Skip to content
AuditingPublished Aug 11, 2026 · 9 min read

ISO 9001 internal audit checklist, clause by clause

A usable ISO 9001 internal audit checklist is not a copy of the standard with question marks added. It pairs each clause with the question you actually ask, the objective evidence you sample, and the acceptance test that decides whether it is a finding.

Share
Executive summary

This checklist covers ISO 9001:2015 clauses 4 through 10. For each clause it gives the audit question, the records to sample, and the failure pattern that most often turns into a nonconformity at surveillance.

Use it as the backbone of a process-based audit: walk the process, sample the evidence, then map what you saw back to the clause — not the other way round.

Key takeaways
  • 01Audit processes, not clauses — then map the evidence back to clauses 4–10.
  • 02Every checklist line needs a named record, not a yes/no box.
  • 03Sample size and traceability decide whether a finding survives challenge.
  • 04Clause 9.2 requires auditor independence from the area audited.
At a glance

How to use this checklist

An ISO 9001 internal audit checklist is a working document that lists, for each clause of ISO 9001:2015, the question the auditor asks, the objective evidence that answers it, and the acceptance criteria that separate an observation from a nonconformity. Build the audit around your processes — sales, design, purchasing, production, calibration, complaint handling — and use the clause table below to confirm coverage before you close the audit.

  1. Pick the process and its owner; confirm scope, shift and site.
  2. Read last cycle's findings and open CAPAs for that process first.
  3. Walk the process end to end and sample records as you go.
  4. Trace one job or order fully — order to delivery — through every record.
  5. Record objective evidence: document number, date, batch, name.
  6. Grade each finding: major, minor or opportunity for improvement.
  7. Map coverage against clauses 4–10 before you write the report.
The checklist

Clauses 4 to 10 — question, evidence, common finding

Copy these rows into your own checklist template and add process-specific lines underneath each clause.

ISO 9001:2015 clauses 4 to 10. Clause 7.1.5 (monitoring and measuring resources) and 8.5.1 (control of production) usually need extra process-specific lines.
ClauseAudit questionObjective evidence to sampleCommon finding
4.1 / 4.2 Context and interested partiesHow were internal and external issues and interested-party requirements determined, and when were they last reviewed?Context register, SWOT or PESTLE record, management review minutes.Written once at certification and never revisited.
4.3 / 4.4 Scope and QMS processesIs the documented scope accurate, and are process interactions defined with inputs, outputs and measures?Scope statement, process map, turtle diagrams, KPI definitions.Scope excludes a clause with no justification.
5.1 / 5.2 Leadership and policyHow does top management demonstrate commitment, and is the quality policy communicated and understood?Policy issue record, communication evidence, interviews at shop-floor level.Staff cannot relate the policy to their own work.
5.3 Roles and authoritiesAre QMS responsibilities and authorities assigned and known?Org chart, job descriptions, delegation records.Authority to stop work is undefined.
6.1 Risks and opportunitiesWhat actions were planned to address risks and opportunities, and were they effective?Risk register with actions, effectiveness review, links to objectives.Risk register with no actions or no evaluation.
6.2 Quality objectivesAre objectives measurable, resourced, monitored and aligned to the policy?Objectives sheet, KPI trend data, action plans with owners and dates.Objectives with no plan, no owner or no measurement.
6.3 Change planningHow are QMS changes planned and controlled?Change requests, impact assessments, resource decisions.Changes made informally with no impact assessment.
7.1 ResourcesAre infrastructure, environment and monitoring equipment adequate and maintained?Maintenance plans, calibration register, certificates traceable to national standards.Equipment in use past its calibration due date.
7.2 / 7.3 Competence and awarenessHow is competence determined, achieved and evaluated?Competence matrix, training records, qualification certificates, effectiveness checks.Training attendance recorded but effectiveness never evaluated.
7.4 CommunicationWhat is communicated about the QMS, to whom, when and by whom?Communication plan, toolbox talks, notice boards, briefing records.No defined plan; communication is ad hoc.
7.5 Documented informationAre documents controlled, current at point of use, and are records legible, retrievable and retained?Master document list, revision status at point of use, retention schedule.Superseded work instructions still in use on the line.
8.1 Operational planning and controlAre process criteria, resources and control of outsourced processes defined?Production plans, control plans, work instructions, outsourcing agreements.Outsourced processes not controlled or defined in the QMS.
8.2 Customer requirementsHow are requirements determined, reviewed before commitment and changes communicated?Contract review records, order acknowledgements, amendment trail.Verbal order changes accepted without documented review.
8.3 Design and developmentAre design inputs, controls, outputs, reviews, verification, validation and changes documented?Design plan, review minutes, verification and validation reports, change log.Verification and validation used interchangeably.
8.4 External providersHow are suppliers evaluated, selected, monitored and re-evaluated, and how is purchased product verified?Approved supplier list, evaluation criteria, performance scorecards, incoming inspection records.Approved supplier list with no re-evaluation evidence.
8.5 Production and service provisionAre identification, traceability, customer property, preservation and post-delivery activities controlled?Batch and job travellers, traceability records, storage and handling controls.Traceability breaks between goods-in and finished stock.
8.6 Release of products and servicesIs there evidence of conformity and authorised release for every delivery?Inspection and test records, release signatures, certificates of conformity.Product released before test results returned.
8.7 Nonconforming outputIs nonconforming output identified, controlled, dispositioned and recorded?NCR log, concession or deviation approvals, segregation and quarantine evidence.Rework performed with no NCR raised.
9.1 Monitoring, measurement, analysisWhat is measured, how is the data analysed, and what did it change?KPI dashboards, customer satisfaction data, trend analysis, resulting actions.Data collected and reported but never acted on.
9.2 Internal auditIs the audit programme risk-based, complete, independent and reported to management?Audit programme, auditor competence records, reports, finding closure log.Auditors auditing their own process; programme behind schedule.
9.3 Management reviewDoes the review cover every required input and produce decisions with owners and dates?Review agenda, minutes, action register against clause 9.3.2 inputs.One or more required inputs missing from the minutes.
10.2 Nonconformity and corrective actionIs root cause established, action taken, effectiveness verified and similar risks reviewed?CAPA register, root-cause analysis, effectiveness verification, extension to similar processes.Correction recorded as corrective action; no root cause.
10.3 Continual improvementWhat improvements were made from audit, data and review outputs?Improvement log, before/after performance data, closed actions.Improvement claimed with no measured result.
Evidence

What counts as objective evidence

A finding survives challenge when the evidence is specific: the document number and revision, the date, the batch or job number, the equipment ID, the name of the person interviewed. "Training records were incomplete" is arguable. "Competence matrix rev 4 lists no qualification for operator badge 214, who ran the CNC cell on 14 July" is not.

01

Strong evidence

A named record, uniquely identified, dated, and traceable to the process step it controls.

02

Weak evidence

A verbal assurance, a screenshot with no identifier, or a sample of one where variation matters.

03

Sample properly

Sample across shifts, lines, sites and time periods — not just the batch the process owner selected for you.

04

Trace one job fully

Following a single order from enquiry to delivery exposes gaps that clause-by-clause questioning never reaches.

Writing it up

Grading and wording the finding

  • Major: the requirement is absent, the system has broken down, or the failure puts product conformity or certification at risk.
  • Minor: a single lapse against a requirement that is otherwise implemented and effective.
  • Opportunity for improvement: conformant, but a weakness that will become a finding if left.
  • Write every finding in three parts — the requirement, the objective evidence, and the gap between them. Never write the corrective action for the auditee.
Programme level

From checklist to audit programme

A checklist audits a process. A programme audits the system: every process, site and clause on a risk-based cycle, with competent auditors independent of the area audited, reported into management review and tracked to verified closure. If your cycle keeps slipping or the same auditors keep auditing their own functions, the checklist is not the constraint — the programme design is.

Frequently asked

Questions we get on this topic

What should an ISO 9001 internal audit checklist include?

For each clause of ISO 9001:2015 it should include the audit question, the objective evidence to sample, the acceptance criteria, space for the record identifier and date, and the finding grade. A checklist that only offers yes/no boxes produces audits that cannot be defended at surveillance.

Which ISO 9001 clauses must an internal audit cover?

Clauses 4 to 10 in full over the audit cycle: context, leadership, planning, support, operation, performance evaluation and improvement. A single audit rarely covers all of them — the programme, not the individual audit, must demonstrate complete coverage across the cycle.

How often are ISO 9001 internal audits required?

ISO 9001 clause 9.2 does not set a frequency; it requires audits at planned intervals determined by risk, process importance, changes and previous results. In practice most organisations audit every process at least annually, with higher-risk or underperforming processes audited more often.

Can an internal auditor audit their own department?

No. Clause 9.2.2 requires the audit programme to ensure objectivity and impartiality, which means auditors must be independent of the activity being audited. Smaller organisations usually solve this by cross-auditing between departments or by co-sourcing qualified external lead auditors.

What is the difference between an internal audit and a certification audit?

An internal audit is a first-party audit you perform on your own management system to find and fix problems. A certification audit is a third-party audit by an accredited certification body to decide whether to grant or maintain your certificate. Certification bodies sample your internal audit records as evidence that the system is being maintained.

Get in touch

Want the audit programme run for you?

Our qualified lead auditors deliver outsourced and co-sourced ISO 9001 internal audit programmes across North America — independent, risk-based and closed to verified effectiveness.

Talk to a Lead Auditor