Deep Interpretation of ISO9001 Clause (27) | 9.2 Internal Audit: From Formalities to True Diagnosis
1. Key Points of the Clause
9.2.1 Provides the purpose of internal audits: The organization shall conduct internal audits at planned intervals to provide information on the quality management system (QMS) regarding whether the system conforms to the organization's own requirements for the QMS; whether it conforms to the requirements of this standard; and whether it is effectively implemented and maintained. These three statements correspond to "compliance with self-defined rules," "compliance with standard rules," and "whether it is truly operational."
9.2.2 Lists six mandatory actions: a) Plan, develop, implement, and maintain an audit program, which should be based on the importance of the relevant processes, changes affecting the organization, and the results of previous audits. The program should include frequency, methods, responsibilities, planning requirements, and reporting; b) Define the audit criteria and scope for each audit; c) Select auditors and conduct the audit to ensure the audit process is objective and impartial; d) Report the audit results to relevant management; e) Take appropriate corrective and corrective actions in a timely manner; f) Retain documented information as evidence of the implementation of the audit program and the audit results.
The standard also notes: ISO 19011 can be referred to for guidance.
2. Interpretation of Intent
First, internal audits are a self-check of the system, complementary to the information sources in 9.1. Clause 9.1 answers "how good the results are" by looking at indicators and data; Clause 9.2 answers "whether the processes are correct and whether they are running as planned" by examining on-site evidence. Without 9.2, it is easy to assume "if the results are acceptable, everything is fine"; without 9.1, it is easy to focus solely on "whether the documents are complete."
Second, the standard does not specify "once a year," but requires "planned intervals," reflecting a risk-based approach. The frequency should be determined by the importance of the process, ongoing changes, and the results of previous audits: more frequent and in-depth audits for important, changing, or repeatedly problematic processes, and less frequent audits for stable and less critical processes. A blanket approach of "auditing all departments once a year" disregards the three criteria mentioned in a).
Third, "objectivity and impartiality" are the minimum requirements for internal audits. The standard explicitly requires selecting auditors and ensuring objectivity and impartiality, implying the operational rule that auditors should not audit activities they are responsible for. Auditing one's own work, due to bias and habit, almost never yields genuine conclusions. This is the fundamental difference between internal audits and self-inspections.
Fourth, the output of internal audits must be closed-loop and reported upwards. Clause e) requires timely corrective and corrective actions, indicating that audit findings are not just for "record-keeping"; Clause d) requires reporting to relevant management, indicating that internal audit conclusions are management information and should be part of the input for 9.3 management review. If internal audit results only circulate within the quality department, both pathways are effectively blocked.
3. Implementation Practices
Step One: Develop an annual audit program based on risk. List all processes and score each process based on three factors: importance (impact on customers, regulations, and delivery), degree of change (changes in personnel, equipment, processes, external suppliers, and organizational structure), and historical performance (nonconformities and complaints from internal and external audits over the past two years, scrap and rework data). Increase the frequency or depth for processes with higher scores and simplify for those with lower scores. The program should specify the processes, frequency, methods, auditor assignments, and reporting requirements, and define scenarios for triggering interim audits, such as major customer complaints, significant changes, and weak clauses before external audits.
Step Two: Establish a "clause—document—process" matrix and develop checklists. The audit criteria should include at least three parts: the corresponding clauses of ISO9001, the organization's own system documents and work instructions, and applicable regulations and customer-specific requirements. The matrix ensures that the annual program covers all applicable clauses, preventing any unclaimed clauses. Checklists should be process-oriented—asking questions about inputs, activities, outputs, resources, criteria, monitoring, and improvement.
Step Three: Collect evidence on-site, focusing on both processes and results. Use interviews, on-site observations, and record sampling together, covering both planned and actual execution, and follow a business thread throughout the entire process: for example, starting from a contract, trace it through review, procurement, production, inspection, release, delivery, and customer feedback. Classify findings by nature: major nonconformities, minor nonconformities, observations, and improvement opportunities. Evidence should be reproducible, with specific details such as time, location, document number, batch, or equipment number, avoiding vague descriptions like "it is understood" or "generally speaking."
Step Four: Create a verifiable chain for reports and closure. Nonconformity reports should clearly state three elements: the requirement, the objective evidence, and the nonconformity statement. The responsible department should conduct a root cause analysis, develop corrective and corrective actions, and complete them on schedule. The internal auditor should verify the effectiveness and then close the nonconformity. Systemic and recurring issues identified in this period should be summarized and included as input for 9.3 management review and tracked in the 10.2 corrective action system.
4. Auditor's Perspective
Common Finding One: Checklists are copied directly from clauses, reducing audits to document verification (9.2.2 b). On-site issues are almost always about "whether there is this procedure" or "whether there is this record," without delving into execution details, observing physical evidence, or tracing data sources. The judgment is straightforward: whether the checklists only have "yes/no" and whether the audit records are full of document names with no on-site facts.
Common Finding Two: Auditors review their own work, compromising objectivity and impartiality (9.2.2 c). Typical scenarios include quality department employees auditing quality management processes, production supervisors auditing their own workshops, or individuals serving as both the audited party and the auditor. Such nonconformities often fail to justify the relationship between the auditor and the audited process when questioned.
Common Finding Three: Audit programs are uniform, with frequency unrelated to risk (9.2.2 a). Each department is audited once a year, and when asked to provide the basis for the program, no scoring, grading, or adjustment records can be produced.
Common Finding Four: Nonconformity reports lack essential elements, and corrective actions remain on paper (9.2.2 e). Only the phenomena are described without referencing the relevant clauses, or issues like "improper record filling" are noted without analysis of the reasons. The measures column often states "strengthen training" or "strictly enforce," without specifying verification times or conclusions. The recurrence of similar issues in the next year's audit is strong evidence of this problem.
Common Finding Five: Internal audit results are not reported to management and are not part of the management review (9.2.2 d). Reports are only sent to functional departments, and the internal audit input in the management review only states "X nonconformities were found and have been rectified," without showing conclusions or trends.
Frequent Misunderstanding: Treating internal audits as a "rehearsal" or "preparation for external audits." Audits are not conducted regularly, but rather concentrated a month or two before external audits, with checklists and records backdated. Timestamps and meeting sign-ins, travel records often contradict each other, becoming the most typical source of major nonconformities during external audits.
5. Self-Inspection Checklist
- Is the annual audit program clearly defined with frequency, methods, responsibilities, and reporting requirements, and are there three criteria (importance, changes, and previous results) to support it?
- Is a matrix established to align clauses with processes, ensuring all applicable clauses are covered within the audit cycle?
- Do auditors avoid auditing activities they are responsible for, and is there a team leader responsible for this?
- Do nonconformity reports include the three essential elements (requirement, objective evidence, nonconformity statement), and are the measures validated and closed?
- Are internal audit results reported to management and top management, and are they included in the management review and 10.2 tracking?
Objective audits ensure that findings can be closed with actions.
Knowledge code: 2.1.1
Version: v20260925
Author: QTank QTank is dedicated to providing systematic professional knowledge, methodologies, and practical tools for quality management practitioners, helping companies continuously improve their quality capabilities.