REAV

Preparing an ISO 9001 audit in a repair workshop

An ISO 9001 auditor is not checking whether your procedures are good. They are checking whether the system you described is the system you run.

Most operations prepare for an ISO 9001 audit by tidying documents, which is preparation for the wrong test. The auditor is sampling for evidence that a described system is the operating one: that decisions were recorded, that the people making them were competent to, that problems were handled rather than absorbed. In a repair workshop, where the work is variable and the devices are unique, that evidence has to come out of daily operations rather than out of a binder assembled the week before.

What the standard is actually asking

ISO 9001 does not describe how to repair anything. It sets out what a management system has to contain so that quality is produced deliberately: defined processes, documented information, competent people, measured results, and a loop that acts on what the measurements show.

The 2015 edition organises this into clauses 4 to 10 and structures them on the Plan-Do-Check-Act cycle - planning in clause 6, operation in 8, evaluation in 9, improvement in 10. It also replaced the old separate requirement for preventive action with risk-based thinking in clause 6.1.

One consequence is worth stating early: certification covers the management system, not the products. A client asking for ISO 9001 is asking whether your process is under control. A client asking for R2v3 or WEEELABEX is asking something narrower about how you handle equipment and data.

The clauses that bite in a repair operation

4.4 - processes and their interactions. In refurbishment, intake, triage, sanitisation, repair, grading and disposition are separate processes with real handovers. The auditor will ask where one ends and the next begins, and who owns the decision at each boundary.

7.2 - competence. Repair work ranges from part swaps to micro-soldering. The requirement is to determine what competence is needed, ensure people have it, act where they do not, and retain evidence. A skills matrix with levels and dates is the usual way to hold all four.

7.5 - documented information. The issue is rarely whether procedures exist. It is version control: whether the procedure a technician followed last March can be identified, and whether an obsolete version is still reachable on the floor.

8.5.2 - identification and traceability. This is where per-device records stop being a quality nicety. The auditor will pick a device and follow it.

8.7 - nonconforming outputs. A device that fails final test has to be identified, controlled so it cannot be shipped by accident, and its disposition recorded. The permitted dispositions are limited on purpose.

9.3 - management review. The clause lists its inputs explicitly, and the list is long. Assembling it is where operations struggle, not holding the meeting.

The five findings that recur

The register only contains polite problems. If reporting a non-conformity creates work for the person reporting it, the register fills with paperwork issues and empties of the real ones. An auditor who compares the register against what technicians say on the floor will notice within an hour.

Corrective actions closed without verification. Clause 10.2 asks for the cause to be addressed and the action to be reviewed for effectiveness. An action closed the day it was decided is a plan, not a corrective action.

Competence records that are not current. Evidence of training on a model or a technique three years ago is not evidence of current competence, particularly where the device mix has moved.

Procedures that describe an older workshop. Documentation ages faster than anything else in a repair operation, because the models change. The gap between the written procedure and the practised one is the single most common finding.

Indicators without a denominator. Reporting repairs completed without repairs attempted, or a repair yield whose scope changed mid-year, gives an auditor no basis to judge whether the system is effective - which is what clause 9 asks.

Preparing without theatre

The useful preparation is an internal audit conducted the way the external one will be. Pick devices at random, follow them, and record where the trail stops. What you find is the finding list, with the advantage that you found it.

Then check the boring things, because they are what gets sampled: that entries are dated, that approvals were given by someone other than the person who did the work, that the current version of each procedure is the one available at the bench, and that the last management review produced decisions rather than minutes.

What does not help is rewriting procedures the week before. A procedure that appeared five days before the audit and describes a practice nobody recognises is worse than an honest gap with a corrective action open against it.

Why this gets easier when the loop is in one place

Most of the difficulty is not the standard. It is that the evidence lives in four systems: indicators in the ERP, non-conformities in a shared file, procedures on a drive, competence in HR. Management review then gets assembled by hand once a year, which is also why it tends to describe a system nobody has examined in between.

When field feedback, the improvement register, the procedure it updates and the competence record sit in the same place, the audit stops being a retrieval exercise. The evidence is a by-product of the work rather than a project.

That is the honest argument for tooling here, and it is a narrow one: the tool does not make an operation compliant. It removes the reason the evidence is scattered.

GustAV holds the improvement register, the audit log, the competence matrix and the procedures in one place, so management review inputs come out of live data instead of being assembled once a year.

See how it works

Sources

← All articles