Start with evidence, not documents
Most organisations approach an ISO 9001 surveillance audit by rewriting procedures. Auditors, however, test whether the system described is the system used. The fastest route to a clean result is to gather the evidence your teams already produce and map it to the clauses it satisfies.
Build a simple evidence register: clause, owner, artefact, location, last review date. Gaps become visible immediately and remediation effort can be prioritised by risk rather than by document count.
- Map existing records to clauses before drafting anything new
- Assign a single accountable owner per clause
- Timebox remediation to the highest-risk gaps first
Run a proportionate internal audit
An internal audit should mirror the scope and sampling approach of the external audit, not exceed it. Interview the people doing the work, follow two or three real jobs end to end, and record nonconformities in the same format your certification body uses.
Close out with discipline
Corrective actions fail when they stop at the symptom. Require a root-cause statement, a containment action, a systemic action and a verification date for every finding. Review the register fortnightly until closure.