What is an ISO Audit Process?
“I am here to audit you.” That phrase can still strike fear in most of us, thanks in part to our good friends at the IRS. In the business world, those five words can send a chill down the spine of everyone from the Finance VP to the shipping department clerk.
But it shouldn’t if you have a well run audit process for internal audits. A strong ISO audit process turns the visit from a surprise inspection into a normal management routine: plan the work, do the audits, check the results, and adjust the system before an external auditor, customer, or regulator has to point out the problem.
Why an ISO Audit Process?
Preparing for audits is just one reason to have a proper internal auditing process or program. Another good reason is that it is frequently a requirement. ISO 9001, for example, includes internal audit requirements in Clause 9.2, and the official ISO 9001:2015 requirements page remains the central reference for the standard.
As noted above, internal audits can ensure your policies, procedures, and processes comply with the required standards and regulations. Do you really want to wait for external auditors to show up before you know how your organization’s internal control or Quality Management System is doing?

If ISO compliance is your only goal in creating and maintaining a system of internal control, or in instituting a Quality Management System like ISO 9000 and its associated internal audits, then you may be missing a great opportunity. Compliance is the floor. Continual improvement is where the audit program starts paying for itself.
If your business or organization is taking the trouble to institute internal control and management systems, shouldn’t you use the system to continually monitor and improve performance? Internal auditing has an important role in the continual improvement mindset. Using control and management simply for compliance is just doing the bare minimum, and few businesses truly succeed with that philosophy.
What is the ISO Audit Process?
The ISO audit process is a planned cycle for checking whether your management system conforms to requirements, whether it is being followed, and whether it is producing useful results. In practice, it means choosing qualified auditors, setting a schedule, defining audit scope, collecting objective evidence, reporting findings, and following through on corrective actions.
Putting an internal auditing process or program in place isn’t difficult or expensive. The key is commitment to applying a small amount of resources in assembling and training an internal audit team, and then scheduling internal audits according to your organizational needs.
For example, a pharmaceutical company complying with FDA regulations will probably want a more aggressive internal audit schedule than a tool company that is ISO 9001 registered. The standard gives the requirement, but the business has to translate that requirement into a practical audit program plan.
What The ISO Audit Process Contains
The ISO audit process is a cycle of planning the audits, performing or doing the audits, checking the audits, and then adjusting the audit plan based on the results of the first audits. This is the PDCA, or process approach, applied to auditing. ISO 19011 provides broader guidelines for auditing management systems, which is why it is a useful reference when building the audit program behind an ISO 9001 system.

How Do You Plan Audits?
Start the audit process with an audit program plan: who is going to audit what by when. Create a schedule of when each audit is going to take place. Determine the audit scope or area to be audited and who the appropriate auditors would be for each audit based on auditor qualifications, including skill, technical knowledge, and experience.
Make sure to plan for needed training for new auditors or refresher training for experienced auditors. This is especially important for IATF 16949 automotive auditing, which has more requirements for auditors, including understanding Advanced Product Quality Planning (APQP), Core Tools, and types of process audits, such as product, manufacturing, and supplier audits.
Important Note: The ISO standard requires that all Critical To Quality (CTQ) processes be audited and that all clauses of the ISO standard that apply to each process be included in your audit program. If the plan skips a CTQ process, the audit program is not really testing the system you depend on.
How Do You Do Audits?
Then implement the plan with a series of audits at planned intervals throughout the year. Check the audit program schedule regularly to ensure each audit is actually getting done. This is a very common audit finding: the audits are planned, something comes up, and the audits are not completed as scheduled.
Remember, you can always perform a full system audit at the end of the audit year to ensure that all CTQ processes have been covered. That should be a backstop, not a substitute for planned intervals. A rushed full system audit rarely produces the same quality of evidence as a disciplined audit program.
How Do You Check Audits?
Check the audit program plan. Did each audit go according to plan? How well was each audit planned? Was each audit report well written with actionable findings? The worst audit report is one that has no findings, positive or negative.

If the process being audited is perfect and meeting all metrics 100%, then state the process objectives, process performance, and conclude that it is perfect. Then state what the improvement goal is and the expected date of completion. This is rare, but it can happen.
More than likely, the process is less than perfect. State what actions are being taken to reach the target and the expected date. There is always an action that can be followed up on for the next audit.
If there are nonconformances or gaps in performance, either with the standard or with your quality objectives, then that is a finding that goes in your audit report. Now check that all findings were acted upon in a timely manner and corrective actions were completed. If you find discrepancies, then you have something to act on in the Adjust phase.
How Do You Adjust Audits?
What were the results of the check step? Was the audit program perfectly executed? Great, then raise the bar and try for higher levels of performance. If not, initiate action, change the audit program plan, and run it through another year of the cycle.
This is where an audit process becomes more than paperwork. The audit program plan should change when results show that a process is high risk, a recurring nonconformance keeps appearing, an auditor needs more training, or a corrective action does not hold. Adjusting the plan is how the organization learns.
Audit Program Communication
Besides committing the appropriate resources, including personnel, budget, and time, training and clear communication are the most important elements of an internal audit process. The internal audit teams should be trained on the audit process as well as the standard or regulation to which audits are being conducted.
Audits, whether internal or external, should always be conducted to a specific standard, regulation, or internal control system, including policies and procedures. This allows auditors to base objective findings on very specific requirements instead of personal opinion, memory, or department folklore.
Communicating the objectives of the internal audit process throughout the organization is also important. If everyone in the organization understands that auditing is always about improving the system, and never about catching someone doing something wrong, this knowledge goes a long way to alleviate fear and dread. It is especially useful when employees understand that the audit will provide meaningful information for continual improvement and effective management as well as preparation for external audits.
Internal Auditor Training Classes
Bizmasterz can help with your internal auditing program. The Internal Auditor Training class covers key areas on which all internal audit team members should be trained, such as audit techniques, the importance of clear communication, appropriate auditor behavior, how to conduct audits that stay within scope and schedule, and audits that provide meaningful information for compliance and continual improvement.

While the Bizmasterz Internal Auditor class uses the ISO 9001 standard, the techniques and information can be applied while auditing to any standard or regulation, including:
- IATF 16949
- TL 9000
- AS 9100
- ISO 14001
- GAAP
- ISO 22000
- Sarbanes-Oxley
- OSHA
- FDA
- FAA
- Internal Policies and Procedures
Bizmasterz Managing Director Dr. Chris Anderson developed and teaches the course. Chris has years of auditing experience across numerous fields and industries, including AS 9100 Aerospace, ISO 9001 manufacturing, IATF 16949 Automotive, FDA/ISO 13485 medical device, Sarbanes-Oxley Accounting, and ITIL Information Technology compliance. Chris also holds certifications involving quality management and auditing from the American Society for Quality (ASQ).
If your organization has an aggressive and well run audit system, when an external auditor shows up, whether from a customer, a regulator, or a third party registrar, then nothing they do or find will be a surprise to you. If the internal audit system has already identified areas for improvement, and plans and activities for improvement are in place, including Corrective Actions, then most external auditors will view your proactive management very positively.
So the next time someone says, “I am here to audit you,” instead of reacting with fear and dread, think of it as what it really is: an opportunity to improve your department and your organization. Bizmasterz is here to help you make auditing a pleasure, not a pain.
Frequently Asked Questions
What Is An ISO Audit Process?
An ISO audit process is a planned method for checking whether a management system, internal control system, or quality process meets defined requirements. It usually includes planning the audit, conducting the audit, checking findings, and adjusting the audit program based on results.
Why Does ISO 9001 Require Internal Audits?
ISO 9001 requires internal audits so an organization can confirm that its quality management system conforms to requirements and is effectively implemented. Internal audits also give management evidence for continual improvement before an external auditor arrives.
How Often Should Internal Audits Be Scheduled?
Internal audits should be scheduled at planned intervals based on risk, process importance, past findings, customer requirements, and applicable standards. A pharmaceutical company under FDA expectations may need a more aggressive schedule than a smaller tool company registered to ISO 9001.
What Should An Audit Program Plan Include?
An audit program plan should identify who audits what, when each audit occurs, the audit scope, auditor qualifications, applicable clauses, and any required training. It should also confirm that CTQ processes and applicable standard requirements are covered.
How Do Internal Audits Support Continual Improvement?
Internal audits support continual improvement by turning objective findings into corrective actions, follow-up checks, and better audit plans. When employees understand that audits improve the system rather than catch people doing something wrong, the process becomes more useful and less threatening.