IMS Internal Audit Procedure Template and Guide (ISO 9001 + ISO 14001:2026 + ISO 45001:2018)

IMS Internal Audit Procedure Template and Guide (ISO 9001 + ISO 14001:2026 + ISO 45001:2018)

$349
One internal audit procedure serving quality, environmental, and OH&S together. Every divergence across the three clauses resolved to the stricter standard, marked by scope, and recorded in the integration decision record.

ISO 9001:2015 + ISO 14001:2026 + ISO 45001:2018 · Clause 9.2 in all three standards

Three standards, three versions of the same clause, and no two of them agree.

A combined audit is the normal case in an integrated system, and this procedure is built for it: one program, one plan, one report, with scope markers throughout showing which obligation applies where.

Twelve of twenty-two obligations carry a dash

The clause cross-reference in this template runs to twenty-two obligations across the three standards. Twelve of them carry at least one dash — a requirement one standard imposes and another does not.

ISO 14001:2026 requires per-audit objectives; the other two do not. ISO 14001:2026 requires the audit program itself to be available; the other two require retained evidence of its implementation. ISO 45001 requires consultation, worker reporting, and continual improvement of OH&S performance; neither other standard does. ISO 9001 and ISO 14001 ask the program to consider changes affecting the organization; ISO 45001 does not. ISO 9001 requires correction and corrective action; ISO 45001 requires action citing Clause 10; ISO 14001 Clause 9.2 requires neither.

That is the practical argument for a combined procedure rather than three separate ones.

The action clause is a genuine three-way split: ISO 9001 is the only one that names correction. ISO 45001 is the only one that names continual improvement and cites Clause 10. ISO 14001 Clause 9.2 carries no action requirement at all. Start from any one of the three and you lose something the other two require.

What this variant carries that the others do not

RequirementWhere it comes fromHow the template handles it
Three-way scope determinationSection 2.1All three, two of three, one only, or uncertain — with guidance on which variant to use instead where fewer than three apply.
[Q] [E] [S] scope markersMSI house standardEvery obligation carries the standard or standards it comes from, so single-standard requirements survive integration.
Three importance lenses, never averagedAppendix D row 8Process importance, environmental significance, and OH&S risk profile recorded separately. Averaging gives a middling audit to a process critical in one discipline.
Combined-audit competence statedMSI house standardAn auditor competent in all three disciplines is uncommon. Where no single auditor covers the scopes, the procedure requires a team with the scopes divided and one lead accountable for the conclusions.
Appendix D across three directionsMSI house standardTen divergences, each naming which standard the house decision came from, because no one standard is strictest throughout.
Process interaction mapISO 9001 Clause 4.4.1The quality scope brings the requirement in. Editable SVG plus embedded image, with the scope of each interface marked.

What you get

43 pages, editable Microsoft Word format. The process interaction map ships alongside as an editable SVG.

  • Complete internal audit procedure in editable Microsoft Word format
  • Audit program built as a controlled document, with defined re-planning triggers rather than a rolling annual calendar
  • Risk-based audit planning section, with the five levers risk actually changes
  • Per-audit objectives field, with worked examples of well-formed and poorly-formed objectives
  • Method-selection step — on-site, remote, or hybrid, chosen against the evidence the objective demands, with the rationale recorded
  • Platform-specific auditor competence prerequisite (MSI house standard)
  • Evidence-reliability check for remote and digital evidence (MSI house standard)
  • Auditor independence rules written as a decision test, not an intention
  • Finding classification scheme with stated criteria, so a finding means the same thing whoever raised it
  • Follow-up and closure path, with the handoff to corrective action defined at one named point
  • Records table with a location, an owning role, and a retention basis for every record
  • Maturity ladder — eight elements, four levels, scoreable as a self-assessment, with Level 3 named as a legitimate place to stop
  • Full clause cross-reference table mapping every obligation to where it is addressed
  • Section mapping to the ISO 19011:2026 published clause structure
  • Process interaction map — editable SVG plus the embedded image, so you can redraw it to your own process names
  • Appendix A — audit plan, built to function as the gate that opens an audit
  • Appendix B — audit program register with the re-planning log
  • Appendix C — desk-level auditor work instruction with a worked example
  • Appendix D — integration decision record: every divergence between the standards, what this procedure does, and what the alternative was

Risk-based audit planning, written as a mechanism

All three clauses require the program to take account of process importance, each through its own lens. The template turns it into a mechanism, with the three rankings recorded separately and the audit set against the highest of them.

What variesHigher riskLower risk
FrequencyEvery cycle, re-audited early where findings recurLonger interval, with the basis recorded
DepthWalked end to end, including handoffsKey controls sampled
Sample sizeLarge enough to support a conclusion about the systemSufficient to confirm the control operates
MethodOn-site, including the shift where supervision is thinnestRecords reviewed remotely
AuditorMost experienced available; second auditor where contestedAny qualified auditor on the register

Why this matters: Most programs answer the importance-of-processes requirement by adjusting frequency alone. A low-risk and a high-risk process both audited annually, same checklist, same two-hour slot, have not been differentiated in any way that changes what the audit finds.

Who this is for

Management representatives and integrated-system managers at organizations holding ISO 9001, ISO 14001, and ISO 45001, and consultants supporting integrated systems. Particularly useful during the ISO 14001:2026 transition, when one of the three clauses moves and the other two do not.

What it does for you

  • One program instead of three. Combined audits are the normal case in an integrated system and this is written for them.
  • Nothing gets lost in the merge. Scope markers show which obligation comes from which standard, so single-standard requirements survive integration.
  • Handle the 14001:2026 transition inside an integrated system. The changed clause is marked and the other two are undisturbed.
  • Resolve the divergences once. Appendix D records all ten, in three directions, with the rejected alternatives.
  • Plan for combined-audit competence. Auditing three disciplines in one pass has staffing implications, and the procedure states them.

$349

Combined variant. All three clauses in full, with the divergences resolved and recorded.

One-time payment. Immediate download. Editable Microsoft Word format.

Questions

Is one integrated audit really better than three separate ones?

For an integrated system, usually yes — one visit, one report, one set of records, and the interfaces between the three systems get examined rather than falling between three audits. The caveat is competence: auditing three disciplines in one pass requires either an auditor qualified across all three or a team with the scopes divided. The procedure states that requirement rather than assuming it away.

Does the climate change amendment apply to all three standards?

Effectively yes, and it is one of the few things in this procedure that applies uniformly. The February 2024 climate action amendment added climate wording to Clauses 4.1 and 4.2 of ISO 9001:2015 and ISO 45001:2018, and ISO 14001:2026 carries climate considerations in its own text. The template notes the uniformity explicitly, because it is the exception in a document full of divergences.

Is this a template or a finished procedure?

Both, and that is deliberate. It is written as a filled-in worked example so you can see what each element looks like when done properly, with bracketed placeholders wherever a value is genuinely yours to set — thresholds, roles, systems, retention periods, audit frequency. You are editing a working document rather than filling in a hollow outline.

What format does it arrive in?

Editable Microsoft Word (.docx). Adapt it, rebrand it, adopt it into your document control system.

Is this built to ISO 19011:2026?

It is structured to the ISO 19011:2026 clause architecture, and it implements the change ISO names in its own foreword — expanded guidance on remote auditing methods, drawing on ISO/IEC TS 17012. Everything beyond that, including the platform-specific competence prerequisite and the evidence-reliability check, is MSI's house standard drawn from 200+ audits attended, and is labeled as such in the document. ISO 19011 is guidance rather than a requirements standard, so no organization is certified against it and no clause of it can be raised as a nonconformity.

Will this pass an audit?

A procedure does not pass an audit; an organization does. What this gives you is a procedure that addresses every requirement of the clause with a named owner and a named record, and that describes a process people can actually follow. Conformity is demonstrated by implementation and evidence — a perfect document over a program that ignores it is still a finding. Unfilled placeholders are unmet requirements, so fill them.

Where does corrective action sit?

Outside this procedure, deliberately. This one owns the audit program, the audit, the report, finding classification, and the follow-up verification. Root cause analysis, the corrective action record, and effectiveness evaluation belong in your corrective action procedure. The handoff is defined at one named point so nothing falls between them.

We use different clause numbering or a different document system.

Every cross-reference is held in a table at the back rather than baked into the body text, precisely so you can renumber to your own system without unpicking the procedure.

Can you help us implement it?

Yes. Call MSI at 760-434-9141 to schedule a planning session.

Not sure where your program stands?

The free Internal Audit Maturity Check scores eight elements of your audit program in under five minutes and returns an element-by-element breakdown with a priority order. It is the same maturity ladder built into this template, so it will tell you which sections matter most to you before you spend anything.

Take the free Internal Audit Maturity Check

Related training

MSI's QMS process interview course covers how to run the interviews an internal audit depends on: QMS Process Interviews

About Management Systems International

Management Systems International, LLC is a veteran-owned, female-owned ISO consulting firm co-founded in 1998. MSI has 28 years of experience, has supported 80+ certifications, attended 200+ audits, and trained 600+ professionals across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

This template encodes the patterns that recur across that work — not one organization’s approach generalized, but the structural weaknesses that show up again and again.

To discuss your audit program directly, call MSI at 760-434-9141 or 888-914-9141.

© 2026 Management Systems International, LLC · All rights reserved.