A certification audit needs relevant evidence about the management system and its implementation. Documents and records can be important, but there is no universal folder of forms that proves conformity for every organization and every standard.
The required information depends on the applicable requirements, scope and activities. Use the standard and the agreed audit arrangements to understand what is needed rather than buying a generic pack and assuming it fits.
Distinguish an instruction from a record
An instruction can describe how work should be carried out. A record can show what happened in a particular instance. Both need context. A procedure that nobody follows and a record that nobody can explain provide a poor account of the system.
For example, a completed review form is more useful when the organization can identify the subject reviewed, the criteria considered, the decision and any action that followed. The presence of a signature does not answer all of those questions.
Organize evidence around processes
Instead of grouping everything into an undifferentiated “ISO folder,” connect information with the activities it supports. A customer requirement may link to an order review, a delivery plan, records of work and feedback. A change may link to an approval, communication and evaluation of the result.
This approach helps people explain their own work and reduces the temptation to treat assessment as a paperwork exercise detached from operations.
Illustrative information categories
- Scope and organizational responsibilities.
- Relevant policies, objectives and process arrangements.
- Records demonstrating how operational activities are controlled.
- Competence and communication information where relevant.
- Internal evaluation and management-review information.
- Findings, corrective action and improvement evidence.
These categories are examples, not a statement that every organization must create a document with each title. Different standards add their own subject-specific requirements.
Use current and understandable records
Check that the information reflects the activities and period under review. If a process changed, explain the change and identify which version applied. Avoid presenting a newly created template as evidence that a process has been operating for months.
Where the evidence is digital, plan access and navigation. A screen full of filenames may be less useful than a clear explanation of how records are created, controlled and retrieved.
Protect confidential information
Discuss access arrangements before the audit when records contain customer secrets, personal information or other restricted material. Do not send credentials or sensitive files in an initial public enquiry. Appropriate controlled access can be planned without assuming that unrestricted copying is necessary.
What if evidence is missing?
Explain the position accurately. Recreating or backdating records to suggest that an activity happened when it did not is not a sound response. Understand the requirement and the actual gap, then address it through the relevant process.
Read Stage 1 vs Stage 2 and the certification process, or contact EQRM with your scope and preparation questions.
Select evidence by the question it answers
For each sample record, note the activity, date, responsible role and requirement or decision it helps explain. Keep links to related records where the work crosses teams. Avoid sending an uncontrolled collection of files before the access arrangements are agreed. Relevant, traceable samples are easier to assess than a large pack without an explanation of what each item demonstrates.
Quick answers
Is a completed template enough to demonstrate conformity?
Not by itself. Evidence should explain what happened in the actual process and how that relates to the applicable requirement.
Must every organization keep an identical evidence folder?
No. The relevant evidence depends on activities, scope and requirements. Agree access and confidentiality arrangements for the information actually needed.