ISO 9001

ISO 9001 Internal Audit: The Complete Guide to Quality Management System Auditing

An ISO 9001 internal audit is a planned, evidence-based assessment of whether an organization's Quality Management System conforms to ISO 9001 requirements and is effectively implemented and maintained. Required under Clause 9.2, it gives management objective information about how the QMS is functioning before an external certification auditor makes that same assessment.

ISO 9001 is the most widely implemented management system standard in the world, and its internal audit requirement — Clause 9.2 — is deceptively simple to state and genuinely demanding to execute well. A credible internal audit doesn't just confirm procedures exist; it tests whether the QMS is actually delivering the customer satisfaction and continual improvement the standard is built around. This guide is written by Maria Falbo, a Lead Auditor with decades of ISO 9001 experience, and covers the full internal audit lifecycle — from planning through corrective action follow-up — whether your organization is on ISO 9001:2015 or transitioning to ISO 9001:2026.

Maria Falbo|Lead Trainer, Logix ISO|August 2026|16 min read

What Is an ISO 9001 Internal Audit?

An ISO 9001 internal audit is a planned, evidence-based assessment of the organization's Quality Management System (QMS). Its purpose is to determine whether the QMS conforms to the requirements of ISO 9001 and to the organization's own procedures, and whether it is effectively implemented and maintained — as required by Clause 9.2 of the standard.

The key distinction is that an internal audit is a first-party audit — conducted by or on behalf of the organization itself, not by a certification body. It is not a compliance inspection, and it is not meant to catch people out. Its value lies in giving management verified, objective information about how the QMS is performing before an external auditor arrives to make that same assessment.

ISO 9001 internal audits are conducted in accordance with ISO 19011, the international guidelines for auditing management systems. Auditors are expected to apply its seven principles throughout: integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, and risk-based approach.

What Makes ISO 9001 Auditing Distinct

ISO 9001 auditing is built around three interlocking principles that shape what a credible audit actually examines: the process approach, customer focus, and risk-based thinking.

The process approach requires the auditor to understand how activities interconnect and influence each other, rather than reviewing each department or function in isolation — tracing how an input from one process becomes the output feeding the next, and where the handoffs between processes are most likely to break down. Organizations running ISO 9001 alongside ISO 14001 or ISO 45001 as an integrated system should pay particular attention here — see our guide on what an integrated management system is for how process ownership and audit programs can be shared across standards.

Customer focus means an audit isn't just checking whether procedures exist — it's checking whether the QMS is genuinely producing the customer satisfaction outcomes the standard exists to deliver. An auditor who confirms a customer feedback procedure exists, without ever checking whether that feedback actually changes anything downstream, has confirmed documentation, not customer focus.

Risk-based thinking, addressed under Clause 6.1, requires organizations to determine risks and opportunities affecting the QMS's ability to achieve its intended results — verifying the organization can demonstrate it actually identified risks and opportunities specific to its own operations, not just documented a generic statement that it did. For a full practical breakdown of this requirement, see our ISO 9001 risk and opportunity management guide.

Common ISO 9001 Nonconformities

Understanding where ISO 9001 audits most frequently find nonconformities is essential background for any internal auditor.

1. Risk and opportunity determination that's generic rather than specific. Organizations often document a boilerplate risk register that doesn't reflect their practical operating context — the same handful of risks copied across product lines, sites, or even entire divisions with no genuine analysis behind them. A risk register that reads identically for a five-person office and a two-hundred-person manufacturing floor is a strong signal it was never genuinely built from that organization's actual operations.

2. Objectives that aren't genuinely measurable. Clause 6.2 requires quality objectives to be measurable where practicable, but it's common to find objectives phrased so vaguely that progress can't actually be tracked against them — "improve customer satisfaction" rather than a specific, trackable target with a defined baseline and timeframe.

3. Corrective actions that address symptoms, not root causes. A nonconformity gets closed with a retraining record or a one-off fix, without the underlying process gap that allowed it to happen in the first place ever being identified. The same nonconformity often resurfaces at the next audit cycle, sometimes with a different employee's name attached to it.

4. Context of the organization treated as a one-time exercise. Clause 4.1 requires organizations to determine internal and external issues relevant to their purpose and strategic direction, including whether climate change is a relevant issue. Organizations that completed this analysis once and never revisited it often have a context statement that no longer reflects their actual current operating environment, market position, or regulatory landscape.

5. Documented information gaps at the evidence level. Procedures exist and look complete, but the specific records needed to demonstrate conformity — calibration evidence, competence records, monitoring data — have gaps that only surface when an auditor actually traces a specific example through to its source, rather than confirming the procedure describing that record exists.

Planning an ISO 9001 Internal Audit

Effective ISO 9001 internal auditing starts well before the audit itself. The audit program — required by Clause 9.2.2 — is the overarching arrangement that schedules and coordinates all internal audits over a defined period, typically a 12-month cycle. The individual audit plan then defines the scope, criteria, schedule, and methods for each specific audit within that program.

Building the Audit Program — The audit program must be risk-based. Clause 9.2.2 requires that it take into account the importance of the processes concerned, changes affecting the organization, and the results of previous audits. In practice, this means higher-risk or historically problematic processes should be audited more frequently than stable, well-established ones. A program that treats every process as equally deserving of the same audit time and depth isn't genuinely risk-based, regardless of what it claims on paper.

Auditor Competence and Independence — Clause 7.2 requires auditors to be competent, and Clause 9.2.2 requires that they conduct audits impartially — meaning they must not audit their own work. This does not mean auditors must be completely independent of the organization. Internal auditors can be employees, provided they are auditing areas they are not responsible for managing. A qualified quality manager can audit production; someone from production can audit the quality function.

Competence for QMS auditing means genuine knowledge of ISO 9001 requirements, familiarity with the organization's actual processes, and training in auditing techniques in line with ISO 19011 — not just general auditing technique applied uniformly regardless of what's being audited.

Pre-Audit Preparation — Before the audit begins, the auditor should review relevant procedures and previous audit findings, applicable customer requirements, and any recent changes to the process or its context. This review tells the auditor where risk is concentrated and where previous nonconformities were found — and shapes where audit time gets spent rather than treating every clause as equally worth the same attention. For a full clause-by-clause breakdown of what ISO 9001 requires, see our ISO 9001 Requirements Explained.

In Practice

The planning gap I see most consistently, across QMS audits generally, is treating the audit program as a fixed annual calendar rather than a genuinely risk-based document. An organization schedules "Purchasing" for Q2 and "Design" for Q3 every single year, regardless of what actually happened in the business over the past twelve months. A process that had a major nonconformity, a key personnel change, or a significant customer complaint since the last audit deserves earlier, more focused attention — not just its regularly scheduled slot on a calendar built once and never genuinely revisited.

Build the skills to conduct credible, evidence-based ISO 9001 internal audits

Our ISO 9001 Internal Auditor course covers the full audit process, from planning through corrective action, built on ISO 9001 and ISO 19011.

View Course

Conducting the Audit: What to Look For

An ISO 9001 internal audit is conducted through three primary evidence-gathering methods: document and records review, physical observation, and interviews with staff. All three are necessary. Document review alone is not sufficient — it tells the auditor what the system says, not what actually happens. Physical observation tells the auditor what is actually being done. Staff interviews reveal whether people understand what's expected of them and why. For a detailed breakdown of what a well-structured audit checklist should cover clause by clause, see our ISO 9001 internal audit checklist guide.

Document and records review establishes what the system says — procedures, work instructions, quality objectives, and the specific records that should demonstrate conformity.

Physical observation establishes what is actually happening — whether documented controls are genuinely being followed on the floor or in the office, whether equipment calibration labels match what's recorded, whether the version of a work instruction posted at a workstation matches the current controlled version rather than an outdated printout someone never replaced.

Interviews reveal whether people understand the QMS and their role within it. Open-ended questions — "walk me through what happens when a customer complaint comes in" — surface genuine understanding far more reliably than a yes/no confirmation that a procedure exists.

The most important discipline throughout is following the evidence rather than a rigid checklist. When an interview or observation surfaces something unexpected — a workaround nobody documented, a step that's routinely skipped under time pressure — the auditor pursues that thread rather than moving on to the next scripted item.

In Practice

One question I find consistently reveals whether a process owner genuinely understands their QMS responsibilities, versus having memorized a procedure: "What would you do if this specific step failed?" Someone who owns the process can answer specifically and immediately, often describing exactly who they'd escalate to and what containment action they'd take first. Someone who's only memorized the documented steps often hesitates, because the procedure was written by someone else and they've never actually had to think through the failure case themselves — which tells you the control exists on paper but hasn't been genuinely absorbed by the person responsible for it.

Reporting Audit Findings and Nonconformities

Audit findings must be reported accurately, objectively, and in sufficient detail for management to understand what was found, where it was found, and what evidence supports it. A finding that says "documentation is inadequate" gives management nothing to act on. A finding that specifies exactly which record was missing, for which process, on which date, and what requirement it fails to satisfy tells management precisely what needs to be fixed — and gives them a genuine basis for verifying the corrective action later actually addresses it.

Classifying Findings — ISO 9001 does not prescribe a finding classification system, but most organizations and certification bodies use a three-tier structure: major nonconformities, minor nonconformities, and observations.

A major nonconformity is a failure that represents either the complete absence of a required QMS element or a systemic breakdown in implementation — for example, no corrective action process existing at all, or a significant customer requirement with no controls in place to meet it. A major nonconformity at a certification audit puts certification at risk until it's resolved.

A minor nonconformity is an isolated departure from a requirement — a few records missing, a procedure not followed on some occasions with no systemic pattern. Multiple minor nonconformities in the same area can indicate a systemic issue and may be escalated to major.

Opportunities for Improvement are not nonconformities — they're areas where the QMS could be strengthened even though it isn't currently failing. A well-written audit report includes both findings and OFIs, giving management a complete picture of current state and improvement potential.

The audit report is a required documented output under Clause 9.2 and a mandatory input to management review under Clause 9.3 — meaning findings aren't just filed away after the audit closes; they're expected to genuinely inform how leadership steers the QMS going forward. If your organization needs expert support strengthening its QMS ahead of a certification audit, our ISO 9001 consulting services cover gap analysis through full certification preparation.

Corrective Action and Follow-Up

Identifying a nonconformity is the beginning of the process, not the end. Clause 10.2 requires that when a nonconformity occurs, the organization reacts to control and correct it, investigates the root cause, determines whether similar nonconformities exist or could occur, implements corrective actions to eliminate the root cause, and reviews the effectiveness of those actions.

This root cause requirement is where many organizations fall short. A corrective action for "operator missed a specification check" might be to retrain the operator — which addresses the symptom. The root cause analysis should go further: why did a trained, competent employee miss that check? Is the work instruction confusing? Is there time pressure that makes the step easy to skip? The corrective action must address the root cause, or the same nonconformity will reappear at the next audit.

Internal auditors play an important role beyond the initial finding. The audit program should include verification activities — a follow-up check at a defined interval to confirm that corrective actions have been implemented and are effective. A corrective action that was "closed" without verification hasn't actually been closed.

In Practice

The corrective actions I see fail most often are the ones that stop at "retrained the employee." A nonconformity gets closed with a training record, but nobody asks why a competent, already-trained person made that specific error in the first place. Often the real answer involves a confusing work instruction, an unrealistic time pressure, or a step that's genuinely easy to skip under normal working conditions. A corrective action that doesn't address that underlying condition won't, in most cases, prevent the same nonconformity from resurfacing at the next audit — and it's the auditor's job, on follow-up, to actually check whether the fix addressed the real cause or just the paperwork.

ISO 9001:2026 — What Changes for Internal Auditors

ISO 9001:2026 is the sixth edition of the standard, replacing ISO 9001:2015. Most certified organizations are still operating under the 2015 edition and will remain so for some time — ISO 9001:2026 carries a three-year transition period, so the changes below are worth understanding now, particularly for internal auditors who will need to update their audit programs once their organization makes the switch. For the full list of everything new in the revision, see ISO 9001:2026 Key Changes.

Defined audit objectives (Clause 9.2.2). Under the 2026 standard, internal audit programs must explicitly document audit objectives for each audit — not just scope and criteria. This is new: the 2015 edition requires criteria and scope to be defined but doesn't explicitly require a stated objective. Auditors transitioning to 2026 should update their program documentation to include this as a distinct field.

Risk and opportunity determination restructured (Clause 6.1). The 2015 edition treats risks and opportunities together in a single combined clause. The 2026 edition splits this into three separate subclauses — determining risks and opportunities, addressing risks, and addressing opportunities — each with its own dedicated requirements. Auditors checking Clause 6.1 conformance under 2026 should expect to see risks and opportunities addressed as complete exercises.

Interested party requirements now require explicit filtering (Clause 4.2). The 2015 edition requires organizations to determine interested parties and their requirements, but stops there. The 2026 edition adds an explicit additional step: organizations must determine which of those requirements will actually be addressed through the QMS. Auditors checking Clause 4.2 conformance under 2026 should expect to see this filtering decision documented, not just a raw list of every stakeholder and everything they might want.

Management review gains a new required input (Clause 9.3.2). The 2026 edition adds a distinct new input: changes in the needs and expectations of interested parties relevant to the QMS. Auditors verifying management review conformance under 2026 should check that this specific input was considered, not just folded into a general context discussion.

Quality culture and ethical behavior become explicit themes (Clauses 7.1.4, 7.3). The 2026 edition adds organizational quality culture and ethical behavior as an explicit awareness item, and references quality culture directly in the discussion of process environment. This doesn't translate into a new checklist item so much as a shift in what "awareness" conformance should be probed for during interviews.

Improvement content restructured (Clause 10). The 2015 edition splits general improvement principles across a separate "General" clause and a closing "Continual Improvement" clause. The 2026 edition merges these into a single Continual Improvement clause that now leads the Improvement section, with Nonconformity and Corrective Action following it in the same position it held before. The underlying expectations an auditor verifies — root cause analysis, effectiveness verification, systemic closure — don't change.

Organizations certified to ISO 9001:2015 are not starting from scratch when they transition. A structured gap analysis against the 2026 requirements is the right starting point, followed by a full step-by-step transition plan and updating the audit program to reflect the new and restructured clauses.

In Practice

A misconception worth addressing directly: climate change is not a new 2026 requirement. The requirement to determine whether climate change is a relevant issue to the organization's context was introduced into ISO 9001:2015 through a 2024 amendment, so it already applies to organizations currently certified to the 2015 edition. I still get asked regularly whether this is "coming" in the new revision — it isn't. The 2026 edition simply carries this requirement forward. Auditors should already be checking for it under the current standard, not waiting for the new edition to make it relevant.

FAQ

Frequently asked questions

How often does an ISO 9001 internal audit need to be conducted?

ISO 9001 requires internal audits at planned intervals but doesn't prescribe a specific frequency. The audit program must be risk-based, meaning higher-risk or historically problematic processes should be audited more frequently than stable ones. Most certified organizations audit their full QMS at least once per 12-month cycle.

Can the same person conduct the ISO 9001 internal audit every year?

Yes, provided they remain competent and impartial, meaning they do not audit areas they are personally responsible for. ISO 9001 does not require auditor rotation, but auditors must maintain current knowledge of the standard and the specific processes they're auditing.

What's the difference between a major and minor nonconformity?

A major nonconformity reflects a systemic failure — a complete absence of a required control, or a pattern of repeated failures with no evidence of correction. A minor nonconformity is an isolated departure with no indication of a broader systemic gap.

Does ISO 9001:2026 change what an internal auditor needs to look for?

Yes, in several specific ways — new required audit objectives, restructured risk and opportunity clauses, an additional management review input, and explicit quality culture themes are the most significant. These changes apply once your organization has transitioned; organizations still on ISO 9001:2015 aren't yet required to meet these specific additions. See the dedicated section above for the full breakdown.

Is climate change a new ISO 9001 requirement in the 2026 revision?

No — this is a common misconception. The requirement to determine whether climate change is a relevant issue to the organization's context was introduced into ISO 9001:2015 through a 2024 amendment, so it already applies to organizations currently certified to the 2015 edition. The 2026 revision carries this requirement forward rather than introducing it.

How does ISO 9001 auditing compare to IATF 16949 auditing for automotive suppliers?

IATF 16949 requires full ISO 9001 conformity as part of its own scope, with automotive-specific additions layered throughout — the audit methodology shares a common foundation, but IATF adds substantial technical depth. For a full comparison, see our article on IATF 16949 vs ISO 9001.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
ISO 9001 Internal Auditor Training
Ready to become a qualified ISO 9001 internal auditor?

Self-paced · 365-day access · Training certificate included

View Course