ISO 27001

ISO 9001 · the internal audit programme

The internal audit programme, written from five answers

Clause 9.2 wants a programme, not a one-off: how often the company audits itself, against what, by whom, how and where the results go, written below from five answers with the 7 clause sections of the standard, 36 clauses in all, and your own processes spread over the year's audits, so that every part of the system is audited at least once a year by someone who did not build it.

Audits a year
Who audits

The schedule for 2026

The clause sections and your processes spread over the audits in order, each at least once a year; an audit on a process reads the process's own procedure, its measures and its records against Clause 8.

Audit 1: October 2026

  • 4: Context of the organization (4 clauses)
  • 5: Leadership (4 clauses)
  • 6: Planning (3 clauses)
  • 7: Support (10 clauses)

Audit 2: April 2027

  • 8: Operation (7 clauses)
  • 9: Performance evaluation (5 clauses)
  • 10: Improvement (3 clauses)

The programme

# Internal audit programme: [company]

Programme owner: [the programme owner] · Approved by: [top management] · Year: 2026

Written on  with the free page on getstandardos.com against Clause 9.2 of ISO 9001:2015. The wording is StandardOS's own; the clause headings are its descriptions, not the standard's text.

## Purpose and criteria

The internal audits check whether the quality management system of [company] meets the requirements of ISO 9001:2015 and the company's own requirements, and whether it is implemented and maintained as written. The criteria for every audit are the standard, the quality policy and the quality objectives, the process map and the procedures under it, and the customer, statutory and regulatory requirements that apply to the products and services on the audit date.

## Frequency and coverage

Two internal audits a year share the system between them: the 7 clause sections of the standard, 36 clauses in all, and the processes of the quality management system are spread over the two audits so that every section and every process is audited at least once a year, the processes weighted by their importance to what the company delivers and by the results of earlier audits. An audit is added when a significant change, a customer complaint or a finding calls for one.

The processes audited as units of their own: [name the processes of the quality management system as the process map names them].

## Auditors and independence

The audits are performed by people of [company] trained for it, chosen for each audit so that nobody audits work they own or perform; where the team is too small for that on a topic, that topic is audited by an external auditor.

An auditor never audits a process they run, a procedure they own or a record they produced. The audit is against evidence: a claim without a record is a finding, not a pass.

## Methods

- Document review: the quality policy, the process map and the procedures read against the criteria before the audit.
- Interviews: the owners of the clauses and processes in scope, asked to show rather than tell.
- Sampling of records: orders, releases, complaints, supplier evaluations, training records and change records, sampled across the period.
- Observation of the process at work: the process followed from input to output where it runs, not where it is written.

## The schedule for 2026

Each audit covers the sections and processes below; the plan for each audit, with its dates, auditor and the records sampled, is written two weeks before it.

### Audit 1: October 2026

- 4: Context of the organization (4 clauses)
- 5: Leadership (4 clauses)
- 6: Planning (3 clauses)
- 7: Support (10 clauses)

### Audit 2: April 2027

- 8: Operation (7 clauses)
- 9: Performance evaluation (5 clauses)
- 10: Improvement (3 clauses)

## Reporting and follow-up

Each audit ends in a written report to [the programme owner] and to top management within two weeks, listing the evidence seen, the findings as nonconformities or observations with the clause or process they touch, and the good practice noted. Every nonconformity enters the corrective action process with an owner and a date; the findings and their status are an input of the next management review.

## Records

This programme, each audit plan, each report and the evidence of the corrective actions are kept as documented information of the quality management system, versioned and available to the certification body.

Approved by [top management] on [date]. Reviewed at the management review and whenever the scope, the risks or the results of the audits call for a change.

This programme is written from the answers given. It is not certification advice; the certification body reads the programme, the plans and the reports at the audit, and the record it accepts is the one the company keeps.
Next: the management review

StandardOS runs the programme it writes

In StandardOS the programme is a calendar: each audit has its date, its scope, its auditor and its checklist drawn from the clause register and the process map, the findings open corrective actions by themselves, and the management review reads the results; a company holding ISO 9001 and ISO 27001 runs one programme for both.

The corrective action recordWrite the quality policyThe ISO 27001 internal audit programme