Skip to product information
1 of 2

"ISOG have continually under-promised and over-delivered. Outstanding service." Paul J, ATM Security

Internal audit checklist

Internal audit checklist

$49

Find your own gaps first, on your own terms, long before an outside assessor ever sees them.

Director-built, not auditor-built
Director-built, not auditor-built
Plain English, no jargon
Plain English, no jargon
Instant download, yours to keep
Instant download, yours to keep

The scariest part of certification is the fear of being caught out. Of an assessor asking a question you had not thought about, and watching you realise, in the moment, that there is a hole in your system.

Here is the thing almost nobody tells you. You can ask yourself every one of those questions first, in private, with all the time in the world to put things right.

That is what an internal audit is, and this checklist is how you do it. You work through the standard clause by clause and, for each point, ask one honest question: can I actually show this is happening? Where you can, you note where the proof lives. Where you cannot, you have just found something worth fixing, quietly, before it ever costs you.

Who this is for

This is for any small or medium sized business with an ISO 9001 quality management system that needs to run its own internal audits, either to prepare for certification or to keep the system honest between assessments. If you want to find your weak spots before an assessor does, this is built for exactly that.

View full details

This is F-1018-7, the ISO 9001 internal audit checklist for your QMS: a ready-to-use form written in plain English and prepared to the requirements of the standard.

It gives you a clause-by-clause grid covering the auditable requirements of ISO 9001, from clause 4 through to clause 10, with space against each point to record your findings and, crucially, the evidence behind them. It includes a simple grading legend, so you can mark each finding as an opportunity for improvement, a minor nonconformance or a major one, exactly as a real auditor would. You tick the clauses you are auditing this time, work through just those, and over a year you cover the whole system in manageable pieces.

Note: this checklist is designed to be used alongside an internal audit procedure (SOP-1018), an audit schedule (F-1018-1) and a corrective action request form (F-1023-1). Those companion documents are not part of this purchase; they come together in the complete system, The ISO 9001 Certification-Ready System. The checklist itself is complete and ready to use on its own.

It turns the fear of an audit into a to-do list

The dread before an assessment comes from not knowing what they will find. This checklist removes that, because you find it first. Every honest answer you cannot back with evidence becomes a simple, private to-do item, fixed on your own terms and your own timescale, so that by the time a real assessor arrives there are no surprises left for them to find.

Built to be used in bite-sized pieces

You do not run the whole thing every time. You tick the clauses you are auditing, work through just those, and over the year you cover the entire system without it ever becoming a huge task. The checklist is laid out so more than one person can each take a section and bring their parts together at the end, which suits a small team perfectly.

It grades findings the way a real auditor does

The built-in legend lets you mark each finding as an opportunity for improvement, a minor nonconformance or a major one, with plain definitions of each. That means you are not just spotting problems, you are learning to judge how serious they are, which is exactly the skill that makes the real assessment feel familiar rather than frightening.

See the Operator's Take before you buy

Every ISO Guidance document contains a boxed note called The Operator's Take: plain advice from someone who ran real businesses first, then trained as a Lead Auditor. Here is the one from this checklist, word for word.

"The real value is not in the ticks, it is in the evidence column. An honest audit is you sitting down and asking, for each point, can I actually show this is happening. Where you can, note where the proof lives. Where you cannot, you have just found something worth fixing, on your own terms, long before an outside assessor ever sees it. That is the whole game: find your own gaps first."

That is the difference between a document written by an operator who audits, and one written by an auditor who has never run a business. It is why you end up with a system that actually improves how the business runs, not just one that passes an audit. Fewer mistakes reach your customers, your people spend less time redoing work that went wrong, and the daily friction that wears everyone down quietly drops away. That is what you are really buying: certification you can earn, and a calmer business on the way to it.

New to internal audits? Read the full guide to ISO 9001 audit checklists first.

A note on where this fits

This is one core document, and it is genuinely useful on its own. A complete, certifiable quality management system is more than any single document: it needs the full set, including the quality manual and the system-level documents. If you decide to go all the way, The ISO 9001 Certification-Ready System brings the whole thing together. This is a sensible step, not the finish line.

Why buy from us

  • Built by a company director, not an auditor. Written by someone who ran real businesses before building management systems, so what you get works in the real world, not just on paper.
  • Written in plain English. No jargon, no clause-speak. If you are new to ISO 9001, it will make sense on day one.
  • The Operator's Take, in every document. Look inside any ISO Guidance document and you will find a boxed note called The Operator's Take: a short, plain comment from someone who has run businesses, explaining why this document actually matters to yours, and how to get real value from it, not just tick a box for an auditor. No other provider gives you this, because it comes from having sat in the chair.
  • Honest, unaccredited, and clear about it. A genuine route to a working system, with no false claims and nothing hidden.

Frequently asked questions

What is an ISO 9001 internal audit checklist?

An ISO 9001 internal audit checklist is a clause-by-clause list of the standard's requirements that you use to check your own quality management system and record whether each one is met. For every point you note your finding and the evidence behind it, which turns a vague sense of readiness into a clear picture of where you stand. It is the main working tool of an internal audit, used both to prepare for certification and to keep the system healthy between assessments.

How do you conduct an ISO 9001 internal audit?

You conduct an internal audit by working through each area of the standard and honestly gathering evidence that your system does what it says. Plan which clauses you are auditing this time, then for each requirement look for real proof rather than assuming it exists, talking to the people who do the work as well as reading the documents. Record what you find, grade how serious any gaps are, raise corrective actions for them, and follow those through to completion. Finding issues is the point, because fixing them before the external assessment is exactly what an internal audit is for.

What should an internal audit checklist include?

An internal audit checklist should include every auditable clause of ISO 9001, from clause 4 on context through to clause 10 on improvement, with space to record findings and the evidence for each. It should let you note conformance, opportunities for improvement, and minor and major nonconformances, so you can judge how serious each finding is. This checklist includes all of that, laid out as a grid you can tick clause by clause, with a grading legend built in.

How often should internal audits be carried out?

Internal audits should be carried out at planned intervals, which for most small and medium sized businesses means covering the whole system at least once a year. Rather than auditing everything in one sitting, many businesses audit a few clauses at a time across the year, which is less disruptive and keeps attention on the system continuously. What matters to an assessor is that the audits are planned, that they genuinely happen, and that the findings are acted on.

What is the difference between a minor and major nonconformance?

A minor nonconformance is a single lapse that is unlikely to cause the system to fail, while a major nonconformance is a serious gap that undermines the system's ability to deliver conforming products or services. A minor might be one missing record or an isolated slip; a major might be a required process that is absent altogether or has broken down. The distinction matters because it tells you how urgently to act, and this checklist includes plain definitions so you can grade your own findings correctly.

Do you need internal audits for ISO 9001 certification?

Yes, internal audits are a requirement of ISO 9001, set out in clause 9.2, and you cannot be certified without them. The standard requires you to audit your own system at planned intervals to check it conforms and is properly maintained. Beyond being mandatory, they are the single most effective way to find and fix problems before the external assessment, which is why running honest internal audits is the best preparation for certification there is.

Written by Mike Armstrong, founder of ISO Guidance. Mike ran companies at director level before building management systems, so the systems ISO Guidance writes are built to work in the real world, not just on paper. ISO Guidance helps small and medium sized businesses get ISO certified without a consultant.