Tag

Corrective Action

ISO 42001 Statement of Applicability structure showing Annex A controls vs Annex B guidance
Audit Preparation Apr 28, 2026 6 min read
ISO 42001 Statement of Applicability and Impact Assessment: Two Errors That Survive Audit Preparation
Organisations building their first ISO/IEC 42001:2023 AI Management System are importing assumptions from ISO 27001 that do not transfer. Two structural errors reach Stage 2 audit preparation uncorrected:…
Read article →
ISO 22301 Clause 8.4 dependency chain from BIA through strategy to plan documentation
Audit Preparation Apr 23, 2026 6 min read
ISO 22301 Clause 8.4: Why Plan-Centric BCMS Implementations Fail Under Exercise Testing
ISO 22301 Clause 8.4 requires business continuity plans built on BIA outputs and selected strategies. Organisations that start with the plan bypass the Clause 8 dependency chain and produce documents that fail under exercise testing.
Read article →
ISO 45001 Clause 4.2 interested parties register traceability to objectives
Audit Preparation Apr 9, 2026 6 min read
ISO 45001 Clause 4.2: Why Your Interested Parties Register Isn’t What the Standard Requires
Most ISO 45001 Clause 4.2 registers list workers and generic needs but never feed into objectives. This article traces the structural dependency from Clause 4.2 through worker consultation under 5.4 to objective-setting under 6.2 — and shows how to close the gap before auditors do.
Read article →
ISO 9001 Clause 6.1 risk register traceability chain from risk identification to operational controls
Audit Preparation Apr 4, 2026 6 min read
Your Risk Register Doesn’t Satisfy ISO 9001 Clause 6.1 — Here’s What Does
Most ISO 9001 risk registers list risks without changing anything downstream. Clause 6.1 conformance requires traceable integration into process controls and quality objectives — a gap ISO DIS 9001:2025 will make structurally visible.
Read article →
Risk-based internal audit programme workflow showing frequency calibration against process risk data
Audit Preparation Apr 3, 2026 10 min read
Your Internal Audit Programme Isn’t Risk-Based — And ISO 9001’s Revision Will Prove It
Most ISO 9001 audit programmes run fixed-rotation schedules with no risk-based frequency rationale. ISO DIS 9001:2025 adds defined per-audit objectives — exposing the structural gap. Here's how to rebuild before transition.
Read article →
8D problem solving form showing root cause analysis fields for IATF 16949
Audit Preparation Mar 27, 2026 7 min read
IATF 16949 Clause 10.2.3: Why the #1 Nonconformity Keeps Coming Back
Clause 10.2.3 is the #1 IATF 16949 major nonconformity because root cause analyses stop at symptoms. Learn what audit-defensible submissions require — mechanism-level causes, objective evidence, systemic reviews, and updated pFMEAs.
Read article →