Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

Independent ISO Internal Audit Services Australia (Clause 9.2)

Need an ISO internal audit before certification, surveillance or recertification? Streamline provides independent ISO internal audit services across Australia, remotely or on-site. We audit your management system against the relevant standard, your own processes and the evidence that shows whether the system is working.

The short answer

An internal audit is your chance to find the problems before the certification body does. Clause 9.2 asks whether the management system meets the applicable ISO requirements, meets your organisation’s own requirements, and is effectively implemented and maintained.

The audit can cover ISO 9001, ISO 27001, ISO 42001, ISO 45001, ISO 14001 or an integrated management system.

Request an internal audit quote →
Independent ISO internal auditor reviewing records and evidence
A useful internal audit tests the system against the standard, your own documented arrangements and what is happening in practice.

What clause 9.2 requires you to check

Clause 9.2 requires internal audits at planned intervals. The audit has to provide information on whether the management system:

  1. conforms to the organisation’s own requirements for its management system;
  2. conforms to the requirements of the applicable ISO standard or standards; and
  3. is effectively implemented and maintained.

In plain English, if the standard says you need to do it, or your own management system says you do it, it is fair game for the audit. That includes the commitments made in your policies, procedures, plans and other management system information.

For ISO 27001 and ISO 42001, the audit criteria also include the applicable controls adopted through the Statement of Applicability. This does not mean every Annex A control automatically applies. It means the audit should test the applicable controls selected by the organisation, together with clauses 4 to 10 and the organisation’s own requirements.

Auditing guidance has changed: ISO 19011 was revised in 2026. Our summary explains what changed in ISO 19011:2026 and what it means for audit programmes.

On this page

  • What clause 9.2 requires you to check
  • When do you need an ISO internal audit?
  • What our ISO internal audit services cover
  • How the internal audit works
  • What you receive
  • Objective does not always mean outsourced
  • Internal audit, gap analysis or certification audit?
  • Remote and on-site audits across Australia
  • How often should internal audits be completed?
  • Fees and how we quote
  • Frequently asked questions

When do you need an ISO internal audit?

Every certified management system requires internal audits at planned intervals. The audit is not only a hurdle before certification. It is one of the checks that tells management whether the system remains suitable, is being followed and is producing the intended results.

  • Before your first certification audit: to confirm the system has been implemented and the evidence is ready.
  • Before a surveillance or recertification audit: to identify weaknesses before the certification body arrives.
  • After significant change: such as a new site, system, process, acquisition, technology platform or regulatory requirement.
  • When performance is slipping: repeated complaints, incidents, missed objectives or recurring corrective actions are signs that the system needs a closer look.
  • When internal independence is difficult: a small team may not have someone competent who can audit without reviewing their own work.

What our ISO internal audit services cover

We agree the scope before the audit starts. That normally includes the applicable clauses of the standard, your documented processes, legal and contractual requirements included in the system, previous findings, objectives, risks, controls and evidence of day-to-day operation.

The work is not a document review dressed up as an audit. We interview the people doing the work, sample records, trace evidence and test whether the controls operate as described. The aim is to find weaknesses that matter, not to produce a long report full of minor observations.

Standards we audit

  • ISO 9001 internal audits for quality management systems
  • ISO 27001 internal audits for information security management systems
  • ISO 42001 internal audits for artificial intelligence management systems
  • ISO 45001 internal audits for work health and safety management systems
  • ISO 14001 internal audits for environmental management systems
  • Integrated audits covering several standards in one coordinated programme

How the internal audit works

1. Scope and audit plan

We confirm the standard, sites, processes, timing and any areas of concern. You receive a practical audit plan so the right people and records are available without bringing the business to a halt.

2. Document and evidence review

We review the relevant management system information, previous audit findings and performance data. During the audit we interview staff, sample records and follow evidence through the process.

3. Findings and closing discussion

We discuss the findings before finalising them. There should be no surprises in the report. You will understand what was found, the evidence behind it and why it matters.

4. Internal audit report

You receive a structured report identifying conformity, nonconformity and opportunities for improvement. It is written for action, with enough evidence to support the finding and demonstrate that clause 9.2 has been addressed.

What you receive

  • An agreed audit scope and plan
  • An opening and closing discussion with the relevant people
  • A clause and process-based assessment supported by sampled evidence
  • A clear internal audit report suitable for management review and certification evidence
  • Findings separated into nonconformities and practical opportunities for improvement
  • Clarification of findings and, if agreed, verification that corrective actions have been closed

Objective does not always mean outsourced

The standards require the audit process to be objective and impartial. They do not say every internal audit must be outsourced. A competent employee can audit an area where they are not responsible for the work and can demonstrate impartiality.

That can be difficult in a small organisation. If the proposed auditor designed, operates or owns the process, they may end up marking their own homework. An external auditor is a practical way to address that problem and bring experience from other management systems.

Where Streamline has already helped with your system, we confirm the independence boundary during scoping. The auditor must not be placed in the position of auditing their own work.

Internal audit, gap analysis or certification audit?

  • Internal audit: tests an implemented management system against the standard, your arrangements and the evidence of operation.
  • Gap analysis: identifies what is missing or underdeveloped, usually earlier in an implementation or improvement project.
  • Certification audit: is conducted by an accredited certification body that decides whether certification can be granted or maintained. See our guide to choosing an ISO certification body in Australia.

We provide internal audits and gap analyses. We do not award certification, which keeps the consultant and certification body roles clear.

Remote and on-site audits across Australia

Our ISO internal audit services are available remotely using Teams or Zoom and on-site by arrangement. Remote auditing works well where records and processes are digital. On-site auditing is better where physical conditions, operational controls, equipment or workplace practices need to be observed. We will recommend the method that fits the scope rather than forcing every audit into the same format.

How often should internal audits be completed?

Clause 9.2 does not prescribe one annual audit for every organisation. Your audit programme should set planned intervals based on the importance of the processes, changes affecting the business and previous audit results. In practice, this requires risk-based thinking.

The programme should not give every process identical attention. A business-critical or higher-risk process, a control protecting sensitive information, an area with significant environmental or safety consequences, a recently changed process or one with recurring findings may need greater frequency, depth or sample size. A stable, lower-risk process may justify less attention.

Importance is wider than a single risk score. It can include customer and business impact, legal and contractual obligations, significant environmental aspects, safety consequences, information sensitivity and the effect of failure on the management system. The audit programme should show how those factors influenced what is audited, when and how deeply.

Many small and medium businesses choose an annual whole-of-system audit, often before certification or surveillance. A larger or integrated system may be covered through several audits across a defined programme.

Fees and how we quote

We normally quote a fixed fee after confirming the standard, scope, number of sites, system complexity and whether the audit will be remote or on-site. A small single-standard system requires less time than a multi-site or integrated management system.

Our ISO internal audit cost guide explains the main price drivers. If you send us the certificate scope or draft scope, standards and number of locations, we can give you a realistic figure without putting you through a sales pitch.

“We recently completed our ISO 9001 and ISO 27001 audits with Scott and couldn’t be happier with the experience. Scott was friendly, professional, efficient, and clearly very knowledgeable.”

Jason Williams, MAX (Tabcorp)

Frequently asked questions

Can internal audits be outsourced?

Yes. An external auditor is an accepted way to obtain competent, objective and impartial audit evidence, particularly where nobody internally can audit without reviewing their own work.

Can I conduct my own ISO internal audit?

You can use an internal employee if they are competent and can audit objectively and impartially. They should not audit work for which they are responsible. In a small team, outsourcing all or part of the programme may be the cleaner option.

Is an internal audit the same as a certification audit?

No. An internal audit is commissioned by your organisation as part of the management system. A certification audit is conducted by a certification body and can result in certification being granted, maintained, suspended or withdrawn.

Can the audit be completed remotely?

Often, yes. Remote audits work well where interviews, records and operational evidence can be accessed digitally. On-site work may still be needed to observe physical activities, controls or workplace conditions.

How long does an internal audit take?

It depends on the standards, scope, number of sites, employee numbers, complexity and maturity of the system. We confirm the audit duration and reporting allowance in the quote so you know what is included.

What happens if the audit finds a nonconformity?

Your organisation records the correction and corrective action, investigates the cause and keeps evidence that the action was effective. The auditor can clarify the finding and verify closure, but management owns the response.

Book an independent ISO internal audit

Tell us which standard or integrated system you need audited, your location, timing and whether this is for certification, surveillance or an existing audit programme. We will confirm the scope, method and fixed fee before work begins.

Request an internal audit quote →

Email hello@streamline.business or call Brisbane on 07 3667 8280, Sydney on 02 8315 7780 or Melbourne on 03 9034 3990.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • Quality inspector in an Australian machining workshop checking a machined aluminium component against a tablet record, with CNC machines and Australian flags behind
    How Much Does ISO 9001 Certification Cost in…
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • Tilt-shift miniature naval shipyard inspection bay with a submarine hull section on keel blocks and workers in hi-vis checking tagged components in a parts quarantine area
    ISO 19443: The Nuclear Supply Chain Standard, and…
  • Manager reviewing a budget spreadsheet
    ISO 27001 Certification Cost & Timeline in Australia…
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • Tilt-shift miniature of an industrial waste and chemical storage compound with segregated skips and bunded drums, beside a building with a solar-panelled roof
    ISO 14001 Certification Cost & Timeline in Australia…

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire