Training module
Auditing Product & Service Development
Assess controls, validation and effectiveness in product and service design and development against ISO 9001 requirements
Do design reviews exist but delivery problems still originate in design?
Design and development controls often appear structured on paper while problems emerge later in production or service delivery. This module develops the capability to test whether design activities are sufficiently controlled to prevent predictable failures.
Overview
What this module is about
Design and development activities determine whether products and services can reliably meet requirements before delivery begins. In ISO 9001, design and development controls are intended to ensure that requirements are translated into workable solutions through structured planning, review, verification, and validation.
In practice, design controls often appear complete in documentation while weaknesses surface later in delivery: unclear inputs, informal design decisions, ineffective reviews, or insufficient validation under real operating conditions.
This module develops the capability to audit whether design and development activities are sufficiently controlled and produce reliable outcomes. Participants first review how design and development functions within ISO 9001 for both products and services, then learn how auditors test planning discipline, review effectiveness, verification and validation evidence, and design change control.
Audience
Who it is for
Management system implementers and coordinators
Executives and department heads accountable for management system performance
Those responsible for processes, policies, assets, risks and controls
Auditors seeking insight into management-side practice, not audit technique
Consultants working on management system design, governance or improvement
Decision supportIs this module for you?
It is a good fit if you…
audit product or service design and development within ISO 9001 management systems.
want to assess whether design controls prevent predictable delivery failures.
seek to judge design review, verification, and validation evidence.
need to test whether design changes are controlled across the lifecycle.
expect to strengthen audit conclusions on design and development effectiveness.
It may not be the best fit if you…
prefer to design products, services, or development processes yourself.
are looking for engineering design methods or innovation techniques.
focus primarily on product development management rather than auditing.
do not intend to audit design and development activities.
Agenda
What is taught
8 parts01Design and development in ISO 9001
How product and service design translate requirements into solutions and why weaknesses in design control frequently appear later in delivery
02Effective auditing of design and development
How auditors judge whether design controls provide credible assurance rather than relying on documentation alone
03Design inputs and planning
How to evaluate whether design inputs are complete, feasible, and aligned with customer, regulatory, and operational requirements
04Design reviews as control points
How to test whether design reviews identify risks, assumptions, and feasibility issues before they reach delivery
05Verification and validation evidence
How auditors distinguish between verification of design outputs and validation under realistic operating conditions
06Design changes across the lifecycle
How to evaluate whether design changes are identified, assessed, approved, and communicated without introducing uncontrolled risk
07Design-to-delivery traceability
How to follow evidence trails linking design decisions, outputs, and delivery outcomes to detect design-related failures
08Case-based audit simulation
Applying the learned concepts, methods, and approaches in a realistic case setting
Outcomes
Learning outcomes
01
Assess whether design and development activities are planned and controlled within the management system
02
Test whether design inputs, reviews, verification, and validation provide credible assurance of performance
03
Trace design decisions and outputs to delivery outcomes using defensible audit evidence
Evaluate whether design changes are controlled across the lifecycle
Detect common design failure patterns such as incomplete inputs or ineffective reviews
Select meaningful sampling targets when auditing design and development activities
Formulate defensible audit conclusions on design and development effectiveness
Materials
The content and the assessment
Written module
The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.
Exercises
Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.
On completion
The assessed exercises must be passed before the certificate is issued.
Scheduling
No public run of Auditing Product & Service Development is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.
Module facts
- Module ID
- HAM-QM-A-02
- Discipline
- Quality Management
- Part of tracks
- Management System Auditor
Case organisation
You work inside a company that already has the problem
Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.
Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.
Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes
Not a case study
Nothing is summarised for you; the evidence is where it would really be
It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after
It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions
Why it matters
Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.
Delivery & dates
How this module reaches you
Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.
No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.
Want this module scheduled?
We will tell you when the next run is scheduled, or run this module in-house with your own case material.
Not sure it is the right module?
Describe your context in a short message and we will tell you honestly.