Team conducting an internal audit

Internal audits: An overview of the process, objectives and preparation

Internal audits are an essential part of effective management systems. They help your company review processes systematically, identify deviations at an early stage and initiate improvements. But how does an internal audit work, who is allowed to conduct it and what matters when preparing for one? This article provides a clear overview of the fundamentals.

17.09.2026

8-minute read

An internal audit examines your own management system and serves as a tool for continuous improvement. It shows whether you implement requirements in daily operations, where risks lie and which measures make sense. To deliver this value, an audit needs clear goals, relevant audit questions, objective assessments and consistent follow-up on results across the company.

What is an internal audit?

An internal audit (also known as a 1st Party Audit) is a systematic, independent, objective and documented self-assessment of your management system conducted by the organisation’s own employees. Based on clearly defined criteria, you assess whether your company or organisation meets the audit criteria and prepare for external certification audits. This enables you to identify risks and weaknesses at an early stage and initiate improvement measures.

Internal audits vs. external audits – the difference

Internal auditExternal audit
Who carries it out?Own employees or people commissioned by themIndependent certification body or business partner (second-/third-party)
GoalSelf-assessment, continuous improvement, preparation for external certificationOfficial certification decision or assessment by business partner
FrequencyBased on the audit programme, usually several times a yearUsually annually (surveillance audit) or every 3 years (recertification)
Special featureAuditors may also provide advicePurely evaluative, independent assessment without advice
ResultInternal audit report, corrective actionsCertificate, refusal or withdrawal of certification

Why internal audits are important

Internal audits show whether your management system works in practice and achieves its objectives in day-to-day operations. Internal auditors assess whether your company meets its requirements and the relevant standard requirements. Deviations, risks and the need for action become visible. This enables you to address improvement potential at an early stage and initiate improvement measures.

Regular internal audits encourage your company to question and optimise its processes, procedures and results. This drives your continuous improvement process and strengthens your company’s risk management.

Are internal audits mandatory?

There is no general legal obligation to conduct internal audits. However, internal audits arepart of the standard requirements for certified management systems, such as ISO 9001 and 27001.

What this means for you: Internal audits are mandatory for your company if you are certified or seeking certification under a certified management system, such as ISO 9001 for quality management or ISO 27001 for information security. The ISO 9001 standard itself requires internal audits to be conducted regularly. Your company must therefore use an internal audit in accordance with ISO 9001 to assess the conformity of its quality management system. According to the results of the ISO Survey 2024, around 45,000 ISO 9001 certificates have been issued in Germany. These certified companies must therefore conduct internal audits regularly.

Internal audits are also mandatory in some regulated industries. These include companies in the financial, pharmaceutical and healthcare sectors. In healthcare, for example, contracted physicians, contracted dentists, hospitals and rehabilitation clinics are required to conduct regular internal audits.

Without certification or the relevant sector-specific requirements, an internal audit is voluntary but recommended. Even without an obligation, your company benefits from identifying improvement potential at an early stage.

The internal audit process – step by step

Your internal audit should follow a clear structure – for example, along these seven steps:

1. Define the audit programme

In the first step, you define the audit programme. This determines how many audits you carry out and specifies scope, areas and timing. In other words, the audit programme is your company’s audit planning for a defined period, approved by your top management.

  • In the audit programme, you define specifically: the number and scope of audits over the period, the roles of those responsible, the organisational units to be audited, the location and timing of the audits, and the prioritisation by risk.
  • Make sure to continuously monitor, evaluate and, where necessary, improve your audit programme. It is also important to align it with your prioritised company goals, not just with standard chapters.

2. Create the audit plan

In the second step, you create a specific audit plan for the individual internal audit. This is usually the responsibility of the internal auditor, who coordinates with the affected departments and process owners.

  • In this step, you define the affected process owners, the auditor involved, the duration and location of the audit, and a clear audit objective.
  • Make sure to schedule fixed dates and clearly name the audit criteria, so the audit remains traceable.

3. Prepare the audit

In the next step, you prepare the content of the audit. You can conduct interviews with employees to gain a better understanding of processes. The internal audit department gathers information, and the auditor creates an audit checklist or question catalogue based on the audit criteria.

  • Here you gather documents and define an audit checklist based on the audit criteria. If necessary, you also conduct and document interviews with employees.
  • Make sure the question catalogue includes cross-cutting questions if several management systems are involved.

4. Conduct the audit

The actual audit starts with an opening meeting, where you clarify the process and the participants introduce themselves. The review then takes place in audit blocks, in which you identify conformity and nonconformity. Finally, the auditor holds a closing meeting.

  • In this step, you document specific conformities and nonconformities and record deviations. You also draw a final conclusion during the closing meeting.
  • Make sure to ask questions as openly as possible and to ask for evidence rather than opinions during the review.

5. Document findings

The auditor records all observations in a structured way. For each finding, they note how severe it is. In practice, auditors use four levels for this: a major nonconformity refers to a critical deviation that you must correct immediately. A minor nonconformity is a small deviation without acute consequences. An observation or improvement suggestion highlights a potential you can use. A positive finding records a strength you should maintain. This way, you sort your findings clearly by severity and immediately see where to act first.

  • For each finding, you document the location, date and evidence, as well as the classification by severity.
  • Make sure to clearly separate facts from evaluation.

6. Prepare the audit report

Following the audit, the auditor prepares a summary audit report and distributes it to the relevant recipients.

  • The audit report includes the audit objective, the audit scope, the audit criteria, the documented findings, the conclusions and, where applicable, improvement recommendations.
  • In the audit report, make sure the conclusions and context are easy to understand, so it can serve as a basis for decisions. A clear structure makes it easier for your company’s management to derive prioritised measures.

7. Track corrective actions

Based on the identified deviations, the audited area derives corrective actions, implements them and reviews their effectiveness.

  • You define specific improvement measures, assign responsibilities and set deadlines for implementation. You also determine a follow-up date for the next audit.
  • Make sure an audit doesn’t end with the report: one of the most common mistakes in internal audits is the lack of follow-through. Also make sure to feed the insights gained into the next audit programme.

Who conducts internal audits? The role of the internal auditor

An internal audit is conducted by an internal auditor, meaning someone from within the company. To ensure meaningful results, this person must be independent of the area being audited, professionally competent, and a strong communicator. For example, the responsibility should not rest solely with the quality management representative if their own process is being audited.

A key difference between external and internal auditors is that internal auditors are also allowed – and encouraged – to provide advice. This way, they not only uncover errors but also foster a culture of continuous improvement within the company.

What qualifications does an internal auditor need?

For an internal audit to deliver reliable results, an internal auditor must have several important qualifications. These include extensive expertise in the audited processes and standards, as well as the ability to interpret complex data. An internal auditor should also have an objective perspective and strong critical thinking skills to avoid making premature assessments of findings. In addition, excellent communication skills are essential, and formal proof of training is recommended to ensure that results can be communicated clearly.

The specific requirements and areas of expertise that internal auditors need to address can vary considerably. For example, anyone conducting information security audits in accordance with ISO 27001 needs not only general auditor competencies but also specific knowledge of this subject area.

However, technological tools are increasingly supporting your day-to-day audit work. You can use artificial intelligence to support automated document review, pattern recognition or report generation. This gives you, as an auditor, more room to focus on the actual assessment and on deriving improvement measures.

Types of internal audits (system, process and product audits)

Your internal audits can have different areas of focus. The type of audit depends on whether you are assessing your entire management system, an individual process or a specific product. The main types of internal audits are system audits, process audits and product audits.

A system audit examines your entire management system or a clearly defined part of it. The internal auditor assesses whether structures, responsibilities and processes are suitable and effectively implemented within your organisation.

A process audit focuses on a specific process, such as procurement or production. During the internal audit, you assess whether the process is working as intended, responsibilities are clearly defined and the desired results are being achieved.

In a product audit, the internal auditor examines an individual product, a single assembly or a specific service. The audit assesses whether defined requirements, specifications and quality characteristics are being met.

Depending on the focus, internal audits can also cover specific topics such as occupational health and safety. In this context, for example, an ISO 45001 audit can be conducted.

Conduct strategy-oriented audits – align audit objectives with business goals

An internal audit shouldn’t only answer the question of whether you meet individual standard requirements. What matters is whether your audited processes support your company’s strategic goals. To this end, you align the audit scope and depth with current priorities, risks and previous audit results.

If your company places a particular focus on improving on-time delivery, you can specifically examine the procurement or production process. In this case, you check not only whether your workflows are documented, but also whether they actually contribute to reliable delivery. This allows you to audit processes with high strategic importance or identifiable weaknesses more intensively or more frequently.

Typical mistakes in internal audits – and how to avoid them

Your internal audits only deliver the expected value if you plan them carefully and follow up on them consistently. In practice, however, things often look different. Typical pitfalls include:

  • Missing or inadequate audit programme: A structured audit programme takes the audit scope, frequency, risks, business goals and previous results into account.
  • Insufficient auditor competence: Your internal auditors must be professionally qualified and assess the audited area as objectively as possible.
  • Audit frequency that is too low: Critical or changing processes should be audited regularly, depending on their level of risk.
  • Lack of follow-through on deviations: For each relevant finding, you should define corrective actions, responsibilities and deadlines.
  • Insufficient documentation: Audit evidence must clearly record what was audited, which evidence was available and how the finding is substantiated.
  • Audits without a clear strategic objective: Without a specific objective, there is a risk that the audit will become nothing more than working through standard clauses.
  • Simply ticking off the checklist: A list of questions provides guidance, but it does not replace active listening, asking follow-up questions and reviewing evidence.

Question set for internal audits

A question set for internal audits can provide guidance and ensure that you address important topics systematically. The questions should be aligned with the objectives of your audit and process, phrased openly and always target specific evidence. You can include general questions as well as standard- or process-specific questions in your question set.

This general question set can support you during the internal audit:

  • “How do you ensure that the process is carried out in accordance with the applicable requirements?”
  • “Please show me the evidence for the implementation of this process step.”
  • “Who is responsible for this process, and how are the employees involved qualified?”
  • “What risks can arise in this process, and how are they monitored?”
  • “What do you do when you identify a deviation?”
  • “How do you verify that the corrective actions taken are effective?”
  • “What improvements have been implemented based on previous audit results?”

A standard-specific question about ISO 45001 could be:

  • “How do you identify and assess hazards to occupational health and safety, and how do you ensure that appropriate measures are derived and implemented?”

A standard-specific question about ISO 50001 could be:

  • “How do you identify and monitor your significant energy uses and energy performance indicators, and how do you use the results to improve energy-related performance?”

It’s important that internal auditors don’t use the question catalogue as a rigid script, but instead listen closely to answers, ask follow-up questions where things are unclear, and directly review the evidence mentioned.

Internal audits across multiple standards

If your company operates several management systems, you do not necessarily need to conduct a separate audit for each standard. An integrated audit allows you to assess common requirements from different standards in a single audit. Audits can be combined, particularly when there are content-related interfaces between standard clauses, for example between ISO 9001 and ISO 14001. This saves you time and avoids duplicate interviews.

For your integrated audit to still deliver meaningful results, you should align the audit scope, question catalogue and expertise with all included standards. You must also clearly assign findings to the relevant standard or the shared process.

Conclusion

Internal audits are more than a formal assessment. They show your company whether your processes are working effectively, whether requirements are being met and where specific opportunities for improvement remain untapped. Effective preparation, independent auditors, clear audit objectives and consistent follow-up on findings are essential. If you also align your audits with your business goals and take an integrated approach across multiple ISO standards, you can continuously and effectively develop your management system.

ISO check: how does ISO finally become a routine?

Do you work with ISO standards such as 9001, 14001, 27001, 45001 or 50001? In this personalised consultation, our leadity experts will show you how to save time, close gaps and navigate your day-to-day ISO work with greater confidence.

  • Save valuable time – during audit preparation and in your day-to-day work
  • Identify data gaps early – and close them quickly with audit-ready documentation
  • Make ISO processes part of your routine – because ISO chaos is not inevitable

You enjoyed reading our article?

Share it with your network via LinkedIn, email or WhatsApp!

More expert articles from our magazine

ISO 14001 – Definition, requirements and certification

ISO 14001 helps organisations manage environmental aspects systematically, reduce environmental impacts and continuously improve their environmental performance. Learn about the requirements of the standard, the benefits of certification and how to implement environmental management in a structured way – including with software.

Mehr erfahren

FAQs on internal audits

Questions and answers about internal audits

If you have any open questions about internal audits in leadity, please feel free to email them to us at kontakt@leadity.de

What is the difference between an internal and an external audit?
Are internal audits legally required?
How often must an internal audit be carried out?
Who is allowed to carry out an internal audit?
What happens if deviations are found in the internal audit?