ISO Internal Audit Guide: How to Conduct an Effective Audit

By July 25th, 2026ISO Audit And Certificate9 min read

ISO Internal Audit Guide: How to Conduct an Effective Internal Audit

An internal audit is a systematic, independent examination of your management system to verify it conforms to the requirements of the standard, your own procedures and applicable regulations. It is a mandatory requirement before certification and a scheduled requirement throughout the certification cycle. Done well, it prepares you for external audit and drives continual improvement.

Published: July 2026  |  Last updated: July 2026  |  Author: Bitrixme Compliance Team

What an Internal Audit Is (and Is Not)

Every ISO management system standard that requires certification also requires the organisation to conduct internal audits at planned intervals. This is not optional. Clause 9.2 of ISO 9001, ISO 27001, ISO 14001 and ISO 45001 all require the organisation to conduct internal audits, retain documented information as evidence and take corrective action on findings.

The internal audit serves a different purpose from the external certification audit. Understanding the distinction affects how you plan, conduct and respond to each.

AspectInternal AuditExternal (Certification) Audit
Who conducts itYour own staff or an external consultantAuditors from an accredited certification body
PurposeIdentify gaps, drive improvement, prepare for external auditVerify conformity and decide whether to issue or maintain certification
ScopeFull or partial, chosen by the organisationThe full scope of the certified management system
FrequencyAt least annually; many organisations conduct audits quarterly or by processStage 1 and Stage 2 for initial certification; surveillance annually; recertification every three years
Auditor independenceMust be independent of the area being auditedIndependent of the organisation entirely
OutcomeNonconformity report, corrective actions, management review inputCertification decision, certificate issue, surveillance or recertification
ConfidentialityInternal to the organisationThe certification body holds audit records under defined terms

Audit Planning

An internal audit programme must be planned, not improvised. The standard requires an audit programme that takes into account the importance of the processes concerned and the results of previous audits. The following steps should be followed.

  1. Define the audit programme for the year. Identify which processes, departments or locations will be audited, at what frequency and by whom. Higher-risk processes and areas with previous nonconformities should be audited more frequently.
  2. Select and assign auditors. Auditors must be competent and independent of the area they audit. A quality manager can audit the HR department but cannot audit their own quality management processes.
  3. Prepare audit plans for each audit. Each individual audit needs a plan covering objectives, scope, criteria, timing, team composition and the list of documents to review. Share the plan with the auditee at least one week in advance.
  4. Prepare audit checklists. A checklist ensures consistent coverage of each clause or requirement. Checklists should be based on the standard, the organisation’s procedures and the results of previous audits.
  5. Schedule opening and closing meetings. Every audit must begin with an opening meeting to confirm scope and logistics, and end with a closing meeting to present findings.

Audit Checklist by Standard

The checklist structure follows the clauses of the standard. Below is a summary of the key areas to cover for the most common ISO standards.

StandardKey Clauses to AuditTypical Evidence to Examine
ISO 90014 (Context), 5 (Leadership), 6 (Planning), 7 (Support), 8 (Operation), 9 (Evaluation), 10 (Improvement)Quality policy, objectives, risk register, training records, process records, internal audit reports, management review minutes, corrective actions
ISO 270014 to 10 (same structure) plus Annex A controlsISMS scope, SoA, risk treatment plan, security policies, access control records, incident reports, business continuity tests, supplier security assessments
ISO 450014 to 10 plus operational planning and control for OH&SOH&S policy, hazard identification records, risk assessments, legal register, incident reports, emergency drill records, worker consultation records
ISO 140014 to 10 plus environmental aspects and legal complianceEnvironmental policy, aspects and impacts register, legal register, operational controls, waste management records, emergency preparedness records, compliance evaluation results
ISO 220004 to 10 plus PRPs and HACCP principlesFood safety policy, PRP records, hazard analysis, HACCP plan, CCP monitoring records, verification records, traceability tests, recall records

A comprehensive checklist maps each clause to the specific documents, records or observations that provide evidence of conformity. General checklists are available, but the most valuable checklist is one adapted to your organisation’s processes and documented procedures.

Conducting the Audit

An effective internal audit follows a consistent methodology. The auditor gathers evidence through three techniques: document review, observation and interview. Each technique serves a different purpose and no single technique is sufficient on its own.

Document Review

Review the documented information that establishes the management system: policies, procedures, work instructions, process maps and records. Check that documents match the approved versions, that records are complete and current, and that the document control system is functioning as designed.

Observation

Walk through operations and observe whether actual practice matches documented procedures. Observation is the most reliable form of audit evidence because it reveals what actually happens, not what the procedure says should happen. An operator who follows an undocumented workaround while a formal procedure sits unused in a binder is a common finding.

Interview

Interview staff at all levels. Ask process operators how they perform their work, what training they received, what they do if something goes wrong and how they know the process is working correctly. Compare their answers with the documented procedure. Management interviews should cover objectives, risk awareness, resource adequacy and review of performance data.

The auditor must record all evidence objectively. Observations, not interpretations, form the basis of audit findings. A useful internal audit finding states the requirement (the clause), the evidence (what was observed or read) and the gap (how the evidence does not meet the requirement).

  • Nonconformity description. A factual statement of what was found. “The internal audit schedule for 2025 shows no audits conducted in Q3, contrary to the requirement for audits at planned intervals.”
  • Clause reference. The specific clause of the standard that the finding relates to. “ISO 9001:2015 clause 9.2.2(a).”
  • Classification. Major or minor. A major nonconformity is a significant failure that affects the ability of the management system to achieve its intended results. A minor nonconformity is an isolated lapse that does not affect system integrity.
  • Root cause. The underlying cause, not the symptom. Root cause analysis tools such as 5 Whys or fishbone diagrams should be applied.
  • Corrective action. The specific action to eliminate the root cause and prevent recurrence, with an owner and deadline.
  • Verification. How and when the effectiveness of the corrective action will be verified.
  • Status of actions from previous management reviews
  • Changes in external and internal issues relevant to the management system
  • Information on management system performance, including customer feedback, process performance and product conformity
  • Internal and external audit results
  • Adequacy of resources
  • Effectiveness of actions taken to address risks and opportunities
  • Opportunities for improvement
  • Knowledge of the standard. The auditor must understand the clauses, their intent and the interaction between them. Training on the specific standard is essential before conducting audits.
  • Audit principles and techniques. The auditor should understand evidence gathering, sampling, interviewing, questioning techniques and documentation of findings. Formal internal auditor training provides this foundation.
  • Knowledge of the organisation’s processes. The auditor must understand how the organisation’s processes work, the risks associated with each process and the regulatory context in which the organisation operates.
  • Impartiality and objectivity. The auditor must be able to set aside assumptions and preconceptions, and to report findings factually regardless of relationships or pressures.
  • Communication skills. The auditor must interview effectively, present findings clearly and write nonconformity reports that are precise and actionable.

How often should we conduct internal audits?

The standards require internal audits at planned intervals. Most organisations conduct a full audit cycle annually, with individual processes or departments audited on a rotating schedule throughout the year. Higher-risk processes should be audited more frequently. A quarterly audit cycle is common for medium to large organisations.

Can the same person audit the whole system?

No. Auditors must be independent of the activity being audited. One person cannot audit their own work. For a small organisation with limited staff, independence can be achieved by having auditors from different departments audit each other’s areas, or by engaging an external internal auditor.

What is the difference between a major and minor nonconformity?

A major nonconformity is a significant failure that affects the ability of the management system to achieve its intended results, such as a key process not being implemented or a complete failure to address a clause requirement. A minor nonconformity is an isolated lapse that does not affect system integrity, such as a single incomplete record or a procedural deviation that has not caused a systemic problem.

Do we need internal audit training before conducting audits?

Yes. Internal auditors need training on the specific standard, audit techniques and interviewing skills. Most organisations send at least two staff members on an ISO internal auditor course to build internal capability. The training cost is modest compared with the cost of engaging external auditors for every audit cycle.

What records must be retained from internal audits?

The organisation must retain documented information as evidence of the implementation of the audit programme and the audit results. This includes the annual audit programme, individual audit plans, completed audit checklists, nonconformity reports, corrective action records and evidence of verification of corrective actions.

Can an external consultant conduct our internal audit?

Yes. Engaging an external consultant to conduct internal audits is acceptable and common, provided the consultant is independent of the activities being audited and does not have a conflict of interest. The same consultant who helped implement the system can conduct the internal audit, but they cannot audit areas where they provided implementation support that directly affects the evidence being examined.

Need an internal auditor for your organisation? We provide internal audit services and internal auditor training across the GCC. Contact us at bitrixme.com/contact or message us on WhatsApp.