What clause 9.2 actually requires
Internal audit is not optional in ISO 9001:2015 — it is clause 9.2, one of the standard’s mandatory requirements, and it is where a surveillance audit most often finds an organisation wanting. The clause is short but exacting. Clause 9.2.1 says the organisation shall conduct internal audits at planned intervals to check that the quality management system conforms both to the organisation’s own requirements and to the requirements of ISO 9001, and that it is effectively implemented and maintained. Clause 9.2.2 then spells out how: plan, establish and maintain an audit programme; define audit criteria and scope for each audit; select auditors and conduct audits to ensure objectivity and impartiality; report results to relevant management; take correction and corrective action without undue delay; and retain documented information as evidence.
Read plainly, that is six obligations an Indian organisation must be able to evidence, not merely assert: a programme, criteria and scope, impartial competent auditors, reported results, timely closure, and retained records. Every one of those is a place a registrar can raise a non-conformance — and every one maps to a capability in audit management software.
The Indian SME certification journey
For most Indian SMEs, ISO 9001 certification runs through a familiar sequence: engage a consultant, build the documented QMS, run the processes for a few months, complete at least one full cycle of internal audits and a management review, then face the certification body’s Stage 1 (documentation and readiness) and Stage 2 (implementation) audits. After certification, surveillance audits follow annually, with recertification every three years.
Internal audit is load-bearing at every step. Stage 2 auditors will ask to see that you have audited the whole system before they arrived; surveillance auditors will sample your internal audit records to judge whether the system is genuinely self-correcting. The common Indian failure mode is well known: audits get done in a rush the week before the external visit, findings are closed on paper without real corrective action, competency records for the internal auditors do not exist, and the same non-conformances recur year after year because nobody tracked whether last year’s corrective action actually worked. A registrar spots this pattern quickly — and it is precisely the pattern a real audit system prevents.
Building the audit programme
Clause 9.2.2(a) requires a programme, not a scatter of audits — and it requires that the programme take into account the importance of the processes concerned, changes affecting the organisation, and the results of previous audits. In practice that means an annual plan that covers every process and clause of the QMS at a frequency set by risk, with more attention to critical or historically weak processes.
A capable system builds this as a single annual and monthly plan: pick the process or area, choose the matching clause-mapped checklist template, set a start date, a frequency and a count, and let it generate the year’s audits automatically — spacing due dates and routing the plan to the quality head for approval. The result is exactly what 9.2.2(a) asks for: a documented programme, risk-weighted, revisable when previous audits show a process needs auditing more often.
- Coverage. Every process and clause audited within the programme cycle — nothing quietly skipped.
- Frequency by importance. Critical or high-risk processes audited more often than stable ones — the risk-based thinking ISO 9001:2015 expects.
- Responsive to last year. Where previous audits raised repeat findings, the plan schedules earlier or more frequent follow-up.
Facing a surveillance audit with your programme in spreadsheets?
See a full clause 9.2 programme — annual plan, competent auditors, clause-mapped findings and closed NCs — running live in 30 minutes on your own processes.
Auditor competence and impartiality
Two requirements catch Indian SMEs repeatedly. First, impartiality: clause 9.2.2(c) says auditors shall not audit their own work. A one-person quality department cannot audit the quality process and claim objectivity — you need a pool of trained auditors from different functions who audit across departments. Second, competence: internal auditors must be trained and qualified, and you must retain evidence of it. “Everyone knows the process” is not a competency record.
ISO 19011 is the guidance every certification body draws on here. A defensible programme scores each auditor against competency criteria — education, training, auditing experience and standard knowledge — attaches the evidence (internal-auditor training certificates, ISO 19011 or lead-auditor course records), and records which audit types each person is authorised to conduct. The auditor competency and authorisation function does exactly this: an eligibility score, attached evidence, an authorised-audit-type matrix, and an approval step, so only competent, impartial, authorised auditors are ever assigned. When a registrar asks “how do you qualify your internal auditors?” you open the matrix rather than searching a drawer.
Conducting the audit and grading findings
With criteria and scope defined and a competent auditor assigned, the audit is conducted against the clause-mapped checklist. Every question gets a conformance verdict, and any answer that is not fully complied — excluding opportunities for improvement and not-applicable items — becomes a finding. Each finding carries a clause number, a description of the discrepancy observed, and an NC category that grades it:
| Finding type | What it means | Typical closure expectation |
|---|---|---|
| Major non-conformance | A clause requirement is absent, or a systemic breakdown risks non-conforming product or a failed process | Root-cause corrective action, verified with evidence, promptly |
| Minor non-conformance | A single lapse against a requirement that has not broken the whole process | Correction plus corrective action, closed without undue delay |
| Opportunity for improvement (OFI) | Conforming, but with scope to do better; not a non-conformance | Considered; no mandatory closure |
Crucially, the system flags each finding fresh versus repetitive — whether this non-conformance is new or a recurrence of one raised before. Repeat findings are the single clearest signal to a registrar that corrective action is not working, and the hardest thing to see on spreadsheets. Grading and repeat-detection turn the audit from a box-ticking ritual into the improvement loop clause 10 expects.
What Indian certification bodies check
When a certification body auditor samples your internal audit programme at a surveillance visit, they are looking for a small, predictable set of things. Knowing them lets you prepare the evidence, not scramble for it.
Evidence a registrar expects to see
Clause 9.2.2(f) requires you to retain documented information as evidence of the programme’s implementation and the audit results. For an Indian SME that means a retrievable record set: the annual audit plan and calendar; auditor competency and authorisation records; the completed checklists with conformance answers and observations; the non-conformance register with clause numbers, grades and fresh-or-repetitive flags; the corrective-action history with due dates and sign-offs; and the closure reports. On spreadsheets these live in different files with no link between finding and closure, so reconstructing the story for a registrar is slow and error-prone.
A system built for clause 9.2 keeps all of it as one linked chain, and stores the supporting files — certificates, evidence photos, closure reports — through document control, versioned and retrievable. See Findings, NC & CAPA closure for how the closure trail is retained per finding.
From last-minute panic to a live programme
A precision-machining SME certified to ISO 9001 used to build its internal audit records in the fortnight before each surveillance visit — and lost marks every year for repeat findings and missing competency records. Moving the programme onto a real system changed the shape of the problem: the annual plan generated the year’s audits up front, only trained auditors from other departments were assignable, findings were graded and clause-referenced as they were raised, and every NC was driven to verified closure with reminders on overdue actions. At the next surveillance audit the quality head answered every registrar question by opening a screen — and the repeat-finding count had fallen because corrective action was finally being verified, not just recorded.
How Fast Audit runs clause 9.2
Fast Audit Software, built in Pune by Improsys, implements the whole of clause 9.2 as one traceable programme for Indian organisations. Author a clause-mapped ISO 9001 checklist template; generate the annual and monthly plan by frequency and coverage; score and authorise impartial, competent auditors; conduct on a mobile worklist with conformance, score, clause and observations; grade and flag findings fresh or repetitive; and drive every NC to closure through auditee, coordinator and auditor sign-off with reminders — all visible on dashboards and the NC register. It runs standalone or as part of the wider suite, on-premise or cloud, and a major NC can escalate into Fast Quality’s 8D / CAPA. For automotive suppliers, the same engine extends to IATF 16949 layered audits.
Frequently asked questions
Is internal audit mandatory for ISO 9001 in India?
Yes. Internal audit is clause 9.2 of ISO 9001:2015, a mandatory requirement, and it applies to every certified organisation in India regardless of size. You must conduct internal audits at planned intervals covering the whole quality management system, use competent and impartial auditors who do not audit their own work, report results to management, take corrective action without undue delay, and retain documented information as evidence. A certification body will sample these records at Stage 2 and at every annual surveillance audit.
What does clause 9.2 of ISO 9001 require?
Clause 9.2.1 requires internal audits at planned intervals to confirm the QMS conforms to both ISO 9001 and the organisation's own requirements and is effectively implemented. Clause 9.2.2 sets out six duties: plan and maintain an audit programme that accounts for process importance and previous results; define criteria and scope for each audit; select impartial, objective auditors; report results to relevant management; take correction and corrective action without undue delay; and retain documented information as evidence. Each duty must be evidenced, not merely asserted.
How do Indian certification bodies check internal audits?
At surveillance and recertification audits, the registrar samples your internal audit records and looks for a documented programme covering the whole QMS at a risk-based frequency; evidence that auditors were competent and impartial; findings that are graded, clause-referenced and recorded; corrective action taken without undue delay and verified with objective evidence; and audit results feeding into management review. Repeat non-conformances that were never truly closed are the most common reason internal audit attracts a finding at surveillance.
How do you prove internal auditor competency for ISO 9001?
You retain evidence that each internal auditor is trained and qualified — typically internal-auditor or ISO 19011 course certificates, records of auditing experience, and knowledge of the standard — and you record which audit types each person is authorised to conduct. In an audit system this is a competency score against defined criteria, attached evidence files, and an authorised-audit-type matrix with an approval step, so only eligible, impartial, authorised auditors are assigned and the record is retrievable on demand for the registrar.
What is the difference between a major and minor non-conformance?
A major non-conformance is the absence of a required clause or a systemic breakdown that risks non-conforming product or a failed process; it demands root-cause corrective action verified with evidence, promptly. A minor non-conformance is a single lapse against a requirement that has not broken the whole process; it needs correction plus corrective action closed without undue delay. An opportunity for improvement is not a non-conformance at all — the process conforms but could be better — and carries no mandatory closure.
How does software help pass an ISO 9001 surveillance audit?
Audit management software keeps the entire clause 9.2 programme as one linked, retrievable chain: the annual plan, auditor competency records, completed checklists, the clause-referenced NC register with fresh-versus-repetitive flags, the corrective-action history with due dates and multi-role sign-off, and closure reports. It sends reminders on overdue actions, prevents unqualified auditors being assigned, and surfaces repeat findings automatically — so at surveillance you answer the registrar by opening a screen instead of rebuilding records, and repeat findings fall because corrective action is actually verified.
