ISO9001 System Document Package (25) | Internal Audit Procedure (9.2)
Document Description: This procedure corresponds to clause 9.2 "Internal Audit" of the ISO 9001:2015 standard. It is a core procedure in the "Performance Evaluation" section of the Quality Management System (QMS) that verifies the system's compliance and effectiveness. It is also a standard practice for companies to conduct self-inspections before certification audits. Its purpose is to systematically, independently, and documentarily check whether the system operation meets the standard requirements, conforms to the company's own document specifications, and is effectively implemented and maintained, and to identify and eliminate nonconformities before external audits. Clause 9.2 is a mandatory check for certification auditors, and the key points of verification usually include: whether the internal audit covers all clauses and processes, whether the auditor reviews their own work, whether nonconformities are closed on schedule and verified for effectiveness, and whether the internal audit results are used as inputs for management review. This procedure is applicable to all manufacturing and service companies, especially small and medium-sized enterprises (SMEs) that need to conduct systematic self-inspections before certification or external audits, and can be directly applied and tailored according to the organization's size.
1. Purpose
To standardize the planning, implementation, reporting, and follow-up verification processes of internal quality management system audits within the company, ensuring that the QMS:
- Meets the requirements of ISO 9001:2015 and the company's QMS document specifications;
- Is correctly implemented and maintained;
- Continuously meets the quality policy, quality objectives, customer requirements, and applicable legal and regulatory requirements, and provides input for improvement.
2. Scope of Application
This procedure applies to all departments, processes, and locations within the scope of the company's QMS, including management, functional departments, production workshops, warehouses, inspection areas, and external service points.
When necessary (such as for second-party audits of key suppliers), this procedure can be referenced, with the audit purpose, criteria, and organizational methods determined by the responsible department. This procedure does not replace specific legal, regulatory, or customer requirements for particular audits (such as specialized safety audits or customer-designated audits).
3. Responsibilities
| Responsible Department/Position | Responsibilities |
|---|---|
| General Manager | Approve the "Annual Internal Audit Plan" and "Internal Audit Report"; provide resource support for internal audits; appoint the audit team leader (or authorize the management representative to appoint) |
| Management Representative | Review the annual internal audit plan; coordinate audit resources; approve the effectiveness of corrective actions for nonconformities; submit internal audit results to management review |
| Responsible Management Department (Quality Department/Enterprise Management Department) | Compile the annual internal audit plan; form the audit team and authorize internal auditors; manage internal audit records; track the closure of nonconformities |
| Audit Team Leader | Compile the "Internal Audit Implementation Plan"; organize the preparation of checklists; chair the opening and closing meetings; assign audit tasks; summarize audit findings and compile the internal audit report |
| Internal Auditor | Prepare checklists according to assigned tasks and conduct on-site audits; collect objective evidence; issue nonconformity reports; attend the opening and closing meetings |
| Head of Audited Department | Cooperate with the audit team by arranging personnel and on-site access; provide objective evidence; analyze the causes of nonconformities, develop, and implement corrective actions; provide feedback on verification results |
Internal auditors must be trained and authorized and must not audit their own work (including processes they are responsible for, or have been involved in planning, implementing, or verifying).
4. Work Procedures
4.1 Annual Audit Plan
- The responsible management department compiles the "Annual Internal Audit Plan" by December each year, which is reviewed by the management representative and approved by the general manager before being distributed to all departments.
- The annual audit plan should ensure that each process of the QMS is audited at least once a year; the interval between two audits should generally not exceed 12 months.
- The frequency and scope of audits should be determined based on the following factors:
- The importance of the relevant processes and their impact on product quality;
- The performance of processes and the system, previous audit results, and distribution of nonconformities;
- Changes in the organizational environment and stakeholder requirements, significant changes (organizational restructuring, new production lines, new product introduction, etc.);
- Customer complaints, findings from external audits, and outputs from management review.
- Additional temporary audits may be conducted in the following situations: a major quality incident or significant customer complaint occurs; there are significant changes in the organizational structure or product structure; before an external audit; when the general manager or management representative deems it necessary.
4.2 Audit Purpose and Criteria
Before each internal audit, the following should be clearly defined:
- Audit Purpose: Evaluate the compliance and effectiveness of the system operation, and identify opportunities for improvement.
- Audit Criteria (Audit Basis):
- ISO 9001:2015 "Quality Management System Requirements";
- The company's QMS documents (quality manual, procedure documents, work instructions, etc.);
- Applicable laws, regulations, standards, and customer requirements;
- Requirements mentioned in the previous audit report, corrective actions, and outputs from management review.
- Audit Scope: Departments, processes, locations, and clauses to be covered.
4.3 Formation and Authorization of the Audit Team
- The management representative or the responsible management department determines the audit team leader and members based on the audit scope, and formally authorizes them with the "Internal Auditor Authorization Letter" after approval by the management representative.
- The audit team should have the necessary capabilities and consist of at least two internal auditors; the audit team leader should have organizational coordination skills and a complete internal audit experience.
- The division of labor within the audit team should ensure independence: auditors must not audit processes for which they are responsible or directly involved.
4.4 Audit Preparation
- The audit team leader compiles the "Internal Audit Implementation Plan," clearly defining the audit purpose, scope, criteria, schedule, audit team division of labor, and audited departments. The plan should be distributed to the audited departments for confirmation 5 to 7 working days in advance. If the audited department has objections to the schedule, they should raise them within 2 working days of receiving the plan, and the audit team leader will coordinate adjustments.
- Auditors should study relevant documents according to their assigned tasks, using the "process approach" (five elements of the turtle diagram: inputs, outputs, activities, resources, performance indicators) and the PDCA cycle to write the "Internal Audit Checklist." The checklist should include: audited process, corresponding clauses, audit points, audit methods (interviews, document review, observation), and a record section.
- The checklist should be reviewed and confirmed by the audit team leader before use. During the audit, the content of the checklist can be reasonably added or deleted based on the on-site situation, but key clauses and important processes must not be omitted.
4.5 Opening Meeting
- An opening meeting should be held before the on-site audit, with participants including all members of the audit team, heads of the audited departments, and relevant accompanying personnel. The meeting should be chaired by the audit team leader and last 20 to 30 minutes.
- The opening meeting should cover: introduction of the audit purpose, scope, criteria, and schedule; confirmation of audit methods (sampling, interviews, on-site observation, document review); explanation of the criteria for identifying nonconformities and communication methods; confirmation of accompanying personnel and necessary resources; confidentiality statement.
- The meeting should form a "Meeting Attendance Sheet" signed by all participants.
4.6 On-Site Audit Implementation
- Auditors should collect objective evidence through interviews, document and record reviews, on-site observations, and sampling verification. The sampling should be representative, and the sample size should be commensurate with the process risk.
- Audit findings should be recorded on the checklist, noting the evidence (document number, record name, time, location, personnel, etc.) to ensure that "every finding is supported by evidence."
- Analyze the collected evidence to determine conformities and nonconformities. Nonconformities are classified by severity:
- Major Nonconformity: Systemic deficiencies (such as a clause not being implemented at all), systemic failures (repeated issues of the same type), serious consequences (such as batch nonconforming products being released), or serious violations leading to system failure.
- Minor Nonconformity: Individual, isolated issues that do not meet requirements and have not caused serious consequences.
- Observations/Improvement Opportunities: Insufficient evidence but potential risks or areas for improvement. These are not issued as nonconformities but are communicated to the audited party verbally or in writing.
- Before issuing a nonconformity report, the auditor should communicate and confirm the facts with the audited department. If the audited department has objections to the determination, the audit team leader and the head of the audited department should verify and rule on the matter.
- Auditors must not propose specific corrective actions or analyze the causes on behalf of the audited party to maintain the independence of the audit.
4.7 Closing Meeting
- A closing meeting should be held after the on-site audit, with the same participants as the opening meeting. The audit team leader should report the overall audit situation, read out the nonconformity reports, announce the audit conclusion (recommended pass, conditional pass, or re-audit after corrective actions), and explain the requirements for subsequent corrective actions and verification.
- The closing meeting should also form a "Meeting Attendance Sheet." The audited department should sign and confirm the nonconformity report, with two copies (one for the audited department and one for the responsible management department).
4.8 Audit Report
- The audit team leader should compile the "Internal Audit Report" within 5 to 7 working days after the closing meeting. The report should include: audit purpose, scope, criteria, audit team composition, audit dates and process overview, summary of audit findings, statistical analysis of nonconformities (by clause or department distribution), comprehensive evaluation of system operation effectiveness, audit conclusion, and improvement recommendations.
- The audit report should be reviewed by the management representative and approved by the general manager. The responsible management department should distribute the report to relevant departments according to the "Document Control Procedure" and use it as a fixed input for management review.
- The entire internal audit process, from the opening meeting to the distribution of the report, should be completed within 10 to 15 working days.
4.9 Corrective Actions and Follow-Up Verification
- The head of the audited department should organize the analysis of the causes of nonconformities and fill in the corrective actions (including completion deadlines) on the "Nonconformity Report." The deadline for minor nonconformities is generally 10 to 15 working days, while the deadline for major nonconformities is determined by the management representative, typically not exceeding 30 working days.
- The implementation of corrective actions should follow the "Nonconforming Product and Corrective Action Procedure."
- The audit team (or internal auditors designated by the responsible management department) should conduct follow-up verification of nonconformities after the rectification deadline:
- Verification methods: review rectification evidence, on-site re-inspection, interview relevant personnel, etc.
- Verification content: whether the rectification is complete, whether the cause analysis is thorough, whether the corrective actions are effective, and whether similar issues have been addressed.
- Verification conclusions should be recorded in the corresponding sections of the "Nonconformity Report" and signed by the verifier. If the verification is invalid, the rectification should be returned for rework and re-verification.
- After all nonconformities are closed, the responsible management department should summarize the rectification status and, if necessary, form a supplementary report for the management representative.
4.10 Text Version of the Process Flowchart
Annual Audit Plan (4.1)
↓
Define Audit Purpose/Criteria/Scope (4.2) → Form and Authorize Audit Team (4.3)
↓
Audit Preparation: Implementation Plan + Checklists (4.4)
↓
Opening Meeting (4.5)
↓
On-Site Audit: Collect Objective Evidence → Determine Nonconformities (4.6)
↓
Closing Meeting: Report Conclusions, Confirm Nonconformities (4.7)
↓
Compile and Approve "Internal Audit Report" (4.8)
↓
Root Cause Analysis and Implementation of Corrective Actions by Audited Department (4.9)
↓
Follow-Up Verification and Closure → Input to Management Review (4.8/4.9)
4.11 Records and Result Application
- Internal audit records (annual plan, implementation plan, checklists, attendance sheets, nonconformity reports, audit report) should be archived and retained by the responsible management department according to the "Record Control Procedure."
- Internal audit results should be used as inputs for management review and for: evaluating opportunities for system improvement, adjusting process performance targets, optimizing resource allocation, and revising system documents.
5. Related Records
| Record Name | Number | Custodian Department | Retention Period |
|---|---|---|---|
| Annual Internal Audit Plan | QR-25-01 | Responsible Management Department | 3 years |
| Internal Audit Implementation Plan | QR-25-02 | Responsible Management Department | 3 years |
| Internal Auditor Authorization Letter | QR-25-03 | Responsible Management Department | 3 years |
| Internal Audit Checklist | QR-25-04 | Responsible Management Department | 3 years |
| Opening/Closing Meeting Attendance Sheet | QR-25-05 | Responsible Management Department | 3 years |
| Nonconformity Report (including corrective actions and verification sections) | QR-25-06 | Responsible Management Department/Audited Department | 3 years |
| Internal Audit Report | QR-25-07 | Responsible Management Department | Long-term |
| Internal Auditor Qualification Training Records/Copies of Certificates | QR-25-08 | Responsible Management Department/Human Resources | Long-term |
Note: The record numbering rules should follow the "Record Control Procedure," and each company can adjust them according to its own numbering system. The format of the record forms can be referenced from the fourth-level document management templates in this package.
6. Related Documents
- ISO 9001:2015 "Quality Management System Requirements" clause 9.2;
- "Record Control Procedure";
- "Document Control Procedure";
- "Nonconforming Product and Corrective Action Procedure";
- "Management Review Procedure";
- "Human Resources Management Procedure" (requirements for internal auditor capabilities and training);
- "Data Analysis and Evaluation Procedure" (statistical analysis of internal audit nonconformities).
Usage Instructions
1. How to Adapt to the Company's Actual Situation
- Organizational Adaptation: In small companies, the responsibilities of the "responsible management department" and the "management representative" can be combined and handled by the quality manager. The audit team can consist of one team leader and 1 to 2 internal auditors, but the independence requirement that "auditors must not audit their own work" must be maintained. If the company lacks internal auditors, it can hire qualified external auditors or conduct mutual audits with sister companies.
- Industry Adaptation: Manufacturing companies should design checklists based on both processes (such as production, inspection, procurement) and clauses. Service companies can focus the audit on customer service processes, complaint handling, and outsourced processes. Engineering projects can include specialized audits of construction sites and subcontractor management. High-risk processes (such as design and development, key operations) should have higher audit frequencies and larger sampling ratios.
- Frequency Adaptation: Companies with mature and stable operations can reduce the audit frequency of low-risk processes to once every two years, with reasons explained in the annual plan. However, the overall plan must still cover all clauses. For new systems, it is recommended to conduct a full-clause audit every six months in the first year.
- Method Adaptation: Rolling audits (covering different processes in different quarters) can be used to reduce the burden on departments during concentrated audits. If conditions permit, process method audits, risk-based audits, or audits combined with specialized inspections can be introduced, but the purpose, criteria, and scope of each audit should be documented in advance.
2. Audit Focus Points
- During certification audits, external auditors will focus on verifying: whether internal audits are conducted according to the annual plan, whether plan adjustments are justified; whether audit records reflect sampling evidence rather than general descriptions; whether auditor independence is met (by comparing the auditor's position with the audited department); whether all nonconformities are closed and verified for effectiveness.
- Common follow-up questions: "Which departments/clauses were the nonconformities concentrated in during the last internal audit? What systemic measures were taken?"—it is recommended to maintain statistics on the distribution of nonconformities by department and clause and to demonstrate the linkage between management review, corrective actions, and nonconformity statistics.
- Note the linkage between 9.2 and 4.4, 7.1.6, 9.1.3, 9.3, 10.2: the internal audit plan should consider risks and performance (risk-based planning); internal audit findings should be included in knowledge management; nonconformity statistical analysis should be included in data analysis reports; internal audit results are fixed inputs for management review. This evidence chain is a frequent verification point in recent audits.
3. Common Errors
- Formalistic Internal Audits: Checklists are generic, audit records only state "compliant" without evidence, and on-site audits become document review meetings, leading to the failure to expose real system issues—internal audits aim to identify improvement opportunities, not to prove "all green."
- Auditors Auditing Their Own Work: Departmental internal auditors auditing their own work violate the independence requirement and will be issued nonconformities; this should be strictly avoided during authorization and division of labor.
- Emphasis on Issuing Nonconformities but Neglecting Closure: Nonconformities are issued but not followed up, or verification only checks whether a "rectification report" has been written without verifying the effectiveness of the measures, leading to repeated issues; it is recommended to include the on-time closure rate of nonconformities in departmental performance indicators.
- Checklists Not Aligned with Standards: Auditors only check records based on procedure documents and do not verify the ISO 9001 standard clauses themselves, missing new requirements (such as organizational environment, risk, knowledge management) in the audit; when compiling checklists, the standard clauses should serve as the framework, and procedure documents should be the content, with each clause being addressed.
- Vague Audit Reports: Reports only list nonconformities without providing a comprehensive evaluation of system effectiveness and improvement recommendations, weakening the support role of internal audits in management decision-making.
Serious internal audits ensure the system remains robust.
Knowledge code: 2.3.1
Version: v20260809
Author: QTank QTank is dedicated to providing systematic professional knowledge, methodologies, and practical tools for quality management practitioners, helping companies continuously improve their quality capabilities.