An internal audit is a first-party audit — your organisation auditing itself against the standard, your own requirements, and applicable regulations.
Every ISO management system standard requires one. In ISO 9001 it is clause 9.2.
What the standard actually asks for
- A programme covering all processes and clauses over a defined period
- Auditors who are competent and objective — they must not audit their own work
- Criteria and scope defined for each audit
- Results reported to relevant management
- Nonconformities acted on, with records retained
There is no requirement to audit everything every year, and no required frequency. What is required is that the programme accounts for the importance of the processes involved, changes affecting the organisation, and the results of previous audits.
Independence is the sticking point for small organisations
In a twenty-person company the person who knows the purchasing process well enough to audit it is usually the person who runs it. Three legitimate routes: train someone from a different function, swap auditors with another site or a peer company, or use an external auditor. Using a consultant for internal audits is common and permitted — it is certification that must be independent, not internal audit.
The failure that matters
An internal audit programme that never finds anything. Auditors read that as either a system nobody is really examining or findings being suppressed. A real audit finds real things, and a clean report every single cycle invites more scrutiny, not less.