ISO internal audit checklist
Internal audit is where an ISO management system proves it is real. Every ISO management-system standard — 9001, 14001, 45001 — requires internal audits at planned intervals. Here is how to run one that improves the system rather than just generating paper.
The steps
1. Build the audit programme
Plan which parts of the system and which sites you will audit over the year, risk-weighted so the important and the shaky areas are covered more often. In practice, programmes are planned so that every part of the system is covered within the audit cycle.
2. Plan the individual audit
Set the scope, criteria (the relevant standard and your own procedures) and objectives. Pick an auditor who is competent and independent of the area being audited. Give people notice of what you will look at.
3. Gather objective evidence
Audit against reality, not just documents: interview people, watch the process, and sample records. Ask open questions and follow the trail — an internal audit is a check that the system is lived, not a paperwork tick.
4. Record findings and non-conformances
Classify what you find — conformity, opportunity for improvement, minor or major non-conformance — with the objective evidence for each, referenced to the clause or procedure it relates to.
5. Corrective action and closure
Each non-conformance needs root-cause analysis, a corrective action with an owner and a date, and verification that the action was effective before it is closed. This is where audits earn their keep.
6. Feed management review
Roll the results up so management review sees audit outcomes, trends and open actions, and can make decisions and allocate resources.
Where it lives
The audit programme, each audit's findings, the non-conformances and the corrective actions all need to be recorded and tracked to closure — which is exactly the audit and corrective-action loop at the heart of a management system. Read more on corrective actions and non-conformances, and how it all rolls into your ISO compliance system.
Run internal audits that close the loop
Schedule audits, capture findings, raise corrective actions and track them to verified closure — with the audit trail behind it.
Compliance audit software →FAQs
Who can carry out an internal audit?
Anyone competent and, crucially, independent of the area they are auditing — you cannot audit your own work. Smaller organisations often cross-audit between functions or use an external party to act as their internal auditor.
How often should we internal-audit?
Often enough that every part of the system is covered within your audit cycle (commonly a year), risk-weighted so higher-risk or weaker areas get audited more frequently. Internal audits must happen at planned intervals.
What's the difference between an internal audit and the certification audit?
The internal audit is your own check that the system works; the certification (external) audit is carried out by a certification body to grant or maintain your certificate. Doing the internal audits well is the best preparation for the external one.
Related: corrective actions & non-conformances, preparing for a certification audit, and what is an IMS.