Internal audits are not a box-ticking exercise. Done well, they are your organisation's early warning system — catching problems before your certification body does, and providing the evidence of continual improvement that every ISO standard demands.
Yet in our experience working with over 100 Malaysian organisations, internal audits are the single area where companies most commonly fall short. The mistakes are predictable: audits are rushed, auditors are untrained, findings are vague, and corrective actions never close the loop.
This guide gives you a practical, clause-by-clause checklist you can use for ISO 9001, ISO 14001, and ISO 45001 internal audits — plus the common mistakes Malaysian SMEs make and how to avoid them.
Clause 9.2 of ISO 9001, ISO 14001, and ISO 45001 all require internal audits at planned intervals. A weak internal audit programme is itself a nonconformity — and one of the most common audit findings Malaysian companies receive.
Before the Audit: Planning and Preparation
A good internal audit starts weeks before anyone walks onto the shop floor. The planning stage is where most Malaysian companies cut corners — and where most problems originate.
1. Establish Your Audit Programme
Your audit programme is the master plan that covers the full 12-month (or certification cycle) audit schedule. It must cover every clause and every process in your management system at least once per cycle. High-risk areas — processes with previous nonconformities, customer complaints, or regulatory requirements — should be audited more frequently.
| Check Item | What to Verify | Evidence Needed |
|---|---|---|
| Audit programme exists | Covers all clauses and processes over the certification cycle | Written programme/schedule document |
| Risk-based frequency | High-risk processes audited more often | Risk assessment linked to audit frequency |
| Previous results considered | Past findings feed into current programme | Reference to prior audit reports |
| Competent auditors assigned | Auditors trained and independent of area being audited | Training records, auditor qualifications |
| Management approval | Programme approved by top management or management representative | Signed-off programme document |
2. Select and Prepare Your Audit Team
Auditor competence is non-negotiable. Every internal auditor should have completed a recognised internal auditor training course and must be independent of the area they are auditing. In small Malaysian SMEs, cross-auditing is the standard approach — the production manager audits purchasing, the purchasing officer audits HR, and so on.
Each auditor should prepare by reviewing the relevant standard clauses, the process procedures, previous audit reports for that area, and any customer complaints or incidents related to those processes.
3. Prepare Your Audit Checklist
Your checklist should not simply list clause numbers. It should contain specific, answerable questions that an auditor can use to verify conformity. Good audit questions follow a pattern: they ask what the process is, how it is controlled, where the evidence is, and whether results meet planned arrangements.
Clause-by-Clause Audit Checklist
The following checklist covers the shared High Level Structure (HLS) clauses used across ISO 9001, ISO 14001, and ISO 45001. Specific requirements for each standard are noted where they differ.
Clause 4 — Context of the Organisation
| Audit Question | What to Look For |
|---|---|
| Has the organisation identified internal and external issues? | Documented SWOT or context analysis, reviewed at least annually |
| Are interested parties identified with their requirements? | List of interested parties (customers, regulators, employees, community) and their needs |
| Is the scope of the management system defined and documented? | Documented scope statement matching the certification scope |
| Are processes and their interactions identified? | Process map or interaction matrix showing inputs, outputs, and responsibilities |
Clause 5 — Leadership
| Audit Question | What to Look For |
|---|---|
| Does top management demonstrate commitment? | Evidence of involvement in management review, resource allocation, policy communication |
| Is the policy appropriate and communicated? | Policy displayed, staff aware of its content, relevant to the scope |
| Are roles, responsibilities, and authorities defined? | Organisation chart, job descriptions, appointment letters for key roles (MR, internal auditors, EHS officer) |
| ISO 45001 only: Is worker consultation and participation demonstrated? | Safety committee minutes, worker feedback mechanisms, participation records |
Clause 6 — Planning
| Audit Question | What to Look For |
|---|---|
| Are risks and opportunities identified and addressed? | Risk register or assessment with actions planned |
| Are objectives set — measurable, monitored, and communicated? | Quality/Environmental/Safety objectives with targets, responsibilities, and timeframes |
| ISO 14001: Are environmental aspects and impacts identified? | Aspect-impact register with significance evaluation |
| ISO 45001: Is hazard identification and risk assessment (HIRA) complete? | HIRA register covering all work activities, regularly reviewed |
| Are legal and regulatory requirements identified? | Legal register with compliance evaluation records |
Clause 7 — Support
| Audit Question | What to Look For |
|---|---|
| Are resources adequate? | Staffing levels, equipment, infrastructure, budget allocation |
| Are personnel competent? | Training records, qualifications, competence assessments |
| Is awareness of the management system demonstrated? | Staff interviews — can they explain the policy, their contribution, consequences of nonconformity? |
| Is documented information controlled? | Document control procedure, version control, approval records, obsolete document handling |
| Are monitoring and measuring devices calibrated? | Calibration schedule, certificates, traceability to national standards |
Clause 8 — Operation
This is the largest and most process-specific clause. The checklist here depends on your industry and scope, but core questions apply universally:
| Audit Question | What to Look For |
|---|---|
| Are operational processes planned and controlled? | Procedures, work instructions, process parameters defined and followed |
| Are customer requirements reviewed before acceptance? | Contract review records, order confirmation, design input verification |
| Is purchasing and supplier evaluation controlled? | Approved supplier list, evaluation criteria, incoming inspection records |
| Are nonconforming outputs identified and controlled? | NCR register, segregation procedures, disposition records |
| ISO 45001: Is emergency preparedness tested? | Emergency drill records, first aid supplies checked, evacuation plans posted |
Clause 9 — Performance Evaluation
| Audit Question | What to Look For |
|---|---|
| Is customer satisfaction monitored? | Survey results, complaint trends, feedback analysis |
| Is the internal audit programme implemented as planned? | Audit schedule vs. actual, audit reports completed, findings tracked |
| Is management review conducted with required inputs? | Meeting minutes covering all required agenda items, actions assigned with deadlines |
| Are KPIs monitored and analysed? | Data on objectives, trends, statistical analysis where applicable |
Clause 10 — Improvement
| Audit Question | What to Look For |
|---|---|
| Are nonconformities investigated with root cause analysis? | CAPA records, root cause methodology used, evidence of effectiveness review |
| Are corrective actions implemented and verified? | Closed CARs with evidence of implementation and verification of effectiveness |
| Is continual improvement demonstrated? | Improvement projects, trend improvements, innovation initiatives documented |
5 Common Internal Audit Mistakes in Malaysia
These are the patterns we see repeatedly across Malaysian companies — and they almost always lead to findings during the certification body's surveillance audit:
1. Copying the Standard as Your Checklist
Simply listing clause numbers ("Check 7.1.5") is not an audit checklist. Your checklist must translate clauses into specific, verifiable questions relevant to your actual processes. A manufacturing plant and a consultancy firm both need to address Clause 8.1, but the questions are completely different.
2. Auditing Only Documentation
A common trap: auditors review files and records but never visit the shop floor, talk to operators, or observe processes. ISO audits require evidence from three sources — documents, records, and observation of actual practice. If your internal audit report contains no interview notes or observation findings, it will be flagged.
3. Writing Vague Findings
A finding that says "Document control needs improvement" is useless. Good audit findings state exactly what was observed, what requirement was not met, and where the evidence was found. Use the format: what was found + what clause or requirement it relates to + where and when it was observed.
4. Not Closing Corrective Actions
Raising findings is only half the job. Each corrective action must be verified for effectiveness — meaning the auditor must confirm not just that the action was taken, but that it actually prevented recurrence. Many Malaysian companies implement actions but never verify them, leaving a trail of open CARs that certification body auditors will immediately question.
5. Lack of Auditor Independence
The operations manager auditing their own operations is a clear conflict of interest and a direct nonconformity against ISO 19011 principles. Even in companies with only 10 employees, cross-auditing or outsourcing internal audits to a consultant is expected.
Schedule your internal audit 6–8 weeks before your surveillance or recertification audit. This gives you enough time to implement corrective actions and verify their effectiveness before the external auditors arrive.
After the Audit: Reporting and Follow-Up
The internal audit report is a critical piece of evidence that your certification body will review during every surveillance audit. It should contain:
- Audit scope, objectives, and criteria
- Audit team members and their independence from audited areas
- Processes and clauses audited
- Findings classified as major nonconformity, minor nonconformity, observation, or opportunity for improvement
- Objective evidence for each finding — what was seen, where, when
- Corrective action requests with deadlines and responsibilities
- Follow-up and verification of corrective action effectiveness
The report should feed directly into your next management review — Clause 9.3 specifically requires internal audit results as a management review input.
When to Outsource Your Internal Audit
Many Malaysian SMEs find it more practical and effective to outsource internal audits to a qualified consultant. This makes sense when:
- Your company is too small to maintain auditor independence internally
- You lack staff with formal internal auditor training
- You want a fresh, independent perspective on your system
- You are preparing for a high-stakes surveillance or recertification audit and want to minimise risk
- You are implementing a new standard and want an experienced auditor to assess readiness
Cari Consultancy provides professional internal audit services for ISO 9001, ISO 14001, ISO 45001, ISO 22000, and Integrated Management Systems across Malaysia.
Frequently Asked Questions
ISO standards require internal audits at planned intervals. For most Malaysian SMEs, conducting a full system audit once or twice per year is standard practice. High-risk processes or areas with previous nonconformities should be audited more frequently. Your audit programme should be based on risk and importance — not just a calendar schedule.
No. ISO 19011 requires auditor independence — you cannot audit your own work or your own department. In smaller Malaysian companies where this is challenging, the common solution is to cross-audit: the operations manager audits HR processes, the HR manager audits purchasing, and so on. Alternatively, you can engage an external consultant like Cari Consultancy to conduct your internal audits.
Internal auditors should complete a recognised internal auditor training course — typically a 2-day programme covering ISO 19011 audit guidelines. They need to understand the standard being audited, basic audit techniques (interviewing, evidence gathering, reporting), and have sufficient knowledge of the processes they are auditing. Cari Consultancy offers internal auditor training programmes accredited for CPD points.
An internal audit is conducted by your own trained personnel (or an outsourced consultant) to verify your system is working as intended. A surveillance audit is conducted by your certification body — the external auditors who issued your ISO certificate — to confirm ongoing compliance. Internal audits prepare you for surveillance audits by catching and fixing issues before the external auditors arrive.
See our guide to 10 Common ISO Audit Findings in Malaysia — the issues your internal audit should be catching before the certification body does. Also read about ISO certification renewal and surveillance audit preparation.
Need Help With Your Internal Audit?
Cari Consultancy conducts professional internal audits for Malaysian companies across all ISO standards. Experienced auditors, clear reports, actionable findings.
Get a Free Quote Internal Auditor Training