ISO 9001
Quality Management SystemsReview process control, customer requirements, operational consistency, performance monitoring, nonconformity, corrective action and continual improvement.
ISO Internal Audit
Astute conducts ISO internal audits in Ghana for organisations using ISO 9001, ISO 14001 and ISO 45001 management systems. We test conformity, implementation, evidence and effectiveness so management can see where the system is working, where controls are weak and what needs attention before certification, surveillance or the next management review.
Not sure whether you need an internal audit, full ISO implementation, staff training or wider process improvement? Use the Astute Business Adviser on this page and explain your current situation.
The purpose of the audit
A useful internal audit tests the management system against applicable requirements and against the organisation's own planned arrangements. It should also determine whether those arrangements are being implemented and maintained in practice.
That requires evidence. Interviews, records, observations, process performance, corrective actions and operational controls should tell a consistent story. Where they do not, the audit should make the gap visible to management.
Is ISO Internal Audit the Right Starting Point?
An internal audit tests an existing system. If the management system has not yet been built or implemented, auditing it too early may only confirm problems that first need implementation support.
Use the calculator to tell us the standard, sites, processes, reason for the audit, deliverables, timing and follow-up support required. You will see an indicative fee before speaking to us.
Standards commonly covered
Review process control, customer requirements, operational consistency, performance monitoring, nonconformity, corrective action and continual improvement.
Review environmental aspects, operational controls, compliance obligations, monitoring, emergency preparedness and environmental performance.
Review hazards, OH&S risks, operational controls, worker participation, incident controls, monitoring and corrective action.
What the audit can examine
Whether the management system has clear boundaries, processes, responsibilities and relevant interested-party considerations.
Whether responsibilities, objectives, approvals and management involvement are evident in practice.
Whether relevant risks and opportunities are identified, acted upon and reflected in operating controls.
Whether controlled documents and records are current, available, identifiable and appropriate to the process.
Whether planned processes and controls are being followed consistently in the areas sampled.
Whether personnel understand their responsibilities and whether competence evidence supports assigned work.
Whether the organisation measures what matters and uses results to understand management-system performance.
Whether problems are recorded, causes are addressed, corrective actions are followed through and improvement is sustained.
What makes an audit useful
Documents are part of the evidence, but they are not the whole management system. A process can have an approved procedure and still be ineffective, inconsistently applied or poorly controlled.
Findings should be supported by objective evidence from the areas and samples reviewed.
Compare documented arrangements with what personnel actually do and what records show.
The audit scope, sampling and reporting should allow findings to be raised without pressure to produce a preferred result.
Management should be able to understand the issue, evidence and required follow-up after the audit.
What Makes an Internal Audit Useful
A credible audit should make the evidence, affected process and required follow-up understandable enough for management and process owners to respond properly.
The standard, sites, processes, audit objectives and relevant organisational requirements should be clear before evidence is sampled.
An audit cannot examine every record or transaction. The sample should be appropriate to the scope, risk and available audit time.
Where a nonconformity is raised, management should be able to understand the requirement, objective evidence and affected arrangement.
If Astute is also asked to support corrective action, the roles should be defined so the independence and objectivity of the audit are not blurred.
A practical audit process
Confirm the standard, scope, sites, processes, audit criteria, timing and available management-system information.
Review relevant documents, prior findings, process information and areas requiring audit attention.
Gather evidence through interviews, record review, observation and process sampling.
Compare evidence with audit criteria and determine conformity, nonconformity and relevant improvement observations.
Present findings clearly, including supporting evidence, affected areas and agreed next actions.
Where included in scope, review corrective-action responses and evidence of closure or continuing action.
Audit duration depends on the selected standard, management-system scope, number of sites, processes, audit objectives, sampling requirements and the organisation's size and complexity.
Typical audit outputs
Deliverables depend on the agreed scope, but the audit should produce a traceable record of what was reviewed, what was found and what management needs to address.
When organisations use this service
Test whether implementation and evidence are sufficiently mature before the independent certification audit.
Identify weaknesses in an existing certified system before the next external assessment.
Provide independent audit support where the organisation needs additional capacity or specialist management-system review.
Review controls after restructuring, new processes, new sites, major incidents or material changes to the operating environment.
Examine areas where the same weaknesses continue to appear despite prior corrective actions.
Give leadership a clearer view of whether key management-system arrangements are functioning as intended.
Rate Calculator & Service Request
Answer a few questions about the ISO standard, reason for the audit, organisation size, sites, audit scope, deliverables, timing and follow-up support. We will use your answers to estimate the likely audit engagement, audit effort and professional fee.
Your answers also become your service request, so you will not need to repeat the same information when we follow up.
ISO Internal Audit & Readiness Review Rate Calculator
Tell us the standard, audit purpose, organisation scope and the level of review you need. We will estimate the likely audit effort, professional fee and payment options.
Your answers also become your service request, so you will not need to repeat the same information when we follow up.
Related ISO support
Frequently asked questions
These are the practical questions that usually affect audit scope, independence, timing, cost, sampling and corrective-action follow-up.
An internal audit is a systematic review of the management system against defined audit criteria. It examines whether planned arrangements conform to applicable requirements and whether the system is implemented and maintained effectively in the areas sampled.
The core scope on this page covers ISO 9001, ISO 14001 and ISO 45001. Other management-system standards should be discussed and confirmed before the engagement is agreed.
Yes. Internal audit is an important part of management-system implementation and can identify gaps before an organisation proceeds to an independent certification audit.
No. Certification decisions are made independently by the certification body. An internal audit can improve management's understanding of conformity and readiness, but it cannot guarantee an external audit result.
The duration depends on scope, standard, number of sites, processes, organisational complexity, audit objectives and required sampling. It should be determined after the audit scope is understood.
Corrective-action or management-system improvement support can be scoped separately. Where independence or objectivity considerations apply, the roles and responsibilities should be made clear before follow-up work begins.
The fee depends on the standard, number of sites, processes in scope, organisation size and complexity, audit objective, sampling required, reporting depth, timing and whether follow-up review is included. Use the calculator on this page for an indicative estimate. The final professional fee is confirmed after the actual scope is reviewed.
No. Internal auditing uses sampling. The auditor selects appropriate processes, records, activities and personnel based on the agreed scope, criteria, risk and available audit time. A clean sample does not mean every transaction in the organisation has been tested.
That situation should be considered carefully because internal-audit objectivity matters. Where Astute has had a prior implementation role, the proposed audit arrangement and any potential conflict should be discussed before the engagement is agreed so responsibilities can be structured appropriately.
The audit should identify the requirement, evidence and nature of the finding. Management remains responsible for determining and implementing an appropriate corrective action. Separate advisory support can be agreed where help with root cause or corrective action is required.
Yes. A focused audit can be scoped around one process, department, site or issue where that meets the organisation's audit objective. The scope and limitations should be clear in the audit plan and report.
Start with the audit scope
Tell us the standard, current certification status, sites, processes and reason for the audit. The calculator will help define the likely audit scope, audit effort, indicative fee and payment options.