Internal audit is the requirement most organisations meet in form and miss in substance. ISO 9001:2015 clause 9.2 requires internal audits at planned intervals to determine whether the quality management system conforms and is effectively implemented and maintained. Many internal audits confirm that documents exist and stop there. This article gives you an ISO 9001 internal audit checklist organised by clause, with the questions and evidence that tend to reveal real issues, and explains how to plan and run the programme around it.

What clause 9.2 actually requires

  • An audit programme — frequency, methods, responsibilities, planning requirements and reporting — that takes into account the importance of the processes, changes affecting the organisation and the results of previous audits
  • Defined audit criteria and scope for each audit
  • Auditors selected so that the audit is objective and impartial — in practice, people do not audit their own work
  • Results reported to relevant management
  • Correction and corrective action taken without undue delay
  • Documented information retained as evidence of the programme and its results

ISO 19011:2018, Guidelines for auditing management systems, is the reference for how to do this well. It is guidance rather than a requirement, but it describes the principles and methods certification body auditors also work to.

Planning the internal audit programme

Audit the processes, not the clauses. A process-based audit of purchasing, for example, will test clauses 6.1, 7.1.5, 7.2, 7.5, 8.4, 9.1 and 10.2 as they apply to purchasing, which is how the system actually works. Use the clause checklist below as a cross-reference to make sure the programme covers every requirement over the year, not as the order in which to ask questions.

Weight the programme by risk. Processes with high customer impact, recent changes, repeated complaints or previous findings should be audited more often or in more depth than stable, low-risk ones. A programme that audits every process once a year with equal effort is not wrong, but it is rarely the best use of your auditors.

The ISO 9001 internal audit checklist

ClauseQuestion to askEvidence to sample
4.1, 4.2When were context and interested party requirements last reviewed, and what changed as a result?Context review record; a risk, objective or decision that it influenced
4.3Does the scope match what the organisation actually does, including sites and any non-applicable requirements?Scope statement; justification for any requirement determined not applicable
4.4Are the processes, their inputs, outputs, owners and measures defined?Process map or equivalent; a process owner who can explain their measures
5.1, 5.3Can top management describe the quality objectives and the results of the last management review?Interview with top management; assigned roles and authorities
5.2Is the quality policy communicated and understood where the work is done?Interviews with staff at different levels
6.1What risks and opportunities were identified for this process and were the actions effective?Risk register entry; evidence of action and its evaluation
6.2Are objectives measurable, owned, monitored and reviewed?Objective records with targets, owners and current results
6.3How was the last significant change to the system planned?Change record showing purpose, consequences, resources and responsibilities
7.1.5Is measuring equipment calibrated or verified, identified and protected?Calibration records for instruments seen in use; action taken when found out of tolerance
7.1.6What happens to process knowledge when an experienced person leaves?Knowledge capture, training material, succession or handover records
7.2, 7.3How is competence determined, achieved and its effectiveness evaluated?Competence matrix; training records; evaluation of effectiveness for a sampled person
7.5Are documents at the point of use current and are records retained and protected?Documents observed in use compared with the master list
8.2How are customer requirements reviewed before commitment, including changes?Sampled orders or contracts with evidence of review and amendment
8.3Where design applies, are inputs, reviews, verification, validation and changes controlled?Design file for a recent project
8.4How are external providers selected, evaluated and monitored, including outsourced processes?Approved supplier list; evaluation records; controls on a sampled outsourced process
8.5Is work carried out under controlled conditions, with identification and traceability where required?Observation of work; work instructions; traceability for a sampled product
8.6, 8.7How is release authorised and what happens to nonconforming output?Release records; nonconforming product log and disposition records
9.1How is customer satisfaction monitored and how is data analysed and used?Satisfaction data; analysis and actions arising
9.2Was the internal audit programme followed and were auditors independent of the work audited?Audit programme; reports; auditor assignments
9.3Did the last management review cover all required inputs and produce decisions?Management review minutes; outputs and actions
10.2Were root causes determined and corrective actions verified as effective?Sampled corrective action records from start to closure

Running the audit

Follow the trail

The most effective internal audit technique is tracing: pick a real customer order, a real complaint or a real batch and follow it through every process it touched, checking the records at each step. Trails find the gaps between processes, which is where most problems sit, and they are much harder to prepare for than a list of questions.

Ask open questions and observe

"Show me how you do this" and "what happens when" produce better evidence than "do you follow the procedure?" Watch the work being done, compare it with the documented method, and note both conformity and the places where practice and documentation differ — sometimes the practice is better and the document should change.

Write findings that can be acted on

A good finding states the requirement, the evidence observed and why the evidence does not meet the requirement. "Calibration not done" is a note. "Clause 7.1.5.2 requires measuring equipment to be calibrated at specified intervals; the torque wrench in use at assembly station 3 was 47 days past its calibration due date" is a finding that someone can investigate and fix.

After the audit

  1. Report findings to the relevant process owner and management promptly
  2. Agree correction and corrective action with the process owner, who owns the fix — not the auditor
  3. Track actions to closure and verify effectiveness after enough time has passed to show whether the problem recurs
  4. Feed audit results and trends into management review, as clause 9.3.2 requires
  5. Use the results to adjust next year’s audit programme

Internal auditors do not need to be full-time specialists, but they do need to be trained. If your team would benefit from structured internal auditor training, see our training calendar or talk to our team about in-house courses.