What clause 9.2 actually asks for
The requirement is shorter than most people expect. Conduct internal audits at planned intervals to determine whether the management system conforms to your own requirements and to the requirements of the standard, and whether it is effectively implemented and maintained.
Read that order again. Your own requirements come first. An internal audit that only checks the standard, and never checks whether you are doing what your own procedures say you do, has skipped half the job — and it is the half that finds real problems.
Around that sit the programme requirements. You need to establish, implement and maintain an audit programme that covers frequency, methods, responsibilities, planning and reporting, and that takes account of the importance of the processes concerned and the results of previous audits.
- Define the criteria and scope for each individual audit, not just the programme.
- Select auditors and conduct audits so that objectivity and impartiality are assured.
- Report results to relevant managers, and to workers and their representatives.
- Take action on nonconformities and continually improve the system.
- Retain documented information as evidence that the programme was implemented and of the results.
What trips people up
The programme is an artefact in its own right. Auditors ask to see it before they ask to see a single audit report, because a folder of reports with no programme behind it cannot demonstrate planned intervals or risk-based coverage.
Build the programme around risk, not the clause list
The most common weak programme mirrors the table of contents of the standard: clause 4 in February, clause 5 in March, and so on until October. It is easy to schedule and it finds almost nothing, because it audits the shape of the documentation rather than the work.
A risk-weighted programme starts from your processes and your incident history instead.
- 1.List your actual processes — not clauses. Permit to work, plant pre-start, contractor onboarding, incident investigation, induction, chemical handling, and so on.
- 2.Rank each by consequence if it fails, rate of change, findings from previous audits, and what workers have told you.
- 3.Assign frequency from the ranking: the high-risk few quarterly, the moderate half-yearly, the stable annually.
- 4.Check the coverage map — every clause of the standard must be touched at least once per certification cycle, and every high-risk process several times a year.
- 5.Publish it, with owners and dates, and treat changes to it as a controlled change.
“Every clause once a year” is a filing exercise. “Every high-risk process four times a year” is a management system.
Scope one audit properly
Most disappointing internal audits are scoped in a sentence and then wander. Four things fix that, and all four belong in writing before you start.
- Criteria — which clauses, which of your own procedures, and which legal or other requirements you are auditing against.
- Scope — which sites, which processes, which people, and what period of records.
- Method — interviews, direct observation of work, record sampling, or a walkthrough of a real event.
- Sample — how many records, chosen how, and why that is defensible.
A defensible sampling convention
The standard does not prescribe a sample size. A convention that holds up: the smaller of ten per cent or ten records per process, never fewer than three, selected across the whole period rather than the most recent week — plus every record connected to an incident or complaint in that period. Write the rule down once and apply it consistently.
Audit the chain, not the document
The difference between an internal audit that produces filler findings and one that changes something is whether you follow a single real thing all the way through the system.
- 1.Pick a real hazard reported in the period — ideally one raised by a worker rather than by management.
- 2.Find the risk assessment it triggered, and check the date against the report date.
- 3.Check the control selected against the hierarchy of controls. Was elimination considered and rejected on a documented basis, or skipped?
- 4.Find the evidence the change was communicated, and that the affected people were trained in it.
- 5.Go to the workplace and confirm the control is actually in place and used as described.
- 6.Confirm it was reviewed for effectiveness, and that the review reached someone with authority.
Wherever that chain breaks is your finding. It is specific, it is evidenced, and nobody can argue it is a paperwork technicality.
The eight records opened first
Across surveillance audits, the same records get requested early. If these eight are current, most of an audit is already answered.
- The hazard and risk register, with review dates and named owners rather than a department.
- The legal and other requirements register, mapped to the obligations that genuinely apply to your operation.
- Competence records set against the requirements of each task, not just a list of courses attended.
- Evidence of worker consultation and participation — the clause auditors probe hardest and organisations evidence worst.
- Incident investigations showing cause analysis and corrective actions closed and verified.
- The audit programme, the reports it produced, and the findings closed out from them.
- Management review inputs and outputs, with decisions and resources actually recorded.
- Monitoring and measurement results, including calibration or verification of any equipment relied on.
Writing findings people will fix
A finding has three parts, and dropping any one of them is why findings get argued instead of fixed: the requirement, the objective evidence, and the gap between them.
- Name the requirement — the clause, or your own procedure and its version.
- State the evidence: which record, which date, who was interviewed. No adjectives.
- Describe the gap in a single sentence a busy manager can read once.
- Grade it against written definitions of major, minor and observation, so grading is consistent between auditors.
- Assign one named owner and a due date, not a team.
- Separate the correction from the corrective action, and record both.
Correction versus corrective action
The correction fixes the instance — the missing record is completed, the guard is refitted. The corrective action addresses the reason it happened at all. An audit where every finding closes with only a correction guarantees the same finding returns next cycle.
Closing the loop before the auditor arrives
Findings that are closed on paper but never verified are the most common cause of a repeat nonconformity being escalated at surveillance.
- 1.Correct the instance immediately and record it.
- 2.Analyse why it was possible, at the level of the system rather than the person.
- 3.Act on that cause, with an owner and a date.
- 4.Verify the action was implemented.
- 5.Verify at a set interval afterwards that it worked — effectiveness is a separate check with its own date.
- 6.Feed the themes, not the individual findings, into management review.
A programme one part-time person can actually run
Most of the organisations we work with have a fraction of a full-time equivalent for this. A programme that fits that reality and still satisfies clause 9.2 looks like this.
- One ninety-minute audit of a single process each month, done properly.
- One deeper audit of a high-risk process each quarter.
- One full-system review annually, timed six to eight weeks before surveillance so findings can be closed.
- Findings reviewed as a standing item at the health and safety committee, monthly.
- One page per audit. Fifteen-page reports do not get read, and length is not evidence of rigour.
Questions we get asked
How often do internal audits have to happen?
The standard says planned intervals, not a fixed frequency. In practice that means every process is audited at least once per certification cycle and your high-risk processes several times a year. What matters is that the interval is justified by risk and previous findings, and that you can show the reasoning.
Can someone audit their own area?
No. Clause 9.2 requires objectivity and impartiality, and auditing your own work fails that on its face. In small organisations the usual solutions are cross-auditing between departments, a trained auditor from another site, or an external contractor for the areas where nobody is independent.
Do internal auditors need a formal qualification?
The standard requires competence, not a certificate. A documented competence basis — training, experience, and evidence they can audit to the standard — is enough. A recognised internal auditor course makes that easier to demonstrate but is not itself a requirement.
What is the difference between an internal audit and the certification audit?
The internal audit is yours: you set the scope, you find the problems, and nothing is at stake beyond fixing them. The certification audit is the certification body sampling your system, including your internal audit programme. A weak internal programme is itself a common finding at certification.
How many audits should a year contain?
Fewer, done properly, beat a full calendar done superficially. For most mid-sized organisations six to ten focused audits a year is realistic and defensible, weighted so the highest-risk processes appear more than once.
General guidance based on ISO 45001:2018 as published. Clause numbering, requirements and your certification body’s expectations should be verified against your current copy of the standard. This is not legal advice.

