Tuesday, June 30, 2026

Internal Audit (Clause 9.2) – Complete Guide for ISO 9001, ISO 14001 & ISO 45001


Internal-Audit-Overview-Infographic

Internal Audit – Complete Guide (ISO 9001, ISO 14001 & ISO 45001)

Introduction

An Internal Audit is one of the most important requirements of ISO Management Systems. It helps an organization evaluate whether its processes are working effectively and complying with ISO standards, legal requirements, and company procedures.

According to ISO 9001:2015, ISO 14001:2015, and ISO 45001:2018 (Clause 9.2), organizations must conduct internal audits at planned intervals to ensure the management system is implemented and maintained effectively.

Internal Audit is one of the most important tools used by an organization to check whether its management system is working as planned.

An organization may have:

  • Policies.
  • SOPs.
  • Objectives.
  • Risk assessments.
  • HIRA.
  • Environmental aspect registers.
  • Training programs.
  • Emergency procedures.
  • Operational controls.
  • Quality procedures.
  • Safety procedures.

But an important question remains:

Are these requirements actually being followed and are they effective?

Internal Audit helps answer this question.

Under the ISO management-system standards, Clause 9.2 deals with Internal Audit.

For an Integrated Management System (IMS), internal audits can cover:

  • ISO 9001 – Quality Management System
  • ISO 14001 – Environmental Management System
  • ISO 45001 – Occupational Health & Safety Management System

Internal Audit is therefore not simply an activity performed to find mistakes.

The purpose of Internal Audit is to provide objective information about whether the management system conforms to planned requirements and is effectively implemented and maintained.


What is an Internal Audit?

An Internal Audit is a systematic and planned examination of an organization's processes, activities, records, and controls.

The auditor checks whether:

  • Required procedures are available.
  • Procedures are being followed.
  • Records are maintained.
  • Applicable requirements are addressed.
  • Objectives are being achieved.
  • Controls are effective.
  • Problems are identified and corrected.

Simple Meaning

Internal Audit = Check → Compare → Find Evidence → Identify Gaps → Improve


What is ISO Clause 9.2?

Clause 9.2 addresses the organization's internal audit requirements.

Although the three standards have similar internal-audit principles, the detailed requirements should be considered according to the applicable standard.

ISO 9001

Internal Audit focuses on the Quality Management System.

ISO 14001

Internal Audit focuses on the Environmental Management System.

ISO 45001

Internal Audit focuses on the Occupational Health & Safety Management System.


Internal Audit in an Integrated Management System

An organization implementing all three standards can develop an integrated audit program.

StandardMain Audit Focus
ISO 9001        Quality
ISO 14001        Environment
ISO 45001        Occupational Health & Safety
IMS        Integrated process performance

For example, a chemical warehouse receiving process can be audited from three perspectives.

ISO 9001

  • Correct material received.
  • Quantity verified.
  • Documentation checked.
  • Material identification maintained.

ISO 14001

  • Chemical leakage controls.
  • Packaging waste.
  • Environmental controls.
  • Spill preparedness.

ISO 45001

  • PPE.
  • Safe unloading.
  • Manual handling.
  • Emergency preparedness.
  • HIRA controls.

One audit activity can therefore provide evidence for multiple management-system requirements.


Why is Internal Audit Important?

Internal Audit helps an organization:

  • Identify nonconformities.
  • Identify weaknesses.
  • Verify implementation.
  • Check process effectiveness.
  • Monitor compliance with internal procedures.
  • Identify improvement opportunities.
  • Verify corrective actions.
  • Prepare for external audits.
  • Reduce operational risks.
  • Support continual improvement.

The biggest benefit is not simply finding findings.

The real benefit is:

Finding problems before they become bigger problems.


Internal Audit vs External Audit

These two activities are different.

Internal AuditExternal Audit
Conducted by or on behalf of the organizationConducted by an external organization/person
Mainly for internal improvement and assuranceMay be for certification, customer, regulatory, or other purposes
Organization controls the audit programExternal auditor controls their audit activity
Can be more frequentUsually conducted according to external requirements
Focuses on organizational processes and system requirementsProvides independent external assessment

Internal Audit Program

The organization should establish an audit program based on relevant considerations.

An audit program can define:

  • What will be audited.
  • When it will be audited.
  • Who will audit.
  • Which criteria will be used.
  • Which processes are covered.
  • Reporting requirements.
  • Follow-up activities.

The audit program should consider the importance of processes, changes affecting the organization, and results of previous audits.


How Often Should Internal Audit Be Conducted?

There is no universal rule that every process must automatically be audited every month or every year.

The organization should determine appropriate audit frequency based on factors such as:

  • Process importance.
  • Risks.
  • Previous audit results.
  • Changes.
  • Performance.
  • Nonconformities.
  • Customer issues.
  • Environmental significance.
  • OH&S risks.

Example

A high-risk chemical storage activity may require more frequent attention than a low-risk administrative activity.

Similarly, a process with repeated audit findings may need additional audit follow-up.


Internal Audit Process

A practical Internal Audit process is:

Prepare Audit Program

Define Audit Scope

Define Audit Criteria

Select Auditor

Prepare Audit Plan/Checklist

Conduct Opening Meeting

Collect Objective Evidence

Interview / Observe / Review Records

Compare Evidence with Criteria

Identify Findings

Conduct Closing Meeting

Prepare Audit Report

Corrective Action

Verify Effectiveness

Close Finding


Step 1 – Prepare the Audit Program

Before starting the audit, prepare an annual or planned audit program.

Example:

Process    Standard    Planned Month    Status
Purchase    ISO 9001    April    Completed
Warehouse    ISO 9001/14001/45001    May    Completed
HR & Training    IMS    June    Completed
Emergency Preparedness    ISO 45001/14001    July    Planned
Waste Management    ISO 14001    August    Planned
Management Review    IMS    September    Planned

The actual program should be based on the organization's processes and risks.


Step 2 – Define Audit Scope

The audit scope defines what is included in the audit.

Example:

Scope: Warehouse receiving, storage, material handling and dispatch activities.

Or:

Scope: Environmental management controls related to waste handling and chemical storage.

A clear scope helps the auditor remain focused.


Step 3 – Define Audit Criteria

Audit criteria are the requirements against which evidence is compared.

Criteria may include:

  • ISO requirements.
  • Company policies.
  • SOPs.
  • Work instructions.
  • Legal requirements where applicable.
  • Customer requirements.
  • Internal procedures.
  • Objectives.
  • Risk controls.

Example

If auditing chemical storage:

Criteria:

  • Storage SOP.
  • HIRA.
  • Environmental aspect register.
  • Emergency procedure.
  • PPE requirements.
  • Applicable ISO requirements.

Step 4 – Select the Auditor

The auditor should be competent and should conduct the audit objectively.

Where appropriate, auditors should not audit their own work in a way that compromises objectivity and impartiality.

Example

If an employee is responsible for maintaining a particular process, assigning that same person to audit their own process may create an objectivity concern.

An organization can use:

  • Trained internal auditors.
  • Cross-functional auditors.
  • Competent employees from another department.
  • External/internal audit support where appropriate.

Auditor Competence

An internal auditor should understand:

  • Applicable ISO requirements.
  • Audit principles.
  • Audit techniques.
  • Process approach.
  • Objective evidence.
  • Nonconformity identification.
  • Root-cause thinking.
  • Reporting.
  • Follow-up.

For an IMS auditor, additional knowledge may be required in:

  • Quality.
  • Environment.
  • OH&S.

Step 5 – Prepare the Audit Checklist

An audit checklist helps the auditor conduct a systematic audit.

However:

An auditor should not treat the checklist as a questionnaire only.

The auditor should follow evidence and ask additional questions where necessary.


Example – Warehouse Audit Checklist

Quality

☐ Material identification verified.

☐ Receiving records maintained.

☐ Damage material controlled.

☐ Expired material controlled.

☐ Dispatch verification performed.

☐ Customer requirements addressed.

Environment

☐ Waste segregation maintained.

☐ Chemical leakage controls available.

☐ Spill kit available.

☐ Environmental aspect controls implemented.

☐ Waste disposal records maintained where applicable.

Safety

☐ PPE available and used.

☐ HIRA controls implemented.

☐ Emergency exits accessible.

☐ Fire extinguishers accessible.

☐ Emergency contacts displayed.

☐ Safety inspections completed.


Step 6 – Opening Meeting

The auditor may conduct a short opening meeting.

The meeting can cover:

  • Purpose.
  • Scope.
  • Criteria.
  • Audit schedule.
  • Persons involved.
  • Method of audit.
  • Communication during the audit.

For a small organization, the opening meeting can be simple.


Step 7 – Collect Objective Evidence

This is one of the most important parts of Internal Audit.

The auditor should collect objective evidence.

Evidence can come from:

Documents

  • Policies.
  • SOPs.
  • Procedures.
  • HIRA.
  • Aspect registers.

Records

  • Inspection records.
  • Training records.
  • Audit records.
  • Maintenance records.
  • Calibration records.
  • Waste records.

Observation

The auditor physically observes the activity.

Interviews

Employees are asked relevant questions.

Sampling

A suitable sample of records or activities is checked.


What is Objective Evidence?

Objective evidence is information that can be verified.

Example

Instead of saying:

"Employees are trained."

The auditor should verify:

  • Training record.
  • Training topic.
  • Date.
  • Participants.
  • Competence/evaluation where applicable.

Another Example

Instead of saying:

"Fire equipment is maintained."

The auditor can check:

  • Physical condition.
  • Inspection record.
  • Maintenance/refill record.
  • Identification/tagging.

Three Important Audit Techniques

A good auditor commonly uses:

1. Interview

Ask the employee.

"What do you do if you find damaged chemical packaging?"

2. Observation

Watch the actual activity.

Is the material actually stored as required?

3. Record Review

Check evidence.

Is the inspection record completed?

This can be remembered as:

Interview + Observation + Records = Strong Audit Evidence


Process Approach to Internal Audit

Internal Audit should not focus only on documents.

The auditor should understand:

Input → Activity → Output → Monitoring → Result

Example – Warehouse Receiving

Input:

Material from supplier.

Activity:

Unloading and inspection.

Output:

Accepted/controlled material.

Records:

Receiving documentation.

Monitoring:

Damage/quantity verification.

Result:

Correct material available for storage/dispatch.

This provides a more practical audit.


ISO 9001 Internal Audit

ISO 9001 Internal Audit focuses on the Quality Management System.

Auditors may examine:

  • Customer requirements.
  • Purchase process.
  • Supplier performance.
  • Receiving.
  • Material identification.
  • Storage.
  • Dispatch.
  • Customer complaints.
  • Nonconformity.
  • CAPA.
  • Quality objectives.
  • Process performance.
  • Documented information.

ISO 14001 Internal Audit

ISO 14001 Internal Audit focuses on environmental management.

Auditors may examine:

  • Environmental aspects and impacts.
  • Significant environmental aspects.
  • Environmental objectives.
  • Waste management.
  • Chemical storage.
  • Spill controls.
  • Resource consumption.
  • Operational controls.
  • Emergency preparedness.
  • Compliance obligations.
  • Environmental performance.

ISO 45001 Internal Audit

ISO 45001 Internal Audit focuses on OH&S management.

Auditors may examine:

  • Hazard identification.
  • HIRA.
  • OH&S risks.
  • PPE.
  • Training.
  • Worker consultation.
  • Safety inspections.
  • Incident reporting.
  • Near misses.
  • Emergency preparedness.
  • Fire safety.
  • Occupational health.
  • OH&S objectives.

Integrated Audit Example – Chemical Warehouse

Consider the activity:

Chemical Unloading

ISO 9001

Auditor checks:

  • Correct material received.
  • Quantity verified.
  • Damage inspection.
  • Supplier documents.

ISO 14001

Auditor checks:

  • Spill prevention.
  • Packaging condition.
  • Waste handling.
  • Environmental emergency controls.

ISO 45001

Auditor checks:

  • PPE.
  • Safe unloading.
  • Manual handling.
  • HIRA.
  • Emergency arrangements.

This is a practical example of an IMS Internal Audit.


Internal Audit Findings

Audit findings should be based on evidence.

Common classifications may include:

  • Conformity.
  • Observation.
  • Opportunity for Improvement.
  • Nonconformity.

The organization should define its own classification method in its audit procedure.


What is a Nonconformity?

A nonconformity occurs when a requirement is not fulfilled.

Example

Requirement:

A documented procedure requires monthly workplace inspections.

Evidence:

The last three months have no inspection records.

Finding

The required inspection process has not been implemented as planned.

The auditor should clearly identify:

  1. Requirement.
  2. Objective evidence.
  3. Gap.

Writing a Good Audit Finding

A strong finding should be:

  • Clear.
  • Specific.
  • Evidence-based.
  • Objective.
  • Traceable.
  • Related to a requirement.

Weak Finding

"Warehouse safety is not good."

This is vague.

Better Finding

"The monthly workplace inspection procedure requires inspection records to be maintained. However, inspection records for June and July were not available for verification."

This provides:

Requirement + Evidence + Gap


Observation vs Nonconformity

Observation

A potential concern that may require attention but does not necessarily demonstrate a failure to meet a requirement.

Nonconformity

A requirement has not been fulfilled.

The organization should use its defined audit classification criteria consistently.


Corrective Action After Internal Audit

When a nonconformity is identified, the organization should take appropriate action.

Typical process:

Finding

Correction

Root Cause Analysis

Corrective Action

Implementation

Effectiveness Verification

Closure

This connects Internal Audit with CAPA.


Internal Audit and CAPA

Internal Audit identifies the problem.

CAPA addresses the problem and its cause.

Example

Audit Finding:

Fire-extinguisher inspection records were not available for the required period.

Correction

Complete the pending inspection.

Root Cause

Responsibility for monitoring the inspection schedule was not clearly assigned.

Corrective Action

  • Assign responsibility.
  • Update monitoring system.
  • Set reminder.
  • Train responsible person.

Effectiveness

Verify subsequent inspection records.


Follow-Up Audit

Audit work does not necessarily end when the report is issued.

Follow-up may be required to verify:

  • Correction completed.
  • Root cause addressed.
  • Corrective action implemented.
  • Action effective.
  • Finding closed.

A simple follow-up record can include:

FindingActionEvidenceEffectivenessStatus
IA-01Procedure updatedRevised SOPEffectiveClosed
IA-02Training completedTraining recordEffectiveClosed

Internal Audit Report

A practical Internal Audit Report can include:

Company Name: __________

Audit No.: __________

Audit Date: __________

Auditor: __________

Process Audited: __________

Audit Scope: __________

Audit Criteria: __________

Summary

  • Conformities.
  • Observations.
  • Nonconformities.
  • Improvement opportunities.

Findings

Sr. No.RequirementEvidenceFindingClassification
1



2



Follow-Up

FindingResponsibleTarget DateStatusEffectiveness

Internal Audit Programmed Example

Audit No.ProcessISOAuditorMonth
IA-01PurchaseISO 9001Internal AuditorApril
IA-02WarehouseIMSInternal AuditorMay
IA-03HR/TrainingIMSInternal AuditorJune
IA-04Emergency PreparednessISO 14001/45001Internal AuditorJuly
IA-05Waste ManagementISO 14001Internal AuditorAugust
IA-06Management ProcessesIMSInternal AuditorSeptember

The organization should determine its actual audit frequency and coverage based on its needs, risks, process importance, previous results, and changes.


Internal Audit Checklist – IMS

ISO 9001

☐ Customer requirements reviewed.

☐ Purchase controls implemented.

☐ Supplier performance monitored.

☐ Receiving process controlled.

☐ Material identification maintained.

☐ Customer complaints monitored.

☐ Nonconformities controlled.

☐ CAPA implemented.

☐ Quality objectives monitored.

☐ Documented information controlled.


ISO 14001

☐ Environmental aspects identified.

☐ Significant aspects evaluated.

☐ Environmental objectives monitored.

☐ Waste segregation implemented.

☐ Chemical spill controls available.

☐ Environmental emergency controls implemented.

☐ Environmental records maintained.

☐ Compliance obligations evaluated.

☐ Environmental performance monitored.

☐ Corrective actions implemented.


ISO 45001

☐ Hazards identified.

☐ HIRA reviewed.

☐ OH&S risks controlled.

☐ PPE available and used.

☐ Training completed.

☐ Worker consultation/participation implemented.

☐ Incident/near-miss reporting available.

☐ Emergency preparedness implemented.

☐ Fire safety controls maintained.

☐ OH&S objectives monitored.


Internal Audit Questions for Warehouse Employees

Auditors may ask employees practical questions.

Question 1

What do you do if you find damaged material?

Expected answer should reflect the actual company procedure.

Question 2

What PPE is required for your activity?

Employee should explain PPE applicable to their task.

Question 3

What do you do in case of chemical leakage?

Employee should know the relevant emergency/spill-response procedure.

Question 4

Where is the emergency exit?

Employee should know the applicable route.

Question 5

Where is the assembly point?

Employee should know the designated location.

Question 6

How do you report a near miss?

Employee should explain the actual reporting process.

Question 7

What happens to damaged or expired material?

Employee should explain the established control process.


Auditor Should Follow the Evidence

A good auditor does not decide the answer before collecting evidence.

For example:

Employee says:

"We inspect the warehouse every month."

Auditor should verify:

  • Inspection checklist.
  • Recent records.
  • Actual workplace condition.
  • Action status for previous findings.

If records are available and workplace conditions support the statement, the evidence is stronger.


Internal Audit Sampling

Auditors generally cannot check every single transaction or record.

Therefore, appropriate sampling may be used.

For example:

Instead of checking every training record, the auditor may select samples based on risk, process importance, and audit objectives.

Similarly:

  • Several receiving records.
  • Several dispatch records.
  • Selected inspection records.
  • Selected CAPA records.
  • Selected training records.

Sampling should be sufficient to provide reasonable audit evidence.


Internal Audit and Risk-Based Thinking

Audit planning should consider risk.

High-risk activities may deserve greater attention.

Chemical Warehouse Example

Higher attention may be given to:

  • Chemical storage.
  • Loading/unloading.
  • Spill response.
  • Fire safety.
  • Manual handling.
  • Emergency preparedness.

Lower-risk administrative activities may require a different level of audit attention.


Internal Audit and Previous Findings

Previous audit results are important when planning future audits.

If the same finding repeatedly occurs:

Management should investigate whether the corrective action was actually effective.

Recurring findings can indicate:

  • Weak root-cause analysis.
  • Inadequate corrective action.
  • Poor implementation.
  • Lack of ownership.
  • Inadequate monitoring.

Internal Audit and Management Review

Internal Audit results should provide useful information for Management Review.

Management may review:

  • Number of findings.
  • Recurring findings.
  • Major process weaknesses.
  • CAPA status.
  • Audit trends.
  • Resource needs.
  • Improvement opportunities.

This creates a management-system cycle:

Internal Audit

Findings

CAPA

Effectiveness

Management Review

Improvement


Common Internal Audit Mistakes

1. Auditing Only Documents

Internal Audit should also verify actual implementation.

2. Checklist-Based Auditing Only

The auditor should investigate evidence rather than simply tick boxes.

3. Auditing Own Work

This can compromise objectivity.

4. Vague Findings

Findings should identify requirement and evidence.

5. No Evidence

An auditor should not make conclusions without objective evidence.

6. No Follow-Up

Findings should be followed up where corrective action is required.

7. Same Finding Every Year

Repeated findings indicate that previous action may not have been effective.

8. Only Auditing Before Certification

Internal Audit should be part of the organization's regular management-system process.

9. Ignoring Employees

Employee interviews can reveal practical implementation issues.

10. Focusing Only on Nonconformities

Audits should also identify conformities, strengths, and improvement opportunities.


How to Conduct an Effective Internal Audit

Before Audit

  • Review previous audit findings.
  • Review process risks.
  • Prepare audit program.
  • Define scope and criteria.
  • Select competent auditor.
  • Prepare checklist.

During Audit

  • Conduct opening meeting.
  • Interview employees.
  • Observe activities.
  • Review records.
  • Collect objective evidence.
  • Compare evidence with criteria.
  • Record findings clearly.

After Audit

  • Conduct closing meeting.
  • Prepare report.
  • Communicate findings.
  • Assign corrective actions.
  • Track target dates.
  • Verify effectiveness.
  • Close findings.

Internal Audit Do's

✔ Plan audits.

✔ Use risk-based planning.

✔ Define scope and criteria.

✔ Use competent auditors.

✔ Maintain objectivity.

✔ Collect objective evidence.

✔ Interview employees.

✔ Observe actual activities.

✔ Review records.

✔ Write clear findings.

✔ Follow up corrective actions.

✔ Verify effectiveness.

✔ Maintain audit records.

✔ Use audit results for improvement.


Internal Audit Don'ts

❌ Do not audit only documents.

❌ Do not make assumptions.

❌ Do not write vague findings.

❌ Do not audit your own work where objectivity is compromised.

❌ Do not ignore evidence.

❌ Do not close findings without verification.

❌ Do not copy previous audit reports without actual verification.

❌ Do not conduct audits only before certification audits.

❌ Do not focus only on finding mistakes.


Internal Audit Checklist

Before closing an Internal Audit, verify:

☐ Audit program established.

☐ Audit scope defined.

☐ Audit criteria defined.

☐ Auditor competency considered.

☐ Auditor objectivity maintained.

☐ Audit plan prepared.

☐ Previous findings reviewed.

☐ Relevant risks considered.

☐ Employees interviewed.

☐ Activities observed.

☐ Records reviewed.

☐ Objective evidence collected.

☐ Findings documented.

☐ Closing meeting completed.

☐ Audit report issued.

☐ Corrective actions assigned.

☐ Target dates defined.

☐ Follow-up performed.

☐ Effectiveness verified.

☐ Findings closed where appropriate.


Practical Example – Internal Audit in a Chemical Warehouse

Suppose the auditor is checking chemical storage.

Step 1 – Requirement

The warehouse SOP requires chemicals to be stored in designated locations with proper identification and controls.

Step 2 – Observation

Auditor checks actual storage.

Step 3 – Interview

Auditor asks the warehouse employee:

"How do you identify this material and what do you do if the package is damaged?"

Step 4 – Record Review

Auditor checks:

  • Inspection records.
  • Damage material records.
  • Relevant training records.
  • Applicable procedures.

Step 5 – Comparison

The auditor compares actual evidence against the established requirements.

Step 6 – Finding

If a requirement is not fulfilled, the auditor records the finding with clear evidence.

Step 7 – Corrective Action

Responsible person investigates the cause and implements appropriate action.

Step 8 – Follow-Up

Auditor verifies whether the action was effective.

This is a practical Internal Audit rather than a document-only audit.


Integrated Audit Example

Consider Waste Management.

ISO 14001

Auditor checks:

  • Waste segregation.
  • Environmental controls.
  • Disposal arrangements.
  • Records.

ISO 45001

Auditor checks:

  • Safe waste handling.
  • PPE.
  • Exposure risks.
  • Manual handling.

ISO 9001

Where relevant, auditor checks:

  • Process controls.
  • Supplier/service-provider requirements.
  • Records and documented information.

This demonstrates how one process can be audited from an IMS perspective.


Internal Audit and Continual Improvement

Internal Audit should ultimately contribute to improvement.

The improvement cycle is:

Plan

Implement

Audit

Identify Gaps

Correct

Verify

Improve

This supports the continual-improvement philosophy of management systems.


Personal Experience

From my experience with warehouse operations and ISO management systems, an Internal Audit becomes effective when the auditor goes to the actual workplace and checks what is really happening instead of only checking files. For example, if a procedure says that damaged chemical material must be identified and controlled, the auditor should physically verify the storage area, ask the warehouse employee about the process, and check the related records. This provides much stronger evidence than simply ticking a checklist.

Key Learning

  • Internal Audit is a systematic evaluation of the management system.
  • Clause 9.2 applies to Internal Audit requirements in ISO 9001, ISO 14001 and ISO 45001.
  • Audit programs should be planned.
  • Audit scope and criteria should be defined.
  • Auditors should be competent and objective.
  • Audits should be based on objective evidence.
  • Interview, observation and record review are important techniques.
  • Findings should be clear and evidence-based.
  • Corrective actions should be followed up.
  • Effectiveness should be verified.
  • Internal Audit results should support Management Review and continual improvement.

Frequently Asked Questions (FAQ)

Q1. What is Internal Audit under Clause 9.2?

Internal Audit is a planned and systematic process used to evaluate whether the management system meets applicable requirements and is effectively implemented and maintained.

Q2. Which ISO standards have Clause 9.2 for Internal Audit?

ISO 9001, ISO 14001 and ISO 45001 all contain Internal Audit requirements under Clause 9.2.

Q3. How often should Internal Audit be conducted?

The organization should establish an appropriate audit program. Frequency should consider process importance, risks, previous audit results, changes, and other relevant factors.

Q4. Can one Internal Audit cover ISO 9001, ISO 14001 and ISO 45001?

Yes. An organization with an IMS can conduct integrated audits covering applicable requirements from all three standards.

Q5. Can an employee audit their own department?

An organization should ensure appropriate objectivity and impartiality. Auditing one's own work should be avoided where it compromises objectivity.

Q6. What is objective evidence?

Objective evidence is verifiable information obtained through documents, records, observation, interviews, measurements, or other appropriate sources.

Q7. What is an audit finding?

An audit finding is the result of evaluating audit evidence against audit criteria.

Q8. What is a nonconformity?

A nonconformity is the non-fulfilment of a requirement.

Q9. Is an Internal Audit checklist mandatory?

A checklist is a useful audit tool, but the organization should use an approach that effectively supports its audit process. A checklist should not replace professional audit judgement.

Q10. What happens after an audit finding?

The organization should address the finding appropriately, determine causes where required, implement corrective action, and verify effectiveness as applicable.

Q11. Should Internal Audit findings be discussed in Management Review?

Relevant audit results should provide input to management evaluation and improvement activities.

Q12. Is Internal Audit only for preparing for certification audits?

No. Internal Audit is an internal management tool for evaluating conformity, effectiveness, risks, and improvement opportunities.


Conclusion

Internal Audit is a powerful tool for maintaining and improving an ISO management system.

The basic cycle is:

Plan

Audit

Collect Evidence

Compare with Requirements

Identify Findings

Correct

Take Corrective Action

Verify Effectiveness

Improve

For an Integrated Management System:

ISO 9001 → Quality

ISO 14001 → Environment

ISO 45001 → Occupational Health & Safety

A strong Internal Audit does not simply ask:

"Is the document available?"

It also asks:

"Is the process actually being followed?"

"What evidence proves it?"

"Is the control effective?"

"Are there recurring problems?"

"What can be improved?"

For a chemical warehouse, this practical approach is especially important. Activities such as chemical storage, loading/unloading, waste handling, emergency preparedness, material identification, and workplace safety should be checked against both documented requirements and actual workplace conditions.

The real purpose of Internal Audit is not to find someone at fault. It is to identify gaps, understand system weaknesses, and help the organization improve before problems become bigger.


Discussion

How does your organization conduct Internal Audits? Do you perform separate audits for Quality, Environment and Safety, or one integrated IMS audit? Share your experience in the comments.


About the Author

Written by Mahesh Chand

Warehouse Safety Professional | Chemical Warehousing | Fire Safety | ISO 9001 & ISO 45001

Mahesh Chand has 12+ years of professional experience in chemical warehousing, industrial safety, warehouse operations, fire prevention, HIRA, risk assessment, emergency preparedness, and ISO management systems. Through Trading Hatke, he shares practical workplace safety knowledge, real industrial experience, and easy-to-understand safety guidance to help safety professionals, students, and organizations build safer workplaces.

📌 Follow Trading Hatke for more practical safety guides, warehouse management tips, and ISO best practices.

Disclaimer: This article is intended for educational and informational purposes only. ISO requirements should be interpreted and implemented according to the applicable standard editions, organizational context, documented management-system processes, and competent professional advice. This article does not replace the official ISO standards or certification-body requirements.


Related Workplace Safety Articles: 

Fire and Emergency Mock Drill – Complete Workplace Guide
https://tradinghatke.blogspot.com/2026/06/article-5-fire-and-emergency-mock-drill.html

Chemical Spills and Leaks – Complete Emergency Response Guide
https://tradinghatke.blogspot.com/2026/06/article-4-chemical-spills-and-leaks.html

How to Use a Fire Extinguisher – Complete PASS Technique Guide
https://tradinghatke.blogspot.com/2026/06/how-to-use-fire-extinguisher-complete.html

Hazard Identification and Risk Assessment (HIRA) – Complete Workplace Guide
https://tradinghatke.blogspot.com/2026/06/article-2-hazard-identification-and.html

What is Personal Protective Equipment (PPE)? – Complete Workplace Safety Guide
https://tradinghatke.blogspot.com/2026/06/article-1-what-is-ppe-importance-of.html

No comments:

Post a Comment

AI in Workplace Safety – How Artificial Intelligence Can Improve Worker Safety

  Introduction Technology is changing the way people work, and workplace safety is also becoming more technology-driven. One of the technolo...