Training module
Auditing Customer Requirements & Communication Management
Evaluate whether customer requirements are defined, agreed, controlled and traceable from commitment through delivery in an ISO 9001 QMS
Do requirement reviews exist but delivery still diverges?
Customer requirements often drift quietly: what was agreed, what changed, what was delivered, and what the customer actually experienced can diverge. This module develops the capability to test that story end-to-end using credible audit evidence.
Overview
What this module is about
Customer focus in ISO 9001 depends on organisations reliably determining requirements, confirming what is agreed, and controlling changes as delivery progresses. When these controls are weak, gaps emerge between what sales commits, what operations delivers, and what customers experience.
This module develops the capability to audit customer and requirements management using practical evidence trails and failure-pattern recognition. Participants first review how requirement determination, review, and change handling are expected to function in ISO 9001. They then learn how auditors test requirement completeness, review discipline, change control, and feedback signals to judge whether requirement management credibly supports delivery.
Audience
Who it is for
Management system implementers and coordinators
Executives and department heads accountable for management system performance
Those responsible for processes, policies, assets, risks and controls
Auditors seeking insight into management-side practice, not audit technique
Consultants working on management system design, governance or improvement
Decision supportIs this module for you?
It is a good fit if you…
audit how customer and requirement management is practiced in delivery.
seek to judge traceability from requirements to delivered outcomes.
want to improve how you audit requirement determination and change handling.
need to test whether gaps reflect control weaknesses or execution drift.
expect to strengthen audit conclusions on requirement management effectiveness.
It may not be the best fit if you…
prefer to define, negotiate, or structure customer requirements yourself.
are looking for methods to manage contracts or customer communications.
focus primarily on improving delivery performance or customer satisfaction.
do not intend to audit customer and requirement management processes.
Agenda
What is taught
8 parts01Customer and requirements management in ISO 9001
How requirement determination, review, confirmation, and change handling function within ISO 9001 and why failures commonly occur at the sales–delivery interface
02Effective auditing of customer and requirements management
How auditors judge whether requirement management provides a reliable baseline for delivery rather than relying on informal assumptions
03Requirement determination and completeness
How to evaluate whether customer, statutory, regulatory, and internal requirements are clearly captured and translated into delivery-ready expectations
04Requirement review before commitment
How auditors test feasibility checks, capability considerations, and alignment between quotes, orders, specifications, and delivery expectations
05Requirement change control across the lifecycle
How to evaluate whether requirement changes are identified, assessed, approved, communicated, and implemented before they affect delivery
06Requirement-to-delivery traceability
How to follow evidence trails from agreements to delivery outcomes and identify patterns such as concessions, undocumented changes, or workaround behaviour
07Customer feedback and complaints as audit evidence
How auditors interpret feedback, complaints, and escalation signals as indicators of requirement management weaknesses
08Case-based audit simulation
Applying the learned concepts, methods, and approaches in a realistic case setting
Outcomes
Learning outcomes
01
Assess whether customer requirements are clearly determined and agreed before commitments are made
02
Test requirement review practices to judge whether delivery risks are identified and controlled
03
Trace requirements from agreement through delivery and acceptance using defensible audit evidence
Evaluate change handling controls across the customer requirement lifecycle
Use customer feedback and complaints as audit evidence for requirement gaps
Select meaningful sampling targets when auditing customer and requirement management
Formulate defensible audit conclusions on requirement management effectiveness
Materials
The content and the assessment
Written module
The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.
Exercises
Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.
On completion
The assessed exercises must be passed before the certificate is issued.
Scheduling
No public run of Auditing Customer Requirements & Communication Management is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.
Module facts
- Module ID
- HAM-QM-A-01
- Discipline
- Quality Management
- Part of tracks
- Management System Auditor
Case organisation
You work inside a company that already has the problem
Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.
Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.
Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes
Not a case study
Nothing is summarised for you; the evidence is where it would really be
It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after
It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions
Why it matters
Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.
Delivery & dates
How this module reaches you
Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.
No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.
Want this module scheduled?
We will tell you when the next run is scheduled, or run this module in-house with your own case material.
Not sure it is the right module?
Describe your context in a short message and we will tell you honestly.