Resources · Quality management
Internal quality audits: how they work and how to prepare
An internal quality audit is a planned, independent check that your processes are being followed and are actually working, carried out by your own people to find gaps while there is still time to fix them.
An internal quality audit is a structured review, run from inside the organisation, that compares how work is supposed to happen with how it actually happens. Its job is not to catch people out. It is to find the gaps between procedure and practice early, so they can be fixed quietly rather than discovered by a customer, a regulator or an external auditor. Done well, an internal audit is one of the few moments where you deliberately go looking for problems before they find you.
What is an internal quality audit?
An internal quality audit is a systematic, independent and documented examination of whether your quality activities meet planned arrangements, whether those arrangements are being followed, and whether they are effective. The word internal simply means it is carried out by, or on behalf of, the organisation itself, rather than by an external certification body or a customer. It is sometimes called a first-party audit for that reason.
ISO 9001 requires organisations to conduct internal audits at planned intervals to check that the quality management system conforms to the standard and to the organisation’s own requirements, and that it is effectively implemented and maintained. The standard sets the obligation; how you meet it is left to you. The independence point matters: auditors should not audit their own work, because it is very hard to see the gaps in a process you run yourself.
An internal audit answers three questions: is the process defined, is it being followed, and is it working? A finding can fail any one of the three.
Why internal audits matter
The honest case for internal audits is that they are a cheap rehearsal. Almost everything an external auditor or a customer could find, you can find first, on your own terms, with time to put it right. An audit that surfaces a problem in March is a far better outcome than the same problem surfacing in a customer complaint or a certification visit in June.
There is a quieter benefit too. Processes drift. A procedure written two years ago slowly stops matching how the work is really done, often for sensible reasons that nobody wrote down. An audit either brings the practice back in line with the procedure or, just as usefully, updates the procedure to match a better way people have found. Both outcomes close the gap between paper and reality, which is where quality problems live.
How an internal quality audit works
A typical internal audit moves through a clear set of stages. The detail varies by organisation, but the shape is consistent.
- Plan and schedule. Decide what will be audited and when, usually across a year, with higher-risk or more variable processes audited more often. This is the audit programme.
- Prepare. The auditor reviews the relevant procedures, the requirements they must meet, and the findings from last time, then builds a checklist or set of questions for the audit.
- Hold an opening meeting. A short conversation to confirm the scope, timing and approach, and to set the tone: this is a check on the process, not on the person.
- Gather evidence. The core of the audit. The auditor observes work, interviews the people doing it, and examines records, comparing what they see against the requirement. Evidence, not opinion, drives every finding.
- Record findings. Each gap is written up clearly: what the requirement is, what was actually found, and the objective evidence for it. Findings are usually classified, for example as major non-conformances, minor non-conformances, or opportunities for improvement.
- Hold a closing meeting. Share the findings with the area audited, so there are no surprises and the facts are agreed.
- Report and follow up. Issue the audit report, then track each finding to resolution through corrective action. The follow-up is the part that actually changes anything.
That final step is where audits live or die. An audit that produces findings nobody acts on is theatre. Each finding should flow into the corrective and preventive action loop, with an owner and a date, so the gap is genuinely closed and verified.
How to prepare for an internal quality audit
If you are the one being audited, good preparation is mostly about being able to show that your process runs the way it is meant to. A few practical steps:
- Re-read the procedure for your area and check that what your team actually does still matches it. Where it does not, that is worth raising yourself rather than waiting for the auditor to find it.
- Make sure records are complete and findable. Most audit findings are not dramatic failures; they are missing, late or inaccurate records. If you can produce the evidence quickly, the audit goes smoothly.
- Check that previous findings were actually closed. A reopened finding from the last audit is one of the easiest things for an auditor to spot and one of the most avoidable.
- Confirm the basics: training records are current, equipment is in calibration, the documents in use are the latest versions.
- Brief your team honestly. Tell them an audit is coming, what it is for, and that the right answer to a question they are unsure of is “let me show you the record” or “I am not certain, let me check”, not a guess.
If you are the auditor, preparation means knowing the requirement well enough to ask precise questions, and planning to follow the evidence rather than a script. The best findings often come from pulling one thread, such as a single record, and following it through the whole process to see whether the system holds together end to end.
Common findings and how to avoid them
Most internal audit findings fall into a few familiar patterns: records that are missing or incomplete, procedures that no longer match practice, training or calibration that has lapsed, and corrective actions from earlier that were never verified as effective. None of these are exotic. They are the ordinary entropy of a busy operation, and the way to keep on top of them is not heroic effort once a year but steady, low-friction record-keeping all year round. That is exactly where good capture tools help.
Making audits less painful with good records
Audits are far easier when the evidence already exists and is easy to find. If non-conformances, inspections and corrective actions have been captured digitally as they happened, preparing for an audit becomes a matter of pulling up the record rather than reconstructing the year from memory. Logincident’s digital reporting captures audits, findings and actions with photo evidence in one place, and the quality solution tracks each finding through to closure, so the trail an auditor wants is already there. The audit itself stays a human judgement; the platform just makes the evidence trivial to produce. For how audits fit the wider system, see the quality management guide.
Frequently asked questions
What is the difference between an internal and an external audit?
An internal audit, also called a first-party audit, is carried out by or on behalf of the organisation itself to check its own quality system. An external audit is carried out by an outside party: a second-party audit by a customer or supplier, or a third-party audit by an independent certification body, for example to certify against ISO 9001.
How often should internal quality audits be done?
ISO 9001 requires audits at planned intervals but does not set a fixed frequency. Most organisations run an annual programme and audit higher-risk or more variable processes more often than stable ones. The schedule should be driven by risk and by where problems have appeared before.
Can someone audit their own work?
No. Auditors should be independent of the activity being audited, because it is very difficult to see the gaps in a process you run yourself. In a small organisation this can mean people from different departments auditing each other, or using a trained external auditor.
What is the difference between a major and a minor audit finding?
A major finding is a significant breakdown: a requirement not met in a way that affects the product or shows part of the system has failed. A minor finding is an isolated lapse that does not undermine the system on its own. Both need correcting; major findings usually demand formal corrective action and closer follow-up.
What happens to the findings after an audit?
Each finding is recorded with objective evidence, shared with the area audited, and assigned an owner and a date for corrective action. The findings feed into the corrective and preventive action loop and are tracked until they are resolved and verified. Following up on findings is what makes an audit worthwhile.
Sources
- International Organization for Standardization, ISO 9001:2015 Quality management systems: Requirements. https://www.iso.org/standard/62085.html
- International Organization for Standardization, ISO 19011:2018 Guidelines for auditing management systems. https://www.iso.org/standard/70017.html
Walk into your next audit with the evidence ready
Capture findings, actions and photo evidence as they happen, all tracked to closure.
Book a demo