Internal Audits as a Formality, External Audits as a Critique? —— Five Practical Steps for IATF 16949 Process Method Internal Audits

By: QTank Published: 8/18/2026 Views: 63
Current rating: ★★★☆☆ Rate this Equivalent to 8 ratings

1. Introduction: Two Internal Audits a Year with "All Green" Results, but External Audits Always "Crash"

A certain automotive parts company (a Tier 1 supplier for transmission shafts to vehicle manufacturers) conducts two internal audits annually: one at the beginning of the year and one mid-year, each lasting two days. The auditors make a round of the various departments, check if records are filled out and if documents are stamped, and announce at the closing meeting, "A total of 11 minor issues were found, all of which have been rectified on-site." Management is very satisfied—no major issues found during the internal audit indicates that the quality management system (QMS) is running well.

However, when the customer's second-party audit and the IATF 16949 surveillance audit arrived consecutively, the certification body issued a major nonconformity: a key characteristic's process parameters were not included in the control plan or daily monitoring, indicating a planning layer deficiency rather than a record layer flaw. The customer's audit also flagged a yellow light due to "8D recurrence prevention not being implemented horizontally." The external auditor pointed out at the closing meeting, "Your internal audit checks whether documents exist, not whether processes are effective."

This is not an isolated case. There is often a significant gap between internal and external audits in many companies: internal audits uncover only superficial issues like "incomplete records, incorrect labels," while external audits consistently identify deeper defects at the planning and interface layers. The difference lies not in the diligence of the auditors but in the audit methodology—internal audits still rely on the old method of "comparing clauses and flipping through documents," whereas IATF 16949 explicitly requires and external audits actually use the process method. This article provides a five-step practical approach from audit planning to nonconformity closure, making internal audits a genuine mechanism for "finding problems first" rather than a dress rehearsal before external audits.

2. Understanding the Difference: What Distinguishes Process Method Audits from "Flipping Through Documents"

IATF 16949 Clause 9.2 has a core requirement for internal audits in just one sentence: audits should cover all processes of the quality management system and be conducted using the process method. The standard does not require a clause-by-clause comparison but rather a focus on the "process" as the main thread, examining inputs, outputs, activities, resources, and performance to ensure they are truly under control. The difference in these two approaches directly determines the quality of audit findings:

Dimension Clause-Based Audit (Flipping Through Documents) Process Method Audit
Audit Object Standard clauses (e.g., 8.5.1 Production Control) Actual processes (welding, incoming inspection, equipment maintenance)
Starting Point Procedure documents in the file cabinet Work being performed on-site
Evidence Source Records, signatures, stamps On-site observation + personnel interviews + data traceability
Typical Findings Missing records, incorrect form versions Uncontrolled processes, broken interfaces, unmonitored indicators
Value for Improvement Low, mostly surface issues High, directly addressing system weaknesses

The core tool of the process method is the turtle diagram: each process is drawn as a "turtle," with the shell representing the process name and the four legs representing "what resources are used (equipment, facilities, systems)," "who does it (personnel and capabilities)," "how it is done (procedures, methods, standards)," and "what the outcome should be (process performance indicators)." The head and tail represent inputs and outputs, respectively. Auditors can systematically ask six questions using the turtle diagram: where do the inputs come from? Who receives the outputs? What resources are used? Who performs the task? What is the basis for the task? How do you know if it is done well? These six questions cover all elements of process control, and any inability to answer them often indicates a nonconformity.

When conducting audits using the process method, it is essential to distinguish the roles of three types of processes: COP (Customer-Oriented Processes) directly add value to the customer, such as product design, production, and delivery; SP (Support Processes) provide resources for COP, such as equipment maintenance, inspection, and training; MP (Management Processes) are responsible for planning and improvement, such as management review, internal audits, and goal management. Audits should follow COP as the main thread, and wherever COP leads, related SP and MP should be reviewed—this ensures no processes are overlooked and that the interfaces between processes are visible.

The audit criteria should include the "three essentials": IATF 16949 standard clauses, customer-specific requirements (CSR), and customer drawings and agreements, along with the company's own procedure documents and work standards. Any audit finding must be traceable to a specific layer of criteria; otherwise, it is just the auditor's subjective impression and lacks solid grounds. Additionally, the three principles of ISO 19011 must be adhered to: impartiality—auditors have no conflict of interest with the audited process; evidence-based—each finding is supported by objective evidence, not speculation; risk-based—focus on areas with the highest risk. These three points form the foundation of a credible internal audit report.

The process method also requires that the audit plan be risk-based: high-risk processes (special processes, customer complaints, new product ramp-ups) should be audited more frequently and in greater depth; low-risk processes should be audited less frequently. The audit plan must also consider previous audit results and management review outputs—processes with nonconformities identified in last year's external audit should be reviewed in detail this year; resource gaps identified in management reviews should be verified during internal audits. Furthermore, IATF 16949 Clause 7.2 has clear requirements for the capabilities of internal auditors, and customer-specific requirements (CSR) often specify that process auditors must receive specialized training such as VDA 6.3. It is not acceptable to randomly assign two engineers to the audit team.

3. Five-Step Practical Approach: From Planning to Closure, This is How to Conduct an Internal Audit

Step One: Plan the Audit Based on Processes and Risks, Not Departments. The annual audit plan should cover all COP, SP, and MP processes. First, list all processes and then score and rank them based on three dimensions: impact on the customer (whether there are special characteristics, whether it is a customer focus area), historical performance (customer complaints, external audit nonconformities, performance indicator achievement rates), and change activity (new projects, new equipment, new processes in the recent period). Processes with high composite scores should be audited twice a year, each time for more than half a day; processes with low scores should be audited once a year, for about two hours. For example, a company might rate the "welding process" as high-risk (due to customer complaints and new equipment introduction) and schedule two audits per year, while rating "document management" as low-risk and scheduling one audit per year. The plan should specify the audit criteria (IATF 16949 standard + customer-specific requirements + company procedure documents), the audit scope, and the required resources, and it should be approved by the management representative before publication.

Step Two: Team Formation and Qualification Confirmation, Auditors Must "Understand the Process." The audit team leader must be familiar with IATF 16949 and the process method, capable of leading turtle diagram analysis and interface tracking. Auditors should be assigned based on their expertise—welding processes should be reviewed by someone with a background in process engineering, incoming inspection by an SQE, and measurement management by someone from the laboratory. The principle of conflict of interest should be strictly followed, and no one should audit a process they are responsible for. Before the audit, a preparatory meeting should be held to standardize the checklists, clarify the sampling plan and time allocation (at least 60% of the time should be spent on-site and in interviews), and distribute the previous round's audit findings, recent customer complaint lists, and performance reports for the auditors to review.

Step Three: Use the Turtle Diagram to Create Checklists, Questions Must "Reach the Field." Before the audit, auditors should collect the procedure documents and performance data for the past three months for the process, draft a turtle diagram, and design checklists around the six elements, with 2-3 verifiable questions for each element. On-site questioning examples: ask the operator, "What do you do if this dimension is nonconforming?"—to verify if the reaction plan has been communicated effectively; ask the team leader, "What is the first-time pass rate for this month? What is the target? Where is the gap?"—to verify if performance indicators are genuinely monitored; ask the equipment technician, "Do the preventive maintenance records match the actual downtime for this equipment?"—to verify if maintenance planning and execution are consistent. Documents are just clues; the field and personnel are the evidence.

Step Four: On-Site Audit, Follow the "Flow" to the End. The process method audit follows the flow of products or information: from incoming material receipt → inspection → storage → material issuance → production → finished product inspection → shipment, all in one line, with more time spent at the interfaces. Interfaces are the "rich mines" of process audits—does the release information from incoming inspection reach the warehouse? Has the notification of process changes been communicated to the production line? During the audit, pay attention to three things: first, compare physical items with records to ensure consistency, such as a record showing calibration is qualified while the calibration label on the measuring tool has expired; second, ask the same question to people at different levels and compare their answers; third, follow up on any leads until the evidence chain breaks, which is often where the nonconformity lies. For example, during the audit of the "welding process," the control plan specifies that "welding gun pressure should be recorded every two hours," but the site had no records for four consecutive hours. When asked, the operator responded, "The pressure is stable, no need to record." Further investigation revealed that the equipment had no pressure monitoring gauge—the control method in the control plan did not match the actual capabilities on-site. This is a typical evidence chain of "disconnection between planning and execution," which can be judged as a minor nonconformity. Such findings cannot be discovered by simply reviewing documents in the office.

Step Five: Nonconformity Grading, Reporting, and Corrective Action Closure. In the context of IATF 16949, nonconformities are generally divided into three levels: major nonconformities (system-level failures, such as no control over key processes, concealment of audit findings), minor nonconformities (local failures, such as non-execution of control requirements for a specific process), and observations (potential risks, not judged as nonconformities). The report must clearly state three elements: the basis for the judgment (which standard or procedure clause was violated), the objective evidence (what was seen at what time and place), and the impact of the issue (what it means for the product, customer, or system). Corrective actions should follow the four steps of "correction → corrective action → preventive action → horizontal deployment," and the audit team must verify their effectiveness—not by reviewing a new document but by returning to the site three months later to confirm that the practices have changed and the indicators have improved. The internal audit report should also be linked to management review: significant findings must be used as inputs for management review, and resource allocation should be decided by the top management.

4. Five Common Pitfalls: Internal Audits Often Fail Here

Pitfall One: Auditing Only Documents, Not the Field. Auditors compare procedure documents and records page by page in the meeting room, spending the entire day without a single visit to the workshop, resulting in a "perfect document system, but a field full of holes." Solution: mandate that on-site and interview time account for no less than 60%.

Pitfall Two: All Findings Are "Improper Record Filling." If the findings of two consecutive internal audits are trivial, it indicates a problem with the checklist design—questions are not focused on whether the process is under control. A genuine internal audit should uncover issues like "no one knows the reaction plan," "performance indicators have not been tracked for three months," and "no training for updated documents."

Pitfall Three: Auditors Afraid to Offend. Internal audit findings are seen as "picking faults," and auditors, out of consideration for colleague relationships, downgrade serious issues to observations. Solution: link internal audit results to departmental performance, have the management representative attend the closing meeting to support the auditors, and, if necessary, introduce cross-factory mutual audits or hire external auditors.

Pitfall Four: Paper-Based Closure of Corrective Actions. The responsible department submits a "revised procedure document" and declares closure, but three months later, the site remains unchanged. Solution: the audit team must verify the effectiveness, clearly stating the verification method (on-site observation, data comparison, product traceability) in the closure application, and non-verified actions should not be closed.

Pitfall Five: Disconnection Between Internal and External Audits. External audits identify types of nonconformities that internal audits have never found—indicating that internal audits are not aligned with customer-specific requirements and the latest standard requirements. Solution: before each annual audit, list the previous year's external audit report, customer audit report, and CSR list as mandatory inputs for the audit plan, and address each item to ensure completeness.

Pitfall Six: Rush Audits. Internal audits are scheduled a week before customer audits or surveillance audits to be "rushed through," with checklists copied from the previous year and all departments reviewed in two days—such internal audits discover nothing except serving as a warm-up for external audits. Solution: approve the audit plan at the beginning of the year and execute it according to the schedule, lock in the audit dates a month in advance and notify relevant departments, and avoid production peaks to ensure the audit proceeds at a steady pace.

5. One-Sentence Summary

Internal audits are not a "dress rehearsal" for external audits but a mechanism for the company to identify system weaknesses in advance and address issues before they are discovered by customers and certification bodies. Using the process method, scheduling audits based on risk, and ensuring findings are closed in management reviews can transform internal audits from a formality into a true "mirror of truth."


Use the process method for internal audits to identify issues first.

Knowledge code: 2.1.2

Version: v20260818

Author: Quality Think Tank

The Quality Think Tank is dedicated to providing systematic professional knowledge, methodologies, and practical tools for quality management practitioners, helping companies continuously improve their quality capabilities.