What Is an Internal Audit?

An internal audit is an organization auditing its own management system on its own behalf. In the literature it is also referred to as a first-party audit.

Its purpose is to verify that the system is implemented in conformity with the requirements of the standard and the organization’s own arrangements, and that it is effective.

Types of audit

Methodological reference

ISO 19011 sets the methodological framework for internal and second-party audits. The 4th edition of the standard was published on 27 May 2026 and withdrew ISO 19011:2018.

Since ISO 19011 is a guidance standard, no transition period was granted; it is in force from publication. If your audit procedure, auditor competence criteria and report templates are still based on the 2018 edition, they need to be updated.

The condition for an effective internal audit

The value of an audit lies in the quality and follow-up of the findings. Findings not based on evidence do not turn into corrective action; findings not followed up are reopened at the next audit.

How often and with what scope audits are conducted is defined in the audit programme.

Internal audit is a common requirement of all management systems; the methodology is independent of the standard. Audit planning, evidence collection and reporting skills are addressed hands-on in the ISO 19011:2026 audit training. For audit competence specific to a particular standard, see our training for that standard.