top of page
bg_3.png
bg_3.png

ISO 9001 Internal Audits Explained Preparation Process and Best Practices

Sep 21
9 min read

An ISO 9001 certificate is not maintained by passing one external audit and then forgetting the system. The real strength of a quality management system comes from routine checks, honest findings, and steady improvement. That is where internal audits play a major role.



An internal audit helps an organization confirm that its processes are working as planned, records are reliable, and customer requirements are being handled consistently. It also helps identify gaps before they become bigger problems during a certification or surveillance audit.


For business owners, managers, quality professionals, and teams new to ISO, internal audits can feel formal or intimidating. They do not need to be. When planned well, they become a practical management tool, not just a compliance activity.


Wide-angle view of a quality inspection checklist on a workshop table
Internal audits work best when records and process evidence are easy to review.

What an ISO 9001 internal audit is and why it matters


An internal audit is a structured review performed by or on behalf of an organization to check whether its quality management system meets planned arrangements, ISO 9001 requirements, and the organization’s own procedures.


In simple terms, it answers three questions:


  • Are we doing what we said we would do?

  • Is our quality system meeting ISO 9001 requirements?

  • Is the system effective in helping us deliver consistent products or services?


ISO 9001 internal audits. are not meant to blame employees or create paperwork for its own sake. Their purpose is to provide evidence, reveal process weaknesses, and support improvement.


A strong internal audit program helps organizations:


  • Detect nonconformities before external auditors find them

  • Confirm that procedures are followed in real work conditions

  • Identify process risks and improvement opportunities

  • Prepare employees for certification and surveillance audits

  • Build confidence in the quality management system


Internal audits also support management review. When leadership has clear audit results, it can make better decisions about staffing, training, supplier performance, customer issues, and process improvement.


A useful internal audit does not only ask whether documents exist. It checks whether the process works in practice.

How to prepare for an ISO 9001 internal audit


Preparation has a direct impact on audit quality. A rushed audit often produces shallow findings. A planned audit gives the team enough time to review the right evidence, speak with the right people, and understand how processes connect.


Define the audit scope


Start by deciding what the audit will cover. The scope may include the full quality management system or selected processes such as purchasing, production, customer service, document control, or corrective action.


A clear scope prevents confusion. It also helps employees understand what the auditor will review.


For example, an audit scope may cover:


  • Customer order review

  • Supplier approval and monitoring

  • Inspection records

  • Handling of nonconforming outputs

  • Corrective action follow-up


The scope should match your audit program, process risks, past audit results, and any major business changes.


Review the audit criteria


Audit criteria are the requirements used as the basis for the audit. These may include ISO 9001:2015 requirements, internal policies, procedures, customer requirements, work instructions, or legal and regulatory obligations that apply to the process.


The auditor should review these criteria before the audit begins. This helps avoid vague questions and keeps the audit focused on evidence.


Build an audit plan


An audit plan should explain when the audit will happen, which areas will be audited, who will participate, and what records may be needed.


A practical plan may include:


  • Audit date and time

  • Process or department being audited

  • Auditor name

  • Process owner or contact person

  • Key documents to review

  • Expected start and close-out times


The plan does not need to be complicated. It just needs to be clear enough for everyone involved.


Select competent auditors


Internal auditors should understand ISO 9001, basic audit methods, and the process being reviewed. They also need objectivity. As a general practice, auditors should not audit their own work.


For smaller companies, this can be challenging. In that case, the organization may train employees from different functions or use an external consultant to support the internal audit program.


Prepare audit questions and checklists


A checklist can help the auditor stay organized, especially when auditing multiple processes. The checklist should not become a script that limits professional judgment.


Good audit questions focus on process performance and evidence. For example:


  • How do you know the latest procedure is being used?

  • What happens when a customer requirement changes?

  • How are inspection results recorded?

  • How do you handle supplier performance issues?

  • Can you show an example of a recent corrective action?


The best questions invite explanation and evidence.


Close-up view of inspection tools beside labeled product samples
Effective preparation connects documents, records, tools, and real process outputs.

ISO 9001 Internal Audits key elements to consider during the audit process


An effective internal audit looks at more than whether a procedure exists. It examines how the process works, how people understand their roles, and whether records support the results.


Process performance


The auditor should review whether the process achieves its intended results. For example, a purchasing process should not only have supplier forms. It should show that suppliers are reviewed, approved, monitored, and addressed when performance problems occur.


Useful evidence may include:


  • Performance indicators

  • Customer feedback

  • Inspection results

  • On-time delivery records

  • Nonconformity logs

  • Corrective action records


Documented information


ISO 9001 uses the term documented information for documents and records. During an audit, the auditor should check whether required information is controlled, available, protected, and suitable for use.


This may include procedures, forms, completed records, process maps, work instructions, training records, and quality objectives.


The goal is not to collect paperwork. The goal is to confirm that the information supports consistent work.


Employee awareness


Employees should understand the parts of the quality system that relate to their work. They do not need to quote ISO clauses. They should be able to explain what they do, how they know requirements, what records they complete, and what happens when something goes wrong.


Simple questions often reveal the most:


  • How do you know what to do?

  • What do you check before completing the task?

  • What happens if the result does not meet requirements?

  • Where do you record the outcome?


ISO 9001 Internal Audits: Nonconformities and corrective actions


When evidence shows a requirement is not met, the auditor should document a nonconformity. The finding should be clear, factual, and linked to a requirement.


A weak finding says, “Records are poor.”


A stronger finding says, “Three completed inspection records from July did not include final acceptance status, although the inspection procedure requires acceptance status before product release.”


Corrective action should address the cause, not just the symptom. If a form was missed, the answer is not always “retrain the employee.” The real cause may be unclear instructions, poor form design, time pressure, or lack of review.


Risk and opportunities


ISO 9001 includes risk-based thinking. Internal audits should consider whether the organization has identified relevant risks and taken suitable action.


This does not require a complex risk register for every activity. It does require sensible thinking about what could affect quality, customer satisfaction, delivery, compliance, and process consistency.


Audit focus

What to look for

Example evidence

Process control

Work is performed as planned

Procedures, work instructions, completed checks

Product or service quality

Requirements are met before release

Inspection records, approvals, customer sign-offs

Competence

People are trained for assigned work

Training records, skill matrices, observed work

Corrective action

Problems are investigated and addressed

Root cause notes, action plans, verification records

Improvement

The system is reviewed and improved

Audit trends, management review outputs, quality objectives


Best practices for conducting an effective internal audit


A good audit depends on preparation, communication, and discipline. The auditor must be thorough without creating fear or unnecessary disruption.


Start with a clear opening conversation


Begin by confirming the audit scope, schedule, purpose, and people involved. Keep it brief and practical.


The opening conversation should make clear that the audit is evidence-based and improvement-focused. This helps reduce anxiety and encourages honest discussion.


Follow the process trail


Instead of reviewing documents in isolation, follow how work moves through the process.


For example, in an order fulfillment audit, start with a customer order. Then review order review, production planning, purchasing, inspection, shipping, and records. This approach shows how departments connect and where handoffs may fail.


Use open questions


Open questions produce better audit evidence than yes-or-no questions.


Strong questions include:


  • Walk me through how this process starts.

  • Show me how you confirm the requirement.

  • What record proves this step was completed?

  • What happens if the result is outside the accepted limit?

  • How do you know this document is current?


These questions encourage employees to explain real practice.


Sample records thoughtfully


Auditors do not need to review every record. Sampling is normal. Select records from different dates, employees, products, services, or suppliers to get a fair view of process performance.


If a problem appears in one sample, review a few more related records to check whether it is isolated or systematic.


Record evidence clearly


Audit notes should be factual. Avoid opinions, vague language, or emotional wording.


Clear evidence may include:


  • Record numbers

  • Dates

  • Procedure names

  • Observed conditions

  • Interview details

  • Specific requirement references


Good notes make it easier to write accurate findings and support corrective action.


Eye-level view of a warehouse shelf with tagged materials and inspection labels
Auditors should review real process evidence where the work happens.

Common internal audit challenges and how to overcome them


Even mature organizations face audit challenges. The key is to recognize them early and build a practical response.


Employees feel nervous about being audited


People may see audits as personal criticism. This can lead to short answers, hidden problems, or resistance.


The solution is to communicate the purpose clearly. Explain that the audit reviews the process, not individual blame. Managers should support openness and avoid reacting harshly to findings.


Audits become checklist exercises


Checklists are useful, but they can make audits mechanical. If the auditor only asks checklist questions, important process issues may be missed.


Use the checklist as a guide, not a limit. Follow evidence. Ask follow-up questions. Look at how the process works from start to finish.


Findings are too vague


Vague findings create weak corrective actions. If the issue is not described clearly, the process owner may not understand what to fix.


Write findings with three parts:


  • The requirement that was not met

  • The evidence reviewed

  • The specific gap found


This structure keeps findings fair and easy to act on.


Corrective actions do not solve the real problem


Some organizations close audit findings quickly but repeat the same issue later. This often happens when corrective action focuses on the immediate error rather than the cause.


To overcome this, ask why the issue happened and whether the same cause could affect other areas. Verify the action after implementation to confirm it worked.


Limited time and resources


Small businesses and growing companies may struggle to schedule audits, train auditors, or review all processes.


A risk-based audit program can help. High-risk or problem-prone processes may need more frequent audits. Stable, low-risk processes may be reviewed less often, as long as the full system is covered according to the organization’s planned audit program.


Internal auditors lack confidence


New auditors may worry about asking the wrong questions or missing requirements. Training helps, but experience matters too.


Pair new auditors with experienced auditors. Review sample findings together. After each ISO 9001 Audit, discuss what went well and what could improve.


FAQ


How often should ISO 9001 internal audits be conducted?


ISO 9001 expects internal audits to be performed at planned intervals. The schedule should reflect process importance, risk, past results, and changes in the organization. Many companies audit key processes at least once per year, but the right frequency depends on the system.


Can an employee conduct an internal audit?


Yes, if the employee is competent and objective. As a best practice, employees should not audit their own work. Smaller organizations may use cross-functional auditors or outside support.


Is an internal audit required before certification?


Yes, organizations seeking ISO 9001 certification should complete internal audits before the external certification audit. Internal audit results help confirm whether the quality management system is ready and where corrective action is needed.


What is the difference between an internal audit and a certification audit?


An internal audit is performed by or for the organization to check its own system. A certification audit is performed by an external certification body to determine whether the organization meets ISO 9001 requirements for certification.


What should happen after an internal audit?


The organization should review findings, assign corrective actions where needed, address root causes, verify effectiveness, and use the results in management review and improvement planning.


Overhead view of a marked quality improvement board with audit notes and process cards
Audit results should lead to clear follow-up and measurable process improvement.

Make internal audits useful, not just required


Internal audits are one of the most valuable tools in an ISO 9001 quality management system. They help organizations see whether processes are controlled, whether employees understand their work, and whether the system supports consistent results.


The best audits are planned, fair, evidence-based, and focused on improvement. They do not rely on intimidation or excessive paperwork. They help leaders make better decisions and help teams correct problems before customers or external auditors find them.


If your organization is preparing for certification or improving an existing quality system, expert support can make the audit process clearer and more effective. Get practical ISO 9001 audit support here.


Treat each internal audit as a learning opportunity. When findings lead to real corrective action and better process control, the quality management system becomes stronger, easier to manage, and more useful to the business.



Comments


bottom of page