What You Should Know About ISO 9001 Internal Audits
Published May 11, 2026
ISO 9001 internal audits are much more than a compliance check. Done well, they provide an independent look at how your quality management system is actually working – whether processes are being followed, whether controls are effective, and where weaknesses or improvement opportunities are hiding.
Internal audits are also a core ISO 9001 requirement and an important part of preparing for and maintaining certification. In this article, we'll explain how they work, what auditors should look for, and how to turn them into a useful business-improvement tool rather than another bureaucratic exercise.
Distinguishing between Internal and External Audits
To grasp the essence of internal audits, it is important to differentiate them from external audits. While internal and external audit activities may appear similar at first glance, they serve distinct purposes and often have different scopes.
External audits are performed by parties outside your organization. These include certification audits conducted by your certification body, as well as customer or supplier audits. Their purpose and scope depend on the type of audit.
Internal audits, by contrast, are conducted on behalf of your own organization as a management and improvement tool. They may be performed by suitably trained employees or outsourced to an external auditor, but the organization remains responsible for its internal audit program.
The important difference is who the audit is for. A certification auditor determines whether your QMS satisfies the requirements for certification. Your internal auditor should help you find weaknesses first – and ideally identify opportunities to make the business work better.
The Objectives of Internal Audits
Internal audits serve several key objectives, including:
Verify conformity
Determine whether applicable ISO 9001 requirements and your own QMS requirements are being met.
Evaluate effectiveness
Check whether processes and controls are actually producing the intended results – not merely whether employees are following documented steps.
Find weaknesses and improvement opportunities
Look for recurring problems, unnecessary complexity, bottlenecks, weak controls and other opportunities to improve performance.
Prepare for external audits
Identify and correct problems before a certification, surveillance or recertification auditor finds them.
How an ISO 9001 Internal Audit Works
A good internal audit is planned around the process being audited, the applicable requirements, previous results and the areas where the organization most needs reliable information. It should follow the flow of real work rather than become a clause-by-clause inspection.
Plan the Audit
Define the audit scope and criteria, select an appropriate auditor, review relevant background information, and decide where to focus based on process importance, changes, past performance, previous audit results and known risks.
Review Relevant Information
Before and during the audit, review the documents and records needed to understand the process. This may include procedures, process maps, objectives, forms, records, previous findings, corrective actions and performance information.
Audit the Actual Process
A good internal audit follows the flow of actual work rather than marching mechanically through ISO clauses. The auditor observes activities, speaks with employees, reviews records and follows evidence across functions to understand whether the process works as intended.
Because an auditor cannot inspect every transaction, employee or record, sampling is used. The objective isn't to prove perfection; it is to gather enough objective evidence to make a sound assessment.
If there is no documented procedure or work instruction, that does not automatically mean there is a problem. ISO 9001 does not require every activity to be documented. The auditor can evaluate the process through interviews, observation, records and results.
The auditor should not recommend creating a procedure simply because one would make the audit easier. New documentation or controls should be recommended only when they are required, needed for consistency or control, or genuinely useful to the business.
Record Findings and Improvements
Audit findings should clearly distinguish between actual nonconformities and improvement opportunities. Not every better idea is a nonconformity, and auditors should resist turning personal preferences into requirements.
Follow Up
Corrective action doesn't end when a form is completed. Follow up to confirm that the underlying cause was addressed and the action was effective.
Internal Audits Before Certification
Before certification, your internal audit program should provide sufficient coverage to demonstrate that the applicable QMS processes and ISO 9001 requirements have been evaluated.
This may be accomplished through one comprehensive audit or a series of planned audits. The important point is that the internal audit program has been implemented, relevant findings have been addressed, and sufficient evidence is available for the certification body to evaluate.
Don't leave the internal audit until the last possible moment. Conducting it early enough gives your organization time to investigate findings, implement corrective action and verify that the corrections actually work before the certification audit.
Streamlining Your Internal Audit Process
To streamline your internal audit process and ensure a stress-free journey towards compliance, consider the following tips:
Appoint the Right Auditors
Choose individuals who are trustworthy, authoritative, possess good people skills, and have analytical or investigative talents. Select auditors who are sufficiently independent of the work being audited to maintain objectivity and impartiality. In larger organizations this often means using auditors from other departments. In small organizations, complete departmental independence may not be practical, so focus on ensuring auditors do not evaluate work for which they are directly responsible. The necessary knowledge and skills – including familiarity with ISO 9001 and auditing techniques – can be acquired through internal auditor and lead auditor training. Additional guidance on auditor competence is available in ISO 19011.
Use Forms and Checklists
Use audit forms and checklists to provide structure, but don't let the checklist dictate the audit. Build questions around the process being audited and use ISO 9001 requirements as criteria rather than treating the audit as a clause-by-clause inspection. An Audit Report Form can then standardize the recording of findings, improvement opportunities and required follow-up.
Standardize the Audit
Design and standardize the internal audit process, treating it as any other business process. Four simple questions keep the audit focused on both conformity and business value:
Can employees describe what they do?
Do employees do what they describe?
Are employees effective at what they do?
Is there an easier or more reliable way to do it?
These questions cover intent, implementation, effectiveness and improvement. ISO 9000 describes effectiveness as "the extent to which planned activities are realized and planned results are achieved." Look beyond compliance and assess whether processes actually support the organization's objectives.
Hold a Closing Meeting with Auditees
Close the audit with the people responsible for the audited processes and anyone who needs to act on the findings. For a company-wide or pre-certification audit, management participation may be appropriate; for a focused process audit, a short discussion with the relevant process owner may be enough. Keep the discussion balanced by recognizing what works well as well as explaining findings and improvement opportunities.
Get Feedback from Auditees
Gather feedback from auditees to gain insights into their experiences and perspectives. Establish a two-way communication channel, enabling auditees to share their thoughts and suggestions during the audit. Incorporate this feedback into future audits to ensure a fair and balanced internal audit process.
Getting Started with the Internal Audit Program
Someone should take responsibility for planning and maintaining the internal audit program. Depending on the organization's size, this may be a quality manager, another manager, a trained internal auditor or an external provider.
Some organizations conduct one comprehensive annual audit; others divide the QMS into smaller audits throughout the year. The schedule should reflect the importance of the processes, changes affecting the organization, previous audit results and areas where problems or risks warrant closer attention.
Equip the person managing the program with comprehensive lead auditor training where appropriate, and provide members of the internal audit team with practical auditor training. The goal is not just to produce competent auditors, but to build an audit program that gives management useful information and drives improvement.
Conclusion
ISO 9001 internal audits play a vital role in achieving and maintaining ISO 9001 certification while driving overall business improvement. Disregard the myth that internal audits should showcase perfection from the outset, as continuous improvement lies at the heart of ISO 9001. Treat internal audits with the respect they deserve, viewing them as opportunities to enhance your company's operations and reap the rewards of ISO 9001.
Some organizations outsource their internal audits because they lack suitable internal auditors; others do it deliberately to gain a fresh, independent perspective or avoid tying up internal resources. Many also use an external lead auditor annually before a surveillance or recertification audit.
Our ISO 9001 Internal Audit Service provides a complete independent audit, practical consulting and a detailed report with actionable findings. When used as the final pre-certification check, it also includes our Certification Guarantee.