How to create an internal audit process
How to design an internal audit process as a cycle rather than a project: a risk-based programme deciding what gets audited, an independence check on every assignment, and a close-out that re-samples.
A worked example, stage by stage
Start with the programme
The chart opens on "Review risks and past findings" rather than on an audit, then builds the annual programme and assigns an auditor to each entry in it. Three rows, and not one of them is an audit — which is the half most internal audit maps leave out.
Independence before planning
"Auditor independent of the area?" routes a No to "Reassign to another auditor", which points back at the gate to be asked again. Only then does planning start: a checklist, dates agreed with the auditee, and "Provide procedures and records" sitting in the auditee's own lane.
The report is not the finish
Fieldwork samples records and grades what it finds. "Evidence meets the requirement?" sends a "Gap found" to "Record nonconformity or observation", both routes converge on the closing meeting, and the report is issued. Most internal audit maps stop on that row.
A finding closes when verified
Root cause is agreed with the process owner, the action is completed by its due date, and then "Corrective action effective?" decides. "Reopen" goes back to row 16 rather than onward, and only the verified route reaches management review and a retained record.
How it works
List every process before scheduling one
The programme needs a denominator. Write down every process in scope with its owner, then note when each was last audited and what came out of it. The gaps in that list are the argument for the schedule, and they persuade management more reliably than the schedule ever does on its own.
Derive each interval from a risk score
Score every process on impact, recent change and finding history, and let the score set the interval: quarterly for one that has failed twice, once a cycle for one that has been stable for years. Record the reason beside the interval, because an auditor asked why dispatch is audited every three years needs an answer.
Build the programme rows first
In QueryChart the opening rows are the programme, not the audit: a Start shape on "Review risks and past findings", then the rows that build the schedule and assign an auditor to each entry. Keeping them in the same chart as the fieldwork is what makes the cycle visible to the person following it.
Add the independence gate as a decision
Phrase the assignment row as a question, then change its Shape column to Decision and give Line to two row numbers, with the answers in Line text in the same order. The reassignment route points back at the gate to be checked again, so its number is smaller than the row it is written on.
Put each step in its owner's lane
Vertical lane holds the role — quality manager, internal auditor, auditee, top management — and Horizontal lane holds the phase. Lanes are what make independence checkable at a glance: when fieldwork rows sit in the same lane as the process under audit, the chart is showing you a finding.
Close the cycle in the auditor's lane
Add the verification row in the auditor's lane, give it a scope — which population, how many records, after how long — and route its failure back to "Agree root cause and corrective action". Then share the link with the auditee, not only the audit team: whoever sees that row knows the finding closes on the re-sample, not the action report.
Frequently asked questions
How often should internal audits be carried out?
At planned intervals set by risk, which for most management systems means every process at least once per certification cycle and the exposed ones considerably more often. ISO 9001 asks for planned intervals and deliberately names no frequency, so auditing everything once a year is a choice rather than a requirement — usually a poor one, because it spreads identical effort across processes with wildly different consequences. Frequency should also move: a process with two open findings has earned an earlier revisit.
Who is allowed to carry out an internal audit?
Anyone trained in auditing who is independent of the area under audit — independence, not seniority, is the constraint. An auditor from another department, from another site, or a contracted one all qualify. The process owner does not, and neither does whoever wrote the procedure being sampled. Small organisations solve this by swapping auditors between functions rather than by waiving the requirement, and the assignment step is where the check belongs, because the assignment is where the conflict is created.
When can an internal audit finding be closed?
When an auditor has gone back to the population the finding came from, sampled it again, and found it now meets the requirement. Close-out is a piece of fieldwork with a scope, a sample size and a date, not a field changed from open to closed, and that is why it waits for an agreed interval rather than the following week: a sample drawn the day after the fix shows the fix was installed, not that it holds. Whether the action was well chosen is the corrective action process's question.
What is the difference between a nonconformity and an observation?
A nonconformity is a failure to meet a stated requirement and it obliges corrective action; an observation is a weakness or an emerging risk that breaches nothing and carries no such obligation. So the grade is a funding decision, not a wording one: mis-grade upwards and the register carries an obligation nobody budgeted for, mis-grade downwards and one that was owed has been quietly discharged. Decide it at the closing meeting, with the clause cited and the sample recorded.