A clean internal audit report feels good. No nonconformities, no observations, no corrective actions. Everything checked, everything compliant, move on.
But when every audit ends that way, year after year, across every process, it is fair to ask: are auditors testing the QMS, or taking a guided tour through it?
A strong audit program is not supposed to manufacture findings. Its job is to determine whether the system conforms to applicable requirements, is effectively implemented and maintained, and produces the intended results. That takes more than confirming that procedures exist. It means testing the process and following evidence where it leads.
The purpose of the auditThe goal is not a clean report or a long list of findings. The goal is useful assurance about whether the QMS is working, and early visibility when it is not.
A zero-finding audit is not automatically a bad audit
A well-controlled process can be audited without a finding. The concern is a repeated pattern of clean reports across a changing QMS where complaints, CAPAs, process changes, supplier issues, training gaps, turnover, new equipment, missed metrics, or workarounds still exist.
Processes drift, people adapt, and documents lag behind practice. If audits never notice these signals, challenge the audit approach. A clean report may reflect strong control, or a narrow sample that never got past the checklist.
Test the system, not just its paperwork
If the objective is only to confirm compliance, auditors may look for evidence that supports an expected answer. A better objective is to determine whether the process is controlled, effective, and operating as intended.
Instead of, “Do you have an SOP?”, ask, “Show me how this work is done.” Instead of confirming training, ask how the organization knows people can perform the task correctly. That is the difference between training completion versus demonstrated competency.
Ask how recurrence was checked after a CAPA, review current supplier performance, and ask what decision a metric informed. These questions test the process, not just whether its records exist.
A checklist should guide the audit, not become the audit
An internal audit checklist helps auditors work consistently and remember requirements. It becomes a problem when completion is treated as proof of effectiveness.
Training example
The procedure is available, training records are complete, and employees have signed. That does not show whether they understand the critical steps, the procedure matches actual work, or errors continue after training. Records and observation answer different questions.
A practical ruleA checklist should guide the audit. It should not prevent the auditor from following the evidence.
Follow the process, not just the procedure
Pick a real change or quality event and follow it from trigger through outcome. For change control, ask what prompted it, who assessed impact and risks, which documents needed revision, whether training or validation applied, how implementation was confirmed, and whether the change achieved its intended result.
A complete change form can coexist with incomplete implementation. Compare the documented steps with work at the point of use, including whether the SOP matches actual practice. Use the same method for complaints, calibration, suppliers, training, document control, risk, and corrective action.
Audit the handoffs
Many QMS weaknesses appear between processes. Consider this chain:
Deviation → CAPA → Change Control → Document Revision → Training → Effectiveness Check
Every record can look complete while a handoff is missed. Did the CAPA trigger a change? Did the revision trigger training before the new process began? Was effectiveness checked, and did the issue return?
Follow the connections that explain how disconnected QMS processes allow problems to recur. A mature QMS should tell one quality story.
Strong audit questions start with “show me”
Ask for a sample and look at what happened.
| Instead of asking | Ask for evidence |
| Would you open a deviation if this happened? | Show me the last three deviations opened by this department. |
| Do supervisors review training? | Show me how training requirements were identified for this employee. |
| Do you monitor suppliers? | Show me recent performance data for a high-risk supplier. |
| Does management review quality performance? | Show me a decision leadership made using information from management review. |
“Show me” moves the audit from intent to evidence. Then sample records, interview people doing the work, observe a process, and follow unexpected results.
Use QMS data before the interview starts
Before the audit, review previous findings, CAPA trends, repeat deviations, complaints, overdue training, supplier performance, process measures, rework, scrap, calibration failures, changes, turnover, returns, and missed quality objectives.
Six CAPAs, several complaints, or overdue actions should influence the audit plan. Process importance, risk, change, prior results, and performance guide where auditors spend time. Frequency and depth can vary. For a broader view of QMS audit readiness, connect risk-based planning to the rest of the system.
Know when to leave the checklist
An employee says, “We do not really use that procedure anymore. We use the spreadsheet the supervisor made.” It may not appear on the checklist, but it could be the most important thing the auditor hears all day.
Ask to see the spreadsheet. Who approved it? How is it controlled and kept current? Does the procedure reflect the work? Follow the evidence and understand the process before deciding what the observation means.
Use judgmentAuditing is not a script. If auditors are afraid to follow unexpected evidence because it falls outside the checklist, the organization loses much of the audit's value.
Findings are not failures of the audit program
Departments may want clean reports, and auditors may avoid conflict. A weakness found internally gives the organization a chance to respond before an outside party finds it.
- Internal audit finding: your organization found it.
- Certification audit finding: the certification body found it.
- Customer audit finding: your customer found it.
- Regulatory observation: the stakes may be significantly greater.
A finding does not prove the QMS has failed. Ignoring a credible weakness because everyone wanted a clean report may say more about the system than documenting it and taking appropriate action.
Do not measure audit success by finding count
Do not set a quota such as “two findings per audit.” It rewards noise. A valid conclusion may be that the process is effective, controls work, prior actions remain effective, and no nonconformities were identified.
That conclusion should follow meaningful testing, not only a procedure review and signature check. The goal is useful information about performance, risk, and improvement.
Five signs your internal audits may be too shallow
- Every audit uses the same checklist every year.The organization changes. The audit should respond to relevant changes, risk, and previous results.
- Auditors spend nearly all their time in a conference room.Documents matter, and so does observing the process where work happens.
- Only managers are interviewed.The people performing the work often know where the process struggles or where workarounds have emerged.
- Records are rarely followed across processes.CAPA, change control, training, document control, risk, and suppliers often interact.
- Reports describe conformity but say little about effectiveness.A process may meet a documented step and still perform poorly or allow repeat problems.
Four questions a better internal audit should answer
- Are we doing what we said we would do?Compare actual practice with the documented process.
- Are we meeting applicable requirements?Consider the organization's own, customer, contractual, and applicable QMS requirements.
- Is the process working?Review results, errors, complaints, trends, and recurring problems.
- Are weaknesses identified and improved?Determine whether the organization learns from problems or keeps working around them.
That is more valuable than a completed checklist. It also gives leadership information it can act on, including what leadership should actually review.
Audits should challenge assumptions fairly
Internal audits need not be adversarial, but they should test assumptions. If training works, review competency evidence. If supplier performance is strong, examine failures. If CAPA is effective, look for recurrence. If the procedure reflects the process, observe the work.
Audit provides value when it gives leadership information the organization did not already know. If it confirms only what everyone expected, ask how much assurance it provided.
What ISO 9001:2026 means for internal audits
ISO 9001:2026 was published on September 16, 2026. Planned audits provide information about whether the QMS conforms to the organization's requirements and ISO 9001, and is effectively implemented and maintained.
Organizations define audit objectives, criteria, and scope, and consider process importance, previous results, and organizational changes when planning the program. Auditors should be objective and impartial. Report results to relevant management, and take needed correction and corrective action without undue delay.
This is a practical summary, not a clause-by-clause explanation. The point is to use audits to evaluate conformity and effectiveness, not to create a finding quota. See ISO's official ISO 9001:2026 page for the published edition and obtain the licensed standard for its complete requirements.
If your internal audits never find anything, ask why
Maybe the QMS is performing exceptionally well. But if processes are changing, quality events are occurring, employees are adapting the work, customers are raising issues, and every audit is perfectly clean, evaluate the audit process itself.
A good internal audit is a structured attempt to determine whether the QMS is working, not a scavenger hunt for signatures. The goal is useful truth, not a finding count.
TakeawayThe best time to discover a weakness in your QMS is when your own auditor finds it. Not your customer. Not your registrar. And not your regulator.