top of page
Search

Best Internal Audit Checklist for ISO Systems

Aug 17
6 min read

An internal audit should tell a director or operations manager something useful before a client, regulator or certification auditor tells them first. The best internal audit checklist is not a long list of ISO clauses copied into a spreadsheet. It is a practical test of whether the management system is working in the places where work, risk and decisions actually occur.

For Australian businesses operating in construction, manufacturing, logistics, security, port operations or contracting, that distinction matters. A procedure may look acceptable in a document folder while workers on site use outdated SWMS, supervisors do not close out hazards, or subcontractor records cannot be produced when a principal contractor asks. An effective checklist exposes that gap early and creates a clear path to fix it.

What Makes the Best Internal Audit Checklist?

A useful checklist links three things: the relevant ISO requirement, the organisation's own documented process, and evidence from day-to-day operations. It should allow an auditor to determine not merely whether a policy exists, but whether people understand it, follow it and achieve the intended result.

The right checklist depends on the scope of your system. An ISO 9001 quality audit will focus on customer requirements, process controls, non-conforming outputs and performance. An ISO 45001 audit must give more attention to consultation, hazard management, incident response and legal duties. ISO 14001 requires a clear view of environmental aspects, compliance obligations, operational controls and emergency preparedness.

For an integrated QHSE system, one audit can cover shared elements such as document control, competence, objectives, corrective actions and management review. The technical controls still need to be tested against each applicable standard. Combining everything into one generic form can save time, but it can also hide critical WHS or environmental failures. The balance depends on the risk profile of the business and the maturity of its management system.

Start With Audit Scope, Risk and Objectives

Before using any checklist, define what the audit is intended to examine. A certification-readiness audit will be broader than a targeted audit of contractor management. A business that has recently experienced an injury, customer complaint, environmental spill or tender rejection should focus the audit on the process connected to that event.

Set the audit scope by identifying the location, business unit, activities, applicable standards and audit period. Then identify the people who need to be interviewed and the records that should be available. This prevents audits becoming a document collection exercise performed away from the work area.

High-risk activities should receive greater attention. For example, a fabrication business may need deeper sampling of plant pre-starts, isolation controls, competency verification and hazardous chemical management. A professional services business may place more weight on client requirements, project reviews, training and data control. The checklist should reflect actual exposure, not just the number of clauses in the standard.

Core Sections for an Internal Audit Checklist

A practical checklist usually works best when it is arranged by process rather than reading like the table of contents of an ISO standard. Each question should prompt the auditor to seek evidence, record observations and identify the responsible person where action is needed.

Context, leadership and planning

Begin by checking whether the system still reflects the business. Has the organisation considered relevant legal, client, supplier and operational issues? Are the scope, policies, responsibilities and objectives current? Can managers explain the performance measures they are accountable for?

For WHS, look for evidence that officers and senior leaders are exercising due diligence. That may include receiving information about incidents, hazards, legal compliance, training, resources and corrective actions. A signed policy alone does not demonstrate active oversight.

Risk, legal and operational controls

This is where the audit must leave the office. Verify that risk assessments match current work, workers have access to required controls, and changes to equipment, processes, sites or personnel are assessed before work starts.

For ISO 45001 systems, assess consultation with workers and health and safety representatives where applicable. Inspect whether hazards are reported, investigated and closed out. Confirm licences, competencies, inductions, PPE, plant inspections and emergency arrangements are suitable for the work being performed.

For ISO 14001, test controls around waste, chemicals, emissions, noise, spills and environmental incidents. The relevant requirements will vary by operation, site and approvals. The audit should confirm that the business knows its obligations and can demonstrate compliance, rather than assuming a register is sufficient.

Documented information and competence

Check whether workers are using current documents at the point of use. Obsolete forms, uncontrolled printed procedures and incomplete records are common findings because they often develop as operations change faster than the system.

Also test competence beyond training attendance. Ask workers to explain key controls relevant to their task. Observe the work where possible. A completed induction record is evidence that information was delivered; it is not, by itself, evidence that the person can carry out the work safely and correctly.

Suppliers, contractors and customer requirements

Many businesses have sound internal controls but weak external-party management. The checklist should examine whether suppliers and subcontractors are selected against defined criteria, appropriately inducted, monitored and reviewed.

For procurement-facing businesses, this evidence can directly affect tender eligibility. Principal contractors and Tier 1 clients commonly request current insurances, licences, policies, risk assessments, incident data, worker competencies and supplier controls. An internal audit should identify missing or inconsistent evidence before it is required under a short tender deadline.

Performance, incidents and improvement

Review leading and lagging indicators, but do not treat the figures as proof of good performance without context. A low incident rate can reflect effective controls, under-reporting or simply a quiet period. Compare data with hazard reports, worker feedback, inspections, corrective actions and changes in work volume.

Test the full corrective action process. Is the issue clearly described? Has the root cause been considered? Is the action assigned, resourced and given a due date? Most importantly, has someone verified that the action was effective after implementation?

Questions That Produce Useful Evidence

The strongest checklist questions do not invite a simple yes or no answer. They ask for evidence and make it difficult to accept assumptions. For example:

  • What changed in this process during the audit period, and how was risk assessed before the change?

  • Show how workers were consulted about the most recent safety or environmental issue.

  • Which current legal, contractual or client requirements apply to this activity, and how is compliance checked?

  • Select a recent corrective action. What evidence shows the action prevented recurrence?

  • Observe the task or inspect the work area. Do the documented controls match what is happening?

Questions of this kind make interviews, records and site observations work together. If the evidence conflicts, the auditor should record the gap rather than deciding that the paperwork is enough.

Record Findings Clearly and Fairly

An internal audit report should distinguish between conformity, nonconformity, observation and opportunity for improvement. The terminology should align with your management system and certification approach, but the principle is simple: findings must be factual, traceable and useful.

A good finding identifies the requirement or internal process, the evidence observed and the nature of the gap. Avoid vague statements such as “safety documentation needs improvement”. A clearer finding might state that three sampled plant inspection records were overdue, contrary to the organisation's inspection schedule, and that the plant was available for use at the time of audit.

Not every issue needs to be escalated as a major system failure. However, repeated minor gaps, overdue actions or controls that exist only on paper can indicate a larger failure of implementation. Consider consequence, recurrence, legal exposure and the likelihood that the issue would affect certification, a client audit or worker safety.

Turn Audit Results Into Operational Improvement

The audit is only valuable if findings lead to action. Assign corrective actions to people with authority to change the process, not simply the person who found the problem. Set realistic due dates, provide resources where needed and require evidence of completion.

Management should review significant findings for trends. If several locations have incomplete inductions, the answer may not be to chase individual records. The underlying issue could be an impractical onboarding process, unclear ownership or a system that supervisors cannot access easily from site.

The Safety Hand approaches internal audits as an operational test of a system, not a paperwork review. That is particularly valuable when preparing for ISO certification, maintaining an existing certification, responding to a client requirement or strengthening director oversight.

A checklist earns its place when it helps the business make better decisions: what needs attention now, who owns the fix, and how the organisation will prove the control works next time it is tested.

 
 
 

Comments


bottom of page