ISO Internal Audits
Without The Headache
Internal audits are a required part of maintaining an ISO management system. We help you stay ahead of your certification, surveillance and recertification audits.
Get Started Today
Tell us about your business and we'll be in touch within 1 business day.
Your internal audit shouldn't be a box-ticking exercise.
An internal audit isn't just about producing another report. It's about checking whether your management system is actually working in practice — not just whether it exists on paper.
- ✓Identify nonconformities before the external auditor does
- ✓Find gaps in processes and documentation
- ✓Check whether procedures are actually being followed day to day
- ✓Prepare confidently for surveillance and recertification audits
A practical audit that tells you what actually needs attention.
Plain-English throughout. Here's exactly what's covered.
Process & Documentation Review
We check relevant processes and documentation against the standard.
Staff Interviews
We speak to the people actually using the system day to day.
Implementation Check
We test whether practice matches what's documented, not just whether it exists.
Nonconformity Identification
Findings and areas of concern are flagged clearly, with evidence.
Corrective Action Discussion
We talk through practical fixes with you before we write anything up.
Audit Report With Priorities
A clear report ranking what matters most, not a wall of minor notes.
Surveillance & Recertification Prep
Findings framed against what your certification body will actually check.
Integrated System Audits
One audit covering more than one ISO standard, where you hold several.
Why bring in an external auditor?
Internal audits need objectivity. Having someone independent review your system can uncover issues that are easily missed when you're too close to the process — and it's particularly useful for SMEs that don't have an experienced internal auditor of their own.
- ✓Independent perspective, free of internal politics
- ✓An experienced ISO auditor, not a first attempt
- ✓Practical findings you can actually act on
- ✓Less pressure on your own team's time
- ✓Issues found before your certification body arrives
Internal audit support for the standards that matter.
What happens during an audit.
Plan
We agree the scope, standard and areas to be audited.
Audit
We review processes, documentation and implementation.
Report
We clearly document findings and areas requiring attention.
Improve
You receive practical guidance on what needs to happen next.
Internal audit at two key points in your ISO journey.
Whether you're working towards certification or already hold one, internal audit shows up at a specific moment for a specific reason.
New to ISO certification?
Before your certification body ever sees your system, we carry out an internal audit — checking it holds up in practice, ahead of your Stage 1 and Certification Audit.
Already certified?
To keep your certificate valid, an internal audit is normally needed at least once a year, ahead of your surveillance or recertification audit. If you're not sure yours has been kept up, or want someone independent to run it, that's exactly what we're here for.
Every audit includes:
- ✓Internal audit findings
- ✓Nonconformities identified
- ✓Areas requiring attention
- ✓Clear evidence from the audit
- ✓Prioritised actions and practical recommendations
- ✓Audit report for your management system records
Not sure where you stand? Talk it through with us on a free discovery call.
🗓️ Book a Free Discovery CallInternal audit support for UK SMEs.
Designed for businesses that need an independent review of their ISO management system, without the cost of employing a full-time specialist.
What Our Clients Say
"Been working with Rowland over the past few months to improve our systems as a business and to implement ISO 9001. Goldenpath have been excellent in 'bridging the gap' and ensuring we spend the time to execute in developing systems. Having an out of business consultant ensures accountability, and Rowland has been very good in simplifying the ISO process."
"Professional and excellent service throughout. Would 100% recommend reaching out to Goldenpath for any help with ISO certifications."
"Their professionalism, knowledge, and clear communication made what can be a complex journey smooth and straightforward. The level of detail, responsiveness, and reassurance they provided gave us complete confidence at every stage."
We take compliance off your desk.
You don't need another complicated report sitting on your desk. We help you understand what's working, what isn't, and what needs to happen next.
Practical. Fixed-Fee. No Surprises.
Not sure whether your ISO system is ready for its next audit?
Talk it through with us. A quick conversation can help you understand where you stand and whether an internal audit could help.
Everything You Need to Know
What is an ISO internal audit?
An ISO internal audit is a planned, independent review of your management system, checking whether your documented processes are actually being followed and whether they meet the requirements of your ISO standard. It's a mandatory clause in every ISO standard — clause 9.2 in ISO 9001, for example — and is normally carried out before your external certification body visits.
Why do I need an internal audit?
Internal audits are a mandatory requirement of every ISO management system standard. Beyond compliance, they let you find and fix nonconformities before your certification body does, reducing the risk of major findings during surveillance or recertification audits.
Can someone in my company carry out the internal audit?
Yes, provided they're independent of the process being audited and suitably competent to assess it. In practice, many SMEs don't have anyone with the time, training or objectivity to audit their own department fairly, which is why they bring in an external auditor instead.
Why use an external internal auditor?
An external auditor brings objectivity that's hard to replicate internally. They aren't influenced by internal politics or day-to-day pressures, so they tend to surface issues that get missed by staff who are too close to the process — and it takes the burden off your own team.
How long does an ISO internal audit take?
Most SME internal audits are completed within a single day on site, depending on the number of sites, processes and standards being audited. We agree the scope and duration with you upfront as part of the planning stage.
What happens if you find a nonconformity?
We document it clearly, explain why it matters against the standard, and agree practical corrective actions with you. This gives you the chance to resolve the issue on your own terms before it's picked up by your certification body.
Do you provide an audit report?
Yes. Every audit ends with a clear written report covering findings, evidence, nonconformities and prioritised actions, kept as part of your management system records for your next certification or surveillance audit.
Which ISO standards do you audit?
We carry out internal audits against ISO 9001 (Quality Management), ISO 14001 (Environmental Management), ISO 45001 (Occupational Health & Safety) and ISO 27001 (Information Security), including integrated systems covering more than one standard.
Can you help us fix the issues found during the audit?
Yes. We can support you with corrective actions directly, and many clients move onto our ongoing Managed Compliance retainer afterwards, so the issues we find don't just get logged — they get closed out.
How often should an ISO internal audit be carried out?
Most businesses run a full internal audit cycle annually, timed ahead of their surveillance or recertification audit, though larger or higher-risk operations sometimes split this into more frequent audits of individual processes throughout the year.
