To conduct an ISO 14001 internal audit, establish a risk-based audit program, plan each audit with defined scope and criteria, prepare by reviewing your environmental aspects register and compliance obligations, gather evidence through document review, site observation, and staff interviews, document and classify findings, and follow up to verify corrective actions address root causes — not just symptoms.
An ISO 14001 internal audit is required under Clause 9.2 — but its real value lies in what it uncovers before your certification auditor does. A well-run EMS audit tells management whether environmental controls are actually working in practice, not just whether they exist on paper. This guide walks through each stage of the ISO 14001 internal audit process, drawing on the approach taught by Maria Falbo, a Lead Auditor with decades of ISO 14001 experience. It applies whether your organization is on ISO 14001:2015 or has transitioned to ISO 14001:2026.
ISO 14001 Clause 9.2 requires organizations to conduct internal audits at planned intervals to determine whether the EMS conforms to requirements and is effectively implemented. The clause has two parts: Clause 9.2.1 sets the objective — conformity and effectiveness — and Clause 9.2.2 governs the audit program itself, requiring it to be planned, implemented, maintained, and risk-based.
One distinction worth understanding before you start: an internal audit assesses conformity to the management system — whether the EMS is documented, implemented, and maintained as required. It is not the same as an evaluation of compliance with legal and regulatory requirements, which is a separate obligation under Clause 9.1.2. Both are required, but they serve different purposes and should not be conflated. An organization can have a fully conforming EMS and still have unresolved regulatory compliance gaps — and vice versa.
ISO 14001 internal audits are conducted in accordance with ISO 19011, the international guidelines for auditing management systems, which sets out the principles, program management, and audit methods that make the process systematic and evidence-based.
The audit program is the overarching framework that governs all internal audit activity across a defined period — typically a 12-month cycle. It is not a single audit. It is the arrangement that coordinates multiple audits across all processes, sites, and functions of the EMS to ensure full coverage over the cycle.
The program must be risk-based. Clause 9.2.2 requires it to account for the environmental importance of the processes being audited and the results of previous audits. Areas with significant environmental aspects — chemical storage, wastewater discharge, air emissions, waste management — warrant more frequent and more rigorous audit attention than lower-risk processes. Areas where previous audits found nonconformities also need increased frequency.
The compliance obligations register is another useful input to program planning: the more demanding the regulatory environment for a given process or location, the higher the audit priority. Under ISO 14001:2026, the program must also explicitly document audit objectives for each audit — what the audit is specifically intended to determine. This is a new requirement compared to the 2015 version, where objectives were implied rather than stated.
The most common audit program weakness is one that applies the same depth and frequency across all EMS processes regardless of risk. I regularly see programs where chemical storage and waste treatment — areas with significant environmental aspects and regulatory implications — are audited at the same interval as document control or training records. The program needs to reflect where the real environmental risk sits. Building that profile requires someone who understands the operation, not just the clauses.
Each audit within the program needs its own audit plan — a document that defines the scope, objectives, criteria, schedule, and methods for that specific audit. The scope sets the boundaries: which processes, locations, and functions are covered. The criteria are the requirements against which conformity will be assessed — the relevant ISO 14001 clauses, the organization's own procedures, and the applicable compliance obligations for that area.
The plan also assigns auditors. Clause 9.2.2 requires impartiality — auditors must not assess areas they are personally responsible for. This does not mean they need to be external. An environmental manager can audit the production department. A production manager can audit the environmental management function. What they cannot do is audit their own work.
Where the audit covers multiple processes or locations, the plan should include a realistic schedule. One of the most consistent causes of ineffective audits is time pressure — auditors rushing through high-risk areas because the plan doesn't allow adequate time for thorough evidence gathering.
Preparation is where audit quality is determined, before the audit begins. An auditor who has reviewed the right documents before walking onto the floor knows exactly where to look, what questions to ask, and what evidence to request.
In preparation for the audit if possible, the auditor should review the environmental aspects and impacts register — focusing on which aspects are assessed as significant, whether the register reflects current operations, and whether any recent process changes could have introduced new aspects that haven't been captured. The compliance obligations register should be reviewed to understand what legal and regulatory requirements apply to the area being audited. Previous audit reports and corrective action records reveal where nonconformities were found last time and whether they were properly closed. Environmental objectives and performance data show where targets are being met and where they are not. Relevant operational control procedures show what controls are supposed to be in place and what records should demonstrate they are being followed.
From this review, the auditor develops checklists — not to follow rigidly line by line, but as a structured framework that ensures coverage and prompts the right questions while leaving room to follow evidence wherever it leads. For a deeper look at what a well-structured ISO 14001 internal audit checklist covers by clause, see our ISO 14001 internal audit checklist guide.
Good preparation fundamentally changes what you find in the audit. Walking in having already reviewed the aspects register and noted that significant aspects related to solvent use haven't been updated since a major process change six months ago — you walk onto the floor already knowing what to look for. An auditor who walks in cold and works from a generic checklist will miss exactly the kinds of gaps that matter. The preparation is not preliminary work. It is part of the audit.
The ISO 14001 Internal Auditor course covers every stage of the audit process, from program planning through corrective action follow-up, built on ISO 14001 and ISO 19011.
ISO 14001 internal audit typically begins with an opening meeting. Its purpose is to confirm that the audit is authorized and understood, establish ground rules, and align expectations before fieldwork begins.
A well-run opening meeting covers the audit scope, objectives, and criteria; the schedule and which areas will be visited; the methods the auditor will use — document review, site observation, interviews; how findings will be classified and communicated; who the auditor needs access to; and the logistics for the closing meeting.
The opening meeting is also the right moment to surface any access or availability issues — not mid-audit. Keep it concise: fifteen to thirty minutes is typically sufficient. It is not a presentation. Its purpose is alignment, not formality.
The audit itself is conducted through three methods: document and records review, physical observation of operations, and interviews with staff. All three are necessary. Each produces a different type of evidence and together they give the auditor a complete picture of how the EMS is actually functioning.
Document and records review establishes what the system says. The auditor reviews EMS documentation — procedures, registers, monitoring records, training records, incident reports, corrective action records, management review minutes — to verify that required elements exist and that records demonstrate they are being applied. Key documents in an ISO 14001 audit include the environmental aspects and impacts register, the compliance obligations register, monitoring and measurement records, operational control procedures, emergency response plans, and environmental objectives performance data.
Physical observation establishes what is actually happening. The most common root cause of ISO 14001 nonconformities is the gap between what procedures describe and what occurs in the operation. Site observation reveals whether waste segregation is being practiced, whether chemical storage conditions match documented requirements, whether monitoring equipment is correctly positioned and in use, and whether environmental controls are being followed in the field — not just on paper. For a deeper explanation of how environmental aspects are identified, evaluated, and used to focus audit attention, see our guide to ISO 14001 environmental aspects and impacts.
Staff interviews reveal whether people understand the EMS and their role within it. Open-ended questions probe genuine understanding rather than rehearsed answers: "Walk me through what happens when you identify a potential environmental spill." "How do you know which waste goes in which container?" The answers reveal the real state of EMS awareness far more reliably than documents alone.
The most important discipline throughout is following the evidence rather than the checklist. When an interview surfaces something unexpected — a process change not reflected in the aspects register, a permit condition that wasn't in the pre-audit review, a corrective action that was closed without verification — the auditor pursues that thread. A checklist followed rigidly at the expense of evidence will consistently miss the most significant findings.
As evidence is gathered, the auditor records findings in real time. Every finding must be supported by objective evidence — something observed, a record reviewed, or a statement made by staff and subsequently verified. Findings without objective evidence cannot be raised as nonconformities.
Findings fall into three categories. A major nonconformity is a systemic failure — either the complete absence of a required EMS element, or a pattern of breakdown that shows the system is not functioning as intended. An example would be an organization that has a compliance obligations register but has never conducted a formal evaluation of whether those obligations are being met, with no records to demonstrate any evaluation has taken place. This is a Clause 9.1.2 failure and a major finding.
A minor nonconformity is an isolated departure with no evidence of a broader pattern — some training records missing for one employee, or monitoring measurements not recorded on the required date. Isolated in itself, but worth tracking: multiple minor nonconformities in the same area across an audit cycle are often the early signal of a systemic issue.
An observation or opportunity for improvement is not a nonconformity — it is an area the auditor has identified as a potential risk or improvement opportunity that does not yet constitute a failure. Including observations in the audit report gives management a forward-looking picture alongside the findings.
Specificity is what makes a nonconformity report useful. "Emergency response procedures are not current" gives management nothing to act on. "The operational control procedure in the solvent storage area has not been updated to reflect the introduction of two new solvent types in March 2026, as confirmed during document review and verified against the chemical inventory records and the site induction log" tells management exactly what failed, where, when, and what evidence supports the finding.
The closing meeting formally concludes the on-site audit. It brings together the same management and key personnel who attended the opening meeting, and its purpose is to present findings before the formal written report is issued.
The closing meeting covers what was audited, the evidence reviewed, all findings — major nonconformities, minor nonconformities, and observations — each with supporting evidence, any areas of good practice observed, and the timeline for the written report and corrective action responses. Findings are presented based on objective evidence. They are not open to negotiation, though auditees may clarify if they believe a finding is based on a misunderstanding of the evidence.
The audit report should be issued promptly after the closing meeting. A report that takes three weeks arrives too late to be useful. The findings are fresh, corrective action timelines need to start, and management needs the written record to assign accountability.
The audit report is a required documented output under Clause 9.2.2 and a mandatory input to management review under Clause 9.3. It is also one of the first things an external certification auditor will ask to see.
The audit does not end when the report is issued. Clause 10.2 requires that nonconformities be addressed through corrective action — and the audit program is responsible for verifying that those actions are implemented and effective, not merely submitted.
For each nonconformity, the responsible party must identify the root cause, define a corrective action that addresses that root cause, implement it, and provide evidence that it is working. The critical point is root cause, not symptom. A corrective action for "aspects register not updated to reflect new equipment" that consists only of updating the register has fixed the symptom. The root cause — why the register wasn't updated when the equipment was commissioned, and what process failed — must be investigated and corrected. Otherwise the same nonconformity reappears at the next audit.
The auditor's role is to verify, not just accept, that corrective actions have been closed effectively. A corrective action marked closed without verification has not actually been closed. Audit program follow-up should include a defined interval check that confirms actions were implemented and are working — and this status must be reported to management as a management review input under Clause 9.3.
For a broader understanding of how the internal audit fits into the full EMS lifecycle, see our ISO 14001 Internal Audit: The Complete Guide. For organizations preparing for initial certification or a transition audit and needing expert support, our ISO 14001 consulting services cover gap analysis, internal audit support, and full certification preparation.
The duration depends on the size and complexity of the organization and the scope of the audit. A small organization auditing its entire EMS might complete the process in a single day. A larger organization with multiple sites and significant environmental aspects may require several days spread across multiple sessions. What matters is that the audit covers all required areas with sufficient depth — not that it is completed quickly.
Internal auditors can be employees of the organization, provided they do not audit their own work. Impartiality means auditors must not assess areas they are personally responsible for — not that they need to be external. Auditors must also be competent, meaning they have adequate knowledge of ISO 14001 requirements, the organization's EMS, and auditing techniques in line with ISO 19011.
Key documents include the environmental aspects and impacts register, the compliance obligations register, previous audit reports and open corrective actions, environmental objectives and performance data, and the operational control procedures relevant to the area being audited. These documents tell the auditor where risk is concentrated and what evidence to look for during fieldwork.
ISO 14001 requires auditors to be competent — meaning they have the relevant knowledge and skills to conduct an effective EMS audit. While the standard does not mandate a specific training certificate, most certification bodies expect to see evidence of auditor training in competence records. A structured internal auditor training course provides that documented evidence and ensures auditors have the methodology to conduct credible, evidence-based audits.
Nonconformities must be addressed through the corrective action process under Clause 10.2. This requires identifying the root cause, implementing a corrective action that addresses that root cause, and verifying that the action is effective. The status of corrective actions must be reported to management as a management review input. Finding nonconformities during an internal audit is a sign the program is working — they should be found internally before your external certification auditor finds them.

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.
Learn more about Maria →Self-paced · 365-day access · Training certificate included