Internal Audit – Complete Guide (ISO 9001, ISO 14001 & ISO 45001)
Introduction
An Internal Audit is one of the most important requirements of ISO Management Systems. It helps an organization evaluate whether its processes are working effectively and complying with ISO standards, legal requirements, and company procedures.
According to ISO 9001:2015, ISO 14001:2015, and ISO 45001:2018 (Clause 9.2), organizations must conduct internal audits at planned intervals to ensure the management system is implemented and maintained effectively.
Internal Audit is one of the most important tools used by an organization to check whether its management system is working as planned.
An organization may have:
- Policies.
- SOPs.
- Objectives.
- Risk assessments.
- HIRA.
- Environmental aspect registers.
- Training programs.
- Emergency procedures.
- Operational controls.
- Quality procedures.
- Safety procedures.
But an important question remains:
Are these requirements actually being followed and are they effective?
Internal Audit helps answer this question.
Under the ISO management-system standards, Clause 9.2 deals with Internal Audit.
For an Integrated Management System (IMS), internal audits can cover:
- ISO 9001 – Quality Management System
- ISO 14001 – Environmental Management System
- ISO 45001 – Occupational Health & Safety Management System
Internal Audit is therefore not simply an activity performed to find mistakes.
The purpose of Internal Audit is to provide objective information about whether the management system conforms to planned requirements and is effectively implemented and maintained.
What is an Internal Audit?
An Internal Audit is a systematic and planned examination of an organization's processes, activities, records, and controls.
The auditor checks whether:
- Required procedures are available.
- Procedures are being followed.
- Records are maintained.
- Applicable requirements are addressed.
- Objectives are being achieved.
- Controls are effective.
- Problems are identified and corrected.
Simple Meaning
Internal Audit = Check → Compare → Find Evidence → Identify Gaps → Improve
What is ISO Clause 9.2?
Clause 9.2 addresses the organization's internal audit requirements.
Although the three standards have similar internal-audit principles, the detailed requirements should be considered according to the applicable standard.
ISO 9001
Internal Audit focuses on the Quality Management System.
ISO 14001
Internal Audit focuses on the Environmental Management System.
ISO 45001
Internal Audit focuses on the Occupational Health & Safety Management System.
Internal Audit in an Integrated Management System
An organization implementing all three standards can develop an integrated audit program.
| Standard | Main Audit Focus |
|---|---|
| ISO 9001 | Quality |
| ISO 14001 | Environment |
| ISO 45001 | Occupational Health & Safety |
| IMS | Integrated process performance |
For example, a chemical warehouse receiving process can be audited from three perspectives.
ISO 9001
- Correct material received.
- Quantity verified.
- Documentation checked.
- Material identification maintained.
ISO 14001
- Chemical leakage controls.
- Packaging waste.
- Environmental controls.
- Spill preparedness.
ISO 45001
- PPE.
- Safe unloading.
- Manual handling.
- Emergency preparedness.
- HIRA controls.
One audit activity can therefore provide evidence for multiple management-system requirements.
Why is Internal Audit Important?
Internal Audit helps an organization:
- Identify nonconformities.
- Identify weaknesses.
- Verify implementation.
- Check process effectiveness.
- Monitor compliance with internal procedures.
- Identify improvement opportunities.
- Verify corrective actions.
- Prepare for external audits.
- Reduce operational risks.
- Support continual improvement.
The biggest benefit is not simply finding findings.
The real benefit is:
Finding problems before they become bigger problems.
Internal Audit vs External Audit
These two activities are different.
| Internal Audit | External Audit |
| Conducted by or on behalf of the organization | Conducted by an external organization/person |
| Mainly for internal improvement and assurance | May be for certification, customer, regulatory, or other purposes |
| Organization controls the audit program | External auditor controls their audit activity |
| Can be more frequent | Usually conducted according to external requirements |
| Focuses on organizational processes and system requirements | Provides independent external assessment |
Internal Audit Program
The organization should establish an audit program based on relevant considerations.
An audit program can define:
- What will be audited.
- When it will be audited.
- Who will audit.
- Which criteria will be used.
- Which processes are covered.
- Reporting requirements.
- Follow-up activities.
The audit program should consider the importance of processes, changes affecting the organization, and results of previous audits.
How Often Should Internal Audit Be Conducted?
There is no universal rule that every process must automatically be audited every month or every year.
The organization should determine appropriate audit frequency based on factors such as:
- Process importance.
- Risks.
- Previous audit results.
- Changes.
- Performance.
- Nonconformities.
- Customer issues.
- Environmental significance.
- OH&S risks.
Example
A high-risk chemical storage activity may require more frequent attention than a low-risk administrative activity.
Similarly, a process with repeated audit findings may need additional audit follow-up.
Internal Audit Process
A practical Internal Audit process is:
Prepare Audit Program
↓
Define Audit Scope
↓
Define Audit Criteria
↓
Select Auditor
↓
Prepare Audit Plan/Checklist
↓
Conduct Opening Meeting
↓
Collect Objective Evidence
↓
Interview / Observe / Review Records
↓
Compare Evidence with Criteria
↓
Identify Findings
↓
Conduct Closing Meeting
↓
Prepare Audit Report
↓
Corrective Action
↓
Verify Effectiveness
↓
Close Finding
Step 1 – Prepare the Audit Program
Before starting the audit, prepare an annual or planned audit program.
Example:
| Process | Standard | Planned Month | Status |
| Purchase | ISO 9001 | April | Completed |
| Warehouse | ISO 9001/14001/45001 | May | Completed |
| HR & Training | IMS | June | Completed |
| Emergency Preparedness | ISO 45001/14001 | July | Planned |
| Waste Management | ISO 14001 | August | Planned |
| Management Review | IMS | September | Planned |
The actual program should be based on the organization's processes and risks.
Step 2 – Define Audit Scope
The audit scope defines what is included in the audit.
Example:
Scope: Warehouse receiving, storage, material handling and dispatch activities.
Or:
Scope: Environmental management controls related to waste handling and chemical storage.
A clear scope helps the auditor remain focused.
Step 3 – Define Audit Criteria
Audit criteria are the requirements against which evidence is compared.
Criteria may include:
- ISO requirements.
- Company policies.
- SOPs.
- Work instructions.
- Legal requirements where applicable.
- Customer requirements.
- Internal procedures.
- Objectives.
- Risk controls.
Example
If auditing chemical storage:
Criteria:
- Storage SOP.
- HIRA.
- Environmental aspect register.
- Emergency procedure.
- PPE requirements.
- Applicable ISO requirements.
Step 4 – Select the Auditor
The auditor should be competent and should conduct the audit objectively.
Where appropriate, auditors should not audit their own work in a way that compromises objectivity and impartiality.
Example
If an employee is responsible for maintaining a particular process, assigning that same person to audit their own process may create an objectivity concern.
An organization can use:
- Trained internal auditors.
- Cross-functional auditors.
- Competent employees from another department.
- External/internal audit support where appropriate.
Auditor Competence
An internal auditor should understand:
- Applicable ISO requirements.
- Audit principles.
- Audit techniques.
- Process approach.
- Objective evidence.
- Nonconformity identification.
- Root-cause thinking.
- Reporting.
- Follow-up.
For an IMS auditor, additional knowledge may be required in:
- Quality.
- Environment.
- OH&S.
Step 5 – Prepare the Audit Checklist
An audit checklist helps the auditor conduct a systematic audit.
However:
An auditor should not treat the checklist as a questionnaire only.
The auditor should follow evidence and ask additional questions where necessary.
Example – Warehouse Audit Checklist
Quality
☐ Material identification verified.
☐ Receiving records maintained.
☐ Damage material controlled.
☐ Expired material controlled.
☐ Dispatch verification performed.
☐ Customer requirements addressed.
Environment
☐ Waste segregation maintained.
☐ Chemical leakage controls available.
☐ Spill kit available.
☐ Environmental aspect controls implemented.
☐ Waste disposal records maintained where applicable.
Safety
☐ PPE available and used.
☐ HIRA controls implemented.
☐ Emergency exits accessible.
☐ Fire extinguishers accessible.
☐ Emergency contacts displayed.
☐ Safety inspections completed.
Step 6 – Opening Meeting
The auditor may conduct a short opening meeting.
The meeting can cover:
- Purpose.
- Scope.
- Criteria.
- Audit schedule.
- Persons involved.
- Method of audit.
- Communication during the audit.
For a small organization, the opening meeting can be simple.
Step 7 – Collect Objective Evidence
This is one of the most important parts of Internal Audit.
The auditor should collect objective evidence.
Evidence can come from:
Documents
- Policies.
- SOPs.
- Procedures.
- HIRA.
- Aspect registers.
Records
- Inspection records.
- Training records.
- Audit records.
- Maintenance records.
- Calibration records.
- Waste records.
Observation
The auditor physically observes the activity.
Interviews
Employees are asked relevant questions.
Sampling
A suitable sample of records or activities is checked.
What is Objective Evidence?
Objective evidence is information that can be verified.
Example
Instead of saying:
"Employees are trained."
The auditor should verify:
- Training record.
- Training topic.
- Date.
- Participants.
- Competence/evaluation where applicable.
Another Example
Instead of saying:
"Fire equipment is maintained."
The auditor can check:
- Physical condition.
- Inspection record.
- Maintenance/refill record.
- Identification/tagging.
Three Important Audit Techniques
A good auditor commonly uses:
1. Interview
Ask the employee.
"What do you do if you find damaged chemical packaging?"
2. Observation
Watch the actual activity.
Is the material actually stored as required?
3. Record Review
Check evidence.
Is the inspection record completed?
This can be remembered as:
Interview + Observation + Records = Strong Audit Evidence
Process Approach to Internal Audit
Internal Audit should not focus only on documents.
The auditor should understand:
Input → Activity → Output → Monitoring → Result
Example – Warehouse Receiving
Input:
Material from supplier.
↓
Activity:
Unloading and inspection.
↓
Output:
Accepted/controlled material.
↓
Records:
Receiving documentation.
↓
Monitoring:
Damage/quantity verification.
↓
Result:
Correct material available for storage/dispatch.
This provides a more practical audit.
ISO 9001 Internal Audit
ISO 9001 Internal Audit focuses on the Quality Management System.
Auditors may examine:
- Customer requirements.
- Purchase process.
- Supplier performance.
- Receiving.
- Material identification.
- Storage.
- Dispatch.
- Customer complaints.
- Nonconformity.
- CAPA.
- Quality objectives.
- Process performance.
- Documented information.
ISO 14001 Internal Audit
ISO 14001 Internal Audit focuses on environmental management.
Auditors may examine:
- Environmental aspects and impacts.
- Significant environmental aspects.
- Environmental objectives.
- Waste management.
- Chemical storage.
- Spill controls.
- Resource consumption.
- Operational controls.
- Emergency preparedness.
- Compliance obligations.
- Environmental performance.
ISO 45001 Internal Audit
ISO 45001 Internal Audit focuses on OH&S management.
Auditors may examine:
- Hazard identification.
- HIRA.
- OH&S risks.
- PPE.
- Training.
- Worker consultation.
- Safety inspections.
- Incident reporting.
- Near misses.
- Emergency preparedness.
- Fire safety.
- Occupational health.
- OH&S objectives.
Integrated Audit Example – Chemical Warehouse
Consider the activity:
Chemical Unloading
ISO 9001
Auditor checks:
- Correct material received.
- Quantity verified.
- Damage inspection.
- Supplier documents.
ISO 14001
Auditor checks:
- Spill prevention.
- Packaging condition.
- Waste handling.
- Environmental emergency controls.
ISO 45001
Auditor checks:
- PPE.
- Safe unloading.
- Manual handling.
- HIRA.
- Emergency arrangements.
This is a practical example of an IMS Internal Audit.
Internal Audit Findings
Audit findings should be based on evidence.
Common classifications may include:
- Conformity.
- Observation.
- Opportunity for Improvement.
- Nonconformity.
The organization should define its own classification method in its audit procedure.
What is a Nonconformity?
A nonconformity occurs when a requirement is not fulfilled.
Example
Requirement:
A documented procedure requires monthly workplace inspections.
Evidence:
The last three months have no inspection records.
Finding
The required inspection process has not been implemented as planned.
The auditor should clearly identify:
- Requirement.
- Objective evidence.
- Gap.
Writing a Good Audit Finding
A strong finding should be:
- Clear.
- Specific.
- Evidence-based.
- Objective.
- Traceable.
- Related to a requirement.
Weak Finding
"Warehouse safety is not good."
This is vague.
Better Finding
"The monthly workplace inspection procedure requires inspection records to be maintained. However, inspection records for June and July were not available for verification."
This provides:
Requirement + Evidence + Gap
Observation vs Nonconformity
Observation
A potential concern that may require attention but does not necessarily demonstrate a failure to meet a requirement.
Nonconformity
A requirement has not been fulfilled.
The organization should use its defined audit classification criteria consistently.
Corrective Action After Internal Audit
When a nonconformity is identified, the organization should take appropriate action.
Typical process:
Finding
↓
Correction
↓
Root Cause Analysis
↓
Corrective Action
↓
Implementation
↓
Effectiveness Verification
↓
Closure
This connects Internal Audit with CAPA.
Internal Audit and CAPA
Internal Audit identifies the problem.
CAPA addresses the problem and its cause.
Example
Audit Finding:
Fire-extinguisher inspection records were not available for the required period.
Correction
Complete the pending inspection.
Root Cause
Responsibility for monitoring the inspection schedule was not clearly assigned.
Corrective Action
- Assign responsibility.
- Update monitoring system.
- Set reminder.
- Train responsible person.
Effectiveness
Verify subsequent inspection records.
Follow-Up Audit
Audit work does not necessarily end when the report is issued.
Follow-up may be required to verify:
- Correction completed.
- Root cause addressed.
- Corrective action implemented.
- Action effective.
- Finding closed.
A simple follow-up record can include:
| Finding | Action | Evidence | Effectiveness | Status |
| IA-01 | Procedure updated | Revised SOP | Effective | Closed |
| IA-02 | Training completed | Training record | Effective | Closed |
Internal Audit Report
A practical Internal Audit Report can include:
Company Name: __________
Audit No.: __________
Audit Date: __________
Auditor: __________
Process Audited: __________
Audit Scope: __________
Audit Criteria: __________
Summary
- Conformities.
- Observations.
- Nonconformities.
- Improvement opportunities.
Findings
| Sr. No. | Requirement | Evidence | Finding | Classification |
| 1 | ||||
| 2 |
Follow-Up
| Finding | Responsible | Target Date | Status | Effectiveness |
Internal Audit Programmed Example
| Audit No. | Process | ISO | Auditor | Month |
| IA-01 | Purchase | ISO 9001 | Internal Auditor | April |
| IA-02 | Warehouse | IMS | Internal Auditor | May |
| IA-03 | HR/Training | IMS | Internal Auditor | June |
| IA-04 | Emergency Preparedness | ISO 14001/45001 | Internal Auditor | July |
| IA-05 | Waste Management | ISO 14001 | Internal Auditor | August |
| IA-06 | Management Processes | IMS | Internal Auditor | September |
The organization should determine its actual audit frequency and coverage based on its needs, risks, process importance, previous results, and changes.
Internal Audit Checklist – IMS
ISO 9001
☐ Customer requirements reviewed.
☐ Purchase controls implemented.
☐ Supplier performance monitored.
☐ Receiving process controlled.
☐ Material identification maintained.
☐ Customer complaints monitored.
☐ Nonconformities controlled.
☐ CAPA implemented.
☐ Quality objectives monitored.
☐ Documented information controlled.
ISO 14001
☐ Environmental aspects identified.
☐ Significant aspects evaluated.
☐ Environmental objectives monitored.
☐ Waste segregation implemented.
☐ Chemical spill controls available.
☐ Environmental emergency controls implemented.
☐ Environmental records maintained.
☐ Compliance obligations evaluated.
☐ Environmental performance monitored.
☐ Corrective actions implemented.
ISO 45001
☐ Hazards identified.
☐ HIRA reviewed.
☐ OH&S risks controlled.
☐ PPE available and used.
☐ Training completed.
☐ Worker consultation/participation implemented.
☐ Incident/near-miss reporting available.
☐ Emergency preparedness implemented.
☐ Fire safety controls maintained.
☐ OH&S objectives monitored.
Internal Audit Questions for Warehouse Employees
Auditors may ask employees practical questions.
Question 1
What do you do if you find damaged material?
Expected answer should reflect the actual company procedure.
Question 2
What PPE is required for your activity?
Employee should explain PPE applicable to their task.
Question 3
What do you do in case of chemical leakage?
Employee should know the relevant emergency/spill-response procedure.
Question 4
Where is the emergency exit?
Employee should know the applicable route.
Question 5
Where is the assembly point?
Employee should know the designated location.
Question 6
How do you report a near miss?
Employee should explain the actual reporting process.
Question 7
What happens to damaged or expired material?
Employee should explain the established control process.
Auditor Should Follow the Evidence
A good auditor does not decide the answer before collecting evidence.
For example:
Employee says:
"We inspect the warehouse every month."
Auditor should verify:
- Inspection checklist.
- Recent records.
- Actual workplace condition.
- Action status for previous findings.
If records are available and workplace conditions support the statement, the evidence is stronger.
Internal Audit Sampling
Auditors generally cannot check every single transaction or record.
Therefore, appropriate sampling may be used.
For example:
Instead of checking every training record, the auditor may select samples based on risk, process importance, and audit objectives.
Similarly:
- Several receiving records.
- Several dispatch records.
- Selected inspection records.
- Selected CAPA records.
- Selected training records.
Sampling should be sufficient to provide reasonable audit evidence.
Internal Audit and Risk-Based Thinking
Audit planning should consider risk.
High-risk activities may deserve greater attention.
Chemical Warehouse Example
Higher attention may be given to:
- Chemical storage.
- Loading/unloading.
- Spill response.
- Fire safety.
- Manual handling.
- Emergency preparedness.
Lower-risk administrative activities may require a different level of audit attention.
Internal Audit and Previous Findings
Previous audit results are important when planning future audits.
If the same finding repeatedly occurs:
Management should investigate whether the corrective action was actually effective.
Recurring findings can indicate:
- Weak root-cause analysis.
- Inadequate corrective action.
- Poor implementation.
- Lack of ownership.
- Inadequate monitoring.
Internal Audit and Management Review
Internal Audit results should provide useful information for Management Review.
Management may review:
- Number of findings.
- Recurring findings.
- Major process weaknesses.
- CAPA status.
- Audit trends.
- Resource needs.
- Improvement opportunities.
This creates a management-system cycle:
Internal Audit
↓
Findings
↓
CAPA
↓
Effectiveness
↓
Management Review
↓
Improvement
Common Internal Audit Mistakes
1. Auditing Only Documents
Internal Audit should also verify actual implementation.
2. Checklist-Based Auditing Only
The auditor should investigate evidence rather than simply tick boxes.
3. Auditing Own Work
This can compromise objectivity.
4. Vague Findings
Findings should identify requirement and evidence.
5. No Evidence
An auditor should not make conclusions without objective evidence.
6. No Follow-Up
Findings should be followed up where corrective action is required.
7. Same Finding Every Year
Repeated findings indicate that previous action may not have been effective.
8. Only Auditing Before Certification
Internal Audit should be part of the organization's regular management-system process.
9. Ignoring Employees
Employee interviews can reveal practical implementation issues.
10. Focusing Only on Nonconformities
Audits should also identify conformities, strengths, and improvement opportunities.
How to Conduct an Effective Internal Audit
Before Audit
- Review previous audit findings.
- Review process risks.
- Prepare audit program.
- Define scope and criteria.
- Select competent auditor.
- Prepare checklist.
During Audit
- Conduct opening meeting.
- Interview employees.
- Observe activities.
- Review records.
- Collect objective evidence.
- Compare evidence with criteria.
- Record findings clearly.
After Audit
- Conduct closing meeting.
- Prepare report.
- Communicate findings.
- Assign corrective actions.
- Track target dates.
- Verify effectiveness.
- Close findings.
Internal Audit Do's
✔ Plan audits.
✔ Use risk-based planning.
✔ Define scope and criteria.
✔ Use competent auditors.
✔ Maintain objectivity.
✔ Collect objective evidence.
✔ Interview employees.
✔ Observe actual activities.
✔ Review records.
✔ Write clear findings.
✔ Follow up corrective actions.
✔ Verify effectiveness.
✔ Maintain audit records.
✔ Use audit results for improvement.
Internal Audit Don'ts
❌ Do not audit only documents.
❌ Do not make assumptions.
❌ Do not write vague findings.
❌ Do not audit your own work where objectivity is compromised.
❌ Do not ignore evidence.
❌ Do not close findings without verification.
❌ Do not copy previous audit reports without actual verification.
❌ Do not conduct audits only before certification audits.
❌ Do not focus only on finding mistakes.
Internal Audit Checklist
Before closing an Internal Audit, verify:
☐ Audit program established.
☐ Audit scope defined.
☐ Audit criteria defined.
☐ Auditor competency considered.
☐ Auditor objectivity maintained.
☐ Audit plan prepared.
☐ Previous findings reviewed.
☐ Relevant risks considered.
☐ Employees interviewed.
☐ Activities observed.
☐ Records reviewed.
☐ Objective evidence collected.
☐ Findings documented.
☐ Closing meeting completed.
☐ Audit report issued.
☐ Corrective actions assigned.
☐ Target dates defined.
☐ Follow-up performed.
☐ Effectiveness verified.
☐ Findings closed where appropriate.
Practical Example – Internal Audit in a Chemical Warehouse
Suppose the auditor is checking chemical storage.
Step 1 – Requirement
The warehouse SOP requires chemicals to be stored in designated locations with proper identification and controls.
Step 2 – Observation
Auditor checks actual storage.
Step 3 – Interview
Auditor asks the warehouse employee:
"How do you identify this material and what do you do if the package is damaged?"
Step 4 – Record Review
Auditor checks:
- Inspection records.
- Damage material records.
- Relevant training records.
- Applicable procedures.
Step 5 – Comparison
The auditor compares actual evidence against the established requirements.
Step 6 – Finding
If a requirement is not fulfilled, the auditor records the finding with clear evidence.
Step 7 – Corrective Action
Responsible person investigates the cause and implements appropriate action.
Step 8 – Follow-Up
Auditor verifies whether the action was effective.
This is a practical Internal Audit rather than a document-only audit.
Integrated Audit Example
Consider Waste Management.
ISO 14001
Auditor checks:
- Waste segregation.
- Environmental controls.
- Disposal arrangements.
- Records.
ISO 45001
Auditor checks:
- Safe waste handling.
- PPE.
- Exposure risks.
- Manual handling.
ISO 9001
Where relevant, auditor checks:
- Process controls.
- Supplier/service-provider requirements.
- Records and documented information.
This demonstrates how one process can be audited from an IMS perspective.
Internal Audit and Continual Improvement
Internal Audit should ultimately contribute to improvement.
The improvement cycle is:
Plan
↓
Implement
↓
Audit
↓
Identify Gaps
↓
Correct
↓
Verify
↓
Improve
This supports the continual-improvement philosophy of management systems.
Personal Experience
From my experience with warehouse operations and ISO management systems, an Internal Audit becomes effective when the auditor goes to the actual workplace and checks what is really happening instead of only checking files. For example, if a procedure says that damaged chemical material must be identified and controlled, the auditor should physically verify the storage area, ask the warehouse employee about the process, and check the related records. This provides much stronger evidence than simply ticking a checklist.
Key Learning
- Internal Audit is a systematic evaluation of the management system.
- Clause 9.2 applies to Internal Audit requirements in ISO 9001, ISO 14001 and ISO 45001.
- Audit programs should be planned.
- Audit scope and criteria should be defined.
- Auditors should be competent and objective.
- Audits should be based on objective evidence.
- Interview, observation and record review are important techniques.
- Findings should be clear and evidence-based.
- Corrective actions should be followed up.
- Effectiveness should be verified.
- Internal Audit results should support Management Review and continual improvement.
Frequently Asked Questions (FAQ)
Q1. What is Internal Audit under Clause 9.2?
Internal Audit is a planned and systematic process used to evaluate whether the management system meets applicable requirements and is effectively implemented and maintained.
Q2. Which ISO standards have Clause 9.2 for Internal Audit?
ISO 9001, ISO 14001 and ISO 45001 all contain Internal Audit requirements under Clause 9.2.
Q3. How often should Internal Audit be conducted?
The organization should establish an appropriate audit program. Frequency should consider process importance, risks, previous audit results, changes, and other relevant factors.
Q4. Can one Internal Audit cover ISO 9001, ISO 14001 and ISO 45001?
Yes. An organization with an IMS can conduct integrated audits covering applicable requirements from all three standards.
Q5. Can an employee audit their own department?
An organization should ensure appropriate objectivity and impartiality. Auditing one's own work should be avoided where it compromises objectivity.
Q6. What is objective evidence?
Objective evidence is verifiable information obtained through documents, records, observation, interviews, measurements, or other appropriate sources.
Q7. What is an audit finding?
An audit finding is the result of evaluating audit evidence against audit criteria.
Q8. What is a nonconformity?
A nonconformity is the non-fulfilment of a requirement.
Q9. Is an Internal Audit checklist mandatory?
A checklist is a useful audit tool, but the organization should use an approach that effectively supports its audit process. A checklist should not replace professional audit judgement.
Q10. What happens after an audit finding?
The organization should address the finding appropriately, determine causes where required, implement corrective action, and verify effectiveness as applicable.
Q11. Should Internal Audit findings be discussed in Management Review?
Relevant audit results should provide input to management evaluation and improvement activities.
Q12. Is Internal Audit only for preparing for certification audits?
No. Internal Audit is an internal management tool for evaluating conformity, effectiveness, risks, and improvement opportunities.
Conclusion
Internal Audit is a powerful tool for maintaining and improving an ISO management system.
The basic cycle is:
Plan
↓
Audit
↓
Collect Evidence
↓
Compare with Requirements
↓
Identify Findings
↓
Correct
↓
Take Corrective Action
↓
Verify Effectiveness
↓
Improve
For an Integrated Management System:
ISO 9001 → Quality
ISO 14001 → Environment
ISO 45001 → Occupational Health & Safety
A strong Internal Audit does not simply ask:
"Is the document available?"
It also asks:
"Is the process actually being followed?"
"What evidence proves it?"
"Is the control effective?"
"Are there recurring problems?"
"What can be improved?"
For a chemical warehouse, this practical approach is especially important. Activities such as chemical storage, loading/unloading, waste handling, emergency preparedness, material identification, and workplace safety should be checked against both documented requirements and actual workplace conditions.
The real purpose of Internal Audit is not to find someone at fault. It is to identify gaps, understand system weaknesses, and help the organization improve before problems become bigger.
Discussion
How does your organization conduct Internal Audits? Do you perform separate audits for Quality, Environment and Safety, or one integrated IMS audit? Share your experience in the comments.
About the Author
Written by Mahesh Chand
Warehouse Safety Professional | Chemical Warehousing | Fire Safety | ISO 9001 & ISO 45001
Mahesh Chand has 12+ years of professional experience in chemical warehousing, industrial safety, warehouse operations, fire prevention, HIRA, risk assessment, emergency preparedness, and ISO management systems. Through Trading Hatke, he shares practical workplace safety knowledge, real industrial experience, and easy-to-understand safety guidance to help safety professionals, students, and organizations build safer workplaces.
📌 Follow Trading Hatke for more practical safety guides, warehouse management tips, and ISO best practices.
Disclaimer: This article is intended for educational and informational purposes only. ISO requirements should be interpreted and implemented according to the applicable standard editions, organizational context, documented management-system processes, and competent professional advice. This article does not replace the official ISO standards or certification-body requirements.
Related Workplace Safety Articles:
Fire and Emergency Mock Drill – Complete Workplace Guide
https://tradinghatke.blogspot.com/2026/06/article-5-fire-and-emergency-mock-drill.html
Chemical Spills and Leaks – Complete Emergency Response Guide
https://tradinghatke.blogspot.com/2026/06/article-4-chemical-spills-and-leaks.html
How to Use a Fire Extinguisher – Complete PASS Technique Guide
https://tradinghatke.blogspot.com/2026/06/how-to-use-fire-extinguisher-complete.html
Hazard Identification and Risk Assessment (HIRA) – Complete Workplace Guide
https://tradinghatke.blogspot.com/2026/06/article-2-hazard-identification-and.html
What is Personal Protective Equipment (PPE)? – Complete Workplace Safety Guide
https://tradinghatke.blogspot.com/2026/06/article-1-what-is-ppe-importance-of.html
%20Overview%20Infographic.png)
No comments:
Post a Comment