Internal Audit

Partner with independent, qualified consultants for your ISO internal audits.

We ensure your organisation meets ISO 9001, ISO 27001, ISO 45001 and ISO 14001 standard requirements while promoting continual improvement to drive operational excellence.

Why Internal Auditing

In the context of ISO, the internal audit process is not a box-ticking exercise, but a mandatory requirement of ISO Management System standards (including ISO 9001, ISO 45001, ISO 14001, and ISO 27001), and is designed to facilitate continual improvement of your organisation’s operations.

A professionally conducted internal audit program acts as a high-level health check for your entire operation, and should be conducted for the following reasons:

1. Mandatory ISO requirement (Clause 9.2)

To achieve and maintain certification for standards like ISO 9001, ISO 14001, ISO 45001, or ISO 27001, you must demonstrate that you are conducting internal audits. Without a documented audit history, your Certification Body cannot issue or renew your ISO Certification.

2. A “Safety Net” for Your Certification

Think of the internal audit as a dress rehearsal. By identifying gaps, process failures, or documentation errors internally, you have the opportunity to implement corrective actions before an external auditor ever sets foot in your office. This significantly reduces the stress and cost associated with external audit “Major Non-Conformances.”

3. Verification of Process Effectiveness

Are your policies, processes and procedures actually being followed on the ground, or are they just merely “dust-collecting documents”? Internal audits provide management with factual evidence that the business is operating exactly how you intended (or not). The internal audit process picks up any gaps between what’s documented versus what is actually happening on the workshop floor or in the field.

4. Drive Continual Improvement

The most successful companies don’t just audit to find “what’s wrong”, but they audit to find “what could be better”. Expert auditors like the team at ISO Certification Experts identify “Opportunities for Improvement” (OFIs) that provide real business benefits and can help you:

  • Eliminate redundant steps in a process.
  • Reduce waste and operational costs.
  • Improve customer satisfaction and product quality.

5. Risk Mitigation & Due Diligence

Internal audits serve as a critical risk management tool. By systematically reviewing your quality, health and safety, environmental, or data security controls, you can identify emerging risks before they turn into expensive incidents, legal liabilities, or data breaches.

Key Differences - Internal vs. External Audits
Expert Tip:

When your internal audits are conducted by an expert third party like us, you gain a level of professional rigor, fresh perspective, and objectivity that internal staff simply cannot provide. This sends a powerful message to your clients and stakeholders that you are committed to the highest standards of governance.

Key Differences - Internal vs. External Audits
Expert Tip:

When your internal audits are conducted by an expert third party like us, you gain a level of professional rigor, fresh perspective, and objectivity that internal staff simply cannot provide. This sends a powerful message to your clients and stakeholders that you are committed to the highest standards of governance.

Why get us to conduct your audits?

  • We’re an expert “fresh set of eyes” providing valuable feedback for continual improvement
  • Often things can be missed or overlooked when audits are conducted by people who are too familiar with the business and its processes
  • Sometimes people aren’t comfortable raising issues when it relates to work undertaken by their colleagues, whom they need to work with every day
  • You don’t have a competent auditor within your business to conduct the audits, who can add real business value from the auditing process
  • Scheduled audits are consistently falling behind schedule
  • You would just rather focus on running the business
  • We can manage and effectively implement your organisation’s ongoing audit schedule

Start Your Journey with ISO Certification Experts

Book a FREE Strategy Session with us to discuss the best approach for your business, understand the benefits for your organisation, and find out how we can best help you achieve your goals!

The types of auditing services we provide

Internal Audits

Also known as ‘First Party Audits’, these are the main types of required audits to meet ISO Standards requirements for Certification. They are required by the ISO Management System standards prior to achieving Certification, and also regularly as part of the ongoing activities required for maintaining Certification.

Second Party Audits

These are not often part of the ISO Certification process. They could be conducted to verify that an interested party (for example, a subcontractor) is working in accordance with the contract arrangements to provide the specified services.

Compliance Audits

These can be project-specific audits or for certain areas of your organisation, and on an ad hoc or regular schedule. We can conduct your site safety and environmental inspections, ensuring your organisation is meeting “best practice” and compliance requirements for your type of workplace.

INTERNAL VS EXTERNAL AUDITS

While they may seem similar, Internal and External audits serve two very different purposes in the ISO Certification process.

  • Internal Audits are conducted by an organisation itself (their employees or an engaged consultant like ISO Certification Experts) to evaluate its own processes against the organisation’s own requirements and the ISO Standards requirements. Internal Audits meet ISO Standards requirements for Certification, and also serve as a proactive management tool, focusing on improving operational efficiency, risk management, and internal controls, with findings reported directly to the board or management. They need to be conducted at least once before achieving the Certification, and then on a regular and ongoing basis after Certification is achieved.
  • External Audits, also known as Certification audits, are performed by independent third-party accredited Conformity Assessment Bodies (CABs) (also commonly known as a Certification Body or Certifier) to provide an unbiased verification of an organisation’s management system against the requirements of the relevant ISO Standards, with the successful outcome resulting in achieving or maintaining ISO Certification. External auditors must remain strictly impartial and are forbidden from providing “consultancy” or any specific advice on how to address the audit findings. They can only tell you what is wrong, not how to fix it.

The table below outlines the key differences in objectives, frequency, and outcomes to help you prepare for both effectively:

FeatureInternal Audit (First-Party)External Audit (Third-Party)
Primary GoalInternal continual improvement.Formal certification and verification of conformance.
RequiredYes, an ISO Standard requirement (Clause 9.2).Yes, required process for achieving Certification.
Who Performs It?Internal qualified staff or hired consultants.Accredited Certification Body auditor.
Who is it for?The company’s management team.Customers, regulators and other relevant stakeholders.
Can the auditor give advice?Yes, they can suggest solutions.No, that is a conflict of interest.
FrequencyAs often as needed, taking a risk-based approach, at “regular intervals”.Usually annually (Certification, Surveillance, or Re-Certification).
ResultInternal Audit Report with findings and Corrective Actions.ISO Certificate & Audit Report with findings.
Impact of FailureAn opportunity to fix issues internally prior to client impact.Risk of losing or failing certification.

Please note ISO Certification Experts is not an Accredited Conformity Assessment Body. We’re a consulting and training business, and we do not conduct Third Party Audits to achieve certification to the requirements of a specific ISO Management System standard. Our role is to assist you in achieving ISO Certification Readiness and Business Process Improvement. No single organisation is allowed to do both the consulting and the certification parts of your project, as this is a conflict of interest and not meeting the ISO governing rule requirements.

The types of auditing services we provide

Internal Audits

Also known as ‘First Party Audits’, these are the main types of required audits to meet ISO Standards requirements for Certification. They are required by the ISO Management System standards prior to achieving Certification, and also regularly as part of the ongoing activities required for maintaining Certification.

Second Party Audits

These are not often part of the ISO Certification process. They could be conducted to verify that an interested party (for example, a subcontractor) is working in accordance with the contract arrangements to provide the specified services.

Compliance Audits

These can be project-specific audits or for certain areas of your organisation, and on an ad hoc or regular schedule. We can conduct your site safety and environmental inspections, ensuring your organisation is meeting “best practice” and compliance requirements for your type of workplace.

INTERNAL VS EXTERNAL AUDITS

While they may seem similar, Internal and External audits serve two very different purposes in the ISO Certification process.

  • Internal Audits are conducted by an organisation itself (their employees or an engaged consultant like ISO Certification Experts) to evaluate its own processes against the organisation’s own requirements and the ISO Standards requirements. Internal Audits meet ISO Standards requirements for Certification, and also serve as a proactive management tool, focusing on improving operational efficiency, risk management, and internal controls, with findings reported directly to the board or management. They need to be conducted at least once before achieving the Certification, and then on a regular and ongoing basis after Certification is achieved.
  • External Audits, also known as Certification audits, are performed by independent third-party accredited Conformity Assessment Bodies (CABs) (also commonly known as a Certification Body or Certifier) to provide an unbiased verification of an organisation’s management system against the requirements of the relevant ISO Standards, with the successful outcome resulting in achieving or maintaining ISO Certification. External auditors must remain strictly impartial and are forbidden from providing “consultancy” or any specific advice on how to address the audit findings. They can only tell you what is wrong, not how to fix it.

The table below outlines the key differences in objectives, frequency, and outcomes to help you prepare for both effectively:

FeatureInternal Audit (First-Party)External Audit (Third-Party)
Primary GoalInternal continual improvement.Formal certification and verification of conformance.
RequiredYes, an ISO Standard requirement (Clause 9.2).Yes, required process for achieving Certification.
Who Performs It?Internal qualified staff or hired consultants.Accredited Certification Body auditor.
Who is it for?The company’s management team.Customers, regulators and other relevant stakeholders.
Can the auditor give advice?Yes, they can suggest solutions.No, that is a conflict of interest.
FrequencyAs often as needed, taking a risk-based approach, at “regular intervals”.Usually annually (Certification, Surveillance, or Re-Certification).
ResultInternal Audit Report with findings and Corrective Actions.ISO Certificate & Audit Report with findings.
Impact of FailureAn opportunity to fix issues internally prior to client impact.Risk of losing or failing certification.

Please note ISO Certification Experts is not an Accredited Conformity Assessment Body. We’re a consulting and training business, and we do not conduct Third Party Audits to achieve certification to the requirements of a specific ISO Management System standard. Our role is to assist you in achieving ISO Certification Readiness and Business Process Improvement. No single organisation is allowed to do both the consulting and the certification parts of your project, as this is a conflict of interest and not meeting the ISO governing rule requirements.

Get a Free Initial Assessment of
your Organisation’s Certification
Readiness via the Form Below

Get a Free Initial Assessment of
your Organisation’s Certification
Readiness

Frequently Asked Questions about ISO Internal Audit Services

An internal audit is where a business evaluates the effectiveness of its own processes to ensure they are working exactly as intended, and are meeting relevant requirements, such as the requirements of ISO Standard(s). Think of it as a mock exam or a routine health check that you perform on your own business before the external auditor shows up to audit your management system for ISO Certification.

Instead of hunting for mistakes to get people in trouble, a healthy internal audit aims to answer three simple questions:
Are we following our own rules? (Are staff actually doing what your written policies, processes and procedures say they should be doing?)
Are we meeting relevant requirements? (Does your way of working meet your legal requirements and the requirements of the ISO standard(s) you are certified to?)
How can we do this better? (Where are the inefficiencies, bottlenecks, or hidden risks that are costing the business time or money?)

The Golden Rule of Internal Auditing: You cannot audit your own work. If you manage the Human Resources department, you can absolutely act as an internal auditor – but you’ll have to audit the Operations, IT or another department, while someone else steps in to audit yours. The ISO Management System Standards require objectivity and impartiality in the internal audit process.
Ultimately, an internal audit is an early-warning system. Finding a major issue during an internal audit is a win because it gives you the chance to fix it internally before an external auditor flags it as a non-conformance.

The short answer is: at planned intervals.
If you open up almost any major international standard (like ISO 9001, ISO 14001, ISO 45001 or ISO 27001) and look at Clause 9.2, you will notice that ISO does not state a specific timeline (like “every 90 days” or “once a year”). Instead, they leave the frequency up to you, expecting you to take a risk-based approach.

While the standard doesn’t say “do this annually”, we recommend a full system audit prior to the first Certification audit, and then regular internal audits within each 12 month period between your ISO audits. To maintain an active ISO certification, an external auditor will visit your business every 12 months and will expect to see records of internal audits that have been conducted over the course of the last year.

Yes, if your business wants to achieve and maintain an internationally-recognised ISO certification, internal audits are mandatory.

Internal audits are a non-negotiable requirement written directly into the clauses of every major international management system standard. If you flip to Clause 9.2 of the standards, the text explicitly states that the organisation shall conduct internal audits at planned intervals.

If an external certification auditor reviews your business and finds that you have skipped your internal audits, it results in an automatic ‘Major Non-Conformance’. This means you can lose your certification (or fail to get it in the first place).

Yes, you can absolutely conduct internal audits in-house, utilising your own employees. ISO standards do not require you to hire outside help for internal audits.

However, if you choose to do them in-house, an external certification auditor will look for proof that you are meeting two ISO requirements: Impartiality and Competence.

  1.  Impartiality (Independence): You cannot check your own “homework”. To ensure an unbiased review, internal staff must always audit a department outside of their own management or day-to-day responsibilities or, if this cannot be achieved, you then need to hire an external consultant like us.
  2.  Competence (Training): You must prove your internal auditors know what they are doing, and have been deemed competent to conduct management system internal audits. Staff selected to audit need proper training (like an internal auditor course) and an understanding of the audit criteria.
    That is why most companies hire consultants to conduct their management system Internal Audits.

This is actually a good thing. Finding a “Non-Conformance” or any other issue during an internal audit is an opportunity to fix the issue before it impacts a client or other important interested party to the organisation, or before the external Certification Body sees it. It demonstrates that your management system is working correctly because you are identifying and correcting gaps yourself.

A Gap Analysis is typically conducted at the very start of your Certification-readiness journey to see what you are missing to meet the requirements of the relevant ISO Standard(s). It’s a more high-level review of your management system against the Standard(s). An Internal Audit, on the other hand, is a formal check of your existing system to ensure it is being followed and remains effective in meeting your own organisation’s requirements as well as the requirements of the relevant ISO Standard(s).

It depends on the size and complexity of your business and the number of ISO standards you are covering. For a small-to-medium sized enterprise, an internal audit might take 1 to 2 days. We provide a clear timeline and audit plan upfront so there is minimal disruption to your daily operations.

No. An internal auditor (like ISO Certification Experts) prepares you and ensures you are ready for the external/certification audit. The final certificate is issued by an Accredited Certification Body after they perform their own external audit. Our goal is to ensure that when they arrive, you pass with flying colors.

Anyone can perform an internal audit, provided they meet two specific conditions: they are competent and they are independent of the area being reviewed.

You do not need a special license to do this. There are three types of people allowed to conduct your internal audits:
Trained and Competent Employees: Any member of your staff who has completed basic internal auditor training and has been deemed competent to conduct management system internal audits in accordance with ISO management system standard requirements.
External Consultants: A hired ISO professional who is qualified and deemed competent as a Lead Auditor or Internal Auditor comes in specifically to review your systems. They bring 100% automatic independence and expert knowledge.

NOTE: Anyone who directly manages, operates, or created the specific process being audited can not conduct the audit. You can never audit your own work.

An internal audit is a structured, step-by-step process. It isn’t a surprise raid; it is a collaborative, planned review.

The audit cycle focuses on gathering objective evidence to ensure your business processes are delivering effectively and match your documented information. An internal audit follows five stages:

  1. The Opening Meeting: The auditor meets with the department manager to confirm the scope of the audit, explain what they will be looking at, and ensure everyone is comfortable with the schedule.
  2. Evidence Gathering: The internal auditor uses three primary methods to verify conformance to your organisation’s own requirements and the requirements of the relevant ISO standards:
    – Interviews: Asking staff to explain how they perform the business processes.
    – Observation: Following a process with a real example in real time.
    – Document Review: Sampling records to verify that the team is following the documented processes.
  3. .The Closing Meeting: The auditor meets back up with management to debrief. They will highlight what the department is doing well and flag any “gaps” or non-conformances found during the day so there are no surprises in the report.
  4. Reporting: The auditor writes a formal Internal Audit Report. This document officially logs the findings, details the objective evidence gathered, and provides recommendations for improvement.
  5. Follow-up and Review:If the audit uncovered any issues, the department manager must outline a plan to fix them, and execute the plan. The auditor will review this during the next internal audit of this process to ensure the changes were effective.

Internal auditing relies on sampling, which means you only interview the necessary representative cross-section of your team.

Aim for a mix of:
– The Department Manager: To confirm the overall process and high-level controls.
– An Experienced Team Member: To verify how the process runs under normal, optimal conditions.
– A Recent Hire (Less than 6 months): This is highly valuable. Interviewing a new starter is the absolute best way to check if your onboarding, safety, and training systems are actually working.

The Focus is on the Process, not the Person: Remind your staff that you are auditing the system, not their individual performance. If a staff member forgets a step, it usually means the company’s training or written procedures need improvement, not that the employee is in trouble.

No. An internal audit cannot strip away your ISO certificate. External third-party auditors actually want to see issues raised in your internal audit reports. It proves to them that your internal audit process is honest, rigorous, and facilitates continual improvement. The only way you would get into trouble with an external auditor is if you hide a problem, or fail to take action to fix it after it was flagged.

Yes, you absolutely have to show your internal audit reports, including all the issues raised, to the external auditor.

During an ISO surveillance or certification audit, the external auditor will specifically ask to see your internal audit reports and your Corrective Action Register. They are required to review them under Clause 9.2 (Internal Audit) and Clause 10.2 (Non-conformance and Corrective Action) of the ISO management system standards.

Here is why showing your mistakes is actually the best strategy for passing your audit:

  1. It Proves Your System Actually Works
    External auditors are naturally suspicious of a “perfect” internal audit log. If you hand them a report from the past 12 months that says “100% conforming, zero issues found, everything is perfect,” they won’t believe it. They know every business has operational friction. A squeaky-clean report flags to the external auditor that either:
    – Your internal auditors did a lazy, superficial job; or
    – Your company is actively hiding systemic failures.

    When you show the external auditor a log detailing identified issues, alongside your documented plans to fix them, it proves your management system is honest, robust, and mature.
  2. The certification auditor will focus on Your Response, Not the Mistake
    An external auditor will not penalise you for a mistake you caught yourself, provided you are actively fixing it. When they look at an internal mistake, they are grading you on your corrective action process: [Internal Issue Found] ➔ [Root Cause Discovered] ➔ [Fix Put in Place] ➔ [Problem Solved]

    If you can show them that preventive and corrective action processes are documented in your records, the external auditor will easily be able to verify that your organisation is living continual improvement.

The One Thing That Will Get You Penalised:
The only time an internal mistake turns into an external penalty (a Major Non-Conformance) is if you knew about the problem and did nothing to fix it.
If an external auditor looks at your internal log and sees a major issue flagged six months ago that still has no corrective or preventive action plan or follow-up, they will likely raise a major non-conformance.

Be transparent. Show them the gaps, show them how you fixed them, and use your internally-identified issues to prove that your business is dedicated to getting better every day.

Have a question we didn’t answer here? Visit our full FAQ page.