Management
They Just Told Me I’m Going to Be the New Internal Auditor – YIKES! (Part 3)
Why do we perform internal audits in the first place, beyond the fact that ISO 9001:2015 requires them?

Audit Scheduling: A Risk-Based Approach
I am a strong advocate for auditing by process rather than by quality element. Auditing by process means staying within one process, auditing it from beginning to end, and incorporating all applicable quality elements within it, rather than jumping from department to department examining one quality element at a time.
Typically, you would plan to audit each process in your organization at least once per year. However, the audit schedule should evolve based on findings. For example, if a process yields many opportunities for improvement, corrective actions, or training issues, you may want to increase that process’s audit frequency to twice per year. Conversely, if a simple process has been performed by the same experienced person for years and everything is consistently in order, you might reasonably schedule it once every two years.
Most organizations schedule audits once per year to satisfy their ISO 9001:2015 requirements. In my opinion, that is not the best approach. Adjusting the audit schedule based on findings is far more effective in achieving the true objectives of internal auditing.
Furthermore, ISO 9001:2015 places considerable emphasis on risk-based thinking and planning, which aligns well with moving away from a fixed yearly audit schedule and toward one based on risk factors. If your organization has a risk management program, the outputs of that program should inform how you schedule your internal audits. If you do not have a formal risk management system, then your internal audits and audit schedules can serve as one of your primary methods of identifying and addressing risk. In that case, pay special attention to the risk-related sections of each process questionnaire when determining your audit frequency.
The Audit Questionnaire: Auditing by Process
Today, many auditors use software to conduct audits, while others prefer paper. In either case, an audit plan or questionnaire typically lists the items to be verified. The traditional approach is to list all procedure requirements with a yes/no conformance checkbox beside each item. However, I believe auditing by process yields far greater insight and a much better opportunity to identify improvement opportunities.
When auditing by process, our questions are more open-ended and follow the flow of the process. Here are examples of the types of questions I use:
- Are there procedures, work instructions, or flowcharts that define this process? If yes, how do you access them, and how do you know if they are current?
- What are the inputs to your process? What exactly do you need in order to start your job?
- Show me how this process is performed.
- What are the outputs of the process? Are records maintained and legible? Is data collected to measure process performance?
- How is the performance of this process measured? How do you know when it is performing well or poorly?
- What are the risks associated with this process, and how do you mitigate them?
- How do other departments affect this process?
- If something goes wrong in the process, what actions are taken? If there is a nonconformance, is it clearly identified and is data collected?
- Are there tools or equipment used in this process? Do they require calibration or preventive maintenance? Are those records current and readily available?
- Interview employees performing the process to gain their perspective on improvement opportunities, preventive actions, or potential risks they are aware of.
- Are employees performing this process trained and competent? Are training records available and current?
You will notice that these questions require the auditor to first read about the process before performing the audit. They allow the auditor to cover all applicable quality elements within a single process from beginning to end, without artificially separating them by department. Personally, my favorite is number six, because ISO talks about risk and this is a real opportunity to evaluate the risk within the process you are auditing.
Opening and Closing Meetings
Many auditors hold an opening meeting when they audit a process or department. Depending on the size of the organization and the formality of management, this meeting can be as brief as a minute or two, or it can be a formal sit-down session prior to the audit. The purpose of the opening meeting is to:
- Introduce the members of the audit team
- Review the scope and objectives of the audit
- Provide a summary of the auditing methods to be used
- Establish communication between the audit team and the auditee
- Confirm that all necessary resources and facilities are available
- Confirm the date and time of the closing meeting and any interim check-ins during the audit
- Answer any questions the auditee may have
If there is an opening meeting, there should also be a closing meeting. The closing meeting should:
- Be held at the end of the audit, prior to preparation of the audit report
- Include the audit team, the auditee’s management, and the responsible functions that were audited
- Present audit observations to auditee management clearly so that they fully understand the results
- Be documented, with records maintained
When using QMS software, it is often possible to review findings and agree on corrective actions in real time during the audit itself. In that case, the closing meeting simply serves as a summary review of everything agreed upon during the audit.
Audit Observations and Follow-Up Actions
Observations or findings from an audit must be addressed and followed up with actions and verification. Most standards require timely action to address findings. Opportunities for improvement, of course, are items that management can decide to act on immediately or defer to a later date.
When I refer to “actions,” I do not necessarily mean you must issue a formal nonconformity report followed by a corrective action. If you have another system for ensuring that actions are issued, tracked, and followed up upon, that is perfectly acceptable. QMS software often handles this directly within the audit process. Alternatively, a simple spreadsheet reviewed at the closing meeting with all parties present can serve the same purpose. There is no requirement in ISO 9001:2015 that audit findings must be processed through your NCR or corrective action process. You may establish a separate action system if you choose.
Whichever system you use, actions must be completed within an agreed timeframe and must be verified to confirm they are effective at eliminating the observation or finding.
I like to work with three or four types of audit observations, each with different action requirements:
- Corrective Action: Requires root cause analysis, containment, and corrective and preventive actions.
- Simple Action: The action is executed and verified. No full root cause process required.
- Opportunity for Improvement: Typically discussed at a management review meeting and may or may not be implemented.
- Industry-Specific Finding: Depending on your industry, you may define a fourth category suited to your context.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!








