Internal audits are not a box-ticking exercise. Done well, they are your organisation's early warning system — catching problems before your certification body does, and providing the evidence of continual improvement that every ISO standard demands.

Yet in our experience working with over 100 Malaysian organisations, internal audits are the single area where companies most commonly fall short. The mistakes are predictable: audits are rushed, auditors are untrained, findings are vague, and corrective actions never close the loop.

This guide gives you a practical, clause-by-clause checklist you can use for ISO 9001, ISO 14001, and ISO 45001 internal audits — plus the common mistakes Malaysian SMEs make and how to avoid them.

📌 Why This Matters

Clause 9.2 of ISO 9001, ISO 14001, and ISO 45001 all require internal audits at planned intervals. A weak internal audit programme is itself a nonconformity — and one of the most common audit findings Malaysian companies receive.

Before the Audit: Planning and Preparation

A good internal audit starts weeks before anyone walks onto the shop floor. The planning stage is where most Malaysian companies cut corners — and where most problems originate.

1. Establish Your Audit Programme

Your audit programme is the master plan that covers the full 12-month (or certification cycle) audit schedule. It must cover every clause and every process in your management system at least once per cycle. High-risk areas — processes with previous nonconformities, customer complaints, or regulatory requirements — should be audited more frequently.

Check ItemWhat to VerifyEvidence Needed
Audit programme existsCovers all clauses and processes over the certification cycleWritten programme/schedule document
Risk-based frequencyHigh-risk processes audited more oftenRisk assessment linked to audit frequency
Previous results consideredPast findings feed into current programmeReference to prior audit reports
Competent auditors assignedAuditors trained and independent of area being auditedTraining records, auditor qualifications
Management approvalProgramme approved by top management or management representativeSigned-off programme document

2. Select and Prepare Your Audit Team

Auditor competence is non-negotiable. Every internal auditor should have completed a recognised internal auditor training course and must be independent of the area they are auditing. In small Malaysian SMEs, cross-auditing is the standard approach — the production manager audits purchasing, the purchasing officer audits HR, and so on.

Each auditor should prepare by reviewing the relevant standard clauses, the process procedures, previous audit reports for that area, and any customer complaints or incidents related to those processes.

3. Prepare Your Audit Checklist

Your checklist should not simply list clause numbers. It should contain specific, answerable questions that an auditor can use to verify conformity. Good audit questions follow a pattern: they ask what the process is, how it is controlled, where the evidence is, and whether results meet planned arrangements.

Clause-by-Clause Audit Checklist

The following checklist covers the shared High Level Structure (HLS) clauses used across ISO 9001, ISO 14001, and ISO 45001. Specific requirements for each standard are noted where they differ.

Clause 4 — Context of the Organisation

Audit QuestionWhat to Look For
Has the organisation identified internal and external issues?Documented SWOT or context analysis, reviewed at least annually
Are interested parties identified with their requirements?List of interested parties (customers, regulators, employees, community) and their needs
Is the scope of the management system defined and documented?Documented scope statement matching the certification scope
Are processes and their interactions identified?Process map or interaction matrix showing inputs, outputs, and responsibilities

Clause 5 — Leadership

Audit QuestionWhat to Look For
Does top management demonstrate commitment?Evidence of involvement in management review, resource allocation, policy communication
Is the policy appropriate and communicated?Policy displayed, staff aware of its content, relevant to the scope
Are roles, responsibilities, and authorities defined?Organisation chart, job descriptions, appointment letters for key roles (MR, internal auditors, EHS officer)
ISO 45001 only: Is worker consultation and participation demonstrated?Safety committee minutes, worker feedback mechanisms, participation records

Clause 6 — Planning

Audit QuestionWhat to Look For
Are risks and opportunities identified and addressed?Risk register or assessment with actions planned
Are objectives set — measurable, monitored, and communicated?Quality/Environmental/Safety objectives with targets, responsibilities, and timeframes
ISO 14001: Are environmental aspects and impacts identified?Aspect-impact register with significance evaluation
ISO 45001: Is hazard identification and risk assessment (HIRA) complete?HIRA register covering all work activities, regularly reviewed
Are legal and regulatory requirements identified?Legal register with compliance evaluation records

Clause 7 — Support

Audit QuestionWhat to Look For
Are resources adequate?Staffing levels, equipment, infrastructure, budget allocation
Are personnel competent?Training records, qualifications, competence assessments
Is awareness of the management system demonstrated?Staff interviews — can they explain the policy, their contribution, consequences of nonconformity?
Is documented information controlled?Document control procedure, version control, approval records, obsolete document handling
Are monitoring and measuring devices calibrated?Calibration schedule, certificates, traceability to national standards

Clause 8 — Operation

This is the largest and most process-specific clause. The checklist here depends on your industry and scope, but core questions apply universally:

Audit QuestionWhat to Look For
Are operational processes planned and controlled?Procedures, work instructions, process parameters defined and followed
Are customer requirements reviewed before acceptance?Contract review records, order confirmation, design input verification
Is purchasing and supplier evaluation controlled?Approved supplier list, evaluation criteria, incoming inspection records
Are nonconforming outputs identified and controlled?NCR register, segregation procedures, disposition records
ISO 45001: Is emergency preparedness tested?Emergency drill records, first aid supplies checked, evacuation plans posted

Clause 9 — Performance Evaluation

Audit QuestionWhat to Look For
Is customer satisfaction monitored?Survey results, complaint trends, feedback analysis
Is the internal audit programme implemented as planned?Audit schedule vs. actual, audit reports completed, findings tracked
Is management review conducted with required inputs?Meeting minutes covering all required agenda items, actions assigned with deadlines
Are KPIs monitored and analysed?Data on objectives, trends, statistical analysis where applicable

Clause 10 — Improvement

Audit QuestionWhat to Look For
Are nonconformities investigated with root cause analysis?CAPA records, root cause methodology used, evidence of effectiveness review
Are corrective actions implemented and verified?Closed CARs with evidence of implementation and verification of effectiveness
Is continual improvement demonstrated?Improvement projects, trend improvements, innovation initiatives documented

5 Common Internal Audit Mistakes in Malaysia

These are the patterns we see repeatedly across Malaysian companies — and they almost always lead to findings during the certification body's surveillance audit:

1. Copying the Standard as Your Checklist

Simply listing clause numbers ("Check 7.1.5") is not an audit checklist. Your checklist must translate clauses into specific, verifiable questions relevant to your actual processes. A manufacturing plant and a consultancy firm both need to address Clause 8.1, but the questions are completely different.

2. Auditing Only Documentation

A common trap: auditors review files and records but never visit the shop floor, talk to operators, or observe processes. ISO audits require evidence from three sources — documents, records, and observation of actual practice. If your internal audit report contains no interview notes or observation findings, it will be flagged.

3. Writing Vague Findings

A finding that says "Document control needs improvement" is useless. Good audit findings state exactly what was observed, what requirement was not met, and where the evidence was found. Use the format: what was found + what clause or requirement it relates to + where and when it was observed.

4. Not Closing Corrective Actions

Raising findings is only half the job. Each corrective action must be verified for effectiveness — meaning the auditor must confirm not just that the action was taken, but that it actually prevented recurrence. Many Malaysian companies implement actions but never verify them, leaving a trail of open CARs that certification body auditors will immediately question.

5. Lack of Auditor Independence

The operations manager auditing their own operations is a clear conflict of interest and a direct nonconformity against ISO 19011 principles. Even in companies with only 10 employees, cross-auditing or outsourcing internal audits to a consultant is expected.

✅ Pro Tip

Schedule your internal audit 6–8 weeks before your surveillance or recertification audit. This gives you enough time to implement corrective actions and verify their effectiveness before the external auditors arrive.

After the Audit: Reporting and Follow-Up

The internal audit report is a critical piece of evidence that your certification body will review during every surveillance audit. It should contain:

The report should feed directly into your next management review — Clause 9.3 specifically requires internal audit results as a management review input.

When to Outsource Your Internal Audit

Many Malaysian SMEs find it more practical and effective to outsource internal audits to a qualified consultant. This makes sense when:

Cari Consultancy provides professional internal audit services for ISO 9001, ISO 14001, ISO 45001, ISO 22000, and Integrated Management Systems across Malaysia.

Frequently Asked Questions

How often should we conduct ISO internal audits in Malaysia?

ISO standards require internal audits at planned intervals. For most Malaysian SMEs, conducting a full system audit once or twice per year is standard practice. High-risk processes or areas with previous nonconformities should be audited more frequently. Your audit programme should be based on risk and importance — not just a calendar schedule.

Can the same person audit their own department?

No. ISO 19011 requires auditor independence — you cannot audit your own work or your own department. In smaller Malaysian companies where this is challenging, the common solution is to cross-audit: the operations manager audits HR processes, the HR manager audits purchasing, and so on. Alternatively, you can engage an external consultant like Cari Consultancy to conduct your internal audits.

What qualifications do internal auditors need in Malaysia?

Internal auditors should complete a recognised internal auditor training course — typically a 2-day programme covering ISO 19011 audit guidelines. They need to understand the standard being audited, basic audit techniques (interviewing, evidence gathering, reporting), and have sufficient knowledge of the processes they are auditing. Cari Consultancy offers internal auditor training programmes accredited for CPD points.

What is the difference between an internal audit and a surveillance audit?

An internal audit is conducted by your own trained personnel (or an outsourced consultant) to verify your system is working as intended. A surveillance audit is conducted by your certification body — the external auditors who issued your ISO certificate — to confirm ongoing compliance. Internal audits prepare you for surveillance audits by catching and fixing issues before the external auditors arrive.

📚 Related Reading

See our guide to 10 Common ISO Audit Findings in Malaysia — the issues your internal audit should be catching before the certification body does. Also read about ISO certification renewal and surveillance audit preparation.

Need Help With Your Internal Audit?

Cari Consultancy conducts professional internal audits for Malaysian companies across all ISO standards. Experienced auditors, clear reports, actionable findings.

Get a Free Quote Internal Auditor Training
CC
Cari Consultancy Sdn Bhd
ISO Audit & Compliance Specialists · Malaysia

Cari Consultancy has conducted hundreds of internal audits across Selangor, Kuala Lumpur, Johor, and Penang. Our audit approach is practical, evidence-based, and designed to genuinely improve your management system — not just satisfy a checkbox.