Most Malaysian SMEs do not fail ISO audits because they lack good practices. They fail because common gaps keep appearing in the same places — gaps that are entirely preventable with the right preparation. After guiding over 200 organisations through certification and surveillance audits, we have seen the same 10 findings come up again and again.

This guide shows you exactly what auditors check, why these findings occur, and how to prevent them before the auditor arrives.

⚡ Important Distinction

A finding does not mean failure. A minor non-conformity means one lapse within an otherwise functioning system. A major non-conformity means a complete absence or breakdown of a requirement. The goal is not zero findings — it is demonstrating that your system catches and corrects issues systematically.

1. Document control failures

What auditors find: Outdated documents at the point of work. The quality manual says Revision 3 but the production floor has Revision 1 pinned to the machine. Three different versions of the same SOP exist in different folders.

Why it matters: Document control (Clause 7.5) underpins everything. If your team works from outdated procedures, every process downstream is potentially non-conforming.

How to fix it: Maintain a master document list that is actually current. Walk the production floor quarterly and physically verify that documents at each workstation match the current revision. If you use printed copies, stamp them "Controlled Copy" with the revision date. If digital, ensure old versions are archived, not just renamed.

2. Internal audits that lack depth

What auditors find: Internal audit reports that look tidy — proper forms filled, signatures collected, "zero findings" reported — but when the external auditor walks the floor, they find issues the internal audit clearly missed.

Why it matters: Clause 9.2 requires internal audits that are effective, not just complete. An internal audit programme that consistently reports zero findings while external auditors find problems signals the system is not functioning as a genuine control mechanism.

How to fix it: Train internal auditors to ask operational questions, not just documentation questions. Instead of "Do you have a procedure for complaints?", ask "Show me the last 3 complaints and walk me through what was done." Ensure auditors never audit their own department. Consider our internal auditor training — it is one of the highest-ROI investments in audit readiness.

3. Corrective actions that address symptoms, not causes

What auditors find: The corrective action report says "staff will be retrained" for every finding. The same issue appears three audits in a row. Root cause analysis states "human error" without digging deeper.

Why it matters: Clause 10.2 requires determining the root cause and preventing recurrence. Repeated findings signal that corrective actions are not working — auditors will escalate.

How to fix it: Use the "5 Whys" technique. Instead of stopping at "operator did not follow procedure," keep asking: Was the procedure unclear? Was training inadequate? Was the workload unrealistic? Address the system weakness, not just individual behaviour.

4. Management review meetings that exist only on paper

What auditors find: Minutes prepared the week before the audit. Slides showing data but no analysis. Decisions recorded but no follow-up actions assigned or tracked. The same "customer satisfaction: satisfactory" year after year with no evidence.

Why it matters: Clause 9.3 requires management review that drives strategic decisions — not a compliance checkbox. Auditors look for evidence that decisions are implemented on the operational floor.

How to fix it: Hold management reviews with real data. Include trend analysis on complaints, audit findings, KPI performance, and process changes. Every item should produce a decision or an action with a named owner and deadline. Track and report progress at the next review.

5. Competency records that do not match reality

What auditors find: The training matrix shows all staff "competent" — but when the auditor interviews an operator, they cannot explain their role in the quality system. A new employee has operated critical equipment for 6 months without formal competency evaluation.

Why it matters: Clause 7.2 requires documented evidence of competence based on education, training, skills, or experience. Training attendance alone does not satisfy this.

How to fix it: Differentiate between "attended training" and "demonstrated competency." For critical processes, implement practical assessments — observed performance, knowledge tests, or work sample reviews. Update records when roles change or new staff join.

6. Risk registers that never change

What auditors find: The risk register was created during initial certification and has not been updated since. Controls are vague ("monitor regularly"). New operational risks — a supplier change, a new product line — are not reflected.

Why it matters: Clause 6.1 requires risk-based thinking that evaluates the effectiveness of controls. A static register suggests risk management is not integrated into daily operations.

How to fix it: Review quarterly. When significant change occurs — new customer, supplier switch, process change, safety incident — update immediately. "Monitor regularly" is not a control; "monthly review of supplier rejection data with escalation if rate exceeds 2%" is a control.

7. Supplier evaluation gaps

What auditors find: Long-standing suppliers never formally evaluated. The approved list has not been reviewed in years. A critical supplier changed their process 6 months ago, leading to quality issues, but no re-evaluation was triggered.

Why it matters: Clause 8.4 requires evaluation and re-evaluation of external providers. Trust-based relationships are common in Malaysian SMEs, but ISO requires objective evidence of performance.

How to fix it: Classify suppliers by risk: critical (affects product quality) versus non-critical. For critical suppliers, track delivery on-time rate, rejection rate, responsiveness. Trigger re-evaluation after major quality incidents, not just annually. A simple quarterly scorecard is sufficient for most SMEs.

8. Monitoring and measurement without follow-through

What auditors find: KPIs are tracked — on-time delivery, complaints, rejection rates — but when a KPI misses its target, no action is taken. Monthly reports show a rising defect trend, but no investigation is initiated.

Why it matters: Clause 9.1 emphasises analysis and evaluation, not just data collection. Collecting data without acting on it is not conforming.

How to fix it: Define trigger points for every KPI. When a KPI breaches the trigger, initiate an investigation. Not every trigger needs a formal corrective action, but every trigger needs a documented response. During management review, present KPIs with trends and analysis — "what do our numbers tell us and what are we doing about it?"

9. Certification scope does not match operations

What auditors find: The company expanded into new services since initial certification, but scope was never updated. A new branch operates outside the certified scope. The quality manual describes processes that no longer exist.

Why it matters: If operations extend beyond certified scope, your certificate may not be valid for contracts you are pursuing — especially government tenders.

How to fix it: Review scope annually against actual operations. If you have added products, services, or locations, discuss a scope extension with your certification body. This can be addressed during a surveillance audit.

10. No evidence of continual improvement

What auditors find: The system is maintained but no improvement initiatives exist beyond corrective actions. No process optimisation, no evidence of using feedback to drive positive change. The system is in stasis — nothing gets worse, nothing gets better.

Why it matters: Clause 10.3 requires continual improvement. If your management system only activates when something goes wrong, it is not meeting this requirement.

How to fix it: Track small wins: a procedure simplified after an internal audit, a packaging change that reduced damage complaints by 15%, a supplier switch that improved lead times. Document these in management review. The auditor wants evidence that the system drives improvement, not just compliance.

Your quarterly pre-audit check

Rather than treating these 10 findings as a checklist for the week before your audit, build them into a quarterly rhythm:

This quarterly check catches most real gaps before the external auditor does. For professional support, Cari Consultancy offers pre-audit gap assessments — we identify and help you close findings before they become official non-conformities.

Frequently Asked Questions

What is the difference between a major and minor non-conformity?

A major non-conformity means a complete absence or total breakdown of a requirement — for example, no internal audit conducted at all. A minor is a single lapse within an otherwise functioning system. Major non-conformities must be resolved before certification is granted.

How many audit findings are normal for a Malaysian SME?

During a first certification audit, 3–6 minor non-conformities is typical for a well-prepared SME. Zero findings is unusual and may concern an auditor — it can signal the internal audit process did not dig deep enough.

Can I fail an ISO audit in Malaysia?

Yes. If the auditor raises one or more major non-conformities, certification will not be granted until those findings are resolved and verified. For surveillance audits, unresolved majors can result in suspension or withdrawal of your certificate. Working with an experienced ISO consultant significantly reduces this risk.

How do I prepare for an ISO surveillance audit?

Close out all findings from the previous audit. Conduct an internal audit covering high-risk processes. Hold a management review with real data. Verify corrective actions from the past 12 months are effective. Ensure documents at the point of work are current revision. Cari Consultancy offers pre-audit preparation support.

📚 Related Reading

For a step-by-step certification walkthrough, see our ISO 9001 Malaysia Guide. For cost planning, see the ISO Certification Cost Guide. If you are pursuing certification for tenders, read ISO for Government Tenders Malaysia.

Prepare for Your Next ISO Audit With Confidence

Cari Consultancy offers pre-audit gap assessments, internal auditor training, and ongoing compliance support. We help you find and fix issues before the external auditor does — so your audit is a confirmation, not a surprise.

Speak to a Consultant Our Training Courses
CC
Cari Consultancy Sdn Bhd
ISO Certification & Audit Specialists · Malaysia

Cari Consultancy has guided over 200 organisations across Asia through ISO certification and ongoing compliance since 2009. Our consultants have sat on both sides of the audit table — we know what auditors look for because we have been auditors ourselves.