The ISO 9001:2026 Internal Audit Checklist, Clause by Clause

ISO 9001:2026 · Internal audit

The 2026 internal audit checklist

What changed for internal audit in the sixth edition, how to write the objective sentence clause 9.2.2 a) now requires, a full clause-by-clause checklist with the 2026 rows flagged, and the ten findings we expect most.

By Mthokozisi Nkosi, Food Scientist & Lead AuditorUpdated 23 September 202613 min read

The short answer

An ISO 9001:2026 internal audit has to do three things the 2015 edition did not require in the same way. Clause 9.2.2 a) now requires you to define the audit objectives, criteria and scope for each audit, so every audit plan carries an objective sentence. Clause 6.1.3 means opportunities are audited separately from risks. And clause 7.3 e) means awareness of quality culture is tested by interviewing people, not by reading an attendance register.

Everything else about internal auditing still follows ISO 19011, now in its fourth edition as ISO 19011:2026, which adds guidance on remote auditing and virtual locations.

What changed for internal audit in 2026

Clause 9.2 keeps its shape. You still need an audit programme, competent and impartial auditors, results reported to relevant management, and retained documented information. Three things are genuinely different.

Change What it means for your audit Evidence to produce
9.2.2 a) adds “objectives” Previously you defined criteria and scope. Now each audit also has stated objectives: what this audit is trying to find out One objective sentence on every audit plan, every time
6.1.2 and 6.1.3 are separate Sampling “the risk register” no longer covers the clause. Risks and opportunities are separate requirements with different required steps Separate checklist rows for 6.1.2 and 6.1.3, and evidence you sampled both registers
7.3 gains e) quality culture Awareness now includes the organizational quality culture and ethical behaviour. This is an interview test Interview notes recording what operators said in their own words, across shifts
9.1.3 goes to eight items Analysis and evaluation now splits risk-action effectiveness from opportunity-action effectiveness at e) and f) Check both lines exist in the analysis, not one combined line
9.3 goes to eight inputs Adds c) changes in needs and expectations of interested parties, and splits risks and opportunities at g) and h) Check the agenda has eight headings and the minutes follow them
Clause 10 has two sub-clauses The old 10.3 is gone. References to it in your own procedures are now dead Check your documents do not cite 10.3

The 123-row internal audit checklist is in the toolkit. It walks every sub-clause from 4.1 to 10.2 with the 2026-specific rows flagged, so a transition audit and a full system audit come from the same file. It ships with audit plan and report templates carrying the 9.2.2 a) objective line.

The audit programme vs the audit plan

These are two documents and auditors find sites confusing them constantly.

Once a year

The audit programme

Covers the whole cycle. Which processes get audited, when, by whom, and how often. Frequency has to reflect the importance of the process, changes affecting it, and the results of previous audits, so a process that failed last time should appear more often, and you should be able to show that it does.

Every audit

The audit plan

One per audit. Date, auditor, auditee, the processes in scope, the criteria, and now the objectives. This is the document 9.2.2 a) lands on. It is also what you hand the auditee beforehand.

The most common 9.2 finding has not changed. A programme that shows every process audited once a year, at the same frequency, with no reference to previous results or to changes, is a schedule rather than a programme. Add a column for “why this frequency” and populate it from last year’s findings.

Writing the 9.2.2 a) objective sentence

An objective says what the audit is trying to establish. It is not the same as scope (what is covered) or criteria (what you are auditing against). One sentence is enough, but it has to be specific to this audit.

Weak: do not use Better
“To audit the process for compliance.” “To determine whether colour acceptance criteria on Line A are defined in controlled documents, applied at the press, and produce records that match the master specification.”
“Internal audit of clause 6.” “To determine whether the 6.1.3 opportunity register has entries taken through all seven steps, and whether at least one entry has a dated effectiveness review.”
“To check the QMS.” “To determine whether the actions from the three major findings raised in the March audit have been implemented and are effective.”
“Compliance with ISO 9001:2026.” “To determine whether operators across both shifts can describe the quality culture expectations in their own words, as required by 7.3 e).”

Scope is where you look. Criteria are what you measure against. Objectives are what you are trying to find out. The 2026 edition wants all three in writing.

The checklist, clause by clause

This is the structure of a complete internal audit checklist for the 2026 edition. Rows marked 2026 are new or changed and are the ones to prioritise on a transition audit.

Clause What to ask for What good looks like
4.1 2026 The context register, including the climate change determination Internal and external issues, reviewed and dated. Climate change has its own entry with a determination, a reason, an owner and a date, including if the determination is “not relevant”
4.2 2026 The interested parties register Parties, their relevant requirements, and a column showing which requirements will be addressed through the QMS. Review dates present
4.3 / 4.4 Scope statement and process map Scope matches what the site actually does. Processes have inputs, outputs, owners, criteria and measures
5.1.1 2026 Evidence against all twelve commitments a) to l) Dated top management actions. For i) quality culture and k) opportunity-based thinking, actions with measurable outcomes, not statements of intent
5.2 The quality policy Visibly reflects the 4.1 context. Evidence it is implemented, not only published
5.3 2026 Responsibilities and authorities matrix Six items a) to f) covered, with reporting on QMS performance and reporting on opportunities held separately, and f) integrity of the QMS during change assigned
6.1.2 2026 The risk register Risks analysed and evaluated, not just listed. Actions proportionate to the risk
6.1.3 2026 The opportunity register Separate register. Entries show determine, analyse, evaluate, plan, integrate, implement, evaluate effectiveness. Some entries not pursued, with reasons
6.2 Quality objectives Measurable, owned, dated, with a stated method of evaluating results
6.3 2026 The change record Seven considerations, including communication of the change, monitoring effectiveness, and a dated review of results. Pull a closed change from six months ago and ask for the review
7.1.5 Calibration register Traceable calibration where measurement traceability is required, or a recorded basis where no standard exists
7.1.6 2026 Organizational knowledge Knowledge retained, applied and shared: accessible, not held by one person or in one locked folder
7.2 Competence records Competence determined, evidence retained, action taken where gaps found
7.3 2026 Awareness: interview five people Five items including e) quality culture and ethical behaviour. Answers in their own words, consistent across shifts
7.5 Document control Current revisions at point of use. External documents, including the standard itself, controlled and current
8.1 2026 Operational planning Process criteria and acceptance criteria separately stated, in writing. Unintended changes reviewed. Externally provided processes controlled
8.2.1 2026 Customer communication procedure Contingency actions addressed where relevant, including who contacts the customer on a supply disruption and at what trigger
8.4 Supplier control Criteria for evaluation, selection, monitoring and re-evaluation. Records of each
8.5 Production control Documented information defining characteristics available at the line. Identification and traceability. Actions to prevent human error. Note this was already in 2015
8.6 / 8.7 Release and nonconforming output Release traceable to the authorising person. Nonconforming output recorded with disposition and authority
9.1.3 2026 Analysis and evaluation Eight items a) to h), with separate lines for effectiveness of risk actions and opportunity actions
9.2.2 2026 The audit programme and plans Objectives, criteria and scope on every plan. Auditor impartiality recorded
9.3 2026 Management review Eight inputs, including c) changes in interested party needs and the g)/h) split. Minutes follow the agenda and record decisions and resources
10 2026 Improvement, nonconformity and corrective action Two sub-clauses. Corrective actions evaluate whether the cause could recur elsewhere. Complaints treated as a source of nonconformities

Auditing by interview, not by folder

The single biggest shift in how a 2026 audit feels is that more of it happens on the floor. Clause 7.3 e) cannot be audited from a file, and 5.1.1 i) is very hard to audit from one either.

  • Ask open questions about their own work. “What do you do if the colour looks off?” tells you more than “Are you aware of the quality policy?”, which only ever gets one answer.
  • Ask across shifts. Night shift is where awareness gaps show. An audit that only ever samples day shift has a sampling problem, and a certification body auditor will find it.
  • Ask in the language people work in. If induction is delivered in English to a workforce that works in isiXhosa or Afrikaans, awareness will not be demonstrable however good the slides were.
  • Record what was said, not that it was asked. “Operator confirmed awareness” is not evidence. A short quote is.
  • Follow the document to the floor and back. Read the procedure, then watch the task, then read the record. Findings live in the gaps between those three.

Independence, and auditing your own work

Clause 9.2.2 c) requires the audit process to be objective and impartial, which in practice means nobody audits their own work. On a small site that is a real constraint.

Situation Workable approach
The QA manager wrote most of the system Train two or three auditors from other functions (production, maintenance, planning) and have them audit the QA-owned processes. The QA manager audits theirs
Twenty-person site, one quality person Cross-audit with another site in the group, or use an external auditor for the processes your own people own. Record the reasoning
A consultant built your system and now offers to audit it Acceptable only if the individual auditing is not the individual who wrote it, and the separation is recorded on the audit plan and in the auditor competence and independence record. If your certification body takes a stricter view, train your own people instead
The auditor reports to the person whose process they audited Change the reporting line for the audit, or swap auditors. This is the version of the problem auditors notice fastest

Remote auditing under ISO 19011:2026

ISO 19011:2026 is the fourth edition of the auditing guidelines and it brings guidance on remote auditing and virtual locations into the main text. It is guidance, not a requirement, but a certification body will expect your internal audits to be consistent with it if you claim to follow it.

What works remotely: document review, record sampling, management review verification, interviews with office-based functions, and follow-up on closed actions. What does not: anything where the evidence is physical. You cannot verify segregation in a warehouse, the condition of tooling, or whether the correct artwork proof is actually at the press, over a video call. Plan a hybrid audit and say in the plan which parts are which.

The ten findings we expect most

  1. No objectives on the audit plan

    Straight 9.2.2 a) finding, and the easiest one to avoid. One sentence per plan.

  2. Opportunity register missing or unworked

    6.1.3. Either no separate register, or one where nothing has reached the effectiveness step.

  3. Change record stops at implementation

    6.3 f) and g). The change was made and communicated, but nobody reviewed whether it worked.

  4. Quality culture evidenced by posters

    5.1.1 i). A values statement and a survey with no recorded action do not demonstrate promotion by top management.

  5. Awareness demonstrated by attendance register

    7.3 e). Signatures prove attendance, not awareness.

  6. Acceptance criteria only in the operator’s head

    8.1. The tolerance is real and correctly applied, but it is not in a controlled document.

  7. Management review agenda still has six inputs

    9.3. Missing c), and risks and opportunities still combined.

  8. Analysis has one line for risk and opportunity actions

    9.1.3 e) and f) require them separated.

  9. Climate change entry blank

    4.1. “Not applicable” with no reason and no date does not satisfy a determination.

  10. Documents still cite clause 10.3

    Clause 10 has two sub-clauses in the 2026 edition. Dead cross-references are an easy finding and a bad look.

Run this as a mock audit before your certification body does. We run pre-certification readiness audits the way the certification body runs them: sampling, floor interviews, document trails and a closing meeting. We also train and calibrate your own internal auditors so the audit stops being an outside cost.

Questions people ask

How often do internal audits have to happen?

ISO 9001 does not set a frequency. Clause 9.2.2 requires a programme whose frequency reflects the importance of the processes concerned, changes affecting the organization, and the results of previous audits. In practice most single-site manufacturers cover every process at least annually, with higher-risk or recently-failed processes audited more often. What an auditor looks for is not the interval but the reasoning behind it, so record why each frequency was chosen.

Do we need a separate audit just for the 2026 transition?

No, and it is usually cheaper not to. Run one full internal audit against the 2026 edition using a checklist that flags the changed clauses, and treat the flagged rows as your transition gap analysis. That gives you one set of findings, one corrective action process and one report, and it is exactly the evidence your certification body will want to see before the transition audit.

Can one internal audit cover ISO 9001 and FSSC 22000 together?

Yes, and it is the largest single saving available to a dual-scheme site. Run a combined audit under ISO 19011:2026 guidance: one auditor walks the process once and audits it against both sets of criteria. Name both standards in the objective sentence and the criteria on the audit plan. Keep the HACCP, prerequisite programme, food defence and recall elements separate, because they have no ISO 9001 equivalent.

What qualifications do internal auditors need?

None are specified by the standard. Clause 7.2 requires competence to be determined, provided and evidenced, and 9.2.2 c) requires objectivity and impartiality. In practice that means training in the standard and in auditing technique, a record of that training, and usually a witnessed audit before someone audits alone. A lead auditor certificate is not required for internal auditing, whatever a training provider tells you.

How many findings should an internal audit raise?

There is no target, but zero is a warning sign. An internal audit programme that raises no findings across a full cycle tells a certification body auditor that the audits are not probing, and it is one of the most reliable triggers for a deeper look. Findings are evidence the system is being tested. A programme that finds and closes its own problems is the strongest thing you can show at stage 2.

ISO 9001:2026 and ISO 19011:2026 are published by the International Organization for Standardization. Clause references follow the sixth edition of ISO 9001 published on 16 September 2026; confirm the lettering against your own controlled copy. ASC Food Safety Consultants is an independent consultancy, training provider and auditing firm and is not a certification body. Our toolkits and courses are our own products and are not approved, endorsed or accredited by ISO or by any certification body.

Leave a Comment

I accept the Terms and Conditions and the Privacy Policy

News & updates 5 new
4.9/5 what do you need today?