IATF 16949

How to Conduct an IATF 16949 Internal Audit: The Automotive Process Approach

To conduct an IATF 16949 internal audit, plan your audit program around system, manufacturing process, and product audits, confirm whether each customer's CSRs already prescribe the audit approach before defining your own, build turtle diagrams to guide process-based questioning, follow a specific part through the process to test genuine understanding, document findings with precise evidence, and verify corrective actions trace back to a real root cause.

Most quality professionals coming to IATF 16949 auditing from a general ISO 9001 background expect the transition to be mostly new terminology layered onto familiar methodology. It isn't. The automotive process approach genuinely changes how an audit gets built and conducted — starting with a detail many auditors miss entirely: for manufacturing process and product audits specifically, the standard doesn't leave the audit methodology up to the organization by default. This guide walks through how to conduct an IATF 16949 internal audit using that process approach, drawing on the audit experience of Maria Falbo, a Lead Auditor with decades of IATF 16949 experience.

Maria Falbo|Lead Trainer, Logix ISO|July 2026|9 min read

What the Automotive Process Approach Means

ISO 9001's process approach requires organizations to manage activities as interconnected processes rather than isolated departmental functions. IATF 16949 takes that same principle and makes it operationally explicit — auditors are expected to follow a product or process through the organization the way it actually flows, tracing inputs to outputs at each stage rather than checking a generic clause list department by department.

In practice, this means an audit trail follows a part from incoming material through each transformation stage to finished product and shipment, examining what controls exist at each transition and how information flows both forward (specifications, work instructions) and backward (inspection results, nonconformity data) along that same path. For a broader explanation of how this differs from general ISO 9001 auditing, see our IATF 16949 Internal Audit: The Complete Guide.

Planning the Audit Program: System, Process, and Product Audits

IATF 16949 structures internal audits into three distinct, clause-governed categories, each with its own coverage requirement.

System audits (Clause 9.2.2.2) cover the organization's QMS processes as a whole, with all processes required to be audited at least once within a three-year calendar period, at a frequency the organization sets based on risk.

Manufacturing process audits (Clause 9.2.2.3) require all manufacturing processes — and all shifts, including shift changes — to be audited within that same three-year period, evaluating the effectiveness and efficiency of each process.

Product audits (Clause 9.2.2.4) verify the finished product itself conforms to specified requirements at appropriate stages of production and delivery.

Auditor competence for system, manufacturing process, and product audits specifically falls under Clause 7.2.3, requiring general audit training aligned with ISO 19011, genuine technical knowledge of the specific process, equipment, and AIAG core tools involved, and IATF 16949 standard knowledge — three distinct competency requirements, not one general auditing credential. For a full breakdown of how IATF's clause structure incorporates these requirements, see our IATF 16949 requirements explained.

Confirming Whether the Customer Already Defines the Approach

This is the step most generic audit planning guidance skips entirely, and it's specific to IATF 16949: for manufacturing process audits, Clause 9.2.2.3 explicitly states the organization must use "customer-specific required approaches for process audit" — and only determines its own approach where the customer hasn't defined one. Clause 9.2.2.4 states the same for product audits.

In practice, this means checking the applicable CSR documents before building an audit plan and program, not after. Where an OEM hasn't specified an approach, organizations commonly draw on established external frameworks rather than building one from scratch — VDA Volume 6 Part 3 for process audits and Part 5 for product audits, or AIAG's CQI series (CQI-8 for layered process audits, and special-process-specific documents like CQI-9 for heat treatment or CQI-11 for plating) where the process falls into one of those categories.

In Practice

A planning mistake I see repeatedly is an audit team building their own process audit methodology from a generic template before checking whether the applicable customer's CSR already prescribes one. The standard doesn't give the organization a choice on this — if GM or Stellantis has defined a specific process audit format as part of their CSR, that's the format the audit has to follow, not a starting point to adapt. Skipping that check doesn't just risk failing the internal audit's own value; the certification body's external auditor will check the same thing, and a self-built methodology that ignores an applicable customer-mandated approach is a nonconformity waiting to be found.

Customer scorecards are also a genuinely useful input at this stage, even though the requirement to formally review them applies directly to certification bodies planning external audits rather than internal ones. Organizations that mirror this practice internally — reviewing current scorecard data to identify where performance has weakened, and weighting audit trail selection toward those areas — are simply applying the same logic a certification body auditor will apply anyway. For a complete explanation of what CSRs are and how to audit them specifically, see our customer specific requirements in IATF 16949 guide.

Build the skills to conduct credible, technically fluent IATF 16949 internal audits

The IATF 16949 Internal Auditor course covers the process approach, turtle diagram methodology, and customer-specific requirements integration, built on IATF 16949 and ISO 19011.

View Course

Conducting the Audit with Turtle Diagrams and Process-Based Questioning

The turtle diagram is the practical tool that operationalizes the process approach during an audit — a one-page visual map of a process, showing inputs, outputs, and four surrounding dimensions: resources, methods, equipment, and metrics.

Process-based questioning follows the process approach's structure rather than a generic clause checklist. Instead of asking "show me your procedure," the auditor asks questions that follow the actual process: "Walk me through what happens when this part arrives at this station. What are you checking for? What do you do if it fails that check? Where does that information go next?" Both closed-ended questions (useful for confirming a specific fact or steering an interview back on track) and open-ended questions (useful for drawing out genuine detail) have a place here, applied deliberately rather than defaulting to one style throughout.

In Practice

The specific technique I rely on most during a manufacturing process audit — building an audit trail — is picking one physical part sitting on the line and tracing exactly what happened to it: what was checked, by whom, against what limits, and what would have happened if it had failed. This is a different exercise from asking someone to describe their process in general terms. An operator can describe a process accurately in the abstract while not always being able to trace what happened to the specific part sitting in front of them, and that gap between general process knowledge and specific traceable evidence is exactly what a process-approach audit is built to expose. This applies to management and support processes as well.

Reporting Nonconformities

Findings from a process-approach audit should reference the specific point in the process where the gap occurred, not just the clause it relates to. "Control plan monitoring frequency not followed" is less useful than a finding specifying the exact station, the specified frequency versus the observed frequency, and how that gap was confirmed.

Findings involving a customer-specific requirement should note which OEM's CSR was involved, and be very specific. Findings are classified as major nonconformities and minor nonconformities, following the same discipline covered in our IATF 16949 Internal Audit: The Complete Guide.

Corrective Action

Corrective action for a process-approach finding should trace back through the process itself, not stop at the immediate symptom. A control plan monitoring gap often has its root cause in an FMEA that wasn't updated after a process change — and that gap frequently traces further back to a change management process that never triggered FMEA review as a standard step.

Under the IATF Rules 6th Edition, major nonconformities carry a strict 15-day window for containment action and root cause analysis — a timeline that applies to internal corrective action discipline just as much as to formal certification body findings.

FAQ

Frequently asked questions

Does the customer always define the manufacturing process audit approach?

No — only where the applicable CSR specifies one. Clauses 9.2.2.3 and 9.2.2.4 require the organization to use the customer-defined approach where one exists, and to determine its own approach only when the customer hasn't specified one, often by drawing on established frameworks like VDA Volume 6 or the AIAG CQI series.

What is a turtle diagram, and is it required by IATF 16949?

A turtle diagram is a one-page visual map of a process, showing inputs, outputs, and four surrounding dimensions: resources, methods, equipment, and metrics. It isn't named as a requirement anywhere in the IATF 16949 text, but it is commonly used.

How is process-based questioning different from a standard audit checklist?

Process-based questioning follows the actual flow of a process and all standard clauses that apply to it, using both closed- and open-ended questions deliberately. This surfaces the gap between documented procedures and actual practices more effectively than a generic checklist.

Do manufacturing process audits need to cover every shift?

Yes — Clause 9.2.2.3 requires all manufacturing processes and all shifts, including shift changeovers, to be covered across the three-year audit cycle, not just the shift that happens to be running when the audit is scheduled.

What happens if an organization builds its own process audit methodology when the customer's CSR already specifies one?

This is a genuine nonconformity, not a minor documentation gap. The standard requires the customer-defined approach to be followed where one exists, and a self-built methodology that bypasses an applicable CSR requirement is exactly the kind of gap a certification body's external auditor is trained to look for.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
IATF 16949 Internal Auditor Training
Ready to become a qualified IATF 16949 internal auditor?

Self-paced · 365-day access · Training certificate included

View Course