Skip to content

Document {{ORG_PREFIX}}-016

Internal Audit Procedure

1. Purpose

This procedure defines how {{ORG_NAME}} audits itself. The programme in Section 3.1 slices the whole IMS into short monthly checks, planned in advance, run by an auditor independent of the area, and logged in the Internal Audit Log. Each slice tests one area against what our own documents say happens there, and against what is actually happening in the work. The programme comes back round, so drift between the two shows up while it is still small. It implements the continual-improvement commitment of the Quality & OH&S Policy.

2. Scope

Every clause-map requirement of both standards, audited through a rolling programme of short monthly slices. One programme serves both disciplines — a slice audits its area's quality and OH&S aspects together. External (certification) audits are out of scope but their findings enter the same corrective-action engine.

3. Procedure

3.1 Audit programme

Instead of one annual audit nobody has time for, the programme runs as twelve short monthly slices; a full cycle covers every clause-map requirement area of both standards at least once. The {{ROLE_QUALITY_MANAGER}} weights the frequency, seeding it with the cycle and re-weighting whenever new findings or new risk emerge mid-cycle: a slice is scheduled more often when it covers work central to the business, when earlier audits raised findings in it, when it has seen recent change, or when it carries higher risk [ORG-DECISION: which slices repeat within a cycle; default: none, cycle covers all]. Scoping follows the same weighting: a slice digs deeper into work that matters most to {{ORG_NAME}} and into areas where earlier audits raised findings.

The programme table below is machine-checked: tools/check_clause_maps.py asserts that the union of the "Clauses covered" tokens spans every clause-index leaf of both standards. Edit it only with that in mind.

Month Slice Clauses covered Auditor role Records
1 Leadership, context & scope Q4; Q5; OHS4; OHS5 [ORG-DECISION: independent role] internal-audits
2 Risk & hazard management Q6.1.1; Q6.1.2; OHS6.1.1; OHS6.1.2.1; OHS6.1.2.2; OHS6.1.2.3; OHS6.1.4 [ORG-DECISION: independent role] internal-audits
3 Objectives & improvement Q6.2; Q10; OHS6.2; OHS10 [ORG-DECISION: independent role] internal-audits
4 Compliance obligations OHS6.1.3; OHS9.1.2 [ORG-DECISION: independent role] internal-audits
5 Competence & awareness Q7.1; Q7.2; Q7.3; OHS7.1; OHS7.2; OHS7.3 [ORG-DECISION: independent role] internal-audits
6 Communication & document control Q7.4; Q7.5; OHS7.4; OHS7.5 [ORG-DECISION: independent role] internal-audits
7 Customer & contract Q8.2; Q9.1.2 [ORG-DECISION: independent role] internal-audits
8 Operational control & delivery Q8.1; Q8.5; Q8.6; OHS8.1.1; OHS8.1.2 [ORG-DECISION: independent role] internal-audits
9 Design & change management Q8.3; Q6.3; OHS8.1.3 [ORG-DECISION: independent role] internal-audits
10 Procurement & contractors Q8.4; OHS8.1.4.1; OHS8.1.4.2; OHS8.1.4.3 [ORG-DECISION: independent role] internal-audits
11 Monitoring, nonconformity & emergency Q9.1.1; Q9.1.3; Q8.7; OHS9.1.1; OHS8.2 [ORG-DECISION: independent role] internal-audits
12 Audit, review & incidents Q9.2; Q9.3; OHS9.2.1; OHS9.2.2; OHS9.3; OHS10.2 [ORG-DECISION: independent role] internal-audits

At instantiation the twelve slices are seeded as dated Schedule register rows (Category: Internal audit) and mirrored as Scheduled rows in the Internal Audit Log; automation A5 prompts the accountable role each month. Where review_programme: quarterly is chosen in the org profile, the same twelve slices are grouped three-per-quarter — coverage is identical, sessions are longer.

3.2 Auditor independence

Auditor selection starts from one rule: no one audits work they own or perform. In a ~25-person organisation this is a real constraint, handled honestly rather than nominally: the {{ROLE_QUALITY_MANAGER}} and {{ROLE_OHS_COORDINATOR}} cross-audit each other's areas, other competent staff are trained as internal auditors for slices touching both, and [ORG-DECISION: external auditor support for the slices no internal person can audit impartially — e.g. slice 12, which covers the audit process itself]. Auditor competence is a Training Curriculum item; the Internal Audit Log records the auditor per session, who must be independent of the area audited.

3.3 Audit execution

Step Action Responsible role Output / record
1 Frame the session: the auditor and the {{ROLE_QUALITY_MANAGER}} agree what this session checks (the clause-map rows for the slice's clauses, the implementing documents, and the standards themselves) and which slice of real work it samples (activities, sites, jobs, and period). Auditor with {{ROLE_QUALITY_MANAGER}} Scope note in the session record
2 Audit against reality: sample records and register rows, follow one job end-to-end where relevant, talk to the people doing the work (awareness questions included), observe field practice where the slice touches it. The test is "is this actually happening", never "does a document exist". Auditor Working notes
3 Record findings: conformities worth noting, nonconformities (requirement not met: cite the clause-map req_id), and observations (conforming but fragile). Auditor Session record
4 Close the loop with people before paper: walk the results through with the managers responsible for the area audited, and take findings relevant to workers to those workers directly and to worker representatives where the workforce has them. OH&S findings are never filed without the people affected hearing them. Auditor Distribution noted in the session record
5 Turn findings into work: every nonconformity becomes a Nonconformity & CAPA Register row (Source: Internal audit) before the session record is filed, carrying both the correction (the immediate fix for the problem found) and the corrective action, handled per the corrective-action procedure; findings and observations also feed the continual-improvement pipeline for OH&S performance. Auditor raises; area owner actions CAPA rows
6 Commit and log: the session record goes to docs/records/internal-audits/YYYY-MM-<slice>.md and the Internal Audit Log row is updated (performed date, auditor, findings count, CAPA links, record link, Status: Done). Together the record and the log show what ran, when, and what each audit found. Auditor Record + register row

4. Records and Registers

Activity Register (index) Record (evidence)
Programme schedule Schedule (Category: Internal audit); Internal Audit Log (Scheduled rows)
Each audit session Internal Audit Log (performed date, auditor, findings, links) docs/records/internal-audits/YYYY-MM-<slice>.md
Findings and actions Nonconformity & CAPA Register Corrective-action records per that procedure

Honest status: docs/records/internal-audits/ is empty until the first slice has actually run. The audit requirement is only honestly "operational" from that first committed record.

5. Exceptions

A slice may be deferred by at most [ORG-DECISION: maximum deferral, e.g. one month] with the {{ROLE_QUALITY_MANAGER}}'s written approval and a rescheduled date — the cycle must still cover every area within [ORG-DECISION: cycle tolerance, e.g. 14 months]. No exception is available to auditor independence or to raising CAPA rows for nonconformities found.

  • quality-ohs-policy — the improvement commitment this implements.
  • nonconformity-corrective-action-improvement-procedure — where findings go.
  • management-review-procedure — audit results are a standing review input.

7. Revision History

Version Date Author Description of Changes Reviewed By Review Date Approved By Approval Date
0.1 2026-07-16 {{ROLE_QUALITY_MANAGER}} Initial draft

8. Document Control

Document{{ORG_PREFIX}}-016
TypeProcedure
Version0.1
StatusDraft
Owner{{ROLE_QUALITY_MANAGER}}
Reviewer{{ROLE_OHS_COORDINATOR}}
Approver{{ROLE_TOP_MANAGEMENT}}
Next Review2026-08-15
ClassificationInternal

Held in the document frontmatter, mirrored to the Document Register.