Internal audit is the requirement most organisations meet in form and miss in substance. ISO 9001:2015 clause 9.2 requires internal audits at planned intervals to determine whether the quality management system conforms and is effectively implemented and maintained. Many internal audits confirm that documents exist and stop there. This article gives you an ISO 9001 internal audit checklist organised by clause, with the questions and evidence that tend to reveal real issues, and explains how to plan and run the programme around it.
What clause 9.2 actually requires
- An audit programme — frequency, methods, responsibilities, planning requirements and reporting — that takes into account the importance of the processes, changes affecting the organisation and the results of previous audits
- Defined audit criteria and scope for each audit
- Auditors selected so that the audit is objective and impartial — in practice, people do not audit their own work
- Results reported to relevant management
- Correction and corrective action taken without undue delay
- Documented information retained as evidence of the programme and its results
ISO 19011:2018, Guidelines for auditing management systems, is the reference for how to do this well. It is guidance rather than a requirement, but it describes the principles and methods certification body auditors also work to.
Planning the internal audit programme
Audit the processes, not the clauses. A process-based audit of purchasing, for example, will test clauses 6.1, 7.1.5, 7.2, 7.5, 8.4, 9.1 and 10.2 as they apply to purchasing, which is how the system actually works. Use the clause checklist below as a cross-reference to make sure the programme covers every requirement over the year, not as the order in which to ask questions.
Weight the programme by risk. Processes with high customer impact, recent changes, repeated complaints or previous findings should be audited more often or in more depth than stable, low-risk ones. A programme that audits every process once a year with equal effort is not wrong, but it is rarely the best use of your auditors.
The ISO 9001 internal audit checklist
| Clause | Question to ask | Evidence to sample |
|---|---|---|
| 4.1, 4.2 | When were context and interested party requirements last reviewed, and what changed as a result? | Context review record; a risk, objective or decision that it influenced |
| 4.3 | Does the scope match what the organisation actually does, including sites and any non-applicable requirements? | Scope statement; justification for any requirement determined not applicable |
| 4.4 | Are the processes, their inputs, outputs, owners and measures defined? | Process map or equivalent; a process owner who can explain their measures |
| 5.1, 5.3 | Can top management describe the quality objectives and the results of the last management review? | Interview with top management; assigned roles and authorities |
| 5.2 | Is the quality policy communicated and understood where the work is done? | Interviews with staff at different levels |
| 6.1 | What risks and opportunities were identified for this process and were the actions effective? | Risk register entry; evidence of action and its evaluation |
| 6.2 | Are objectives measurable, owned, monitored and reviewed? | Objective records with targets, owners and current results |
| 6.3 | How was the last significant change to the system planned? | Change record showing purpose, consequences, resources and responsibilities |
| 7.1.5 | Is measuring equipment calibrated or verified, identified and protected? | Calibration records for instruments seen in use; action taken when found out of tolerance |
| 7.1.6 | What happens to process knowledge when an experienced person leaves? | Knowledge capture, training material, succession or handover records |
| 7.2, 7.3 | How is competence determined, achieved and its effectiveness evaluated? | Competence matrix; training records; evaluation of effectiveness for a sampled person |
| 7.5 | Are documents at the point of use current and are records retained and protected? | Documents observed in use compared with the master list |
| 8.2 | How are customer requirements reviewed before commitment, including changes? | Sampled orders or contracts with evidence of review and amendment |
| 8.3 | Where design applies, are inputs, reviews, verification, validation and changes controlled? | Design file for a recent project |
| 8.4 | How are external providers selected, evaluated and monitored, including outsourced processes? | Approved supplier list; evaluation records; controls on a sampled outsourced process |
| 8.5 | Is work carried out under controlled conditions, with identification and traceability where required? | Observation of work; work instructions; traceability for a sampled product |
| 8.6, 8.7 | How is release authorised and what happens to nonconforming output? | Release records; nonconforming product log and disposition records |
| 9.1 | How is customer satisfaction monitored and how is data analysed and used? | Satisfaction data; analysis and actions arising |
| 9.2 | Was the internal audit programme followed and were auditors independent of the work audited? | Audit programme; reports; auditor assignments |
| 9.3 | Did the last management review cover all required inputs and produce decisions? | Management review minutes; outputs and actions |
| 10.2 | Were root causes determined and corrective actions verified as effective? | Sampled corrective action records from start to closure |
Running the audit
Follow the trail
The most effective internal audit technique is tracing: pick a real customer order, a real complaint or a real batch and follow it through every process it touched, checking the records at each step. Trails find the gaps between processes, which is where most problems sit, and they are much harder to prepare for than a list of questions.
Ask open questions and observe
"Show me how you do this" and "what happens when" produce better evidence than "do you follow the procedure?" Watch the work being done, compare it with the documented method, and note both conformity and the places where practice and documentation differ — sometimes the practice is better and the document should change.
Write findings that can be acted on
A good finding states the requirement, the evidence observed and why the evidence does not meet the requirement. "Calibration not done" is a note. "Clause 7.1.5.2 requires measuring equipment to be calibrated at specified intervals; the torque wrench in use at assembly station 3 was 47 days past its calibration due date" is a finding that someone can investigate and fix.
After the audit
- Report findings to the relevant process owner and management promptly
- Agree correction and corrective action with the process owner, who owns the fix — not the auditor
- Track actions to closure and verify effectiveness after enough time has passed to show whether the problem recurs
- Feed audit results and trends into management review, as clause 9.3.2 requires
- Use the results to adjust next year’s audit programme
Internal auditors do not need to be full-time specialists, but they do need to be trained. If your team would benefit from structured internal auditor training, see our training calendar or talk to our team about in-house courses.