\n\n","wordCount":2699,"timeToRead":"PT10M","keywords":["iso 9001 internal audit checklist","how to conduct iso 9001 internal audit","iso 9001 clause 9.2","internal audit programme iso 9001","iso 9001 auditor competence","industria","blog","RAG","IA","inteligencia artificial"]}
Industry

ISO 9001 Internal Audit Checklist: How to Prepare and Conduct One

IgeraIndustria Quality Team
August 13, 2026
10 min read
Internal auditor using a checklist to conduct an ISO 9001 Clause 9.2 internal audit on the shop floor

IgeraIndustria Quality Team  ·  Updated 2026-08-13  ·  10 min read

Direct answer

An ISO 9001 internal audit under Clause 9.2 has five stages: (1) build an annual audit programme covering every process at least once, weighted by risk and past results; (2) plan each individual audit with defined criteria and scope; (3) run the audit — opening meeting, evidence gathering by interview/observation/document sampling, closing meeting; (4) write the audit report and log findings as nonconformities or observations; (5) verify that corrections and corrective actions are implemented and effective. This article is the step-by-step execution guide — for what Clause 9 requires conceptually across 9.1-9.3, see our Clause 9 explainer.

Plenty of quality managers understand what Clause 9.2 requires on paper but freeze the first time they actually have to run an audit: how do you open it, what do you ask, how many records do you sample, and what turns an observation into a nonconformity? This checklist walks through the mechanics an auditor actually needs on the day, not just the clause text.

Step 1 — Build the annual audit programme

Clause 9.2.2 requires the organisation to plan, establish, implement and maintain an audit programme that takes into account the importance of the processes concerned, changes affecting the organisation, and the results of previous audits. In practice this means every process in the QMS scope gets audited at least once per certification cycle (most organisations run it annually), with higher-risk or previously nonconforming processes audited more frequently.

  • List every process in scope — pull it directly from your process map or context-of-the-organisation documentation (Clause 4).
  • Weight by risk and history: a process with recurring nonconformities or one that is safety- or customer-critical gets audited more than once a year; a stable, low-risk support process may only need one visit.
  • Assign an auditor to each process respecting independence (see Step 2).
  • Set the calendar — spread audits through the year rather than compressing them into the month before the certification audit; a rushed programme is itself a common finding.
  • Get the programme approved by top management or the quality manager and keep it as documented information — the certification auditor will ask for it directly.

Step 2 — Confirm auditor independence and competence

Two requirements trip up small teams more than any other part of Clause 9.2:

  • Independence: an auditor cannot audit their own work. A production supervisor can audit purchasing, HR, or sales — never the production line they manage day to day. In a small company with few people qualified to audit, this is usually solved by cross-training staff to audit each other's areas, or by contracting an external auditor to cover the processes nobody internally can audit independently.
  • Competence: ISO 9001 requires auditors to be objective and impartial and to have the competence needed to conduct audits — it does not mandate a specific certification such as ISO 9001 lead auditor (ISO 17021). The recommended practical minimum is a 16-24 hour internal auditor course based on the ISO 19011 guideline, plus enough process knowledge of the area being audited to ask meaningful questions and recognise a real gap.

Document who is qualified to audit which processes, and keep the training evidence (course certificate, or a record of mentored audits if trained internally) — auditors are asked for this as often as they ask for it.

Step 3 — Plan the individual audit: criteria and scope

Before walking the floor, every individual audit needs two things defined in writing:

  • Criteria — what you are auditing against: the relevant ISO 9001 clauses plus the organisation's own procedures, work instructions and quality objectives for that process.
  • Scope — which processes, areas, shifts or locations are included, and which are explicitly excluded.

Prepare an audit checklist or question list in advance, built from the criteria — this is what keeps the audit systematic rather than a free-form conversation, and it is what you will annotate with findings on the day.

Sample question structure by audit area

Area What to ask / check Evidence to sample
Process control Does the operator follow the documented work instruction? Can they locate it at the workstation? Current revision on the wall vs master document list.
Competence (7.2) Is this operator trained and evaluated for this task? Training matrix cross-checked against personnel file.
Monitoring (9.1) Is process data actually being collected and reviewed, not just targeted? Recent KPI records with an analysis or decision attached.
Nonconformity (10.2) Was root cause analysed, or just the immediate symptom fixed? Sample of closed NCRs with owner, date and effectiveness check.
Supplier control (8.4) Are critical suppliers evaluated on a defined frequency? Current evaluation record for a sample of critical suppliers.

Step 4 — Run the audit: opening meeting, evidence gathering, closing meeting

Whether it is a two-person internal team or a contracted external auditor standing in, the mechanics of the day follow the same three-part structure certification auditors use, scaled down:

  • Opening meeting (5-10 minutes): confirm scope, criteria, timing and who will be interviewed. Restate that the audit is about the system, not about testing individuals.
  • Evidence gathering: combine three methods — interview staff performing the process, observe the process actually happening, and sample documented information (records, forms, logs). A verbal answer alone ("yes, we always do that") is not evidence; ask to see the record that proves it.
  • Take notes against the checklist as you go, referencing the specific clause and document each finding relates to — this is what turns into the audit report.
  • Closing meeting: summarise what was observed, present preliminary findings (nonconformities, observations, opportunities for improvement) to the process owner before leaving, and agree next steps. No auditee should hear about a finding for the first time in the written report.

A verbal assurance is not audit evidence

The most common internal audit mistake is accepting "we always do it that way" without asking to see the record. Auditors — internal or external — are trained to sample objective evidence, not opinions.

Step 5 — Classify findings correctly

Not every gap found during an internal audit is a nonconformity. Distinguish:

  • Nonconformity: a documented requirement — from ISO 9001 or from the organisation's own procedure — that is not being met, backed by objective evidence.
  • Observation: a potential weakness that is not yet a breach of a requirement but could become one if left unaddressed.
  • Opportunity for improvement: a suggestion that goes beyond compliance — nothing is wrong, but something could work better.

Certification bodies further split nonconformities into major (systemic, or an entire required process missing) and minor (an isolated lapse). Applying the same discipline internally — rather than logging everything as a generic "finding" — makes the corrective action process meaningful and gives management review something concrete to act on under Clause 9.3.

Step 6 — Structure the audit report

Clause 9.2.2 requires audit results to be reported to relevant management and retained as documented information. A usable internal audit report covers, at minimum:

Internal audit report — minimum structure

  1. Audit identification — date, auditor(s), process/area, scope and criteria.
  2. Summary of the audit — who was interviewed, documents reviewed, overall impression.
  3. Findings list — each finding classified (nonconformity / observation / opportunity for improvement), with the specific clause or procedure reference and the objective evidence observed.
  4. Positive findings — what is working well; a report that is 100% negative findings is as suspicious to an auditor as one with none at all.
  5. Conclusion — overall statement on whether the process/area meets the audit criteria.
  6. Distribution — sign-off by the auditor and acknowledgement by the process owner, with the report retained and fed into the corrective action log (Clause 10.2) and the next management review (Clause 9.3.2).

Step 7 — Close the loop: corrections and corrective action

Clause 9.2.2 explicitly requires that management of the area audited take corrections and corrective actions without undue delay, and verify their implementation. This is where internal audits most often lose their value: the finding gets written down, a correction is made, and nobody ever checks whether the corrective action actually worked. Every nonconformity from an internal audit should carry an owner, a target date, and a scheduled effectiveness check — the same discipline covered in our article on why ISO 9001 audits fail on common nonconformities.

The complete checklist in one place

  • ☐ Annual audit programme covers every process, weighted by risk and audit history, and is approved.
  • ☐ Auditor assigned to each process does not audit their own work.
  • ☐ Auditors have documented competence (course certificate or mentored-audit record).
  • ☐ Each individual audit has written criteria and scope before it starts.
  • ☐ A checklist or question list is prepared in advance from the criteria.
  • ☐ Opening meeting held; process owner knows scope and timing.
  • ☐ Evidence gathered via interview, observation and document sampling — not verbal assurance alone.
  • ☐ Closing meeting held; no finding is a surprise in the written report.
  • ☐ Findings correctly classified as nonconformity, observation, or opportunity for improvement.
  • ☐ Report retained as documented information and distributed to relevant management.
  • ☐ Every nonconformity has an owner, a target date, and a scheduled effectiveness check.
  • ☐ Audit results feed the next management review (Clause 9.3.2).

// IgeraIndustria demo — preparing an internal audit

Quality Manager: I'm auditing the purchasing process next week. Pull everything relevant.

IgeraIndustria: Purchasing process (Clause 8.4) — audit prep pack: (1) Procedure PUR-PRO-003, rev. 4, approved 2026-02-10. (2) Supplier evaluation records: 11 of 12 critical suppliers current; ACEROS MARTÍNEZ evaluation is 14 months overdue. (3) Last internal audit of this process: 2025-08-14, one minor nonconformity (missing re-evaluation criteria for new suppliers), closed 2025-09-02, no effectiveness check logged. (4) Open corrective actions linked to this process: none. Recommend sampling the ACEROS MARTÍNEZ file and verifying whether the 2025 corrective action was actually effective.

Frequently asked questions

How long should an internal audit of a single process take?

ISO 9001 does not set a duration. For a small process in an SME, half a day including the opening and closing meeting is typical. Larger or more complex processes, or ones with a history of findings, can take a full day. What matters is that the time is enough to sample real evidence, not just skim the documentation.

Can one person run the entire internal audit programme alone?

Only for the processes they are independent of. A sole quality manager cannot audit their own department's processes with credibility. In very small organisations this usually means contracting an external auditor for a handful of processes each cycle, or training a second internal staff member to audit reciprocally.

What is the difference between this checklist and preparing for the certification audit?

This checklist covers the internal audit your own organisation runs under Clause 9.2, which is a requirement of the standard itself and happens on your own schedule. Preparing for the certification body's Stage 1 and Stage 2 audit is a separate, related exercise — see our guide on preparing for the ISO 9001 certification audit for that process.

Does every internal audit need a formal checklist document?

ISO 9001 does not mandate a specific format, but a written checklist derived from the audit criteria is the practical way to keep the audit systematic, make sure nothing is missed, and give the auditor something to annotate findings against during the visit. It also becomes part of the objective evidence that a real audit — not a conversation — took place.

What happens to findings that never get an effectiveness check?

They are one of the most common nonconformities auditors raise against Clause 9.2 and 10.2 together: a correction was made, but nobody verified whether the root cause was actually eliminated. Certification auditors routinely sample closed internal audit findings specifically to check this.

Stop rebuilding your audit prep pack from scratch every cycle. IgeraIndustria retrieves the exact procedure, record and prior finding for any process before you walk the floor.

Explore IgeraIndustria for ISO 9001

Article reviewed by IgeraIndustria Quality Team, updated 2026-08-13. References: ISO 9001:2015 Clause 9.2 (Internal audit); ISO 19011:2018 Guidelines for auditing management systems. This article does not constitute certification advice — consult your certification body for scheme-specific requirements.

#iso 9001 internal audit checklist#how to conduct iso 9001 internal audit#iso 9001 clause 9.2#internal audit programme iso 9001#iso 9001 auditor competence

COMPARTIR

Comparte el conocimiento con tu red