Most internal audit programs I inspect were built once, three or four years ago, and never touched again. The schedule says every process gets audited once a year, the checklist mirrors the standard's table of contents clause by clause, and whoever had time that quarter got assigned as auditor. Then a surveillance auditor or an FDA investigator asks a simple question — "how did you decide this frequency?" — and there's no answer. That gap, not the audit itself, is what turns into a nonconformity.
Clause 9.2 of ISO 9001:2015 (and its equivalents in ISO 13485:2016 clause 8.2.4, ISO 14001:2015 clause 9.2, and ISO 42001:2023 clause 9.2) doesn't tell you how often to audit or exactly what to cover. It tells you to have a program, and to be able to justify it. In my experience, internal audit deficiencies related to program design, not execution, are among the most consistently cited nonconformities in third-party surveillance audits across accredited certification bodies. The finding is rarely "you didn't audit." It's "you can't show why you audited this way."
This piece walks through the three decisions that make or break an internal audit program: how often to audit, what to audit, and who's qualified to do it.
What an Internal Audit Program Actually Has to Do
An internal audit program is not a checklist. It's a planning document that answers four questions before a single audit is scheduled: what needs auditing, how often, using what method, and audited by whom. ISO 19011:2018, the guidance standard for auditing management systems, frames this as establishing audit program objectives (clause 5.2) and then determining extent based on the size and nature of the organization, the complexity and risk of its processes, and the results of previous audits (clause 5.3.2).
That last input — previous audit results — is the one most programs skip. A static annual cycle treats a process with zero findings for three years the same as a process with a major nonconformity last quarter. Auditors following ISO 19011 are supposed to let history change the plan. If your program doesn't do that, it's compliant on paper and blind in practice.
How Often Should Internal Audits Be Conducted?
There is no universal number. ISO 9001, ISO 13485, and ISO 14001 all avoid mandating a frequency, and that's deliberate — a five-person calibration lab and a 400-person contract manufacturer carry different risk profiles even under the same standard. What the standards require instead is a documented rationale tied to risk, process criticality, and change.
In practice, I build frequency around four inputs, weighted differently depending on the organization:
Process risk and criticality. Processes tied directly to product safety, regulatory submissions, or customer-facing nonconformities get audited more often than administrative processes. A sterilization validation process at a Class II medical device manufacturer does not sit on the same clock as the training records process, even though both live under the same QMS.
Change volume. New processes, recently transferred products, new suppliers, and post-CAPA processes all warrant a shortened interval. If a process changed significantly in the last audit cycle, the next audit should happen sooner than the standard rotation, not later.
Historical performance. A process with a clean audit history for two consecutive cycles can often move to a longer interval. A process with a recurring finding should never get a longer interval until it demonstrates two clean cycles in a row.
External signal. Customer complaints, regulatory inspection trends in your sector, and supplier performance data should all be able to trigger an unscheduled audit outside the fixed calendar. A program that can only audit on the schedule it published in January isn't risk-based, it's just scheduled.
IATF 16949 is the exception that proves the rule: it explicitly requires a three-year audit cycle covering all processes, all shifts, and includes mandatory annual manufacturing process audits and product audits per customer-specific requirements. Where IATF applies, the frequency question is partially answered for you. Everywhere else, you're building the logic yourself, and you need to be able to explain it in a sentence to an auditor who asks.
How Do You Determine Internal Audit Scope?
Scope decisions fail in one of two directions. Either the program audits by clause — a "documented information audit," a "management review audit" — which produces findings that read like a compliance scavenger hunt and tell you nothing about whether the process actually works. Or it audits by department, which misses the handoffs between departments where most real failures live.
The more useful unit is the process, audited end to end, against both the standard's requirements and the organization's own documented method. A process-based audit of, say, corrective action doesn't stop at "is there a CAPA procedure." It follows an actual CAPA from initiation through root cause investigation, effectiveness check, and closure, across whichever functions touched it. That's where you find the gap between what the procedure says and what people do — which is the gap that actually produces field failures and regulatory citations.
Scope should also flex with purpose. Not every audit needs to cover a full process top to bottom. A targeted audit — following up on a prior finding, verifying a single corrective action, checking a specific customer complaint pattern — is a legitimate and often more efficient use of audit resources than another full-scope sweep. The audit program should explicitly allow for both, rather than forcing every entry on the calendar into the same shape.
One more scope decision that gets missed: outsourced and supplier-controlled processes. If a critical process is performed by a contract manufacturer or a key supplier, your internal audit program needs a mechanism — whether that's a supplier audit, a documented review of the supplier's own audit results, or an on-site assessment — for confirming that process is controlled. Auditing only what happens inside your own walls when a critical process happens outside them is a scope gap that inspectors will find before you do.
What Competence Requirements Apply to Internal Auditors?
This is where I see the most avoidable failures, because the fix is usually cheap and the finding is usually expensive. ISO 19011:2018 clause 7 lays out auditor competence as a combination of personal behavior, knowledge and skills (generic auditing skills plus discipline-specific and sector-specific knowledge), and the education, work experience, auditor training, and audit experience needed to acquire them. None of that requires third-party certification — an organization can determine and document its own competence criteria — but it does require the organization to be able to demonstrate the criteria were applied.
Three requirements come up in nearly every finding I've reviewed:
Independence from the area audited. ISO 9001 clause 9.2.2 and ISO 13485 clause 8.2.4 both require that auditors not audit their own work. This doesn't mean auditors can't work in the department they're auditing across a broader career — it means the specific audit assignment can't have the auditor evaluating a process they own or directly supervise. Small organizations solve this with cross-training auditors across departments or bringing in an external auditor for functions too small to self-audit independently.
Documented training, not just tenure. "She's been doing quality for fifteen years" is not evidence of auditor competence. What auditors need is training in audit techniques (interviewing, sampling, evidence-gathering, nonconformity writing) plus enough knowledge of the standard and the process being audited to recognize a real gap versus a paperwork variance. I generally recommend a documented internal auditor course, refreshed periodically, plus a period of auditing under observation by a qualified auditor before someone audits solo.
Ongoing evaluation, not one-time qualification. Competence determined once at hire and never revisited doesn't hold up. ISO 19011 clause 7.6 calls for auditors to be evaluated, and clause 5.3.2 expects the audit program itself to be monitored for whether it's achieving its objectives — which includes whether the auditors assigned are actually finding what a competent audit should find. An auditor who has produced zero findings across a dozen audits in a facility with an active CAPA backlog is a competence question, not a compliment.
For regulated manufacturers operating under FDA's Quality System Regulation, 21 CFR 820.22 requires the quality audit be conducted by individuals who do not have direct responsibility for the matters being audited — the same independence principle as ISO, applied under a different citation. FDA doesn't mandate specific credentials either, but investigators do ask to see training records for the auditors who performed the audits in the file they're reviewing.
Comparing Audit Program Requirements Across Standards
| Standard | Frequency requirement | Independence requirement | Competence documentation |
|---|---|---|---|
| ISO 9001:2015 (cl. 9.2) | Risk-based, organization-defined; no fixed interval | Auditors must not audit their own work | Organization defines and records criteria |
| ISO 13485:2016 (cl. 8.2.4) | Risk-based, organization-defined; explicitly considers process status and importance | Auditors must not audit their own work | Documented procedure required for auditor selection |
| ISO 14001:2015 (cl. 9.2) | Risk-based, organization-defined | Objectivity and impartiality required | Organization defines and records criteria |
| ISO 42001:2023 (cl. 9.2) | Risk-based, organization-defined; ties to AI risk assessment outputs | Auditors must not audit their own work | Organization defines and records criteria |
| IATF 16949:2016 | Fixed 3-year full-scope cycle; annual manufacturing process and product audits | Auditors must not audit their own work | Auditor qualification per IATF-recognized scheme required |
| 21 CFR 820.22 (FDA QSR) | Not specified; must be "established" and followed | Personnel must not have direct responsibility for matters audited | Training records subject to inspection review |
The pattern across every row: independence is non-negotiable everywhere, frequency is almost always left to the organization's own risk judgment except under IATF, and competence has to be documented even where it isn't rigidly prescribed. An auditor who can't produce that documentation on request is the single most common gap I encounter in program reviews.
How to Build a Risk-Based Audit Schedule
A defensible schedule starts with a process risk ranking, not a calendar. List every process in the QMS scope, score each against a small set of criteria — safety/regulatory impact, historical finding count, change frequency, customer complaint volume — and let the score set the base interval. High-risk processes land on a shorter cycle, low-risk stable processes on a longer one, with an explicit trigger list (new process, major change, customer complaint spike, prior major nonconformity) that can pull any process off its scheduled interval and onto an unscheduled audit.
Write the logic down once, in the audit program procedure itself, and then let the annual schedule be a mechanical output of applying that logic rather than a fresh negotiation every January. That's what turns "we audit based on risk" from a phrase in the procedure into something you can actually walk an auditor through with the risk matrix in hand.
Common Internal Audit Program Design Mistakes
The failures I see most often cluster around a handful of patterns: auditing to the clause structure instead of the process, never revising frequency based on findings, letting the same one or two people do every audit regardless of independence, treating internal auditor training as a one-time event, and — the quiet one — never actually checking whether the audit program itself is working. ISO 19011 expects the program to be monitored and improved, the same way any other process is. An audit program that hasn't changed in three years despite changes in the business it's auditing is itself a finding waiting to be written.
The organizations that get real value out of internal audits are the ones that treat the program as a live risk-management tool rather than a compliance obligation to clear once a year. The clause requires a program. It doesn't require it to be any good. That part is on you.
Frequently Asked Questions
How often does ISO 9001 require internal audits? ISO 9001:2015 does not set a fixed frequency. Clause 9.2 requires the organization to plan, establish, implement, and maintain an audit program that takes into account the importance of the processes concerned, changes affecting the organization, and the results of previous audits — meaning frequency has to be risk-based and documented, not arbitrary.
Can the same person audit their own department? No. ISO 9001, ISO 13485, ISO 14001, and 21 CFR 820.22 all require that auditors be independent of the process they audit, meaning they cannot audit work they are directly responsible for. Smaller organizations typically address this through cross-department auditor pools or by bringing in an outside auditor for functions too small to self-audit.
What qualifies someone to be an internal auditor? There is no universal certification requirement under ISO or FDA regulations. The organization must define its own competence criteria — typically a combination of auditor training, supervised audit experience, and knowledge of the relevant standard and process area — and keep records showing each auditor meets them.
Does every process need to be audited every year? Not necessarily. A risk-based program can extend the interval for low-risk, stable processes with a clean audit history while shortening it for high-risk or recently changed processes. What matters to an auditor reviewing your program is that the interval decision is documented and tied to actual risk criteria, not that every process gets audited annually.
How does IATF 16949 change the frequency requirement? IATF 16949 is more prescriptive than the ISO 9001 core requirements: it requires a full audit cycle covering all applicable processes within three years, plus mandatory annual manufacturing process audits and product audits, removing much of the organization's discretion over base frequency that exists under ISO 9001 alone.
For organizations building or repairing an internal audit program from scratch, Certify Consulting's ISO 9001 gap assessment services and our internal auditor training programs are built around this same risk-based logic rather than a generic clause-by-clause checklist.
Last updated: 2026-08-04
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.