Back to Resources
    Downloads
    ISO 9001

    ISO 9001 Internal Audit Checklist

    ByEditor·
    Share:
    ISO 9001 Internal Audit Checklist

    Download this resource

    Please enter your details to access the download.

    This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

    The internal audit is one of the most important requirements of ISO 9001 and, if handled poorly, one of the most common causes of problems at the certification stage. Conducted well, it is your organization's own quality check before an external auditor arrives. Conducted badly, it gives you false confidence while leaving gaps that will surface at the worst possible moment.

    This guide explains what an internal audit must cover, how to approach it effectively, and provides a clause-by-clause checklist of the questions your internal auditor should be asking. The checklist is designed to be used directly: either as a structured guide during your audit, or as the basis for building your own organization-specific audit tool.

    What an ISO 9001 Internal Audit Must Achieve

    ISO 9001 Clause 9.2 sets out the requirements for internal audit. In plain terms, your internal audit program must do three things: confirm that the QMS conforms to the requirements of the standard, confirm that the QMS is effectively implemented and maintained, and generate findings that feed into corrective action and management review processes.

    A common mistake is treating the internal audit as a document review. Auditors who sit in an office reading procedures and ticking boxes are not auditing in any meaningful sense. An effective internal audit involves talking to the people who actually do the work, observing processes in practice, and checking that records reflect what really happens rather than what the procedure says should happen.

    Important: auditor independence. ISO 9001 requires that internal audits are conducted by people who are not responsible for the activities being audited. Someone cannot audit their own work. In small businesses where this is logistically difficult, consider using a trusted colleague from a different function, a trained external auditor working on your behalf, or a peer audit arrangement with another organization.

    Preparing for the Internal Audit

    Before conducting the audit, your internal auditor should prepare the following:

    • An audit plan setting out which areas will be covered, who will be interviewed, and on what dates
    • A copy of the ISO 9001:2015 standard or a clause-by-clause summary of requirements
    • The organization's quality policy, objectives, process maps, and documented procedures
    • Records from the previous audit cycle (if applicable), to check whether previous nonconformities have been closed
    • A blank nonconformity log for recording findings during the audit

    Example: Hartley Precision Engineering, a Sheffield-based precision manufacturer, prepares for their annual internal audit by sending a short briefing note to all department heads two weeks in advance. The note explains what the auditor will be looking for in each area and which records should be made available. This reduces the time spent waiting for documents on the day and significantly improves the quality of the audit conversations.

    The Internal Audit Checklist

    The checklist below is organized by clause. Not every question will apply to every organization, and your auditor should adapt the questions to the specific context of your business. The "evidence to look for" column is a guide to what makes a satisfactory answer, not an exhaustive list.

    Clause 4: Context of the Organization

    ClauseAudit questionEvidence to look for
    4.1Can you explain the internal and external issues that affect the organization's ability to achieve its quality objectives?Documented context analysis or SWOT or equivalent; reviewed at management review
    4.2Who are your interested parties and what are their relevant requirements?List of interested parties with requirements noted; evidence of monitoring changes
    4.3What is included in the scope of the QMS and what, if anything, is excluded?Written scope statement; any exclusions justified with reasoning
    4.4Can you walk me through the key processes in your QMS and how they interact?Process map or turtle diagram; inputs, outputs, owners and interactions documented

    Clause 5: Leadership

    ClauseAudit questionEvidence to look for
    5.1How does top management demonstrate commitment to the QMS?Evidence of leadership involvement in management review; quality policy signed by top management; resources allocated
    5.2Is the quality policy communicated and understood by staff?Quality policy displayed or accessible; staff can describe it in their own words when asked
    5.3Are roles, responsibilities, and authorities clearly defined and communicated?Organization chart; role descriptions or responsibility matrix; staff aware of their own responsibilities

    Clause 6: Planning

    ClauseAudit questionEvidence to look for
    6.1How do you identify and address risks and opportunities relevant to the QMS?Risk register or equivalent; actions assigned; evidence of review
    6.2What are your current quality objectives and how are they being measured?Written objectives with measurable targets, named owners, and timescales; progress data available
    6.3How do you plan and manage changes to the QMS?Change control process; evidence that changes are evaluated before implementation

    Clause 7: Support

    ClauseAudit questionEvidence to look for
    7.1How do you ensure the right resources are in place to operate and improve the QMS?Resource planning records; evidence that infrastructure and environment are maintained
    7.2How do you manage staff competence?Competence requirements defined per role; training records; evaluation of training effectiveness
    7.3How do you ensure staff are aware of the quality policy, objectives, and their contribution?Induction records; toolbox talks; briefing notes; staff can articulate the policy
    7.4How is communication managed internally and externally?Communication plan or equivalent; records of meetings, briefings and customer communications
    7.5How is documented information created, controlled, updated, and retained?Document control procedure; version control in place; obsolete documents removed or marked

    Clause 8: Operation

    ClauseAudit questionEvidence to look for
    8.1Are operational processes planned, controlled, and carried out as documented?Procedures match observed practice; records of outputs available; criteria for acceptance defined
    8.2How are customer requirements determined and reviewed before acceptance?Sales or order review process; evidence of customer requirement capture; records of review
    8.3If applicable, how is the design and development process controlled?Design plans; review, verification and validation records; change controls
    8.4How do you control externally provided products, processes, and services?Approved supplier list; supplier evaluation criteria and records; purchase order controls
    8.5How do you control production or service delivery?Work instructions; calibration records; traceability system; records of output
    8.6How do you ensure products or services meet requirements before release?Inspection records; release authorization; evidence that criteria are met before sign-off
    8.7How do you manage nonconforming outputs?Nonconformity procedure; records of nonconforming items; disposition decisions documented

    Clause 9: Performance Evaluation

    ClauseAudit questionEvidence to look for
    9.1How do you monitor and measure process and product performance?KPIs and performance data; customer satisfaction data; analysis of trends
    9.2How is the internal audit program planned and managed?Audit schedule; auditor competence records; previous audit reports and nonconformity closure
    9.3Has a management review taken place and what were the outputs?Management review minutes; agenda covered required inputs; actions assigned with owners and dates

    Clause 10: Improvement

    ClauseAudit questionEvidence to look for
    10.1How does the organization identify and act on improvement opportunities?Improvement log or equivalent; evidence of actions taken; link to objectives
    10.2How are nonconformities identified, recorded, and addressed?Corrective action log; root cause analysis records; evidence that actions are effective; recurrence checked
    10.3How does the organization demonstrate continual improvement?Trend data showing improvement; updated objectives; evidence that the QMS evolves in response to findings

    Recording and Reporting Findings

    Every internal audit must produce a written report. At minimum, the report should record the audit scope, the dates and areas covered, the auditor's name, the findings (including any nonconformities raised), and the conclusions. ISO 9001 requires this documented information to be retained.

    Nonconformities should be graded. A major nonconformity indicates a complete absence of a required element or a systemic breakdown. A minor nonconformity is an isolated or less critical lapse. Observations or opportunities for improvement are findings that do not constitute nonconformities but are worth addressing.

    Each nonconformity must be followed up with a corrective action: the immediate fix, a root cause analysis, and a longer-term action to prevent recurrence. The internal audit report and resulting corrective actions must be presented at the next management review meeting.

    Common Internal Audit Mistakes to Avoid

    • Only auditing documentation and not observing actual practice
    • Failing to interview frontline staff, focusing only on managers
    • Not retaining adequate records of the audit conversations and findings
    • Closing nonconformities without verifying that the corrective action has actually worked
    • Auditing the same areas every year and neglecting others
    • Conducting the audit too close to the certification body audit, leaving no time to address findings

    Timing recommendation. Aim to complete your internal audit at least six to eight weeks before your certification body audit. This gives you time to raise corrective actions, carry out root cause analysis, implement fixes, and gather evidence that the actions have been effective before the external auditor arrives.

    Frequently Asked Questions

    What must an ISO 9001 internal audit cover?
    An ISO 9001 internal audit must cover the requirements of the standard (Clauses 4 to 10), the processes within the scope of your QMS, and any areas where previous nonconformities or risks have been identified. The audit does not need to cover every process in exhaustive depth in a single cycle, but over time the full scope of the QMS must be audited. Clause 9.2 of the standard sets out the specific requirements for internal audit planning, conduct, and reporting.
    Who can conduct an ISO 9001 internal audit?
    Internal audits must be conducted by people who are not responsible for the activities being audited. ISO 9001 does not require internal auditors to hold a formal qualification, but auditors should be competent and understand both the standard's requirements and the audit process. In practice, many organizations send their internal auditor on a recognized two-day lead auditor or internal auditor training course before conducting their first audit. In very small businesses where independence is difficult to achieve, an external auditor can be brought in to conduct the internal audit on your behalf.
    How often must an ISO 9001 internal audit be conducted?
    ISO 9001 requires internal audits to be conducted at planned intervals, but does not specify a minimum frequency. In practice, most organizations conduct at least one full internal audit cycle per year, typically in the period leading up to their annual surveillance or recertification audit. Higher-risk processes or areas where previous nonconformities have been raised may warrant more frequent auditing. Your audit program should be documented and reviewed periodically.
    What is the difference between an internal audit and a certification audit?
    An internal audit is conducted by or on behalf of your own organization as a self-assessment of your QMS. It is a requirement of the standard and is intended to identify gaps before an external auditor does. A certification audit is conducted by an independent, accredited certification body and results in the award, continuation, or withdrawal of your ISO 9001 certificate. The internal audit feeds into the management review process and helps prepare the organization for the certification audit, but it does not replace it.
    Share:

    Need Help With ISO Certification?

    Get quotes from accredited registrars and ISO experts.