GeoBusinessIQGeoBusinessIQ

Internal quality audits: finding your own problems before somebody else does

What this answers

Is our audit programme finding things we did not already know, or confirming what we hoped?

An internal audit programme exists to give the business bad news early and cheaply, at a moment when fixing the issue costs a conversation rather than a containment. Most programmes fail at exactly that point. They are scheduled evenly across departments regardless of risk, conducted by people who report to the area they are examining, and closed out with actions that restate the finding as a promise to be more careful.

Written for: quality managers, internal auditors, site management teams.

Schedule by risk, not by fairness to departments

Coverage spread evenly over the year gives equal attention to a stable process making a low-consequence part and to a new line running a safety-critical feature with unfamiliar tooling. Weight the plan instead towards recent change, recent complaints, processes whose failure would reach a customer undetected, areas with staff turnover, and anything the last audit found weak. Keep some deliberately unscheduled capacity for reacting to a problem while it is live. Publishing the full year in advance is convenient administratively and guarantees that every area is at its best exactly once.

Independence is structural, not a matter of good intentions

Nobody audits work they perform, specify or manage, and nobody audits an area whose manager writes their appraisal. In a small plant that is hard, and the workarounds are to swap auditors between areas, to bring in an auditor from a sister site, or to use a competent outsider periodically. Where independence is genuinely unachievable, say so in the report rather than pretending. The failure mode is not usually dishonesty; it is that a person embedded in an area stops seeing its habits, and cannot ask the naive question that exposes them.

Auditor competence is more than an auditing course

A qualified auditor who does not understand the process will verify that records exist and miss that they are meaningless. The strongest internal auditors are experienced people from another function — a maintenance engineer auditing assembly, a planner auditing goods receipt — trained in evidence and questioning technique. Pair a technical person with an experienced auditor when the process is unfamiliar. Guard against the opposite failure too: a subject expert who spends the audit fixing the problem or explaining how they used to do it, and returns with no findings and no notes.

The soft-finding problem and how to see it

Programmes decay quietly. Findings become observations, observations become verbal comments, and eventually the report contains only praise and a note that housekeeping could improve. Two indicators expose this early: how many internal audits raised anything substantive over the past cycle, and how many issues found by customers or external auditors had been walked past internally. When the second number exceeds the first, the programme is decorative. Reviewing the ratio in front of the management team, rather than the completion percentage of the schedule, changes what auditors feel able to write.

Closing out without pretending

An action that reads as retraining the operator or reminding the team almost never holds, because it treats a system weakness as a memory lapse. Push for a change in the arrangement itself: the check that was not possible becomes possible, the document that was ambiguous is rewritten, the step that could be skipped is made impossible or visible. Verification means returning to the same area later and looking again, not accepting an email confirming completion. Findings that survive their own closure are the most valuable data the programme generates, so track them separately.

Frequently asked questions

How often should each area be audited?
Frequently enough that a control failure is caught within a period you could contain, which varies enormously by area. A high-consequence process with frequent changes may warrant several looks a year, while a stable low-risk operation with a clean history may need only an annual check. Fix the frequency to the risk assessment, review that assessment when something changes, and record why an area was moved up or down the plan.
Should internal audits be used to prepare for a certification audit?
Using them as rehearsal is legitimate and using them only as rehearsal is a waste. If the programme runs hard in the weeks before an external visit and idles afterwards, the plant is buying a certificate rather than managing risk. A better pattern is steady coverage year-round, with an additional readiness review before the external audit that focuses on evidence availability and on any area where the previous external visit raised something.
Can we use production staff as auditors without disrupting output?
Yes, and it is often the best option, provided the time is planned rather than squeezed in. Budget the hours in the area's plan, keep individual audits short and focused on one process, and train enough people that no single auditor becomes a bottleneck. The side benefit is substantial: people who audit another department come back with ideas about their own, which is a return the programme rarely gets credit for.

Data limitations

  • Standards are referenced, never reproduced. Pages describe what a standard governs and point to the issuing body; they do not restate its requirements, and conformity is determined by the standard itself and by an accredited assessment, not by anything here.
  • Manufacturing figures are operator-supplied inputs, not market data. GeoBusinessIQ holds no factory costs, production volumes, yields, cycle times, tooling prices or capacity data and does not estimate them — every result reflects only the figures you enter.

Explore the graph

Sources

  • International Organization for Standardization ISO (accessed )
    Covers: International standards for quality management, environmental management, occupational health and safety, and industrial processes.
    Does not cover: The content of any standard, conformity decisions, or certification status of any organisation.
    Why it matters: Cited so a reader can reach the issuing body's own public description of a standard. Standard text is never reproduced here.
    Review cadence: annual
  • NIST Manufacturing Extension Partnership NIST MEP (accessed )
    Covers: A public programme supporting small and medium manufacturers with operational, quality and technology adoption practice.
    Does not cover: Results attributable to any specific manufacturer, or improvement figures transferable to another plant.
    Why it matters: Cited for the operational practice it publishes for smaller manufacturers, not for benchmarks or outcome claims.
    Review cadence: annual

Educational and operational information only — not legal, engineering, safety, customs, tax, or financial advice. Requirements vary by jurisdiction, product, process, and contract; confirm with the relevant authority or a qualified professional before acting.

Last updated: