Skip to main content

ISO Internal Audit

Know What Is Working, What Is Not and What Needs Corrective Action Before the External Audit.

Astute conducts ISO internal audits in Ghana for organisations using ISO 9001, ISO 14001 and ISO 45001 management systems. We test conformity, implementation, evidence and effectiveness so management can see where the system is working, where controls are weak and what needs attention before certification, surveillance or the next management review.

Not sure whether you need an internal audit, full ISO implementation, staff training or wider process improvement? Use the Astute Business Adviser on this page and explain your current situation.

Audit against clear criteriaThe standard, the organisation's own arrangements and the agreed scope define what is being tested.
Findings follow evidenceNonconformities and observations should be supported by objective evidence from the areas and samples reviewed.
Implementation is testedThe audit compares what documents say should happen with what people actually do and what records show.
Objectivity is protectedThe audit should be able to raise uncomfortable findings without being pushed toward a preferred conclusion.

The purpose of the audit

An Internal Audit Is More Than a Clause Checklist.

A useful internal audit tests the management system against applicable requirements and against the organisation's own planned arrangements. It should also determine whether those arrangements are being implemented and maintained in practice.

That requires evidence. Interviews, records, observations, process performance, corrective actions and operational controls should tell a consistent story. Where they do not, the audit should make the gap visible to management.

Is ISO Internal Audit the Right Starting Point?

Use an internal audit when the management system already exists and you need an independent view of how it is working.

An internal audit tests an existing system. If the management system has not yet been built or implemented, auditing it too early may only confirm problems that first need implementation support.

ISO Internal Audit is usually suitable when:

  • Your management system is implemented and you need to test conformity, evidence and effectiveness before certification, surveillance or recertification.
  • Management wants an independent view of whether departments are following agreed controls and maintaining the required records.
  • Recurring nonconformities or weak corrective actions suggest that previous fixes may not be addressing the real cause.
  • Your internal audit programme needs extra capacity, broader coverage or a more independent review of selected areas.
  • There has been a significant change such as a new site, restructuring, major incident or process change and management wants assurance that controls still work.

Another service may be better when:

  • The management system is still being built or major requirements are not yet implemented. ISO & Management Systems consulting may be the better route.
  • The main weakness is that staff do not understand their ISO responsibilities. ISO 9001 Training may be more appropriate.
  • The audit findings point to wider workflow, accountability, SOP, KPI or control weaknesses beyond the management system. Process Excellence may be the stronger route.
  • You only need a quick initial view of readiness. A focused gap assessment may be more efficient than a full internal audit programme.

Already know the audit standard and scope?

Use the calculator to tell us the standard, sites, processes, reason for the audit, deliverables, timing and follow-up support required. You will see an indicative fee before speaking to us.

Get an Indicative Estimate

Standards commonly covered

Internal audit support across core management systems.

01

ISO 9001

Quality Management Systems

Review process control, customer requirements, operational consistency, performance monitoring, nonconformity, corrective action and continual improvement.

02

ISO 14001

Environmental Management Systems

Review environmental aspects, operational controls, compliance obligations, monitoring, emergency preparedness and environmental performance.

03

ISO 45001

Occupational Health & Safety Management Systems

Review hazards, OH&S risks, operational controls, worker participation, incident controls, monitoring and corrective action.

What the audit can examine

Evidence from the system, not assumptions about the system.

01Context, scope and process structure

Whether the management system has clear boundaries, processes, responsibilities and relevant interested-party considerations.

02Leadership and accountability

Whether responsibilities, objectives, approvals and management involvement are evident in practice.

03Risks, opportunities and planning

Whether relevant risks and opportunities are identified, acted upon and reflected in operating controls.

04Documented information

Whether controlled documents and records are current, available, identifiable and appropriate to the process.

05Operational controls

Whether planned processes and controls are being followed consistently in the areas sampled.

06Competence and awareness

Whether personnel understand their responsibilities and whether competence evidence supports assigned work.

07Monitoring and performance evaluation

Whether the organisation measures what matters and uses results to understand management-system performance.

08Nonconformity and improvement

Whether problems are recorded, causes are addressed, corrective actions are followed through and improvement is sustained.

What makes an audit useful

Audit the Process as It Operates, Not Only the Documents It Produces.

Documents are part of the evidence, but they are not the whole management system. A process can have an approved procedure and still be ineffective, inconsistently applied or poorly controlled.

01Follow evidence

Findings should be supported by objective evidence from the areas and samples reviewed.

02Test implementation

Compare documented arrangements with what personnel actually do and what records show.

03Protect audit objectivity

The audit scope, sampling and reporting should allow findings to be raised without pressure to produce a preferred result.

04Make findings actionable

Management should be able to understand the issue, evidence and required follow-up after the audit.

What Makes an Internal Audit Useful

The report should help management act, not simply produce a list of clauses.

A credible audit should make the evidence, affected process and required follow-up understandable enough for management and process owners to respond properly.

The scope and criteria are agreed before fieldwork.

The standard, sites, processes, audit objectives and relevant organisational requirements should be clear before evidence is sampled.

Sampling is explained and proportionate.

An audit cannot examine every record or transaction. The sample should be appropriate to the scope, risk and available audit time.

Findings distinguish evidence from opinion.

Where a nonconformity is raised, management should be able to understand the requirement, objective evidence and affected arrangement.

Follow-up is controlled separately.

If Astute is also asked to support corrective action, the roles should be defined so the independence and objectivity of the audit are not blurred.

A practical audit process

From audit planning to corrective-action follow-up.

Step 01

Plan

Confirm the standard, scope, sites, processes, audit criteria, timing and available management-system information.

Step 02

Prepare

Review relevant documents, prior findings, process information and areas requiring audit attention.

Step 03

Audit

Gather evidence through interviews, record review, observation and process sampling.

Step 04

Evaluate

Compare evidence with audit criteria and determine conformity, nonconformity and relevant improvement observations.

Step 05

Report

Present findings clearly, including supporting evidence, affected areas and agreed next actions.

Step 06

Follow Up

Where included in scope, review corrective-action responses and evidence of closure or continuing action.

Audit duration depends on the selected standard, management-system scope, number of sites, processes, audit objectives, sampling requirements and the organisation's size and complexity.

Typical audit outputs

Management should leave the audit knowing what needs attention.

Deliverables depend on the agreed scope, but the audit should produce a traceable record of what was reviewed, what was found and what management needs to address.

Confirmed audit scope and criteria Audit plan or schedule Processes, departments and evidence sampled Conformity and implementation observations Documented nonconformities where identified Supporting objective evidence Improvement observations where appropriate Audit report and management briefing Corrective-action requirements Follow-up or closure review where scoped

When organisations use this service

Internal audit support at different stages of the management-system cycle.

01

Before Certification

Test whether implementation and evidence are sufficiently mature before the independent certification audit.

02

Before Surveillance or Recertification

Identify weaknesses in an existing certified system before the next external assessment.

03

Annual Internal Audit Programme

Provide independent audit support where the organisation needs additional capacity or specialist management-system review.

04

After Significant Change

Review controls after restructuring, new processes, new sites, major incidents or material changes to the operating environment.

05

Recurring Nonconformities

Examine areas where the same weaknesses continue to appear despite prior corrective actions.

06

Management Assurance

Give leadership a clearer view of whether key management-system arrangements are functioning as intended.

Rate Calculator & Service Request

See the likely audit scope and indicative fee before you contact us.

Answer a few questions about the ISO standard, reason for the audit, organisation size, sites, audit scope, deliverables, timing and follow-up support. We will use your answers to estimate the likely audit engagement, audit effort and professional fee.

Your answers also become your service request, so you will not need to repeat the same information when we follow up.

ISO Internal Audit & Readiness Review Rate Calculator

Find Out What Your ISO Internal Audit May Cost.

Tell us the standard, audit purpose, organisation scope and the level of review you need. We will estimate the likely audit effort, professional fee and payment options.

Your answers also become your service request, so you will not need to repeat the same information when we follow up.

Step 1 of 6

Step 1

What audit or readiness review do you need?

Which standard(s) should be covered? Select all that apply.
Why do you need the audit? Select all that apply.

Step 2

How large is the audit scope?

Step 3

What should the audit cover?

Select all that apply.

Step 4

What should you receive?

Select all that apply.

Step 5

Timing and payment.

Step 6

Where should we send your estimate?

Frequently asked questions

Questions buyers usually ask before commissioning an ISO internal audit.

These are the practical questions that usually affect audit scope, independence, timing, cost, sampling and corrective-action follow-up.

What is an ISO internal audit?

An internal audit is a systematic review of the management system against defined audit criteria. It examines whether planned arrangements conform to applicable requirements and whether the system is implemented and maintained effectively in the areas sampled.

Which standards can the audit cover?

The core scope on this page covers ISO 9001, ISO 14001 and ISO 45001. Other management-system standards should be discussed and confirmed before the engagement is agreed.

Can the audit be used before certification?

Yes. Internal audit is an important part of management-system implementation and can identify gaps before an organisation proceeds to an independent certification audit.

Does an internal audit guarantee certification?

No. Certification decisions are made independently by the certification body. An internal audit can improve management's understanding of conformity and readiness, but it cannot guarantee an external audit result.

How long does the audit take?

The duration depends on scope, standard, number of sites, processes, organisational complexity, audit objectives and required sampling. It should be determined after the audit scope is understood.

Can Astute help us close audit findings?

Corrective-action or management-system improvement support can be scoped separately. Where independence or objectivity considerations apply, the roles and responsibilities should be made clear before follow-up work begins.

How much does an ISO internal audit cost?

The fee depends on the standard, number of sites, processes in scope, organisation size and complexity, audit objective, sampling required, reporting depth, timing and whether follow-up review is included. Use the calculator on this page for an indicative estimate. The final professional fee is confirmed after the actual scope is reviewed.

Do you audit every record and every employee?

No. Internal auditing uses sampling. The auditor selects appropriate processes, records, activities and personnel based on the agreed scope, criteria, risk and available audit time. A clean sample does not mean every transaction in the organisation has been tested.

Can you audit a department where you previously helped write the procedures?

That situation should be considered carefully because internal-audit objectivity matters. Where Astute has had a prior implementation role, the proposed audit arrangement and any potential conflict should be discussed before the engagement is agreed so responsibilities can be structured appropriately.

Will the audit report tell us exactly how to fix every nonconformity?

The audit should identify the requirement, evidence and nature of the finding. Management remains responsible for determining and implementing an appropriate corrective action. Separate advisory support can be agreed where help with root cause or corrective action is required.

Can the audit cover only one department or process?

Yes. A focused audit can be scoped around one process, department, site or issue where that meets the organisation's audit objective. The scope and limitations should be clear in the audit plan and report.

Start with the audit scope

Need an Independent View of How Your ISO System Is Performing?

Tell us the standard, current certification status, sites, processes and reason for the audit. The calculator will help define the likely audit scope, audit effort, indicative fee and payment options.