Skip to content
itmad

Capabilities / Auditing

Internal Audits

Outsourced internal audits for organisations certified by another body: qualified auditors delivering the full programme against your standard, with findings that stand up at certification audit.

Industrial & ManufacturingGovernment & PublicOil & GasConstruction & Real EstateBanking & InsuranceHealthcare & MedicalEducationIT & SecurityFood SafetyEnergy

Every management system standard requires internal audits at planned intervals, covering every clause and every process across the cycle. Most organisations know this and most struggle with it — not because it is difficult, but because the people competent to audit a department are usually the people who work in it.

The independence problem

The standard requires auditors not to audit their own work. In a small or medium organisation that is often impossible: the quality manager wrote the procedures, the operations manager runs the process, and there is nobody left who both understands the work and is independent of it.

The result is an internal audit programme that exists on paper, produces no findings of substance, and is written up as a non-conformity at the certification audit — usually with the observation that the internal audits did not detect issues the external auditor found in a day.

Where we can and cannot act

ITMAD is an accredited certification body, and ISO/IEC 17021-1 prohibits a certification body from performing internal audits for an organisation it certifies. We apply that strictly: where ITMAD holds your certification, we will not conduct your internal audits in any capacity.

Where your certification is held by another body — which is the case for most clients who need this service — there is no conflict. Our auditors bring the competence applied in accredited certification work, without the certification relationship that would compromise it. Put differently: we audit you as thoroughly as your certification body will, and we have no incentive to find your system compliant.

What the service covers

  • Programme planningAn audit programme covering every clause and process across the cycle, weighted by risk, by previous findings and by change in the organisation — rather than the same schedule repeated annually.
  • Audit deliveryAudits conducted on site to ISO 19011 principles, sampling objective evidence and interviewing at the levels where requirements are actually met.
  • Findings and reportingNon-conformities classified by severity with the evidence recorded, written so the finding can be acted on rather than merely logged.
  • Corrective action follow-upVerification that action addressed the cause and was effective, not simply that a form was closed.
  • Management review inputConsolidated reporting in the form the standard requires as an input to management review.
  • Multi-site programmesCoordinated auditing across dispersed sites, with consistent criteria applied so results are comparable between locations.

Standards covered

Internal audit programmes are delivered against any management system standard, including ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22000 and HACCP, ISO 22301, ISO 50001, ISO 41001 and ISO 37001, and for integrated systems covering more than one at once. Where you hold several, integrated internal auditing covers the common clauses once.

When organisations use this

  • Where no internal auditor can audit a function without auditing their own work
  • Ahead of first certification, where the standard requires a completed internal audit before stage 2
  • Between certification cycles, to keep the programme running rather than compressing it before surveillance
  • Where sites are too dispersed to audit with internal resources
  • Following an internal audit non-conformity at certification audit
  • Where the internal audit function has lost the personnel who ran it
  • To supplement an internal team on the technical areas they lack competence in

What you receive

  • An audit programme covering the full cycle, agreed with you before it starts
  • Audit reports with findings, objective evidence and classification
  • Non-conformity records in your own format where you have one
  • Follow-up verification of corrective action
  • Consolidated summary suitable as management review input
  • Auditor competence records for your certification body to examine

Related services

Where the audit is of your suppliers rather than your own system, supplier audits cover that. Where you need gap assessment ahead of certification rather than a recurring programme, pre-assessment applies.