Section 1.1: ISO 9000 Family, Fundamentals, and Vocabulary

Key Takeaways

  • The ISO 9000 family consists of multiple standards: ISO 9000 (vocabulary), ISO 9001 (requirements), and ISO 9004 (guidance for sustained success).
  • ISO 9001:2015 is the only certifiable standard in the family and represents the primary audit criteria for QMS certification.
  • Auditors must use ISO 9000:2015 terminology precisely, including the critical distinction between correction (symptom fix) and corrective action (root-cause prevention).
  • Audits are classified into first-party (internal), second-party (supplier), and third-party (independent certification) audits.
  • Third-party auditors must remain strictly independent and avoid consulting, meaning they identify nonconformities but do not design solutions.
Last updated: July 2026

ISO 9000 Family, Fundamentals, and Vocabulary

Quality Management Systems (QMS) built around the ISO 9000 family are governed by a suite of standards that define the language, requirements, and methods for auditing and certification. For a Lead Auditor, understanding the distinction between these standards is not merely academic; it determines what constitutes an audit criterion, how nonconformities are framed, and the legal and professional boundaries of the auditor's authority.

The ISO 9000 Family of Standards

The ISO 9000 family is not a single standard but a coherent set of documents. A Lead Auditor must navigate five core standards, each serving a unique function:

  1. ISO 9000:2015 (Quality management systems — Fundamentals and vocabulary): This standard establishes the starting point for all QMS standards. It defines the seven Quality Management Principles (QMPs) and contains the official vocabulary and definitions. Every term used in ISO 9001 is defined here. When writing an audit report, the auditor uses the terminology defined in ISO 9000 to ensure clarity and avoid ambiguity.
  2. ISO 9001:2015 (Quality management systems — Requirements): This is the only standard in the family containing requirements (indicated by the word 'shall') against which an organization can be certified. It is the primary audit criteria for third-party audits. If a practice does not violate a requirement in ISO 9001 (or the organization's own documented QMS), it cannot be cited as a nonconformity.
  3. ISO 9004:2018 (Quality management — Quality of an organization — Guidance to achieve sustained success): This document provides guidance for organizations seeking to go beyond the baseline requirements of ISO 9001. It focuses on long-term performance improvement and self-assessment. Because it contains only guidelines (indicated by the word 'should'), it cannot be used as audit criteria for certification audits. An auditor must never write a nonconformity against ISO 9004.
  4. ISO 19011:2018 (Guidelines for auditing management systems): This standard provides guidance on managing an audit programme, planning and conducting management system audits, and evaluating the competence of the audit team. It is the operational playbook for first-party (internal) and second-party (supplier) auditors.
  5. ISO/IEC 17021-1:2015 (Conformity assessment — Requirements for bodies providing audit and certification of management systems): This standard governs the rules and requirements for certification bodies (Registrars) that perform third-party audits. It sets the criteria for auditor independence, audit time allocation, and certification decision-making.

Key ISO 9000 Vocabulary for Auditors

An auditor must use ISO 9000 vocabulary with absolute precision. Confusing these terms in an audit report weakens the findings and can lead to disputes with the auditee.

  • Quality: The 'degree to which a set of inherent characteristics of an object fulfills requirements.' Crucially, quality is not a static measure of luxury or grade; it is a measure of fulfillment. A basic product that meets its specified requirements is a high-quality product in ISO terms, whereas a premium product that fails its specifications is of low quality.
  • Requirement: A 'need or expectation that is stated, generally implied or obligatory.' Stated requirements are written in procedures or contracts. Obligatory requirements include statutory and regulatory laws. 'Generally implied' requirements are those that are standard practice in the industry (e.g., a hotel room is expected to be clean, even if not explicitly stated in the booking contract).
  • Conformity vs. Nonconformity: Conformity is the 'fulfillment of a requirement,' while nonconformity is the 'non-fulfillment of a requirement.' Every nonconformity written by an auditor must be backed by objective evidence and traced back to a specific requirement.
  • Objective Evidence: 'Data supporting the existence or verity of something.' Objective evidence is obtained through observation, measurement, testing, or interviewing. It is verifiable and free from bias or opinion. An auditor's finding must always rest on objective evidence.
  • Audit Criteria: The 'set of requirements used as a reference against which objective evidence is compared.' Criteria can include ISO 9001, customer contracts, regulatory statutes, and the organization's own quality manual and procedures.
  • Audit Evidence: 'Records, statements of fact or other information which are relevant to the audit criteria and verifiable.'
  • Audit Findings: The 'results of the evaluation of the collected audit evidence against audit criteria.' Findings can indicate conformity, nonconformity, or opportunities for improvement (OFIs).
  • Process: A 'set of interrelated or interacting activities which transforms inputs into outputs.'
  • Procedure: A 'specified way to carry out an activity or a process.' Procedures can be documented (written) or undocumented (carried out consistently through training).

Correction vs. Corrective Action

One of the most heavily tested concepts in Lead Auditor exams is the distinction between correction and corrective action.

  • Correction: Action taken to eliminate a detected nonconformity. It is immediate containment or fixing of a symptom. Examples include reworking a defective part, scraping a bad batch of chemicals, or re-calibrating a tool that has drifted out of specification. Correction does not address why the issue happened.
  • Corrective Action: Action taken to eliminate the cause of a detected nonconformity and prevent recurrence. This requires investigating the root cause (using tools like the 5 Whys, Ishikawa fishbone diagrams, or fault tree analysis) and implementing systemic changes. For example, if a tool drifted out of specification, the corrective action might be changing the maintenance schedule from monthly to weekly, or installing automatic sensors to detect drift early.

An auditor must verify that the auditee has performed both: correction to fix the immediate problem, and corrective action to protect the system long-term.

Audit Classifications and the Auditor's Role

Audits are classified by the relationship between the auditor and the auditee:

  1. First-party audit: An internal audit. The organization audits its own processes (Clause 9.2). It helps the organization evaluate its own QMS and identify opportunities for improvement.
  2. Second-party audit: An external audit conducted by a customer (or on behalf of a customer) on a supplier. The customer has a direct commercial interest in the supplier's performance. These audits help qualify suppliers and monitor ongoing contract conformity.
  3. Third-party audit: An independent audit conducted by an accredited certification body (Registrar) or regulatory authority. These audits have no commercial interest in the auditee and are conducted to grant, maintain, or revoke ISO 9001 certification. They must conform to the strict requirements of ISO/IEC 17021-1.

The Auditor-Consultant Boundary

A fundamental principle of third-party auditing is the separation of auditing and consulting. Under ISO/IEC 17021-1, an auditor must remain independent. The auditor's role is to evaluate evidence against criteria and report findings. The auditor must never design or suggest solutions for the auditee, write procedures or policies for the organization, or recommend specific software, consultants, or systems to fix a nonconformity.

Suggesting how to fix a finding creates a conflict of interest, as the auditor would later be auditing their own work. The auditor states what the nonconformity is and which requirement was breached; the auditee determines how to solve it.

Test Your Knowledge

A calibration technician immediately re-calibrates an out-of-tolerance sensor found during an audit. In ISO 9000 vocabulary, which action has been performed?

A
B
C
D
Test Your Knowledge

Which of the following represents valid audit criteria for a third-party ISO 9001:2015 certification audit?

A
B
C
D
Test Your Knowledge

What is the correct role of a third-party auditor when documenting a nonconformity?

A
B
C
D