3.5 Internal Audits as an Improvement Technique
Key Takeaways
- The CQIA Body of Knowledge lists internal audits under Improvement Techniques, not under standards compliance — the exam expects you to treat an audit as a source of improvement opportunities.
- First-party audits are internal, second-party audits are performed on or by a customer or supplier, and third-party audits are performed by an independent registrar for certification.
- ISO 9001:2015 Clause 9.2 requires internal audits at planned intervals, with auditor selection ensuring objectivity and impartiality; auditors must not audit their own work.
- An audit finding must be supported by objective evidence traceable to a stated requirement; an auditor reports the nonconformity and never prescribes the corrective action.
- Audit findings are graded as major nonconformity, minor nonconformity, observation, or opportunity for improvement, and the audit closes only when corrective action effectiveness is verified.
3.5 Internal Audits as an Improvement Technique
Where the CQIA Body of Knowledge places a topic tells you how it will be tested. Internal audits appear as entry III.B.5, inside Improvement Techniques, alongside brainstorming, PDCA, affinity diagrams, and cost of poor quality. ASQ is signalling that the audit is not primarily a compliance ritual — it is a structured method for discovering improvement opportunities. Expect scenario items that ask what an auditor should do, not items that ask you to recite clause numbers.
1. The Three Audit Parties
Candidates lose points by confusing these three, and the distinction is purely about who performs the audit relative to whom is audited.
| Party | Who audits | Who is audited | Purpose |
|---|---|---|---|
| First-party (internal) | The organization audits itself, using its own trained personnel | Itself | Self-assessment; find and fix problems before anyone else does |
| Second-party | A customer audits a supplier (or an organization audits its own supplier) | A trading partner | Verify a supplier can meet contractual requirements |
| Third-party | An independent registrar or certification body | The organization | Award or maintain certification, such as to ISO 9001 |
Internal audit is first-party. A supplier audit you conduct at your vendor's plant is second-party. A registrar's surveillance visit is third-party. Only the first of these belongs to BoK entry III.B.5.
2. Audit Classification by Subject
Independently of the party, audits are classified by what they examine:
- System audit — evaluates the whole management system against a standard such as ISO 9001. Broadest scope.
- Process audit — evaluates one process against its defined method: are the inputs, controls, settings, and outputs as specified?
- Product audit — evaluates a finished item against its specification, effectively re-inspecting a product already accepted.
Scope narrows from system to process to product; sampling depth increases in the same direction.
3. What ISO 9001:2015 Clause 9.2 Requires
Clause 9.2 is short and testable. Internal audits must be conducted at planned intervals to determine whether the management system conforms both to the organization's own requirements and to the standard, and whether it is effectively implemented and maintained. The organization must:
- Plan, establish, implement and maintain an audit programme, including frequency, methods, responsibilities, planning requirements, and reporting — and the programme must take into account the importance of the processes concerned, changes affecting the organization, and the results of previous audits. Risk drives audit frequency; a troubled process is audited more often than a stable one.
- Define the audit criteria and scope for each audit.
- Select auditors and conduct audits so as to ensure objectivity and the impartiality of the audit process. This is the source of the rule that auditors must not audit their own work.
- Ensure results are reported to relevant management.
- Take appropriate correction and corrective action without undue delay.
- Retain documented information as evidence of the programme's implementation and the audit results.
ISO 19011 provides the guidance on how to actually audit management systems — auditor competence, the audit process, and programme management. ISO 9001 says audits must happen; ISO 19011 describes how to do them well.
4. The Audit Lifecycle
PROGRAMME PLANNING -> AUDIT PLAN -> OPENING MEETING -> EVIDENCE GATHERING
^ |
| v
FOLLOW-UP / VERIFY <- CORRECTIVE ACTION <- REPORT <- CLOSING MEETING
- Programme planning. Set the annual schedule using process importance, change, and prior results.
- Audit plan and preparation. Define scope, criteria, and dates; assign an independent audit team; build the checklist from the actual requirements.
- Opening meeting. Confirm scope, schedule, method, and how findings will be communicated.
- Evidence gathering. Interview, observe the work, and examine records. Follow the process approach: trace a real transaction end to end rather than reading procedures in a conference room.
- Closing meeting. Present findings to the auditee so there are no surprises in the report.
- Report. Document each finding with the requirement, the evidence, and the nonconformity statement.
- Corrective action. The auditee analyzes root cause and determines the action. The auditor does not.
- Follow-up and closure. The audit closes only when the auditor verifies the action was implemented and effective.
5. What Makes a Finding Legitimate
Every audit finding rests on three legs. Remove any one and it is an opinion, not a finding.
| Leg | Question | Example |
|---|---|---|
| Requirement | What rule was breached? | "Work instruction WI-204 requires a torque check every 25 units." |
| Objective evidence | What did you actually see? | "Torque log for line 3 on 14 August shows no entries between units 50 and 175." |
| Nonconformity statement | How does the evidence violate the requirement? | "Torque verification was not performed at the required frequency." |
Objective evidence must be verifiable — records, observed conditions, statements confirmable from more than one source. "Several operators seemed unfamiliar with the procedure" is not objective evidence; "three of four operators interviewed could not locate the current revision of WI-204" is.
Grading Findings
| Grade | Meaning |
|---|---|
| Major nonconformity | Absence or total breakdown of a required element, or a failure likely to result in nonconforming product |
| Minor nonconformity | An isolated lapse in an otherwise implemented system |
| Observation | A single occurrence or a weakness trending toward nonconformity; not yet a breach |
| Opportunity for improvement (OFI) | Conforming, but improvable — the audit's contribution as an improvement technique |
The Independence Rule and the Small-Organization Problem
Auditors must not audit their own work. In a small company where the quality manager wrote every procedure, this is genuinely hard. Accepted solutions are cross-functional auditing — a trained production supervisor audits purchasing and vice versa — or engaging an external contract auditor. What is not acceptable is having the process owner audit their own process and declaring it independent.
6. Why This Is an Improvement Technique
An audit programme that produces only pass/fail conformity verdicts is being underused. Its improvement value comes from the data it generates:
- Pareto the findings by clause and by process to see where the system is systematically weak.
- Track repeat findings. A nonconformity that recurs after a closed corrective action proves the root cause analysis was wrong — usually a containment action mistaken for a corrective action.
- Feed audit results into management review. ISO 9001 requires it, and it converts audit output into resourced action.
- Harvest the OFIs. Auditors see every process in the organization and are uniquely positioned to spot practices that one area does well and others could adopt.
A medical device manufacturer sends two of its own quality engineers to a component vendor's facility to verify that the vendor can meet contract requirements. How should this audit be classified?
During an internal audit, an auditor observes that a required in-process inspection was skipped, then tells the department supervisor to add a second inspector to the line. What is wrong with the auditor's conduct?
An internal audit programme schedules every process for audit exactly once per year, regardless of history. Two processes have generated repeat nonconformities for three consecutive cycles. Which ISO 9001:2015 Clause 9.2 requirement is the programme failing to satisfy?
Which of the following would qualify as objective evidence supporting an audit finding?