Audits & Certification

Preparing Internal Audits per ISO 9001: The Ultimate Checklist

Most “internal audit checklists” online are generic project-management advice with a norm number bolted on. This one isn’t. It walks through what ISO 9001:2015 §9.2 and ISO 19011:2018 actually require, separates “requirement” from “good practice,” and ends with a condensed checklist you can hold your own audit programme against.

What §9.2 Actually Requires - and What It Doesn’t

§9.2.1 states why internal audits exist: to confirm the QMS conforms to your own requirements and to ISO 9001, and that it is effectively implemented and maintained. §9.2.2 states how: plan, establish, implement, and maintain an audit programme including frequency, methods, responsibilities, planning requirements, and reporting; define audit criteria and scope for each audit; select auditors who ensure objectivity and impartiality; report results to relevant management; take correction and corrective action without undue delay; and retain documented information as evidence.

Everything beyond that - sampling technique, interview style, tooling - is good practice, not a clause requirement. Knowing the difference matters when an external auditor asks “how do you know this satisfies 9.2,” because “we’ve always done it this way” isn’t an answer to that question.

Building the Audit Programme

  • Risk- and change-based frequency (ISO 19011 §5.2). A process with a recent nonconformity, new equipment, a new hire in a critical role, or a supplier change should be audited more often than “once a year, every year, regardless.” Frequency driven purely by a fixed calendar is the single most common finding auditors write against §9.2.2.
  • Coverage matrix. Track which clauses and which processes have been audited in the current certification cycle. When the certification body asks “how do you know your programme covers everything,” this matrix is the answer - not a verbal assurance.
  • Programme-level criteria vs. audit-level criteria. The programme defines scope and frequency across the whole QMS; each individual audit then narrows criteria down to the specific clauses, procedures, and legal/customer requirements relevant to that process.

Auditor Independence and Competence (§9.2.2c)

Auditors must not audit their own work. The failure mode that shows up repeatedly in small QM teams: the quality manager who owns the CAPA process also audits the CAPA process. It’s not malicious - it’s usually the only person with time and training - but it’s precisely the objectivity gap §9.2.2c exists to close. If your team is too small to avoid this entirely, document the mitigation (e.g., a peer review of that specific audit) rather than ignoring the conflict.

Competence per ISO 19011 §7 is two-dimensional: knowledge of the standard and knowledge of the process or technical domain being audited. An auditor who knows ISO 9001 well but has never worked in procurement will miss things a procurement-literate auditor catches immediately - and vice versa. Pairing auditors across domains is a cheap fix that most programmes skip.

Preparing the Individual Audit (ISO 19011 §6.3)

  • Define audit criteria precisely: which clauses, which internal SOPs, which customer or legal requirements apply to this process - not the QMS in general.
  • Turn criteria into working documents - a checklist and a question catalog. Building a catalog that actually surfaces objective evidence (rather than yes/no answers) is its own discipline; see our audit question catalog guide for the process-based method.
  • Confirm logistics before the day itself: opening meeting agenda, who needs to be available, sampling plan, and time allocated per process based on its risk ranking - not split evenly regardless of risk.

qportal ties criteria directly to a hierarchical audit criteria catalog, so every planned audit inherits the right clauses and linked questions instead of someone rebuilding the list from scratch each cycle.

During the Audit: Sampling and Evidence, Not Accusation

Objective evidence must be verifiable (ISO 19011 §6.4.4) - records, direct observation, or statements corroborated from an independent source. A single interview answer is not evidence on its own; if a process owner says “we always do X,” the audit needs a record or a second, independent confirmation before it counts as a finding either way.

Every finding should trace back to a specific clause or criterion. This isn’t bureaucracy for its own sake - it’s what makes the finding defensible when the same nonconformity resurfaces in the external audit and someone asks “did we already know about this.”

Classifying and Closing Findings

  • Nonconformity vs. observation/opportunity for improvement. Classifying everything as “major” to look thorough erodes the credibility of the classification system - and makes real majors harder to distinguish.
  • Root cause vs. symptom. A checklist item that says “corrective action written” is not the same as “root cause documented.” See our CAPA process article for the distinction and the methods (5 Whys, Ishikawa, FMEA) that actually get you to a systemic cause.
  • Effectiveness verification is not optional (§10.2.2). An audit isn’t closed when the action is marked “done” - it’s closed when someone confirms, after a defined period, that the nonconformity hasn’t recurred.

Evaluating the Audit Programme Itself

§9.2.2 and ISO 19011 §6.6 both call for periodically evaluating the programme, not just individual audits: is coverage actually complete, are auditors performing consistently, are the same findings recurring across cycles despite corrective actions. Most QM teams never take this step - which is unfortunate, because it’s one of the cheapest ways to demonstrate programme maturity to an external auditor who asks about it directly.

The Checklist

Planning

  • Audit programme covers frequency, methods, responsibilities, and reporting
  • Frequency is risk- and change-based, not purely calendar-based
  • Coverage matrix shows every clause/process audited within the cycle

Preparation

  • Audit criteria defined per audit: clauses, SOPs, legal/customer requirements
  • Auditor assigned has no conflict of interest with the audited process
  • Auditor competence matches both the standard and the technical domain
  • Question catalog and checklist prepared from the criteria, not generic
  • Opening meeting agenda and sampling plan set in advance

Execution

  • Evidence corroborated from records or independent sources, not single statements
  • Every finding linked to a specific clause or criterion

Reporting

  • Findings classified consistently (nonconformity / observation / OFI)
  • Root cause distinguished from symptom for every nonconformity
  • Corrective action owner and deadline documented

Follow-up

  • Effectiveness verified after a defined period, not just “action closed”
  • Prior audit’s open actions confirmed closed before this audit starts

Programme review

  • Coverage, auditor performance, and recurring findings evaluated at least annually

Conclusion

A checklist only works if it’s tied to what the clause actually says. Programmes that separate requirement from good practice, that assign auditors deliberately instead of by availability, and that verify effectiveness rather than just closing actions walk into their external audit with evidence already organized - not assembled under time pressure during the audit itself.