ISO 9001 Internal Audit Procedure Template and Guide

ISO 9001 Internal Audit Procedure Template and Guide

$149
A complete, editable ISO 9001 Clause 9.2 internal audit procedure - written as a working document, not an outline. Includes the audit program as a controlled document, a per-audit objectives field, and the method-selection step most procedures have never had.

ISO 9001:2015 · Clause 9.2 Internal audit

Your internal audit program probably runs on time. The question worth asking is whether it is still the right program.

This is a complete Clause 9.2 procedure covering the program, the individual audit, auditor selection and independence, reporting, and the action duty that Clause 9.2.2 e) places inside the audit clause. It arrives as an editable Word document, written as a filled-in worked example, with bracketed placeholders everywhere a value is genuinely yours to set.

The defect this is written to close

ISO 9001 Clause 9.2.2 a) requires the audit program to take into consideration the importance of the processes concerned, changes affecting the organization, and the results of previous audits. Most certified organizations built a schedule at certification and have copied it forward ever since. A schedule that has not moved in four years is evidence on its face that none of those three inputs was considered.

The reason is structural rather than careless. Management review examines audit results; nothing routinely examines the audit plan. So the plan persists.

What this template does about it: The three inputs Clause 9.2.2 a) names are written as conditions that reopen the program, each with an owner and a response time, rather than as considerations at annual planning that nobody revisits.

What this variant carries that the others do not

RequirementWhere it comes fromHow the template handles it
Correction and corrective actionClause 9.2.2 e)ISO 9001 is the only standard in this family that names correction alongside corrective action. Section 6.11 separates them, because findings that close on correction alone reappear two cycles later.
Changes affecting the organizationClause 9.2.2 a)A program input that ISO 13485, ISO 45001, and ISO 7101 do not name. Written as a re-planning trigger with a 20-working-day response.
The external-finding feedback loopMSI house standardA certification body finding in an area the internal program recently passed is a finding about the audit program, not only about the process. It has its own trigger, its own KPI, and Level 4 of the maturity ladder.
Climate change as an audit criterionClauses 4.1 and 4.2, Amd 1:2024The February 2024 climate amendment applies to ISO 9001:2015. Whether climate was determined relevant, and what followed, is a legitimate line of inquiry most audit plans do not list.

What you get

33 pages, editable Microsoft Word format. The process interaction map ships alongside as an editable SVG.

  • Complete internal audit procedure in editable Microsoft Word format
  • Audit program built as a controlled document, with defined re-planning triggers rather than a rolling annual calendar
  • Risk-based audit planning section, with the five levers risk actually changes
  • Per-audit objectives field, with worked examples of well-formed and poorly-formed objectives
  • Method-selection step — on-site, remote, or hybrid, chosen against the evidence the objective demands, with the rationale recorded
  • Platform-specific auditor competence prerequisite (MSI house standard)
  • Evidence-reliability check for remote and digital evidence (MSI house standard)
  • Auditor independence rules written as a decision test, not an intention
  • Finding classification scheme with stated criteria, so a finding means the same thing whoever raised it
  • Follow-up and closure path, with the handoff to corrective action defined at one named point
  • Records table with a location, an owning role, and a retention basis for every record
  • Maturity ladder — eight elements, four levels, scoreable as a self-assessment, with Level 3 named as a legitimate place to stop
  • Full clause cross-reference table mapping every obligation to where it is addressed
  • Section mapping to the ISO 19011:2026 published clause structure
  • Process interaction map — editable SVG plus the embedded image, so you can redraw it to your own process names
  • Appendix A — audit plan, built to function as the gate that opens an audit
  • Appendix B — audit program register with the re-planning log
  • Appendix C — desk-level auditor work instruction with a worked example

Risk-based audit planning, written as a mechanism

Clause 9.2.2 a) requires the audit program to take into consideration the importance of the processes concerned. That is the requirement that makes risk-based prioritization mandatory rather than optional. The template turns it into a mechanism.

What variesHigher riskLower risk
FrequencyEvery cycle, re-audited early where findings recurLonger interval, with the basis recorded
DepthWalked end to end, including handoffsKey controls sampled
Sample sizeLarge enough to support a conclusion about the systemSufficient to confirm the control operates
MethodOn-site, including the shift where supervision is thinnestRecords reviewed remotely
AuditorMost experienced available; second auditor where contestedAny qualified auditor on the register

Why this matters: Most programs answer the importance-of-processes requirement by adjusting frequency alone. A low-risk and a high-risk process both audited annually, same checklist, same two-hour slot, have not been differentiated in any way that changes what the audit finds.

Who this is for

Quality managers, audit program managers, and consultants at ISO 9001 certified or certifying organizations. Particularly useful where the audit schedule has not changed since certification, where auditors are working from a checklist inherited at transition, or where findings close without anyone verifying they worked.

What it does for you

  • Turn the schedule back into a program. The three inputs Clause 9.2.2 a) names become triggers that reopen the plan, so the program stays current between reviews.
  • Give every audit a stated purpose. An objective tells the auditor what conclusion the audit is meant to support. Audits with one are shorter and sharper.
  • Vary the audit by risk, not just the date. Interval, depth, sample, method, and auditor all move with assessed risk, and the basis is recorded.
  • Make findings comparable. Classification criteria are stated, so a major raised by one auditor means what a major raised by another means.
  • Close the loop where most programs leak. Verification that the action worked is a defined step with an owner, not an assumption.

$149

Single-standard variant. ISO 9001:2015 Clause 9.2, in full.

One-time payment. Immediate download. Editable Microsoft Word format.

Questions

Does it cover the whole standard?

No. It covers ISO 9001 Clause 9.2 in full. It is one procedure in a management system and it references the neighboring processes — corrective action, competence, document control, management review — rather than replacing them.

We also hold ISO 13485. Do we need both variants?

Take the Device combined variant instead. It resolves the divergences between Clause 9.2 and Clause 8.2.4 explicitly and records every decision at Appendix D, which is work you would otherwise do yourself.

Is this a template or a finished procedure?

Both, and that is deliberate. It is written as a filled-in worked example so you can see what each element looks like when done properly, with bracketed placeholders wherever a value is genuinely yours to set — thresholds, roles, systems, retention periods, audit frequency. You are editing a working document rather than filling in a hollow outline.

What format does it arrive in?

Editable Microsoft Word (.docx). Adapt it, rebrand it, adopt it into your document control system.

Is this built to ISO 19011:2026?

It is structured to the ISO 19011:2026 clause architecture, and it implements the change ISO names in its own foreword — expanded guidance on remote auditing methods, drawing on ISO/IEC TS 17012. Everything beyond that, including the platform-specific competence prerequisite and the evidence-reliability check, is MSI's house standard drawn from 200+ audits attended, and is labeled as such in the document. ISO 19011 is guidance rather than a requirements standard, so no organization is certified against it and no clause of it can be raised as a nonconformity.

Will this pass an audit?

A procedure does not pass an audit; an organization does. What this gives you is a procedure that addresses every requirement of the clause with a named owner and a named record, and that describes a process people can actually follow. Conformity is demonstrated by implementation and evidence — a perfect document over a program that ignores it is still a finding. Unfilled placeholders are unmet requirements, so fill them.

Where does corrective action sit?

Outside this procedure, deliberately. This one owns the audit program, the audit, the report, finding classification, and the follow-up verification. Root cause analysis, the corrective action record, and effectiveness evaluation belong in your corrective action procedure. The handoff is defined at one named point so nothing falls between them.

We use different clause numbering or a different document system.

Every cross-reference is held in a table at the back rather than baked into the body text, precisely so you can renumber to your own system without unpicking the procedure.

Can you help us implement it?

Yes. Call MSI at 760-434-9141 to schedule a planning session.

Not sure where your program stands?

The free Internal Audit Maturity Check scores eight elements of your audit program in under five minutes and returns an element-by-element breakdown with a priority order. It is the same maturity ladder built into this template, so it will tell you which sections matter most to you before you spend anything.

Take the free Internal Audit Maturity Check

Related training

MSI's QMS process interview course covers how to run the interviews an internal audit depends on: QMS Process Interviews

About Management Systems International

Management Systems International, LLC is a veteran-owned, female-owned ISO consulting firm co-founded in 1998. MSI has 28 years of experience, has supported 80+ certifications, attended 200+ audits, and trained 600+ professionals across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

This template encodes the patterns that recur across that work — not one organization’s approach generalized, but the structural weaknesses that show up again and again.

To discuss your audit program directly, call MSI at 760-434-9141 or 888-914-9141.

© 2026 Management Systems International, LLC · All rights reserved.