CALL: +27 87 150 5559
5 Main Steps in an ISO 9001 Internal Audit
Many companies see the required process for Internal Audit as a form of necessary evil that they need to endure in order to maintain ISO9001 registration.
At best, they think it is a duplicate effort of the registrar, not realizing that the Internal Audit can be much more effective because it looks at the processes more often and more thoroughly than the registrar has time for.
At worst, the Internal Auditors are seen as some sort of internal police force that it is best to protect yourself against by hiding essential data or outright misleading with false information.
Steps in the Internal Audit
In fact, as a process owner, the Internal Audit process can be the best way to have an outside set of eyes take a close look at your process to help identify areas for improvement, or possibly complacency, which can help you streamline your process to run better, faster or more efficiently. Below are five main steps in the Internal Audit process and how they can best be used to focus the internal process owners on improving their processes.
1) Planning the Audit Schedule. A key part of a good process is having an overall Audit Schedule that is readily available to let everyone know when each process will be audited over the upcoming cycle (usually a yearly schedule). If you were not to have a plan and went with surprise audits, the message that is given from senior management is “We don’t trust our employees.” By publishing the audit intentions, the message is that this is meant as a support to the process owners and the auditors are there to help. This can allow the process owners to time the finish of any improvement projects that they are working on to be before the audit, so that they can gather valuable information on the implementation, or to request the auditors to focus on helping to gather information for other planned improvements.
2) Planning the Process Audit. The first step in planning the individual process audits is to confirm with the process owners when the audit will take place. The overall plan above is more of a guideline as to how often processes will be audited, and roughly when, but the confirmation allows the auditor and process owner to collaborate to determine the best time to review the process. This is when the auditor can review previous audits to see if any follow-up is required on comments or concerns previously found, and when the process owner can identify any areas that the auditor can look at to assist the process owner to identify information. A good audit plan can make sure that the process owner will get value out of the audit process.
3) Conducting the Audit. An audit should start with a meeting of the process owner to make sure that the audit plan is complete and ready. Then there are many avenues for the auditor to gather information during the audit: reviewing records, talking to employees, analyzing key process data or even observing the process in action. The focus of this activity is to gather evidence that the process is functioning as planned in the QMS, and is effective in producing the required results. One of the most valuable things that an auditor can do for a process owner is not only to identify areas that do not have evidence that they are functioning properly, but also to point out areas of a process that may function better if changes are made.
4) Reporting on the Audit. A closing meeting with the process owner is a necessity to ensure that the flow of information is not delayed. The process owner will want to know if there are any areas of weakness that need to be addressed, but will also be interested in knowing if any areas exist that might be improved. This should be followed with a written record as soon as possible to provide the information in a more permanent format to enable follow-up of the information. By identifying not only the non-conforming areas of the process, but also the positive areas and potential improvement areas, the process owner will get a better value from the Internal Audit, which will allow for process improvements.
5) Follow-up on Issues or Improvements Found. As with many areas of the standard, follow-up is a critical step. If problems have been found and corrective actions taken, making sure that the problem is actually fixed is a key part of fixing it. If improvement projects have been completed from opportunities identified in the audit, then seeing how much the process has improved is a great motivator for future improvements.
Focus on process improvement to get the most out of an Internal Audit
By using the Internal Audit process to focus on helping to improve the processes, and not just to maintain compliance, the company can see more value out of the audits. Process improvement is one of the key elements of an ISO9001 Quality Management System, and should be one of the main motivators of a company that wants to implement and maintain a good QMS. Process improvement not only helps with efficiency, but saves time and money in the process. If used properly, the Internal Audit, instead of being a “necessary evil,” can be one of the biggest contributors toward process improvement in the QMS.
Let Apliso Help You Today
Contact Apliso Management Solutions
Please enter your details below and we will get back to you shortly
We value your privacy and would never spam you
What is Apliso?
Apliso is the business portal designed to help in the application of the International Organisation for Standardization (ISO) solutions and standards for companies and organisations. We provide solutions and services to companies and organisations who have either implemented ISO based management systems and standards or are interested in implementing ISO standards and management systems. On the Apliso portal you will find links to tools that ensure compliance to the requirements of the ISO standards or contact with experts who can assist in the development and implementation of your management system according to the requirements of the applicable standard.
How Can Apliso Help Your Business?
Track Non-conformances
A key requirement of ISO Management systems is the logging, tracking, correction and prevention of Non-conformances or Non-compliance. Use the Apliso NC Management system to log all your non-conformances. Allocate resources to complete corrective actions, complete effective root cause analysis and execute effective preventative action.
Customer Complaint Mngt
Your business or organisation depends on the speedy resolution of all customer complaints. The Apliso Customer Complaint management system allows you to quickly log a complaint, allocate the appropriate resource to correct the complaint. This is followed by effective root cause analysis and preventative action to ensure no repeat complaints. Comprehensive reports and complaint status is standard in the system.
Business Improvements
How do you drive business improvement – easy you log any event, incident, or error that occurs. You allocate these events to the appropriate people to correct, and then apply effective root cause analysis and carefully planned preventative action to ensure no future event and drive improvement. Use detail analysis to monitor and measure improvements.
Health & Safety Incidents
Occupational health and safety requirements are such that any incident or near miss must be logged, corrected and effectively closed out. Appropriate controls should be put in place to prevent further occurrences of such events. Apliso Incident Management application allows you to comply to the requirements and effectively manage your Health and Safety requirements.
Management System Implementation
You have decided to implement or need more information on an ISO Management system (ISO 9001 Quality or ISO 14001 Environment Management or ISO 27001 Information Security Management plus more). You need assistance or advice on how to go about these requirements, what is involved, how long it will take etc. – Apliso provides this expert consulting service.
© 2015 isostandards.co.za. Legal Information
