Weak internal audits read the procedure back to the process owner, tick every clause and find nothing. Months later the certification body samples the same process and raises the nonconformity the internal audit should have found first.
Clause 9.2 of ISO 9001:2026 asks for two things: an audit programme, and audits that actually test whether the quality management system conforms and works. This free ISO 9001 internal audit checklist covers the second part, one audit at a time, for quality managers, internal auditors and process owners. It takes a single audit from its slot in the programme through planning, process-based fieldwork, graded findings, the report and corrective action under clause 10.2. It produces the records the standard asks you to keep: the plan, the evidence behind each finding, the report to management, the corrective action trail and the input to management review.
The Audit Programme, One Internal Audit and the Certification Audit
Clause 9.2 of ISO 9001:2026 requires internal audits at planned intervals that tell you whether the quality management system conforms to your own requirements and to the standard, and whether it is effectively implemented and maintained. Clause 9.2.2, the internal audit programme, sets out how those audits are planned: their frequency, methods, responsibilities, planning and reporting, shaped by how important each process is and what earlier audits found.
The standard does not say how often each process must be audited, how long an audit should take or what it must cover. The ISO 9001 Auditing Practices Group, drawn from ISO/TC 176 and the accreditation community, expects a risk-based programme instead: processes with a history of problems, or where failure would hurt customers, get audited more often. For how to audit, the current guidance is ISO 19011:2026. It is guidance, not a requirement, so a certification auditor cannot raise a nonconformity against it.
Three different jobs get called “the ISO audit”. This checklist does the middle one.
Audit programme
Owned by the quality manager
Answers: which processes get audited, when, by whom and how deeply.
Cadence: set once a year, adjusted after every audit.
Output: the audit schedule, auditor pool and the risk reasoning behind it.
One internal audit
Run by an internal auditor (this checklist)
Answers: does this process conform, and does it work?
Cadence: each slot in the programme, plus unscheduled audits after a failure.
Output: a plan, evidence, graded findings, a report and verified corrective action.
Certification body audit
Run by an external, accredited auditor
Answers: can the certificate be issued or kept?
Cadence: set by the certification body’s own cycle.
Output: the certification decision. Out of scope here, although its auditors will sample your internal audit records.
What the ISO 9001 Internal Audit Checklist Covers
Five phases take one audit from its programme slot to a filed report. A sixth switches on only when the audit raises a nonconformity, and stays open until the fix is verified.
Phase 1
Phase 1: Confirm the Audit’s Place in the Programme
The first task asks two scope questions. Their answers switch on the external-provider sampling task in Phase 3 and the transition gap task in Phase 4.
Open the audit record from the programme schedule — record the process, site, date and the programme entry this audit fulfils
Record why the programme scheduled this process now — its importance, previous audit results and any recent changes (clause 9.2.2)
Define the audit objectives, scope and criteria — the clauses, procedures, customer and statutory requirements this audit tests against
Appoint an auditor who neither works in nor manages the process — record how objectivity and impartiality were assured
Confirm the auditor’s competence record — audit training, experience and any technical knowledge the process needs (clause 7.2)
Pull the last audit’s findings for this process — with the status of every corrective action raised against it
Phase 2
Phase 2: Prepare the Audit Plan
Review the process’s documented information — process map, procedures, work instructions and the records it must retain
Review performance data before fieldwork — KPI trends, complaints, internal nonconformities and supplier issues since the last audit
Map the process as an audit trail — inputs, outputs, criteria, resources, responsibilities, risks and interfaces (clause 4.4)
Agree the sampling approach — judgement-based or statistical, the population and how many records per sample
Write the audit plan and send it to the process owner — timings, people to interview, records to sample, shifts or locations to observe
Phase 3
Phase 3: Audit the Process
The external-provider task appears only when Phase 1 records that the process relies on outsourced processes, products or services.
Hold the opening meeting — confirm objectives, scope, the plan, how findings will be graded and when the closing meeting is
Follow the work from input to output — observe it and interview the people who do it, not only the process owner
Sample records against the criteria — log each record’s reference so anyone can find the same evidence again
Test whether the process’s KPIs are measured, analysed and acted on — including its quality objectives (clauses 6.2 and 9.1.3)
Check the process’s risks and opportunities — the 2026 edition treats them separately; were actions planned for each, and did they work? (clause 6.1)
Sample the controls over external providers — selection criteria, monitoring and re-evaluation records (clause 8.4)
Record every observation with objective evidence — what was seen, where, who was present and which requirement it relates to
Phase 4
Phase 4: Grade the Findings & Close the Audit
The transition gap task appears only when Phase 1 records that the organisation is still certified to ISO 9001:2015.
Write each finding as requirement, evidence and gap — one statement the process owner can check against the record
Grade each finding — major or minor nonconformity, observation, or opportunity for improvement, using your audit procedure’s definitions
If still certified to ISO 9001:2015, log 2026-only gaps separately — they feed the transition plan, not the nonconformity count
Walk the findings through with the process owner before the closing meeting — agree the facts, even if the grading is disputed
Hold the closing meeting — present the findings, agree response dates and record who attended
Record good practice worth copying into other processes — a clean audit still has something to report
Phase 5
Phase 5: Report & Feed Management Review
Issue the audit report to relevant management — findings, evidence and grading (clause 9.2)
State the audit conclusion — does the process conform, and is it effectively implemented and maintained?
Update the audit programme — mark this audit complete and adjust how often this process is audited, based on the results
Add the results to the management review input log — audit results, nonconformity trends and corrective action status (clause 9.3.2)
File the plan, notes, evidence and report — documented information on the programme and its results (clause 9.2)
Phase 6 — If Nonconformities Raised
Phase 6: Corrective Action & Verification
Shown only when Phase 4 records at least one nonconformity. The auditor, not the process owner, completes the verification task.
Contain and correct each nonconformity promptly — and deal with any product or service already affected (clause 10.2)
Determine the root cause — and check whether similar nonconformities exist elsewhere or could occur
Agree the corrective action plan — an owner, a due date and the evidence that will show it worked
Implement the action — and change the QMS itself where the cause requires it
Verify effectiveness once enough time has passed — re-sample records produced after the fix
Close the finding and retain the evidence — the nonconformity, the action taken and its result (clause 10.2)
The ISO 9001 Clauses a Single Internal Audit Evidences
The table maps each requirement that governs an internal audit to its clause in ISO 9001:2026 and to the phase that produces the evidence. Your own audit procedure and your certification body’s rules decide the detail, so treat the table as a starting point, not legal or certification advice.
Requirement
ISO 9001:2026
What the audit has to show
Evidenced in
Audits at planned intervals
9.2
Conformity to your requirements and the standard; effective implementation
Phases 1 and 5
Internal audit programme
9.2.2
Frequency, methods, responsibilities, planning and reporting, weighted by process importance and earlier results
Phases 1 and 5
Criteria and scope for each audit
9.2
Defined before fieldwork and in the plan
Phases 1 and 2
Objectivity and impartiality
9.2
Auditor independent of the process
Phase 1
Auditor competence
7.2
Training and experience on record
Phase 1
Results reported to relevant management
9.2
Report issued to the people who own the process
Phase 5
Documented information
9.2, 10.2
Programme records, audit results, nonconformities and actions
Phases 5 and 6
Input to management review
9.3.2
Audit results and nonconformity and corrective action status
Phase 5
Nonconformity and corrective action
10.2
Containment, root cause, action and effectiveness review
Phase 6
ISO 9001 itself does not grade nonconformities. “Major” and “minor” come from ISO/IEC 17021-1, the standard certification bodies work to: a major nonconformity affects the capability of the management system to achieve its intended results, and a minor one does not. Most internal audit procedures borrow them. Write yours down and apply them consistently.
ISO published ISO 9001:2026 on 16 September 2026, replacing the 2015 edition, and this checklist uses its clause numbers. Certificates to ISO 9001:2015 stay valid through the transition. Under the requirements published the same day by Global Accreditation Cooperation Incorporated (Global ACI), new accredited certifications may only be issued to the 2026 edition from 31 March 2028, and organisations certified to ISO 9001:2015 have until 30 September 2029 to transition. The structure is familiar, but some numbering moved: corrective action, split into 10.2.1 and 10.2.2 in the 2015 edition, is a single clause 10.2 in 2026. The 2026 edition also incorporates the 2024 climate change amendment, and its new Annex A explains the requirements without adding any.
Why Run Your ISO 9001 Internal Audits in CheckFlow?
1
The programme launches each audit
Give each process its own recurring schedule, quarterly for a problem process and annually for a stable one, and each audit opens on time, assigned to its auditor. A data set of processes, owners and risk ratings fills Phase 1.
2
Evidence sits under each finding
Sampled record references go into form fields, and photos and documents attach to the task they support. The activity trail shows who completed each step and when, so an external auditor can see the audit was planned, independent and reported.
3
Nonconformities cannot close quietly
Conditional logic opens Phase 6 only when a nonconformity is raised. Enforced step order stops the verification task from being ticked before the action is in place, and dynamic due dates run from the closing meeting. When a standard is revised, template versioning keeps each completed audit on the criteria it was run against.
CheckFlow is not a certification body and cannot certify you to ISO 9001, and it is not a document control system for your QMS. It runs the audit work and keeps the evidence trail. For implementing an ISO management system from gap analysis to certification, use the broader ISO Compliance Checklist. CheckFlow’s compliance checklist software shows how recurring audits, approvals and evidence fit across the rest of your compliance calendar.
On a factory floor, internal audits run alongside daily inspections and changeovers. CheckFlow for manufacturing covers those shop-floor checklists, so audit findings and the processes they test sit in one place.
Anyone competent who can audit objectively and impartially, as clause 9.2 requires. In practice auditors do not audit their own work or a process they manage. Competence falls under clause 7.2, so keep each auditor’s training and experience on record. Small organisations often swap auditors between departments or buy in an external auditor for the processes the quality manager runs. The programme and the follow-up still belong to you.
Does every process have to be audited every year?
+
ISO 9001 does not say so. It requires audits at planned intervals and a programme that reflects how important each process is and what earlier audits found. Many organisations cover the whole QMS once a year because it is simple to defend. A risk-based programme may audit a problem process quarterly and a stable one less often. Either way, record the reasoning.
What is the difference between a correction and a corrective action?
+
A correction fixes the problem you found: relabelling the batch, recalibrating the gauge, completing the missing record. A corrective action removes the cause so it does not happen again, and clause 10.2 expects you to review whether it worked. Audit findings that close on a correction alone tend to come back at the next audit.
Is ISO 19011 mandatory for ISO 9001 internal audits?
+
No. ISO 19011 is guidance on auditing management systems, not a requirement. The ISO 9001 Auditing Practices Group confirms that an auditor cannot raise a nonconformity against it. It is still worth reading: it covers the principles of auditing, managing an audit programme, conducting audits and auditor competence. The current edition is ISO 19011:2026, published in May 2026.
How is an internal audit different from the certification audit?
+
An internal audit is your own check, run to your programme and criteria, and its job is to find problems. The certification audit is carried out by an accredited certification body to decide whether you can hold the certificate. Its auditors will sample your internal audit records, and a programme that never finds anything is itself a warning sign.
What does ISO 9001:2026 mean for our internal audits?
+
Audit against the 2026 edition now, because that is where the requirements are heading. ISO lists the main changes as quality culture and ethical behaviour, separate treatment of risks and opportunities, and stronger management of change, so plan audits that test those. If you are still certified to ISO 9001:2015, you have until 30 September 2029 to transition, at a surveillance or recertification audit or a separate transition audit. Until then, log gaps against the new edition for the transition plan rather than as nonconformities. Your certification body will confirm your own timing.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
Find the Nonconformity Before Your Certification Body Does
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more