Skip to main content
Practice 12 — ISO Internal Audit

Find it before the certification body does.

Every ISO management system standard requires internal audit at planned intervals, and requires the auditor to be impartial. In a small team that is hard to arrange internally, because the people who know the system are the people who built it.

ESGweise provides independent ISO internal audit across ISO 9001, ISO 14001, ISO 45001, ISO 50001, ISO 22301 and ISO 27001 for organisations in the UAE and wider GCC. Audits satisfy the clause 9.2 requirement for planned, impartial internal audit, and are scheduled as a rolling risk-weighted programme rather than a single sweep before the certification visit.

01 Why it is outsourced

The impartiality problem

The standard is explicit that auditors must not audit their own work. That is straightforward in a large organisation with a dedicated audit function and close to impossible in a team of fifteen.

What usually happens instead is that the management representative audits the system they maintain, records that everything conforms, and the certification body finds in two days what a year of internal audit did not. The finding is rarely technical. It is that nobody with an incentive to look actually looked.

02 Standards covered

Single or integrated

  • ISO 9001 quality management
  • ISO 14001 environmental management
  • ISO 45001 occupational health and safety
  • ISO 50001 energy management
  • ISO 22301 business continuity
  • ISO 27001 information security

Where several systems are integrated, the audit is integrated too. Auditing a shared document control process three times against three standards wastes everyone's week and produces three versions of the same finding.

03 How we run it

A programme, not an event

01

Risk-weighted plan

Full scope covered across the certification cycle, with frequency weighted by risk and by where findings have arisen before.

02

Fieldwork against evidence

Records, observation and interview rather than a walk through the manual. A system that reads well and operates differently is the common case.

03

Findings that are actionable

Classified, with the clause cited and the root cause identified, so corrective action addresses the cause rather than the symptom.

04

Closure tracked to evidence

Corrective actions verified as effective, not merely marked complete. Open findings rolling from year to year is the pattern certification bodies look for.

Related: ISO implementation builds the system, certification support takes it through the external audit, and HSE systems covers the safety and environmental side in operational detail.

Frequently asked

ISO Internal Audit — questions we hear most

What is an ISO internal audit?

A planned examination of whether your management system operates as documented and meets the requirements of the standard. Every ISO management system standard requires it, and it is not optional: clause 9.2 in the harmonised structure obliges the organisation to conduct internal audits at planned intervals. It is the organisation checking itself, ahead of and independently from the external certification audit.

Can we use an external firm for internal audit?

Yes, and it is common. The standard requires objectivity and impartiality, which means an auditor cannot audit their own work. In a small team that is difficult to arrange internally, since the people who know the system are the people who built it. Using an external auditor satisfies the impartiality requirement and usually produces a more useful finding set, because there is nothing to protect.

Does an internal audit replace the certification audit?

No. They are separate and serve different purposes. Internal audit is your own assurance that the system works, required by the standard itself. The certification audit is conducted by an accredited certification body and is what results in the certificate. A weak internal audit programme is one of the most common reasons a certification audit produces major findings, because problems that should have surfaced internally arrive in front of the external auditor instead.

How often should internal audits be run?

At planned intervals covering the full scope of the system within the certification cycle, with frequency weighted by risk and by past performance. In practice most organisations run a rolling programme so that every process and site is audited at least once a year, with higher-risk areas visited more often. A single annual sweep just before the external audit meets the letter of the requirement and defeats its purpose.

Engage on this practice

Thirty minutes. We figure out if there's a fit.

We don't pitch on the call. We listen, ask sharp questions, and tell you honestly whether iso internal audit is what you need — or what else might be.

Speak with our team