An IMS internal audit examines several management system standards in a single programme, usually quality, environment and occupational health and safety. Because ISO 9001, ISO 14001 and ISO 45001 share the same high-level structure, one audit team can check the common clauses once and then examine the topic-specific requirements. Done well, it saves time and shows leaders how the parts of the system fit together. Done badly, it produces three overlapping audits with a single cover sheet.
This guide explains how to plan and run an IMS internal audit: what the standards require, how to build the programme, how to choose and train auditors, how to sample evidence and how to report findings so they lead to action.
Free gap assessment
Are you ready for the 2026 edition of ISO 9001?
Score yourself against the new edition, free, including the risk and opportunity split and the clause 10 renumbering that breaks converted checklists.
Run the free ISO 9001 gap assessment → or View premium report sample
What the standards require of an IMS internal audit
The management system standards built on the ISO high-level structure, also called Annex SL, each contain an internal audit clause, numbered 9.2 in the current editions. It requires the organisation to conduct internal audits at planned intervals to provide information on whether the system conforms to the organisation’s own requirements and to the standard, and whether it is effectively implemented and maintained. Auditors must be objective and impartial, results must be reported to relevant management, corrections must be made without undue delay, and documented information must be kept as evidence of the programme and the results. Our overview of Annex SL explains why the clause looks the same across standards.
Guidance on how to do all this appears in ISO 19011:2018, guidelines for auditing management systems, which also covers combined audits. You can read its listing on iso.org. The guideline is not certifiable, but certification bodies expect an audit programme that follows its principles.
Benefits of a combined IMS internal audit
- Less disruption. Process owners are interviewed once instead of three times.
- Consistent findings. A weakness in document control or management review is seen as one issue, not three.
- A view of interactions. Auditors can see where a quality change affects safety or environmental risk.
- Lower cost. Fewer audit days are needed for the shared requirements.
The trade-off is competence. A combined audit needs auditors who understand more than one discipline, or teams that pair specialists. Otherwise the audit skims the technical requirements and concentrates on paperwork.
Building the IMS internal audit programme
The programme is the plan for the whole cycle, usually a year or three years. Base it on risk and importance. Give more attention and frequency to processes with significant risks, past incidents or complaints, recent changes, or poor previous results. Cover every process, site, shift and requirement within the cycle, and record the reasoning for the scope.
| Programme element | What to decide |
|---|---|
| Objectives | What the programme must show, such as conformity, effectiveness or readiness for certification |
| Scope | Standards, sites, processes and requirements covered |
| Frequency | Based on risk, changes and previous results |
| Resources | Auditors, time and travel; competence needed |
| Criteria | Standards, legal requirements, procedures, customer requirements |
| Reporting | Who receives results and when |
Coordinate the programme with your integrated management review, so audit results are an input to management decisions. Leaders should see trends, not just individual findings.
Choosing the audit approach for an IMS internal audit
Process-based audits
Rather than auditing clause by clause, follow a process from input to output and check every relevant requirement along the way. An order-to-delivery audit, for example, tests contract review (quality), environmental controls in packaging, and safe handling in the warehouse in one trail. This approach finds gaps between departments and matches how the work is done.
Clause-based audits for shared requirements
Some requirements are best audited centrally, such as document control, internal audit itself, management review, corrective action and competence. Audit them once for all standards, using the IMS document control arrangements as a reference. Then spend your process audits on topic-specific requirements.
Auditor competence and independence
Auditors must be objective and impartial. In practice this means they should not audit their own work. In small organisations that is hard, so use auditors from another department, share auditors with a sister site, or use an external provider for sensitive areas. Competence covers audit method, knowledge of each standard and enough understanding of the technical area to ask sensible questions. Train new auditors, observe them on their first audits and keep records of competence. A short calibration meeting before each cycle helps auditors apply the same judgment to what counts as a nonconformity.
Preparing and running the audit
For each audit, agree the objectives, scope, criteria and timetable and give the auditee notice. Auditors should review earlier reports, open actions, procedures, risk registers, incident data and objectives before arriving. Prepare a plan of what to sample and questions to ask, but stay flexible.
During the audit, collect evidence by interview, observation and record review. Ask open questions such as “show me how you decide”, and follow the evidence. Sampling matters: choose records across periods, shifts and products, and include some selected by the auditor, not offered by the auditee. Record what was seen, not just conclusions, so that findings can be traced.
Writing IMS internal audit findings
A useful finding states the requirement, the evidence and the gap. Distinguish nonconformities from observations and opportunities for improvement. Grade nonconformities by severity, for example major where a requirement is missing or a system failure is likely to lead to a defect or injury, and minor for isolated lapses. For a combined audit, note which standards a finding affects, so a single corrective action can serve them all. Our guide to the IMS risk register shows how risk information can support the severity decision.
Remote and multi-site audits
Some evidence can be reviewed remotely, such as records, dashboards and interviews by video. Physical conditions, housekeeping, machine guarding and waste storage still need someone on site. For multi-site organisations, sample sites by risk, rotate the auditors, and compare results between sites to spot practices worth sharing or problems that repeat. Agree in advance what technology will be used and how confidential information will be protected.
Follow-up and corrective action
Findings only matter if they are closed. Each nonconformity needs containment, root cause analysis, corrective action, an owner and a date, and later verification that the action worked. Track open items in a single register, and escalate those that are late. Feed the results into management review, including numbers by standard, repeat findings and time to close. A repeat finding is a sign that the earlier corrective action addressed the symptom, not the cause.
A hypothetical example of an IMS internal audit
The following is a hypothetical example invented for illustration. A packaging manufacturer holds ISO 9001, ISO 14001 and ISO 45001. Its annual programme includes eight process audits and three clause-based audits. In the process audit of “new product introduction”, two auditors, one quality and one safety specialist, follow a trial run from design review to first production.
They find that design review records exist, but a new solvent was approved without an environmental aspect assessment, and a guarding change was made without updating the risk assessment. One combined corrective action requires the change procedure to include environmental and safety checks. The cause was a change form that asked only about quality impact. The fix is a single revised form, verified at the next cycle, which closes findings under three standards at once.
Common mistakes in an IMS internal audit
Typical weaknesses include auditing to a checklist without following evidence, programmes that cover only what is easy, auditors who lack technical knowledge, audits of one’s own department, findings without evidence, slow follow-up, repeat findings with the same corrective action and reports that go no further than the quality manager. Another is treating certification audits as the real test and internal audits as a formality, when the internal programme is where problems should be found first.
Templates and tools for the IMS internal audit
Consistent tools make audits faster and easier to compare. You need an audit programme, an audit plan, a checklist or question set for each process, a findings form and a report format. The Integrated Management System Toolkit provides documents for the shared and topic-specific requirements you will audit against. Whichever tools you use, keep them the same across sites and cycles so results can be compared.
For the wider picture of implementing the system you are auditing, see our IMS implementation guide and the description of the integrated management system manual.
IMS internal audit FAQ
Can one audit cover several ISO standards at once?
Yes. Standards built on the same high-level structure share requirements, so a combined audit can check them together, provided auditors have the competence for each topic.
How often should an IMS internal audit be carried out?
The standards require audits at planned intervals. Most organisations cover every process at least once a year or over a three-year cycle, with more frequent audits of higher-risk areas.
Who can perform an IMS internal audit?
Trained, competent people who are objective and impartial, so not auditing their own work. Use auditors from other departments, shared auditors or an external provider where needed.
Does an internal audit have to follow ISO 19011?
No, it is guidance, not a requirement. Certification bodies, however, generally expect a programme consistent with its principles.
What should happen to the audit results?
They must be reported to relevant management, corrected without undue delay and kept as documented information. They should also feed the management review.