16.3 Main Activities in an Internal Audit
Key Takeaways
- Internal audit activities follow a managed sequence: initiate, prepare (document review and plan), conduct (opening, evidence collection, findings), report, and complete/follow-up
- Each audit needs defined objectives, scope, and criteria before fieldwork begins
- Evidence must be objective, verifiable, and sufficient relative to the risk and environmental importance of the process
- Findings should be classified consistently (conformity, nonconformity, opportunity for improvement) and reported to relevant management
- Follow-up verifies corrective action effectiveness; closing the loop is part of programme credibility and Clause 10 improvement
16.3 Main Activities in an Internal Audit
Quick Answer: An individual internal EMS audit follows ISO 19011’s conducting-audit guidance: initiate the audit; prepare (including document review and the audit plan); conduct activities to collect evidence and generate findings; prepare and distribute the report; then complete the audit and perform follow-up as required. ISO 14001 Clause 9.2 expects defined criteria/scope, impartial auditors, management reporting, and retained evidence of results.
While Section 16.1 addressed managing the programme, this section focuses on the activities inside one internal audit. Lead Auditors—whether performing first-party work or evaluating a client’s internal audits during certification—must recognize when those activities are complete, competent, and risk-based.
Activity Sequence Overview
| Phase | Main activities | EMS-focused outputs |
|---|---|---|
| Initiate | Confirm feasibility, appoint team leader/team, establish contact | Agreed objectives/scope/criteria; access arrangements |
| Prepare | Document review; risk-based plan and sampling strategy | Audit plan, checklists/work documents, logistics |
| Conduct | Opening meeting; collect/verify evidence; generate findings; closing meeting | Working papers, clear findings with evidence |
| Report | Prepare, approve, distribute audit report | Documented results for management and records |
| Complete & follow-up | Close audit file; verify corrective actions where needed | Updated NC status; input to programme monitoring |
These phases mirror ISO 19011 Clause 6 and should be scaled to audit size—but not skipped. A half-day internal audit of a low-aspect process still needs criteria, a plan (even concise), evidence, and a report.
1. Initiating the Audit
Initiation confirms that the audit can be done: scope is clear, criteria exist, information is available, and cooperation is feasible. For internal EMS audits, objectives often include verifying conformity of specific processes (e.g., operational control of hazardous waste, emergency preparedness, compliance evaluation) and assessing whether controls are effective. Scope defines boundaries—sites, processes, shifts, contractors. Criteria typically include ISO 14001 clauses relevant to the process, EMS documented information, and applicable compliance obligations.
Feasibility issues (records unavailable, key staff on shutdown, unsafe access) should be escalated to the programme manager before forcing a hollow audit.
2. Preparing the Audit Plan and Document Review
Document review examines the environmental policy, aspect/impact registers, compliance obligation lists, operational controls, monitoring results, previous audit findings, and relevant permits or procedures. The goal is not to “audit on paper only,” but to identify risks, changes, and sampling priorities for fieldwork.
The audit plan (ISO 19011) specifies objectives, scope, criteria, schedule, team roles, methods (interview, observation, record sampling), and logistics. Risk-based sampling for EMS work prioritizes significant aspects, recent changes, prior nonconformities, and interfaces (contractors, multi-shift operations). Work documents—question sets, sampling sheets—support consistency without becoming a substitute for professional judgment.
3. Conducting Audit Activities
Opening meeting. Confirm plan, methods, confidentiality, and safety rules; introduce the team; clarify that the audit evaluates the EMS, not individual blame.
Collecting and verifying information. Use interviews, observation of activities and conditions, and review of documented information. EMS evidence examples: observed segregation of waste streams, calibration status of emission monitors, training records for spill response, permit condition tracking, and life-cycle related operational controls where claimed. Information becomes audit evidence when verified and relevant to audit criteria. Sufficiency depends on risk: a single tidy procedure is rarely enough for a high-significance process.
Generating findings. Compare evidence to criteria. Outcomes typically include conformity, nonconformity (failure to fulfill a requirement), and optionally observations/opportunities for improvement. Nonconformities should be factual, criterion-referenced, and supported by evidence—not opinions about “best practice.” Grade major/minor only if the organization’s (or CB’s) scheme defines those terms; internally, consistency of definition matters more than labels alone.
Closing meeting. Present findings so they are understood and acknowledged; explain reporting and follow-up expectations; avoid negotiating away clear nonconformities.
4. Preparing and Distributing the Audit Report
The report should enable management action. Typical contents: objectives, scope, criteria, team, dates, findings summary, nonconformity details, conclusions on conformity and effective implementation (aligned with Clause 9.2.1 intent), and any uncertainties or unresolved obstacles. Reports are distributed to relevant management and retained as documented information evidencing audit results (Clause 9.2.2).
5. Completing the Audit and Follow-up
The audit is complete when planned activities are finished and the approved report is distributed. Follow-up verifies that corrections and corrective actions address causes and are effective—especially for EMS issues that could recur as environmental incidents or compliance breaches. Ineffective follow-up is itself a programme weakness and a frequent certification finding. Results also feed programme monitoring (were objectives met?) and management review inputs.
Auditor Behaviors That Strengthen Internal Audits
- Trace from significant aspects → operational controls → monitoring → competence → emergency readiness.
- Sample implementation on the floor, not only controlled documents.
- Test how compliance obligations are evaluated and acted upon (Clause 9.1.2), not merely listed.
- Record enough evidence that a third party can understand the finding months later.
- Escalate independence conflicts before fieldwork.
Common Activity Failures
| Failure | Why it matters |
|---|---|
| No defined criteria/scope per audit | Violates Clause 9.2.2; findings become unanchored |
| Checklist ticking without verification | Misses ineffective implementation |
| Findings without evidence or criterion | Cannot drive credible corrective action |
| Report never reaches management | Breaks the Clause 9.2 reporting requirement |
| No follow-up on NCs | Recurring environmental and compliance risk |
Mini Case
An internal team audits “operational planning and control” for a solvent cleaning line. Preparation shows a new solvent introduced three months ago (change) and a prior NC on secondary containment. The plan prioritizes observation of storage, spill kits, training for the new chemical, and waste manifests. Fieldwork finds the SDS available but operators unaware of revised PPE, and containment drains left open. Findings cite organizational operational-control requirements and ISO 14001 Clause 8.1, supported by interview and observation evidence. The report goes to the plant manager and EHS lead; follow-up later verifies retraining effectiveness and sealed containment. That sequence—initiate, prepare, conduct, report, follow-up—is the main activity chain Lead Auditors must know cold.
Which sequence best reflects the main activities of an individual internal audit aligned with ISO 19011?
During preparation of an internal EMS audit, what is the primary purpose of document review?
What makes information collected during an internal audit usable as audit evidence?
After an internal EMS audit identifies a nonconformity on hazardous-waste labeling, what follow-up activity best demonstrates effective completion of the audit cycle?