An ISO 14001 internal audit is not optional: clause 9.2 requires audits at planned intervals, and
your certification body will expect at least one against the 2026 text before your transition audit. This is a working ISO 14001
internal audit checklist by clause, plus how to build the programme itself.
The ISO 14001 internal audit programme comes before the checklist
Clause 9.2 asks for a programme that takes account of the environmental importance of the
processes concerned and the results of previous audits. Build the ISO 14001 internal audit programme
from the aspects register: processes carrying significant aspects get audited more often and in more
depth. Record that reasoning — a programme that cannot explain its own frequencies is a
finding in itself.
Two further ISO 14001 internal audit requirements catch smaller organisations. Auditors must be
objective and impartial, so whoever maintains the registers cannot audit them; train a colleague from
another function or bring someone in. And results must reach relevant management and feed management
review under 9.3.
The ISO 14001 internal audit checklist by clause
Clause 4 — Context. Are internal and external issues current, and does
climate change appear as a context issue in its own right rather than as an afterthought? Are
interested parties and their needs recorded? Is the scope documented and does it match the sites and
activities that actually exist?
Clause 5 — Leadership. Can top management describe the environmental policy
and their own accountability for the EMS? Are roles, responsibilities and authorities documented, and
do the people holding them know it? Ask one directly.
Clause 6 — Planning. Is the significance methodology documented, not just
the register? Does the aspects register cover abnormal and emergency conditions and the life cycle
beyond your gate? Is the compliance obligations register specific and current, and does it include
voluntary commitments? Are objectives measurable, resourced and owned? And under the new
clause 6.3: was the last significant change to the organisation or its processes
planned, with the EMS consequences considered before the change rather than after?
Clause 7 — Support. Competence against defined requirements for people whose
work affects significant aspects. Awareness: can staff state the significant aspects relevant to their
job and the consequences of not following procedure? Communication, internal and external, with
records. Document control — and specifically, are people working from 2026-edition documents or
from 2015 leftovers?
Clause 8 — Operation. Trace controls from a significant aspect into the
actual workplace. Test the extended requirement on externally provided processes, products and
services: how are environmental requirements communicated to suppliers and contractors, and how is
compliance verified? For 8.2, when was the last emergency test, who took part, and what changed as a
result?
Clause 9 — Performance evaluation. What is monitored, against what target,
and is the measuring equipment calibrated or verified? Has compliance with each obligation been
evaluated and recorded? Does management review cover the restructured inputs and outputs and produce
decisions with owners and dates?
Clause 10 — Improvement. Take a nonconformity: was root cause reached, was
effectiveness verified, and were the registers updated as a result?
Audit programme, checklists and forms for the 2026 edition.
The ISO 14001 Toolkit includes the internal audit procedure, a risk-based programme template, clause-by-clause checklists and the nonconformity and corrective action forms — all written to ISO 14001:2026.
Findings that recur at almost every ISO 14001 internal audit
- Compliance obligations listed but never evaluated. The most common finding in
the standard, and the easiest to test. - Significance criteria undocumented, so nobody can explain the scoring.
- Aspects registers covering only normal operating conditions.
- Life cycle ignored beyond the organisation’s own boundary.
- Supplier and contractor controls asserted but not evidenced — a bigger
exposure under the 2026 edition than the 2015 one. - Emergency procedures never tested, or tested and never evaluated.
- Monitoring equipment out of calibration, which quietly invalidates the data.
- Corrective actions closed on completion rather than on verified effectiveness.
Getting value from an ISO 14001 internal audit, not a paper exercise
The most informative ISO 14001 internal audit is a trace rather than a clause march. Take one significant aspect and
follow it end to end: its register entry and significance rationale, the compliance obligation
attached to it, the operational control, the competence of the people doing the work, the monitoring
data, the calibration behind that data, and the last management review that discussed it. One trace
tests clauses 6 through 9 at once and reveals whether the system is real. Pair it with a walk around
the site asking people what they do when something spills, and the audit starts earning its cost.
References
- ISO 14001:2026 — the current edition on iso.org.
- ISO’s publication announcement — 15 April 2026.
- ISO 14001:2015 — the previous edition, now withdrawn.
- ANAB on the 2026 transition — the accreditation body’s summary of the changes.
More on ISO 14001
- ISO 14001:2026 transition
- ISO 14001 certification
- ISO 14001 implementation guide
- ISO 14001 mandatory documents
- the ISO 14001 register
- ISO 14001 internal audit checklist — you are here
All of these are covered by the ISO 14001 Toolkit, written to the 2026 fourth edition. For background see ISO 14001 compliance, or browse the free ISO templates.