Standards
Internal Audit
A planned, systematic review of a management system by the organisation itself.
Last reviewed 3 July 2026
An internal audit is a planned, systematic review of a management system by the organisation itself, governed by the ISO 19011 guidance on auditing management systems. To meet the ISO 9001, ISO 14001, and ISO 45001 expectation it has to be planned (a programme covering every process and area on a cycle), competence-based (auditors independent of the area being audited), documented (findings, nonconformities, and opportunities for improvement), and followed up to corrective-action closure.
The independence rule is the one that gets missed. An auditor who audits their own area is auditing their own work, and the finding rate collapses — not because the area is clean but because the auditor knows where not to look. A defensible internal-audit programme rotates auditors across areas, scopes them against the standard rather than the procedure, and feeds the findings into the management review so that leadership sees the systemic gaps, not the individual nonconformities. The internal audit is the check in Plan-Do-Check-Act; without it, the act has nothing to act on. See management review, NCR, and CAPA.