How to Conduct Internal Audits for Quality Management?

Table of Contents

Internal audits are an essential part of an effective Quality Management System (QMS). They help organizations determine whether their processes are working as intended, identify nonconformities, evaluate risks, and uncover opportunities for improvement.

A well-planned internal audit is more than a compliance exercise. It provides management with an independent view of how effectively processes are being implemented and whether they continue to support organizational objectives.

Whether your organization follows ISO 9001, ISO 14001, ISO 45001, ISO 13485, IATF 16949, or another quality management system standard, structured management system internal audits can help maintain compliance and improve process performance. For guidance on auditing management systems, organizations can also refer to ISO 19011:2026, which covers audit principles, managing audit programs, conducting management system audits, and auditor competence.

What Is an Internal Audit?

An internal audit is a systematic and documented process used to evaluate whether an organization’s processes and management system conform to defined requirements.

Auditors typically compare actual practices against:

  • Applicable ISO or industry standards
  • Internal policies and procedures
  • Work instructions and documented processes
  • Regulatory and legal requirements
  • Customer requirements
  • Organizational objectives and KPIs

The goal is not simply to find problems. An effective internal audit determines whether the management system is implemented, effective, and capable of achieving its intended results.

Why Are Internal Audits Important?

Regular internal audits provide organizations with valuable insight into their processes and controls.

Maintain Compliance: Internal audits help organizations identify gaps against applicable standards and regulatory requirements before they become major compliance issues.

Identify Nonconformities: Audits can reveal issues such as missing records, outdated procedures, incomplete training, ineffective corrective actions, or processes that are not being followed.

Evaluate Process Effectiveness: A process may technically comply with a procedure but still fail to deliver the expected results. Auditing helps determine whether processes are actually effective.

Reduce Operational Risk: Early identification of weaknesses allows organizations to address risks before they result in product defects, customer complaints, safety incidents, or regulatory problems.

Support Continual Improvement: Audit findings provide valuable input for corrective actions, process improvements, management reviews, and risk management.

How to Conduct an Internal Audit?

The internal audit process generally follows a structured cycle:

Plan → Prepare → Conduct → Report → Correct → Verify → Improve

Let’s look at each internal audit step.

Step 1: Define the Audit Objectives

Before starting an audit, clearly determine what you want the audit to accomplish.

Possible objectives include:

  • Evaluating conformity with ISO 9001 requirements
  • Assessing compliance with internal procedures
  • Reviewing the effectiveness of a manufacturing process
  • Evaluating supplier controls
  • Checking corrective action effectiveness
  • Assessing regulatory compliance
  • Identifying process risks and improvement opportunities

Clear objectives help auditors stay focused and make the audit results more useful.

Step 2: Define the Audit Scope

The audit scope establishes the boundaries of the audit.

It should specify:

  • Processes or departments being audited
  • Locations covered
  • Products or services involved
  • Applicable standards and requirements
  • Relevant time period
  • Activities included or excluded

For example, an internal audit may focus specifically on purchasing and supplier management, rather than auditing the entire QMS.

Step 3: Develop an Audit Program

Organizations should establish an internal audit program based on their processes, risks, previous audit results, and business priorities. Not every process necessarily requires the same level of audit attention. High-risk or historically problematic processes may require more frequent or detailed audits.

A structured risk management process can help organizations identify and prioritize areas that require greater audit attention.

An audit program may include:

Audit AreaFrequencyRisk Level
Document ControlAnnualMedium
ProductionTwice per yearHigh
Supplier ManagementAnnualHigh
TrainingAnnualMedium
CalibrationAnnualHigh
CAPAQuarterlyHigh


The audit program should also consider previous nonconformities and whether corrective actions were effective.

ISO 19011:2026 provides guidance on managing audit programs and conducting management system audits, including considerations for audit planning and auditor competence.

Step 4: Select Qualified Auditors

Auditors should have appropriate knowledge, skills, and experience.

An auditor should understand:

  • The applicable management system standard
  • Audit principles and techniques
  • Relevant organizational processes
  • Applicable regulatory requirements
  • Risk-based thinking
  • Evidence evaluation
  • Reporting and communication

Maintain Auditor Independence

Whenever possible, auditors should not audit their own work.

For example, a Quality Manager who directly owns the document-control process should ideally not be the sole auditor responsible for evaluating that same process.

Independence improves objectivity and credibility. ISO 19011:2026 also provides guidance on auditor competence and the evaluation and development of auditors.

Step 5: Review Relevant Documents

Before conducting the audit, review the information relevant to the audit scope.

This may include:

  • Policies
  • Procedures
  • Work instructions
  • Previous audit reports
  • Nonconformance records
  • CAPA records
  • Risk assessments
  • Training records
  • Customer complaints
  • Process KPIs
  • Management review outputs
  • Previous corrective actions

This preparation allows auditors to identify areas that deserve additional attention. It also helps confirm that employees are working with current procedures and controlled information, which can be particularly important where organizations face challenges in document control.

Step 6: Prepare an Audit Checklist

An audit checklist helps auditors organize their assessment and ensure important requirements are covered. A good checklist should not simply contain questions copied from the standard. It should connect requirements to actual organizational processes. An ISO 9001 internal audit checklist can provide a useful starting point for organizing these requirements and areas of evidence.

For example, instead of simply asking:

“Is employee competence maintained?”

The auditor could examine:

  • How are competency requirements defined?
  • How are employees trained?
  • How is training effectiveness evaluated?
  • What happens when an employee is found to be incompetent?
  • Are training records complete and current?
  • Are competency gaps reflected in the organization’s risk assessment?

A checklist should guide the audit rather than restrict the auditor’s investigation.

Step 7: Conduct the Opening Meeting

Begin the audit with a short opening meeting involving relevant personnel.

Explain:

  • Audit objectives
  • Audit scope
  • Audit criteria
  • Audit schedule
  • Audit methods
  • Roles and responsibilities
  • Expected cooperation
  • How findings will be communicated

The purpose is to establish a clear and professional understanding of the audit.

Step 8: Collect Objective Evidence

Understanding how an internal audit is conducted requires looking beyond documented procedures.

Auditors also need to collect objective evidence rather than relying solely on statements.

Evidence may include:

  • Documents
  • Records
  • Interviews
  • Observations
  • System data
  • Process measurements
  • Photographs where appropriate
  • Transaction histories
  • Electronic records

A useful audit technique is:

Ask → Observe → Verify → Record

For example:

Ask: “How do you control obsolete documents?”

Observe: Review how employees access procedures.

Verify: Check document revision history and approval records.

Record: Document the evidence and determine whether the process conforms to requirements.

The evidence collected should be sufficient to support the conclusions reached in the audit report.

Step 9: Interview Employees

Employee interviews are an important part of internal auditing.

Ask open-ended questions such as:

  • “Can you walk me through this process?”
  • “What do you do when you identify a nonconformance?”
  • “How do you know which procedure is the current version?”
  • “What happens if this equipment is found to be out of calibration?”
  • “How do you escalate a customer complaint?”

Avoid leading questions that encourage employees to give the answer they think the auditor wants.

The objective is to understand how the process actually works.

Step 10: Observe the Actual Process

Documentation tells you how a process should work. Observation shows you how it actually works.

For example, during a production audit, the auditor may observe:

  • Material identification
  • Production instructions
  • Inspection activities
  • Equipment condition
  • Employee practices
  • Product traceability
  • Environmental controls
  • Handling of nonconforming products

This comparison between documented procedures and actual practices can reveal important process gaps.

Step 11: Evaluate Audit Findings

After collecting evidence, evaluate whether the evidence demonstrates conformity or nonconformity.

Typical audit findings include:

Conformity

The process meets the applicable requirement and evidence supports its effective implementation.

Nonconformity

A requirement has not been fulfilled.

For example:

The calibration procedure requires measuring equipment to be calibrated annually. During the audit, equipment ID CAL-024 was found in use with an expired calibration status.

Nonconformities should not simply be recorded and closed. Significant findings may need to move into a corrective action process, creating a connection between audit findings and CAPA so that the underlying cause can be addressed and recurrence prevented.

Observation

An issue that may not constitute a formal nonconformity but deserves attention.

Opportunity for Improvement

A process may meet requirements but could potentially be made more effective or efficient.

Organizations should clearly distinguish between these categories according to their audit methodology.

Step 12: Document Nonconformities Clearly

A good audit finding should be based on evidence and clearly explain the gap. Clear internal audit documentation is essential for showing what was audited, what evidence was reviewed, and why a particular finding was raised.

A useful structure is:

Requirement → Evidence → Gap

For example:

Requirement: The organization’s procedure requires completed training records to be maintained.

Evidence: Training records for three employees assigned to the production line did not contain documented effectiveness evaluations.

Gap: The required training effectiveness evaluation was not consistently implemented.

Avoid vague findings such as:

“Training process needs improvement.”

Specific findings are much easier to investigate and correct.

Step 13: Conduct the Closing Meeting

At the end of the audit, communicate the results to relevant personnel.

Discuss:

  • Audit scope and objectives
  • Positive findings
  • Nonconformities
  • Observations
  • Opportunities for improvement
  • Required corrective actions
  • Expected timelines
  • Follow-up activities

Findings should be discussed based on objective evidence rather than personal opinions.

Step 14: Prepare the Audit Report

The internal audit report should provide a clear record of what was audited and what was discovered.

A typical report includes:

  • Audit date
  • Audit scope
  • Audit objectives
  • Audit criteria
  • Auditors
  • Audited departments/processes
  • Evidence reviewed
  • Findings
  • Nonconformities
  • Observations
  • Opportunities for improvement
  • Overall conclusion
  • Required follow-up actions

A strong report should allow management to quickly understand the condition of the audited process.

Step 15: Initiate Corrective Actions

When a nonconformity is identified, the organization should determine its root cause rather than simply correcting the immediate problem. Appropriate corrective actions should address the underlying cause.

For example:

Problem: A required inspection record was missing.

Correction: Complete the missing record where appropriate.

Root Cause Investigation: Why was the record not completed?

Possible causes could include:

  • Unclear responsibility
  • Poorly designed form
  • Lack of training
  • Ineffective supervision
  • System usability issues
  • Process design weakness

The corrective action should address the underlying cause.

For recurring or significant issues, a structured root cause analysis can help determine why the problem occurred and how to prevent recurrence.

Step 16: Verify Corrective Action Effectiveness

Closing a corrective action does not necessarily mean the problem has been solved.

The organization should verify whether the corrective action actually prevented recurrence.

For example:

A training program was revised after repeated documentation errors. Three months later, the organization reviews new records to determine whether the errors have actually decreased.

If the problem continues, further investigation may be necessary.

Common Internal Audit Mistakes to Avoid

Even organizations with mature QMS processes can make mistakes during internal audits.

Auditing Only for Compliance: An audit that focuses entirely on checking clauses may overlook process effectiveness and business risks.

Using a Checklist Without Investigation: Simply checking “Yes” or “No” against a checklist does not constitute an effective audit.

Focusing Only on Documentation: A procedure can look perfect on paper while the actual process operates differently.

Treating Every Issue as a Major Nonconformity: Findings should be classified objectively based on evidence and applicable requirements.

Accepting Verbal Explanations Without Evidence: Statements from employees should be verified through records, observations, or other objective evidence where appropriate.

Failing to Follow Up: An audit has limited value if findings are documented but corrective actions are never verified for effectiveness.

Auditing the Same Areas the Same Way Every Time: Audits should evolve based on risks, previous findings, process performance, complaints, incidents, and organizational changes.

How Technology Can Improve Internal Audits

Traditional internal audits often involve spreadsheets, paper checklists, email communication, and manually maintained reports.

A digital QMS can centralize and automate many parts of the audit process. Audit management software can help organizations manage audit schedules, plans, checklists, findings, corrective actions, follow-up activities, and audit reports in one system.

With an audit management system, organizations can manage:

  • Audit schedules
  • Audit plans
  • Auditor assignments
  • Audit checklists
  • Evidence
  • Findings
  • Nonconformities
  • Corrective actions
  • Follow-up audits
  • Audit reports
  • Audit dashboards
  • Supplier audits

Integration with other QMS processes can provide even greater visibility. For organizations evaluating software, factors such as audit scheduling, checklist management, finding tracking, corrective action workflows, reporting, and integration with other QMS processes should be considered when choosing audit management software.

For example:

Audit Finding → NCR → Root Cause Analysis → CAPA → Effectiveness Verification

This creates a traceable workflow from identifying a problem to confirming that it has been resolved.

QISS QMS includes Audit Management alongside connected processes such as Document Control, Nonconformance, CAPA, and Risk Management. Its audit functionality is designed to support planning, execution, analysis, and follow-up within the broader QMS.

Dashboards can also help management monitor metrics such as:

  • Open audit findings
  • Overdue findings
  • Findings by department
  • Recurring findings
  • CAPA effectiveness
  • Audit completion rate
  • Audit trends
  • Risk-related findings

Internal Audit Best Practices

To make internal audits more effective:

  1. Use a risk-based audit approach.
  2. Focus on process effectiveness, not just documentation.
  3. Use objective evidence.
  4. Interview employees at different levels.
  5. Observe actual work practices.
  6. Connect audit findings to organizational risks.
  7. Investigate recurring findings carefully.
  8. Track corrective actions to completion.
  9. Verify corrective action effectiveness.
  10. Use audit trends to support management decisions.
  11. Maintain auditor competence and independence.
  12. Use digital tools to improve traceability and visibility.

Final Thoughts

Internal audits should not be viewed simply as a requirement for maintaining ISO certification. When conducted effectively, they become a powerful management tool for understanding how well an organization’s processes are performing.

The most effective approach goes beyond asking “Are we compliant?”

It asks:

Are our processes working?

Are risks being controlled?

Are problems recurring?

Are corrective actions effective?

Are our processes helping us achieve our business and quality objectives?

By following a structured audit process, from planning and evidence collection through reporting, corrective action, and effectiveness verification, organizations can turn internal audits into a continuous improvement mechanism.

For organizations managing multiple standards, departments, sites, auditors, and corrective actions, a digital QMS with ISO 9001 management software can further simplify audit management by bringing the entire audit lifecycle into one centralized platform.

Request a demo of QISS QMS to see how you can manage audits, findings, corrective actions, and other quality processes in one connected system.

Related Articles:

About The Author
All Categories
Latest Posts
Optimizing Sample Intake, Processing, and Disposal Workflows
Implementing a Health & Safety Management System During Rapid Organizational Growth
Documentation and Record-Keeping Best Practices for Lab Samples
How to Present Health & Safety Findings and Investment Value to Executives
Risk Management Strategies for Sample Loss or Misidentification
Post Side Banner QMS
Post Side Banner LIMS
Post side Banner ISO Management
Scroll to Top