Document {{ORG_PREFIX}}-016
Internal Audit Procedure¶
1. Purpose¶
This procedure defines how {{ORG_NAME}} audits itself. The programme in Section 3.1 slices the whole IMS into short monthly checks, planned in advance, run by an auditor independent of the area, and logged in the Internal Audit Log. Each slice tests one area against what our own documents say happens there, and against what is actually happening in the work. The programme comes back round, so drift between the two shows up while it is still small. It implements the continual-improvement commitment of the Quality & OH&S Policy.
2. Scope¶
Every clause-map requirement of both standards, audited through a rolling programme of short monthly slices. One programme serves both disciplines — a slice audits its area's quality and OH&S aspects together. External (certification) audits are out of scope but their findings enter the same corrective-action engine.
3. Procedure¶
3.1 Audit programme¶
Instead of one annual audit nobody has time for, the programme runs as twelve short monthly slices; a full cycle covers every clause-map requirement area of both standards at least once. The {{ROLE_QUALITY_MANAGER}} weights the frequency, seeding it with the cycle and re-weighting whenever new findings or new risk emerge mid-cycle: a slice is scheduled more often when it covers work central to the business, when earlier audits raised findings in it, when it has seen recent change, or when it carries higher risk [ORG-DECISION: which slices repeat within a cycle; default: none, cycle covers all]. Scoping follows the same weighting: a slice digs deeper into work that matters most to {{ORG_NAME}} and into areas where earlier audits raised findings.
The programme table below is machine-checked: tools/check_clause_maps.py
asserts that the union of the "Clauses covered" tokens spans every
clause-index leaf of both standards. Edit it only with that in mind.
| Month | Slice | Clauses covered | Auditor role | Records |
|---|---|---|---|---|
| 1 | Leadership, context & scope | Q4; Q5; OHS4; OHS5 | [ORG-DECISION: independent role] | internal-audits |
| 2 | Risk & hazard management | Q6.1.1; Q6.1.2; OHS6.1.1; OHS6.1.2.1; OHS6.1.2.2; OHS6.1.2.3; OHS6.1.4 | [ORG-DECISION: independent role] | internal-audits |
| 3 | Objectives & improvement | Q6.2; Q10; OHS6.2; OHS10 | [ORG-DECISION: independent role] | internal-audits |
| 4 | Compliance obligations | OHS6.1.3; OHS9.1.2 | [ORG-DECISION: independent role] | internal-audits |
| 5 | Competence & awareness | Q7.1; Q7.2; Q7.3; OHS7.1; OHS7.2; OHS7.3 | [ORG-DECISION: independent role] | internal-audits |
| 6 | Communication & document control | Q7.4; Q7.5; OHS7.4; OHS7.5 | [ORG-DECISION: independent role] | internal-audits |
| 7 | Customer & contract | Q8.2; Q9.1.2 | [ORG-DECISION: independent role] | internal-audits |
| 8 | Operational control & delivery | Q8.1; Q8.5; Q8.6; OHS8.1.1; OHS8.1.2 | [ORG-DECISION: independent role] | internal-audits |
| 9 | Design & change management | Q8.3; Q6.3; OHS8.1.3 | [ORG-DECISION: independent role] | internal-audits |
| 10 | Procurement & contractors | Q8.4; OHS8.1.4.1; OHS8.1.4.2; OHS8.1.4.3 | [ORG-DECISION: independent role] | internal-audits |
| 11 | Monitoring, nonconformity & emergency | Q9.1.1; Q9.1.3; Q8.7; OHS9.1.1; OHS8.2 | [ORG-DECISION: independent role] | internal-audits |
| 12 | Audit, review & incidents | Q9.2; Q9.3; OHS9.2.1; OHS9.2.2; OHS9.3; OHS10.2 | [ORG-DECISION: independent role] | internal-audits |
At instantiation the twelve slices are seeded as dated Schedule register rows
(Category: Internal audit) and mirrored as Scheduled rows in the Internal
Audit Log; automation A5 prompts the accountable role each month. Where
review_programme: quarterly is chosen in the org profile, the same twelve
slices are grouped three-per-quarter — coverage is identical, sessions are
longer.
3.2 Auditor independence¶
Auditor selection starts from one rule: no one audits work they own or perform. In a ~25-person organisation this is a real constraint, handled honestly rather than nominally: the {{ROLE_QUALITY_MANAGER}} and {{ROLE_OHS_COORDINATOR}} cross-audit each other's areas, other competent staff are trained as internal auditors for slices touching both, and [ORG-DECISION: external auditor support for the slices no internal person can audit impartially — e.g. slice 12, which covers the audit process itself]. Auditor competence is a Training Curriculum item; the Internal Audit Log records the auditor per session, who must be independent of the area audited.
3.3 Audit execution¶
| Step | Action | Responsible role | Output / record |
|---|---|---|---|
| 1 | Frame the session: the auditor and the {{ROLE_QUALITY_MANAGER}} agree what this session checks (the clause-map rows for the slice's clauses, the implementing documents, and the standards themselves) and which slice of real work it samples (activities, sites, jobs, and period). | Auditor with {{ROLE_QUALITY_MANAGER}} | Scope note in the session record |
| 2 | Audit against reality: sample records and register rows, follow one job end-to-end where relevant, talk to the people doing the work (awareness questions included), observe field practice where the slice touches it. The test is "is this actually happening", never "does a document exist". | Auditor | Working notes |
| 3 | Record findings: conformities worth noting, nonconformities (requirement not met: cite the clause-map req_id), and observations (conforming but fragile). | Auditor | Session record |
| 4 | Close the loop with people before paper: walk the results through with the managers responsible for the area audited, and take findings relevant to workers to those workers directly and to worker representatives where the workforce has them. OH&S findings are never filed without the people affected hearing them. | Auditor | Distribution noted in the session record |
| 5 | Turn findings into work: every nonconformity becomes a Nonconformity & CAPA Register row (Source: Internal audit) before the session record is filed, carrying both the correction (the immediate fix for the problem found) and the corrective action, handled per the corrective-action procedure; findings and observations also feed the continual-improvement pipeline for OH&S performance. | Auditor raises; area owner actions | CAPA rows |
| 6 | Commit and log: the session record goes to docs/records/internal-audits/YYYY-MM-<slice>.md and the Internal Audit Log row is updated (performed date, auditor, findings count, CAPA links, record link, Status: Done). Together the record and the log show what ran, when, and what each audit found. |
Auditor | Record + register row |
4. Records and Registers¶
| Activity | Register (index) | Record (evidence) |
|---|---|---|
| Programme schedule | Schedule (Category: Internal audit); Internal Audit Log (Scheduled rows) | — |
| Each audit session | Internal Audit Log (performed date, auditor, findings, links) | docs/records/internal-audits/YYYY-MM-<slice>.md |
| Findings and actions | Nonconformity & CAPA Register | Corrective-action records per that procedure |
Honest status: docs/records/internal-audits/ is empty until the first slice
has actually run. The audit requirement is only honestly "operational" from
that first committed record.
5. Exceptions¶
A slice may be deferred by at most [ORG-DECISION: maximum deferral, e.g. one month] with the {{ROLE_QUALITY_MANAGER}}'s written approval and a rescheduled date — the cycle must still cover every area within [ORG-DECISION: cycle tolerance, e.g. 14 months]. No exception is available to auditor independence or to raising CAPA rows for nonconformities found.
6. Related Documents¶
quality-ohs-policy— the improvement commitment this implements.nonconformity-corrective-action-improvement-procedure— where findings go.management-review-procedure— audit results are a standing review input.
7. Revision History¶
| Version | Date | Author | Description of Changes | Reviewed By | Review Date | Approved By | Approval Date |
|---|---|---|---|---|---|---|---|
| 0.1 | 2026-07-16 | {{ROLE_QUALITY_MANAGER}} | Initial draft | — | — | — | — |
8. Document Control
| Document | {{ORG_PREFIX}}-016 |
|---|---|
| Type | Procedure |
| Version | 0.1 |
| Status | Draft |
| Owner | {{ROLE_QUALITY_MANAGER}} |
| Reviewer | {{ROLE_OHS_COORDINATOR}} |
| Approver | {{ROLE_TOP_MANAGEMENT}} |
| Next Review | 2026-08-15 |
| Classification | Internal |
Held in the document frontmatter, mirrored to the Document Register.