Auditing a healthcare quality management system (QMS) is one of the more demanding assignments an ISO auditor takes on. The environment is complex, the terminology is unfamiliar, and the stakes feel high. Nurses, doctors, allied health professionals, and administrators all operate under layers of clinical governance, accreditation frameworks, and regulatory requirements that have nothing to do with ISO 9001. If you walk in without a clear strategy, you will either get drawn into clinical debates you are not qualified to have, or you will audit so superficially that you miss genuine system failures.
On this page
This article is for auditors who have been assigned to audit a healthcare organisation against ISO 9001 or ISO 13485, and for internal auditors working inside hospitals, clinics, aged care providers, and community health services. The goal is to help you audit the management system effectively without pretending to be a clinical expert.
Understand the Boundary Before You Walk In
The single most important thing to get right before auditing a healthcare QMS is understanding where your audit scope begins and ends. ISO 9001 audits the quality management system. It does not audit clinical practice, clinical outcomes, or medical decision making. Those areas belong to the Australian Commission on Safety and Quality in Health Care, AHPRA, the Aged Care Quality and Safety Commission, or the relevant clinical governance body.
Your job is to audit whether the organisation has a functioning system that:
- Identifies its processes and manages them consistently
- Sets quality objectives and monitors whether they are being achieved
- Manages risks and opportunities in a structured way
- Controls externally provided services and products
- Responds to nonconformities and drives improvement
- Engages top management in the performance of the system
When a nurse tells you that a particular wound dressing protocol is clinically superior, that is not your territory. When the same nurse tells you that staff have not been trained on the updated protocol and no records exist to confirm competence, that is very much your territory.
Draw that line clearly in your opening meeting and hold it throughout the audit. It protects you, it protects the auditee, and it keeps the audit focused on what the standard actually requires.
Exemplar Global Recognised Training ProviderRTP No. 310970Know Enough About the Sector to Ask Sensible Questions
You do not need clinical qualifications to audit a healthcare QMS. You do need enough sector awareness to understand the key processes, the language used, and the regulatory environment the organisation operates in. Without that baseline, your questions will be vague and your sampling will be random.
Key processes to understand in healthcare
Before the audit, spend time reviewing the organisation's process map or quality manual. Most healthcare QMSs will include processes around:
- Patient intake, triage, and registration
- Clinical service delivery (which you observe for system evidence, not clinical correctness)
- Medication management and pharmacy controls
- Equipment maintenance, calibration, and sterilisation
- Infection prevention and control
- Complaints and feedback handling
- Incident reporting and investigation
- Staff credentialling and competence verification
- Supplier and contractor management
- Document and record control
You are not auditing whether the clinical content of these processes is correct. You are auditing whether the processes are defined, followed, monitored, and improved. That distinction matters every time you frame a question.
Familiarise yourself with relevant regulatory frameworks
Australian healthcare organisations operate under a significant regulatory burden. The National Safety and Quality Health Service (NSQHS) Standards, the Aged Care Quality Standards, NDIS Practice Standards, and various state based health legislation all create compliance obligations that intersect with the ISO QMS. Understanding which frameworks apply helps you audit Clause 4.2 (interested parties) and Clause 6.1 (risks and opportunities) more intelligently. You are not checking compliance with those frameworks directly, but you are checking whether the organisation has identified them as relevant requirements and built them into its system.
For a deeper look at how ISO 9001 applies specifically in healthcare settings, the article on ISO 9001 for healthcare providers covers the alignment between the standard and clinical governance in useful detail.
Where to Focus Your Audit Energy
Healthcare QMSs tend to have particular strengths and particular weaknesses. Knowing where the risk sits helps you allocate your audit time more effectively.
Competence and credentialling
Clause 7.2 requires the organisation to determine the competence needed for roles affecting quality, ensure people have that competence, and retain evidence. In healthcare, this translates to credentialling, registration verification, mandatory training completion, and scope of practice controls.
This is one of the richest areas to audit in any healthcare organisation. Ask to see how the organisation verifies that staff are registered with AHPRA where required. Ask how it tracks mandatory training completion. Ask what happens when a staff member's registration lapses or a training record is overdue. Then sample the records and see whether the system matches the description.
Common findings here include training matrices that are not kept current, no process for verifying registration renewals, and competence assessments that exist on paper but are not consistently applied.
Document and record control
Healthcare generates enormous volumes of documented information. Clinical policies, procedures, patient records, equipment logs, incident reports, and audit records all need to be controlled. Clause 7.5 requires the organisation to control the creation, updating, and availability of documented information.
In practice, many healthcare organisations struggle with version control across multiple sites or departments. Printed copies of superseded policies sitting in ward folders are a classic finding. Ask how staff know which version of a procedure is current. Ask how document reviews are triggered when legislation or clinical guidelines change. Ask who has authority to approve changes to controlled documents.
Nonconforming outputs and incident management
Clause 8.7 requires the organisation to identify and control outputs that do not conform to requirements. In healthcare, this overlaps heavily with the incident reporting and management system. Medication errors, equipment failures, patient complaints, and near misses all represent potential nonconforming outputs.
The audit question is not whether the clinical response to an incident was appropriate. The audit question is whether the system for identifying, recording, investigating, and learning from incidents is functioning as designed. Are incidents being reported? Are root causes being identified? Are corrective actions being implemented and verified? Are trends being analysed and presented to management?
If the incident management system is robust, you will find evidence of trend analysis feeding into management review and driving systemic improvement. If it is weak, you will find isolated incident reports with no follow through and management reviews that discuss incidents in general terms without data.
Supplier and contractor management
Healthcare organisations rely heavily on external providers. Pathology services, radiology, pharmacy suppliers, equipment maintenance contractors, cleaning and sterilisation services, locum and agency staff, and IT providers all affect the quality of care delivered. Clause 8.4 requires the organisation to control these external providers based on the risk they represent.
Ask how the organisation evaluates and selects critical suppliers. Ask how it monitors ongoing performance. Ask what happens when a supplier fails to meet requirements. Agency and locum staff are a particularly important area because they directly deliver clinical services and must meet the same competence requirements as permanent staff. Many organisations have gaps here.
Management review
Clause 9.3 requires top management to review the QMS at planned intervals to ensure it remains suitable, adequate, and effective. In healthcare, management review often competes with clinical governance committee meetings, board reporting, and accreditation cycles. The result is sometimes a management review that exists on paper but does not genuinely engage leadership in QMS performance.
Ask to see the management review records. Check whether the inputs required by the standard are present: audit results, customer feedback, process performance, nonconformity trends, risk and opportunity status, and resource adequacy. Check whether the outputs include decisions and actions, not just discussion. Check whether actions from previous reviews have been followed up.
Audit Techniques That Work in Healthcare Settings
Follow the process, not the clause
Process based auditing is always more effective than clause by clause auditing, and it is especially valuable in healthcare where the processes are complex and interconnected. Pick a process, follow it from start to finish, and gather evidence about how it is planned, controlled, monitored, and improved. A patient complaint, for example, can take you through Clause 8.2 (customer requirements), Clause 8.7 (nonconforming outputs), Clause 10.2 (corrective action), and Clause 9.3 (management review) in a single thread.
For practical guidance on this approach, the article on process based vs clause based auditing is worth reading before you plan your healthcare audit.
Use observation carefully
Observation is a powerful evidence gathering technique in healthcare, but it requires care. You may be able to observe a reception process, a medication storage area, an equipment maintenance log, or a sterilisation workflow. You are observing for system conformance, not clinical correctness. If you observe a process that is not being followed as documented, that is a finding. If you observe a process that you think could be done differently from a clinical perspective, that is not your finding to make.
Always seek permission before entering clinical areas, respect patient privacy, and follow the organisation's infection control requirements. These are not just courtesies. They are requirements under the organisation's own system, and failing to observe them would undermine your credibility as an auditor.
Interview at multiple levels
Healthcare organisations are hierarchical. Senior clinicians, nurse unit managers, administrators, and front line staff often have very different understandings of the QMS. Interview at multiple levels to get a complete picture. Top management should be able to articulate quality objectives and demonstrate engagement with system performance data. Middle management should be able to describe how processes are monitored and how issues are escalated. Front line staff should be able to describe how they access current procedures, report incidents, and raise concerns.
Gaps between what management describes and what front line staff experience are some of the most valuable findings an auditor can surface. They indicate that the system exists at a policy level but has not been embedded in daily practice.
Do not be intimidated by clinical expertise
One of the more common challenges for auditors in healthcare is the dynamic that arises when a senior clinician challenges the relevance of an audit question. A consultant surgeon or a chief nursing officer who questions why an ISO auditor is asking about their department can be unsettling, particularly for less experienced auditors.
Hold your ground professionally. You are not questioning clinical judgement. You are verifying that the management system operates as intended. Frame your questions around the system, not the clinical content. If the auditee says their process works fine, ask them how they know. Ask what data they use to monitor performance. Ask what happened the last time something went wrong. Those questions are always legitimate, regardless of the clinical context.
Common Nonconformities in Healthcare QMS Audits
Based on experience across healthcare audits, the following nonconformities appear regularly:
- Competence records that are incomplete or not current: Training matrices not updated, AHPRA registration not verified at renewal, mandatory training overdue for a significant proportion of staff.
- Document control failures: Superseded versions in circulation, no review schedule for clinical policies, approval records missing from controlled documents.
- Incident management gaps: Incidents recorded but root cause analysis not completed, corrective actions not verified for effectiveness, trend data not presented to management review.
- Supplier evaluation not applied to agency staff: No process for verifying that locum and agency staff meet the same competence requirements as permanent employees.
- Quality objectives that are not measurable or not monitored: Objectives stated in vague terms with no data collected to track performance against them.
- Management review inputs incomplete: Customer feedback, audit results, or risk status not included in review records.
Working with ISO 13485 in Medical Device Contexts
If you are auditing a healthcare organisation that manufactures, supplies, or maintains medical devices, ISO 13485 may apply instead of or alongside ISO 9001. ISO 13485 has a stronger emphasis on risk management (aligned with ISO 14971), regulatory requirements, and the traceability of products. The audit approach is similar in principle but the specific requirements around design controls, post market surveillance, and product traceability are more demanding.
If you are auditing against ISO 13485 without prior experience in medical device quality systems, engage a technical expert to support the audit. ISO 19011 explicitly provides for this, and it is far better to acknowledge the gap than to audit areas where you lack the technical knowledge to evaluate evidence competently.
Preparing Your Audit Plan for a Healthcare Organisation
A well constructed audit plan is essential in healthcare because access to areas and personnel needs to be coordinated carefully. Clinical rosters, patient care schedules, and shift patterns all affect when and where you can conduct interviews and observations. Work with the quality manager to build a realistic plan that gives you access to the right people and processes without disrupting patient care.
Allocate time for document review before site visits. Healthcare organisations generate extensive documented information and reviewing key documents in advance, such as the quality policy, quality objectives, risk register, management review records, and supplier evaluation records, allows you to use site time more efficiently.
Risk base your sampling. If the organisation has had a recent sentinel event, a complaint spike, or a regulatory notice, those areas warrant deeper attention. If a particular department or site has not been audited recently, include it in your plan. The article on how to audit a process you have never seen before offers practical guidance that translates well to unfamiliar healthcare environments.
Exemplar Global Recognised Training ProviderRTP No. 310970Reporting Findings in a Healthcare Context
When you write your findings, be precise about what you observed, what evidence you gathered, and which requirement has not been met. Avoid clinical language you are not qualified to use. Avoid language that implies a patient safety risk unless you have specific evidence of a system failure that creates that risk. Healthcare organisations are sensitive to findings that could be interpreted as regulatory breaches or liability issues, and imprecise language causes unnecessary alarm.
A finding that says the organisation's incident management process does not consistently result in root cause analysis being completed and documented, as required by Clause 10.2 is specific, evidence based, and actionable. A finding that says patient safety is at risk due to poor incident management is vague, inflammatory, and outside your scope as an ISO auditor.
For guidance on writing findings that drive genuine improvement, the article on how to write a nonconformity report that actually gets fixed is directly applicable to healthcare audit contexts.
Building Competence to Audit Healthcare Organisations
Auditing healthcare QMSs well requires a combination of auditing skill and sector awareness. If you are new to healthcare, invest time in understanding the regulatory environment before your first assignment. Read the NSQHS Standards. Understand the Aged Care Quality Standards if you are auditing aged care. Review the NDIS Practice Standards if you are working in disability services. None of this makes you a clinical expert, but it gives you enough context to ask intelligent questions and understand the answers.
If you are looking to build a stronger foundation in auditing practice across complex environments, Audit Workshop offers training at Foundation, Internal Auditor, and Lead Auditor levels across ISO 9001 and ISO 13485. The courses are built around practical auditing skills, not just standard interpretation, and they are designed for practitioners who need to audit effectively in real organisations, including healthcare settings.













