Periodic inspection

What is an internal audit and why is it required?

An internal audit is the organisation testing, at planned intervals and on evidence, whether its own management system meets the requirements and is effectively implemented. Clause 9.2 of ISO 45001 requires it explicitly. Its purpose is not to collect documents but to see whether the system really works — and where it does not.

Definition

An internal audit is the organisation testing its own system at planned intervals. It asks two questions:

  1. Does the system conform to the organisation's own requirements and to the standard's?
  2. Is it effectively implemented and maintained?

The first looks at documents, the second at the floor. An audit that does only the first has audited the filing.

Why it is required

Clause 9.2 of ISO 45001 requires an internal audit. Beyond the requirement it has a function: it is how an organisation finds its own defect before somebody outside does. A finding that surfaces at a certification audit, or after an accident, always costs more than the same finding surfacing internally.

What “on evidence” means

An auditor's impression is not, on its own, a finding. A finding is supported by evidence: a record, an observation, an interview note, a measurement. “It felt wrong to me” is not a finding — at best it is the start of an observation.

Different from an external audit

An external audit comes to certify conformity; an internal audit is done to improve. That difference should change how findings are received: many findings in an internal audit is not bad news but a sign the audit works. A zero-finding internal audit report is usually a sign the audit did not happen.

Manage this in Optifora

Optifora is not a single program but a compliance platform assembled from modules. The catalogue states which module is ready today and which is on the roadmap.

See what Optifora is