ISO 9001 Internal Audit: It Is Not About Filling in a Checklist, but About Seeing Whether the System Really Works

Anasayfa / Blog / ISO 9001 Internal Audit: It Is Not About…
ISO 9001 Internal Audit
B
BESA Editör
May 16, 2026
8 min read 222

ISO 9001 internal auditing is not a formality to be completed before external audits. A real internal audit is a powerful management tool that reveals whether processes produce intended results, risks are under control, and the quality management system is actually working in practice.

Many organizations with an ISO 9001 quality management system see internal auditing merely as a mandatory preparation activity before the external audit. However, an internal audit is not just about filling in a few forms, ticking ready-made question lists, or checking whether files are in place. A real ISO 9001 internal audit is a powerful management tool that shows whether the company's quality management system actually works, whether processes produce the intended results, and whether the system can detect risks before errors reach the customer.

Clause 9.2 of the ISO 9001:2015 standard requires organizations to conduct internal audits at planned intervals. During these audits, it should be evaluated whether the quality management system conforms both to the requirements of the standard and to the organization's own requirements. However, the key point here is not only to ask, "Is it compliant or not?" The more important question is: Is this system actually implemented, and does it deliver the expected results?

In many companies, internal auditing turns into a desk-based document review. The auditor takes a checklist and asks questions such as "Is there a procedure?", "Is there a form?", "Are records kept?" and then ticks the boxes. At first glance, this method may look orderly; however, it often fails to reveal the real performance of the system. Because the existence of documentation does not mean that the practice is correct. An instruction may be written, but it may not be applied in the field. A form may be completed, but the data may not reflect reality. A target may be defined, but no one may be monitoring it. This is why internal auditing is not merely a document check; it is an activity for seeing how the process actually works.

One of the biggest mistakes made in ISO 9001 internal audits is basing the audit only on ready-made question lists. A checklist is a useful tool, but it is not the audit itself. A good internal auditor does not simply ask, "Is this record available?" Instead, they ask deeper questions such as "What does this record show?", "Which risk does this process control?", "What is the impact of this activity on the customer?", "Has a previously identified error occurred again?", and "Has this process really improved?" Because the purpose of a quality management system is not to keep tidy documents in a folder, but to ensure that the organization operates in a stable, controlled, and customer-focused manner.

Another common mistake in internal audits is failing to go to the field. A quality system does not live only in procedures; it lives in production, service delivery, purchasing, customer relations, storage areas, laboratories, offices, and daily operations. Therefore, a good internal audit should not be limited only to document review. The auditor should observe where the process is being carried out, speak with employees, check records on site, and evaluate whether the actual practice is consistent with what is written in the documents. Because many nonconformities are visible not in the file, but in the field.

Another important mistake is giving equal weight to all processes. An ISO 9001 internal audit should be conducted with risk-based thinking. More time should be allocated to processes that are critical for the organization, directly affect customer satisfaction, have a high probability of producing errors, or have had previous nonconformities. For example, a process where customer complaints are concentrated, a purchasing activity where supplier-related problems have increased, or a production process where repeated errors occur should be examined in greater depth during the internal audit. The purpose of an internal audit is not to allocate equal time to every clause, but to understand how strong the system is at the organization's most critical points.

Writing nonconformities is also one of the weak areas in many organizations' internal audits. A nonconformity should not be written with general and open-ended statements. Expressions such as "Records are incomplete," "Implementation is insufficient," or "The procedure is not followed" are not enough on their own. A well-written nonconformity should clearly show which requirement has not been met, what concrete evidence exists, and why the situation constitutes a nonconformity. For example, the statement "Although the purchasing supplier evaluation procedure states that suppliers must be evaluated once a year, no evaluation records were found for three main suppliers for the year 2025" is much stronger. Because in this statement, the requirement, the evidence, and the nonconformity are clearly visible.

However, the value of internal auditing is not limited only to finding nonconformities. A good internal audit also reveals opportunities for improvement. In some cases, there may not be an obvious nonconformity, but the process may still be made more effective, faster, or better controlled. For example, records may be kept, but there may be unnecessary repetition. Customer complaints may be closed, but root cause analysis may be weak. Trainings may be conducted, but training effectiveness may not be measured. Such findings are important opportunities for the improvement of the quality management system.

The follow-up of corrective actions is also one of the most critical stages of internal auditing. In many companies, a nonconformity is identified, a corrective action form is opened, but the issue is not truly followed up. However, in the ISO 9001 approach, the important point is not only to close the error, but to prevent it from recurring. For this reason, root cause analysis should be performed, whether the action taken is truly effective should be checked, and whether the same problem occurs again should be monitored. If the same nonconformity is written every year, this means that a corrective action has not been implemented; only a temporary solution has been applied.

An effective ISO 9001 internal audit should proceed as follows: First, an audit plan should be prepared, and the processes and scope to be audited should be determined. Then, previous nonconformities, customer complaints, performance indicators, risks, and previous audit results should be reviewed. During the audit, attention should be paid not only to documents but also to actual implementation; employees should be interviewed, sample records should be checked, and the real flow of the process should be observed. Findings should be reported in a clear, evidence-based, and understandable manner. Afterwards, corrective actions should be followed up, and the results obtained should be converted into meaningful data for management review.

The questions asked during an internal audit should also not be classic and superficial. Instead of asking "Do you have a procedure?", it is more valuable to ask "How do you measure the success of this process?" Instead of asking "Is there a training record?", it is stronger to ask "How did you determine that this training was effective?" Instead of asking "Has the complaint form been filled in?", it is more meaningful to ask "What was changed to prevent this complaint from recurring?" Because a good auditor does not merely look for records; they question the logic, effectiveness, and results of the system.

When organizations use internal audits correctly, the need to panic before external audits decreases. Because the system has already been checked regularly, weak points have been identified in advance, and necessary improvements have been made. This is important not only for maintaining the certificate, but also for managing the organization in a healthier way. This is also the real purpose of ISO 9001: to establish and continuously improve a system that prevents errors instead of correcting them afterwards.

As a result, an ISO 9001 internal audit is not a formality. It should not be carried out merely to prepare a report to show the external auditor. Internal auditing is the organization's way of holding a mirror up to itself. In this mirror, the organization should not only see whether documents are in order, but also whether processes really work, whether risks are controlled, whether customer expectations are met, and whether the system is continuously improving.

It should not be forgotten that a good internal audit is not conducted to satisfy the external auditor, but to warn the system before an error reaches the customer. A checklist is only a tool. The real audit is the ability to see the actual condition of the process in the field and to strengthen the quality management system not only on paper, but also in practice.


Articles in This Series

  • 5 Practical Tips for Internal Auditors
  • ISO 9001 Internal Audit: It Is Not About Filling in a Checklist, but About Seeing Whether the System Really Works
  • How to Prepare an ISO 9001 Internal Audit Checklist? A Ready Question List and Application Tips Coming Soon
  • How to Write a Nonconformity in an ISO 9001 Internal Audit? Sample Findings and Correct Wording Techniques Coming Soon
  • ISO 9001 Corrective Action: How to Perform Root Cause Analysis? Coming Soon
  • ISO 9001 Management Review: How to Use Internal Audit Results? Coming Soon