Skip links

Internal Audits

What an internal audit is for

Not to prove you are compliant. To find out whether you are.

An internal audit that never finds anything is not evidence of excellence. It is evidence the audit is not looking — and an experienced external auditor treats it that way.

The purpose is to find problems while they are yours to fix, before a customer or a certification body finds them for you.

The three kinds

Internal — first party. You audit yourself. This article.

Customer — second party. A customer audits you, usually before contracting or after a problem.

Certification — third party. An accredited body audits you for a certificate.

The internal one is the only one you control, and it is the one that determines how the other two go.

Planning the programme

Audit everything over a cycle, usually a year — not everything at once.

Weight it by risk and by history. Processes that have caused problems get audited more often. Processes that have run cleanly for years get audited less.

That is risk-based thinking applied to auditing, and it is what standards expect. Auditing everything equally is both expensive and less effective.

Write the schedule down, and follow it. A programme that slips every quarter is a finding waiting to happen.

FIGURE 1: PLANNING THE PROGRAMME

Cover everything over a cycle

  • Usually a year. Not everything at once.

Weight by risk and history

  • Problem areas more often, stable areas less.

Write the schedule down

  • And follow it. Slippage is itself a finding.

Auditors independent of the work

  • Nobody audits their own process.

Who audits

Nobody audits their own work.

Why: you cannot see the gaps in a process you designed. And even with good intentions, the incentive is wrong.

In a small company this is awkward and solvable. Cross-audit between departments. Someone from operations audits purchasing; someone from purchasing audits operations.

Auditors need training. Not necessarily formal qualification for internal work, but they need to know how to audit — how to sample, how to ask, what evidence means.

An untrained auditor checks whether the documents exist. A trained one checks whether the process works.

How an audit actually runs

Prepare. Read the procedure, the previous audit, any nonconformities in that area, any customer complaints. Come in knowing what to look at.

Open. A short meeting. Explain scope and how long it will take. Reduce the anxiety — you get better information from people who are not defensive.

Gather evidence. The core of it, below.

Close. Report what you found, immediately. No surprises later.

Follow up. Findings become corrective actions, and somebody verifies they worked.

Gathering evidence

Three methods, and you need all three.

Ask. Talk to the people doing the work. How do you do this? What happens when it goes wrong? What is annoying about it?

That last question is the most productive one in auditing. People will tell you where the process is broken if you ask about friction rather than compliance.

Observe. Watch it being done. The gap between the procedure and reality shows here, and it shows fast.

Examine records. Sample. Pick some completed jobs and trace them through. Was every step done? Is the record complete?

Trace both directions. Take a finished product and work backwards to the order. Take an order and work forwards. Different problems surface each way.

FIGURE 2: AUDITING WELL AND AUDITING BADLY

Auditing well

  • Watching work being done
  • Asking what is annoying about the process
  • Sampling records and tracing them
  • Findings that change something

Auditing badly

  • Checking documents exist
  • Asking whether the procedure is followed
  • Reviewing the same clean file each time
  • Findings that are all administrative

Asking good questions

Open questions get information. Closed questions get agreement.

Weak: “Do you follow the procedure?” — the answer is yes, always, and you have learned nothing.

Better: “Show me how you do this.” Then watch.

Better still: “What happens when the part is late?” or “When did this last go wrong?”

And the one that works best: “What is annoying about this process?”

People are honest about friction in a way they are not about compliance. And friction is where the process is failing.

Writing findings

A finding needs three things.

What was found. Specific. The record, the date, the observation.

Which requirement it relates to. A clause, or an internal procedure.

Evidence. What you actually saw.

Not: “documentation could be improved”. That is an opinion and nobody can act on it.

Instead: “Three of ten inspection records sampled from March had no inspector signature, which the procedure requires.”

Somebody can act on that.

Grade them. Major nonconformity, minor nonconformity, observation. Grading matters — treating everything as major means nothing gets prioritised.

After the audit

Findings become corrective actions, and the same rules apply as anywhere else.

Find the root cause. Not “remind the team to sign”.

Change something structural.

Verify it worked. Come back later and check.

Track to closure. An audit finding list that only grows is a system not working.

The audit is not the point. What happens afterwards is.

FIGURE 3: THE AUDIT CYCLE

Prepare

  • Read the procedure, previous findings, complaints

Gather evidence

  • Ask, observe, sample records

Report findings

  • Specific, evidenced, graded

Follow up

  • Root cause, action, verification

Making people willing

The practical problem nobody writes about.

If an audit feels like an inspection people can fail, they will show you the clean file.

Four things that help:

Say what it is for. Finding problems while they are cheap, not catching people.

Never make it disciplinary. The moment a finding leads to blame, information stops.

Report friction as well as nonconformity. If somebody tells you the process is impractical, that is a finding about the process — and treating it that way makes people talk.

Show that findings lead to change. If nothing ever improves, people stop bothering.

What auditors look for in your audits

When a certification body assesses you, they look at your internal audit programme specifically.

Did you cover everything over the cycle?

Were the auditors independent of what they audited?

Did the audits find anything? A programme with no findings is itself a finding.

Were findings closed with root cause and verification?

That third point catches people out. A perfect internal audit record is not the good news it appears to be.

The short version

An internal audit is for finding problems while they are still yours to fix.

Ask, observe, and sample records — all three. Documents existing is not evidence the process works.

Ask what is annoying about the process. It is the most productive question available.

Write findings that are specific and evidenced, then root-cause and verify them.

And if your audits never find anything, they are not working. That is the signal to change how you audit, not a reason to be pleased.

Internal audits that never find anything?

Get in touch. That usually means the audit is checking documents rather than watching work — and it is a straightforward thing to fix.

Leave a comment

Drag