Clause 9.2 of ISO 9001: Internal Auditing (2024)

I think the internal auditing clause of ISO 9001 has had more articles, blogs, webinars, videos and letters to the editor produced about it than any other clause in ISO 9001. Perhaps only Document Information (clause 7.5) comes close to having a similar number of column inches dedicated to analysing it.

Not to buck the trend, I have written and presented numerous times on the subject of Internal Auditing.

Here is a list of those articles I have written about it:

  • The Use of Risk Based Thinking When Creating an Internal Audit Schedule
  • Is it time to STOP Internal Auditing?
  • 5 Habits of Successful QHSE Compliance Managers
  • Internal Audits - Your (Not So) Secret Weapon

Here are the webinars I have presented on the topic:

  • Tips and Tricks to Add Value to Your Audit Reports
  • Freshening-up Your Internal Auditing Programme
  • Are you Running an Effective Internal Audit Programme
  • How to Create an Internal Audit Schedule
  • Creating Internal Audit Schedules
  • 7 Keys to Running an Effective Internal Audit Programme

Clause 9.2 of ISO 9001: Internal Auditing (1)

Clause 9.2.1 Conduct internal audits at planned internals.

  • The technique of doing internal audits is up to you.
  • The length of the intervals between audits is up to you.
  • The way you’ll decide how your organisation conforms to your QMS and ISO 9001 is up to you.
  • The manner by which you’ll determine how effective and maintained the system is, is up to you.

It really is a free-for-all. The only requirement is that you have to do it. I have found that internal audits give great value but it can be a confrontational experience and, depending on your interview technique, people can be uncooperative and defensive.

I would highly recommend getting some internal auditor training from local experts to help find the best techniques to prevent and/or overcome such experiences.

Clause 9.2.2 How to conduct audits

This clause can be broken into the following sections.

1. Plan your approach to internal audits based on the importance of the processes. A mistake most companies make is to audit absolutely everything once a year. The standard gives you flexibility around this, so use your resources wisely and only audit what is important or what is the highest risk to your business.

2. For each audit, work out the scope of what will be covered. You can’t audit 100% of the process, but you do need to cover enough to be satisfied that the important issues have been captured.

3. Make sure the auditors are independent of the process under audit. This can be tricky so you need to give it plenty of thought.

4. Report all findings to the relevant mangers so there aren’t any surprises.

5. Ensure that the corrective actions from the audit are dealt with.

6. Retain the audit results in a document.

Here at Mango we are taking an innovative approach to internal auditing. We are using a DIME (documented, implemented, monitored and effective) matrix to ensure the QMS conforms. The DIME approach is referenced in this webinar: Freshening-up Your Internal Auditing Programme.


Takeaways

Here is a list of takeaways that will help you meet clause 9.2:

  1. Only audit what is important or what is the highest risk to your business.
  2. For each audit work out the scope of what will be covered.
  3. Make sure the auditors are independent of the process.
  4. Keep records of the audit.

View previous blogs in this series "How to Implement a QMS and Achieve ISO 9001 Certification":

How to Implement a QMS and Achieve ISO 9001 Certification - Part 1: Introduction

How to Implement a QMS and Achieve ISO 9001 Certification - Part 2: Customer Focus

How to Implement a QMS and Achieve ISO 9001 Certification - Part 3:Leadership

How to Implement a QMS and Achieve ISO 9001 Certification - Part 4:Engagement of People

How to Implement a QMS and Achieve ISO 9001 Certification - Part 5: Process Approach

How to Implement a QMS and Achieve ISO 9001 Certification - Part 6: Improvement

How to Implement a QMS and Achieve ISO 9001 Certification - Part 7:Evidence Based Decision Making

How to Implement a QMS and Achieve ISO 9001 Certification - Part 8: Relationship Management

How to Implement a QMS and Achieve ISO 9001 Certifiaction - Part 9: Clauses 0.1, 0.2, 0.3, 1, 2 and 3 of ISO 9001:2015

How to Implement a QMS and Achieve ISO 9001 Certification - Part 10: Clauses 4.1, 4.2, 4.3 and 4.4 – Context, Interested Parties, Scope,QMS

How to Implement a QMS and Achieve ISO 9001 Certification - Part 11: Clauses5.1 Leadership and Commitment

How to Implement a QMS and Achieve ISO 9001 Certification - Part 12: Clause 5.2Policy

How to Implement a QMS and Achieve ISO 9001 Certification - Part 13: Clause 5.3 Roles, Responsibilities and Authorities

How to Implement a QMS and Achieve ISO 9001 Certification - Part 14: Clause 6.1Actions to Address Risks and opportunities

How to Implement a QMS and Achieve ISO 9001 Certification - Part 15: Clause 6.2 Objectives

How to Implement a QMS and Achieve ISO 9001 Certification - Part 16: Clause7.1 Resources

How to Implement a QMS and Achieve ISO 9001 Certification - Part 17: Clause7.2 and 7.3 - Competence and Awareness

How to Implement a QMS and Achieve ISO 9001 Certification - Part 18: Clauses 7.5 - Documented Information

How to Implement a QMS and Achieve ISO 9001 Certification - Part 19: Clauses 8.1 - Operational Planning and Control

How to Implement a QMS and Achieve ISO 9001 Certification - Part 20: Clauses 8.2 - Requirements for Products and Services

How to Implement a QMS and Achieve ISO 9001 Certification - Part 21: Clauses 8.3 - Design and Development

How to Implement a QMS and Achieve ISO 9001 Certification - Part 22: Clauses 8.4 - Control of Externally Provided Processes, Products and Services

How to Implement a QMS and Achieve ISO 9001 Certification - Part 23: Clauses 8.5 -Production and Service Provision

How to Implement a QMS and Achieve ISO 9001 Certification - Part 24: Clause 8.6 - Release of Products and Services

How to Implement a QMS and Achieve ISO 9001 Certification - Part 25: Clause 8.7 - Control of Non-Conforming Outputs

How to Implement a QMS and Achieve ISO 9001 Certification - Part 26: Clause 9.1 - Monitoring, Measurements, Analysis and Evaluation

Clause 9.2 of ISO 9001: Internal Auditing (2024)

FAQs

Clause 9.2 of ISO 9001: Internal Auditing? ›

Clause 9.2 of ISO 9001 specifies the requirements for internal audits. The objectives of internal audits are as follows: To ensure that the quality management system (QMS) conforms to the requirements of ISO 9001 and to the organization's own requirements, policies, and procedures.

What does ISO 14001 Clause 9.2 2 require of an internal audit system? ›

Clause 9.2.2 Internal Audit Programme

“The organization shall plan, establish, implement and maintain an audit programme(s) including the frequency, methods, responsibilities, planning requirements and reporting of its internal audits.

What is the 9.2 2.1 internal audit program? ›

IATF 16949 9.2. 2.1 requires Management Review to include a review of the audit program effectiveness. This can be evaluated against not only the metric assigned to the internal audit process, if it's defined as a process but also other indirect metrics, such as scrap, customer PPM, launch metrics, etc.

What does clause 9 of ISO 9001 concern? ›

Clause 9 of the ISO 9001:2015 standard, titled “Performance Evaluation,” serves the purpose of establishing requirements for monitoring, measuring, analyzing, and evaluating the performance of a quality management system (QMS).

Which ISO 9001 2015 clauses for internal audit? ›

This is part of the continuous improvement process. In summary, Clause 9.2 of ISO 9001:2015 emphasizes the importance of internal audits as a tool for evaluating the effectiveness of the QMS and ensuring its ongoing improvement.

Is internal audit mandatory for ISO 9001? ›

ISO 9001 requires companies to conduct internal audits at planned intervals to provide information on whether the QMS conforms to: the company's own self-imposed requirements for its QMS and. the requirements of the ISO 9001 standard, and. the effective implementation and maintenance of the QMS.

What is the ISO standard for internal audit? ›

ISO 19011 is defined as the standard that sets forth guidelines for auditing management systems. The standard contains guidance on managing an audit program, the principles of auditing, and the evaluation of individuals responsible for managing the audit programs.

What is the ISO for internal audit? ›

Internal audits help identify processes that may not be fully implemented according to ISO 9001 requirements, allowing corrective action to be taken. Internal audits serve as a means of readiness, enabling organizations to identify and rectify any nonconformities before the external audit takes place.

How hard is the Certified Internal Auditor test? ›

The Certified Internal Auditor (CIA) exam is a challenging test that requires in-depth knowledge of auditing, business, and compliance practices. Many candidates make the mistake of trying to memorize CIA exam questions and answers, but this is not an effective way to study.

What is clause 9 in ISO 9001 2015? ›

Clause 9 emphasizes the importance of conducting internal audits at planned intervals. These audits provide a systematic and objective evaluation of an organization's quality management system, focusing on the system's effectiveness and adherence to ISO 9001 requirements.

What is Clause 9 of ISO 9001 2015? ›

ISO 9001:2015 Clause 9 Performance Evaluation

Determine what, how, when and by whom results will be measured and evaluated. Determine the methods for obtaining, monitoring and reviewing customer satisfaction. Have an objective, planned and effectively implemented internal audit program.

What is clause 9.3 in ISO 9001? ›

Key points outlined in Clause 9.3 include:

Top management is required to review the organization's QMS at planned intervals to ensure its continuing suitability, adequacy, effectiveness, and alignment with the strategic direction of the organization.

What does Clause 9.2 1 requires the organization to do? ›

1 Conduct internal audits at planned internals. The technique of doing internal audits is up to you. The length of the intervals between audits is up to you.

How often should you do an internal audit for ISO 9001? ›

The basic requirement of the quality management system is that it is audited at least once per year. If many issues are found during audits, then additional audits can be undertaken to help get that part of the system working effectively again as soon as possible.

What is required to perform an internal audit? ›

The steps to preparing for an internal audit are 1) initial audit planning, 2) involve risk and process subject matter experts, 3) frameworks for internal audit processes, 4) initial document request list, 5) preparing for a planning meeting with business stakeholders, 6) preparing the audit program, and 7) audit ...

What are the ISO 14001 requirements? ›

Requirements for ISO 14001 Certification

Conducting a thorough environmental impact assessment. Setting environmental objectives and targets. Monitoring and measuring environmental performance. Continually improving the EMS based on regular reviews and evaluation.

What is the requirement of internal audit? ›

All companies listed on stock exchanges in India must have an internal auditor. Turnover - 200 crores or more. Paid Up Share Capital - 50 crores or more. Outstanding loans/ Borrowing from banks or financial institutes - Exceeding limit of 100 crores or more.

What is the Clause 9.1 2 of ISO 14001 2015? ›

An organisation in addition to evaluating the fulfilment of its compliance obligations, is also expected to maintain a knowledge and understanding of its compliance status. As per ISO 14001:2015, Clause 9.1. 2, an understanding of the organisation's compliance status must be demonstrated.

Top Articles
Latest Posts
Article information

Author: Annamae Dooley

Last Updated:

Views: 5717

Rating: 4.4 / 5 (45 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Annamae Dooley

Birthday: 2001-07-26

Address: 9687 Tambra Meadow, Bradleyhaven, TN 53219

Phone: +9316045904039

Job: Future Coordinator

Hobby: Archery, Couponing, Poi, Kite flying, Knitting, Rappelling, Baseball

Introduction: My name is Annamae Dooley, I am a witty, quaint, lovely, clever, rich, sparkling, powerful person who loves writing and wants to share my knowledge and understanding with you.