ISO 9001 Internal Audit Checklist: Clause by Clause for the 2026 Edition

ISO 9001 Internal Audit Checklist: Clause by Clause for the 2026 Edition

An internal audit is the health check of a quality management system, and a good checklist is what keeps it systematic. This ISO 9001 internal audit checklist is written for ISO 9001:2026, published in September 2026. It covers every clause from 4 to 10 and flags the questions that are new in this edition, so you can use it for routine audits and as a transition gap audit.

What clause 9.2 requires of internal audits

Internal audits at planned intervals must tell you whether the QMS conforms to your own requirements and to ISO 9001, and whether it is effectively implemented and maintained. The audit programme sets frequency, methods, responsibilities, planning and reporting, and must consider:

  • the importance of the processes concerned;
  • the results of previous audits;
  • changes affecting the organization.

For each audit you define the objectives, criteria and scope; select auditors so the audit is objective and impartial; report results to relevant managers; and take correction and corrective action without undue delay. Keep evidence of the programme and the results.

Before the audit

  • Set the audit objective, for example "verify the new risk and opportunity process is effective".
  • Confirm scope (processes, sites, shifts) and criteria (ISO 9001:2026, your procedures, customer requirements).
  • Check impartiality: auditors should not audit their own work. Independence can be shown by freedom from responsibility for the activity audited.
  • Review previous findings, open corrective actions and changes since the last audit.
  • Pull current documents and records from your document control system.

The ISO 9001 internal audit checklist

Questions marked (new in 2026) reflect changes in the latest edition. Adapt the wording to your processes, and audit by process rather than reading clauses aloud to auditees.

Clause 4: Context of the organization

  • 4.1 Have relevant internal and external issues been determined, and how are they monitored and reviewed?
  • 4.1 (new in 2026) Has the organization determined whether climate change is a relevant issue, and is the reasoning recorded?
  • 4.2 Are relevant interested parties and their requirements identified and kept under review?
  • 4.2 c) (new in 2026) Has the organization decided which of those requirements the QMS will address?
  • 4.3 Does the scope state product and service types, and justify any requirement declared not applicable?
  • 4.4 Are processes, their inputs, outputs, interactions, criteria, performance indicators, owners, risks and opportunities determined?

Clause 5: Leadership

  • 5.1.1 Can top management show how they take accountability for QMS effectiveness and integrate it into business processes?
  • 5.1.1 i) (new in 2026) How does top management promote quality culture and ethical behaviour? Ask for concrete examples.
  • 5.1.1 k) Is opportunity-based thinking promoted alongside risk-based thinking?
  • 5.1.2 Are customer and legal requirements determined and consistently met?
  • 5.2 Is the quality policy appropriate, communicated, understood and available to interested parties as appropriate?
  • 5.3 Are roles assigned, including responsibility for maintaining QMS integrity when changes are planned and implemented?

Clause 6: Planning

  • 6.1.1 Were risks and opportunities determined from the context (4.1) and interested parties (4.2)?
  • 6.1.2 (new in 2026) Are risks analysed and evaluated, with actions proportionate to their impact, integrated into processes and checked for effectiveness? Are disruption risks considered?
  • 6.1.3 (new in 2026) Are opportunities analysed, evaluated and acted on through their own cycle, with effectiveness evaluated?
  • 6.2 Are quality objectives measurable, monitored and planned (what, resources, who, when, how evaluated)?
  • 6.3 (expanded in 2026) For recent QMS changes, were communication, effectiveness monitoring and review of results planned?

Clause 7: Support

  • 7.1.4 Is the working environment (social, psychological and physical factors) suitable for the processes?
  • 7.1.5 Are measuring instruments calibrated or verified, identified and safeguarded? When one was found unfit, was the impact on past results assessed?
  • 7.1.6 Is critical knowledge retained, applied and shared, and how are changing needs and trends considered?
  • 7.2 Is competence defined and evidenced, and is the effectiveness of training evaluated?
  • 7.3 Are people aware of the policy, relevant objectives, their contribution and the implications of not conforming?
  • 7.3 e) (new in 2026) Are people aware of the organization's quality culture and expected ethical behaviour?
  • 7.4 Are internal and external communications defined?
  • 7.5 Is documented information identified, approved, version-controlled and protected, including external documents, and are records protected from unintended change?

Clause 8: Operation

  • 8.1 Are operations planned with criteria for processes and acceptance, and are unintended changes reviewed?
  • 8.2.1 Does customer communication include contingency information, including about disruptions, where relevant?
  • 8.2.3 Are requirements reviewed before committing to supply, and are differences resolved?
  • 8.3 If design applies, are planning, inputs, controls, outputs and changes evidenced?
  • 8.4 Are external providers evaluated, selected, monitored and re-evaluated against criteria?
  • 8.5 Is production or service provision controlled, including validation of special processes, prevention of human error, traceability and customer property?
  • 8.6 Is release evidenced with acceptance criteria and the person authorizing release?
  • 8.7 Are nonconforming outputs identified and controlled, including those detected after delivery?

Clause 9: Performance evaluation

  • 9.1.1 Is it defined what is monitored and measured, how and when, and are results analysed?
  • 9.1.2 How is customer satisfaction monitored?
  • 9.1.3 (changed in 2026) Does analysis evaluate the effectiveness of risk actions and of opportunity actions separately?
  • 9.2 Does the audit programme reflect process importance, previous results and changes? Are auditors impartial?
  • 9.3.2 (changed in 2026) Do management review inputs include changes in interested party needs and the effectiveness of risk actions and opportunity actions as separate items?
  • 9.3.3 Are decisions on improvement, QMS changes and resources recorded?

Clause 10: Improvement

  • 10.1 (consolidated in 2026) Are results of analysis and management review used to determine and act on improvement opportunities? Continual improvement now sits entirely in 10.1.
  • 10.2 For a sample of nonconformities: was the cause found, were similar cases checked, was effectiveness reviewed, and were risks and opportunities updated where needed?

After the audit

  • Write findings with the requirement, the evidence and the gap. Grade them as major or minor nonconformities or opportunities for improvement.
  • Hold a closing meeting and report results to the relevant managers.
  • Raise corrective actions without undue delay and track them in CAPA management software.
  • Feed results and trends into the next management review.

Internal audits are now a natural place to run your 2026 transition gap check. ISO audit software such as SmartISO can generate checklists against ISO 9001:2026 clauses, record evidence on site and push findings straight into corrective actions. Read our ISO 9001:2026 guide for the full change list.

Frequently asked questions

How often should ISO 9001 internal audits be done?

At planned intervals, which you set. Most organizations cover the whole QMS at least once a year and audit high-risk or changing processes more often.

What is the difference between a major and minor nonconformity?

A major nonconformity is the absence or total breakdown of a required element, or a failure likely to result in nonconforming product reaching customers. A minor nonconformity is an isolated lapse in an otherwise working system.

Can we use a generic checklist?

As a starting point, yes. Tailor the questions to your processes, products and the objective of each audit, and audit by process so you follow real work rather than the clause order.

Do we need to audit against ISO 9001:2026 now?

Organizations certified to the previous edition stay certified during the transition period. Auditing against the 2026 requirements early shows you the gaps to close before your certification body's transition audit. Confirm dates with your certification body.