Introduction: ISO 9001 Internal Audit
An ISO 9001 internal audit is one of the most valuable tools an organisation can use to check the health of its quality management system (QMS). While the word “audit” may sound daunting, internal audits are not about catching people out — they are about identifying opportunities to improve, ensuring compliance, and making sure processes are running as effectively as possible.
If your business is certified to ISO 9001:2015, conducting regular internal audits is not optional. They are a requirement of the standard, designed to provide assurance that your QMS is functioning as intended and supporting continual improvement.
What is an ISO 9001 Internal Audit?
In simple terms, an internal audit is a structured review carried out within your organisation to test whether your processes comply with ISO 9001 requirements.
Unlike an ISO 9001 external audit (conducted by a certification body), an internal audit is performed by your own trained auditors or by a competent external consultant hired to act on your behalf.
An ISO 9001 internal audit will typically:
- Assess whether processes meet ISO 9001 requirements
- Check that company policies and procedures are being followed
- Identify gaps, weaknesses, or nonconformities
- Highlight opportunities for improvement
Internal audits are not just about compliance. They help your organisation stay agile, improve efficiency, and ensure customer satisfaction.
Why are ISO 9001 Internal Audits Important?
Carrying out internal audits offers a wide range of benefits, beyond simply “ticking the box” for certification.
Benefits include:
- Ensuring compliance with ISO 9001:2015 requirements
- Providing evidence of conformity to customers and stakeholders
- Identifying risks and areas where processes may break down
- Supporting continual improvement and innovation
- Helping prepare for external certification audits
- Increasing employee engagement and accountability
Internal audits act as a health check for your ISO 9001 QMS — ensuring that your business is not only compliant but also continuously improving.
The ISO 9001 Internal Audit Process
To make an internal audit effective, it needs to follow a structured approach. According to ISO 19011 (the international guidelines for auditing management systems), the process typically includes:
Steps in the audit process:
- Planning the audit – defining the scope, criteria, and schedule
- Selecting auditors – ensuring auditors are competent and independent
- Conducting the audit – gathering objective evidence through interviews, observation, and reviewing records
- Reporting findings – documenting nonconformities, observations, and positive practices
- Corrective actions – ensuring issues are addressed and improvements made
- Follow-up – checking that corrective actions have been effectively implemented
When carried out properly, this process ensures your audit is fair, transparent, and useful to the organisation.
Roles and Responsibilities in Internal Auditing
A successful ISO 9001 internal audit depends on having the right people involved at every stage. It isn’t just about assigning someone to tick boxes — it’s about ensuring the audit team has the competence, independence, and confidence to ask the right questions and evaluate processes fairly.
The effectiveness of an audit often comes down to the preparation and professionalism of the people carrying it out, as well as the openness of those being audited.
Key roles include:
- Internal Auditor – plans and conducts the audit, collects evidence, and reports findings
- Lead Auditor – oversees the audit programme, ensures consistency, and mentors other auditors
- Auditee – the person or team being audited; provides information and records
- Top Management – reviews results and ensures corrective actions are taken
To maintain impartiality, auditors should not audit their own work. Many organisations train staff across different departments so they can audit each other, ensuring independence while building a stronger culture of quality.
How to do an internal audit for ISO 9001?
An ISO 9001 internal audit checks how well your organisation’s quality management system (QMS) is working and whether it meets the standard’s requirements.
The sequence below follows a practical, process-based approach aligned with ISO 19011 guidance, using UK spelling and plain language so teams can pick it up and run with it.
- Plan the audit programme
Define the annual audit programme based on risks, previous findings, process performance, customer feedback and regulatory needs. Prioritise high-risk or change-heavy areas first. - Set the scope, objectives and criteria
For each individual audit, confirm what’s in scope (sites, processes, shifts), why you’re auditing (objectives), and the criteria (ISO 9001 clauses, your own procedures, KPIs). - Appoint competent, independent auditors
Choose auditors trained in ISO 9001 and audit techniques who are independent of the activities being audited. Assign a lead auditor to coordinate. - Prepare the audit plan
Schedule dates, processes, people to interview and time blocks. Share the plan with auditees early so they can prepare records and key staff. - Review documents and data
Before “fieldwork”, read relevant procedures, process maps, risk registers, previous audit reports, nonconformity logs, complaints and KPI trends to focus your sampling. - Tailor your checklist
Build a process-based checklist that follows inputs → activities → outputs → performance measures, rather than clause-by-clause only. Keep it flexible to follow evidence. - Hold the opening meeting
Confirm scope, objectives, methods, timings, the grading of findings (e.g., major/minor nonconformity, observation, opportunity for improvement) and communication rules. - Gather objective evidence
Use interviews, on-the-job observation and record sampling to test both conformity and effectiveness. Trace requirements end-to-end (e.g., customer order → delivery → feedback). Record what you saw, where, when, and with whom. - Identify and classify findings
Compare evidence with criteria. Raise nonconformities where requirements are not met; log observations and opportunities for improvement where risk or inefficiency exists. - Validate causes with the auditee
Discuss findings to ensure they’re factually correct. Avoid prescribing solutions; focus on causes and risks. - Closing meeting
Summarise what was covered, recap findings with examples, agree initial timelines for corrective actions, and explain next steps for reporting and follow-up. - Issue the audit report
Document scope, team, methods, sampled evidence, findings (with clause/process references), and agreed actions. Keep it clear, concise and timely. - Corrective action and root-cause analysis
Auditees analyse root causes (e.g., 5 Whys, fishbone), define SMART corrective actions, assign owners and due dates, and update risks where relevant. - Verify effectiveness
The auditor (or another independent person) checks that actions were implemented and actually prevent recurrence—not just paper fixes. Close findings when evidence shows effectiveness. - Retain records and feed management review
Keep audit plans, reports, nonconformity logs and verification evidence. Present trends, recurring issues and improvement results into management review. - Improve the audit programme
Use feedback, KPIs and lessons learned to refine auditor training, sampling depth, checklists and scheduling for the next cycle.
Done well, this step-by-step flow turns the ISO 9001 internal audit from a once-a-year tick-box into a continuous source of insight. Keep the tone collaborative, follow the process trail rather than just documents, and always verify that actions work in practice—not only on paper.
Common Audit Findings & Corrective Actions
During an ISO 9001 internal audit, auditors may come across a range of findings. These are usually grouped into three categories:
- Nonconformities – where a requirement is not met (e.g., missing records, outdated procedures)
- Observations – potential weaknesses that may lead to problems if not addressed
- Opportunities for improvement – suggestions to make processes more efficient or effective
When nonconformities are raised, organisations must take corrective action. This means identifying the root cause, fixing the issue, and ensuring it does not happen again. For example:
- If a calibration record is missing → corrective action may include updating the procedure and retraining staff.
- If customer complaints are not being tracked → a new complaints log system may need to be introduced.
Corrective actions should always focus on long-term prevention, not just short-term fixes. Instead of only addressing the immediate problem, organisations should look at the root cause to stop the issue from happening again. This approach not only resolves the nonconformity but also strengthens the overall quality management system.
Having the right tools makes the ISO 9001 internal audit process much smoother and more effective. Well-prepared resources help auditors stay organised, ensure nothing important is overlooked, and provide clear evidence of compliance.
The right tools also make it easier for teams to track findings, follow up on corrective actions, and demonstrate improvements over time.
Useful tools and documents include:
- Audit checklist – Build a tailored checklist that aligns with your organisation’s processes and ISO 9001 clauses
- Audit plan – scope, objectives, and schedule of the audit
- Audit report template – to ensure consistent reporting of findings
- Nonconformity report (NCR) – for documenting and tracking corrective actions
- Records of previous audits – to check progress and trends over time
These documents not only help the auditor stay organised but also provide evidence for external certification bodies.
Supporting Standards & Guidelines
While ISO 9001 sets out the requirements for quality management systems, internal audits are supported by other standards and guidelines:
- ISO 19011 – provides detailed guidance on auditing management systems
- ISO 9001 clauses – particularly Clause 9.2, which specifies the requirements for internal audits
- Management review – another ISO 9001 requirement, which uses audit results as inputs to ensure top management is actively involved
Together, these standards create a robust framework for ensuring your audits are meaningful and effective.
Best Practices for Effective ISO 9001 Internal Audits
To get the most value from your ISO 9001 internal audits, it helps to go beyond simply meeting the minimum requirements of the standard.
By following proven best practices, you can transform audits from a compliance task into a genuine driver of improvement and efficiency across the organisation. Consider the following approaches:
- Train auditors thoroughly, including on interview skills and report writing
- Encourage a culture of openness — audits are for improvement, not blame
- Focus on process effectiveness, not just compliance
- Use risk-based thinking to prioritise audit areas
- Follow up on corrective actions to ensure lasting improvement
By adopting these practices, internal audits become less of a chore and more of a strategic tool. Instead of being seen as an obligation, they can provide valuable insights, strengthen processes, and support long-term business success.
Conclusion
An ISO 9001 internal audit is far more than a compliance exercise. Done well, it provides powerful insights into your quality management system, highlights opportunities for improvement, and ensures your organisation is always ready for external ISO 9001 certification.
By planning carefully, using the right tools, and focusing on continual improvement, internal audits can drive real value — strengthening processes, building customer trust, and supporting long-term success.



