ISO 7101 Internal Audit Procedure Template and Guide

ISO 7101 Internal Audit Procedure Template and Guide

$149
A complete, editable ISO 7101 Clause 9.2 internal audit procedure for healthcare organizations. Covers the twelve-month audit floor, the trained-and-qualified-auditor requirement, and the audit objectives ISO 7101 has required since 2023.

ISO 7101:2023 · Clause 9.2 Internal audit

ISO 7101 states things the other management system standards leave to judgment, and its internal audit clause is where that is clearest.

Clause 9.2.2 sets a floor: internal audits shall be performed at a minimum once every twelve months. No other standard in this family states a frequency. Planned intervals elsewhere means whatever you can justify; here there is a number.

A floor, not a target

Read carefully, the twelve-month minimum is a floor on the audit program rather than a target for individual audits: every part of the management system within scope is audited at least once in any twelve-month period.

In a clinical organization the scope is wide — wards, theatres, outpatients, diagnostics, pharmacy, medical records, procurement, estates, and the governance processes holding them together. A twelve-month cycle across all of it is achievable, but only if coverage is planned as a whole rather than assembled audit by audit. Organizations that plan audit by audit discover in month eleven that four services have not been covered and cannot be.

What this template does about it: The program register carries a limit date column — last audited plus twelve months — so the obligation becomes arithmetic anyone can check at a glance, including an assessor.

What this variant carries that the others do not

RequirementWhere it comes fromHow the template handles it
A twelve-month audit floorClause 9.2.2The only stated frequency in the family. Coverage is planned as a whole, with a limit date recorded per process.
Trained and qualified individualsClause 9.2.2 d)Competence stated inside the audit clause, which no other standard in the family does. An auditor register records which services each auditor is qualified for, and the audit plan has a do-not-proceed field.
Reporting in a timely mannerClause 9.2.2 c)The timeliness qualifier appears in no other version of this clause. An adverb is not auditable, so the template states an interval and records the closing date against the issue date.
Audit objectives since 2023Clause 9.2.2 a)ISO 7101 has required them three years longer than ISO 14001. For a healthcare organization this is established practice, not a 2026 retrofit.
Patient dignity, consent, and confidentialityMSI house standardYou are a visitor in a care setting before you are an auditor. Handled in the work instruction and in the exception paths.

What you get

36 pages, editable Microsoft Word format. The process interaction map ships alongside as an editable SVG.

  • Complete internal audit procedure in editable Microsoft Word format
  • Audit program built as a controlled document, with defined re-planning triggers rather than a rolling annual calendar
  • Risk-based audit planning section, with the five levers risk actually changes
  • Per-audit objectives field, with worked examples of well-formed and poorly-formed objectives
  • Method-selection step — on-site, remote, or hybrid, chosen against the evidence the objective demands, with the rationale recorded
  • Platform-specific auditor competence prerequisite (MSI house standard)
  • Evidence-reliability check for remote and digital evidence (MSI house standard)
  • Auditor independence rules written as a decision test, not an intention
  • Finding classification scheme with stated criteria, so a finding means the same thing whoever raised it
  • Follow-up and closure path, with the handoff to corrective action defined at one named point
  • Records table with a location, an owning role, and a retention basis for every record
  • Maturity ladder — eight elements, four levels, scoreable as a self-assessment, with Level 3 named as a legitimate place to stop
  • Full clause cross-reference table mapping every obligation to where it is addressed
  • Section mapping to the ISO 19011:2026 published clause structure
  • Process interaction map — editable SVG plus the embedded image, so you can redraw it to your own process names
  • Appendix A — audit plan, built to function as the gate that opens an audit
  • Appendix B — audit program register with the re-planning log
  • Appendix C — desk-level auditor work instruction with a worked example

Risk-based audit planning, written as a mechanism

Clause 9.2.2 requires the audit program to consider the importance of the processes concerned. That is the requirement that makes risk-based prioritization mandatory. The template turns it into a mechanism, with clinical risk and patient safety incident history as two of the lenses — within the twelve-month cap, which cannot be lengthened however well a process performs.

What variesHigher riskLower risk
FrequencyEvery cycle, re-audited early where findings recurLonger interval, with the basis recorded
DepthWalked end to end, including handoffsKey controls sampled
Sample sizeLarge enough to support a conclusion about the systemSufficient to confirm the control operates
MethodOn-site, including the shift where supervision is thinnestRecords reviewed remotely
AuditorMost experienced available; second auditor where contestedAny qualified auditor on the register

Why this matters: Most programs answer the importance-of-processes requirement by adjusting frequency alone. A low-risk and a high-risk process both audited annually, same checklist, same two-hour slot, have not been differentiated in any way that changes what the audit finds.

Who this is for

Quality and accreditation leads at healthcare organizations certified or certifying to ISO 7101. Particularly useful where an audit procedure was adapted from ISO 9001 and the healthcare-specific obligations in Clause 9.2.2 were never added.

What it does for you

  • Meet the twelve-month floor by design. Coverage planning with a recorded limit date per process is what makes it work across clinical and non-clinical services.
  • Qualify your auditors on the record. Clause 9.2.2 d) puts competence inside the audit clause, so a register stating which services each auditor covers is the natural evidence.
  • Define timely. The clause says results are reported to relevant managers in a timely manner, and an interval beats an adverb.
  • Audit where care actually happens. Night shift and weekend working are where supervision is thinnest and practice drifts furthest from procedure.
  • Keep clinical audit and internal audit apart. They are different disciplines with different methods, and the template audits whether clinical audit runs without trying to conduct one.

$149

Single-standard variant. ISO 7101:2023 Clause 9.2, in full. Written throughout for a healthcare organization.

One-time payment. Immediate download. Editable Microsoft Word format.

Questions

Does this replace clinical audit?

No, and it should not. Clinical audit of care against clinical standards is a distinct discipline with its own methodology. An internal audit under this procedure may examine whether clinical audit is being conducted and acted upon; it does not conduct one. The template states the boundary explicitly.

Can we audit a low-risk service less often than every twelve months?

No. In every other variant of this procedure, a process with no findings across several cycles is a candidate for a longer interval. Here it is not — Clause 9.2.2 caps the interval at twelve months regardless of how well a process performs. The only adjustment available is to audit more often, in more depth, or with a sharper objective.

Is this a template or a finished procedure?

Both, and that is deliberate. It is written as a filled-in worked example so you can see what each element looks like when done properly, with bracketed placeholders wherever a value is genuinely yours to set — thresholds, roles, systems, retention periods, audit frequency. You are editing a working document rather than filling in a hollow outline.

What format does it arrive in?

Editable Microsoft Word (.docx). Adapt it, rebrand it, adopt it into your document control system.

Is this built to ISO 19011:2026?

It is structured to the ISO 19011:2026 clause architecture, and it implements the change ISO names in its own foreword — expanded guidance on remote auditing methods, drawing on ISO/IEC TS 17012. Everything beyond that, including the platform-specific competence prerequisite and the evidence-reliability check, is MSI's house standard drawn from 200+ audits attended, and is labeled as such in the document. ISO 19011 is guidance rather than a requirements standard, so no organization is certified against it and no clause of it can be raised as a nonconformity.

Will this pass an audit?

A procedure does not pass an audit; an organization does. What this gives you is a procedure that addresses every requirement of the clause with a named owner and a named record, and that describes a process people can actually follow. Conformity is demonstrated by implementation and evidence — a perfect document over a program that ignores it is still a finding. Unfilled placeholders are unmet requirements, so fill them.

Where does corrective action sit?

Outside this procedure, deliberately. This one owns the audit program, the audit, the report, finding classification, and the follow-up verification. Root cause analysis, the corrective action record, and effectiveness evaluation belong in your corrective action procedure. The handoff is defined at one named point so nothing falls between them.

We use different clause numbering or a different document system.

Every cross-reference is held in a table at the back rather than baked into the body text, precisely so you can renumber to your own system without unpicking the procedure.

Can you help us implement it?

Yes. Call MSI at 760-434-9141 to schedule a planning session.

Not sure where your program stands?

The free Internal Audit Maturity Check scores eight elements of your audit program in under five minutes and returns an element-by-element breakdown with a priority order. It is the same maturity ladder built into this template, so it will tell you which sections matter most to you before you spend anything.

Take the free Internal Audit Maturity Check

Related training

MSI's ISO 7101 healthcare quality management system overview course covers the standard as a whole: ISO 7101 Overview: HCQMS

About Management Systems International

Management Systems International, LLC is a veteran-owned, female-owned ISO consulting firm co-founded in 1998. MSI has 28 years of experience, has supported 80+ certifications, attended 200+ audits, and trained 600+ professionals across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

This template encodes the patterns that recur across that work — not one organization’s approach generalized, but the structural weaknesses that show up again and again.

To discuss your audit program directly, call MSI at 760-434-9141 or 888-914-9141.

© 2026 Management Systems International, LLC · All rights reserved.