
There are two kinds of internal audit programs. In the first, the audit is a snapshot of a system that runs all year; prep is light because the evidence already exists. In the second, the audit is an event the organization performs: two weeks of chasing signatures, reconciling registers, and back-filling records so the system looks the way the procedure says it should.
The second kind technically satisfies clause 9.2. It also produces almost nothing of value, because an audit of freshly groomed evidence audits the grooming, not the system. This guide is about running the first kind, and about what preparation legitimately looks like when you do.
Start with why internal audits exist
Clause 9.2 asks one real question: is the QMS conforming and effective? Not “are the binders tidy.” Is the system as practiced the system as documented, and is it producing results? Every prep activity should serve that question. Anything that exists only to look good for the auditor is waste, and experienced auditors see through it anyway.
Build an audit schedule that means something
The standard requires a planned audit program that considers importance of processes, changes affecting the organization, and previous audit results. In practice, most schedules are a flat rotation: every process, once a year, same depth. That’s compliant and lazy.
A risk-weighted schedule looks different:
- Processes with recent nonconformances, customer complaints, or major changes get audited sooner and deeper.
- Stable processes with clean history get lighter coverage.
- New processes get audited early in their life, when correction is cheap.
If your NCR and corrective-action data lives in a queryable system, this weighting takes minutes. If it lives in spreadsheets, this is one more place the schedule quietly defaults to flat rotation because the data is too painful to assemble.
The pre-audit checklist
Four to six weeks out, verify the inputs. Every item on this list is a common external-audit finding when skipped:
Documentation
- The audit program (annual schedule) is current and approved, not just individual audit plans.
- The internal audit procedure matches how you actually audit. If you’ve moved to remote interviews or sampling changes, update the procedure first.
- Auditor competence records exist, and no auditor is scheduled to audit their own work; clause 9.2 requires objectivity and impartiality, and this is the easiest place to lose it in a small company.
Prior loop closure
- Findings from the previous internal audit have corrective actions that are closed or genuinely in progress. An open finding from last year is the first thing an external auditor pulls.
- Effectiveness checks on those corrective actions were actually performed, not just scheduled.
Evidence spot-check
- Pull five controlled documents at random; confirm the floor copies match released revisions.
- Pull five training records against current document revisions; look for people trained on superseded versions.
- Pull the calibration list; check for anything overdue before the auditor does.
If those spot-checks pass, deep prep is unnecessary. If they fail, you’ve learned something more useful than any audit finding: your system drifts between audits, and the fix isn’t better prep; it’s better system.
Prepare the auditees, not the paperwork
The highest-value prep hour is spent with the people being audited, and not to coach answers. Cover three things:
- What an audit is: sampling against requirements, not a performance review. Findings are about the system.
- How to answer: truthfully, from what they actually do, showing the real records. “I don’t know, but I know where to find it” is a good answer.
- What not to do: guess, improvise, or produce documents they don’t normally use. An operator reciting the quality policy from a laminated card impresses no one; an operator who can pull up the current work instruction for their station demonstrates a working system.
During the audit: write findings worth acting on
A finding should carry three things: the requirement (clause or internal procedure), the evidence (specific and traceable: “WI-041 Rev C at station 4, register shows Rev D effective 3 March”), and the nature of the gap. “Training records need improvement” is not a finding; it’s a mood. Findings written with requirement-evidence-gap discipline turn into corrective actions that can actually be investigated.
And every finding should flow into the same corrective-action loop as your NCRs: same root-cause discipline, same effectiveness checks, same escalation when due dates slip. Audit findings tracked in a separate spreadsheet, disconnected from the CAPA system, are the most commonly orphaned records in quality.
After: the part everyone skips
The audit isn’t finished at the closing meeting. It’s finished when:
- Findings are logged with owners and due dates in the corrective-action system.
- Root causes are identified for anything systemic.
- Effectiveness is verified on a defined timeline.
- Results are summarized as an input to management review (clause 9.3 explicitly requires it).
The pattern worth noticing: nearly everything in this article gets easier when audit records, NCRs, corrective actions, training, and document control live in one system instead of five. Not because software audits for you (it can’t) but because the fire drill is the cost of scattered evidence. Organizations that dread audit prep aren’t bad at auditing. They’re paying, in concentrated two-week installments, for the retrieval costs their tools defer all year.