ISO 9001 Internal Audit Checklist Template

Weak internal audits read the procedure back to the process owner, tick every clause and find nothing. Months later the certification body samples the same process and raises the nonconformity the internal audit should have found first.

Clause 9.2 of ISO 9001:2026 asks for two things: an audit programme, and audits that actually test whether the quality management system conforms and works. This free ISO 9001 internal audit checklist covers the second part, one audit at a time, for quality managers, internal auditors and process owners. It takes a single audit from its slot in the programme through planning, process-based fieldwork, graded findings, the report and corrective action under clause 10.2. It produces the records the standard asks you to keep: the plan, the evidence behind each finding, the report to management, the corrective action trail and the input to management review.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: September 2026

The Audit Programme, One Internal Audit and the Certification Audit

Clause 9.2 of ISO 9001:2026 requires internal audits at planned intervals that tell you whether the quality management system conforms to your own requirements and to the standard, and whether it is effectively implemented and maintained. Clause 9.2.2, the internal audit programme, sets out how those audits are planned: their frequency, methods, responsibilities, planning and reporting, shaped by how important each process is and what earlier audits found.

The standard does not say how often each process must be audited, how long an audit should take or what it must cover. The ISO 9001 Auditing Practices Group, drawn from ISO/TC 176 and the accreditation community, expects a risk-based programme instead: processes with a history of problems, or where failure would hurt customers, get audited more often. For how to audit, the current guidance is ISO 19011:2026. It is guidance, not a requirement, so a certification auditor cannot raise a nonconformity against it.

Three different jobs get called “the ISO audit”. This checklist does the middle one.

Audit programme

Owned by the quality manager

Answers: which processes get audited, when, by whom and how deeply.

Cadence: set once a year, adjusted after every audit.

Output: the audit schedule, auditor pool and the risk reasoning behind it.

One internal audit

Run by an internal auditor (this checklist)

Answers: does this process conform, and does it work?

Cadence: each slot in the programme, plus unscheduled audits after a failure.

Output: a plan, evidence, graded findings, a report and verified corrective action.

Certification body audit

Run by an external, accredited auditor

Answers: can the certificate be issued or kept?

Cadence: set by the certification body’s own cycle.

Output: the certification decision. Out of scope here, although its auditors will sample your internal audit records.

What the ISO 9001 Internal Audit Checklist Covers

Five phases take one audit from its programme slot to a filed report. A sixth switches on only when the audit raises a nonconformity, and stays open until the fix is verified.

Phase 1

Phase 1: Confirm the Audit’s Place in the Programme

The first task asks two scope questions. Their answers switch on the external-provider sampling task in Phase 3 and the transition gap task in Phase 4.

  • Open the audit record from the programme schedule — record the process, site, date and the programme entry this audit fulfils
  • Record why the programme scheduled this process now — its importance, previous audit results and any recent changes (clause 9.2.2)
  • Define the audit objectives, scope and criteria — the clauses, procedures, customer and statutory requirements this audit tests against
  • Appoint an auditor who neither works in nor manages the process — record how objectivity and impartiality were assured
  • Confirm the auditor’s competence record — audit training, experience and any technical knowledge the process needs (clause 7.2)
  • Pull the last audit’s findings for this process — with the status of every corrective action raised against it
Phase 2

Phase 2: Prepare the Audit Plan

  • Review the process’s documented information — process map, procedures, work instructions and the records it must retain
  • Review performance data before fieldwork — KPI trends, complaints, internal nonconformities and supplier issues since the last audit
  • Map the process as an audit trail — inputs, outputs, criteria, resources, responsibilities, risks and interfaces (clause 4.4)
  • Agree the sampling approach — judgement-based or statistical, the population and how many records per sample
  • Write the audit plan and send it to the process owner — timings, people to interview, records to sample, shifts or locations to observe
Phase 3

Phase 3: Audit the Process

The external-provider task appears only when Phase 1 records that the process relies on outsourced processes, products or services.

  • Hold the opening meeting — confirm objectives, scope, the plan, how findings will be graded and when the closing meeting is
  • Follow the work from input to output — observe it and interview the people who do it, not only the process owner
  • Sample records against the criteria — log each record’s reference so anyone can find the same evidence again
  • Test whether the process’s KPIs are measured, analysed and acted on — including its quality objectives (clauses 6.2 and 9.1.3)
  • Check the process’s risks and opportunities — the 2026 edition treats them separately; were actions planned for each, and did they work? (clause 6.1)
  • Sample the controls over external providers — selection criteria, monitoring and re-evaluation records (clause 8.4)
  • Record every observation with objective evidence — what was seen, where, who was present and which requirement it relates to
Phase 4

Phase 4: Grade the Findings & Close the Audit

The transition gap task appears only when Phase 1 records that the organisation is still certified to ISO 9001:2015.

  • Write each finding as requirement, evidence and gap — one statement the process owner can check against the record
  • Grade each finding — major or minor nonconformity, observation, or opportunity for improvement, using your audit procedure’s definitions
  • If still certified to ISO 9001:2015, log 2026-only gaps separately — they feed the transition plan, not the nonconformity count
  • Walk the findings through with the process owner before the closing meeting — agree the facts, even if the grading is disputed
  • Hold the closing meeting — present the findings, agree response dates and record who attended
  • Record good practice worth copying into other processes — a clean audit still has something to report
Phase 5

Phase 5: Report & Feed Management Review

  • Issue the audit report to relevant management — findings, evidence and grading (clause 9.2)
  • State the audit conclusion — does the process conform, and is it effectively implemented and maintained?
  • Update the audit programme — mark this audit complete and adjust how often this process is audited, based on the results
  • Add the results to the management review input log — audit results, nonconformity trends and corrective action status (clause 9.3.2)
  • File the plan, notes, evidence and report — documented information on the programme and its results (clause 9.2)
Phase 6 — If Nonconformities Raised

Phase 6: Corrective Action & Verification

Shown only when Phase 4 records at least one nonconformity. The auditor, not the process owner, completes the verification task.

  • Contain and correct each nonconformity promptly — and deal with any product or service already affected (clause 10.2)
  • Determine the root cause — and check whether similar nonconformities exist elsewhere or could occur
  • Agree the corrective action plan — an owner, a due date and the evidence that will show it worked
  • Implement the action — and change the QMS itself where the cause requires it
  • Verify effectiveness once enough time has passed — re-sample records produced after the fix
  • Close the finding and retain the evidence — the nonconformity, the action taken and its result (clause 10.2)

The ISO 9001 Clauses a Single Internal Audit Evidences

The table maps each requirement that governs an internal audit to its clause in ISO 9001:2026 and to the phase that produces the evidence. Your own audit procedure and your certification body’s rules decide the detail, so treat the table as a starting point, not legal or certification advice.

Requirement ISO 9001:2026 What the audit has to show Evidenced in
Audits at planned intervals9.2Conformity to your requirements and the standard; effective implementationPhases 1 and 5
Internal audit programme9.2.2Frequency, methods, responsibilities, planning and reporting, weighted by process importance and earlier resultsPhases 1 and 5
Criteria and scope for each audit9.2Defined before fieldwork and in the planPhases 1 and 2
Objectivity and impartiality9.2Auditor independent of the processPhase 1
Auditor competence7.2Training and experience on recordPhase 1
Results reported to relevant management9.2Report issued to the people who own the processPhase 5
Documented information9.2, 10.2Programme records, audit results, nonconformities and actionsPhases 5 and 6
Input to management review9.3.2Audit results and nonconformity and corrective action statusPhase 5
Nonconformity and corrective action10.2Containment, root cause, action and effectiveness reviewPhase 6

ISO 9001 itself does not grade nonconformities. “Major” and “minor” come from ISO/IEC 17021-1, the standard certification bodies work to: a major nonconformity affects the capability of the management system to achieve its intended results, and a minor one does not. Most internal audit procedures borrow them. Write yours down and apply them consistently.

ISO published ISO 9001:2026 on 16 September 2026, replacing the 2015 edition, and this checklist uses its clause numbers. Certificates to ISO 9001:2015 stay valid through the transition. Under the requirements published the same day by Global Accreditation Cooperation Incorporated (Global ACI), new accredited certifications may only be issued to the 2026 edition from 31 March 2028, and organisations certified to ISO 9001:2015 have until 30 September 2029 to transition. The structure is familiar, but some numbering moved: corrective action, split into 10.2.1 and 10.2.2 in the 2015 edition, is a single clause 10.2 in 2026. The 2026 edition also incorporates the 2024 climate change amendment, and its new Annex A explains the requirements without adding any.

Why Run Your ISO 9001 Internal Audits in CheckFlow?

1

The programme launches each audit

Give each process its own recurring schedule, quarterly for a problem process and annually for a stable one, and each audit opens on time, assigned to its auditor. A data set of processes, owners and risk ratings fills Phase 1.

2

Evidence sits under each finding

Sampled record references go into form fields, and photos and documents attach to the task they support. The activity trail shows who completed each step and when, so an external auditor can see the audit was planned, independent and reported.

3

Nonconformities cannot close quietly

Conditional logic opens Phase 6 only when a nonconformity is raised. Enforced step order stops the verification task from being ticked before the action is in place, and dynamic due dates run from the closing meeting. When a standard is revised, template versioning keeps each completed audit on the criteria it was run against.

CheckFlow is not a certification body and cannot certify you to ISO 9001, and it is not a document control system for your QMS. It runs the audit work and keeps the evidence trail. For implementing an ISO management system from gap analysis to certification, use the broader ISO Compliance Checklist. CheckFlow’s compliance checklist software shows how recurring audits, approvals and evidence fit across the rest of your compliance calendar.

On a factory floor, internal audits run alongside daily inspections and changeovers. CheckFlow for manufacturing covers those shop-floor checklists, so audit findings and the processes they test sit in one place.

Frequently Asked Questions

Who can carry out an ISO 9001 internal audit?

+

Anyone competent who can audit objectively and impartially, as clause 9.2 requires. In practice auditors do not audit their own work or a process they manage. Competence falls under clause 7.2, so keep each auditor’s training and experience on record. Small organisations often swap auditors between departments or buy in an external auditor for the processes the quality manager runs. The programme and the follow-up still belong to you.

Does every process have to be audited every year?

+

ISO 9001 does not say so. It requires audits at planned intervals and a programme that reflects how important each process is and what earlier audits found. Many organisations cover the whole QMS once a year because it is simple to defend. A risk-based programme may audit a problem process quarterly and a stable one less often. Either way, record the reasoning.

What is the difference between a correction and a corrective action?

+

A correction fixes the problem you found: relabelling the batch, recalibrating the gauge, completing the missing record. A corrective action removes the cause so it does not happen again, and clause 10.2 expects you to review whether it worked. Audit findings that close on a correction alone tend to come back at the next audit.

Is ISO 19011 mandatory for ISO 9001 internal audits?

+

No. ISO 19011 is guidance on auditing management systems, not a requirement. The ISO 9001 Auditing Practices Group confirms that an auditor cannot raise a nonconformity against it. It is still worth reading: it covers the principles of auditing, managing an audit programme, conducting audits and auditor competence. The current edition is ISO 19011:2026, published in May 2026.

How is an internal audit different from the certification audit?

+

An internal audit is your own check, run to your programme and criteria, and its job is to find problems. The certification audit is carried out by an accredited certification body to decide whether you can hold the certificate. Its auditors will sample your internal audit records, and a programme that never finds anything is itself a warning sign.

What does ISO 9001:2026 mean for our internal audits?

+

Audit against the 2026 edition now, because that is where the requirements are heading. ISO lists the main changes as quality culture and ethical behaviour, separate treatment of risks and opportunities, and stronger management of change, so plan audits that test those. If you are still certified to ISO 9001:2015, you have until 30 September 2029 to transition, at a surveillance or recertification audit or a separate transition audit. Until then, log gaps against the new edition for the transition plan rather than as nonconformities. Your certification body will confirm your own timing.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Find the Nonconformity Before Your Certification Body Does

Free trial — no credit card required.