16.3 Main Activities in an Internal Audit

Key Takeaways

  • Internal audit activities follow a managed sequence: initiate, prepare (document review and plan), conduct (opening, evidence collection, findings), report, and complete/follow-up
  • Each audit needs defined objectives, scope, and criteria before fieldwork begins
  • Evidence must be objective, verifiable, and sufficient relative to the risk and environmental importance of the process
  • Findings should be classified consistently (conformity, nonconformity, opportunity for improvement) and reported to relevant management
  • Follow-up verifies corrective action effectiveness; closing the loop is part of programme credibility and Clause 10 improvement
Last updated: July 2026

16.3 Main Activities in an Internal Audit

Quick Answer: An individual internal EMS audit follows ISO 19011’s conducting-audit guidance: initiate the audit; prepare (including document review and the audit plan); conduct activities to collect evidence and generate findings; prepare and distribute the report; then complete the audit and perform follow-up as required. ISO 14001 Clause 9.2 expects defined criteria/scope, impartial auditors, management reporting, and retained evidence of results.

While Section 16.1 addressed managing the programme, this section focuses on the activities inside one internal audit. Lead Auditors—whether performing first-party work or evaluating a client’s internal audits during certification—must recognize when those activities are complete, competent, and risk-based.

Activity Sequence Overview

PhaseMain activitiesEMS-focused outputs
InitiateConfirm feasibility, appoint team leader/team, establish contactAgreed objectives/scope/criteria; access arrangements
PrepareDocument review; risk-based plan and sampling strategyAudit plan, checklists/work documents, logistics
ConductOpening meeting; collect/verify evidence; generate findings; closing meetingWorking papers, clear findings with evidence
ReportPrepare, approve, distribute audit reportDocumented results for management and records
Complete & follow-upClose audit file; verify corrective actions where neededUpdated NC status; input to programme monitoring

These phases mirror ISO 19011 Clause 6 and should be scaled to audit size—but not skipped. A half-day internal audit of a low-aspect process still needs criteria, a plan (even concise), evidence, and a report.

1. Initiating the Audit

Initiation confirms that the audit can be done: scope is clear, criteria exist, information is available, and cooperation is feasible. For internal EMS audits, objectives often include verifying conformity of specific processes (e.g., operational control of hazardous waste, emergency preparedness, compliance evaluation) and assessing whether controls are effective. Scope defines boundaries—sites, processes, shifts, contractors. Criteria typically include ISO 14001 clauses relevant to the process, EMS documented information, and applicable compliance obligations.

Feasibility issues (records unavailable, key staff on shutdown, unsafe access) should be escalated to the programme manager before forcing a hollow audit.

2. Preparing the Audit Plan and Document Review

Document review examines the environmental policy, aspect/impact registers, compliance obligation lists, operational controls, monitoring results, previous audit findings, and relevant permits or procedures. The goal is not to “audit on paper only,” but to identify risks, changes, and sampling priorities for fieldwork.

The audit plan (ISO 19011) specifies objectives, scope, criteria, schedule, team roles, methods (interview, observation, record sampling), and logistics. Risk-based sampling for EMS work prioritizes significant aspects, recent changes, prior nonconformities, and interfaces (contractors, multi-shift operations). Work documents—question sets, sampling sheets—support consistency without becoming a substitute for professional judgment.

3. Conducting Audit Activities

Opening meeting. Confirm plan, methods, confidentiality, and safety rules; introduce the team; clarify that the audit evaluates the EMS, not individual blame.

Collecting and verifying information. Use interviews, observation of activities and conditions, and review of documented information. EMS evidence examples: observed segregation of waste streams, calibration status of emission monitors, training records for spill response, permit condition tracking, and life-cycle related operational controls where claimed. Information becomes audit evidence when verified and relevant to audit criteria. Sufficiency depends on risk: a single tidy procedure is rarely enough for a high-significance process.

Generating findings. Compare evidence to criteria. Outcomes typically include conformity, nonconformity (failure to fulfill a requirement), and optionally observations/opportunities for improvement. Nonconformities should be factual, criterion-referenced, and supported by evidence—not opinions about “best practice.” Grade major/minor only if the organization’s (or CB’s) scheme defines those terms; internally, consistency of definition matters more than labels alone.

Closing meeting. Present findings so they are understood and acknowledged; explain reporting and follow-up expectations; avoid negotiating away clear nonconformities.

4. Preparing and Distributing the Audit Report

The report should enable management action. Typical contents: objectives, scope, criteria, team, dates, findings summary, nonconformity details, conclusions on conformity and effective implementation (aligned with Clause 9.2.1 intent), and any uncertainties or unresolved obstacles. Reports are distributed to relevant management and retained as documented information evidencing audit results (Clause 9.2.2).

5. Completing the Audit and Follow-up

The audit is complete when planned activities are finished and the approved report is distributed. Follow-up verifies that corrections and corrective actions address causes and are effective—especially for EMS issues that could recur as environmental incidents or compliance breaches. Ineffective follow-up is itself a programme weakness and a frequent certification finding. Results also feed programme monitoring (were objectives met?) and management review inputs.

Auditor Behaviors That Strengthen Internal Audits

  • Trace from significant aspects → operational controls → monitoring → competence → emergency readiness.
  • Sample implementation on the floor, not only controlled documents.
  • Test how compliance obligations are evaluated and acted upon (Clause 9.1.2), not merely listed.
  • Record enough evidence that a third party can understand the finding months later.
  • Escalate independence conflicts before fieldwork.

Common Activity Failures

FailureWhy it matters
No defined criteria/scope per auditViolates Clause 9.2.2; findings become unanchored
Checklist ticking without verificationMisses ineffective implementation
Findings without evidence or criterionCannot drive credible corrective action
Report never reaches managementBreaks the Clause 9.2 reporting requirement
No follow-up on NCsRecurring environmental and compliance risk

Mini Case

An internal team audits “operational planning and control” for a solvent cleaning line. Preparation shows a new solvent introduced three months ago (change) and a prior NC on secondary containment. The plan prioritizes observation of storage, spill kits, training for the new chemical, and waste manifests. Fieldwork finds the SDS available but operators unaware of revised PPE, and containment drains left open. Findings cite organizational operational-control requirements and ISO 14001 Clause 8.1, supported by interview and observation evidence. The report goes to the plant manager and EHS lead; follow-up later verifies retraining effectiveness and sealed containment. That sequence—initiate, prepare, conduct, report, follow-up—is the main activity chain Lead Auditors must know cold.

Test Your Knowledge

Which sequence best reflects the main activities of an individual internal audit aligned with ISO 19011?

A
B
C
D
Test Your Knowledge

During preparation of an internal EMS audit, what is the primary purpose of document review?

A
B
C
D
Test Your Knowledge

What makes information collected during an internal audit usable as audit evidence?

A
B
C
D
Test Your Knowledge

After an internal EMS audit identifies a nonconformity on hazardous-waste labeling, what follow-up activity best demonstrates effective completion of the audit cycle?

A
B
C
D