Download this resource
Please enter your details to access the download.
The internal audit is one of the most important requirements of ISO 9001 and, if handled poorly, one of the most common causes of problems at the certification stage. Conducted well, it is your organization's own quality check before an external auditor arrives. Conducted badly, it gives you false confidence while leaving gaps that will surface at the worst possible moment.
This guide explains what an internal audit must cover, how to approach it effectively, and provides a clause-by-clause checklist of the questions your internal auditor should be asking. The checklist is designed to be used directly: either as a structured guide during your audit, or as the basis for building your own organization-specific audit tool.
What an ISO 9001 Internal Audit Must Achieve
ISO 9001 Clause 9.2 sets out the requirements for internal audit. In plain terms, your internal audit program must do three things: confirm that the QMS conforms to the requirements of the standard, confirm that the QMS is effectively implemented and maintained, and generate findings that feed into corrective action and management review processes.
A common mistake is treating the internal audit as a document review. Auditors who sit in an office reading procedures and ticking boxes are not auditing in any meaningful sense. An effective internal audit involves talking to the people who actually do the work, observing processes in practice, and checking that records reflect what really happens rather than what the procedure says should happen.
Important: auditor independence. ISO 9001 requires that internal audits are conducted by people who are not responsible for the activities being audited. Someone cannot audit their own work. In small businesses where this is logistically difficult, consider using a trusted colleague from a different function, a trained external auditor working on your behalf, or a peer audit arrangement with another organization.
Preparing for the Internal Audit
Before conducting the audit, your internal auditor should prepare the following:
- An audit plan setting out which areas will be covered, who will be interviewed, and on what dates
- A copy of the ISO 9001:2015 standard or a clause-by-clause summary of requirements
- The organization's quality policy, objectives, process maps, and documented procedures
- Records from the previous audit cycle (if applicable), to check whether previous nonconformities have been closed
- A blank nonconformity log for recording findings during the audit
Example: Hartley Precision Engineering, a Sheffield-based precision manufacturer, prepares for their annual internal audit by sending a short briefing note to all department heads two weeks in advance. The note explains what the auditor will be looking for in each area and which records should be made available. This reduces the time spent waiting for documents on the day and significantly improves the quality of the audit conversations.
The Internal Audit Checklist
The checklist below is organized by clause. Not every question will apply to every organization, and your auditor should adapt the questions to the specific context of your business. The "evidence to look for" column is a guide to what makes a satisfactory answer, not an exhaustive list.
Clause 4: Context of the Organization
| Clause | Audit question | Evidence to look for |
|---|---|---|
| 4.1 | Can you explain the internal and external issues that affect the organization's ability to achieve its quality objectives? | Documented context analysis or SWOT or equivalent; reviewed at management review |
| 4.2 | Who are your interested parties and what are their relevant requirements? | List of interested parties with requirements noted; evidence of monitoring changes |
| 4.3 | What is included in the scope of the QMS and what, if anything, is excluded? | Written scope statement; any exclusions justified with reasoning |
| 4.4 | Can you walk me through the key processes in your QMS and how they interact? | Process map or turtle diagram; inputs, outputs, owners and interactions documented |
Clause 5: Leadership
| Clause | Audit question | Evidence to look for |
|---|---|---|
| 5.1 | How does top management demonstrate commitment to the QMS? | Evidence of leadership involvement in management review; quality policy signed by top management; resources allocated |
| 5.2 | Is the quality policy communicated and understood by staff? | Quality policy displayed or accessible; staff can describe it in their own words when asked |
| 5.3 | Are roles, responsibilities, and authorities clearly defined and communicated? | Organization chart; role descriptions or responsibility matrix; staff aware of their own responsibilities |
Clause 6: Planning
| Clause | Audit question | Evidence to look for |
|---|---|---|
| 6.1 | How do you identify and address risks and opportunities relevant to the QMS? | Risk register or equivalent; actions assigned; evidence of review |
| 6.2 | What are your current quality objectives and how are they being measured? | Written objectives with measurable targets, named owners, and timescales; progress data available |
| 6.3 | How do you plan and manage changes to the QMS? | Change control process; evidence that changes are evaluated before implementation |
Clause 7: Support
| Clause | Audit question | Evidence to look for |
|---|---|---|
| 7.1 | How do you ensure the right resources are in place to operate and improve the QMS? | Resource planning records; evidence that infrastructure and environment are maintained |
| 7.2 | How do you manage staff competence? | Competence requirements defined per role; training records; evaluation of training effectiveness |
| 7.3 | How do you ensure staff are aware of the quality policy, objectives, and their contribution? | Induction records; toolbox talks; briefing notes; staff can articulate the policy |
| 7.4 | How is communication managed internally and externally? | Communication plan or equivalent; records of meetings, briefings and customer communications |
| 7.5 | How is documented information created, controlled, updated, and retained? | Document control procedure; version control in place; obsolete documents removed or marked |
Clause 8: Operation
| Clause | Audit question | Evidence to look for |
|---|---|---|
| 8.1 | Are operational processes planned, controlled, and carried out as documented? | Procedures match observed practice; records of outputs available; criteria for acceptance defined |
| 8.2 | How are customer requirements determined and reviewed before acceptance? | Sales or order review process; evidence of customer requirement capture; records of review |
| 8.3 | If applicable, how is the design and development process controlled? | Design plans; review, verification and validation records; change controls |
| 8.4 | How do you control externally provided products, processes, and services? | Approved supplier list; supplier evaluation criteria and records; purchase order controls |
| 8.5 | How do you control production or service delivery? | Work instructions; calibration records; traceability system; records of output |
| 8.6 | How do you ensure products or services meet requirements before release? | Inspection records; release authorization; evidence that criteria are met before sign-off |
| 8.7 | How do you manage nonconforming outputs? | Nonconformity procedure; records of nonconforming items; disposition decisions documented |
Clause 9: Performance Evaluation
| Clause | Audit question | Evidence to look for |
|---|---|---|
| 9.1 | How do you monitor and measure process and product performance? | KPIs and performance data; customer satisfaction data; analysis of trends |
| 9.2 | How is the internal audit program planned and managed? | Audit schedule; auditor competence records; previous audit reports and nonconformity closure |
| 9.3 | Has a management review taken place and what were the outputs? | Management review minutes; agenda covered required inputs; actions assigned with owners and dates |
Clause 10: Improvement
| Clause | Audit question | Evidence to look for |
|---|---|---|
| 10.1 | How does the organization identify and act on improvement opportunities? | Improvement log or equivalent; evidence of actions taken; link to objectives |
| 10.2 | How are nonconformities identified, recorded, and addressed? | Corrective action log; root cause analysis records; evidence that actions are effective; recurrence checked |
| 10.3 | How does the organization demonstrate continual improvement? | Trend data showing improvement; updated objectives; evidence that the QMS evolves in response to findings |
Recording and Reporting Findings
Every internal audit must produce a written report. At minimum, the report should record the audit scope, the dates and areas covered, the auditor's name, the findings (including any nonconformities raised), and the conclusions. ISO 9001 requires this documented information to be retained.
Nonconformities should be graded. A major nonconformity indicates a complete absence of a required element or a systemic breakdown. A minor nonconformity is an isolated or less critical lapse. Observations or opportunities for improvement are findings that do not constitute nonconformities but are worth addressing.
Each nonconformity must be followed up with a corrective action: the immediate fix, a root cause analysis, and a longer-term action to prevent recurrence. The internal audit report and resulting corrective actions must be presented at the next management review meeting.
Common Internal Audit Mistakes to Avoid
- Only auditing documentation and not observing actual practice
- Failing to interview frontline staff, focusing only on managers
- Not retaining adequate records of the audit conversations and findings
- Closing nonconformities without verifying that the corrective action has actually worked
- Auditing the same areas every year and neglecting others
- Conducting the audit too close to the certification body audit, leaving no time to address findings
Timing recommendation. Aim to complete your internal audit at least six to eight weeks before your certification body audit. This gives you time to raise corrective actions, carry out root cause analysis, implement fixes, and gather evidence that the actions have been effective before the external auditor arrives.
