From audit to management review: the data chain nobody designs
Two weeks before the management review, somebody is sitting with four exports open: audit reports as PDFs, an action list out of the task tracker, complaint data from the ERP, supplier scores from a spreadsheet. Two days later there is a deck that nobody could reproduce in the same shape twice.
It is the same pattern as the fortnight before a certification audit, one level up: evidence being assembled that should have been accumulating all along. And it has the same cause — not carelessness, but a chain that breaks at a specific point.
The chain breaks at capture, not at analysis
Management review is generally treated as an analysis problem: too little time, too many sources, not enough tooling. That is the wrong diagnosis.
ISO 9001:2015 requires, in 9.3.2 c), information on the performance and effectiveness of the quality management system, including trends in customer satisfaction, the extent to which objectives have been met, process performance, nonconformities and corrective actions, monitoring and measurement results, audit results, and the performance of external providers [1].
Trends are comparisons over time. A comparison over time requires the same quantity to have been captured on the same basis across several periods. And that is not decided during analysis. It is decided in the moment somebody writes an observation down in an audit interview. The APG guidance notes explicitly that management review inputs can come in many forms — reports, trend charts and so on [4]. The presentation is free; the comparability underneath it is not.
Capture it as free text — “inspection characteristics not consistently agreed with supplier, see goods-in” — and you have a professionally sound finding and an unanalysable row. It can be counted, not grouped. Three years later the same issue appears in different words and nobody can demonstrate that it is the same issue.
Why the certification auditor notices
There is a practical reason to take this seriously that goes beyond compliance.
The APG guidance on internal audits — the APG being the joint working group of ISO/TC 176 and the International Accreditation Forum — calls it good practice in third-party audits to audit the organization’s internal audit processes towards the end of the audit. The reason is stated outright: the auditor can then compare the results of the internal audit process against their own findings, and thereby evaluate the effectiveness of that process and of the resulting corrective actions [2].
That is an uncomfortable construction when the internal backlog is thin. An internal audit programme that recorded no finding against a process for two years, where the external auditor finds two on the first day, becomes an object of the audit in its own right — however tidy the reports look.
One clarification from the same paper, because it is regularly misrepresented: among the things a third-party auditor considers is the guidance provided by ISO 19011 — coupled with the explicit note that ISO 9001 does not require the organization to use ISO 19011 [2]. It is an offer, not an obligation. What it does contribute is set out on the ISO 19011 standard page.
Five fields that have to exist at capture
Read clauses 9 and 10 together and exactly five items emerge that cannot be filled in later without losing their evidential value:
| Field | What it is needed for later |
|---|---|
| Requirement reference — the clause or document audited against | Without it there is no history per requirement, and no statement about which areas of the standard recur |
| Process reference — which process, not which department | 9.1.3 requires process performance to be evaluated; 9.2.2 requires the importance of the processes concerned as a planning factor |
| Severity on a fixed scale | Without a stable scale, any distribution over time is an artefact of grading practice rather than of the system |
| Effectiveness criterion — set when the action is decided | 10.2.1 requires the effectiveness of corrective action to be reviewed; without a criterion named up front it cannot be evidenced afterwards |
| Owner and due date on the finding itself | The basis for any statement about overdue items, and the only way to establish status without asking around |
Four of the five cost seconds at capture. The fifth — the effectiveness criterion — costs thought, which is why it gets pushed to the end, where it stops serving its purpose. Why that happens and how to phrase the criterion is covered at length in audit findings and the effectiveness record.
Whether the first field appears cleanly at all is largely settled by how the question catalogue is built. A catalogue that follows the process landscape and carries a requirement reference per question produces the link automatically; a catalogue written as prose never does. That difference is the subject of the audit question catalogue under ISO 19011.
The one analysis that says something about the system
A well-captured backlog will yield plenty of numbers. Most of them describe the quality function’s own workload: audits performed, findings recorded, share of actions closed on time. Why those measures are weak is covered in quality KPIs under clause 9.1.
One analysis stands apart, because it is the only one that describes the system rather than its caretakers: history per requirement, not per audit year.
The reason is procedural as well as substantive. ISO/IEC 17021-1:2015 — the standard for bodies certifying management systems — notes at clause 3.12 that several minor nonconformities against the same requirement can together demonstrate a systemic failure and therefore constitute a major nonconformity [5]. Carry the same point through three cycles as three individually harmless observations and you are not accumulating three small residual risks; you are assembling the justification for an escalation. Visible to the external auditor, invisible in your own annual statistics.
That analysis is trivial when the requirement reference is a field. It is impossible when it lives inside a sentence.
The return path almost nobody evidences
The chain does not end at the management review. It runs from there back into audit planning, and on this stretch the standard is unusually concrete.
ISO 9001:2015 requires in 9.2.2 that the organization plan, establish, implement and maintain an audit programme, including frequency, methods, responsibilities, planning requirements and reporting, taking into consideration exactly three factors: the importance of the processes concerned, changes affecting the organization, and the results of previous audits [1][2]. The third factor is the return path.
The APG guidance develops it. Applying risk-based thinking, it says, the requirement is intended to focus the internal audit programme on those processes and areas where past history indicates problems have occurred, or where problems are likely because of the nature of the processes themselves. Processes with higher levels of risk or nonconformities should have priority in the internal audit programme. And explicitly: the organization should have a process for utilizing past audit results in the planning of future internal audits [2].
That closes the loop — but only if the analysis from the previous section exists. Without a history per process and per requirement, risk-based programme planning is an assertion. How to build a defensible annual plan from it is set out in the audit programme planning guide.
The APG guidance on improvement describes the same return path from the other end: where top management has set a realistic objective for a process and there is no evidence of improvement, that information must be fed back into the management review so that top management can decide what action is appropriate — readjusting the objective, or providing other means to affect the process [3].
What ISO 9001:2026 breaks in this chain
ISO/TC 176/SC 2 announced on 7 August 2026 that ISO/FDIS 9001 had been approved and that the sixth edition is scheduled for publication on 16 September 2026 [6]. The announcement names no transition arrangement, and no competent body has published one to date.
For the data chain described here the revision has one very concrete consequence, and it lands on the most important of the five fields. The requirement reference is a clause number — and some of those numbers change, because on the published FDIS position clause 6.1 is being split into separate clauses for risks and for opportunities. Findings from past audits carry the old mapping, new audits test against the new structure, and both populations coexist for years.
Overwrite the question catalogue at that point and you retroactively destroy exactly the history this article is about. The approach — versioning rather than overwriting — is described in ISO 9001:2026 and the internal audit; the overview of the revision sits on the ISO 9001:2026 standard page.
If you are in a spreadsheet today
Assessment: for many organizations a spreadsheet is the realistic starting point, and changing the tool is not the first move worth making. Three changes work there too:
- Requirement reference as its own column, filled from a fixed list rather than typed freely. That is the difference between countable and groupable.
- Severity from a closed value list, three levels are enough. A scale interpreted differently each year manufactures trends that are not there.
- One row per finding across all years, not one worksheet per audit year. The latter is the most common structure and the one that systematically prevents analysis over time.
Where a spreadsheet’s limits actually lie, and at which requirement it breaks structurally, is covered with clause references in Excel or software in quality management.
What a tool has to do here
Stated as a requirement on tooling, this is unusually simple: make the five fields part of capture, and hold the requirement reference as structure rather than as text.
qportal models the standard as a hierarchical catalogue of audit criteria — clauses up to three levels deep, linked to question catalogues, findings and actions. Audit programme, finding, action and effectiveness review sit in one connected record with a status history, so history per requirement is a query rather than a reconstruction. The audit side is described on the audit management page, action tracking on the actions and CAPA page, and the full path of a finding in the findings lifecycle documentation.
Roadmap note: the evaluation layer above this — indicator definitions and preparation for the management review — is on the roadmap and is not shipped. The order follows the subject matter: the data behind a management review is created during audits and in the processes that follow. An analytics layer over an unstructured backlog produces better-looking charts and no defensible statements.
Conclusion
Management review rarely fails at the reviewing. It fails because the data it is supposed to draw on does not exist in a form that permits comparison over time.
That is settled years earlier, in an audit interview where somebody writes down an observation — with or without a requirement reference, with or without a process, with or without an effectiveness criterion agreed up front. Those fields cost very little. Reconstructing them later is the reason somebody sits with four exports before every review.
If you change one thing, change this: hold the requirement reference as a field with a fixed value list, not as a clause in the finding text. Every analysis capable of saying something about the system depends on that single decision.
Sources
- ISO 9001:2015, Quality management systems — Requirements. International Organization for Standardization, Geneva; consulted in the bilingual edition DIN EN ISO 9001:2015-11, Beuth Verlag, Berlin. (Clauses 6.1, 9.1.3, 9.2.2, 9.3.2, 10.2.1)
- ISO 9001 Auditing Practices Group: Guidance on: Internal Audits. Edition 1 Amd 1, 2020-07-19, issued by ISO/TC 176 together with the International Accreditation Forum. Reproduces ISO 9001:2015 clause 9.2.2 verbatim, and ISO 9004:2018 clause 10.5. https://committee.iso.org/home/tc176/iso-9001-auditing-practices-group.html (accessed 2026-09-03)
- ISO 9001 Auditing Practices Group: Guidance on: Improvement. Edition 1, 2016-01-13. (accessed 2026-09-03)
- ISO 9001 Auditing Practices Group: Guidance on: Policy, Objectives and Management Review. Edition 1, 2016-01-13. (accessed 2026-09-03)
- ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements. Edition 1, 2015-06, ISO/CASCO. Clause 3.12 and its note, freely readable in the ISO Online Browsing Platform. https://www.iso.org/obp/ui/en/#!iso:std:iso-iec:17021:-1:ed-1:v1:en (accessed 2026-09-03)
- ISO/TC 176/SC 2: ISO 9001 revision update. Announcement of 2026-08-07 on the approval of ISO/FDIS 9001 and the publication date of the sixth edition on 2026-09-16. https://committee.iso.org/sites/tc176sc2/home/news/content-left-area/news-and-updates/news-1.html (accessed 2026-09-03)
The APG papers carry an explicit disclaimer that they have not been subject to an endorsement process by ISO, ISO/TC 176 or IAF; they are expert interpretation, not requirements. The International Accreditation Forum ceased operations on 2026-01-01 and was folded together with ILAC into Global ACI; the papers remain available through ISO/TC 176.
Consultancy, certification-body and content-marketing pages are not cited. Normative text is copyrighted; requirements are paraphrased here with a clause reference. Where this text goes beyond the sourced evidence, it is marked as an assessment.
Frequently asked questions
- Which audit data must feed the management review?
- ISO 9001:2015 lists audit results, and nonconformities and corrective actions, explicitly among the inputs in 9.3.2 c) — and asks for them as trends, meaning over time. A snapshot of currently open actions does not satisfy that; what is needed is a basis of capture that stays comparable across several periods.
- Why can audit findings so rarely be analysed?
- Because the fields that make analysis possible were never captured. A free-text finding with no clause reference, no process reference and no fixed severity scale can be counted but not grouped. Trends require the same categories to stay stable across years, which is why capture determines analysis — not reporting.
- What is the most informative analysis of an audit backlog?
- History per requirement rather than per audit year. It shows which clauses recur across cycles. ISO/IEC 17021-1:2015 notes at clause 3.12 that several minor nonconformities against the same requirement can together demonstrate a systemic failure and therefore constitute a major nonconformity — an organization that does not run this analysis first sees the escalation in its certification audit.
- Do management review results feed back into audit planning?
- Yes, at a clause you can point to. ISO 9001:2015 names the results of previous audits in 9.2.2 as one of three factors to take into consideration when planning the audit programme. The ISO 9001 Auditing Practices Group adds that the organization should have a process for using past audit results in the planning of future internal audits.
- Will the certification auditor compare our internal audits with their own findings?
- Usually, yes. The APG guidance on internal audits calls it good practice in third-party audits to audit the internal audit process towards the end of the audit, so that the auditor can compare the results of that process against their own findings and judge its effectiveness. An internal backlog that is silent on what the external auditor finds on day one is itself a finding.