Troy, Michigan — serving the US / (248) 890-9283
Wilkshire Consulting logo WILKSHIREMANAGEMENT SYSTEMS

ISO 9001 Internal Audits: A Step-by-Step Guide

ISO 9001 Internal Audits: A Step-by-Step Guide
  • 3 days ago
  • 6 min read

An ISO 9001 internal audit is a scheduled, structured check of your own quality management system — done by your own people (or someone you bring in) rather than an outside certification body — to confirm the system is working the way it’s supposed to and to catch problems before your external auditor does. Clause 9.2 of the standard requires them, but the smart way to think about internal audits isn’t “the standard makes me.” It’s “this is the cheapest place to find problems.”

An issue you catch in an internal audit costs you a corrective action. The same issue caught in your certification audit costs you a nonconformity on the record and a scramble to close it before your certificate is at risk. Same problem, very different price tag. Here’s how to run one properly.

Before You Start: Independence Matters

One rule shapes everything else — auditors can’t audit their own work. The person reviewing a process needs to be independent of it. That doesn’t mean you need an outsider for everything; it means the person auditing shipping shouldn’t be the person who runs shipping. Small companies get creative here: cross-train a couple of people to audit each other’s areas, or bring in outside help for the areas where internal independence isn’t realistic. Either way, protect the objectivity — an audit where people grade their own homework isn’t worth running.

Step 1: Plan the Audit Program

Start at the program level, not the individual audit. Clause 9.2 wants you auditing all the processes in your QMS over a defined cycle — usually annually, though higher-risk or historically problematic areas may warrant more frequent attention. Map out which processes get audited when across the year so nothing falls through the cracks and you’re not cramming every audit into the month before recertification.

Risk should drive the schedule. A process that’s caused problems, changed recently, or carries heavy customer impact deserves more frequent, more thorough attention than one that’s been quietly stable for years.

Step 2: Define Scope and Criteria for Each Audit

For each individual audit, get specific about two things:

  • Scope — which process, area, or clauses you’re examining this time. “The whole QMS” is not a scope; “order fulfillment, clauses 8.4 through 8.6” is.
  • Criteria — what you’re auditing against. Usually that’s the relevant clauses of ISO 9001, plus your own documented procedures, plus any customer or regulatory requirements that apply.

Clear scope and criteria are what keep an audit from wandering. They tell everyone — auditor and auditee — exactly what’s on the table.

Step 3: Prepare

Good audits are mostly won before anyone walks the floor. The auditor should review the relevant procedures, look at the results of the last audit of this area (did those findings actually get closed?), check related data like customer complaints or nonconformance records, and build a checklist or set of questions to work through.

That last part matters: a prepared auditor asks specific, evidence-seeking questions. An unprepared one asks “so, everything going okay here?” and learns nothing.

Step 4: Hold an Opening Meeting

Keep it short, but do it. Confirm the scope, the schedule, and who you’ll need to talk to. Set the tone while you’re at it — an internal audit is a shared effort to improve the system, not an inspection to catch people out. When staff feel like they’re being hunted, they hide problems. When they feel like they’re helping find and fix issues, they show you where the bodies are buried. You want the second kind of audit.

Step 5: Gather the Evidence

This is the actual audit. The auditor works through the process collecting objective evidence — not opinions, evidence — through three main methods:

  • Interviews. Ask people to walk you through how they actually do the work. Open-ended questions (“show me how you handle a nonconforming part”) beat yes/no questions every time.
  • Document and record review. Check that records exist, are complete, and match what people described. The gap between “what the procedure says” and “what the records show” is where findings live.
  • Observation. Watch the work happen. Does practice match the documented process?

The golden thread throughout is objective evidence. “I think this is fine” is not a finding. “The procedure requires two signatures and these three records have one” is.

Step 6: Identify and Classify Findings

As you go, you’ll turn up findings. Sort them:

  • Conformity — the process meets the requirement. Worth noting the good, not just the bad.
  • Nonconformity — a requirement isn’t being met. These usually get graded major (a systemic breakdown, or something that puts the QMS’s integrity at risk) or minor (an isolated lapse).
  • Opportunity for improvement — not a violation, but something that could work better. These are gold; they’re the difference between an audit that just polices and one that actually improves the business.

Every finding needs to be backed by the specific evidence and the specific requirement it relates to. Vague findings don’t get fixed.

Step 7: Hold a Closing Meeting

Bring the audited area’s team together and walk through what you found — conformities, nonconformities, and improvement opportunities. No surprises: anything you’re going to write up should already have been discussed when you found it. The closing meeting confirms everyone understands the findings and agrees on what happens next.

Step 8: Report the Results

Document the audit in a clear report: scope, criteria, who was involved, what you found, and the evidence behind each finding. This report feeds two things — the corrective action process, and your management review (Clause 9.3), where leadership looks at audit results across the organization to steer the QMS. Keep it factual and specific. A report nobody can act on is just paperwork.

Step 9: Corrective Action and Follow-Up

This is the step people skip, and it’s the one that actually matters. Findings without follow-through are worse than no audit at all — they prove you knew about a problem and didn’t fix it.

For each nonconformity, the responsible area investigates the root cause (not just the symptom), implements a correction, and puts something in place to stop it recurring. Then someone verifies the action actually worked and closes it out. Track every finding to closure. When your next audit of that area rolls around, the first thing to check is whether last time’s findings stayed fixed.

The Mindset That Makes Internal Audits Worth It

The businesses that get the most out of internal audits treat them as a tool, not a chore. They’re not performing compliance theater for the certification body — they’re using a structured, honest look at their own operation to find problems while they’re cheap to fix. Run that way, internal audits stop being the thing you dread before recertification and start being one of the more useful management tools you’ve got.

Quick answers:

How often do I need to conduct internal audits?

ISO 9001 requires audits at planned intervals covering all QMS processes — commonly on an annual cycle, with higher-risk areas audited more often. The standard doesn’t mandate a fixed frequency; it should be risk-based.

Can employees audit their own department?

No. Auditors must be independent of the area they audit to keep the results objective. Cross-training staff to audit each other’s areas, or using an outside auditor, solves this.

What’s the difference between a major and minor nonconformity?

A major indicates a systemic failure or a breakdown that threatens the QMS’s integrity; a minor is an isolated lapse. Majors typically require more urgent, thorough corrective action.

Do internal auditors need to be certified?

Not formally, but they should be trained and competent in both the audit process and ISO 9001. Many organizations invest in internal auditor training to build that capability in-house.

Not sure whether now’s the right time — or which standard fits? Book a quick call and we’ll help you figure out where you stand.

Next step

Recognise this problem in your own system?

Thirty minutes, free, no obligation. You'll leave knowing where you stand whether or not you hire us.

Call Book free call