Internal audit · clause 9.2
Internal audit checklist for ISO 9001, 45001 and 14001.
An internal audit is how you find the gaps in your own management system before a certification body or a client does. ISO 9001, 45001 and 14001 all require one under clause 9.2. This checklist explains what the clause asks, how to run an audit in a small Australian business, how to score it, and how the AI internal auditor in PolicySystem does the first pass. We are not a certification body.
What clause 9.2 requires
- Audits at planned intervals, covering the whole system over the cycle.
- An audit programme: frequency, methods, responsibilities, planning and reporting.
- Criteria and scope defined for each audit.
- Auditors selected for objectivity and impartiality.
- Results reported to relevant management (and, in 45001, to workers).
- Nonconformities addressed with corrective action.
- Documented information kept as evidence of the programme and the results.
The seven steps
- Plan. Set the scope (which standards, which sites), the clauses to cover, the dates and who audits what. Record the plan; the certification body will ask for it.
- Prepare. Pull the current versions of every policy and procedure and the registers behind them. Read the clauses you are auditing. Write your questions in advance.
- Gather evidence. For each clause: does the document exist, is it controlled, is there proof it is used. Sample real records. Talk to the people doing the work, not just the person who wrote the procedure.
- Score and record findings. Conforms, minor nonconformity, major nonconformity, observation. Write the evidence next to each finding so a stranger could follow it.
- Raise corrective actions. Every nonconformity becomes an entry in the CAPA register with a root cause, an owner and a due date. Observations can too if they matter.
- Report and review. Summarise the audit for the owner or director. It is a required input to management review under clause 9.3.
- Follow up. Check corrective actions were done and worked. Close them. The next audit starts by reviewing the last one.
Questions to ask under each clause
| Clause | Ask | Look at |
|---|---|---|
| 4 Context | Is the scope current? Have clients, sites or work types changed? | Scope statement, interested parties list |
| 5 Leadership | Is the policy signed, current and known to workers? | Policy control block, induction records |
| 6 Planning | Are hazards and risks identified and reviewed? Are objectives measured? | Hazard register, legal register, objectives |
| 7 Support | Is everyone competent and current? Are documents controlled? | Training register expiry, document versions |
| 8 Operation | Are procedures followed on the job? Are chemicals, contractors and emergencies controlled? | SDS register, contractor records, drill evidence |
| 9 Performance | What is measured, and did management review the results? | Management review minutes, previous audit |
| 10 Improvement | Are incidents investigated and corrective actions closed? | Incident register, CAPA register |
The ISO 45001 checklist takes the same table down to sub-clause level with the register that answers each one.
How the AI internal auditor works
It reads your issued policies and the entries in your registers, scores each clause of the standards you selected, and writes a finding for every gap in plain language: what is missing, which clause it fails, and which form in the system closes it. The first audit is created at the end of onboarding so you start with a baseline score rather than a blank page. A person reviews the findings, raises the corrective actions and signs the report. Rerun it before Stage 1 and again before Stage 2 and watch the score climb.
Mistakes that make an internal audit worthless
- No findings. Every real audit finds something. Zero findings tells the certification body the audit did not happen.
- Auditing the documents and never the practice. Talk to the people doing the work.
- Findings with no corrective action. A finding that is not in the CAPA register is a finding that will be there next year.
- No plan, so some clauses are never audited.
- Auditing the day before Stage 1 with no time to fix anything.
Where to next
ISO 45001 checklist · Management review · Document control · Incident register · How to get certified · ISO for tenders
Common questions.
Clause 9.2 in both standards. You check your own management system at planned intervals to confirm it meets the standard and your own requirements, and that it is implemented and maintained. You record findings, report them to management and take corrective action. It is your dress rehearsal for the certification body.
Anyone competent who is not auditing their own work, as far as practical. In a ten-person business that might be the office manager auditing the field procedures and the supervisor auditing the office ones. An AI internal auditor gives you an independent first pass and a score; a person still walks the findings and signs the report.
At least once per year across every clause, and before your Stage 2 certification audit. Many small businesses split it into two half-days six months apart so it never feels like a wall. High-risk activities and recent incidents justify more frequent checks.
A nonconformity: the system says one thing and practice does another, or the standard requires something the system does not have. An observation: not a nonconformity yet, but heading there. An opportunity for improvement. Each nonconformity should become a corrective action with an owner and a due date.
No. It scores each clause against the evidence in your policies and registers and lists what is missing and which form to file. Certification requires a JAS-ANZ accredited body. The AI auditor is how you walk into that audit knowing the answers.