Skip to content

ISO Glossary

Internal audit

A first-party audit of your own management system, conducted by you. Required by every ISO management system standard, and the mechanism that finds problems before a certification body does.

An internal audit is a first-party audit — your organisation auditing itself against the standard, your own requirements, and applicable regulations.

Every ISO management system standard requires one. In ISO 9001 it is clause 9.2.

What the standard actually asks for

  • A programme covering all processes and clauses over a defined period
  • Auditors who are competent and objective — they must not audit their own work
  • Criteria and scope defined for each audit
  • Results reported to relevant management
  • Nonconformities acted on, with records retained

There is no requirement to audit everything every year, and no required frequency. What is required is that the programme accounts for the importance of the processes involved, changes affecting the organisation, and the results of previous audits.

Independence is the sticking point for small organisations

In a twenty-person company the person who knows the purchasing process well enough to audit it is usually the person who runs it. Three legitimate routes: train someone from a different function, swap auditors with another site or a peer company, or use an external auditor. Using a consultant for internal audits is common and permitted — it is certification that must be independent, not internal audit.

The failure that matters

An internal audit programme that never finds anything. Auditors read that as either a system nobody is really examining or findings being suppressed. A real audit finds real things, and a clean report every single cycle invites more scrutiny, not less.

All glossary terms