Guides · Auditing

How to run an internal audit your certification body will respect

The ISO 19011 approach scaled for a small business — programme, plan, findings and follow-up, from someone who audits for a living.

Why internal audits go wrong in SMEs

Three patterns account for most weak internal audit programmes: audits done once, in a panic, the month before the certification visit; checklists that ask "is there a procedure?" instead of "does the process work?"; and findings that get recorded but never actioned. Your certification body's auditor has seen all three a hundred times — and a hollow internal audit programme is itself a nonconformity against clause 9.2.

Start with a programme, not an audit

ISO 19011 — the auditing guideline your CB auditor was trained on — starts above the individual audit: a programme that covers every process over a defined cycle, weighted by risk. Processes that are new, changed, customer-critical or previously troubled get audited more often. A simple one-page schedule showing what gets audited, when, by whom, against which clauses, is worth more than any amount of checklist paperwork.

Plan each audit around the process, not the clause list

Pick the process, then identify which clauses apply to it. Build your questions from three sources: the standard's requirements, your own documented procedures, and what went wrong last time (previous findings, complaints, nonconformities). The best audit questions follow a real transaction end to end — take one recent order, one recent complaint, one recent hire, and trace what actually happened against what should have.

Independence with a small team

Clause 9.2.2 requires auditors to be objective and impartial — auditing your own work is out. In a small business, cross-train two or three people so they can audit each other's areas, or bring in an external auditor for a day or two per cycle. Document auditor competence either way: your CB will ask.

Classify findings the way your certification body does

  • Major nonconformity — the system element is missing or has broken down entirely; product/service conformity is at risk.
  • Minor nonconformity — an isolated lapse against a requirement that otherwise works.
  • Observation / opportunity for improvement — not a breach, but a weakness worth addressing before it becomes one.

Classifying honestly matters more than scoring well. An internal audit that finds nothing is not a good result — it's an audit your CB will discount.

Close the loop, and verify it stayed closed

Every finding needs an owner, a root cause (a real one — "human error" is a symptom, not a cause), a corrective action, and a verification of effectiveness after a defined interval. That last step is the most-skipped and most-checked: your CB auditor will pick a closed finding and ask "how do you know the fix worked?" If your system enforces the verification interval automatically, that question stops being scary.

Report so leadership actually reads it

One page: what was audited, against what, what was found (classified), what happens next, and the auditor's honest view of whether the process is in control. Trends across audits — the same finding recurring in different areas — are management review gold.

Written by Gareth Bewley PCQI, BSI-certified ISO 9001:2015 Lead Auditor. Published 4 July 2026.

See where you stand first

The free readiness check scores you across the six areas your auditor will examine — instantly, no sign-up.