Many organisations hold ISO 9001, ISO 14001 and ISO 45001 at the same time, and many of them treat the internal audit as a box to tick before the certification body returns. The audit gets done, the report gets filed, and very little changes. That wastes the one part of the management system that is entirely within your control, and it is usually the part that finds problems early enough to fix them cheaply.

An internal audit that brings value looks different from one that simply satisfies a checklist. It tests the requirements of the standard and the requirements of your own processes, it produces findings written in language the process owner can act on, and it leaves behind a record of opportunities for improvement and good practice that someone actually reads.

What the internal audit requirement actually asks for

The internal audit clause, normally found at clause 9.2, is deliberately light on templates. It asks for a planned and systematic approach rather than a particular form. In practice that means an audit programme which sets out when audits will happen, what will be covered and against what criteria, and it means results are reported to management so decisions can be made.

A sound programme covers the facets of preparing for and conducting audits properly: scope, criteria, frequency, methods, responsibilities and auditor competence. The standards also require auditors to be objective and impartial. If the same person always audits their own area, that requirement is not really met, and the audit quietly stops finding anything uncomfortable.

The three standards ask different questions

The three standards govern distinct areas of performance, even though they share a common structure and are often held together.

Standard

What it governs

ISO 9001

Quality management and customer satisfaction

ISO 14001

Environmental management

ISO 45001

Occupational health and safety

Because organisations frequently hold all three at once, integrated audits are common and can be efficient. The risk is that quality questions dominate the agenda while environmental and health and safety topics get a lighter touch. Plan integrated audits with equal weight, and be ready to split them when an activity needs undivided attention.

Standards are revised periodically and some revisions are in progress, so confirm the edition you are certified against with your certification body before you set audit criteria for the year.

Plan the programme around risk

The audit programme is the annual or multi-year plan. It should be driven by the importance of each process, the risks attached to it, changes in the business and the results of previous audits. A process that has just changed, or a site with a run of incidents, deserves attention sooner rather than later.

  • Map every clause of each standard and every internal process, then record which audit covers what, so nothing slips through the gaps over the cycle.

  • Set the scope precisely. "Operations" is too vague; "goods in, inspection and storage" tells everyone what is in and out.

  • Define the criteria before the audit, covering the standards, your own procedures and any customer or regulatory requirements that apply.

  • Allow enough time. A two hour slot for a complex process almost guarantees a shallow audit.

  • Assign auditors with no responsibility for the area being audited.

Audit the standard and the process together

Two questions need answering in every internal audit. The first is whether the management system meets the requirements of the standard. The second is whether the organisation is following its own processes and procedures, and whether those procedures match what actually happens.

Auditors who test only against clauses produce findings about documents. Auditors who test only against internal procedures can miss a requirement the organisation has never addressed. Holding both lenses at once is what turns an audit into something useful.

A trace is a good way to combine the two. Pick a real job, order or project and follow it from start to finish: the enquiry, the planning, the work, the checks, the handover, the review. At each stage ask what should happen, what did happen, and what the evidence shows.

Staying objective and impartial

Objectivity is not a personality trait, it comes from how the audit is set up. A few practical controls do most of the work.

  • Nobody audits their own work or the area they manage. This is the biggest single source of soft findings.

  • In a smaller organisation, look for alternatives: swap auditors with another site, use a trained auditor from a different department, or bring in external support where independence cannot be achieved internally.

  • Base every finding on evidence you can point to, and link it to the requirement it relates to.

  • Watch for familiarity bias. An auditor who has worked in a department for years may accept a practice as normal when it does not meet the requirement.

  • Declare conflicts of interest before the audit, and step aside if a personal relationship or past dispute would affect judgement.

Training supports this. Combined internal auditor courses covering ISO 9001, ISO 14001 and ISO 45001 are widely available over two days, often delivered in-house so the content can be tailored to your processes. Good training develops the skills to assess and report on the conformance and implementation of processes, which is a different skill from knowing the standard by heart.

factory inspection
Photo by Kateryna Babaieva on Pexels

Gather evidence that stands up

Most of the value in an audit comes from what happens in the room and on the floor, not from the desk review. Interviews, observation and sampling of records each tell part of the story, and none of them is reliable alone.

  1. Read the procedures and previous findings beforehand, so on-site time is spent testing rather than reading.

  2. Open with a short meeting that confirms scope, criteria, timing and how findings will be reported.

  3. Ask open questions, then stay quiet. "Walk me through what happens when a delivery is rejected" gets further than "do you follow the procedure".

  4. Sample deliberately rather than conveniently. Records that are easy to find are not always representative.

  5. Summarise each point back to the auditee before you write it down.

Write findings people can act on

A finding is only useful if the reader knows what was required, what was found and where the evidence sits. Vague statements such as "documentation could be improved" waste everybody's time.

Finding type

What it means

Nonconformity

A requirement of the standard, a procedure or an applicable obligation has not been met. Corrective action is needed.

Observation

Currently conforming, but at risk of drifting out of conformity if nothing changes.

Opportunity for improvement

The requirement is met, but there is a better way of working worth considering.

Good practice

Something done well that is worth sharing with other teams, sites or shifts.

One caution: do not soften a genuine nonconformity into an opportunity for improvement to keep the atmosphere pleasant. It flatters the report and hides the problem until an external auditor finds it.

Make room for opportunities for improvement and good practice

These are often the first things dropped when an audit runs short of time, which is a shame, because they are what makes the exercise feel worthwhile to the people being audited. A finding that recognises a well-run handover or tidy waste segregation costs nothing and makes the next audit easier to arrange.

Record opportunities for improvement separately from nonconformities so they do not dilute the corrective action process. Not every one needs to be taken up, and process owners should be able to explain why something has been parked. The point is that it was considered and a decision was made. Good practice deserves more than a line in a report: if one team has solved a recurring problem, the audit programme is the obvious place to spot it and the management review is the obvious place to spread it.

document review
Photo by Ron Lach on Pexels

Close the loop after the audit

The audit is finished when the actions are done, not when the closing meeting ends. Corrective actions need owners, dates and an honest look at root cause. If the same finding appears in three consecutive audits, the action addressed the symptom rather than the cause.

Report results into the management review so the audit feeds decisions about resources, training and priorities. Track completion, watch for repeat findings, and ask whether audits are still finding anything. A programme that produces no findings year after year is more likely to be a soft audit than a perfect system.

Frequently Asked Questions

Who can carry out an internal audit?

Anyone who is competent and impartial can carry out an internal audit. The standards require auditors to be objective, so nobody should audit their own work or the area they manage. In larger organisations that often means a trained auditor from another department. Smaller organisations sometimes share auditors between sites or bring in external help where independence cannot be achieved internally.

How often should internal audits be carried out?

The standards do not set a fixed frequency. The programme should cover all the requirements over a defined cycle, with more frequent audits for higher risk, higher importance or recently changed processes. Many organisations audit each process at least once a year, but longer or shorter cycles are acceptable as long as the plan is justified and covers everything by the end of the cycle.

Can one audit cover ISO 9001, ISO 14001 and ISO 45001 at the same time?

Yes. Organisations frequently hold all three standards together, and an integrated audit programme is a common and efficient way to cover them. The main risk is imbalance, with quality process questions crowding out environmental and health and safety topics. Plan integrated audits so each standard gets equal weight, and split them where an activity needs deeper scrutiny.

What is the difference between a nonconformity and an opportunity for improvement?

A nonconformity means a requirement has not been met, whether that requirement comes from the standard, your own procedures or an applicable obligation. Corrective action is expected. An opportunity for improvement means the requirement is met but the process could work better. Record both, and keep them separate so real problems are not quietly downgraded.

Do internal auditors need formal training?

The standards require competence, not a specific certificate. Many organisations use combined internal auditor training covering ISO 9001, ISO 14001 and ISO 45001 to build that competence, often delivered over two days and available in-house so the content matches their own processes. Training is only part of it. Experience of the processes being audited and a disciplined, evidence-based approach matter just as much.

Talk to Smart Quality

Tell us what you need help with. Our team will be in touch to discuss your enquiry.

Loading the enquiry form…

Prefer to speak to us? Call 01202 374272.