Internal audit process flowchart template
Internal audit process flowchart template: risk-based audit programme, auditor independence check, fieldwork, nonconformities, corrective action and follow-up.
What the internal audit process flowchart process is
An internal audit is an organisation checking itself against its own procedures and against whatever standard it works to. The cycle in this template is the one management system standards expect: ISO 9001, ISO 14001 and ISO 27001 all require audits at planned intervals, an audit programme that takes account of process importance and previous results, auditors who are objective and impartial, findings acted on without undue delay, evidence of the programme and its results retained, and audit results fed into management review.
Two things decide whether an audit programme is useful or just paperwork. The first is independence: an auditor reviewing a process they run will not report against themselves, which is why this chart makes the independence check an explicit decision with a reassignment route rather than a line in a procedure nobody reads. The second is evidence. A finding is only defensible if it points at a specific record, sample or interview, so the fieldwork step exists to capture document numbers, dates and sample sizes while the auditor is still in the room, and the final step closes the audit by retaining those records rather than by sending an email.
The other place audit programmes fail is after the report. Findings get raised, corrective actions get agreed, and then nothing verifies that the action worked. The chart handles this with a follow-up decision that either verifies the action or reopens it back to root cause analysis, so a nonconformity cannot be closed on the strength of a promise. If you maintain the audit procedure itself as a controlled document, keep it under version control with a recorded approval, since a certification auditor will usually ask which revision was in force at the time of a given audit.
What this flowchart covers
In this template
- Four swimlanes - quality manager, internal auditor, auditee or process owner, and top management - laid across six phases: audit programme, planning, fieldwork, reporting, corrective action, and follow-up and review.
- Programme setup owned by the quality manager: review risks and past findings, build the annual audit programme, and assign an auditor to each audit.
- An explicit independence decision, 'Auditor independent of the area?', where a No routes to reassigning another auditor and rechecking before any planning begins.
- Preparation and document review: audit plan and checklist, notification and date confirmation with the auditee, the auditee supplying procedures and records, and a pre-audit document review.
- Fieldwork with an 'Evidence meets the requirement?' decision - conforming evidence goes straight to the closing meeting, a gap routes through recording a nonconformity or observation first.
- Close-out: issue the audit report as a retained record, agree root cause and corrective action with the process owner, complete it by the due date, then a 'Corrective action effective?' check that either reopens the action or passes results to management review before the audit is closed and records retained.
When to use this template
- You are writing or revising the documented internal audit procedure for ISO 9001, ISO 14001, ISO 27001 or a comparable management system.
- You are preparing for a certification or surveillance audit and need to show how audits are planned, who audits whom, and where the evidence is kept.
- Findings are being raised but corrective actions drift past their due dates and nobody verifies whether they worked.
- You are training new internal auditors who have only seen the on-site day and not the programme, reporting and follow-up around it.
- You run a small organisation where auditor independence is genuinely difficult and you need a defensible way to demonstrate it.
How it works
Rename the lanes to your actual roles
Replace 'Quality manager' with whoever owns the audit programme - it may be a compliance lead, HSE manager or ISMS manager - and adjust 'Auditee / process owner' to the title your organisation uses. Keep top management as a separate lane even if it is one person, because the reporting line into management review needs to be visible.
Write down what drives audit frequency
Add your rule to the audit programme step: which processes are audited every cycle, what triggers an extra audit (a major nonconformity, a process change, a new supplier, a customer complaint trend) and what the minimum coverage is over a certification cycle. A programme with no stated rationale is a common finding in itself.
Define the independence test
State what disqualifies an auditor at the independence decision: auditing their own work, auditing a process they manage or report into, or having designed the procedure under audit. Record the alternative you use when the pool is small - cross-department swaps, a trained auditor from another site, or a contracted auditor.
Fix your finding categories and what each obliges
Decide how you distinguish major nonconformity, minor nonconformity and observation, and record it on the nonconformity step. Be explicit that observations do not require corrective action, otherwise auditors under-report to avoid creating work.
Set corrective action timescales
Put real numbers on the corrective action steps: how long the process owner has to propose root cause and action, how long to implement, and when verification happens. Something like ten working days to respond and sixty to complete is common, but pick what your organisation can actually meet.
Name where the evidence lives
Annotate the report and closure steps with the actual location and retention period for checklists, sampling notes, reports and action records. Evidence of the audit programme and its results has to be retained, and 'in the auditor's inbox' will not satisfy a certification auditor.
Frequently asked questions
What are the stages of the internal audit process?
Six, as shown in this chart. Build a risk-based annual audit programme from process risk and previous findings. Assign an auditor and confirm they are independent of the area. Plan the audit, notify the auditee and review documents beforehand. Carry out the audit on site: opening meeting, sampling records and interviewing staff, closing meeting. Report the results, recording nonconformities and observations separately. Then agree corrective action with an owner and due date, verify it worked, and feed the results into management review before closing the audit and retaining the records.
How do you keep auditor independence in a small organisation?
The requirement is that auditors do not audit their own work, not that you employ a separate audit department. In practice that means swapping auditors between departments - the person who runs purchasing audits the warehouse and vice versa - training staff outside the quality function as auditors, borrowing a trained auditor from another site or group company, or contracting an external auditor for the areas where nobody internal is impartial. The chart makes this a decision point with a reassignment loop so the check happens before planning rather than after the report is challenged.
How often should internal audits be carried out?
No management system standard sets a fixed interval. ISO 9001, ISO 14001 and ISO 27001 all say audits are carried out at planned intervals and that the programme takes account of the importance of the processes concerned, changes affecting the organisation and the results of previous audits. In practice most organisations cover every process at least once per three-year certification cycle, audit high-risk or previously nonconforming processes annually or more often, and add unplanned audits after significant changes or incidents.
What is the difference between a nonconformity and an observation?
A nonconformity is a failure to meet a stated requirement - a clause of the standard, your own procedure, or a legal or customer requirement - and it obliges you to correct it, investigate the cause and take corrective action. An observation is something the auditor noted that is not a breach: a weak control, an inconsistency, or a practice that will become a problem if left. It does not require corrective action. Keeping the two clearly separated matters, because if observations are treated as findings, auditors quietly stop recording them.