Step 3 — Plan the individual audit: criteria and scope
Before walking the floor, every individual audit needs two things defined in writing:
- Criteria — what you are auditing against: the relevant ISO 9001 clauses plus the organisation's own procedures, work instructions and quality objectives for that process.
- Scope — which processes, areas, shifts or locations are included, and which are explicitly excluded.
Prepare an audit checklist or question list in advance, built from the criteria — this is what keeps the audit systematic rather than a free-form conversation, and it is what you will annotate with findings on the day.
Sample question structure by audit area
| Area |
What to ask / check |
Evidence to sample |
| Process control |
Does the operator follow the documented work instruction? Can they locate it at the workstation? |
Current revision on the wall vs master document list. |
| Competence (7.2) |
Is this operator trained and evaluated for this task? |
Training matrix cross-checked against personnel file. |
| Monitoring (9.1) |
Is process data actually being collected and reviewed, not just targeted? |
Recent KPI records with an analysis or decision attached. |
| Nonconformity (10.2) |
Was root cause analysed, or just the immediate symptom fixed? |
Sample of closed NCRs with owner, date and effectiveness check. |
| Supplier control (8.4) |
Are critical suppliers evaluated on a defined frequency? |
Current evaluation record for a sample of critical suppliers. |
Step 4 — Run the audit: opening meeting, evidence gathering, closing meeting
Whether it is a two-person internal team or a contracted external auditor standing in, the mechanics of the day follow the same three-part structure certification auditors use, scaled down:
- Opening meeting (5-10 minutes): confirm scope, criteria, timing and who will be interviewed. Restate that the audit is about the system, not about testing individuals.
- Evidence gathering: combine three methods — interview staff performing the process, observe the process actually happening, and sample documented information (records, forms, logs). A verbal answer alone ("yes, we always do that") is not evidence; ask to see the record that proves it.
- Take notes against the checklist as you go, referencing the specific clause and document each finding relates to — this is what turns into the audit report.
- Closing meeting: summarise what was observed, present preliminary findings (nonconformities, observations, opportunities for improvement) to the process owner before leaving, and agree next steps. No auditee should hear about a finding for the first time in the written report.
A verbal assurance is not audit evidence
The most common internal audit mistake is accepting "we always do it that way" without asking to see the record. Auditors — internal or external — are trained to sample objective evidence, not opinions.
Step 5 — Classify findings correctly
Not every gap found during an internal audit is a nonconformity. Distinguish:
- Nonconformity: a documented requirement — from ISO 9001 or from the organisation's own procedure — that is not being met, backed by objective evidence.
- Observation: a potential weakness that is not yet a breach of a requirement but could become one if left unaddressed.
- Opportunity for improvement: a suggestion that goes beyond compliance — nothing is wrong, but something could work better.
Certification bodies further split nonconformities into major (systemic, or an entire required process missing) and minor (an isolated lapse). Applying the same discipline internally — rather than logging everything as a generic "finding" — makes the corrective action process meaningful and gives management review something concrete to act on under Clause 9.3.
Step 6 — Structure the audit report
Clause 9.2.2 requires audit results to be reported to relevant management and retained as documented information. A usable internal audit report covers, at minimum:
Internal audit report — minimum structure
- Audit identification — date, auditor(s), process/area, scope and criteria.
- Summary of the audit — who was interviewed, documents reviewed, overall impression.
- Findings list — each finding classified (nonconformity / observation / opportunity for improvement), with the specific clause or procedure reference and the objective evidence observed.
- Positive findings — what is working well; a report that is 100% negative findings is as suspicious to an auditor as one with none at all.
- Conclusion — overall statement on whether the process/area meets the audit criteria.
- Distribution — sign-off by the auditor and acknowledgement by the process owner, with the report retained and fed into the corrective action log (Clause 10.2) and the next management review (Clause 9.3.2).
Step 7 — Close the loop: corrections and corrective action
Clause 9.2.2 explicitly requires that management of the area audited take corrections and corrective actions without undue delay, and verify their implementation. This is where internal audits most often lose their value: the finding gets written down, a correction is made, and nobody ever checks whether the corrective action actually worked. Every nonconformity from an internal audit should carry an owner, a target date, and a scheduled effectiveness check — the same discipline covered in our article on why ISO 9001 audits fail on common nonconformities.
The complete checklist in one place
- ☐ Annual audit programme covers every process, weighted by risk and audit history, and is approved.
- ☐ Auditor assigned to each process does not audit their own work.
- ☐ Auditors have documented competence (course certificate or mentored-audit record).
- ☐ Each individual audit has written criteria and scope before it starts.
- ☐ A checklist or question list is prepared in advance from the criteria.
- ☐ Opening meeting held; process owner knows scope and timing.
- ☐ Evidence gathered via interview, observation and document sampling — not verbal assurance alone.
- ☐ Closing meeting held; no finding is a surprise in the written report.
- ☐ Findings correctly classified as nonconformity, observation, or opportunity for improvement.
- ☐ Report retained as documented information and distributed to relevant management.
- ☐ Every nonconformity has an owner, a target date, and a scheduled effectiveness check.
- ☐ Audit results feed the next management review (Clause 9.3.2).
// IgeraIndustria demo — preparing an internal audit
Quality Manager: I'm auditing the purchasing process next week. Pull everything relevant.
IgeraIndustria: Purchasing process (Clause 8.4) — audit prep pack: (1) Procedure PUR-PRO-003, rev. 4, approved 2026-02-10. (2) Supplier evaluation records: 11 of 12 critical suppliers current; ACEROS MARTÍNEZ evaluation is 14 months overdue. (3) Last internal audit of this process: 2025-08-14, one minor nonconformity (missing re-evaluation criteria for new suppliers), closed 2025-09-02, no effectiveness check logged. (4) Open corrective actions linked to this process: none. Recommend sampling the ACEROS MARTÍNEZ file and verifying whether the 2025 corrective action was actually effective.
Frequently asked questions
How long should an internal audit of a single process take?
ISO 9001 does not set a duration. For a small process in an SME, half a day including the opening and closing meeting is typical. Larger or more complex processes, or ones with a history of findings, can take a full day. What matters is that the time is enough to sample real evidence, not just skim the documentation.
Can one person run the entire internal audit programme alone?
Only for the processes they are independent of. A sole quality manager cannot audit their own department's processes with credibility. In very small organisations this usually means contracting an external auditor for a handful of processes each cycle, or training a second internal staff member to audit reciprocally.
What is the difference between this checklist and preparing for the certification audit?
This checklist covers the internal audit your own organisation runs under Clause 9.2, which is a requirement of the standard itself and happens on your own schedule. Preparing for the certification body's Stage 1 and Stage 2 audit is a separate, related exercise — see our guide on preparing for the ISO 9001 certification audit for that process.
ISO 9001 does not mandate a specific format, but a written checklist derived from the audit criteria is the practical way to keep the audit systematic, make sure nothing is missed, and give the auditor something to annotate findings against during the visit. It also becomes part of the objective evidence that a real audit — not a conversation — took place.
What happens to findings that never get an effectiveness check?
They are one of the most common nonconformities auditors raise against Clause 9.2 and 10.2 together: a correction was made, but nobody verified whether the root cause was actually eliminated. Certification auditors routinely sample closed internal audit findings specifically to check this.
Stop rebuilding your audit prep pack from scratch every cycle. IgeraIndustria retrieves the exact procedure, record and prior finding for any process before you walk the floor.
Explore IgeraIndustria for ISO 9001
Continue reading — ISO 9001 series
Article reviewed by IgeraIndustria Quality Team, updated 2026-08-13. References: ISO 9001:2015 Clause 9.2 (Internal audit); ISO 19011:2018 Guidelines for auditing management systems. This article does not constitute certification advice — consult your certification body for scheme-specific requirements.