ISO Certification

ISO Internal Audits: What They Are, Why You Need Them, and How to Run One

What an internal audit actually involves under ISO standards, why every certification requires one, common mistakes that make them worthless, and when it's worth outsourcing.

Published 3 October 2026 · By Prashant Sharma, Founder of ISO Audit Align

Every ISO management system standard requires internal audits — ISO 27001, ISO 9001, ISO 45001, all of them. It’s one of the most misunderstood requirements, because done badly it’s a box-ticking exercise, and done well it’s the single best way to catch problems before an external auditor does.

What an internal audit actually is

An internal audit is a structured, independent check of your management system against the requirements of your ISO standard — run by or on behalf of your own organisation, not by your certification body. Its job is to find real gaps: non-conformances, weak evidence, processes that exist on paper but don’t actually happen in practice.

It is not the certification audit. The certification audit is run by an accredited external body and is what actually gets or keeps your certificate. The internal audit is your own rehearsal — and your chance to fix problems before they count against you externally.

Why it’s required, not optional

Every major ISO management system standard includes an internal audit clause for the same reason: certification bodies need evidence your organisation genuinely monitors itself, not just that a consultant built a good system once. An internal audit programme with real findings and tracked corrective actions is some of the strongest evidence you can show an external auditor that your system is actually alive.

What a credible internal audit programme looks like

  • Planned and cyclical — a programme covering every relevant clause and process area within your certification cycle, not an improvised one-off.
  • Independent — the person auditing a process shouldn’t be the person who owns or performs it. This is where small businesses often need outside help, since the person who understands the system best is frequently the person who built it.
  • Evidence-based — findings backed by what was actually checked (records, interviews, observations), written the way a certification auditor would expect to see them.
  • Tracked to closure — a finding that’s raised and never resolved is worse than not auditing at all, because it shows up as a repeat issue in your next external audit.

Common mistakes that make internal audits worthless

  • Auditing your own work. Even well-intentioned, this produces findings that are too soft to be useful.
  • Treating it as a paperwork exercise. An internal audit that never finds anything isn’t evidence of a strong system — it’s usually evidence of a weak audit.
  • No follow-through. Findings raised once and never tracked to actual closure. This is the single most common gap certification auditors flag.
  • One audit covering everything, once a year, rushed. A credible programme spreads coverage across the cycle rather than cramming it all into a pre-audit panic.

Doing it yourself vs outsourcing

Self-running internal audits works when someone genuinely independent of the processes being audited has the time and standard-specific knowledge to do it properly, on schedule, every cycle. In practice, many smaller organisations outsource this specifically because the realistic internal choice — the person who built the system — can’t audit their own work, and nobody else has the capacity or expertise to do it credibly.

If your internal audits need a reset

Whether you need someone to run the full programme or just want a second opinion on whether your current approach would hold up, book a free consultation and we’ll talk through what a credible internal audit programme looks like for your actual system.

Ready to get certified?

45-minute no-obligation consultation. Honest assessment. Fixed-price proposal.

Book Free Consultation
Chat with us