How to Conduct an ISO Internal Audit
A practical guide to running internal audits that find something useful: competence, planning, sampling, writing findings, and how often to audit.
By Julian Russell, Managing Director
Lead Auditor: ISO 9001, ISO 14001, ISO 27001, ISO 45001 and ISO 50001
The short answer. An internal audit checks that your management system is being followed and is working. Every ISO management system standard requires them. Done properly they find problems before the certification body does. Done as a box-ticking exercise a fortnight before the surveillance audit, they find nothing and waste everyone's time.
Internal audits are where management systems either earn their keep or quietly stop meaning anything. This page covers how to run one that is worth doing.
Who is allowed to audit
Whoever conducts the audit needs to demonstrate competence in four areas. Certification bodies do check this, usually by asking to see the auditor's training records.
Auditing capability. How to plan an audit, gather evidence, ask open questions and write up a finding. This is a skill in its own right and it is not obvious.
Knowledge of your management system. The actual policies, procedures and processes in use, not the ones written three years ago.
Knowledge of the standard. The requirements of ISO 9001, ISO 27001 or whichever standard applies, at enough depth to recognise a gap.
Independence from the process. This does not mean employees cannot audit. It means they cannot audit an area they are responsible for managing. In a small organisation this usually means people audit each other's areas, which works perfectly well.
Competence can come from a formal auditor training course, or from tailored internal auditor training delivered against your own system, which many organisations find more useful because the examples are their own.
Planning: the part that determines whether it is useful
Most poor audits are poor because of what happened before anyone walked into a room.
Audit the whole system across the cycle, not every process every time. A programme that covers everything annually is usually the wrong shape. Audit high-risk and high-change areas more often, stable ones less.
Go where the risk is. New processes, areas that have had complaints or non-conformities, anything that changed since the last audit, and anything the certification body raised last time.
Send an agenda in advance. Surprise audits are for television. Telling people what you will look at gets you better evidence and less defensiveness.
Decide your sample before you start. How many records, from which period, chosen how. Deciding afterwards is how you end up with a sample that proves whatever you already thought.
Running the audit
Ask what happens, then ask to see it. The gap between the two is the entire point of the exercise. "Talk me through how you handle a customer complaint" followed by "can you show me the last three" will tell you more than any checklist.
Follow the thread rather than the document. If a procedure says three approvals and the records show one, that is worth more time than the next twelve questions on your list.
Record what you saw, specifically. "Purchase order 4471 dated 12 May was approved by one signatory where the procedure requires two" is a finding. "Approvals process needs improvement" is an opinion, and it will not survive contact with the person who has to fix it.
Distinguish between a non-conformity, where a requirement is not being met, and an opportunity for improvement, where it is being met but could work better. Blurring the two makes both less useful.
Writing it up
A finding needs three things: the requirement, the evidence, and the gap between them. If any of those is missing, the person receiving it cannot act on it.
Report to people who can do something about it. An audit report that goes only to the quality manager changes nothing. Findings need owners and dates, and those need to reach the management review.
Be honest about what you did not look at. An audit report that implies full coverage when you sampled six records from one month is worse than one that states the sample plainly.
How often
The standards require a programme, not a frequency, so there is no universal answer. What determines it:
- Size and complexity. More processes and more sites means more audit days.
- Maturity. A system in its first year needs more attention than one that has run cleanly for five.
- Risk and change. Restructures, new sites, new products and new software all warrant a look.
- Previous findings. Anywhere that generated a non-conformity should be revisited.
The common failure is doing the whole programme in one panicked fortnight before the surveillance visit. It satisfies the letter of the requirement and delivers none of the value, and experienced certification body auditors recognise the pattern immediately.
Spreading audits through the year is less work overall, not more, because problems surface while they are still small.
Doing it yourself or bringing someone in
Both are legitimate. The honest version of the trade-off:
Internal auditors know the business, cost nothing extra, and build capability that stays with you. They are also closer to the work, which can make genuine independence harder, and in small teams finding someone independent of every process is not always possible.
External auditors bring independence, and experience of how other organisations solve the same problems, which is often the most valuable part. They cost money and need time to understand your business.
A common middle path is external auditors for the first cycle or for the higher-risk areas, with internal auditor training so the work can move in-house afterwards.
Where to go next
If you would rather not run the programme yourselves, see our internal auditing service. For building internal capability, see ISO training. Findings that need closing out are covered by non-conformity close-out support.
Frequently asked questions
How often should internal audits be carried out?
The standards require an audit programme rather than a set frequency. The right interval depends on the size and complexity of the organisation, the maturity of the system, how much has changed, and where previous non-conformities arose. Spreading audits through the year works better than completing them all shortly before a surveillance audit.
Can an employee conduct our internal audits?
Yes, provided they are competent in auditing technique, your management system and the relevant standard, and are independent of the area being audited. Independence means not auditing a process you are responsible for managing, not that employees cannot audit at all.
What is the difference between an internal audit and a certification audit?
An internal audit is carried out by or on behalf of your own organisation to check that the system is working. A certification audit is carried out by an accredited certification body and determines whether your certificate is issued or maintained. The certification body will expect to see that internal audits have taken place.
What makes a good audit finding?
Three things: the requirement, the evidence, and the gap between them. A finding that names the record, the date and the specific requirement can be acted on. A general observation that a process needs improvement usually cannot.
Do internal auditors need a formal qualification?
No standard requires a specific certificate, but you must be able to demonstrate competence, and certification bodies do ask for evidence. That can come from a recognised auditor training course or from tailored training delivered against your own management system.
