 10,000 participants annually across course levels

Where ISOQAR Academy May Fall Short

  • Course pricing isn’t fully published for every format — in-house and group quotes typically require a direct request
  • Course value depends heavily on where your team already stands: a foundation course won’t add much for an experienced auditor, and an internal auditor course won’t help a team with no prior standard familiarity
  • Classroom locations are UK-based (Manchester, London, Bristol, Leamington Spa, and similar venues) — manufacturers outside the UK should confirm live virtual availability and time zone fit before booking
  • As with any training provider, actual instructor quality varies by who’s assigned to your specific session — a strong course catalog doesn’t guarantee every individual instructor is an equally strong fit for your industry

What ISOQAR Academy Training Costs

ISOQAR Academy doesn’t publish fixed pricing on its course pages — every course listing directs you to request details and book directly rather than showing a price upfront. That’s a call-for-quote model, not hidden pricing, but it does mean you can’t budget from the website alone. What’s generally true:

  • Individual seats on public courses are typically the standard entry point for one or two employees.
  • In-house delivery for multiple employees is worth comparing directly against per-seat pricing once you’re training several people — don’t assume one option is cheaper without requesting both quotes.
  • The standard itself usually isn’t included in the course fee. Budget separately for a current copy before class starts.
  • Live virtual delivery can meaningfully reduce total cost for smaller shops by cutting travel and time away from the floor, particularly for foundation-level courses that don’t require the same hands-on format as auditor training.

Because pricing isn’t published, request a written quote for your specific course, format, and group size before committing a budget — and get it in writing rather than relying on a verbal figure from an initial call.

If you haven’t priced out the full path to certification — training, documentation, gap assessment, and audit fees together — see the complete breakdown of ISO certification costs before committing to training in isolation.


Which Course Level Fits Your Shop?

Where you land depends on what competence already exists on your team — not on whether training is generically “a good idea.”

No prior experience with the standard and no internal audit experience on staff → Start with the foundation course. Booking internal auditor training before your team understands the standard’s requirements means teaching people to audit against clauses they haven’t learned yet.

Team already understands the standard but has never formally audited against it → The internal auditor course is the right level. A CQI/IRCA-certified track is worth the modest premium over a generic version if anyone might use the credential beyond this one employer.

Pursuing certification across multiple standards at once → The IMS Internal Auditor course (or the CQI/IRCA conversion course, if someone’s already qualified in one standard) is built for exactly this and avoids sending your team through three separate single-standard courses.

One experienced auditor already on staff → That person may be able to mentor others through the standard’s requirements without sending the whole team through a full course — formal training becomes most valuable for newer team members who don’t have that internal resource.

Multiple employees need the same training → Compare in-house group quotes against per-seat public course pricing before booking. In-house sessions built around your own documentation are usually the more efficient option past two or three people.

⚠️ Common mistake: booking lead auditor training as a first step before your shop has working documentation in place. That course assumes real familiarity with the standard already — it’s the wrong entry point for a team still building its QMS.


How ISOQAR Academy Compares to BSI Group Training

BSI Group runs a parallel training catalog and is the other name that comes up constantly in this conversation. Both providers offer foundation, internal auditor, and lead auditor courses across the major ISO standards, and both run CQI/IRCA-certified tracks at the auditor level.

FactorISOQAR AcademyBSI Group
Foundation courseYesYes
Internal auditor courseYesYes
Lead auditor courseYesYes
CQI/IRCA-certified tracksYesYes
Live virtual deliveryYesYes
In-house deliveryYesYes
UK classroom networkSmaller, regional venuesBroader national footprint

Neither provider wins universally — the practical differences tend to come down to course availability for your specific standard and format, instructor pool in your region, and quoted price for your group size, not a meaningful difference in the underlying accreditation of the courses themselves. Compare BSI Group’s ISO training courses alongside ISOQAR Academy before booking, particularly if you’re training multiple people and requesting in-house quotes from both.

For U.S. manufacturers specifically: both providers’ classroom networks are UK-based, so live virtual delivery is likely to be the practical default for a single-employee booking — reserve in-person or in-house formats for cases where you’re training several people at once and travel makes more sense.

If you’re already working with ISOQAR as your certification body → training through ISOQAR Academy keeps your documentation and terminology consistent with the language your certification auditor will use, though it isn’t required — you can train with one provider and certify with another.

If brand or provider isn’t a factor → request quotes from both and let course content, instructor experience, and price for your group size make the decision.


A Note on Certification vs. Training

ISOQAR Academy training vs certification for ISO management systems
ISOQAR Academy training builds auditor competence, while ISO certification independently evaluates whether a management system meets the applicable standard.

Worth being direct about this distinction: ISOQAR Academy trains your team. ISOQAR’s certification division audits your organization and issues your certificate. These are related but separate parts of the same company, and it’s a common point of confusion.

Completing an ISOQAR Academy course does not guarantee a smoother certification audit, whether that audit is conducted by ISOQAR or a different certification body entirely. Training builds competence — it doesn’t buy leniency, and the certification decision itself is a separate engagement with its own scope, quote, and timeline.

If you’re also evaluating which certification body to use — ISOQAR, BSI, or another UKAS-accredited provider — that’s a distinct decision from which training to book, and one worth researching separately. See the full breakdown of ISO certification bodies for that comparison.


ISOQAR Academy training readiness checklist for manufacturers
Use this ISOQAR Academy training checklist to match the right course to your team’s competence, audit experience, QMS readiness, and delivery needs.

Quick Checklist: Is Your Shop Ready to Book Training?

  • ✅ You’ve identified whether your team needs foundation-level or auditor-level training — not defaulted to auditor training by habit
  • ✅ You know whether you’re pursuing a single standard or an integrated audit across multiple standards
  • ✅ You’ve compared in-house group pricing against individual seat pricing for your team size
  • ✅ You’ve budgeted separately for the standard itself, since course fees typically don’t include it
  • ✅ You’ve confirmed live virtual availability if your shop is outside the UK or wants to avoid travel cost
  • ⚠️ If your QMS documentation isn’t far enough along to give auditors real processes and records to work with, reconsider the timing of internal auditor training — there’s little to practice against otherwise

FAQ

Does ISOQAR Academy training count toward certification?

No single training course is required for certification. What matters is that your internal auditors are genuinely competent to plan, conduct, and report an effective audit — training is one path to building that competence, not a certification requirement in itself. Your certification body will assess whether your organization has established and maintained personnel competent to carry out its management system and audit activities, not which specific course they attended.

Is ISOQAR Academy training CQI/IRCA accredited?

A meaningful portion of ISOQAR Academy’s internal auditor, IMS internal auditor, and conversion courses are CQI/IRCA-certified, accredited through the Chartered Quality Institute’s International Register of Certificated Auditors. Confirm accreditation status for the specific course you’re booking, since not every course level carries this certification.

Can I train with ISOQAR Academy and certify with a different body?

Yes. Training and certification are separate engagements, even when both are available through ISOQAR. You can complete ISOQAR Academy training and pursue certification with BSI, another UKAS-accredited body, or ISOQAR’s own certification division — whichever fits your shop’s needs.

How much does ISOQAR Academy training cost?

Pricing isn’t published on ISOQAR Academy’s course pages — course listings direct you to request details and book directly. Individual public-course seats are generally the entry point for one or two employees; in-house delivery is quoted separately and worth comparing directly once you’re training several people. Request a written quote for your specific course, format, and group size before budgeting.

Does the course include a copy of the standard?

Course inclusions vary by course and format. Confirm directly with ISOQAR Academy whether the applicable standard is included before enrolling — if not, budget separately for a current copy.

Is virtual training as effective as classroom training?

For foundation-level courses, live virtual formats generally work well. For auditor-level courses with hands-on practical exercises, in-person classroom formats offer more natural opportunities for group exercises, though live virtual delivery remains a reasonable option if travel cost or time away from the floor is the deciding factor.

Can one course cover ISO 9001, ISO 14001, and ISO 45001 together?

Yes — the IMS Internal Auditor course covers all three standards together for teams starting from scratch, and the CQI/IRCA conversion course extends an existing single-standard auditor’s skills to add the other two. Either route is typically more efficient than three separate single-standard courses for shops pursuing or maintaining an integrated management system — which one fits depends on whether your team already holds a single-standard auditor qualification.

Is ISOQAR Academy the same as ISOQAR certification?

No. ISOQAR Academy is the training division; ISOQAR’s certification division conducts the third-party audits that result in your certificate. They’re related parts of the same company but function as separate engagements with separate scopes and pricing.


📥 Free Resources

  • ISO 9001 Roadmap — Step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — Practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — Evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts

Not Sure What to Do Next?

🔹 Still researching whether formal training makes sense for your shop? Start with the ISO 9001 Roadmap to see exactly where your QMS stands before you commit a training budget.

🔹 Ready to look at course options? Review ISOQAR Academy’s current ISO 9001, 14001, and 45001 training courses and request a quote for your team size.

🔹 Want to compare against another training provider first? Compare BSI Group’s ISO training courses.

🔹 Still deciding on a certification body altogether? See how the major players stack up in Best ISO Certification Bodies — Ranked & Reviewed.


Training is one line item in a bigger certification budget, and it earns its cost once the rest of your QMS groundwork is in place — not before. Get the sequence right, and ISOQAR Academy training becomes the thing that builds real auditor competence on your team, not just a certificate on the wall.

The Standards Navigator covers ISO training, certification, and provider selection in plain, practitioner-level language — no sales pitch, just what actually moves the needle toward a compliant, audit-ready QMS.


Stay Ahead of Training and Certification Decisions

Most manufacturers who end up frustrated with a training investment aren’t dealing with a bad course — they’re dealing with a mismatch between the course level they booked and where their team actually stood.

Organizations that build their QMS, develop competence, and conduct meaningful internal audits before certification tend to walk into the certification process with fewer surprises than shops that bolt on training as an afterthought once a customer starts asking questions.

The Standards Navigator covers ISO training providers, certification body selection, and QMS implementation for manufacturers building a compliant, audit-ready quality system.

👉 Get updates on training provider comparisons and certification body reviews

👉 Be first to access new gap assessment tools and implementation resources

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

ISO 13485 Gap Assessment: A Step-by-Step Guide for Medical Device Manufacturers (2026)

Learn how to run an ISO 13485 gap assessment step by step — from scoping and clause mapping to grading findings and building a remediation timeline before your certification audit.

How to run an ISO 13485 gap assessment before your certification body ever sees your QMS.

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Gap Assessment Is the Step Most Manufacturers Skip

Many manufacturers don’t discover their biggest ISO 13485 gaps until they systematically compare their QMS against the standard.

An ISO 13485 gap assessment gives you a structured way to find those gaps before your certification body does. It’s a clause-by-clause comparison of your current quality management system against what ISO 13485:2016 actually requires — and it’s one of the highest-leverage steps between “we think we’re ready” and “we’re ready for Stage 1.”

This guide walks through the gap assessment process step by step: how to scope it, how to run it, how to grade what you find, and how to turn the results into a remediation plan your team can actually execute before your audit window opens.

From the Floor: As a certified ISO 9001 Internal Auditor, the pattern I see most often in gap assessments — regardless of which standard is on the cover — is a QMS that has real documentation but no clause map. Procedures exist. Records exist. But nobody has walked the standard clause by clause and confirmed each requirement actually has evidence behind it. That’s exactly what a gap assessment is designed to expose, and finding it internally gives your team more control over the remediation timeline than discovering it during certification.

Before you build a remediation plan, you need to know where the gaps actually are. Run the free ISO 13485 Gap Assessment Checklist and get a clause-by-clause starting point for your own QMS.


In This Guide

  • What an ISO 13485 gap assessment actually is, and how it differs from an internal audit
  • The eight-step process, from scoping to remediation
  • How to grade findings so your team knows what to fix first
  • A readiness checklist for what “gap-assessed” should actually mean
  • Answers to the questions manufacturers ask most before their first assessment


👉 Start Here (Top Resources)

  • Own the standard you’re assessing against: ISO 13485:2016 — ANSI Webstore — you can’t run an accurate gap assessment without the current clause text in front of you. Use code CC2026 for 5% off through December 31, 2026.
  • Close the gaps once you find them: 9001Simplified — documentation kits built for manufacturers who need to build or rebuild QMS documentation without hiring a full-time consultant.
  • Get your team trained on the requirements before they run the assessment: ISO 13485 Training — BSI Group — a team that understands the clause structure finds gaps faster and more accurately than one working from intuition.

What an ISO 13485 Gap Assessment Actually Is

A gap assessment is not an audit. It’s not a certification activity, and no external party has to be involved. It’s an internal, structured comparison: for every requirement in ISO 13485:2016, does your QMS have documented evidence that requirement is met — and if not, how far off is it?

That distinction matters because it changes the tone of the exercise. An internal audit (covered in our guide on how to audit a medical device QMS) assumes a QMS is largely built and tests whether it’s being followed. A gap assessment assumes nothing — it’s asking “does this exist at all, and if it does, is it complete.”

Gap Assessment vs. Internal Audit

Gap AssessmentInternal Audit
Primary questionDoes the requirement and supporting evidence exist?Is the QMS being followed and operating effectively?
Typical timingOften performed during QMS development or transitionPerformed as part of the established audit program
Main outputGap list and remediation planAudit findings and corrective action
Evidence examinedDocuments, records, and implementation evidenceProcess implementation, records, and objective evidence
PurposeIdentify what needs to be built, changed, or strengthenedEvaluate conformity and implementation of the established QMS

Quick Answer

QuestionQuick Answer
Is a gap assessment required for ISO 13485 certification?No. It’s not a formal requirement of the standard, but it’s a practical risk-reduction step manufacturers can use to identify gaps before a certification audit.
How long does a gap assessment take?As a planning estimate, a single-site manufacturer with an existing QMS might spread the assessment across roughly 2–4 weeks of part-time effort. Actual duration varies significantly with QMS maturity, scope, number of sites, product lines, and team availability.
Can I do a gap assessment myself, or do I need a consultant?You can do it yourself with a structured checklist and a working knowledge of the standard. Consultants add value for complex or first-time QMS builds, but the assessment itself doesn’t require outside certification.
What’s the difference between a gap assessment and an internal audit?A gap assessment checks whether documentation and evidence exist against each clause. An internal audit checks whether an existing, documented QMS is actually being followed in practice.

The Eight-Step Gap Assessment Process

Step 1: Define Scope and Assemble Your Team

Before you open the standard, decide what’s actually in scope. Which sites? Which product lines? Which regulatory markets — because that determines which country-specific requirements layer on top of the ISO 13485 baseline. If you’re weighing whether MDSAP applies to your assessment scope, our MDSAP vs ISO 13485 guide walks through that decision separately.

Assemble a small cross-functional team — quality, at minimum, plus whoever owns design, production, and supplier management. A gap assessment run entirely by one person in the quality department tends to miss operational gaps that only show up on the floor.

Step 2: Gather Current QMS Documentation

Pull everything: your quality manual, procedures, work instructions, forms, records, and any prior audit findings — internal or external. If your document control system is disorganized, this step alone often reveals your first gap. See our guide on ISO 13485 documentation requirements for what a complete document set should include.

Step 3: Build Your Clause Map

At a high level, ISO 13485:2016 organizes its requirements across five main clause groups: Quality Management System (Clause 4), Management Responsibility (Clause 5), Resource Management (Clause 6), Product Realization (Clause 7), and Measurement, Analysis and Improvement (Clause 8). Build a simple matrix — clause number down one side, your corresponding procedure or record down the other. Anywhere that cell is blank is your first visible gap, before you’ve even started evaluating quality.

ISO 13485 gap assessment clause map connecting requirements to procedures, records, and objective evidence
An ISO 13485 gap assessment clause map connects each requirement to the corresponding QMS procedure, work instruction, records, and objective evidence.

Step 4: Walk Each Clause Against the Evidence

This is the core of the assessment. For each clause, ask three questions: Does a documented procedure exist? Does it match what the standard actually requires — not just what sounds similar? And is there objective evidence (records, forms, logs) that the procedure is being followed, not just written?

CAPA is worth flagging specifically here because it requires the team to connect nonconformance, root cause, corrective action, and effectiveness verification across the QMS. Our breakdown of CAPA requirements under ISO 13485 covers what auditors expect to see connected — traceable within the QMS rather than reconciled manually across separate systems.

This is often where gap assessments slow down because the work is tedious, not because it’s conceptually difficult. If your team needs a structured starting point instead of building the clause matrix from scratch → Run the free ISO 13485 Gap Assessment Checklist.

ISO 13485 gap assessment showing how procedures, records, and objective evidence demonstrate QMS conformity
An ISO 13485 gap assessment should verify not only that procedures exist, but that records provide objective evidence the QMS is being followed.

Step 5: Grade Each Finding

Not every gap carries the same weight. A missing signature on a training record is not the same category of problem as a design control process that doesn’t exist. Grade findings on a simple scale:

  • Critical — the requirement is effectively absent. No procedure, no evidence, no compensating control.
  • Major — a procedure exists but has a significant gap against the clause requirement, or evidence of following it is inconsistent.
  • Minor — the procedure and evidence both exist, but execution has small, correctable inconsistencies.

Grading matters because it drives sequencing. These labels are an internal prioritization framework, not ISO 13485-defined finding classifications — the exact grading terminology and criteria used by a certification body or regulatory program can vary. For an internal assessment, the important thing is to apply your criteria consistently so the team knows which gaps require immediate attention.

Step 6: Prioritize Remediation

Start with the gaps that present the greatest risk to QMS conformity or product and regulatory compliance. In most cases, that means addressing foundational gaps such as a missing design-control process or nonexistent CAPA system before working through lower-risk administrative issues. Major findings come next, typically grouped by clause area so one person or team can work through related gaps together rather than jumping between unrelated processes.

If you are rebuilding documentation from a critical or major finding → start with the clause itself, not a generic template. A procedure written to satisfy a checklist item without matching your actual process creates a new gap the moment an auditor asks a follow-up question.

If you are working through a backlog of minor findings → batch them by owner and set a single close-out date rather than tracking dozens of individual deadlines. Minor findings left open individually tend to get lost; batched with a deadline, they get closed.

Step 7: Build a Remediation Timeline

Attach real dates to every finding, not target quarters. Critical findings should have the shortest timeline your team can realistically execute — these are the gaps most likely to create significant problems during a certification assessment if they remain unresolved. Build in a buffer before your target certification audit date; remediation almost always takes longer than the first estimate, especially where a new procedure requires training staff to actually follow it.

Step 8: Re-Assess Before You Schedule Your Audit

A gap assessment isn’t a one-time snapshot. Once remediation work closes out your critical and major findings, re-walk those specific clauses to confirm the fix actually holds — not just that a document was updated, but that the evidence trail behind it exists. This is also the point where many manufacturers benefit from a full internal audit as a final check before scheduling Stage 1.


Common Mistakes That Undermine a Gap Assessment

Treating the assessment as a documentation review only. Confirming a procedure exists isn’t the same as confirming it’s followed. A gap assessment that never looks at records — training logs, CAPA files, supplier evaluations — will miss exactly the kind of gap an auditor finds first, because auditors ask for objective evidence, not just the procedure. Our guide on common mistakes in ISO 13485 QMS implementation covers this pattern in more depth.

Assessing against an old edition of the standard. ISO 13485:2016 is the current edition, but manufacturers working from a QMS built years ago sometimes have procedures written against superseded clause numbering. Confirm you’re assessing against the current published text before you start building your clause matrix.

Skipping the connection to FDA’s QMSR. If you sell into the United States, consider whether your gap assessment also needs to address FDA’s QMSR requirements and inspection expectations — FDA’s QMSR, effective February 2, 2026 and incorporating ISO 13485:2016 by reference, expanded what FDA can review during an inspection. Records that were previously exempt from routine inspection under the legacy QSR — management review, internal quality audit, and supplier audit records — are not exempt under QMSR. That’s worth building into your assessment scope rather than assuming an ISO 13485-only assessment automatically covers it.


Gap Assessment Readiness Checklist

✅ Scope defined — sites, product lines, and regulatory markets confirmed
✅ Cross-functional team assembled, not just quality department staff
✅ Full current QMS documentation set gathered and organized
✅ Clause matrix built against ISO 13485:2016, Clauses 4 through 8
✅ Each clause walked against both procedure and objective evidence, not procedure alone
✅ Findings graded — critical, major, minor — using consistent criteria
✅ Remediation timeline built with real dates, prioritized by severity
✅ Critical and major findings re-assessed after remediation, before scheduling your audit

ISO 13485 gap assessment process showing how manufacturers find, prioritize, remediate, and re-assess QMS gaps before certification
An ISO 13485 gap assessment turns identified QMS gaps into a prioritized remediation plan, followed by verification and re-assessment before the certification audit.

Frequently Asked Questions

Is a gap assessment required before ISO 13485 certification?

No. It’s not a formal requirement in the standard itself. It’s a risk-reduction step manufacturers use to avoid discovering major or critical nonconformities for the first time during an actual certification audit, where findings can delay certification.

How is a gap assessment different from an internal audit?

A gap assessment asks whether documentation and evidence exist at all against each clause — it’s typically run once, early, often before a QMS is fully built out. An internal audit assumes a documented QMS exists and tests whether it’s actually being followed in day-to-day operation. A common approach is to run the gap assessment first, then use internal audits on a recurring schedule once the QMS is established.

Who should be involved in a gap assessment?

At minimum, someone from quality who knows the standard well enough to interpret clause intent, plus representation from any function the clauses touch directly — design, production, supplier management. A single-person assessment tends to miss operational gaps that only surface when someone from outside quality reviews the finding.

How long does a gap assessment typically take?

As a planning estimate, a manufacturer with an existing QMS and a single site in scope might spread the assessment across roughly 2–4 weeks of part-time effort. Actual duration varies significantly with QMS maturity, scope, number of sites, product lines, and team availability — manufacturers building a QMS from scratch, or with multiple sites in scope, should expect it to take longer.

Can I use the same gap assessment for MDSAP readiness?

Largely, yes — MDSAP audits use ISO 13485:2016 requirements alongside applicable regulatory requirements from participating authorities, so a thorough ISO 13485 gap assessment covers most of the same ground. MDSAP layers those country-specific regulatory requirements on top of the ISO 13485 baseline, so if MDSAP is in scope, your assessment should also map those additional requirements. See our MDSAP vs ISO 13485 guide for how the two relate.

What happens if I find a critical gap close to my planned audit date?

Push the audit date. Scheduling a certification audit around a known critical gap doesn’t make the gap disappear — it moves the risk of discovering that gap into the certification audit, where the certification body will determine whether the issue constitutes a nonconformity and how it should be classified, instead of remaining an internal finding you controlled the timeline on.

Do I need a consultant to run a gap assessment?

Not necessarily. A structured checklist and a working knowledge of the standard’s clause structure is enough for most single-site manufacturers with an existing QMS. Consultants add the most value for first-time QMS builds, multi-site assessments, or situations where the internal team lacks bandwidth to run the assessment alongside daily operations.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still figuring out where your QMS stands? Start with the ISO 13485 Gap Assessment Checklist — it’s the fastest way to see your clause-by-clause starting point before you build a full remediation plan.

🔹 Ready to close documentation gaps you’ve already identified? 9001Simplified’s documentation kits are built for manufacturers assembling or rebuilding QMS documentation without a full-time consultant.

🔹 Need to confirm your clause matrix against the current standard? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off through December 31, 2026.

🔹 Want your team trained before they run the assessment? BSI Group’s ISO 13485 training builds the clause knowledge that makes a gap assessment faster and more accurate.

Treating a gap assessment as a formality can leave significant gaps undiscovered until the certification audit. A properly executed assessment gives your team an opportunity to find those gaps internally, assign ownership, and control the remediation timeline before the certification audit begins. The Standards Navigator will keep this guide current as ISO 13485 and its related regulatory frameworks continue to evolve.


Stay Ahead of Your Next Audit Cycle

Skipping the gap assessment step doesn’t remove the risk of undiscovered gaps — it increases the chance that a gap will first be identified during the certification process, in front of an auditor, where the certification body determines whether it constitutes a nonconformity. Running it properly moves that discovery earlier, onto your own timeline, with your team in control of the fix.

The Standards Navigator tracks how ISO 13485, MDSAP, and FDA’s QMSR continue to shift so your QMS doesn’t fall behind a requirement you didn’t know had changed.

👉 Get updates on ISO 13485 requirements and medical device compliance as they happen
👉 Be first to access new gap assessment tools and documentation resources as we build them

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

MDSAP vs ISO 13485: What’s the Difference and Do You Need Both in 2026?

MDSAP and ISO 13485 are often confused, but they answer different questions. This guide breaks down how the MDSAP audit program relates to the ISO 13485:2016 standard, what changed with FDA’s 2026 QMSR, and which manufacturers actually need MDSAP registration.

Whether the MDSAP consolidated audit program adds real value to your QMS — or scope you don’t need yet.

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Two Audits, One QMS Standard — and a Decision Most Manufacturers Get Wrong

MDSAP vs ISO 13485 is a distinction worth getting right before you scope an audit program: these are not competing options, and they are not two paths to the same certificate. Treating them as interchangeable is exactly how manufacturers end up either over-auditing themselves or discovering — mid-application — that a market they assumed was covered isn’t.

If you sell into more than one of the five MDSAP countries, this decision affects your audit calendar, your registrar spend, and your regulatory submission timeline for years. If you sell only into the EU or UK, most of what follows doesn’t apply to you at all — and that’s worth knowing before you spend a quarter evaluating a program you don’t need.

This guide breaks down exactly what MDSAP is, how it relates to ISO 13485:2016, and — now that the FDA’s Quality Management System Regulation has replaced the legacy 21 CFR Part 820 — what changed for US-market manufacturers in 2026.

From the Floor: With 25+ years in heavy industrial manufacturing and a certified ISO 9001 Internal Auditor credential, I’ve seen the same regulated-QMS failure pattern show up regardless of which standard is on the cover — 9001 or 13485. It’s not missing documentation. It’s documentation that exists but doesn’t connect: a CAPA log that references a nonconformance report that was never actually closed out in the corrective action file. Stack five regulatory authorities’ expectations on top of each other instead of one, and that gap can become a nonconformity that appears in the MDSAP audit record used by the participating Regulatory Authorities.

Before you evaluate MDSAP, confirm your QMS actually conforms to ISO 13485:2016 first — MDSAP audits against it, it doesn’t substitute for it. Run the free ISO 13485 Gap Assessment Checklist and see exactly where your documentation stands before you add audit scope on top of it.

In This Guide

  • What MDSAP actually is, and how it relates to ISO 13485:2016
  • A side-by-side comparison of both frameworks
  • What changed in 2026 with the FDA’s QMSR and the revised MDSAP Audit Approach
  • Decision-stage signals for whether MDSAP applies to your business
  • What MDSAP costs — and what it saves — compared to separate country audits
  • Documentation issues that can create problems in MDSAP-scope audits
  • A readiness checklist and answers to the questions manufacturers ask most


👉 Start Here (Top Resources)

  • Own the standard MDSAP is built on: ISO 13485:2016 — ANSI Webstore — the foundation document every MDSAP audit is measured against. Use code CC2026 for 5% off through December 31, 2026.
  • Close documentation gaps before you’re audited on them: 9001Simplified — documentation kits built for manufacturers assembling or tightening a QMS without hiring a full-time consultant.
  • Get your team trained on the underlying requirements: ISO 13485 Training — BSI Group — BSI is one of the Auditing Organizations recognized under MDSAP, and their training builds the ISO 13485 foundation your audit is scored against.

What Is ISO 13485, and What Is MDSAP Built on Top Of It?

ISO 13485:2016 is the quality management system standard for medical device manufacturers. It’s a standalone document you can certify to on its own — covered in detail in our What Is ISO 13485 guide.

MDSAP (Medical Device Single Audit Program) is not a standard. It’s a regulatory audit program. Five participating Regulatory Authorities — Australia’s TGA, Brazil’s ANVISA, Health Canada, Japan’s MHLW/PMDA, and the U.S. FDA — use a single consolidated audit, conducted by an MDSAP-recognized Auditing Organization, to assess the applicable QMS and regulatory requirements across participating markets, rather than requiring separate audits from each regulator. That audit is scored against ISO 13485:2016 as the baseline, with country-specific regulatory requirements layered on top for each market a manufacturer participates in.

Standalone ISO 13485 certification, by contrast, is issued by certification bodies accredited through national accreditation bodies — in the US, that’s typically ANAB. MDSAP Auditing Organizations go through a separate recognition process run directly by the participating Regulatory Authorities, not through the standard accreditation pathway.

In plain terms: ISO 13485 is what you’re audited against. MDSAP is who accepts that audit, and how many regulators it satisfies at once.


Quick Answer

QuestionQuick Answer
Is MDSAP the same as ISO 13485?No. MDSAP is a multi-country regulatory audit program built on top of ISO 13485:2016 — it doesn’t replace the standard, it audits against it plus country-specific requirements.
Do I need ISO 13485 certification before MDSAP?No. Your QMS must conform to ISO 13485:2016, but you don’t necessarily need a separate ISO 13485 certificate before undergoing an MDSAP audit — the MDSAP audit itself assesses that conformance.
Is MDSAP required?Only for Class II–IV Canadian market access. In the other participating MDSAP markets, participation is generally voluntary, although it can consolidate applicable regulatory assessments across multiple markets.
Does MDSAP replace FDA inspections entirely?No. MDSAP audit results can be used by FDA within its regulatory program, but FDA retains its authority to conduct inspections, including for-cause inspections.

MDSAP vs ISO 13485: Side-by-Side

CategoryISO 13485:2016MDSAP
What it isA quality management system standardA multi-jurisdiction regulatory audit program
BasisStandalone documentBuilt on ISO 13485:2016 plus country-specific regulatory requirements
Who administers itCertification bodies accredited by ANAB or an equivalent accreditation bodyAuditing Organizations recognized by the five participating Regulatory Authorities
Countries coveredGlobal — recognized wherever ISO 13485 certification is acceptedAustralia, Brazil, Canada, Japan, United States
Can you buy it?Yes — it’s a purchasable standard documentNo — it’s an audit program, not a document
Mandatory?Often required by customers, notified bodies, or regulators (EU MDR, for example)Mandatory only for Class II–IV Canadian market access; voluntary elsewhere
Audit frequencyPer your certification body’s surveillance schedule — typically annualInitial audit followed by annual surveillance audits within the certification cycle
What you getAn ISO 13485 certificateAn MDSAP certification document and audit report each participating Regulatory Authority can use within its own regulatory program

For the broader question of how ISO 13485 stacks up against the standard most manufacturers compare it to first, see ISO 9001 vs ISO 13485.


The 2026 Regulatory Shift: QMSR and the Revised MDSAP Audit Approach

MDSAP vs ISO 13485 infographic showing the 2026 FDA QMSR transition and changes to medical device quality records
MDSAP vs ISO 13485: The 2026 FDA QMSR aligns U.S. medical device quality requirements with ISO 13485:2016 and changes FDA access to management review, internal audit, and supplier audit records.

Two changes landed in 2026 that directly affect this comparison.

On February 2, 2026, the FDA’s Quality Management System Regulation (QMSR) officially took effect, replacing the legacy 21 CFR Part 820 Quality System Regulation and incorporating ISO 13485:2016 by reference. That doesn’t make US manufacturers MDSAP-compliant automatically — it means the US regulatory baseline now speaks the same structural language as ISO 13485, closing a gap that used to require manufacturers to maintain two separate documentation logics. We cover the mechanics of that shift in FDA QSR vs ISO 13485.

The QMSR also removed a long-standing FDA inspection exemption. Under the prior QSR, §820.180(c) shielded management review records, internal quality audit reports, and supplier audit reports from routine FDA inspection. The QMSR eliminates that exemption entirely — FDA’s own QMSR FAQ confirms investigators now have authority to review management review, quality audit, and supplier audit records as part of a standard inspection. For manufacturers who treated those records as internal-only, that’s a meaningful shift in what “audit-ready” documentation needs to look like.

Around the same window, the MDSAP Regulatory Authority Council released a revised Audit Approach document (MDSAP AU P0002.010), updating the audit sequence and process guidance auditors use during MDSAP assessments. If your last MDSAP audit was conducted under the prior version, don’t assume your documentation package is still current against the revised approach — verify against the current edition before your next audit window.

It can be tempting to assume that QMSR compliance automatically covers MDSAP scope. It doesn’t — QMSR alignment closes the gap between the US baseline and ISO 13485, but MDSAP still layers the applicable regulatory requirements of each participating jurisdiction on top of that baseline. Check where your QMS actually stands before you assume you’re covered → Run the ISO 13485 Gap Assessment Checklist.


Do You Need MDSAP? Decision-Stage Signals

  • If you are selling only into the EU or UK → you still need to meet the applicable medical-device QMS and conformity-assessment requirements for those markets, but MDSAP is not generally required there.
  • If you are selling into Canada at Class II, III, or IV → MDSAP is mandatory. Health Canada requires an MDSAP certificate, issued by a recognized MDSAP Auditing Organization, as part of the device license application.
  • If you sell into several of the five MDSAP countries → compare the cost and disruption of MDSAP against the separate regulatory assessments that would otherwise apply. Three or more can be a useful practical threshold for comparison, but the right number depends on your specific audit costs, inspection history, device scope, and market plans.
  • If you are already ISO 13485 certified and sell only into the US → weigh MDSAP against your actual FDA inspection frequency and any near-term expansion plans before adding audit scope you may not need yet.
MDSAP decision flowchart showing when medical device manufacturers need MDSAP for Canada and when it is generally voluntary in other markets
A practical MDSAP decision guide showing when certification is required for Canadian Class II–IV devices and when manufacturers should evaluate MDSAP based on market scope, audit costs, and regulatory strategy.

What MDSAP Actually Costs You — And What It Saves

The most common objection we hear is straightforward: MDSAP audits cost more than a standard ISO 13485 surveillance audit, so why add the expense?

That’s true in isolation — an MDSAP audit typically runs longer and costs more per audit day than a single-standard ISO 13485 surveillance visit, because the auditor is assessing conformance to multiple regulatory frameworks in one visit. But the comparison that matters isn’t MDSAP audit cost versus ISO 13485 audit cost. It’s MDSAP audit cost versus the combined cost of separate inspections from Health Canada, ANVISA, TGA, and PMDA, run independently, on different schedules, each requiring separate audit prep. For manufacturers selling across several MDSAP markets, the consolidation can make the overall audit program less costly and less disruptive than managing multiple separate regulatory assessments — but the business case depends on device classification, facility count, audit scope, your Auditing Organization, and your existing inspection cadence, so get a scoped quote rather than budgeting off a generic number.

Manufacturers building out documentation to support a broader audit scope shouldn’t be doing it from scratch. If your QMS documentation isn’t structured to hold up under multiple regulatory frameworks at once, that’s the gap to close first → 9001Simplified’s documentation kits are built for exactly this kind of consolidation work.


Documentation Issues That Can Create Problems in MDSAP Readiness

One area worth checking closely is CAPA traceability. CAPA records should connect clearly to the underlying nonconformance, investigation, corrective action, and effectiveness evidence, rather than leaving the auditor to reconcile separate systems manually — see our breakdown of common mistakes in ISO 13485 QMS implementation and the full CAPA requirements under ISO 13485 for what auditors expect to see connected.

Another area to review is how regulatory requirements are mapped into the QMS. MDSAP audits ISO 13485 alongside applicable jurisdiction-specific requirements, so documentation that only reflects one regulator’s language may need additional mapping before an MDSAP audit. Our guide on ISO 13485 documentation requirements covers how to structure it correctly the first time.


MDSAP vs ISO 13485 readiness infographic showing CAPA traceability, document control, regulatory mapping, internal audits, and audit evidence
MDSAP vs ISO 13485: MDSAP readiness depends on connected evidence across CAPA, document control, regulatory mapping, internal audits, and market scope.

MDSAP Readiness Checklist

✅ QMS is currently certified — or verified compliant — to ISO 13485:2016
✅ CAPA records cross-reference nonconformance reports within the QMS itself, not a separate tracking tool
✅ Document control system is organized by ISO 13485 clause structure, not by individual regulator language
✅ You’ve confirmed which of the five MDSAP countries you actually sell into or plan to
✅ You’ve reviewed your documentation against the revised MDSAP Audit Approach (AU P0002.010)
✅ You’ve scoped audit cost and timeline with an MDSAP-recognized Auditing Organization
✅ Internal audit process already traces process interactions, not just individual clause compliance — see how to audit a medical device QMS


Frequently Asked Questions

Is MDSAP the same thing as ISO 13485?

No. ISO 13485:2016 is the quality management system standard. MDSAP is a regulatory audit program that assesses conformance to that standard, plus country-specific requirements from five participating Regulatory Authorities, in a single consolidated audit.

Do I need to be ISO 13485 certified before I can apply for MDSAP?

Your QMS needs to conform to ISO 13485:2016 — MDSAP auditors assess that conformance directly as part of the MDSAP audit itself. In practice, most manufacturers already hold or are pursuing ISO 13485 certification before entering the MDSAP process.

Which countries does MDSAP cover?

Five participating Regulatory Authorities: Australia (TGA), Brazil (ANVISA), Canada (Health Canada), Japan (MHLW/PMDA), and the United States (FDA). A number of other regulators participate as observers or affiliate members without full recognition of MDSAP audit results.

Is MDSAP required to sell medical devices in the United States?

No. The FDA accepts MDSAP audit results as part of its compliance program, and the 2026 QMSR incorporates ISO 13485:2016 by reference, but MDSAP participation itself remains voluntary for US-only manufacturers.

How did the FDA’s 2026 QMSR change affect MDSAP?

The QMSR, effective February 2, 2026, replaced 21 CFR Part 820 and incorporated ISO 13485:2016 by reference — narrowing the gap between US regulatory expectations and the ISO 13485 baseline that MDSAP already audits against. It doesn’t grant automatic MDSAP compliance; it changes what the US regulatory floor requires your documentation to look like.

How much does an MDSAP audit cost compared to a standard ISO 13485 audit?

MDSAP audits generally run longer and cost more per audit than a single-standard ISO 13485 surveillance audit, since the scope covers multiple regulatory frameworks in one visit. Pricing varies significantly by Auditing Organization, facility count, and audit scope — get a quote scoped to your specific situation rather than relying on a general figure.

Can a small manufacturer participate in MDSAP?

Yes. Any manufacturer with a product that falls under the scope of at least one participating Regulatory Authority may apply. It tends to make the most financial sense for manufacturers selling into several of the five MDSAP countries, where consolidating audits can produce clearer savings — though the exact threshold depends on your specific cost structure.

Does an MDSAP certificate replace my ISO 13485 certificate?

Not automatically, and it depends on the market. In Canada, the MDSAP certificate has replaced the standalone ISO 13485 certificate in the device license application process for Class II–IV devices. In most other participating markets, manufacturers typically maintain both, since ISO 13485 certification is often required independently by customers or notified bodies.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements before pursuing MDSAP or standalone certification.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification.

Not Sure What to Do Next?

🔹 Still researching whether MDSAP applies to you? Start with the ISO 13485 Gap Assessment Checklist — confirm your QMS conforms to ISO 13485:2016 before you evaluate adding MDSAP scope on top of it.

🔹 Ready to close documentation gaps before your next audit? 9001Simplified’s documentation kits are built for manufacturers structuring a QMS to hold up under more than one regulatory framework at once.

🔹 Need to buy the ISO 13485:2016 standard itself? Get it directly from ANSI Webstore — code CC2026 takes 5% off through December 31, 2026.

🔹 Want your team trained on the requirements before your MDSAP audit? BSI Group’s ISO 13485 training builds the foundation MDSAP auditors score against.

MDSAP isn’t a bigger version of ISO 13485 certification — it’s a different question entirely: not “is your QMS compliant,” but “how many regulators can rely on the same answer.” Get that distinction right before you scope an audit program you may not need, or miss one you do. The Standards Navigator will keep tracking how MDSAP and the 2026 QMSR shift continue to interact as more guidance comes out.


Stay Ahead of the Next Regulatory Shift

Manufacturers who treat MDSAP as “extra paperwork” usually find out the hard way — mid-application, with a Canadian import deadline already on the calendar. Manufacturers who map their audit scope to their actual markets first spend less on audits and never scramble for a certificate they didn’t know they’d need.

The Standards Navigator tracks how ISO 13485, MDSAP, and FDA’s QMSR continue to shift against each other so you don’t have to monitor five regulators’ guidance pages yourself.

👉 Get updates on medical device compliance and regulatory changes as they happen
👉 Be first to access new gap assessment tools and documentation resources as we build them

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

BSI AS9100 Training Review: Is It Worth It for Small Manufacturers in 2026?

AS9100 doesn’t require a specific training course — it requires competent auditors. This review breaks down what BSI’s AS9100 training actually covers, its pros and cons against other providers, realistic cost ranges, and a five-scenario framework for deciding whether formal training is the most efficient path for your shop.

AS9100 doesn’t require you to buy a training course — it requires competent people. Here’s how to figure out the most efficient path to get there

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


AS9100 Doesn’t Require a Training Course. It Requires Competent People.

Nearly every training provider will tell you their course is essential. Here’s what the standard itself actually requires: it doesn’t name BSI, ISOQAR, or anyone else. It requires that your internal auditors be competent — genuinely capable of planning, conducting, and reporting an effective audit against AS9100.

That leaves you with a real question, not a marketing one: is formal BSI AS9100 training the most efficient way for your shop to establish that competence, or is there a faster, cheaper path that gets you there just as well?

This isn’t a promotional writeup for BSI’s course catalog. It’s a decision framework for figuring out which path fits where your shop actually stands — and what that path costs.

From the Floor: I’ve sat in on the decision more than once — which employees get sent to formal standards training and which get handed the standard and told to figure it out. The pattern I’ve seen holds regardless of which standard is involved: the people who come back and actually change how audits get run aren’t the ones who sat through the most polished course. They’re the ones who used the class time to work through their own facility’s real nonconformances instead of generic case studies. That’s the filter I’d apply before signing off on any training spend — including this one.

If you haven’t run a gap assessment against AS9100 Rev D yet, that’s the decision that should come before a training decision — not after. Operations managers who evaluate training before understanding their QMS gaps may be solving the wrong problem first.

👉 Before you spend a dime on training, find out exactly where your QMS stands. Run the AS9100 Rev D Gap Assessment Checklist — a 74-item, 12-section clause-by-clause tool that shows you precisely which sections need work before you decide who needs training and in what format.

In This Guide:

  • What BSI’s AS9100 training actually covers, course by course
  • The honest pros and cons of BSI’s training — and how it compares to other providers
  • What it costs — and how BSI’s pricing model actually works
  • A decision framework: which competence-building path fits your shop
  • A cost comparison: formal training vs. experience-based routes vs. skipping it
  • What training actually establishes, and where it doesn’t help
  • FAQ: certificates, recertification, and whether training is technically required


👉 Start Here: Where to Look Into AS9100 Training

If your shop is evaluating formal AS9100 training, BSI Group is one of the established providers worth comparing against — its AS9100 training portfolio covers requirements training, internal auditor training, and lead auditor training. Review BSI’s AS9100 training course options.

If you haven’t bought a current copy of the standard yet, check whether the current course fee includes a copy of the applicable standard. If it doesn’t, budget separately for your copy before class starts. Purchase the current AS9100/SAE standard through ANSI Webstore.


What BSI’s AS9100 Training Actually Covers

BSI’s AS9100 training isn’t a single course — it’s a track, and small manufacturers tend to only need the first one or two levels of it.

The entry-level course covers the AS9100 Rev D requirements themselves: what each clause demands, how the aerospace-specific additions build on the ISO 9001 foundation, and how the standard maps to your existing documentation. This is the right starting point if your team understands ISO 9001 already but has never worked with the aerospace-specific clauses — configuration management, first article inspection, counterfeit parts controls, and the rest.

The internal auditor course goes a step further. It’s built around conducting audits against AS9100 and AS9101, and it typically runs as a multi-day, instructor-led format — in person or live online — with practical audit exercises rather than lecture alone. This is the course that matters most if you’re planning to run your own internal audit program instead of outsourcing every internal audit to a consultant.

Beyond that sits lead auditor training, which is usually more than a small shop needs unless someone is being developed to lead aerospace audits or pursue auditing professionally.

If you are new to AS9100 and still building your quality management system → start with the requirements-level course, not internal auditor training. You can’t audit effectively against clauses your team doesn’t understand yet.

BSI AS9100 training path showing requirements, internal auditor, and lead auditor training levels
BSI AS9100 training offers different levels of learning, from understanding AS9100 requirements to developing internal and lead auditor skills.

Pros and Cons of BSI AS9100 Training

What BSI Does Well

  • Established global training and certification organization with a broad aerospace training portfolio
  • Full AS9100 course catalog spanning requirements, internal auditor, and lead auditor levels
  • Both live online and in-person delivery formats available
  • Course completion certificates from an established training provider
  • In-house delivery available for training multiple employees at once

Potential Drawbacks

  • Pricing isn’t published upfront for most course types — expect to go through a quote request
  • May run higher than some smaller or regional training providers, depending on format and group size
  • Course value depends heavily on where your team already stands — a requirements-level course won’t add much for an already-experienced auditor, and an internal auditor course won’t help a team with no prior standard familiarity
  • Small shops adding AS9100 to an existing ISO 9001 program may only need the requirements-level course, not BSI’s full auditor track

How BSI Compares to Other AS9100 Training Providers

BSI isn’t the only organization offering AS9100 training. Smaller, regional, and boutique training providers also run AS9100 requirements and internal auditor courses, and sometimes at a lower per-seat cost than a multi-national provider like BSI. A provider with an established aerospace training portfolio may offer a familiarity advantage, but don’t assume the provider’s name substitutes for demonstrated auditor competence.

If you’re comparing multiple providers, weigh course content and instructor experience against price alone. An aerospace-specific internal auditor course taught by an instructor with real AS9100 audit experience is worth more than a generic quality-auditing course relabeled for aerospace. Ask any provider — BSI included — how their course specifically addresses the AS9100-unique clauses (configuration management, counterfeit parts, first article inspection) rather than treating AS9100 as ISO 9001 with an extra chapter.


What It Costs — and How BSI’s Pricing Model Works

This is the part that frustrates small manufacturers the most: BSI’s course pages typically direct buyers toward public-course enrollment for individual seats and a separate quote process for private or in-house training, so pricing can vary by course, delivery format, and group size rather than sitting on a single published price list.

That’s not unusual for the industry, and it also means published cost figures age fast. A rough, non-exhaustive comparison across a few established AS9100 training providers suggests 2-day internal auditor courses can run anywhere from roughly $1,000 to $1,600+ per seat depending on provider, country, and delivery format — treat this as an illustrative snapshot rather than a sourced market rate, and confirm current pricing directly with the provider before budgeting.

A practical consideration: shops training more than one or two people are generally better served requesting an in-house quote for the whole quality team rather than booking individual seats one at a time — it’s worth comparing against per-seat pricing, and it often means the session gets built around your actual facility’s documentation instead of a generic case study.

Two things push the real cost higher than the course fee alone:

  • Check whether the standard itself is included. Course fees don’t always cover it — if it isn’t, budget separately for your copy.
  • Travel and time away from the floor add up fast for in-person formats — live online delivery can be a practical choice for smaller shops trying to control the total cost.

If your facility hasn’t priced out the full certification path yet — training, gap assessment, documentation, audit fees — that’s worth doing before training in isolation. See the full breakdown of what AS9100 certification actually costs.


Formal Training vs. Alternatives: A Straight Comparison

ApproachWhat You GetBest ForTypical Cost Range
BSI formal training (requirements or internal auditor course)Structured instruction, practical audit exercises, recognized course certificateShops building an internal audit program from scratch or preparing for first-time AS9100 certificationVaries by provider, format, country, and group size — confirm current pricing directly before budgeting
Experience-based route (auditor learns on the job, under an existing certified internal auditor)Practical familiarity, no course feeShops that already have at least one AS9100-experienced auditor on staff to mentor othersTime cost only — no direct training fee
Documentation kit + self-study (no formal course)Templates and structure, but does not by itself establish internal-auditor competenceShops still in the early documentation-build phase, not yet auditingCost of the documentation kit only

If you are preparing for your first AS9100 certification and have no one on staff with prior aerospace QMS audit experience → formal training is one of the strongest ways to build and demonstrate the required auditor competence. Self-study can contribute to that competence, but you’ll need a defensible way to show your internal auditor is capable of planning and conducting effective audits.

If you are already ISO 9001 certified and simply adding the AS9100-specific clauses → your existing internal auditors may only need requirements-level training rather than repeating a full internal auditor course.


The Real Question: What’s the Most Efficient Path to Auditor Competence?

Not every shop needs the same answer. Where you land depends on what competence you already have on staff — not on whether training is generically “a good idea.”

No aerospace experience and no internal audit experience on staff → Formal training is highly valuable here. This is the shop with the least existing competence to draw on, and a structured course is one of the more direct and defensible ways to build it.

Strong QMS experience and already-trained internal auditors, but new to aerospace → Requirements-level training is often the better starting point, not a full internal auditor course. Your team already knows how to audit — they need the aerospace-specific clause knowledge, not a repeat of general auditing fundamentals.

An experienced aerospace auditor already on staff → You may not need to send everyone through the same course. That person can mentor others through the aerospace-specific requirements, and only newer team members may need formal training.

Multiple employees need the same training → Compare public-seat pricing against in-house delivery before booking. In-house sessions built around your own facility’s documentation are often the more efficient option once you’re training more than one or two people.

No mature QMS yet → A gap assessment and requirements-level understanding should come before loading anyone into auditor training. Sending a team through internal auditor training before the documentation exists may mean teaching them to audit against requirements you haven’t fully built out yet.

⚠️ Common mistake: sending a single employee to lead auditor training as a first step, before the shop has even completed its documentation. That course assumes working familiarity with the standard already in place — it’s the wrong entry point for a shop still building its QMS.


The ROI Question: What Training Actually Establishes

BSI AS9100 training and auditor competence comparison showing training knowledge, audit methods, experience, and demonstrated ability
BSI AS9100 training can help build auditor competence, but completing a course does not replace demonstrated auditing ability.

Training helps establish auditor competence — it doesn’t replace the underlying requirement to actually demonstrate that competence. That distinction matters more than the sales pitch usually lets on: an internal auditor doesn’t need a specific course, they need to be genuinely capable of planning and conducting an effective audit, however they got there.

Where training earns its cost is in areas like configuration management, counterfeit parts controls, and first article inspection — areas where generic ISO 9001 knowledge may not transfer cleanly to aerospace-specific requirements. An internal auditor who’s never been walked through these clauses in a structured setting is more likely to miss a gap during their own internal audit, which means the external auditor finds it first.

That said, training doesn’t fix a documentation problem. If your procedures don’t exist yet, sending someone to auditor training won’t create them — it just teaches someone how to audit against requirements you haven’t built out. For many first-time shops, the practical sequence is gap assessment, initial QMS documentation development, targeted training, then internal audits. Requirements-level training can make sense earlier; internal auditor training becomes more valuable once there’s an actual system to audit.

👉 Not sure if your documentation is even ready for an internal auditor to work against? Run the AS9100 Rev D Gap Assessment Checklist first — it takes less than an hour and tells you exactly which of the 12 major sections still need work.


✅ Quick Checklist: Is Your Shop Ready to Book Training?

  • ✅ Your AS9100-specific documentation is drafted, even if not finalized
  • ✅ You’ve identified who will actually conduct internal audits going forward
  • ✅ You know whether you need requirements-level training, internal auditor training, or both
  • ✅ You’ve priced in-house/group rates against individual seat pricing for your team size
  • ✅ You’ve budgeted separately for the standard itself, since course fees typically don’t include it
  • ⚠️ If you can’t check the first two boxes, reconsider booking internal auditor training yet — the timing may be premature
BSI AS9100 training roadmap showing gap assessment, QMS development, targeted training, internal audit, and certification readiness
A practical AS9100 training sequence connects QMS development, targeted training, internal auditing, and certification readiness.

FAQ

Is AS9100 training legally required for certification?

No. AS9100 does not prescribe a specific training provider or course for internal auditors. The organization is responsible for ensuring its auditors are competent to perform effective audits, and IAQG does not specify a particular 9100-series training course as mandatory. Formal training is one common way small shops establish and document that competence, but it isn’t the only path if you already have qualified aerospace audit experience in-house.

How long does BSI’s AS9100 internal auditor course take?

Multi-day formats are standard across the industry for this course level, typically delivered across two to three consecutive days, whether in person or through live online instruction. Confirm current course length and format directly with BSI, since schedules and formats are updated periodically.

Does the training include a copy of the AS9100 standard?

Course inclusions vary by provider and delivery format. Confirm directly with BSI whether the applicable standard is included before enrolling — if not, budget separately for a current copy.

Can one person get trained and cover the whole shop’s internal audit needs?

For a very small operation, one competent internal auditor may be enough, provided the audit program can maintain appropriate objectivity and coverage — auditors generally shouldn’t audit their own work or processes they’re directly responsible for. Larger shops or those with multiple product lines often train two or more people so audits aren’t bottlenecked by one person’s schedule or independence limits.

Is virtual training as effective as in-person for AS9100?

For the requirements-level course, virtual formats work well. For internal auditor training, in-person formats offer more natural opportunities for hands-on practice exercises, though live online formats with interactive workshops are a reasonable substitute if travel cost or time away from the floor is the deciding factor.

Does BSI training count toward recertification of an existing auditor?

Course-to-course requirements vary by prior certification and course provider. If your auditor already holds a credential from a different accredited provider, confirm directly with BSI whether their program requires a re-sit or a full course before enrolling.

What’s the difference between BSI’s requirements course and internal auditor course?

The requirements course teaches what the standard demands, clause by clause. The internal auditor course teaches how to plan, conduct, and report an audit against those requirements — it assumes the requirements-level knowledge already exists.

Is ISOQAR an alternative for AS9100 training?

No — as of publication, ISOQAR does not offer AS9100-specific training courses. For AS9100 training specifically, BSI is the option covered in this review; confirm current course catalogs directly with any provider before enrolling, since offerings can change over time.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching whether formal training makes sense for your shop? Start with the AS9100 Rev D Gap Assessment Checklist to see exactly where your QMS stands before you commit a training budget.

🔹 Ready to move forward with a specific course? Compare BSI’s current AS9100 training course options and request an in-house quote if you’re training more than one person.

🔹 Need the standard itself before class starts? Buy the current AS9100/SAE standard through ANSI Webstore.

🔹 Still deciding on a certification body altogether? See how the major players stack up in AS9100 Certification Bodies — Ranked & Reviewed.

Training is one line item in a much bigger certification budget, and it’s only worth spending on once the rest of your QMS groundwork is in place. Get the sequence right, and training becomes the thing that keeps an auditor from finding a gap your own team should have caught first. At The Standards Navigator, that’s the entire point — clear, practitioner-level guidance on what actually moves the needle toward certification, without the sales pitch.


Stay Ahead of Aerospace Audit Requirements

A common Stage 1 problem isn’t simply misunderstanding AS9100 — it’s discovering that training, documentation, or internal audit readiness isn’t as mature as the organization assumed.

Shops that treat certification as a sequence — documentation, then training, then internal audits — walk into Stage 1 with far fewer surprises than shops that bolt on training as an afterthought once a customer starts asking questions.

The Standards Navigator covers AS9100 certification, training decisions, and aerospace supplier compliance in plain, practitioner-level language — no fluff, no sales pitch.

👉 Get updates on AS9100 certification and aerospace supplier compliance
👉 Be first to access new gap assessment tools and aerospace QMS resources

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

AS9100 Documentation Requirements: What Auditors Actually Check (2026)

This guide breaks down what AS9100 Rev D actually requires in documented information — from first article inspection and traceability records to counterfeit parts prevention and configuration management. It explains which records auditors pull first, where most aerospace suppliers fall short, and how AS9100 documentation differs from a standard ISO 9001 system.

A clause-by-clause breakdown of what your aerospace QMS documentation needs — and where most suppliers fall short

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Documentation Gap That Fails Aerospace Audits

AS9100 documentation requirements cover the documented information needed to operate and demonstrate an aerospace QMS, along with aerospace-specific records and controls in areas such as configuration management, traceability, counterfeit parts prevention, first article inspection, and FOD control. The exact documents and records an organization maintains depend on its processes, applicable requirements, and customer flow-downs.

AS9100 documentation isn’t ISO 9001 paperwork with an aerospace label stuck on it. Traceability records, first article inspection (FAI) data, and configuration management records aren’t background paperwork — auditors use them as objective evidence that aerospace parts were manufactured and controlled according to applicable requirements.

Most suppliers assume a quality manual and a stack of procedures covers it. Then an auditor selects a part number, asks for the traceability record behind its FAI, and finds the two don’t connect — what looked like a minor gap becomes a major nonconformance.

Whether you’re mapping documentation before your first Stage 1 audit or checking an existing system against Rev D, this breaks down exactly what auditors pull first — and where the gaps usually are.

FROM THE SHOP FLOOR: I’ve sat across the table from an AS9100 auditor who skipped the quality manual entirely and went straight for first article inspection records on a part we’d shipped eight months earlier. We had the FAI — what we didn’t have was the linked traceability record showing which material heat lot went into it. That gap alone became a major finding. Auditors aren’t grading your paperwork; they’re testing whether your records actually trace back to the part in front of them.

👉 Most AS9100 documentation gaps don’t surface until an auditor asks for a specific record — by then it’s too late to fix quietly. Run the AS9100 Rev D Gap Assessment Checklist before your next audit and find out exactly where your documentation stands.

In this guide:

  • What AS9100 documented information actually requires — and where it goes beyond ISO 9001
  • Whether you still need a quality manual under Rev D
  • The core records auditors pull first: FAI, traceability, counterfeit parts, FOD
  • Two documentation areas most suppliers underbuild
  • Common findings and how to close them before your audit
  • Where to buy the standard and find training if you’re building this from scratch


👉 Start Here


What “Documented Information” Actually Means Under AS9100

AS9100 Rev D uses the same “documented information” language as ISO 9001 — but the aerospace-specific clauses layer on requirements that don’t exist in a standard ISO 9001 system at all.

AS9100 Rev D does not explicitly require a document called a quality manual. The practical takeaway is that eliminating a document called a “quality manual” does not eliminate the need to document and communicate how your QMS is structured.

Many aerospace organizations continue to use a quality manual because it provides a practical way to describe the QMS and its relationship to the applicable requirements — and it’s the document reviewers commonly use to navigate everything else.

Where AS9100 genuinely goes further than ISO 9001 is in the aerospace-specific documented information requirements: first article inspection, more extensive material and process traceability, counterfeit parts prevention, foreign object debris (FOD) control, and configuration management. None of these have a real equivalent in a baseline ISO 9001 system — see What Is AS9100? for the full standard overview if you’re still mapping out scope.

If you’re building this documentation structure from scratch rather than adapting an existing ISO 9001 system, the ISO Documentation Kits for Manufacturers page is a reasonable starting point for the underlying procedures and forms — just plan to adapt anything generic to AS9100’s aerospace-specific requirements before relying on it for certification.


AS9100 documentation requirements showing an aerospace auditor reviewing FAI, traceability, counterfeit parts prevention, FOD control, and process records
AS9100 documentation requirements include objective evidence showing that aerospace parts and processes were controlled as required.

The Core Records Auditors Pull First

First Article Inspection Records

A common audit approach is to select a specific part number and request the FAI record supporting it, along with the traceability behind it. FAI reporting itself is governed by AS9102, published by SAE International. Full requirements — including what counts as a valid FAI and when a re-FAI is triggered — are covered in First Article Inspection Requirements.

Traceability Records

Traceability records should allow applicable material, batch/lot, and process information to be traced through the product lifecycle to the shipped part, based on the organization’s processes and applicable requirements — not just exist as separate records. See AS9100 Traceability Requirements for what Clause 8.5.2 actually demands.

Counterfeit Parts Prevention Records

Documented controls for counterfeit parts prevention are required under Clause 8.1.4 — and auditors check whether they’re actually followed, not just written. Full breakdown in AS9100 Counterfeit Parts Standards.

FOD Control Records

AS9100 expects documented controls and evidence appropriate to the organization’s processes for preventing foreign object debris — the specific form that takes varies by operation. See FOD Control Standards for what Clause 8.5.4 requires.

A recurring pattern I’ve seen: these four record types exist independently but aren’t cross-referenced. An auditor pulls an FAI, asks for the traceability record behind it, and finds no clear link between the two documents — even though both technically exist. In practice, that kind of disconnect often draws more scrutiny than a missing document, because it suggests the system isn’t actually being used to trace parts, just to generate paperwork.

The Audit Trail: Part Number → Revision → Material Lot → Process Route → FAI → Final Record

An auditor doesn’t just want to see that each record in that chain exists individually. They want to see how the records relate to each other and to the specific part in front of them. (This makes a strong visual for the published page — worth building as a simple graphic rather than just text.)

👉 If your traceability records and FAI paperwork don’t reference each other by part number and revision, that’s a gap worth closing before an audit tests it. Download the Manufacturing Compliance Checklist and confirm your records connect.

AS9100 documentation requirements audit trail showing part number, drawing revision, material heat lot, process routing, FAI, and shipped product
AS9100 documentation requirements connect the part number, revision, material, process, inspection, and final shipment into a traceable audit trail.

Two Documentation Areas Most Suppliers Underbuild

Configuration Management Documentation (Clause 8.1.2)

Configuration management — tracking exactly which design revision, engineering change, and customer-approved deviation applies to a given part — gets far less attention than FAI or traceability, but auditors increasingly check it as a standalone item. If your documentation doesn’t clearly show which configuration was in effect at the time of manufacture, that’s a gap worth closing before it becomes a finding. This is dense enough to deserve its own dedicated breakdown — flagging it here as a topic to watch.

Risk-Based Documentation for Special Processes

Special processes — such as welding, heat treating, and nondestructive testing — carry their own documented risk requirements under AS9100’s risk-based thinking clauses. Nadcap accreditation may apply separately when required by a customer or applicable supply-chain requirements; that accreditation question is covered in NADCAP vs AS9100. The documentation angle specifically — how you document special-process risk decisions, distinct from whether you’re Nadcap-accredited — is underserved content-wise and worth a dedicated piece.


How AS9100 Documentation Differs from ISO 9001

CategoryISO 9001AS9100
Quality ManualNot explicitly mandatedNot explicitly mandated, but commonly used in practice
First Article InspectionNo aerospace-specific FAI requirementIncorporated through AS9100 and applicable customer requirements; AS9102 (SAE) governs FAI reporting
TraceabilityGeneral requirement, scope flexibleMore extensive material/process traceability, including customer- and product-specific requirements where applicable
Counterfeit Parts PreventionNo equivalent requirementDocumented controls required (Clause 8.1.4)
Configuration ManagementNo equivalent requirementRequired (Clause 8.1.2)
FOD ControlNo equivalent requirementDocumented controls and evidence appropriate to the organization’s processes and applicable requirements

For the full standard-by-standard comparison beyond documentation specifically, see AS9100 vs ISO 9001.

👉 Building this documentation structure without a consultant is realistic — but only if you’re working from the current edition. Buy the AS9100 Rev D standard through ANSI Webstore and use code CC2026 for 5% off.


What Happens When Documentation Doesn’t Hold Up

A documentation gap doesn’t automatically fail an audit — but an auditor who finds one disconnected record set often digs deeper, and what started as a single finding turns into a pattern of findings across the whole system. That’s the real cost: not the first gap, but what it triggers.

The cost objection: it’s fair to wonder whether this level of documentation rigor is overkill for a small shop with a handful of part numbers. When FAI and traceability requirements apply, a five-person shop and a five-hundred-person supplier may need to maintain the same core record types for a given part number; the difference is the complexity of the system used to manage them.

If you’re deciding whether your existing system is ready, AS9100 Internal Audit Process walks through running that check yourself before a registrar does it for you. And if you haven’t picked a certification body yet, AS9100 Certification Bodies — Ranked & Reviewed is a good next stop — worth confirming the body you choose is itself accredited by a recognized accreditor such as ANAB.

In practice, traceability is a significant part of aerospace QMS auditing because auditors need objective evidence that product and process records can be connected to the requirements they support.


Quick Documentation Checklist

✅ Quality manual (or equivalent scope document) references all applicable Rev D clauses

✅ FAI records exist and cross-reference traceability records by part number and revision

✅ Traceability records identify applicable material heat/lot/batch information for shipped parts, based on customer, product, and process requirements

✅ Documented controls for counterfeit parts prevention are in place and actively followed, not just written

✅ FOD controls are documented and supported by evidence appropriate to the organization’s processes and applicable requirements

✅ Configuration management records show which design revision applied at time of manufacture

✅ Special process records (welding, heat treat, NDT, etc.) are retained per customer and registrar requirements


AS9100 documentation requirements showing the difference between controlled documents and records used as objective audit evidence
AS9100 documentation requirements distinguish controlled information from records that provide objective evidence processes were performed.

FAQ

Is a quality manual required under AS9100 Rev D?

Not explicitly by the standard’s own wording — but many aerospace organizations continue to use one because it provides a practical way to describe the QMS and map it to the standard’s structure. Skipping it entirely can create more audit friction than it saves in paperwork, since certification bodies commonly expect some document that fills that role.

What documents does an AS9100 auditor ask for first?

A common audit approach is to select a specific part number and request the first article inspection record supporting it, followed by the traceability record behind that FAI. Auditors use this pairing to test whether your documentation system actually connects, not just exists.

What’s the difference between documented information and records under AS9100?

Documented information is the broader AS9100 term covering anything required to be created, maintained, and controlled — procedures, work instructions, and forms all count. Records are a specific type of documented information that provide evidence of results, like a completed FAI or a calibration record. Every record is documented information, but not everything documented is a record.

How long do AS9100 records need to be retained?

Retention periods vary by customer contract and registrar requirement rather than a single fixed AS9100 rule — many aerospace customers require retention well beyond typical ISO 9001 timeframes, sometimes for the life of the program. Check your specific customer flow-down requirements rather than assuming a default period applies.

Do I need separate documentation for each customer?

Not necessarily separate systems, but you likely need customer-specific supplemental requirements layered onto your core AS9100 documentation — most aerospace OEMs have their own flow-down requirements beyond the base standard.

What is a common AS9100 documentation finding?

One recurring documentation problem is records that exist individually but aren’t cross-referenced — an FAI with no linked traceability record, or a traceability record that doesn’t tie back to the part it supports. The documents technically exist; they just don’t function as a connected system.

Can I use the same documentation system for ISO 9001 and AS9100?

Largely yes for the shared core structure, but AS9100-specific records (FAI, counterfeit parts prevention, configuration management, FOD control) have no ISO 9001 equivalent and need to be built as additions, not substitutions.

Do I need software to manage AS9100 documentation, or can spreadsheets work?

Spreadsheets can work for a small shop with limited part numbers, but the risk grows with volume — the more parts and revisions you’re tracking, the easier it becomes for records to silently disconnect from each other, which is the exact failure pattern auditors catch most often.

How much documentation does a small aerospace supplier actually need?

The same core record types as a larger supplier — a small shop doesn’t get a reduced list of required records. What differs is the complexity of the system used to manage them; a simpler operation can often meet the same requirements with a leaner, more manual system than a high-volume supplier needs.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching what AS9100 documentation actually requires? Start with What Is AS9100? for the full standard overview.

🔹 Ready to build your documentation structure? Buy the current AS9100 Rev D standard through ANSI Webstore — you can’t build compliant documentation from an outdated edition.

🔹 Need training to get your team up to speed? BSI Group’s AS9100 training courses cover documentation requirements clause by clause.

🔹 Want a professional gap assessment first? Download the free AS9100 Rev D Gap Assessment Checklist.

Documentation is where AS9100 audits are actually won or lost — not in the quality manual, but in whether your records connect to the parts they’re supposed to trace. Get the structure right from the beginning, and maintaining audit-ready evidence becomes far easier. That’s the standard The Standards Navigator holds every AS9100 guide to.


Stay Ahead of Your Next AS9100 Audit

Most aerospace suppliers don’t fail audits because they lack documentation — they fail because their documentation doesn’t connect. FAI records that don’t reference traceability. Traceability that doesn’t tie to configuration. Individually complete, collectively disconnected.

Suppliers who struggle treat documentation as a checklist exercise, built once and left alone. Suppliers who succeed build cross-referencing into every record from day one, so nothing has to be reconstructed under audit pressure.

The Standards Navigator covers AS9100 implementation for aerospace suppliers building audit-ready quality systems from the ground up.

👉 Get updates on AS9100 and aerospace compliance

👉 Be first to access new gap assessment checklists and documentation templates

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

AS9100 Internal Audit Process: A Step-by-Step Guide for 2026

AS9100 Clause 9.2 requires more than an ISO 9001 internal audit program — customer and regulatory requirements have to be built into your audit criteria, and results have to reach management. This guide breaks down the six-part audit workflow, what a real internal audit checklist should cover, how findings feed into management review and AS9101 reporting, and the objectivity gap that trips up small aerospace quality teams.

How aerospace suppliers plan, conduct, and close out a Clause 9.2-compliant internal audit program

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your Internal Audit Program Is What Helps Keep Your AS9100 Certification Credible

An AS9100 certificate doesn’t prove your QMS is working. Your AS9100 internal audit process helps prove that it is.

Most operations managers treat internal audits as a compliance formality — something to schedule before the registrar shows up, not something that actually finds problems. That approach works right up until a surveillance audit surfaces a nonconformance your own internal audit should have caught six months earlier. At that point, the registrar isn’t just questioning the finding. They’re questioning whether your internal audit program is real.

If you’re already certified and running audits on autopilot, or preparing for your first AS9100 certification and building this process from scratch, the standard is specific about what “real” looks like. Clause 9.2 lays out exactly what your internal audit program has to prove, and AS9100 Rev D adds requirements ISO 9001 doesn’t have.

From the Floor: I’ve sat in gap assessment meetings where the documented internal audit schedule looked airtight on paper — every process, every quarter, neatly assigned. Then you pull the actual audit records and half of them are checklist walk-throughs with no objective evidence attached, no findings, no closure dates. An auditor doesn’t need long to spot the difference between an internal audit program that’s running and one that’s just being logged.

👉 Before you build or rebuild your internal audit program, run the AS9100 Rev D Gap Assessment Checklist — a 74-item, clause-by-clause tool that shows you exactly where your current audit coverage has gaps before an external auditor finds them for you.


In This Guide

  • What Clause 9.2 actually requires, and where AS9100 goes beyond ISO 9001
  • The six-step internal audit process defined in Clause 9.2.2
  • How internal audit findings feed into management review and AS9101 reporting
  • A ready-to-use internal audit checklist structure
  • Common mistakes that turn a real audit program into a paperwork exercise
  • Where to buy the standard and where to get trained on running compliant audits


👉 Start Here (Top Resources)

  • AS9100D — ANSI Webstore — the current edition of the standard, including the exact Clause 9.2 language your audit program has to satisfy. Use coupon code CC2026 for 5% off through December 31, 2026.
  • ISO 19011:2018 — ANSI Webstore — the audit guidelines standard referenced directly by AS9100 internal audit resources; worth owning if you’re training internal auditors.
  • AS9100 Training — BSI Group — for teams that need to formally qualify internal auditors on AS9100-specific requirements, not just general ISO 9001 audit technique.

What Clause 9.2 Actually Requires

Clause 9.2.1 requires you to conduct internal audits at planned intervals to determine whether your quality management system conforms to three things: your own organization’s requirements, the AS9100 standard itself, and the QMS is effectively implemented and maintained. That’s the ISO 9001 baseline.

AS9100 Rev D builds directly on that clause text. Under the standard’s Annex L structure, the aerospace-specific language is written straight into Clause 9.2.1 itself: your organization’s requirements for internal audit purposes must explicitly include customer requirements and applicable statutory and regulatory requirements — not just your internal procedures. That’s not guidance layered on top of ISO 9001; it’s part of the clause language you’re audited against. Audit results also have to be reported to relevant management, not just filed.

Most common finding: Internal audit programs that check ISO 9001 conformance thoroughly but never verify against a specific customer’s flow-down requirements or purchase order quality clauses. That’s a Clause 9.2 gap I commonly see when aerospace suppliers transition from ISO 9001 to AS9100.

ISO 9001 Baseline (Clause 9.2)Aerospace-Specific Clause 9.2 Language (Annex L Addition)
Conformance to the organization’s own QMS requirementsMust explicitly include customer, statutory, and regulatory requirements
Conformance to the standardAS9100 Rev D requirements, including its aerospace-specific additions
Effective implementation and maintenanceResults must be reported to relevant management, feeding directly into management review

If you are preparing for your first AS9100 certification → build your audit criteria around customer and regulatory requirements from day one, not as an afterthought once ISO 9001 conformance is handled.

👉 Need to see the exact Clause 9.2 language for yourself before you build your audit program around it? Get the current AS9100D edition from the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.


The AS9100 Internal Audit Process: A Six-Part Workflow Built From Clause 9.2.2

AS9100 audit program showing risk-based planning, audit frequency, previous findings, and an annual internal audit schedule in an aerospace manufacturing facility
A risk-based AS9100 audit program considers process importance, changes, previous findings, and risk when establishing the internal audit schedule.

Clause 9.2.2 lays out the requirements your audit program has to satisfy — the audit program itself, planning and conduct, auditor objectivity, reporting, corrective action, and retained documented information. Read together, that maps cleanly onto six practical steps, and an auditor will ask about all six.

1. Audit Program

Establish, implement, and maintain an audit program that identifies frequency, methods, responsibilities, planning requirements, and reporting. This has to account for the importance of the processes involved, changes affecting your organization, and the results of previous audits — not a static calendar you set once and never revisit.

2. Audit Criteria and Scope

Define what standard, procedure, or requirement each audit is measured against, and how far that audit reaches — which processes, which shifts, which locations if you run more than one facility.

3. Auditor Selection

Select auditors and conduct audits in a way that ensures objectivity and impartiality. Nobody audits their own work. On a small quality team this is often the hardest requirement to satisfy on paper — it usually means cross-training auditors across departments so a floor supervisor never audits the process they run.

4. Reporting Results

Audit results go to relevant management — not just the quality manager’s file. If a finding touches production scheduling, engineering, or purchasing, that function’s management needs visibility into it.

5. Corrective Action

Take appropriate correction and corrective action without undue delay when nonconformities are found. “Without undue delay” is intentionally vague in the standard, but in practice, your corrective action process should establish a documented target closure date appropriate to the severity of the finding — an open-ended promise to “look into it” won’t hold up as objective evidence of an effective process.

6. Retained Documentation

Keep documented information as evidence of the audit program’s implementation and the audit results. These are among the first records an external auditor is likely to examine: not your procedure, but your actual audit records — schedules, checklists, findings, objective evidence, and closure dates.

👉 If your audit records are more calendar than evidence, that’s the gap that surfaces during a surveillance audit — not a certification audit. Run the gap assessment checklist against your current program before your next registrar visit, not after.

AS9100 internal auditor reviewing work instructions, actual work, inspection records, and objective evidence on an aerospace manufacturing floor
An effective AS9100 internal audit follows the evidence from documented procedures to actual work, inspection records, and process effectiveness.

What Should an AS9100 Internal Audit Checklist Include?

A checklist built only around ISO 9001 clause conformance misses the aerospace-specific scope Clause 9.2.1 actually requires. Use this as the framework for what each internal audit needs to cover:

Audit AreaWhat the Auditor Should Verify
Process requirementsApplicable AS9100 clauses and internal procedure requirements
Customer requirementsPurchase order and contract flow-down requirements
Regulatory requirementsApplicable statutory and regulatory obligations
Objective evidenceActual records and direct observations, not verbal confirmation
Process effectivenessWhether the process is achieving its intended result, not just running
FindingsNonconformities clearly supported by objective evidence
Corrective actionRoot cause analysis, corrective action, and verification of effectiveness
Follow-upClosure evidence and confirmation the fix actually worked

If your operation also carries program-specific deliverables under AS9145 (APQP and PPAP), extend your audit criteria to those documents too — see AS9145 Explained for what’s typically in scope. And if any of your special processes are already covered under NADCAP, coordinate your internal audit scope so you’re not duplicating external oversight — NADCAP vs AS9100 breaks down where the two programs overlap and where they don’t.

AS9100 corrective action workflow showing audit finding, containment, root cause analysis, corrective action, effectiveness verification, and closure
An AS9100 corrective action is not complete until the organization verifies that the action worked and documents the results.

How Internal Audit Results Feed Into Management Review

Internal audit findings aren’t the end of the process — Clause 9.3 requires them as an input into management review. Corrective actions from internal audits, along with trending data like recurring nonconformities, similar issues across multiple processes, and top process concerns, should show up as agenda items top management actually discusses. That requirement comes from your QMS’s management review clause, not from any external audit form.

Separately, when your registrar conducts your certification or surveillance audit, results get documented on AS9101 — the standardized audit report form referenced by SAE International and logged in the IAQG OASIS database. AS9101 doesn’t dictate what your internal management review has to look like. But an external auditor completing that form will ask to see your management review minutes, and if internal audit trends never make it into those minutes, that gap is easy to spot — not because AS9101 requires a specific format, but because the disconnect itself signals the management review process isn’t functioning as intended.

If you are already ISO 9001 certified and adding AS9100 → your internal audit process likely doesn’t need to change structurally. What changes is audit criteria — you now have to audit against customer and regulatory requirements your ISO 9001 program never had to touch, and management review needs a direct line from audit findings to those aerospace-specific requirements.


Objection: “We Don’t Have Staff to Audit Objectively”

This is the most common pushback on small aerospace shops — a 15-person quality team can’t realistically avoid people auditing processes adjacent to their own work.

It’s a real constraint, but it’s manageable without adding headcount. Cross-train two or three people across departments so each can audit outside their own process. A machinist trained as an internal auditor can objectively audit the receiving inspection process; the receiving inspector can objectively audit machining documentation. Registrars don’t require a dedicated audit department — they require evidence that whoever conducted the audit had no stake in the outcome. Document that logic in your audit program procedure, and it holds up.


Quick Internal Audit Readiness Checklist

✅ Audit program covers all applicable processes at a frequency justified by risk and past findings

✅ Audit criteria explicitly reference customer purchase order requirements, not just internal procedures

✅ Auditors are demonstrably independent of the process they’re auditing

✅ Findings include objective evidence — not just a pass/fail checkbox

✅ Corrective actions have documented target closure dates

✅ Audit results appear as a distinct agenda item in management review minutes

⚠️ If any of these are missing, that’s the gap a registrar finds before you do


Frequently Asked Questions

What does Clause 9.2 of AS9100 actually require?

Clause 9.2 requires organizations to run internal audits at planned intervals to confirm the QMS conforms to the organization’s own requirements — which under AS9100 must include customer, statutory, and regulatory requirements — conforms to the AS9100 standard itself, and is effectively implemented. Results must be reported to relevant management.

How often do AS9100 internal audits need to happen?

The standard doesn’t set a fixed interval. Frequency has to be justified by the importance of the process, the results of previous audits, and any changes affecting the organization. Higher-risk processes — special processes, product safety-critical operations — typically warrant more frequent audits than lower-risk administrative processes.

Can one person run the entire internal audit program on a small team?

Generally, yes, as long as objectivity is maintained. The requirement is independence from the process being audited, not a minimum team size. On very small teams this can require creative scheduling or occasionally bringing in an outside auditor for processes where no internal person can honestly claim independence.

Do internal audit findings have to be reported to the registrar?

No. Internal audit results are reported to your own relevant management, not to the certification body. The registrar reviews your internal audit records and evidence of corrective action during surveillance and recertification audits — they don’t need real-time reporting.

What’s the difference between an internal audit and the AS9101 certification audit?

Your internal audit program is something you run yourselves, on your own schedule, against your own and the standard’s requirements. AS9101 is the standardized form your registrar uses to document the results of your external certification and surveillance audits, which then get logged in the IAQG OASIS database. A strong internal audit program is largely what prepares you to pass the AS9101-documented external audit cleanly.

Can internal audits be conducted remotely?

The standard doesn’t prohibit it, and many quality teams do conduct document reviews and some process audits remotely. Physical, in-person audits are still strongly preferred for shop floor processes where objective evidence — traveler stamps, calibration tags, first article records — needs to be directly observed rather than described.

What happens if our internal audit program has gaps when the registrar shows up?

It depends on severity and pattern, and classification is ultimately the auditor’s call based on the evidence in front of them. An isolated missed audit interval on a low-risk process may be treated differently from a persistent systemic failure, depending on the evidence and the auditor’s assessment. A pattern of audits with no objective evidence, no findings ever recorded, or no connection to management review calls into question whether the QMS’s self-monitoring is functioning at all — which is the kind of gap that tends to draw closer scrutiny.

Is a documented procedure enough, or do we need to prove the audits actually happened?

A procedure alone isn’t enough. Registrars expect to see the records: audit schedules, completed checklists with objective evidence, documented findings, and closure evidence for corrective actions. The procedure describes what you’re supposed to do — the records prove you did it.


📥 Free Resources

  • AS9100 Rev D Gap Assessment Checklist — 74-item, clause-by-clause checklist for aerospace suppliers assessing their QMS, including internal audit coverage, before certification.
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.

Not Sure What to Do Next?

🔹 Still researching what AS9100 internal audits require? Start with the What Is AS9100? pillar guide, then read AS9100 vs ISO 9001 to see exactly which requirements are new to you if you’re already ISO 9001 certified.

🔹 Ready to build or fix your internal audit program? Run the AS9100 Rev D Gap Assessment Checklist against your current audit records, then check the AS9100 Implementation Timeline to see where audit program maturity fits into your certification schedule.

🔹 Need to buy the standard or get auditors trained? Get the current edition from the ANSI Webstore with code CC2026 for 5% off, and see AS9100 Certification Bodies: Ranked & Reviewed for AS9100 auditor training through BSI Group.


A weak internal audit program is one of the most common reasons a QMS that looks compliant on paper fails to hold up in front of a registrar. Build the six-step process the standard actually asks for, put real objective evidence behind every audit, and your surveillance audits stop being a surprise. That’s what The Standards Navigator’s AS9100 coverage is built around — the requirements as they’re actually enforced, not just as they’re written.


Before You Go

Most aerospace suppliers don’t lose points on AS9100 audits because they misunderstand Clause 9.2 — they lose points because their internal audit program looks good on paper and falls apart under objective evidence review.

Shops that treat internal audits as a real management tool catch their own nonconformances before a registrar does. Shops that treat them as a scheduling formality find out the hard way, usually during a surveillance audit, that “completed” and “effective” aren’t the same thing.

The Standards Navigator covers the AS9100 requirements aerospace suppliers actually get audited against — not just the clause text, but how registrars interpret it in practice.

👉 Get updates on AS9100 implementation and internal audit best practices

👉 Be first to access new aerospace gap assessment tools and checklists

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.