ISO 9001-2015 Internal Audit Checklist Example
ISO 9001-2015 Internal Audit Checklist Example
ISO 9001:2015
Internal Audit
Checklist
System & Process Compliance Auditing
Double click here to insert ISO 9001:2015 Internal Audit Checklist
your organization’s name
or logo. System & Process Compliance Auditing
Table of Contents
GUIDANCE .................................................................................................................................................................................................................................................. 3
Guidance
About this Checklist
The audit checklist is just one of the many tools which are available from the auditor’s toolbox that help ensure your audits address the necessary
requirements. It stands as a reference point before, during and after the audit process and if developed for a specific audit and used correctly will provide the
following benefits:
The audit findings ‘traffic lights’ are intended to visually communicate the risk posed by the audit finding of any system or processes being audited. The rating
system is stratified from ‘compliant’ to ‘major non-conformance’ to convey a concise and consistent method for scoring each audit finding. At the end of the
audit, you can transfer the findings into an Excel spreadsheet to create charts, summary tables and trend data to paste into your audit report or management
review documentation.
This methodology should be uniformly applied to all types of internal audit (gap analysis, system audits and process audits) that your organization will likely
undertake.
Compliant means adherence with the requirements of the standard and the EQMS. The
COMPLIANT Continue to monitor trends/indicators.
process is implemented and documented and records exist to verify this.
A low risk issue that offers an opportunity to improve current practice. Processes may Review and implement actions to improve the process(s).
OFI cumbersome or overly complex but meet their targets and objectives. Unresolved OFIs may Monitor trends/indicators to determine if improvement was
degrade over time to become non-compliant. achieved.
A medium risk, minor non-conformance resulting in deviation from process practice not
Investigate root cause(s) and implement corrective action by
MINOR N/C likely to result in the failure of the management system or process that will not result in the
next reporting period or next scheduled audit.
delivery of non-conforming products nor reduce the effectiveness of the EQMS.
A high risk, major non-conformance which directly impacts upon customer requirements, Implement immediate containment action, investigate root
MAJOR N/C likely to result in the customer receiving non-conforming products or services, or which may cause(s) and apply corrective action. Re-audit in 4 weeks to
reduce the effectiveness of the EQMS. verify correction.
Principles of Auditing
Auditing relies on a number of principles whose intent is to make the audit become an effective and reliable tool that supports your company’s management
policies and procedures whilst providing suitable objective information that your company can act upon to continually improve its performance. Adherence to
the following principles are considered to be a prerequisite for ensuring that the conclusions derived from the audit are accurate, objective and sufficient. It
also allows auditors working independently from one another to reach similar conclusions when auditing in similar circumstances. The following principles
relate to auditors.
1. Ethical conduct: Trust, integrity, confidentiality and discretion are essential to auditing;
2. Fair presentation: Audit findings, conclusions and reports reflect truthfully and accurately the audit activities ;
3. Professional care: Auditors must exercise care in accordance with the importance of the task they perform;
4. Independence: Auditors must be independent of the activity being audited and be objective;
5. Evidence-based approach: Evidence must be verifiable and be based on samples of the information available.
Audit Methodology
Introduction 4. Are links between other processes established?
The adoption of the ‘process approach’ is mandated by ISO 9001:2015 and 5. Are processes and their links monitored?
is one of the most important concepts relating to quality management 6. Are records maintained?
systems. Process auditing is about auditing your organization’s processes
As part of the process approach, the process audits must be scheduled
and their interactions, which together comprise the quality management
according to the processes defined by your management system. The audit
system.
schedule should not be based on the clauses of the standard, but it should
The process approach is one of the core quality management principles, instead be based upon the importance and criticality of the process itself.
which is defined as a ‘consistent and predictable results are achieved more The process approach to auditing should cover three vital stages:
effectively and efficiently when activities are understood and managed as
1. Preparing for the audit; (desk review)
interrelated processes that function as a coherent system’.
2. Auditing the process and its linkages;
The process audit provides assurance that the processes have been
implemented as planned and provides information on the ability of the 3. Preparing the summary and audit report;
process to produce a quality output. Done properly, a process audit is An audit of customer related processes should be conducted at planned
much more than verification that processes are being followed. Although intervals in order to determine whether the processes conform to planned
preparation can take a day or two, actual audit time is about two hours per arrangements in order to determine whether the process is properly
shift. implemented and maintained and to provide process performance
A process is a set of interrelated activities that transform inputs, such as information to top management.
materials, customer requirements and labor, via a series of activities into Effective process auditing requires the auditor to identify and record audit
outputs, such as a finished product or service. Various stages of the trails that will make a difference to your organization. The audit should
process must meet various applicable clauses of the standard. There are six begin with the process owner in order to understand how the process
characteristics to look out for when auditing a process: interacts with the other process inputs, outputs, suppliers and/or
1. Does the process have an owner? customers.
2. Is the process defined? The auditor should be able to determine whether the outputs are complete
3. Is the process documented? and that process measurements demonstrate whether all of the outputs
Opportunities for
Clause No.
Minor N/C
Major N/C
Compliant
OFI
Provide reference to documented Provide suggestions for
information to justify the finding process improvement
Has your organization determined external and internal
issues relevant to its purpose and its strategic direction
4.1 1
that affect its ability to achieve the intended result(s) of
its EQMS?
Does your organization monitor and review information
4.1 2
about these external and internal issues?
Audit Findings
Question No. Opportunities for
Clause No.
Minor N/C
Major N/C
Compliant
OFI
Provide reference to documented Provide suggestions for
information to justify the finding process improvement
When determining this scope, has your organization
4.3 8 considered the requirements of relevant interested
parties referred to in 4.2?
Question No. ►
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24
Criteria ▼
OFI
MINOR N/C
MAJOR N/C