ISO 9001:2015 Internal Audit
Goal
Plan, conduct, and document an ISO 9001:2015 internal audit using objective evidence, correct finding classification, and clear audit reporting. Use this skill for planning an audit programme, conducting process-based or clause-based audits, preparing for third-party certification, or training internal auditors.
When to use
- Planning an internal audit programme
- Conducting an internal audit (process-based or clause-based approach)
- Preparing for a third-party surveillance or recertification audit
- Training an internal auditor
Required Internal Audit Checklist
☐ Define audit scope, criteria, and objectives before starting ☐ Verify auditor competence and independence (not auditing own work) ☐ Audit the process flow first — map evidence to ISO clauses afterwards ☐ Use open questions throughout — no leading questions, no yes/no questions ☐ Verify every answer with objective evidence ("show me", "let me see") ☐ Use sampling: interview multiple people, review multiple records, different time periods ☐ Classify findings correctly (Major / Minor / OFI) — do not downgrade under pressure ☐ Record objective evidence clearly and traceably for every finding ☐ Check effectiveness of previous corrective actions from prior audit cycles ☐ Confirm process performance against KPIs ☐ Issue a balanced audit report (findings + strengths) ☐ Track all Major and Minor NCs to closure with owner, due date, and effectiveness verification
Audit approach — process-based first
Preferred audit method: audit the process flow first, then map evidence to ISO clauses.
Follow the process: inputs → activities → outputs → performance indicators. Find where requirements are addressed in practice. Only then link findings to specific clauses. This avoids "checklist auditing" and produces more useful, systemic findings.
Use sampling throughout: interview at least 2–3 people, review at least 2–3 records, and cover different time periods. One record is not enough to confirm systemic conformity.
Audit finding classification
| Grade | Definition |
|---|---|
| Major non-conformance | Complete absence of a required element; systemic failure of a process; direct failure to achieve the intended result of the QMS |
| Minor non-conformance | Isolated or single occurrence of a requirement not being met; partial implementation; one piece of objective evidence missing |
| OFI (Observation / Opportunity for Improvement) | Technically conforming, but auditor sees risk or a better approach — no immediate action required |
Guidance: A major NC directly threatens the QMS intent; a minor NC is a gap that could become major if not addressed. Downgrading a major to minor to avoid customer concern is an audit integrity failure.
Repeated minor non-conformances in the same process may constitute a major non-conformance due to systemic failure — treat patterns as systemic, not isolated.
Writing findings: Each finding must include:
- Requirement (the ISO clause or procedure that was not met)
- Objective evidence (what was observed, measured, or reviewed)
- Statement of non-conformity (what the gap is)
Avoid conclusions without linking evidence to the specific requirement.
Clause-by-clause key questions
§4 — Context of the Organisation
§4.1 — Understanding the organisation and its context
- Is the context of the organisation documented (internal and external issues affecting the QMS)?
- Are strategic direction and relevant interested parties considered?
- Is the analysis reviewed and updated? When was it last updated?
- Evidence: SWOT, PEST analysis, or equivalent strategic analysis document
§4.2 — Understanding needs and expectations of interested parties
- Is there a list of interested parties (customers, regulators, employees, suppliers)?
- Are their relevant needs and expectations identified?
- Which of these have become QMS requirements?
- Evidence: stakeholder register, customer requirements register
§4.3 — Scope of the QMS
- Is the scope documented?
- Is it justified (exclusions explained if any)?
- Is it available to interested parties?
- Evidence: scope statement in Quality Manual or equivalent
§4.4 — QMS and its processes
- Are QMS processes identified with their inputs and outputs?
- Are process sequence and interactions defined (process map)?
- Are resources, responsibilities, and monitoring defined for each process?
- Are process risks, KPIs, and owners defined for each QMS process?
- Evidence: process map or turtle diagrams
§5 — Leadership
§5.1 — Leadership and commitment
- Can top management demonstrate involvement in the QMS? (not just sign the policy)
- Is customer focus promoted at the leadership level?
- Are quality objectives integrated into business processes?
- Can top management explain current quality objectives, major risks, and customer performance issues without relying on the quality manager?
- Evidence: management review records, objective tracking, signed policies
§5.2 — Policy
- Is the quality policy documented, signed by top management?
- Does it provide a framework for quality objectives?
- Is it communicated and understood by employees? (test: ask a random employee)
- Is it available to interested parties?
- Evidence: quality policy document + evidence of communication (intranet, notice boards, training)
§5.3 — Roles, responsibilities and authorities
- Are QMS-relevant roles defined with clear responsibilities?
- Is there a designated management representative (or equivalent)?
- Are responsibilities for customer focus assigned?
- Evidence: organisation chart, job descriptions, quality roles matrix
§6 — Planning
§6.1 — Actions to address risks and opportunities
- Are risks and opportunities identified from the §4.1 and §4.2 analysis?
- Are actions defined to address significant risks?
- For each significant risk: is there a defined action, owner, due date, and follow-up evidence?
- Are actions integrated into QMS processes?
- Evidence: risk register, risk-based thinking documented in process documents
§6.2 — Quality objectives and planning
- Are quality objectives established at relevant functions and levels?
- Are they SMART? (Specific, Measurable, Achievable, Relevant, Time-bound)
- Are there plans to achieve each objective (resource, responsible, timeline)?
- Are they monitored and communicated?
- Evidence: quality objectives document with current KPI data
§6.3 — Planning of changes
- When changes to the QMS are planned, is there a structured approach?
- Are purpose and potential consequences assessed before the change?
- Is integrity of the QMS maintained through changes?
- Evidence: change management records, MOC (Management of Change) procedure
§7 — Support
§7.1.1 — Resources (general)
- Does the organisation determine and provide necessary resources?
- Are resource constraints documented and addressed?
§7.1.2 — People
- Are sufficient competent people available for QMS processes?
§7.1.3 — Infrastructure
- Is infrastructure (buildings, equipment, IT) identified and maintained?
- Is maintenance documented?
- Evidence: equipment list, maintenance schedule and records
§7.1.4 — Environment for the operation of processes
- Are process environment requirements identified and maintained?
- (Temperature, humidity, cleanliness, noise — as applicable)
§7.1.5 — Monitoring and measurement resources
- Is all monitoring and measurement equipment identified?
- Is calibration / verification performed at defined intervals?
- Are calibration records maintained?
- Is equipment identified with calibration status?
- What happens when a gauge is found out-of-calibration? (suspect product assessment)
- Evidence: calibration master list, calibration certificates, out-of-cal procedure
§7.2 — Competence
- Are competence requirements defined for all quality-affecting roles?
- Are training records maintained for all relevant personnel?
- Is effectiveness of training evaluated?
- Are personnel aware of their contribution to quality objectives?
- Can sampled employees explain what they do if they detect a non-conforming output?
- Evidence: competence matrix, training records, evaluation results
§7.3 — Awareness
- Are personnel aware of the quality policy?
- Do they know their contribution to achieving quality objectives?
- Do they know the implications of non-conforming output?
- Can sampled employees explain what they do if they detect a non-conformance?
- Evidence: induction training records, toolbox talks, awareness campaign evidence
§7.4 — Communication
- Is internal and external communication relevant to the QMS defined?
- What is communicated? By whom? To whom? When? How?
§7.5 — Documented information
- Is documented information required by the standard available and current?
- Is organisation-specific documented information identified?
- Is document control defined (review, approval, version control, distribution)?
- Is access controlled — only current versions at point of use?
- Is obsolete documentation prevented from unintended use?
- Are records protected from modification and kept for defined periods?
- Evidence: document control procedure, master document list, sample controlled documents
§8 — Operation
§8.1 — Operational planning and control
- Are operational processes planned and controlled?
- Are process criteria established?
- Are controls implemented to meet criteria?
- Is documented information maintained to confirm processes were carried out as planned?
§8.2 — Requirements for products and services
- Are customer requirements determined (including legal/regulatory)?
- Are requirements reviewed before commitment (order review)?
- Are customer communications processes defined?
- Evidence: order review records, customer requirement register
§8.4 — Control of externally provided processes/products/services
- Is there an approved supplier list?
- Are supplier evaluation criteria defined?
- Are suppliers monitored (performance data, audits)?
- Are purchasing controls appropriate to the risk?
- Evidence: approved supplier list, supplier evaluation records, supplier KPIs
§8.5.1 — Control of production and service provision
- Are work instructions available at the point of use?
- Are product/service characteristics and acceptance criteria defined?
- Are process controls defined and maintained in alignment with Control Plan / work instructions?
- Is suitable monitoring/measurement equipment available and used?
- Is qualified personnel used? Are qualification records available?
- Are outputs identified and traceable?
- Evidence: work instructions at workstations, control plans, batch records
§8.5.2 — Identification and traceability
- Can product be traced from raw material to delivery?
- Is traceability documented throughout the process?
- Can suspect material be isolated when needed?
§8.7 — Control of nonconforming outputs
- Is there a documented process for controlling non-conforming product?
- Is non-conforming product identified and segregated?
- Are dispositions documented with approval?
- Is corrective action initiated for significant NCs?
- Evidence: NCR log, NCR records, quarantine area, disposition approvals
§9 — Performance Evaluation
§9.1 — Monitoring, measurement, analysis and evaluation
- Are quality KPIs defined and monitored?
- Is customer satisfaction measured and monitored?
- Is the data analysed and used for decision-making?
- Evidence: KPI dashboard, customer satisfaction data, trend analysis
§9.2 — Internal audit
- Is there an internal audit programme covering all QMS processes?
- Is the audit programme based on process importance, prior results, and risk?
- Are auditors competent and independent of the area being audited?
- Are audit findings documented and corrective actions followed up?
- Are audit records maintained?
- Evidence: audit programme, audit reports, CAPA from audit findings
§9.3 — Management review
- Is management review conducted at planned intervals?
- Does the agenda cover all required inputs? (§9.3.2)
- Are outputs documented (decisions and actions)?
- Are action items followed up from previous reviews?
- Evidence: management review minutes with all required inputs and action tracking
§10 — Improvement
§10.1 — General
- Is there evidence of continual improvement activity?
- Are opportunities for improvement being identified and acted upon?
§10.2 — Nonconformity and corrective action
- Is there a documented process for corrective action?
- Are root causes investigated for significant NCs?
- Are corrective actions proportionate to the effect of the non-conformity?
- Are corrective actions reviewed for effectiveness?
- Are actions taken to prevent similar NCs in other areas?
- Are records maintained? (§10.2.2)
- Evidence: CAPA register, CAR records, VOE evidence
§10.3 — Continual improvement
- Are quality objectives driving improvement?
- Is performance data used to identify improvement opportunities?
- Are improvement tools (8D, PDCA, lean, Six Sigma) used systematically?
Audit report structure
INTERNAL AUDIT REPORT
Standard: ISO 9001:2015
Audit criteria: ISO 9001:2015 clauses, internal procedures, customer-specific requirements (if applicable)
Scope: [Process or clause range]
Date: [Audit date]
Auditor: [Name, qualification]
Auditee: [Department/process owner]
FINDINGS SUMMARY:
Major NC: [count]
Minor NC: [count]
OFI: [count]
FINDINGS:
Finding 1 — MAJOR NC
Clause: §9.3 Management Review
Requirement: ISO 9001 §9.3.2 requires management review to include analysis of
quality objectives performance.
Evidence: Management review minutes dated 2026-03-15 reviewed. Quality objective
tracking data was not included or referenced. Quality manager confirmed no objectives
were discussed at the last two management reviews.
Finding: Systemic absence of quality objectives review in management review process.
[Repeat for each finding]
STRENGTHS:
[Positive observations — balanced audit report]
REQUIRED ACTIONS:
[List major and minor findings requiring CAPA with target dates]
Corrective action follow-up
All Major and Minor NCs must enter corrective action tracking with:
- Owner (named person)
- Target due date
- Effectiveness verification (evidence that the action worked, not just that it was done)
The audit programme must follow up on all prior CARs — open CARs from previous audits must be reviewed in the next cycle.
Common audit mistakes
- Leading questions: "You do have a calibration procedure, right?" → ask open questions: "How do you manage measurement equipment calibration?"
- Accepting verbal answers: always ask for objective evidence (show me, let me see)
- Clause-hunting vs. process approach: audit the process first, then map to clauses — not the other way round
- Downgrading findings under pressure: if the evidence supports a Major NC, write a Major NC
- Not following up previous findings: the audit programme must track closure of prior CARs
- Single-record sampling: one conforming record does not confirm systemic conformity — always sample multiple records and people
Output Format
At the start of each use, ask the user:
"How would you like to receive the output? A — Structured Markdown (formatted tables and sections, ready to copy) B — Plain tables (simplified structure for Excel or Word) C — Narrative report (flowing text for a formal document or email)
Default: A."
Adapt all output sections to the chosen format. If the platform or session context already defines a format preference, skip this question.
Reference files
- Clause-by-clause question bank
Changelog
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | 2026-06-01 | @RBraga01 | Initial release |
| 1.1 | 2026-06-03 | @migmcc | Expanded clause-by-clause question bank and evidence anchors |
Source: hashgraph-online/awesome-codex-plugins → plugins/RBraga01/Quality-Engineering-Skills/skills/audit/iso-9001-internal-audit/SKILL.md