Quick Summary: A quality management system internal audit is a systematic, in-house review to verify that your business operations align with established standards, policies, and objectives. It's a critical tool for ensuring compliance with standards like ISO 45001, identifying risks, and driving continuous improvement in safety and efficiency.

A quality management system internal audit is essentially a structured look in the mirror for your business. It's an in-house review to make sure your day-to-day operations actually line up with the standards you’re meant to follow, your own policies, and your overall business goals. Think of it as a methodical way to confirm you’re not just saying what you do, but really doing what you say—especially when it comes to crucial areas like worker safety and process quality.

This guide reframes that audit process. It’s not just a box-ticking exercise for compliance; it's a powerful tool for making your business safer, smarter, and more efficient.

Transforming Audits From Requirement to Resource

For many Australian businesses, especially in fields like construction and manufacturing, the words "internal audit" often bring on a sigh. It can feel like just another chore you have to do to keep your certifications. But if that's all you see it as, you're missing out on a massive opportunity.

A well-executed internal audit is one of the most effective tools you have for driving real, measurable improvement.

It’s about moving beyond simply checking for compliance. A great audit becomes a strategic deep dive that uncovers hidden risks, flags inefficient processes, and even sparks ideas for innovation. Getting your team to see it this way is a game-changer—it turns a potentially disruptive task into a genuinely valuable activity everyone can get behind.

The Real ‘Why’ Behind the Audit Process

At its heart, an internal audit is about two things: verification and improvement. It provides you with objective proof that your quality management system (QMS) isn't just a document sitting on a shelf, but a living, breathing part of your business that works. For any business serious about safety, that’s everything.

A good audit gives you a clear line of sight into:

  • Conformance: Are we actually following the rules of standards like ISO 45001 and our own internal procedures on the ground?
  • Effectiveness: Is our system working? Is it preventing incidents, cutting down on defects, and making work safer for our people?
  • Resilience: Can our processes withstand pressure or unexpected hiccups without compromising on quality or safety?

This process isn’t a one-off event; it’s a continuous cycle of planning, checking, and improving.

Diagram illustrating the three steps of the QMS audit cycle: planning, doing, and reporting.

This constant loop ensures that what you learn from one audit feeds directly into the next one. That’s how you build a genuine culture of continuous improvement, not just a series of standalone checks.

To get a clearer picture, let's break down the audit cycle into its core phases. This gives you a high-level roadmap of the entire process, from that initial planning meeting right through to making long-term improvements.

The Four Phases of the Internal Audit Cycle

Audit PhaseCore ObjectiveKey Activities
1. Planning & PreparationEstablish clear goals and scope for the audit.Defining objectives, selecting the audit team, creating checklists, and scheduling interviews.
2. Conducting the AuditGather objective evidence to assess conformance and effectiveness.Performing interviews, observing processes, reviewing records, and sampling documentation.
3. Reporting & AnalysisCommunicate the audit results clearly and objectively.Documenting findings (conformances and non-conformances), analysing root causes, writing the audit report.
4. Follow-up & ImprovementEnsure corrective actions are effective and drive continuous improvement.Verifying corrective actions, closing out findings, and feeding insights into the next audit cycle.

Each of these phases builds on the last, creating a robust framework that turns the audit from a simple check-up into a catalyst for positive change.

Defining a Clear Audit Scope and Objectives

To really make audits a powerful resource, it helps to think about them in the same way you’d approach other quality assurance processes. For instance, in the world of construction, building commissioning is a systematic process to verify that a building’s systems work as designed. An internal audit needs that same level of focus.

It all starts with a well-defined scope and crystal-clear objectives. Without this, an audit can easily wander off course, becoming a massive time-sink that produces very little useful information. The scope sets the boundaries—which departments, processes, or locations will you look at? The objectives spell out what you hope to find out.

A well-planned audit answers specific questions. Instead of a vague goal like, "Is our safety system working?", a much better objective is, "To verify that the new forklift pre-start checklist procedure, implemented in March, is being followed correctly by all warehouse staff." That kind of specificity is what delivers real value.

Imagine you're running a construction company in Adelaide. Your audit scope might be narrowed to just one high-risk activity, like working at heights on the new commercial project downtown. The objective would be to confirm that every single related safety procedure—from harness inspections to the Safe Work Method Statements (SWMS)—is being followed to the letter.

By narrowing the focus, you get a deep and meaningful review instead of a shallow, surface-level check. As you learn more about what it takes to get and maintain an ISO 45001 certification, you'll see how this targeted approach is essential for compliance. More importantly, it ensures every audit gives you concrete, actionable insights that strengthen your entire business.

Putting Together Your Internal Audit Program and Team

A solid quality management system internal audit doesn't just happen. It’s the result of a thoughtful, well-designed program that acts as the backbone for your entire audit effort. Think of it less as a rigid calendar of dates and more as a strategic roadmap, guiding you to focus on what truly matters.

For a small or mid-sized Aussie business, this means ditching the one-size-fits-all approach. Your goal should be an annual program that’s directly linked to risk. It’s common sense, really: high-stakes processes, like those directly affecting worker safety or product quality, need a closer look more often than low-risk admin tasks.

Designing an Audit Schedule That Makes Sense

Taking a risk-based approach is simply the most efficient way to use your time and resources. It stops your team from feeling like they’re constantly under the microscope—what we call "audit fatigue"—and directs your energy toward the areas that could really hurt the business if they went wrong.

So, how do you build this schedule? Start by mapping out your key processes and then prioritise them. You’ll want to consider a few things:

  • Past Performance: Where have things gone wrong before? Any process that has a history of nonconformities or incidents should be at the top of your list for more frequent checks.
  • Process Criticality: How crucial is this step to your final product or the safety of your people? A failure in a critical welding procedure, for instance, carries a hell of a lot more risk than a simple filing mistake in the office.
  • Recent Changes: Have you brought in new equipment, hired new people, or changed a procedure? Any change introduces new, unknown risks, so it's smart to audit these areas sooner rather than later to make sure everything is working as it should.

Once you rate your processes against these criteria, a natural schedule will start to take shape. Your high-risk areas might get a look-over every six months, while stable, low-risk processes might only need a check-in every 18 months or so.

Finding the Right People for Your Audit Team

Your audit program is only ever as good as the people running it. The success of any quality management system internal audit comes down to the competence and objectivity of your auditors.

An internal auditor isn't there to play "gotcha." They're a fact-finder, and the role demands a unique mix of technical know-how and people skills.

A great auditor is curious, objective, and diplomatic. Their goal isn't to find fault with people but to find facts that expose weaknesses in the system.

Here are the non-negotiables for an effective internal auditor:

  • Objectivity: This is crucial. The auditor must be completely independent of the area they are auditing. You can't have the workshop manager auditing their own team’s work—it’s a clear conflict of interest.
  • Process Knowledge: They need to properly understand not just the process they’re looking at, but also the standards they’re auditing against, like ISO 45001.
  • Communication Skills: An auditor has to be able to ask good, clear questions, really listen to the answers, and then report what they find in a constructive, evidence-based way.

The Power of a Co-Sourced Audit Model

Let's be realistic. For many small and mid-sized businesses, building a fully independent internal audit team with all the right expertise is a big ask. This is where a hybrid or co-sourced model can be a game-changer. It’s all about combining the deep operational knowledge of your own staff with the fresh eyes and specialised expertise of an external consultant.

This approach genuinely gives you the best of both worlds. Your people know the business inside-out, while the external auditor brings impartiality and an expert-level understanding of the standards. It also becomes a brilliant professional development opportunity, as your internal team learns new skills with every audit they're part of.

No matter which model you choose, maintaining professional standards is essential. A report from the Victorian Auditor-General's Office found that only co-sourced teams were consistently meeting the Institute of Internal Auditors (IIA) Standards for performing regular external quality assessments. This just goes to show how an external partner can help keep things rigorous and ensure your audit function is up to scratch. You can dig into the findings on internal audit performance in their full report.

In the end, whether you build a team in-house or co-source, the objective is the same: you need competent, objective auditors who can give you a clear, honest picture of your business. If you're interested, we have a detailed breakdown of what an ISO internal audit involves.

Mastering the On-Site Audit: From Plan to Practice

Okay, you've mapped out your audit programme and your team is prepped. Now it's time to move from the planning phase into the real world. The on-site part of a quality management system internal audit is where the rubber meets the road—it’s where you gather the hard evidence to see if your system is actually doing what it's supposed to.

Getting this right isn't about catching people out; it's about uncovering facts. A methodical, respectful approach is your best bet for gathering accurate information that will genuinely help the business improve.

A man in a face mask and cap writes on a clipboard during an on-site audit in a factory.

Developing a Checklist That Is Actually Useful

Think of your audit checklist as your most important tool on-site. It's much more than a simple to-do list; it’s your roadmap, keeping you focused on the audit's objectives and ensuring you don't miss anything critical. A generic template you've downloaded from the internet just isn’t going to cut it here.

A truly effective checklist is one you've customised for your own operations. It needs to be directly linked to the standards you're auditing against, whether that's ISO 9001 or specific OHS requirements like ISO 45001.

Here’s how to build one that works:

  • Turn Clauses into Questions: Take a clause from the standard—say, one on hazard identification—and rephrase it as a practical, open-ended question. Something like, "Show me how your team completes a pre-start risk assessment for this piece of machinery."
  • Weave in Your Own Procedures: You're not just auditing against the standard; you're checking compliance with your own internal documents. Add questions that reference your Safe Work Method Statements (SWMS), policies, and work instructions. For example: "Can you walk me through the steps you follow for the lockout-tagout procedure, as it's written in SWMS-003?"
  • Leave Room to Write: This might sound obvious, but your checklist needs plenty of space to jot down what you see, who you talk to, and which documents you review. These details are gold when you're writing your final report.

This level of preparation elevates your checklist from a memory aid to a dynamic tool for conducting a thorough quality management system internal audit.

The Art of Gathering Evidence

Once you're on the factory floor or in the office, your primary mission is to collect objective evidence. This is the verifiable, factual information that proves whether a process meets the required standard. There are three main ways to do this: interviewing staff, reviewing documentation, and observing work as it happens. A sharp auditor knows how to blend all three to build a complete and accurate picture.

The golden rule of auditing has always been 'Trust, but verify.' An interview tells you how a process is meant to work. Observation and records show you what actually happens day-to-day.

To do this effectively, you need to understand the strengths and weaknesses of each technique.

A Comparison of Evidence Gathering Techniques

This table breaks down the three core methods for collecting audit evidence. Understanding the pros and cons of each will help you choose the right approach for any given situation.

TechniqueDescriptionIdeal for VerifyingCommon Pitfall to Avoid
InterviewsSpeaking directly with employees involved in the process being audited.Understanding of procedures, awareness of safety policies, and the 'why' behind actions.Asking leading questions that suggest a 'correct' answer, or making the employee feel intimidated.
ObservationWatching a process or task being performed in its natural work environment.Actual adherence to safety procedures, use of personal protective equipment (PPE), and workplace conditions.The 'Hawthorne effect,' where people behave differently simply because they know they are being watched.
Document ReviewExamining records, procedures, forms, and other documentation.Record-keeping accuracy, completion of required checks (e.g., maintenance logs), and traceability.Only reviewing the 'perfect' examples provided; it’s crucial to use sampling to see a true cross-section.

By combining these methods, you can cross-reference what you’re told with what you see and what’s on paper, giving you a much more reliable audit outcome.

Conducting Effective Interviews

How you speak to people during an audit is everything. Remember, your goal is to gather information, not to conduct an interrogation. The key to getting honest, useful answers is making staff feel comfortable and respected.

Start by explaining that the audit is about checking the system, not the person. Frame your questions in an open-ended way to encourage a proper conversation. Phrases like "Can you tell me about…" or "How do you handle…?" work far better than a string of 'yes/no' questions that can feel like a test.

For example, imagine you're on a construction site in Perth. Instead of asking a blunt question like, "Do you inspect your harness before use?", try this: "Can you show me how you inspect your harness before you start work at heights?"

This approach gets the team member to actively demonstrate their knowledge and practice, which gives you much richer, more reliable evidence. The key is to keep it conversational and professional, ready to navigate any tricky conversations with a bit of diplomacy.

From Observations to Action: Documenting Findings and Driving Real Change

The real value of an internal audit isn't found during the interviews or the document reviews. It’s what happens after. This is where your on-site observations transform into documented findings, creating the spark for genuine, lasting improvement in your quality management system.

Your goal here is to do more than just point out problems. It's about kicking off a process that leads to meaningful solutions, ensuring your audit report becomes a road map for positive change, not just another document filed away.

How to Classify Your Audit Findings

Not all findings carry the same weight. To help management understand the urgency and risk, you need to classify what you’ve found. This is crucial for prioritising what gets fixed first.

In my experience, almost all findings fall into one of these three buckets:

  • Major Nonconformity: Think of this as a serious breakdown in your system. It could be a complete failure to meet a key part of the standard or a situation that puts your product, service, or people at significant risk. For example, if you discovered that none of the mandatory daily pre-start checks on high-risk equipment had been done for a week, that's a major problem.
  • Minor Nonconformity: This is more of an isolated slip-up. It's a failure to follow a procedure in a single instance, but it doesn't signal a total system collapse. A good example is finding one fire extinguisher out of ten has missed its monthly inspection tag. It's a weakness you need to fix before it grows.
  • Opportunity for Improvement (OFI): An OFI isn’t a failure at all. It’s a suggestion for making a good process even better. You might see a paper-based form that’s technically compliant but keeps getting lost. Suggesting a move to a simple digital version to reduce that risk is a classic OFI.

It's worth remembering that classifying findings is about bringing clarity to a situation, not assigning blame. Every finding, no matter the type, is an objective, evidence-based statement about a process—not a person.

Writing Findings That Actually Lead to Change

The way you word a finding makes all the difference. Get it wrong, and people get defensive. Get it right, and you provide a clear, undeniable path to a solution.

A solid finding always has three distinct parts:

  1. The Problem Statement: A short, sharp sentence explaining what’s wrong.
  2. The Evidence: The objective proof you collected. Be specific. "Reviewed maintenance log #ML-123," "observed operator at workstation B," or "interviewed the site supervisor."
  3. The Requirement: The specific rule that was broken. This could be a clause from the standard (like ISO 45001 Clause 8.1.2) or a step in your own internal procedure.

Let’s put it into practice. Imagine you're auditing a small manufacturing business in Victoria. You might write: "The procedure for handling hazardous chemicals was not followed. I observed two unmarked containers of solvent in the main workshop, which is contrary to internal procedure CHEM-004 and OHS regulations." It’s clear, fact-based, and gives the team everything they need to start fixing it.

Getting Past the Quick Fix to Find a Real Solution

When a nonconformity pops up, the first instinct is always to apply a band-aid. An uncalibrated gauge? Simple, recalibrate it. A missing signature? Just get someone to sign the form.

While you do need to fix the immediate issue, these actions are just containment. They are not corrective actions. They stop the bleeding but do nothing to heal the wound.

A true corrective action gets to the root cause of the problem to make sure it never, ever happens again. This means you have to dig a bit deeper and ask "why?" a few times. This is where a simple Corrective Action Plan (CAP) becomes indispensable.

Let's walk through an example:

  • Problem: A safety guard was removed from a machine. (The quick fix is to put it back on).
  • Why was it removed? Because it was slowing down production.
  • Why did it slow things down? Because it was a pain to adjust for different jobs.
  • Why was it a pain to adjust? The adjustment mechanism was poorly designed.
  • Root Cause: A design flaw in the guarding itself.
  • Corrective Action: Redesign the guard so it can be adjusted easily without being removed.

This process is exactly how a quality management system internal audit drives lasting improvement. It's no surprise that organisations get better at this over time. For instance, data from Australia's Therapeutic Goods Administration (TGA) shows that between July 2021 and June 2023, the average number of major nonconformities per audit dropped from 3.4 to 1.9. This drop didn't happen by magic; it reflects how a mature QMS, consistently sharpened by effective internal audits and root cause analysis, systematically eliminates risks. You can dig into the numbers yourself in the TGA's public report on QMS audits.

By focusing on root causes and following up to verify your solutions have worked, you turn your audit from a simple compliance tick-box into a powerful engine for improving your business.

Reporting Results to Inspire Action

So, the on-site work is done and you've documented your findings. You might think the heavy lifting is over, but honestly, the most critical part of any quality management system internal audit is just beginning. How you communicate the results is everything—it's the difference between sparking real, meaningful improvement and writing another report that gathers dust on a shelf.

A great audit report doesn’t just list problems. It tells a clear, compelling story that gets management to sit up, take notice, and, most importantly, take action. Think of the audit's conclusion not as the end, but as the kick-off for the next improvement cycle.

A tablet, pen, and document on a wooden table in a meeting room with a 'INSIGHTS FOR ACTION' sign.

Structuring a Report That Actually Gets Read

Let’s be realistic: senior managers are incredibly time-poor. If you hand them a dense, fifty-page report loaded with jargon, you've lost before you've even started. Your report's structure needs to be built for a quick scan, allowing a busy director to grasp the key takeaways in just a few minutes.

The golden rule is to lead with the most important information. Start with a sharp, concise summary that gives a high-level view of the audit's outcome before you get into the weeds.

From my experience, this is a structure that works every time:

  • Executive Summary: A one-page snapshot is all you need. Cover the audit’s purpose, the most significant findings, and your overall conclusion. This is the part that will get the most attention.
  • Audit Scope and Objectives: Briefly remind everyone what was audited. Which departments, processes, or locations were included? What did you set out to achieve?
  • Positive Observations and Strengths: An audit shouldn't be all doom and gloom. Highlighting what the team is doing right builds morale and reinforces good habits. Don't skip this.
  • Summary of Findings: This is where you list the nonconformities (both major and minor) and opportunities for improvement. Keep it factual and avoid a blame-game tone.

This logical flow gives the reader immediate context, shows them the good before the bad, and paints a clear, honest picture of the system's health.

Presenting Findings to Secure Management Buy-In

Your goal isn't just to inform management; it's to persuade them. You need to frame your findings in a way that connects directly to what they care about most: risk, efficiency, and the bottom line. Don't just state a problem—explain its potential impact on the business.

For example, a finding about poor record-keeping isn't just a minor admin slip-up. Frame it as a genuine business risk: "This could cause us to fail a tender pre-qualification," or "This could lead to a compliance breach during a WorkSafe inspection." Suddenly, it’s not so minor anymore.

Expert Tip: I always link my audit findings directly to business objectives. When a nonconformity is presented as a roadblock to winning a major contract or a direct threat to worker safety, it gets immediate attention and the resources to fix it.

This kind of strategic communication is a big reason why Australian organisations are often so good at acting on audit recommendations. A benchmarking study revealed that 85.5% of Internal Audit Managers in Australia agreed that management consistently follows through on their findings. This shows that when reports are framed correctly, they’re seen as vital tools for business improvement. You can dig into the data in this benchmarking comparison of internal audit effectiveness.

Closing the Loop with Management Reviews

The audit process isn't truly finished until its findings are tabled and discussed at your management review meetings. This is the crucial step that creates accountability and formally closes the loop on the entire quality management system internal audit cycle.

During the management review, your report becomes a key piece of evidence, allowing leadership to:

  • Assess QMS Performance: The results provide a clear, evidence-based snapshot of how well the system is actually working.
  • Allocate Resources: Management can see precisely where they need to invest in more training, better equipment, or process improvements.
  • Drive Continual Improvement: The findings become official action items, complete with owners and deadlines. This ensures the lessons from the audit fuel the next wave of improvements.

By embedding the audit outcomes into these high-level, strategic discussions, you guarantee the whole process contributes to building a healthier, safer, and more resilient business. That, right there, is the mark of a truly mature and effective QMS.

Common Questions About QMS Internal Audits

Even with the best plan in the world, questions always come up when you're in the thick of a quality management system internal audit. It’s a common experience, especially for Australian businesses trying to juggle compliance with the everyday reality of getting the job done. Let's tackle some of the most frequent queries we get from clients.

How Often Should We Conduct Internal Audits?

There’s no magic number here, as the right audit frequency really comes down to your specific business. As a general rule of thumb, though, you should aim to cover your entire QMS at least once a year. This gives you a solid baseline and ensures nothing gets missed for too long.

But a far better approach is to think in terms of risk. Your high-risk areas—the ones that directly affect product quality or, crucially, your team's safety—need more attention. Auditing these every six months is a smart move. On the other hand, stable, low-risk administrative processes might be perfectly fine with a check-in every 18 months. It's about putting your focus where it matters most.

Can We Use Our Own Staff as Internal Auditors?

Yes, and you absolutely should! Using your own people is a fantastic way to go, as they already have an intimate understanding of how your business actually works. There’s just one golden rule you can't break: the auditor must be independent of the area being audited.

For example, you can’t have your warehouse manager audit the warehouse’s own processes. That’s a clear conflict of interest and it defeats the purpose of an objective review. A great strategy is to cross-train staff from different departments to audit each other. This not only guarantees impartiality but also helps spread valuable process knowledge across the company.

What Is the Difference Between an Internal and External Audit?

This one trips a lot of people up, but the distinction is pretty simple. They serve completely different functions.

  • Internal Audits (First-Party): Think of these as a self-check. They're conducted by your team, for your team. The whole point is continuous improvement—finding and fixing issues before they escalate and getting your systems ready for the real deal.

  • External Audits (Third-Party): These are carried out by an independent certification body, like the ones who grant ISO 45001 certification. Their job is to formally verify if your QMS meets the standard. The result determines whether you get or keep your certificate.

An internal audit is like the team running drills and practice plays before the grand final. The external audit is the grand final.

What Happens if a Nonconformity Is Found?

Finding a nonconformity isn’t a sign of failure; it's a sign that your audit process is working. Honestly, it's an opportunity. It means you've successfully pinpointed a weakness before it could cause a real headache.

When you find one, the first job is to contain the immediate issue. But the more important task is to kick off your corrective action process. This means digging deep to find the root cause—don't just patch the symptom, ask "why" until you get to the source—and then putting a fix in place to make sure it can't happen again.

Do We Need Special Software for Our Audits?

It’s not an absolute must-have, but dedicated software can be a game-changer for your efficiency, particularly as you scale. A modern Quality Management Software platform helps you:

  • Schedule and keep track of your entire audit programme.
  • Manage checklists and store evidence without a mountain of paper.
  • Log nonconformities and follow corrective actions through to completion.
  • Generate professional reports without spending hours formatting spreadsheets.

For a small business, a well-organised folder system might do the trick to start. But as your operations get more complex, a digital QMS can save a huge amount of admin time and minimise the risk of important tasks getting lost in the shuffle.


A well-run quality management system internal audit is one of the most powerful tools you have for strengthening your business, keeping your team safe, and winning bigger contracts. At ISO45001 Consulting, we specialise in helping Australian businesses build practical, effective safety management systems that get real results. We take the guesswork out of the process, guiding you from the initial setup all the way to certification and beyond.

Ready to turn your compliance work into a genuine competitive advantage? Contact us today to get started.