ISO 9001:2015
Performance evaluation – ISO 9001:2015

ISO 9001:2015 9.2: Internal audit

At planned intervals the organization carries out internal audits that tell it whether its QMS meets both its own requirements and those of the standard, and whether the system is effectively implemented and maintained. It plans, sets up, runs and maintains an audit programme that fixes how often audits happen, the methods and responsibilities, what planning must cover, and how results are reported, weighted by how important each process is, by changes that affect the organization and by what earlier audits found. For each audit it sets criteria and scope; it chooses auditors and runs audits so that they are objective and impartial; it makes sure results reach the relevant managers; it takes suitable correction and corrective action promptly; and it retains documented information showing the programme was carried out and what it found.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 45 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

COBIT 2019 · 3 controls

  • MEA04.01 MEA04.01 Ensure that assurance providers are independent and qualified
  • MEA04.04 MEA04.04 Define the scope of the assurance initiative
  • MEA04.08 MEA04.08 Report and follow up on the assurance initiative
  • 4.5.5 Internal Audit
  • SPC1-4.5.6 Internal Audit

ISO 14001:2015 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme

ISO 21001:2025 · 2 controls

  • 9.2.1 9.2.1 General
  • 9.2.2 9.2.2 Internal audit programme
  • ISO-37002-9.2 Internal audit
  • ISO37002-9.2 Internal Audit

ISO 37301:2021 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme
  • ISO-39001-9.2 Internal audit
  • ISO39001-9.2 Internal Audit
  • ISO-41001-9.2 Internal audit
  • ISO41001-9.2 Internal Audit

ISO 45001:2018 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme
  • ISO-50001-9.3 Internal audit
  • 9.2 Internal audit

ISO 56002 · 2 controls

  • ISO-56002-9.2 Internal audit
  • ISO56002-9.2 Internal audit

ISO/IEC 27003:2017 · 2 controls

  • CPS220-11 Annual Audit Review of the Framework
  • AS9100D-9.2 Internal Audit
  • OS4.4 Standard 4.4 Systematic monitoring, evaluation and continuous improvement

ISO 10002:2018 · 1 control

  • 8.5 8.5 Auditing of the complaints-handling process

ISO 13485:2016 · 1 control

ISO 14004:2016 · 1 control

  • 9.2 Internal audit

ISO 19011:2018 · 1 control

  • 6.2 Initiating audit

ISO 21001:2018 · 1 control

  • 9.2 9.2 Internal audit

ISO 22000:2018 · 1 control

  • 9.2 Internal audit

ISO 22301:2019 · 1 control

  • 9.2 Internal audit

ISO 27001:2022 · 1 control

  • 9.2.2 Internal audit programme

ISO 27701:2019 · 1 control

  • ISO28001-4.17 Internal audit

ISO 30401 · 1 control

  • ISO30401-9.2 Internal audit

ISO 37001:2016 · 1 control

  • 9.2 9.2 Internal audit

ISO 55001:2014 · 1 control

  • 9.2 Internal audit

ISO/IEC 27031:2011 · 1 control

  • 27031-9.2 Internal Audit

ISO/IEC 42001:2023 · 1 control

  • 9.2 Internal audit

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Performance evaluation – ISO 9001:2015

Query this from an agent

The graph holds this control, the 45 it maps to, and the evidence behind each claim, over MCP and REST.