ISO 9001

How to Conduct an ISO 9001 Internal Audit: A Step-by-Step Guide

To conduct an ISO 9001 internal audit, confirm the audit's scope and criteria against the audit program, prepare by reviewing relevant procedures and prior findings, hold an opening meeting, gather evidence through document review, observation, and interviews, document findings with specific evidence, hold a closing meeting to present results, issue a formal report, and verify corrective actions address the root cause.

Understanding why internal audits matter is one thing — actually running one, from the moment it's scheduled to the moment a corrective action is verified and closed, is a different skill entirely. This guide walks through the practical mechanics of conducting an ISO 9001 internal audit step by step. It is written by Maria Falbo, a Lead Auditor with decades of ISO 9001 experience, and is applicable whether your organization is on ISO 9001:2015 or is transitioning to ISO 9001:2026.

Maria Falbo|Lead Trainer, Logix ISO|August 2026|8 min read

Before You Begin: What Needs to Be in Place

Before any individual audit can happen, two things need to already exist: a risk-based audit program covering the full audit cycle, and an auditor who's both competent and impartial for the area being audited — meaning they don't audit their own work. If your organization doesn't yet have an established audit program, that's a planning-level decision that sits above any single audit — see our ISO 9001 Internal Audit: The Complete Guide for that broader context. This guide assumes the program already exists and walks through conducting one specific audit within it.

Plan the Individual Audit

Every individual audit needs its own plan, defining the scope, criteria, objective and schedule for that specific audit — not just referencing the broader program.

Scope defines exactly what's being audited — which process, which site, which product line. Criteria define what the audit is being measured against — the relevant ISO 9001 clauses, the organization's own procedures, and any applicable customer or regulatory requirements.

If your organization is transitioning to ISO 9001:2026, one addition applies here specifically: the standard now also requires a stated audit objective — a clear statement of why this particular audit is being conducted now, not just what's in scope and what it's being measured against. Organizations still on ISO 9001:2015 aren't required to document this separately, though stating a clear objective is good practice regardless of edition.

Prepare Before the Audit

Preparation is where audit quality gets determined, before the audit itself even begins. Pull together what's already known: has this area had findings before, and were they genuinely closed out or just marked resolved? What does the customer actually require here, beyond the base standard? Has anything changed since the last audit — new equipment, a process tweak, a personnel change — that the current procedure might not reflect?

This preparation is also where a structured checklist gets built — not as a rigid script, but as a framework ensuring comprehensive coverage. For a detailed breakdown of what a well-structured ISO 9001 audit checklist should cover clause by clause, see our ISO 9001 internal audit checklist guide.

Build the skills to conduct credible, evidence-based ISO 9001 internal audits from start to finish

Our ISO 9001 Internal Auditor course covers the full audit process, built on ISO 9001 and ISO 19011.

View Course

Hold the Opening Meeting

An ISO 9001 internal audit typically begins with a brief opening meeting to confirm the audit is understood and authorized before the fieldwork starts. A well-run opening meeting covers the scope, objectives, and criteria; the schedule and which areas will be visited; the methods the auditor will use; and who the auditor needs access to. Fifteen to thirty minutes is usually sufficient — this isn't meant to be a lengthy formality.

Gather Evidence: Document Review, Observation, and Interviews

The audit itself is conducted through three methods, and all three are necessary.

Document and records review comes first — pull the procedures, work instructions, and records covering the process.

Physical observation is where that paperwork gets tested against reality — watch the process actually happen, and check whether what's posted at the workstation, on the equipment, and in the calibration log lines up with what the documents claim.

Interviews are where the first two methods get stress-tested at once — ask someone to walk through a step in their own words rather than just confirm they follow it, and you'll find out fast whether they're working from genuine understanding.

In Practice

The single most valuable habit I try to instill in new auditors is following the evidence rather than the checklist. If an interview surfaces something unexpected — e.g. a step that's routinely skipped under time pressure — that thread is worth pursuing immediately, even if it means departing from the planned sequence. A checklist tells you where to start; it shouldn't dictate where the audit ends.

Document Findings as You Go

Record findings in real time as evidence emerges, rather than trying to reconstruct everything from memory at the end of the day. Every finding needs to be supported by objective evidence — something observed, a record reviewed, or a statement confirmed during an interview.

Vague findings don't help anyone fix anything. Instead of writing down a general impression, capture the specific detail as it happens — which record, which station, which person confirmed it, and on what date — while it's still in front of you and easy to verify, not reconstructed from memory later.

Hold the Closing Meeting

The closing meeting formally concludes the on-site portion of the audit, bringing together the same people who attended the opening meeting to present findings before the written report is issued. Cover what was audited, the evidence reviewed, all findings with their supporting evidence, and the expected timeline for corrective action responses.

Issue the Report

The audit report should follow promptly after the closing meeting, while the findings and context are still fresh for everyone involved. Clause 9.2 requires the report as a documented output, and Clause 9.3 requires it to feed into management review — practically, that means routing it to whoever actually controls resources and priorities for the area audited, not just archiving it in a shared drive nobody opens again.

Follow Up on Corrective Actions

The audit doesn't end when the report is issued. Whoever owns the nonconformity needs to investigate why it actually happened, put a fix in place that targets that real cause, and show it's holding up over time — and the auditor's follow-up isn't complete until that evidence has been checked, not just filed alongside the original finding.

In Practice

The follow-up step people skip most often is actually re-checking the fix, not just confirming the paperwork got submitted. I've seen plenty of corrective actions marked "closed" where the same underlying condition — a confusing work instruction, an unrealistic deadline — was still sitting there untouched, waiting to produce the exact same finding at the next audit.

FAQ

Frequently asked questions

How long does an ISO 9001 internal audit take?

It depends on the size and complexity of the scope. A single-process audit might take a few hours; a full-site audit covering multiple functions may take several days. What matters is comprehensive coverage of the defined scope, not speed.

Do I need a written checklist to conduct an ISO 9001 internal audit?

Not strictly required by the standard, but strongly recommended as a structured framework to ensure coverage — provided it's used as a guide rather than a rigid script that prevents following evidence where it leads.

Can one person conduct the entire audit alone?

Yes, for smaller audits. Larger or more technically complex audits sometimes use an audit team, with a lead auditor coordinating. The core requirement is competence and impartiality, not team size.

What happens if the auditor and the process owner disagree about a finding?

The auditor's role is to present objective evidence, not to win an argument. If a genuine disagreement remains after discussion, it's appropriate to note the process owner's response alongside the finding and let it be resolved through a defined mechanism, rather than the auditor unilaterally overriding it or dropping a well-evidenced finding to avoid conflict.

Does ISO 9001:2026 change the basic steps of conducting an audit?

No — the fundamental sequence remains the same. The one specific addition is that audit plans must now state a formal objective alongside scope and criteria, covered in the planning step above.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
ISO 9001 Internal Auditor Training
Ready to become a qualified ISO 9001 internal auditor?

Self-paced · 365-day access · Training certificate included

View Course