Skip to content
AuditingPublished Sep 14, 2026 · 7 min read

Internal Quality Audits: What They Are and How to Run Them

Internal quality audits check whether your QMS conforms to standards like ISO 9001. Learn scope, preparation, evidence, reporting, and closeout steps.

Share
Executive summary

An internal quality audit reviews and evaluates a company's procedures and processes to confirm that the system conforms to a quality standard such as ISO 9001. It is performed by the organization on itself, which is why it is also called a first-party audit. The aim is not to catch people making mistakes. It is to establish, with evidence, whether the quality management system actually does what the organization says it does.

Ask quality managers how they feel about audit season and you will get mixed answers. Internal audits can feel inconvenient, and for the people being audited they can be nerve-wracking. Handled well, though, they are one of the most useful tools a quality function has. They take the temperature of the management system, teach the organization something about its own operations, and build the evidence base you need before any third-party auditor walks through the door.

What Is an Internal Quality Audit?

An internal audit of a quality management system is a systematic examination designed to ensure compliance with established quality standards and processes. Three elements of that definition matter. It is systematic, meaning it follows a defined method rather than a casual walkthrough. It is an examination, meaning it relies on evidence rather than opinion. And it is about compliance, meaning the reference point is an external or internal standard, not personal preference.

A quality audit in a manufacturing setting is typically described as a first-party audit when the organization conducts it on its own systems, processes and quality management system. That ownership is what separates an internal audit from the assessments carried out by customers, registrars, or other outside bodies.

Why Internal Quality Audits Matter

A well-designed audit program is not simply a compliance obligation. It lets an organization evaluate its operations, its internal controls, and its risk management processes at any time, on its own schedule, so that it is prepared for any third-party audit that follows. That timing advantage is significant. Findings raised internally can be corrected quietly, with root cause analysis, rather than surfaced under the pressure of an external review.

Regulated industries give the clearest example of the value. In pharmaceutical manufacturing, internal audits are expected to add value to the pharmaceutical quality system, protect patients, and drive continuous improvement. The same logic scales down to smaller operations in other sectors: an audit that only confirms conformity has done half its job. The other half is identifying where the system can perform better.

There is also a cultural benefit. An audit is a good educational exercise and a practical way to take the temperature of your quality management system. People learn how their work connects to the standard, and leadership gets an honest picture of system health rather than a summary prepared for a customer visit.

What an Internal Audit Examines

Audits are sometimes described as a single activity, but they cover several distinct areas. The table below sets out what an internal quality audit typically reviews and what each review is intended to establish.

Notice that only part of the table is about finding problems. Assessing control effectiveness and verifying adherence to quality goals are equally about confirming that the system works, which is information worth having when you need to defend a process decision.

Internal Audits and Third-Party Audits

The distinction is straightforward once the terminology is clear. A first-party audit is conducted by the organization on its own systems, processes, and quality management system. A third-party audit comes from outside the organization, which is why preparation matters so much. Internal audits are the rehearsal that makes the external review predictable.

Organizations that run a formal internal audit function also need to consider how the audit activity itself is evaluated. A Quality Assurance and Improvement Program enables an evaluation of the internal audit activity's conformance with the Definition of Internal Auditing. In practice, this means the audit program is subject to its own quality expectations, not exempt from them. Teams should confirm the specific requirements that apply to their organization directly with the relevant standard or oversight body.

How to Run an Internal Quality Audit Effectively

Effective audits follow a repeatable sequence. The steps below work for a single audit and for a rolling program across multiple sites, departments, or projects.

Define the scope and the reference standard

Before scheduling anything, write down what is being audited and against what. A scope might cover one process, one department, one project, or the entire quality management system. The reference standard might be ISO 9001 , a customer specification, an internal procedure set, or a combination. Ambiguity here is the most common reason an audit produces arguments instead of findings, because participants arrive with different ideas about what is being assessed.

Build the audit schedule into normal operations

Audits that happen only when a third-party visit is announced tend to be rushed and defensive. Treat the schedule as part of routine operations, spaced so that each area is reviewed with enough frequency to stay current. An audit performed at any time should feel like normal business, because it can be performed at any time.

Prepare the audit team and the evidence trail

Assign auditors who understand the process being examined and who can read the standard against which it is judged. Prepare the working documents in advance: the audit plan, the questions or checklist derived from the standard, and the list of records you expect to sample. Telling the auditee which records will be requested, without telling them which answers to give, shortens the audit and reduces friction.

Conduct the audit and collect objective evidence

An audit is an examination, so every conclusion needs evidence behind it. Walk the process, observe the work, interview the people who perform it, and sample records against the requirements. Record what you see and hear rather than what you assume. Where a practice diverges from the procedure, capture the specific record, date, or observation so the finding can be verified later.

Report findings and close out corrective actions

Write findings that describe the condition, the requirement, and the evidence, without editorializing about individuals. Distinguish between nonconformities that need corrective action and observations that suggest improvement. Then track each corrective action to completion and verify that it actually worked. A closed action that was never verified is not a closed action. This closeout discipline is what turns an audit into continuous improvement rather than a paperwork exercise.

Common Pitfalls in Internal Audit Programs

Most weak audit programs fail in recognizable ways. Treating the audit as a scramble rather than a scheduled activity is one. Checking conformity only, and ignoring the improvement opportunities the audit surfaces, is another. Raising findings without a disciplined corrective action process leaves the same issues to be found again next cycle. Skipping the verification step lets fixes drift. And leaving the internal audit function itself unevaluated means the program never improves at the same rate as the systems it reviews.

Each of these problems is fixable with structure: a schedule, a defined scope, evidence discipline, and a closeout process that ends in verification.

When to Bring In Independent Support

Some organizations need outside help to get the program off the ground. Jags Assurance works with industrial project owners, EPC and EPCM programs, and regulated manufacturers across North America on quality management system design, implementation, and audit readiness, including ISO 9001 certification preparation . Where internal audit findings touch fabrication, welding, or inspection activities, independent verification from a qualified team can confirm that corrective actions address the real condition. Confirm the specific requirements that apply to your operation with the relevant standard body before finalizing your audit program.

Frequently asked

Questions we get on this topic

What is the difference between an internal audit and a third-party audit?

An internal audit, also called a first-party audit, is conducted by the organization on its own systems, processes, and quality management system. A third-party audit is performed by an outside body. The internal version gives you control over timing, so problems can be identified, corrected, and verified before an external reviewer sees the system.

What does an internal quality audit actually examine?

It reviews the organization's systems, processes, and practices to confirm they meet set quality standards. It also assesses how effective internal controls are, verifies adherence to quality goals, evaluates risk management processes, and identifies areas where the system can be improved. Findings can confirm strong performance as well as flag nonconformities.

Do internal audits only apply to ISO 9001?

No. ISO 9001 is one common reference standard, but the audit measures the system against whatever standard, specification, or internal requirement the organization has adopted. Regulated sectors add their own expectations. In pharmaceutical manufacturing, for example, internal audits are expected to add value to the pharmaceutical quality system, protect patients, and drive continuous improvement.

How do internal audits prepare an organization for external review?

They let you evaluate operations, internal controls, and risk management processes on your own schedule, at any time, so the organization is prepared for any third-party audit. Internal findings can be worked through corrective action before an external auditor arrives, which reduces the volume of surprises and gives the team practice with the evidence and interview process.

Get in touch

Need independent quality assurance on your project?

Talk to our team about inspection, auditing and QMS support.

Contact Jags Assurance