Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 9001 internal audit checklist covering clauses 4 to 10 of the quality management system

ISO 9001 Internal Audit: The Complete 2026 Checklist Guide

The ISO 9001 internal audit is the one activity in a quality management system that tells you the truth before a certification body does. Clause 9.2 of ISO 9001:2026 requires it at planned intervals, and the sixth edition — published September 2026 — changed what the audit has to look for: separated risks and opportunities, seven considerations in change planning, quality culture and ethical behaviour, a climate-change determination, and a renumbered clause 10. This guide explains what clause 9.2 asks for, gives a clause-by-clause checklist on the 2026 numbering, and sets out how to run an audit that stands up at the transition visit.

ISO 9001 internal audit checklist covering clauses 4 to 10 of the quality management system

For the wider context, see our complete ISO 9001 guide; for what changed in the new edition, ISO 9001:2026 changes.

What an ISO 9001 internal audit has to establish

Clause 9.2.1 is precise about the purpose. An ISO 9001 internal audit provides information on whether the QMS conforms to two sets of criteria — the organization’s own requirements for its QMS, and the requirements of the standard — and whether it is effectively implemented and maintained. Every audit report therefore answers two questions, not one: does this part of the system conform, and is it actually working? A procedure that matches the standard word for word but that nobody follows fails the second question.

Clause 9.2.2 covers the mechanics of the ISO 9001 internal audit programme. The organization plans, establishes, implements and maintains an audit programme with its frequency, methods, responsibilities, planning requirements and reporting, taking into account the importance of the processes, the results of previous audits and changes affecting the organization. For each audit it defines objectives, criteria and scope; selects auditors and conducts audits in a way that ensures objectivity and impartiality; reports results to relevant managers; takes correction and corrective action without undue delay; and keeps documented information as evidence of the programme and the results. The standard points to ISO 19011 for guidance on auditing.

Why the 2026 edition changes the checklist

The audit clause itself is unchanged from 2015, apart from the sub-clause title “Internal audit programme” at 9.2.2. What changed is the criteria the audit tests against. Nineteen of the 65 requirements in clauses 4 to 10 are revised, new or renumbered, and an ISO 9001 internal audit run from a 2015 checklist will miss every one of them. The items below are the ones a 2015 checklist does not contain.

Clause New or revised requirement What the auditor looks for
4.1 Determination of whether climate change is a relevant issue A recorded determination with reasoning, approved by top management
5.1.1 i), 7.1.4, 7.3 e) Quality culture and ethical behaviour promoted, reflected in the environment, briefed Signed statement; concern channel; staff who can say how to raise a concern
6.1.2 / 6.1.3 Risks and opportunities determined, analyzed, evaluated and actioned separately Two registers or two clearly separated sections, each with effectiveness results
6.3 Seven considerations when planning changes Change records showing communication, effectiveness monitoring and review of results
9.1.3 e) f) Effectiveness of risk actions and of opportunity actions evaluated separately Two evaluations in the analysis, not one blended figure
9.3.2 g) h) Two separate management-review inputs Minutes with the two items taken and recorded separately
10.1 Continual improvement (2015’s 10.1 and 10.3 merged) No live document cites clause 10.3

The ISO 9001 internal audit checklist, clause by clause

Build the ISO 9001 internal audit checklist with one line per numbered sub-clause — 65 in all — with an audit question, the evidence examined and a result: conforms, nonconformity, observation, opportunity for improvement, or not applicable where the scope statement justifies it. The questions below are the ones that find the most.

Clause 4: context

  • Are external and internal issues determined and reviewed, and is the climate-change determination recorded (4.1)?
  • Are interested parties, their relevant requirements, and which ones the QMS addresses recorded and reviewed (4.2)?
  • Does the scope state the products and services covered and justify every non-applicable requirement (4.3)?
  • Do the processes have inputs, outputs, criteria, indicators, resources, owners, risks and opportunities determined (4.4.1)?

Clause 5: leadership

  • Can top management show evidence for each of the twelve commitments, including promoting quality culture and ethical behaviour and both risk-based and opportunity-based thinking (5.1.1)?
  • Does the quality policy meet all five criteria, including taking account of context and supporting strategic direction (5.2.1), and is it communicated and applied (5.2.2)?
  • Are all six responsibilities of 5.3 assigned to named roles, including reporting on opportunities for improvement?

Clause 6: planning

  • Are risks analyzed, evaluated and actioned with proportionality shown (6.1.2)?
  • Are opportunities analyzed, evaluated and actioned in their own right, with actions appropriate to context (6.1.3)?
  • Do quality objectives meet all eight criteria and carry the five planning elements (6.2)?
  • Do change records address all seven considerations (6.3)?

Clause 7: support

  • Is infrastructure managed for on-site, remote and hybrid work (7.1.3), and are social, psychological and physical factors of the environment controlled (7.1.4)?
  • Is measuring equipment calibrated or verified, identified and safeguarded, and is out-of-tolerance impact assessed (7.1.5)?
  • Is organizational knowledge, including knowledge in digital systems, determined and retained (7.1.6)?
  • Is competence evidenced and training effectiveness evaluated (7.2)? Can staff describe the policy, their contribution, the implications of nonconformity, relevant objectives and the quality culture and ethical behaviour (7.3)?
  • Is documented information controlled, is external-origin information identified, and is evidence protected from alteration (7.5)?

Clause 8: operation

  • Are acceptance and process criteria defined and are records kept as evidence (8.1)?
  • Are requirements reviewed before commitment, differences resolved and undocumented requirements confirmed (8.2.3)?
  • Do design projects show plan, inputs, reviews, verification, validation, outputs and controlled changes (8.3)?
  • Are external providers evaluated, monitored and re-evaluated, and is purchasing information adequate (8.4)?
  • Is production or service provision under controlled conditions, including human-error prevention and validated special processes (8.5.1)? Is identification, status and traceability visible (8.5.2)?
  • Do release records show conformity to acceptance criteria and the person authorizing release (8.6)? Are nonconforming outputs controlled, dispositioned and recorded with authority (8.7)?

Clauses 9 and 10: evaluation and improvement

  • Are indicators measured as planned, and are all eight evaluations of 9.1.3 made — with risk and opportunity effectiveness separate?
  • Is customer satisfaction obtained by the stated methods and reviewed (9.1.2)?
  • Does the audit programme cover every process and clause, and are auditors independent of what they audit (9.2)?
  • Does management review include every input of 9.3.2 and record the results of 9.3.3?
  • Are improvement opportunities determined and actioned (10.1), and do corrective actions show cause analysis, effectiveness review and updates to risks and opportunities (10.2)?

How to run an ISO 9001 internal audit that holds up

Programme. The ISO 9001 internal audit programme covers every process and every clause at least once in the cycle, and more often where importance, previous results or change warrant it. A changed process, a new site or a new edition of the standard gets audited within a few months of the change — which is why a full re-audit belongs on every transition plan.

Objectivity. Nobody audits their own work or an area they manage. In a small organization that means training a person from another function, or bringing in an external auditor for the areas the quality manager runs. Record the independence decision in the auditor register; it is the first thing a certification auditor checks about your programme.

Evidence. Every finding is stated with the requirement, the evidence and the location, so it can be verified. An ISO 9001 internal audit collects evidence by interview, observation of work, and sampling of documents and records — and the sampling should be recorded (“release records IR-001 to IR-010”), not summarized (“release records reviewed”).

Reporting and follow-up. Report to the process owner and the relevant managers within days, not weeks. Nonconformities go into corrective action without undue delay — containment inside a week, a cause analysis and plan inside a few weeks — and the auditor verifies closure by evidence. Audit results are a management-review input (9.3.2 d 3), so trends in findings should be presented there.

The two conclusions. End every report with the two answers clause 9.2.1 asks for: conforms to the organization’s own requirements and to ISO 9001:2026, yes or with the nonconformities listed; effectively implemented and maintained, yes, partly or no, with reasons.

Audit with confidence.

Our ISO 9001 Toolkit — 84 templates rebuilt on the 2026 text, $99 — ships an internal audit checklist seeded with all 65 requirements, an audit programme and auditor register, an audit plan and report template, and every policy and record the audit will check, mapped to ISO 9001:2026 in Word and Excel.

Explore the ISO 9001 Toolkit →

Common ISO 9001 internal audit findings

  • Auditing the document, not the practice. The report says the procedure exists; it never says whether anyone followed it last month.
  • Findings without evidence. “Calibration needs improvement” cannot be verified or closed. “Gauge G-12 overdue since 3 June; label illegible” can.
  • The quality manager auditing quality. Independence is a requirement, not a preference.
  • A 2015 checklist on a 2026 system. It asks about 10.3 and one register, and never asks about culture, climate or the seven change considerations.
  • Corrective actions closed on completion, not effectiveness. Clause 10.2.1 requires the effectiveness of corrective action to be reviewed.

Frequently asked questions

Is an internal audit required for ISO 9001?

Yes. Clause 9.2 of ISO 9001:2026 requires internal audits at planned intervals to provide information on whether the QMS conforms to the organization’s own requirements and the standard, and whether it is effectively implemented and maintained.

Who can conduct an ISO 9001 internal audit?

Competent people who are independent of the activity audited — from another function inside the organization, or an external auditor acting on the organization’s behalf. Clause 9.2.2 requires auditor selection and audit conduct to ensure objectivity and impartiality.

How often should you run ISO 9001 internal audits?

At planned intervals set by the audit programme, taking into account the importance of the processes, previous audit results and changes. Most organizations cover every process and clause across a twelve-month programme, with high-importance processes audited more often.

Do we need a new ISO 9001 internal audit for the 2026 edition?

Yes. A transition is a change affecting the organization, and 9.2.2 requires the programme to take such changes into account. Audit the whole system against the 2026 criteria before the certification body’s transition audit, with particular attention to the nineteen revised, new or renumbered requirements.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.