A study of 200 aerospace and transportation companies found that internal auditing was the most influential ISO 9001 continual-improvement requirement examined in relation to customer satisfaction, alongside corrective actions.
That finding raises an important question: Are your internal audits actually helping improve your QMS, or are they simply checking boxes?
A well-run internal audit can show whether the QMS is working as intended, where processes are breaking down, and whether corrective actions are producing lasting results. Instead of checking whether procedures exist, auditors examine how work is performed, evaluate objective evidence, identify findings, and use those findings to drive improvement.
This guide covers the QMS internal audit procedure, how to create an effective audit plan, the ISO 9001 audit process step by step, and how audit findings can be used to strengthen the QMS over time.
What Is an ISO 9001 Internal Audit?
An ISO 9001 internal audit is a systematic review of an organization’s QMS conducted by the organization or on its behalf. The purpose is to determine whether the QMS conforms to applicable requirements and is effectively implemented and maintained.
An internal audit may cover specific processes, departments, locations, or QMS requirements. The audit should establish whether:
- Processes are being performed as intended
- Applicable requirements are being followed
- Records and other evidence support conformity
- Previous audit findings have been addressed
- Recurring problems or opportunities for improvement exist
Unlike a certification audit conducted by an external certification body, an internal audit is part of the organization’s own QMS activities. The ISO 9001 Auditing Practices Group describes internal audits as a feedback mechanism that can help identify weaknesses and opportunities for improvement.
For organizations managing multiple quality processes, ISO 9001 software can help bring documented information and related quality activities into a more connected workflow.
Understanding the QMS Internal Audit Procedure
A QMS internal audit procedure defines how an organization plans, conducts, documents, and follows up on its internal audits. It provides a consistent framework so individual audits do not depend entirely on how one auditor approaches the process.
A typical procedure establishes:
- Audit criteria: The requirements against which processes will be evaluated
- Responsibilities: Who plans, conducts, reviews, and follows up on audits
- Audit methods: How evidence will be collected, such as interviews, observation, and record review
- Findings and reporting: How nonconformities and observations are documented and communicated
- Corrective action and follow-up: How findings are addressed and their effectiveness verified
- Audit records: What information is retained as evidence of the audit
The procedure provides the overall framework, while an individual audit plan applies that framework to a specific audit.
How to Create a QMS Internal Audit Plan
An audit plan sets out what will be audited, when it will happen, who will conduct it, and how the audit will be carried out. Effective planning helps auditors focus their time on the processes and areas that matter most.
Define Audit Scope and Objectives
Start by determining the processes, departments, locations, or requirements included in the audit.
The objective should also be clear. For example, an audit may evaluate whether a production process is being followed consistently, whether required records are maintained, or whether corrective actions from a previous audit have been effectively implemented.
Identify Processes and Requirements
Identify the requirements and criteria relevant to the processes being audited. These may include ISO 9001 requirements, internal procedures, work instructions, customer requirements, and applicable regulatory obligations.
Planning around processes rather than simply moving through clauses can help auditors understand how activities interact and where controls are actually applied. The ISO 9001 Auditing Practices Group recommends developing audit plans around processes and considering linked processes together where appropriate.
Select Auditors
Auditors should have the knowledge and competence needed for the processes being assessed. They should also be sufficiently objective and impartial.
Where practical, an auditor should not audit their own work. Separating the person performing a process from the person evaluating it can help reduce conflicts of interest and encourage more objective findings.
Establish the Audit Schedule
Set the audit date, duration, processes to be covered, auditors, and relevant participants.
The schedule should consider process importance, previous findings, organizational changes, and performance. Higher-risk areas or processes with a history of nonconformities may require greater attention.
Organizations should also use previous audit results when planning future audits rather than treating each audit as an isolated event.
These considerations form part of the broader ISO 9001 internal audit requirements that shape an effective audit program.
Prepare Audit Checklists
An audit checklist turns the scope and criteria into practical questions and evidence points.
A useful checklist can include:
- Processes or activities to examine
- Applicable requirements
- Questions for employees
- Documents and records to review
- Process controls to observe
- Previous findings requiring follow-up
A checklist should guide the audit without preventing auditors from following relevant evidence when something unexpected appears.
ISO 9001 Audit Process: Step-by-Step
Once the audit is planned, the audit team can move through the process systematically.
1. Plan the Audit
Confirm the audit objectives, scope, criteria, schedule, auditors, and responsibilities.
Before the audit begins, review relevant procedures, records, previous findings, and corrective actions. This gives auditors context and helps them determine where to focus their attention.
2. Prepare Audit Criteria and Checklist
Translate the audit scope and applicable requirements into practical questions and evidence points.
The focus should be on how requirements are implemented within actual processes, not simply whether a document contains the required wording.
3. Conduct the Opening Meeting
The opening meeting establishes a common understanding of the audit.
Explain the objectives, scope, criteria, schedule, participants, and responsibilities. The meeting is also an opportunity to confirm access to relevant people, processes, locations, and records.
4. Perform Internal Audit of the Process
Examine the process as it actually operates.
Auditors may interview employees, observe activities, review records, examine process outputs, and trace activities from one stage to another. The goal is to understand whether the process is implemented as intended and produces the expected results.
For example, auditing document control should not stop at confirming that a document-control procedure exists. The auditor should examine how documents are approved, updated, distributed, and controlled in practice.
This process-based approach is central to conducting internal audits effectively.
5. Collect Objective Evidence
Audit conclusions should be based on verifiable evidence.
Evidence can come from observation, measurement, records, interviews, or other sources. The ISO 9001 Auditing Practices Group emphasizes that auditors should evaluate evidence objectively against the audit criteria.
A useful way to structure findings is:
Requirement → Actual practice → Evidence → Conclusion
For example, instead of simply stating that employees are not following a procedure, the auditor should identify the relevant requirement, describe what was observed, and document the evidence supporting the finding.
6. Identify Nonconformities and Observations
When evidence shows that a requirement has not been met, document the nonconformity clearly.
A useful finding should identify:
- The applicable requirement
- What was observed
- The objective evidence supporting the finding
- Where or in which process the issue occurred
Relevant observations, conformities, and strengths can also be recorded where they provide useful information about process performance.
7. Conduct the Closing Meeting
The closing meeting communicates the audit results to relevant personnel.
Present the findings clearly, explain the evidence behind them, and confirm the next steps for corrective action and follow-up. Any factual misunderstandings should be clarified before the audit is closed.
8. Prepare the Audit Report
The audit report should provide a clear record of what was audited and what was found.
It can include:
- Audit objectives and scope
- Audit criteria
- Date and duration
- Auditors and participants
- Processes reviewed
- Findings and supporting evidence
- Required corrective actions
- Follow-up requirements
A useful report should make it possible for someone who was not present during the audit to understand what was examined and what requires attention.
9. Follow Up on Corrective Actions
The audit process does not end when the report is issued.
For each relevant finding, the organization should determine the cause, define and implement corrective action, and verify whether the action was effective.
The basic cycle is:
Finding → Root cause → Corrective action → Implementation → Effectiveness verification → Closure
Closing a finding should depend on evidence that the issue has been addressed and that the corrective action has achieved its intended result.
How QMS Internal Audits Improve Quality
Internal audits become more valuable when organizations look for patterns across findings rather than treating each finding as an isolated issue.
For example, repeated findings related to document updates may indicate a weakness in the underlying document-control process. Similarly, if the same type of issue appears after a corrective action has been closed, the organization may need to reassess the root cause or the effectiveness of the action.
Reviewing audit results across processes and audit periods can reveal:
- Recurring nonconformities
- Weak or inconsistent process controls
- Training needs
- Documentation problems
- Corrective actions that are not producing the intended results
- Processes that may require more frequent auditing
This turns the internal audit from a compliance activity into a source of information for QMS improvement.
Common Challenges in ISO 9001 Internal Audits
- Auditing Documents Instead of Processes: A procedure may look complete on paper while the actual process works differently. Auditors should examine how requirements are implemented, not simply confirm that documentation exists.
- Insufficient Objective Evidence: Findings without clear evidence can be difficult to defend or act upon. Auditors should document what they observed, reviewed, or verified.
- Inconsistent Auditor Approach: Different auditors may interpret the same process differently. Consistent criteria, competent auditors, and practical checklists can help improve consistency.
- Recurring Findings: Repeated findings often indicate that corrective actions have addressed symptoms without resolving the underlying cause. Recurring issues should influence future audit planning and corrective-action reviews.
- Treating Audits as a Compliance Exercise: An audit focused only on completing a checklist can miss process weaknesses. The objective should be to understand how the QMS performs in practice and where it can be improved.
Best Practices for Effective QMS Internal Audits
- Audit Processes, Not Just Documentation: Follow the process from inputs to activities, controls, outputs, and records. This helps reveal gaps between documented procedures and actual practice.
- Base Findings on Evidence: Every significant finding should be supported by objective evidence. This makes findings clearer and gives process owners a practical basis for corrective action.
- Prioritize Based on Risk and Performance: Audit time should reflect the importance and performance of processes. Previous findings, changes, recurring problems, and other risk indicators can help determine where additional attention is needed.
- Maintain Auditor Competence and Objectivity: Auditors need sufficient knowledge of both auditing methods and the processes they assess. They should also maintain an objective approach throughout the audit.
- Verify Corrective-Action Effectiveness: Closing an action because it was completed is not the same as confirming that it worked. The organization should verify whether the corrective action actually prevented the problem from recurring. Connecting audit findings to CAPA can help make this part of the improvement cycle more structured.
- Use Results to Plan Future Audits: Audit results should influence future planning. Processes with recurring findings, significant changes, or weaker performance may need greater attention in subsequent audits.
Internal Audit Improvement Process
A practical improvement process connects audit results to corrective action and future planning.
Key activities include:
- Analyze recurring findings: Look for patterns across processes and audit periods.
- Identify root causes: Determine why issues are occurring instead of addressing only their symptoms.
- Track corrective actions: Assign responsibilities and monitor progress toward completion.
- Evaluate effectiveness: Verify that corrective actions have produced the intended result.
- Monitor audit trends: Compare findings and process performance over time.
- Update audit plans: Use findings, changes, and performance information to determine future audit priorities.
The cycle can be summarized as:
Audit → Findings → Corrective Action → Effectiveness → Improvement → Future Audit Planning
When these steps remain connected, audit results are less likely to disappear into separate reports, spreadsheets, or follow-up emails. Audit management software helps keep the audit cycle organized by connecting audit activities, findings, corrective actions, and follow-up in one place.
QMS Internal Audit Checklist
An important part of preparing for an ISO 9001 internal audit is using a checklist to make sure key QMS areas are reviewed consistently. A checklist helps auditors organize requirements, identify areas that need attention, and avoid overlooking important processes or records.
To help assess your QMS before an audit, use QIA’s free:
The checklist can be used alongside your internal audit plan to identify areas that may require closer review, follow up on previous issues, and prepare the QMS for a more effective audit. It should support the audit process rather than replace the auditor’s evaluation of actual processes and objective evidence.
Key Takeaways for Effective QMS Internal Audits
An effective ISO 9001 internal audit starts with a clear procedure and a practical audit plan. Auditors need defined criteria, relevant evidence, and an objective approach to evaluating how processes actually operate.
The process should not end with the audit report. Findings need appropriate corrective action, and corrective actions need effectiveness verification. Recurring issues should also influence future audit planning.
When audits, findings, corrective actions, and follow-up are connected, internal auditing becomes a practical source of information for maintaining and improving the QMS. QISS QMS brings these quality activities into one system, with dedicated workflows for audit management, nonconformance, CAPA, document control, and related quality processes.
Looking to manage these workflows in one system? Request a free demo of QISS QMS.