Exemplar Global Certified Courses from USD 99. Ending Soon!

Management Systems Glossary for Beginners: Key Terms Explained

AW

Team @ Audit Workshop

15 min read
Management Systems Glossary for Beginners: Key Terms Explained

If you are new to ISO standards, the terminology can feel like a foreign language. Words like nonconformity, documented information, and interested parties appear constantly in standards, audit reports, and training materials, and if you do not know what they mean, you will struggle to understand what is actually being asked of you. This management systems glossary is designed to give you clear, plain English definitions of the terms you will encounter most often, whether you are implementing a system, preparing for an internal audit, or just starting your journey into ISO auditing.

The definitions here are grounded in how these terms are actually used in practice, not just how they appear in standards documents. Where a term has a specific meaning in ISO, that is noted. Where there is a practical nuance worth knowing, it is included.

Core Concepts: What Is a Management System?

Management System

A management system is the set of policies, processes, procedures, and records an organisation uses to achieve its objectives in a particular area. A quality management system focuses on consistent product and service delivery. An environmental management system focuses on managing environmental impacts. An occupational health and safety management system focuses on worker safety. The system is not just the documents. It is the way the organisation actually operates.

Standard

A standard is a published document that sets out requirements, specifications, or guidelines. ISO standards like ISO 9001, ISO 14001, and ISO 45001 are voluntary international standards that organisations can choose to implement and certify against. A standard tells you what you need to do, not necessarily how to do it.

Requirement

In ISO standards, a requirement is something the organisation shall do. The word shall is always used for requirements. If the standard says should, it is a recommendation, not a requirement. This distinction matters enormously in auditing. An auditor can only raise a nonconformity against a shall statement.

Clause

ISO standards are divided into numbered sections called clauses. ISO 9001, ISO 14001, and ISO 45001 all follow the same clause structure from Clause 4 to Clause 10, thanks to the Harmonised Structure. Clause 4 covers context, Clause 5 covers leadership, Clause 6 covers planning, and so on. Understanding the clause structure helps you navigate any modern ISO standard.

If you want a deeper look at how the clause structure works across standards, the article on the High Level Structure in ISO standards is worth reading.

Organisational Context Terms

Context of the Organisation

This refers to the internal and external factors that affect an organisation and its ability to achieve its objectives. External factors include things like regulation, market conditions, and community expectations. Internal factors include culture, resources, and organisational structure. Understanding context is required under Clause 4.1 of all major ISO standards.

Interested Parties (Stakeholders)

Interested parties are people or organisations that can affect, or be affected by, your management system. They include customers, employees, regulators, suppliers, local communities, and shareholders. Identifying interested parties and understanding their needs and expectations is a Clause 4.2 requirement. The term stakeholder is sometimes used informally to mean the same thing.

Scope

The scope defines the boundaries and applicability of the management system. It tells you which parts of the organisation, which locations, and which products or services are covered by the system. The scope needs to be documented and must be realistic. A certification audit will only cover what is within the defined scope.

Leadership and Policy Terms

Top Management

Top management refers to the person or group of people who direct and control an organisation at the highest level. In a small business, this might be the owner or managing director. In a large organisation, it could be the executive leadership team. ISO standards place specific obligations on top management, including demonstrating commitment to the system and setting policy.

Policy

A policy is a formal statement from top management that sets the direction for the management system. A quality policy commits the organisation to meeting customer requirements and continually improving. An environmental policy commits to protecting the environment. A policy must be documented, communicated to all workers, and available to interested parties. It should not be a generic statement copied from the internet.

Roles, Responsibilities, and Authorities

ISO standards require that roles relevant to the management system are assigned, communicated, and understood. Someone needs to own each part of the system. Auditors will check that people know what they are responsible for and that those responsibilities are documented somewhere, whether in job descriptions, procedure documents, or an organisational chart.

Planning Terms

Risk

In ISO standards, risk is the effect of uncertainty on objectives. It can be positive (an opportunity) or negative (a threat). Risk does not just mean something bad might happen. It means there is uncertainty about whether an objective will be achieved. Risk based thinking is woven through all modern ISO standards and replaces the old concept of preventive action.

Opportunity

An opportunity is a positive risk. It is a set of circumstances that could allow the organisation to improve performance, expand capability, or better meet objectives. ISO 9001 and ISO 14001 both require organisations to consider opportunities alongside risks when planning the management system.

Objective

Objectives are measurable goals that the organisation sets for its management system. Quality objectives might relate to customer satisfaction scores or defect rates. Environmental objectives might relate to waste reduction or energy consumption. OH&S objectives might relate to incident frequency rates. ISO standards require objectives to be measurable, monitored, communicated, and updated as needed.

Risk Based Thinking

Risk based thinking means considering what could go wrong (or go right) when making decisions and designing processes. It is not a formal risk assessment methodology. It is a way of approaching work that ensures risks and opportunities are considered before problems occur. The article on risk based thinking with practical examples explains this concept in detail with worked scenarios.

Support and Resource Terms

Competence

Competence is the ability to apply knowledge and skills to achieve intended results. ISO standards require organisations to determine what competence is needed, ensure people have it, and keep evidence that they do. Competence is not just about qualifications. It includes experience and demonstrated ability. A training record alone does not prove competence. Evidence of effective performance does.

Awareness

Awareness means that workers understand the policy, their contribution to the management system, the benefits of conformity, and the consequences of not conforming. Awareness is different from competence. A worker can be aware of the quality policy without being competent to perform a specific task. Auditors often test awareness by asking workers simple questions during site visits.

Documented Information

Documented information is the ISO term for documents and records. A document is information the organisation uses to operate, like a procedure or work instruction. A record is evidence that something was done, like a completed checklist or a signed inspection form. ISO standards no longer use the terms documents and records separately. They are both covered by the single term documented information.

Document Control

Document control refers to the processes for creating, reviewing, approving, distributing, and retiring documents. Controlled documents must be current, protected from unintended alteration, and available where they are needed. Obsolete documents must be identified or removed from use. Document control is one of the most commonly audited areas and one of the most common sources of nonconformities.

Infrastructure

Infrastructure refers to the physical and technical resources needed to operate processes. This includes buildings, equipment, vehicles, IT systems, and utilities. ISO 9001 Clause 7.1.3 requires organisations to determine, provide, and maintain the infrastructure needed to achieve conformity of products and services.

Operations Terms

Process

A process is a set of interrelated activities that transforms inputs into outputs. Every organisation operates through processes, whether they are formally documented or not. The process approach means managing work as a system of interconnected processes rather than as isolated functions. ISO standards require organisations to identify their processes, set criteria for them, and ensure they are controlled.

Procedure

A procedure describes how a process or activity is carried out. It answers the question how do we do this? Procedures can be documented or undocumented. ISO standards do not always require procedures to be written down, but in practice, documented procedures are the clearest way to demonstrate control. The article on the process approach explained with examples is a useful companion read here.

Work Instruction

A work instruction is more detailed than a procedure. It provides step by step guidance for performing a specific task. Where a procedure might describe the overall inspection process, a work instruction would describe exactly how to calibrate a specific piece of equipment. Work instructions are typically used where precision and consistency are critical.

Outsourced Process

An outsourced process is one that the organisation needs for its management system but has chosen to have performed by an external party. ISO 9001 requires organisations to control outsourced processes. The fact that a process is outsourced does not remove the organisation's responsibility for it. Auditors will check that appropriate controls exist over outsourced work.

Nonconforming Output

A nonconforming output is a product or service that does not meet requirements. It might be a defective component, an incorrect report, or a service delivered incorrectly. ISO 9001 Clause 8.7 requires organisations to identify and control nonconforming outputs to prevent their unintended use or delivery.

Performance Evaluation Terms

Monitoring

Monitoring means tracking performance over time to detect trends or changes. It is an ongoing activity. Monitoring customer satisfaction, measuring defect rates, and tracking incident frequency are all examples of monitoring. ISO standards require organisations to determine what needs to be monitored, how it will be monitored, and when results will be analysed.

Measurement

Measurement involves assigning a number to something. It is more specific than monitoring. Measurement produces data that can be compared against targets or benchmarks. Calibration is often relevant here. If you are measuring something with an instrument, that instrument needs to be fit for purpose and, where appropriate, calibrated.

Internal Audit

An internal audit is a systematic, independent, and documented process for evaluating whether the management system conforms to requirements and is effectively implemented. Internal audits are conducted by the organisation itself, or by someone acting on its behalf. They are a Clause 9.2 requirement across all major ISO standards. They are not the same as a certification audit.

Management Review

A management review is a formal meeting or process where top management evaluates the performance and suitability of the management system. It must cover specific inputs defined in the standard, such as audit results, customer feedback, and objective performance. The outputs must include decisions on improvement and resource needs. It is a Clause 9.3 requirement.

Key Performance Indicator (KPI)

A KPI is a measurable value that demonstrates how effectively an organisation is achieving key objectives. In a management system context, KPIs might include customer complaint rates, environmental incident counts, or safety observation scores. ISO standards do not prescribe which KPIs to use, but they do require that performance be monitored and evaluated.

Improvement Terms

Nonconformity

A nonconformity is a failure to meet a requirement. The requirement might come from the ISO standard, a legal obligation, or the organisation's own documented procedures. Nonconformities can be major or minor. A major nonconformity is a failure that affects the ability of the system to achieve its intended outcomes. A minor nonconformity is an isolated lapse that does not undermine the system as a whole.

Corrective Action

A corrective action is a response to a nonconformity that addresses the root cause to prevent recurrence. It is not the same as a correction. A correction fixes the immediate problem. A corrective action fixes the system so the problem does not happen again. ISO standards require organisations to investigate root causes and verify that corrective actions are effective.

Correction

A correction is an immediate fix for a nonconformity. If a batch of products is found to be defective, withdrawing and reworking them is a correction. It addresses the symptom, not the cause. Corrections and corrective actions are often both needed, but they serve different purposes.

Continual Improvement

Continual improvement is the ongoing effort to enhance performance. It does not mean constant change. It means a systematic approach to identifying and acting on opportunities to do better. ISO standards require organisations to continually improve the suitability, adequacy, and effectiveness of the management system. Improvement should be evidenced over time.

Root Cause Analysis

Root cause analysis is the process of identifying the underlying cause of a nonconformity or problem. Common methods include the Five Whys, fishbone diagrams, and fault tree analysis. The root cause is not the symptom. If a worker did not follow a procedure, the root cause might be that the procedure was unclear, not that the worker was careless.

Audit Specific Terms

Audit Criteria

Audit criteria are the requirements against which audit evidence is compared. For a certification audit, the criteria are the requirements of the ISO standard. For an internal audit, the criteria might also include the organisation's own procedures and objectives. The criteria must be defined before the audit begins.

Audit Evidence

Audit evidence is the information used to determine whether audit criteria are met. It can be documents, records, observations, or statements from interviews. Evidence must be verifiable. An auditor cannot raise a finding based on a hunch. Every finding must be supported by objective evidence.

Audit Finding

An audit finding is the result of evaluating audit evidence against audit criteria. Findings can be conformities, nonconformities, or observations. A finding is not just a problem. It can also be a positive result showing that the system is working as intended.

Observation

In auditing, an observation is a finding that does not meet the threshold for a nonconformity but is worth noting. It might be a potential weakness or an area where improvement is possible. Different certification bodies use this term differently, so it is worth clarifying what it means in any specific audit context.

Auditee

The auditee is the organisation or person being audited. In an internal audit, the auditee is typically a department, team, or process owner within the organisation. In a certification audit, the auditee is the organisation seeking or maintaining certification.

Lead Auditor

A lead auditor is a qualified auditor who has the authority to manage and lead an audit team. They are responsible for planning the audit, directing the team, communicating with the auditee, and producing the audit report. Lead auditor qualifications are recognised through schemes like Exemplar Global and IRCA.

Certification and Accreditation Terms

Certification

Certification is the process by which an independent certification body confirms that an organisation's management system meets the requirements of a specific ISO standard. Certification is voluntary. It is granted following a successful Stage 1 and Stage 2 audit and maintained through annual surveillance audits and a three year recertification cycle.

Accreditation

Accreditation is the formal recognition that a certification body is competent to carry out certification. In Australia, JAS ANZ is the national accreditation body. Accreditation is not the same as certification. The certification body gets accredited. The organisation gets certified. Choosing an accredited certification body matters for the credibility of your certificate.

Surveillance Audit

A surveillance audit is a periodic audit conducted by the certification body between recertification audits. It checks that the management system continues to conform to requirements and is being maintained effectively. Surveillance audits typically occur annually and cover a subset of the system rather than a full review.

Nonconformity Report (NCR)

A nonconformity report documents a specific nonconformity found during an audit. It should include a clear statement of what was found, the requirement that was not met, and the objective evidence supporting the finding. A good NCR gives the auditee enough information to investigate the root cause and implement an effective corrective action.

Getting the Language Right from the Start

Understanding this terminology is not just useful for passing audits. It changes the way you read standards, write procedures, and have conversations with auditors and certification bodies. When you know what documented information actually means, you stop over documenting. When you understand the difference between a correction and a corrective action, you stop treating symptoms as solutions.

If you are ready to move beyond definitions and start applying these concepts in real audits, Audit Workshop offers training at Foundation, Internal Auditor, and Lead Auditor levels across ISO 9001, ISO 14001, and ISO 45001. The courses are built around practical application, not just theory, and are delivered by an auditor with over 500 external audits across multiple industries. Whether you are just starting out or looking to formalise your skills, you can explore the options at auditworkshop.com.

Frequently Asked Questions

ISO standards use the term documented information to cover both. In practice, a document is information used to guide or control work, such as a procedure or policy, while a record is evidence that an activity was carried out, such as a completed inspection checklist or a signed training form. Documents are typically subject to revision control. Records are retained as evidence and should not be altered after the fact.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
ISO 45001:2018 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
ISO 14001:2026 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.