The internal audit process in one view
The internal audit process is the disciplined sequence a quality or compliance team follows to check that its own processes conform to a standard, to its own procedures and to customer requirements — and then to drive every gap it finds to a proven close. For an ISO 9001 or IATF 16949 manufacturer this is not optional housekeeping; clause 9.2 of ISO 9001 requires the organisation to conduct internal audits at planned intervals, and the whole certificate rests on being able to show a registrar that the programme actually runs.
Stripped to its essentials, a single internal audit moves through the same eight steps whatever the standard: manage the audit programme, plan the individual audit, prepare the checklist, hold the opening meeting, gather evidence, raise findings, report and hold the closing meeting, then track corrective action to closure. The discipline is in never skipping a step and never letting a finding die in an inbox.
The principles behind it — ISO 19011
Audit management is not improvised. ISO 19011, the international guideline for auditing management systems, sets out the principles every internal auditor is expected to work by, and Indian certification bodies audit against them directly. The seven principles are worth knowing because they explain why each step of the process exists:
- Integrity — the auditor works honestly, responsibly and within the law.
- Fair presentation — findings and reports reflect the audit truthfully and accurately.
- Due professional care — auditors apply diligence and judgement suited to the task.
- Confidentiality — information obtained during the audit is safeguarded.
- Independence — auditors are independent of the activity audited; nobody audits their own work.
- Evidence-based approach — conclusions rest on verifiable evidence from a rational sample.
- Risk-based approach — the programme and each audit are planned around the risks involved.
Two of these — independence and the evidence-based approach — are the ones a system enforces best. Independence means an auditor is assigned to audit a department other than their own; the evidence-based approach means every conformance verdict is traceable to what was actually seen — exactly what a recorded checklist answer captures.
Step 1 — Manage the audit programme
Before any single audit is planned, someone owns the audit programme: the annual view of every audit that must happen across every process, area and plant in a year. Building it is a risk-based exercise — processes that are critical, that have failed before, or that changed recently are audited more often than stable, low-risk ones. The output is an annual audit plan and calendar that says which process is audited, against which standard, in which month, by roughly whom.
In a manual programme this lives in a spreadsheet nobody updates once the year gets busy: audits slip, and the team crams three months of them into one panicked fortnight before the surveillance visit. A real programme generates the year's audits up front by frequency and count, spaces the due dates automatically, and routes the plan for approval — a controlled commitment, not a wish list.
Step 2 — Plan the individual audit
Each planned audit needs four things fixed before it happens: its scope (which process or area, which shifts, which sites), its criteria (the standard clauses, the procedures and the customer-specific requirements it is judged against), its schedule (the date and duration), and its auditor. The auditor decision is where independence and competency meet: the person assigned must be qualified for that audit type and must not be auditing their own area.
This is why auditor competency and authorisation is a step in its own right, not an afterthought. An auditor is scored against a criteria framework, their evidence (lead-auditor certificates, training records) is held on file, and the audit types they are authorised to conduct are recorded. When the plan assigns auditors, only eligible, authorised people appear — the control that a registrar most often asks to see.
Step 3 — Prepare the checklist and open
An auditor should never arrive empty-handed. The audit checklist — the reusable set of clause-mapped questions for that audit type — is prepared in advance so the audit is repeatable and comparable across auditors and across the year. Preparing also means reviewing the previous audit's findings for that area, because a professional audit always checks whether last time's non-conformances have stayed closed.
The audit then opens with a brief opening meeting where the auditor confirms scope, plan, criteria and practicalities with the auditee — setting the tone that an audit is a cooperative check of the process, not an exam of the person. For the method, see how to create an audit checklist that works.
Step 4 — Gather evidence and conduct
Conducting the audit is the visible part: the auditor walks the process, observes operations, interviews the people doing the work and samples records — control plans, work instructions, calibration logs, training records, previous NCs. Against each checklist question the auditor records a conformance verdict: complied, an opportunity for improvement, not applicable, or a non-conformance. Crucially, the verdict is anchored to a clause and to what was actually seen, so it can survive challenge.
Sampling matters here: no auditor checks every record, so the evidence-based principle asks for a rational sample large enough to support the conclusion. Doing this on paper and re-typing it later is where detail is lost, which is why mobile checklist entry on the floor — recording conformance, score, clause and observation at the point of observation — is now standard practice. For product and process audits the same step also captures parameter checks, sample readings and defect grades against the control plan.
Auditing on clipboards and re-typing the results?
See a live audit conducted on a phone — conformance, clause and observation recorded on the floor, NCs graded on the spot, and the report generated the moment you close. 30 minutes, on your standards.
Step 5 — Raise and grade the findings
Every non-compliant answer becomes a finding. A finding is not just "there was a problem" — it carries a clause number, a factual discrepancy statement (what was required versus what was found), and a grade. The standard grades are:
| Finding type | What it means | What it demands |
|---|---|---|
| Major non-conformance | A whole requirement is absent, or a failure that breaks the system's ability to deliver conforming product | Containment, root-cause and corrective action, often before the certificate is granted or renewed |
| Minor non-conformance | A single lapse against a requirement that is otherwise met — an isolated slip | Correction and corrective action within an agreed due date |
| Opportunity for improvement (OFI) | Conforms today, but could be strengthened before it becomes a problem | Considered, not mandatory; good programmes track them anyway |
The single most valuable attribute a finding can carry is the fresh-versus-repetitive flag — whether this non-conformance is new or a recurrence of one raised before. A repeat NC is the clearest signal that earlier corrective action failed, and it is invisible unless findings are recorded against clauses and compared automatically. See Findings, NC & CAPA Closure for how each finding is structured.
Step 6 — Report and close the meeting
The audit ends with a closing meeting where the auditor presents the findings, agrees them with the auditee and the area's head, and sets due dates. The output is the audit report and the non-conformance register — audit number, date, type, clause, discrepancy, grade, fresh/repetitive flag and owner. This register is the document a certification body reads first, so it must be complete and dated, not reconstructed from memory a week later.
Steps 7 & 8 — Corrective action and verified closure
The audit's value is realised only now. Each finding enters a controlled CAPA loop rather than an email thread:
Two distinctions separate a serious programme from a cosmetic one. First, correction is not corrective action: fixing today's defective part is correction; stopping it recurring is corrective action, and only the second closes an NC. Second, closure requires verification with evidence by someone other than the person who did the work. A major finding can escalate into Fast Quality's 8D / CAPA engine; for the mechanics, see the benefits of doing this in software.
Why the process fails on spreadsheets, and holds in a system
A mid-sized Indian manufacturer runs twelve internal audits a year. On spreadsheets the plan drifts, two audits are missed, and at the surveillance visit the registrar finds four NCs from last year still "open" with no evidence of closure. Re-run on a system: the audits are generated and approved up front, only competent auditors are assigned, findings are recorded on a phone against clauses, and every NC is driven through auditee, coordinator and auditor sign-off with reminders. The quality head opens the dashboard and shows the registrar the whole programme — planned, conducted, closed — at a glance.
How Fast Audit Software runs the process
Fast Audit Software, built by Improsys in Pune, implements every step above on one linked chain: reusable checklist templates; an annual and monthly plan generated by frequency and count and routed for approval; competency-gated auditor assignment; mobile checklist entry with conformance, score, clause and observations; graded findings flagged fresh or repetitive; and corrective action tracked through auditee, coordinator and auditor sign-off with reminders — all on auditee, auditor and HOD dashboards. It runs cloud or on-premise, standalone or across the Fast Suite, for ISO 9001 and IATF 16949, ISO 14001/45001, supplier and product/process audits.
Frequently asked questions
What are the steps of the internal audit process?
The internal audit process runs through eight steps: (1) manage the audit programme — the annual, risk-based calendar of audits; (2) plan the individual audit — fix its scope, criteria, date and a competent, independent auditor; (3) prepare the clause-mapped checklist and hold the opening meeting; (4) gather evidence by observing, interviewing and sampling records, recording a conformance verdict per question; (5) raise findings, each with a clause, discrepancy and major/minor/OFI grade and a fresh-or-repetitive flag; (6) report and hold the closing meeting, issuing the non-conformance register; (7) drive corrective action — correction, root cause and preventive action; and (8) verify and close each NC with objective evidence, with reminders on overdue actions.
What is ISO 19011 and how does it relate to internal audits?
ISO 19011 is the international guideline for auditing management systems. It defines seven principles auditors work by — integrity, fair presentation, due professional care, confidentiality, independence, the evidence-based approach and the risk-based approach — and gives guidance on managing an audit programme, conducting audits and evaluating auditor competence. It is guidance rather than a certifiable standard, but ISO 9001 and IATF 16949 internal audits are expected to follow it, and certification bodies check that auditors are independent of the area they audit and that findings rest on verifiable evidence.
What is the difference between a major and a minor non-conformance?
A major non-conformance is the absence of a whole required control, or a failure serious enough to break the system's ability to deliver conforming product; it usually must be corrected, with root cause and corrective action, before a certificate is granted or renewed. A minor non-conformance is an isolated lapse against a requirement that is otherwise met; it needs correction and corrective action within an agreed due date. An opportunity for improvement is not a non-conformance at all — the process conforms today but could be strengthened.
What is the difference between correction and corrective action?
Correction is the immediate fix — reworking or containing the affected product or record. Corrective action is what stops the problem recurring: investigating the root cause and changing the process, method or control so the same non-conformance does not come back. A finding is not closed by correction alone; it closes only when corrective action has been implemented and its effectiveness verified with objective evidence, ideally by someone other than the person who carried it out.
How often must internal audits be conducted for ISO 9001?
ISO 9001 clause 9.2 requires internal audits at planned intervals, but it does not fix a single frequency. In practice most organisations audit every process at least once a year and audit critical or previously non-conforming processes more often, using a risk-based schedule. The programme must cover the whole management system over its cycle, consider the importance and past performance of each process, and be documented so a certification body can see the plan, the completed audits and the closure of their findings.
