top of page

Effective Internal Auditing Best Practices for ISO 9001 and AS9100: Enhancing Efficiency and Collaboration | My ISO Consultants

Writer: My ISO Jay
My ISO Jay
Dec 14, 2024
6 min read

Updated: 4 days ago

Internal audits should do more than confirm whether documented requirements are being followed. A well-planned ISO 9001 or AS9100 internal audit should evaluate whether processes are effective, identify meaningful risks and weaknesses, verify objective evidence, and uncover opportunities to improve the Quality Management System (QMS). The most effective audits combine auditor independence with a collaborative approach that helps employees provide accurate information and helps management understand where improvement is actually needed.


What Makes an ISO 9001 or AS9100 Internal Audit Effective?


An effective internal audit is a systematic, objective evaluation of whether the management system is being implemented as intended and producing effective results. Strong audits rely on verifiable evidence, appropriate sampling, knowledgeable auditors, risk-based planning, and clear reporting. For AS9100 organizations, audit planning should also reflect the importance and performance of aerospace processes, previous audit results, organizational changes, and areas that present greater quality or operational risk.


2026 Auditing Update: ISO 19011:2026 is now the current international guidance standard for auditing management systems. It provides updated guidance on audit principles, audit program management, auditor competence, evidence-based auditing, and risk-based auditing.


1. Engage Auditees Collaboratively While Maintaining Auditor Independence

Successful audits are collaborative, but auditors must still maintain independence and objectivity. Auditees should understand that the purpose of the audit is to evaluate processes and objective evidence, not to assign blame. Framing questions around how work is actually performed encourages employees to provide useful information while allowing the auditor to independently evaluate whether applicable requirements and process objectives are being met.


A respectful, non-confrontational approach can also improve the quality of the evidence collected. Employees are generally more willing to explain actual practices, process variations, and known weaknesses when they understand that the audit is intended to improve the system rather than punish individuals.


2. Use a Funnel Approach When Asking Questions

Effective questioning helps auditors gather complete information without turning the audit into an interrogation. Start with broad, open-ended questions that allow the auditee to explain how a process works. Follow with more focused questions to clarify responsibilities, records, controls, and exceptions. Closed-ended questions are most useful when confirming a specific fact or piece of evidence.


This approach gives the auditor context first and detail second, making it easier to recognize inconsistencies, missing controls, and areas that warrant deeper review.


3. Practice Active Listening

Auditors should spend more time listening than talking. Pay attention not only to the answer given, but also to how the process is described, what records are referenced, and whether the explanation matches what can be observed in practice. Follow-up questions should be based on the information provided rather than on a rigid script.


Active listening can reveal process weaknesses, undocumented workarounds, unclear responsibilities, or effective practices that would be missed if the auditor focused only on a checklist.


4. Select Samples Independently Using a Risk-Based Approach

Auditors should select samples independently and use a risk-based approach rather than relying only on records selected by the auditee. Sampling should consider process risk, previous findings, changes, performance trends, customer or regulatory concerns, and the importance of the activity being evaluated. Because audits are conducted within limited time and resources, appropriate sampling helps provide reliable audit conclusions without attempting to examine every available record.


Sample selection should be sufficient to test whether the process is operating consistently, while giving additional attention to areas where failure could have a greater impact on product quality, compliance, delivery, or customer requirements.


5. Explain the Real Effects of Audit Findings

Auditors should connect significant findings to their actual business or operational effects whenever the evidence supports doing so. These may include product quality, customer satisfaction, delivery performance, compliance risk, rework, wasted resources, operational disruption, or financial impact. Explaining why a finding matters helps management understand its significance and prioritize appropriate corrective action.


The goal is not to exaggerate consequences, but to show how a breakdown in the management system can affect real business outcomes.


6. Validate Evidence and Discuss Findings Before Finalizing Them

Before finalizing a finding, auditors should review the supporting evidence and discuss the finding with the auditee to confirm that the facts and context have been understood correctly. The purpose is to identify misunderstandings or missing information before the audit report is issued. Auditee agreement is not required when objective evidence supports the finding, but the conclusion should be clear, factual, and traceable to the applicable audit criteria.


This step improves report accuracy and reduces avoidable disputes during the closing meeting or corrective-action process.


7. Avoid Nitpicking

Internal audits should focus on issues that materially affect management system conformity or effectiveness. Auditors should distinguish isolated, low-risk clerical issues from evidence of a broader process or systemic failure, while still documenting nonconformities when applicable requirements are not met.


A strong auditor distinguishes between an isolated clerical mistake and evidence of a broader process problem. That judgment helps keep audit time focused on findings that can actually improve the organization.


8. Write Clear, Actionable Audit Findings

Audit findings should provide enough context for management to understand what was observed, what evidence supports the conclusion, and which requirement or internal control applies. A useful write-up should make it clear whether the issue appears isolated or may represent a broader systemic weakness.


Clear reporting makes corrective action easier because the organization can address the actual problem instead of spending time trying to interpret what the auditor meant.


9. Recognize Areas of Strength

Internal audits should identify effective practices as well as weaknesses. Recognizing areas of strength can reinforce behaviors that support quality, consistency, and continual improvement, and it can help management identify practices worth applying elsewhere in the organization.


Positive observations should remain specific and evidence-based. The goal is to acknowledge what is working well without weakening the auditor's objectivity or overlooking legitimate problems.


10. Use Risk-Based Audit Planning to Focus Time Where It Matters Most

Audit time should be allocated according to risk and importance rather than divided equally across every process. Higher-risk processes, recent changes, previous nonconformities, weak performance trends, customer concerns, and critical operational activities may warrant greater audit depth or frequency. A risk-based audit program helps organizations use limited audit resources efficiently while concentrating attention where failures could have the greatest impact.


For AS9100 organizations, audit frequency and depth should also reflect the status and importance of processes, changing conditions, and results from previous audits. This helps the internal audit program remain responsive to the actual condition of the QMS rather than becoming a fixed annual checklist exercise.


Frequently Asked Questions About ISO 9001 and AS9100 Internal Audits


How often should ISO 9001 and AS9100 internal audits be performed?

ISO 9001 and AS9100 do not require every process to be audited on a fixed annual schedule. Internal audits are conducted at planned intervals, with frequency and depth based on process importance, risk, changes, previous audit results, performance, and applicable customer or regulatory requirements. Higher-risk or changing processes may need more frequent review.


What should an ISO 9001 or AS9100 internal audit include?

An effective internal audit evaluates both conformity and process effectiveness. Auditors review objective evidence such as records, process performance, previous findings, corrective actions, and whether documented processes are followed in practice. Sampling should be risk-based and sufficient to support reliable conclusions. AS9100 audits should also address applicable aerospace-specific requirements and process risks.


Can ISO 9001 and AS9100 internal audits be outsourced?

Yes. A competent external auditor or consulting firm can perform internal audits on an organization's behalf. The auditor should be competent, objective, and impartial, and the audit should evaluate the organization against applicable criteria. Using outsourced internal auditing services is especially useful when internal staff lack independence, specialized ISO 9001 or AS9100 knowledge, or available time. The organization remains responsible for its audit program and findings.


What is the difference between an ISO 9001 or AS9100 internal audit and a certification audit?

An internal audit is performed by the organization or someone acting on its behalf to evaluate its management system for internal purposes. A certification audit is conducted by an independent third-party certification body to support a certification decision. Internal audits help identify gaps and improve readiness; certification audits determine whether the organization conforms to the applicable certification standard.


Conclusion

Strong internal audits can do much more than meet management system requirements and support certification readiness. They can help organizations identify weaknesses earlier, improve process effectiveness, and reduce surprises during certification and surveillance audits. If your organization needs an independent review of its Quality Management System, My ISO Consultants provides professional internal auditing services for organizations working with ISO 9001 consulting services, AS9100 consulting services, and other management system standards.


Our team can help evaluate audit readiness, identify meaningful gaps, strengthen audit programs, and provide objective auditing support tailored to your organization's operations and certification needs.


Auditor Class
Auditors Teaching Auditors

(844) MYISOPRO

PO Box 4372

Crestline, CA 92325

We service the entire United States and most countries, but we consider the following areas of California, Arizona, Texas and Nevada "Local" to us: San Bernardino County, Riverside County, Los Angeles County, Orange County, San Diego County, Ventura County, Sacramento County, San Jose, Santa Clara County, Fresno County, Phoenix Area, San Antonio, Austin, Reno and Las Vegas areas

© 2025 by My ISO Consultants

bottom of page