audit (internal)
**Internal audit** is a **systematic self-assessment of an organization's quality management system performed by trained internal auditors** — verifying that documented processes are followed, identifying nonconformances and improvement opportunities, and ensuring ongoing compliance with ISO 9001, IATF 16949, or other quality standards before external auditors arrive.
**What Is an Internal Audit?**
- **Definition**: A planned, independent, and documented examination of quality system processes conducted by the organization's own trained auditors to determine compliance with established requirements and effectiveness of the quality management system.
- **Frequency**: ISO 9001 requires auditing all QMS processes at least annually; high-risk or problem areas may be audited quarterly or more frequently.
- **Independence**: Auditors must not audit their own work — cross-department or cross-shift auditing ensures objectivity.
**Why Internal Audits Matter**
- **External Audit Preparation**: Internal audits identify and fix nonconformances before external certification auditors discover them — avoiding costly certification failures.
- **Continuous Improvement**: Audits surface process gaps, inefficiencies, and improvement opportunities that might otherwise go unnoticed.
- **Management Visibility**: Audit results provide senior management with objective data on quality system health and compliance across all departments.
- **Regulatory Compliance**: ISO 9001, IATF 16949, AS9100, and ISO 13485 all mandate formal internal audit programs as a core QMS requirement.
**Internal Audit Process**
- **Step 1 — Annual Plan**: Create audit schedule covering all QMS processes, weighted by risk and previous findings.
- **Step 2 — Preparation**: Review process documentation, previous audit findings, and customer complaints for the area being audited.
- **Step 3 — Opening Meeting**: Communicate audit scope, criteria, and schedule to the auditee department.
- **Step 4 — Evidence Collection**: Interview personnel, observe processes, review records, and verify compliance through objective evidence.
- **Step 5 — Finding Classification**: Classify findings as major nonconformance, minor nonconformance, observation, or opportunity for improvement.
- **Step 6 — Closing Meeting**: Present findings to auditee management — agree on corrective action timelines.
- **Step 7 — Corrective Action**: Auditee implements corrective actions; auditor verifies effectiveness within agreed timeframe.
- **Step 8 — Management Review**: Audit results reported to management review for systemic analysis and resource allocation.
**Audit Finding Types**
| Type | Definition | Required Response |
|------|-----------|-------------------|
| Major NC | System failure, missing process | Immediate corrective action |
| Minor NC | Single instance of non-compliance | CAPA within 30-60 days |
| Observation | Potential risk, not yet a failure | Track, optional action |
| OFI | Opportunity for improvement | Best practice recommendation |
Internal auditing is **the quality system's immune system** — continuously scanning for weaknesses, identifying problems early, and triggering corrective responses that keep the entire quality management system healthy and effective.