Internal audit process flowchart template
Internal audit process flowchart template: risk-based audit programme, auditor independence check, fieldwork, nonconformities, corrective action and follow-up.
How it works
Rename the lanes to your actual roles
Replace 'Quality manager' with whoever owns the audit programme - it may be a compliance lead, HSE manager or ISMS manager - and adjust 'Auditee / process owner' to the title your organisation uses. Keep top management as a separate lane even if it is one person, because the reporting line into management review needs to be visible.
Write down what drives audit frequency
Add your rule to the audit programme step: which processes are audited every cycle, what triggers an extra audit (a major nonconformity, a process change, a new supplier, a customer complaint trend) and what the minimum coverage is over a certification cycle. A programme with no stated rationale is a common finding in itself.
Define the independence test
State what disqualifies an auditor at the independence decision: auditing their own work, auditing a process they manage or report into, or having designed the procedure under audit. Record the alternative you use when the pool is small - cross-department swaps, a trained auditor from another site, or a contracted auditor.
Fix your finding categories and what each obliges
Decide how you distinguish major nonconformity, minor nonconformity and observation, and record it on the nonconformity step. Be explicit that observations do not require corrective action, otherwise auditors under-report to avoid creating work.
Set corrective action timescales
Put real numbers on the corrective action steps: how long the process owner has to propose root cause and action, how long to implement, and when verification happens. Something like ten working days to respond and sixty to complete is common, but pick what your organisation can actually meet.
Name where the evidence lives
Annotate the report and closure steps with the actual location and retention period for checklists, sampling notes, reports and action records. Evidence of the audit programme and its results has to be retained, and 'in the auditor's inbox' will not satisfy a certification auditor.
Frequently asked questions
What are the stages of the internal audit process?
Six, as shown in this chart. Build a risk-based annual audit programme from process risk and previous findings. Assign an auditor and confirm they are independent of the area. Plan the audit, notify the auditee and review documents beforehand. Carry out the audit on site: opening meeting, sampling records and interviewing staff, closing meeting. Report the results, recording nonconformities and observations separately. Then agree corrective action with an owner and due date, verify it worked, and feed the results into management review before closing the audit and retaining the records.
How do you keep auditor independence in a small organisation?
The requirement is that auditors do not audit their own work, not that you employ a separate audit department. In practice that means swapping auditors between departments - the person who runs purchasing audits the warehouse and vice versa - training staff outside the quality function as auditors, borrowing a trained auditor from another site or group company, or contracting an external auditor for the areas where nobody internal is impartial. The chart makes this a decision point with a reassignment loop so the check happens before planning rather than after the report is challenged.
How often should internal audits be carried out?
No management system standard sets a fixed interval. ISO 9001, ISO 14001 and ISO 27001 all say audits are carried out at planned intervals and that the programme takes account of the importance of the processes concerned, changes affecting the organisation and the results of previous audits. In practice most organisations cover every process at least once per three-year certification cycle, audit high-risk or previously nonconforming processes annually or more often, and add unplanned audits after significant changes or incidents.
What is the difference between a nonconformity and an observation?
A nonconformity is a failure to meet a stated requirement - a clause of the standard, your own procedure, or a legal or customer requirement - and it obliges you to correct it, investigate the cause and take corrective action. An observation is something the auditor noted that is not a breach: a weak control, an inconsistency, or a practice that will become a problem if left. It does not require corrective action. Keeping the two clearly separated matters, because if observations are treated as findings, auditors quietly stop recording them.