Preparation for ISO Certification 21 Nov 2025

Internal audits in accordance with ISO standards

A practical guide to ISO internal audits: what they are, why ISO 9001/14001/27001 require them, how ISO 19011 supports good auditing, and what competence really means for internal auditors.

Auditing Management Systems in Practice

Internal auditing is one of the key elements of management systems based on ISO standards such as ISO 9001, ISO 14001, and ISO/IEC 27001.
Although it is often perceived merely as a formal requirement related to certification, in practice it plays a far more significant role.

A well-planned and properly conducted ISO internal audit is one of the fundamental tools used to:

  • assess the effectiveness of the management system,
  • confirm compliance with requirements,
  • identify areas requiring improvement.

At the same time, performing internal audits is one of the more demanding roles within the entire management system.
Not everyone feels comfortable in this role – and that is completely natural.

What is an internal audit?

An internal audit is a systematic, independent, and documented process aimed at obtaining objective evidence and evaluating it against predefined criteria.

Put simply, an internal audit allows an organization to verify whether its management system operates as planned and whether it genuinely supports the achievement of organizational objectives.

In ISO-based management systems, audit criteria typically include:

  • requirements of the relevant ISO standards (e.g. ISO 9001, ISO 14001, ISO/IEC 27001),
  • legal and regulatory requirements,
  • internal procedures, policies, and instructions,
  • organizational objectives, commitments, and internal arrangements.

It is important to emphasize that an internal audit is not an assessment of employees or their competencies.
The subject of the audit is the system, processes, and decisions – not individual people.

Internal audit as a requirement of ISO standards

An internal audit is not a “best practice by choice” nor an optional addition to a management system.
Within ISO-based management systems, it is a mandatory requirement that every organization must fulfill.

The obligation to conduct internal audits arises directly from core management system standards, including:

  • ISO 9001:2015 – Clause 9.2 Internal audit
  • ISO 14001:2015 – Clause 9.2 Internal audit
  • ISO/IEC 27001:2022 – Clause 9.2 Internal audit

Regardless of whether the system concerns quality, environmental management, information security, or another discipline, the logic remains the same:
the organization must regularly verify whether its management system operates as intended.

ISO standards require organizations to:

  • plan internal audits, rather than perform them on an ad hoc basis,
  • define audit scope, frequency, and methods in relation to risks and processes,
  • ensure auditor objectivity and impartiality,
  • analyze audit results, rather than treat them as a formality,
  • take post-audit actions if nonconformities or weaknesses are identified.

In practice, this means that an internal audit should function as a management tool, not as a one-time activity conducted solely before a certification audit.

It is also worth noting that the draft editions of ISO 9001:2026 and ISO 14001:2026 maintain the requirement for internal audits.
This clearly confirms that internal auditing remains a permanent and essential element of management systems, regardless of changes to the standards themselves.

ISO 19011 – the foundation of good auditing practices

Management system standards such as ISO 9001, ISO 14001, and ISO/IEC 27001 clearly state that internal audits must be conducted.
However, they do not provide detailed guidance on how to audit effectively in practice.

This is where ISO 19011 – Guidelines for auditing management systems comes into play.

ISO 19011:

  • is not a certifiable standard,
  • does not lead to certification,
  • represents a set of good auditing practices that support structured, objective, and effective audits.

In other words:
certification standards define what must be done, while ISO 19011 explains how to audit properly.

What does ISO 19011 cover?

ISO 19011 structures the entire auditing process and covers, among other things:

  • principles of auditing, such as integrity, objectivity, confidentiality, and an evidence-based approach,
  • management of the audit programme, including long-term planning,
  • audit planning and execution, step by step,
  • auditor competence, including knowledge, skills, and professional attitude,
  • auditing of integrated management systems, such as quality, environmental, and information security systems,
  • a risk-based approach, focusing audit efforts on what matters most to the organization.

As a result, ISO 19011 goes beyond theory and supports practical, conscious auditing of management systems.

Why is ISO 19011 so important?

In practice, ISO 19011 serves as a reference point for professional auditing, both for internal audits and for audits conducted by certification bodies.

This guideline:

  • helps distinguish auditing from inspection or control,
  • supports the development of auditor competence,
  • enables audits to be conducted in a consistent and comparable manner,
  • increases the real value of audits for the organization.

For organizations and internal auditors alike, ISO 19011 provides a foundation for a mature approach to auditing, whether a single system or an integrated system is being audited.

Who conducts an internal audit?

An internal audit is conducted by an internal auditor or an audit team appointed by the organization in accordance with its internal rules.
ISO standards do not prescribe a specific job title or position – what matters is who performs the auditor role and under what conditions.

In practice, an internal auditor may be:

  • an employee of the organization, properly prepared for the role,
  • a person from a different department than the audited area, ensuring objectivity,
  • an integrated management system auditor, where multiple systems are in place,
  • in certain cases, an external auditor, if the organization chooses to outsource internal audits.

Regardless of the approach, ISO standards and ISO 19011 emphasize not who audits, but whether the required conditions are met.

Key requirements when selecting an internal auditor

For an internal audit to deliver real value, the organization must ensure:

  • independence from the audited area,
  • impartiality in evaluating evidence and forming conclusions,
  • no auditing of one’s own work, processes, or decisions.

In practice, this means that even individuals with extensive knowledge and experience are not always suitable auditors for every area.

This element – independence and professional distance – is what distinguishes internal auditing from routine supervision or operational control.

Internal auditor competence according to ISO 19011

One of the most common misconceptions about internal audits is the belief that knowing the ISO standard is sufficient to be a good auditor.
ISO 19011 clearly demonstrates that internal auditor competence is much broader.

An internal auditor should:

  • understand the requirements of the audited ISO standards (e.g. ISO 9001, ISO 14001, ISO/IEC 27001),
  • understand organizational processes and context, not just documented procedures,
  • be familiar with reference documents such as policies and instructions,
  • be able to plan and conduct audits in a structured manner,
  • analyze audit evidence and formulate fact-based conclusions,
  • communicate clearly and professionally, including in challenging situations,
  • maintain objectivity and confidentiality throughout the audit process.

However, technical knowledge and skills are only one side of the role.

Personal attributes of an internal auditor

ISO 19011 also emphasizes the importance of auditor attitude, which in practice determines audit quality.
Key personal attributes include:

  • assertiveness,
  • calmness and composure,
  • curiosity and the ability to ask meaningful questions,
  • resistance to pressure,
  • communication culture and respect for auditees.

These attributes ensure that auditing is perceived as a dialogue about the system, not as a form of control.

Competence is built over time

Internal auditor competence does not develop overnight.
It is built gradually through:

  • training,
  • participation in audits,
  • mentoring,
  • practical audit experience.

A good auditor is not created after a single course or a first audit.
It is a process that requires time, experience, and conscious development.

Objectives of internal audits

An internal audit is not an end in itself.
Its purpose is not to “tick off a standard requirement”, but to provide the organization with reliable information on how the management system works in practice.

A well-planned internal audit:

  • confirms compliance with ISO standards, legal requirements, and internal arrangements,
  • evaluates the effectiveness of the management system,
  • identifies risks and weaknesses before they become real problems,
  • highlights areas for improvement and organizational development,
  • prepares the organization for certification body audits, reducing surprises,
  • provides management with objective, fact-based information for decision-making.

In practice, internal auditing acts as a systemic early warning mechanism, enabling proactive improvement rather than reactive problem-solving.

Does an internal auditor need a certificate?

No.
This is one of the most frequently repeated myths related to internal auditing.

ISO standards do not require internal auditors to hold a certificate.
Instead, they require auditors to be:

  • competent, with appropriate knowledge, skills, and experience,
  • impartial, independent from the audited area,
  • formally appointed in accordance with organizational rules.

A training certificate may support development, particularly at the beginning, but it does not by itself make someone a good auditor.

In practice, audit quality depends on:

  • experience,
  • the ability to analyze evidence,
  • communication skills,
  • the ability to draw meaningful conclusions.

This is why auditor competence is built primarily through practice, not certification alone.

Stages of an internal audit according to ISO 19011

Although the detailed audit process may vary depending on the organization, industry, or management system, ISO 19011 defines a common logical structure that ensures consistent and effective auditing.

An internal audit typically includes the following stages:

1. Audit programme

The organization plans audits over a broader timeframe, usually annually or across the certification cycle.
The audit programme defines which areas will be audited, how often, and why, considering risks, process importance, and previous audit results.

2. Audit planning

This stage focuses on a specific audit and includes defining:

  • audit objectives,
  • audit scope,
  • audit criteria,
  • the audit team,
  • the audit schedule.

Good planning prevents confusion and misunderstandings during execution.

3. Conducting the audit

This is the stage most commonly associated with auditing.
It involves interviews, observations, and document and record review.
The objective is to collect objective evidence, not to confirm preconceived assumptions.

4. Reporting

After the audit, the auditor prepares a report documenting findings, conclusions, and – where applicable – nonconformities or observations.
The report should be clear, factual, and reliable, serving as a basis for further action.

5. Post-audit actions

This final stage involves analyzing audit results and implementing corrective or improvement actions.
It is at this point that the audit translates into real change within the management system.

Internal audit is not for everyone

Internal auditing is a role that is intellectually, communicatively, and emotionally demanding.
It requires not only system knowledge but also the ability to conduct discussions, ask difficult questions, and remain objective in ambiguous situations.

It is not uncommon for individuals serving as internal auditors to decide to step away from the role over time because they no longer feel comfortable in it.
This is a natural situation and does not indicate system weakness.

On the contrary, it often reflects organizational maturity – an understanding that internal audits should be conducted by people genuinely prepared for the role, not by those who are forced into it.

Internal audits work best when:

  • the auditor understands the role and its significance,
  • the organization, including management, provides real support,
  • the auditor feels competent and safe in the role, both technically and organizationally.

Only under such conditions does auditing move beyond formality and begin to support the system rather than burden it.

What internal auditors must not do

Equally important as what internal auditors should do is what they must not do.
Crossing these boundaries quickly undermines trust in the audit process.

An internal auditor should not:

  • evaluate people instead of processes and system operation,
  • propose operational solutions that belong to process owners,
  • act under pressure from stakeholders or management,
  • ignore inconvenient or conflicting evidence,
  • use audits for personal gain or to settle relationships.

These boundaries are particularly important under ISO 19011, which emphasizes independence, objectivity, and integrity.

An internal auditor must remain an independent observer of the system, capable of objectively assessing its performance.
They are not system designers, implementation consultants, or operational decision-makers.

Internal audit as real value

When conducted consciously and in line with ISO 19011 principles, internal auditing can be one of the most valuable elements of a management system.
Not because “the standard requires it”, but because it provides reliable insight into how the system actually works.

A well-designed internal audit:

  • improves management system effectiveness,
  • reduces the risk of nonconformities before certification audits,
  • supports informed management decisions,
  • contributes to real organizational improvement rather than formal compliance.

There is one condition:
internal auditing must not be treated as a box-ticking exercise.

When audits become routine and unreflective, they lose value.
When conducted by competent auditors, with respect for independence and objectivity, they become a tool for system development rather than a burden.

On certiget.pl and certiget.eu, you can also find a detailed catalog of management system certification bodies from around the world, including Poland, with the ability to compare offers and search by standard.

Article author


Lukasz Kowalski

Managing Director

Certiget.

Lukasz Kowalski is an expert in the certification body market and management system certification processes. He is the founder of Certiget – the world's first platform created to increase transparency in the certification market and help organizations make informed decisions when selecting a certification body. He gained his experience both by implementing and improving management systems within organizations and at British Standards Institution (BSI) – one of the world's most renowned certification bodies. This unique background enables him to understand the certification process from the perspective of both organizations seeking certification and certification bodies. He specializes in ISO management systems and the certification market. His articles are based on practical experience as well as the latest international standards and accreditation requirements.


Share this article