CRAIG WILLETTS ISO & BUSINESS CONSULTANT
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
  • Business Articles
    • New Business Tips >
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Quality Management
    • ISO 14001 Environmental Management
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Anti-Bribery Management
    • ISO 22000: Food Safety Management
    • ISO 37301: Compliance Management
    • ISO 27701: Privacy Information Management That Goes Beyond GDPR Paperwork
    • ISO 20000 Tips: IT Service Management Made Simple.
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting

Internal audits in plain English 

Picture
If you hear “internal audit” and think “paperwork exercise”, you’re not alone.

But done properly, an internal audit is one of the simplest ways to:
- catch issues before an external auditor does
- stop repeat nonconformities
- prove your system actually works day-to-day

Here’s the plain-English version — what it is, why it matters, and how to do it properly without turning it into a box-ticking nightmare.

What is an internal audit (really)?
An internal audit is a structured check that your processes are:
- being followed
- working as intended
- producing the right evidence

It’s not about “finding fault”.
It’s about finding gaps early — while they’re still easy (and cheap) to fix.

Why internal audits matter (even if you’ve never failed an audit)
Internal audits help you:
-stay in control (instead of reacting to problems)
-reduce risk (issues are spotted before they become incidents/complaints)
-improve performance (you see what’s slowing you down)
-build confidence (you’re ready when a client or auditor asks for evidence)

What auditors expect to see
Most standards expect internal audits to be:
- planned (not random)
- competent (done by someone who understands what “good” looks like)
- recorded (evidence exists)
- followed up (actions are completed and checked)

The simple internal audit process (step-by-step)
Step 1: Plan your audit schedule
Keep it realistic.
For most SMEs:
- audit key processes across the year
- increase frequency for high-risk areas

Example schedule:
- Document control & records
- Training/competence
- Supplier/subcontractor control
- Corrective actions
- Operations/service delivery

Step 2: Define the scope
Be clear on:
- what process you’re auditing
- which site/team it covers
- what time period you’re checking

Step 3: Use a checklist (but don’t rely on it)
A checklist keeps you consistent.
But the best audits come from asking:
- “Show me how you do this.”
- “Where’s the evidence?”
- “What happens when it goes wrong?”

Step 4: Sample evidence (don’t try to check everything)
Pick a handful of real examples:
- 3–5 jobs
- 3–5 training records
- 3–5 supplier files

Audits are about confidence — not perfection.

Step 5: Record findings in plain English
Keep findings simple:
-What you saw
-What it should be
-What’s missing
-What risk it creates

Step 6: Raise corrective actions (with owners + due dates)
If you don’t assign an owner and a date, it won’t happen.

Step 7: Follow up and verify effectiveness
This is where most businesses fall down.

A quick rule:
- fix it
- then check it stayed fixed

Common internal audit mistakes (that cause nonconformities)
- audits are skipped when you’re busy
- audits are “tick-box” with no real sampling
- findings are vague (“needs improvement”)
- actions are raised but never closed
- no follow-up evidence

A simple internal audit template you can copy
Use this structure:
- Audit title + date
- Scope + auditor
- Checklist questions
- Evidence sampled
- Findings (conformity / observation / nonconformity)
- Actions (owner, due date)
- Follow-up outcome

How CAW helps
If you want internal audits done properly (and quickly), we can:
- run your internal audits for you
- train your team to do them confidently
- tighten up the system so audits become easy

If you want the internal audit checklist we use with clients, message us and we’ll send it over.
Picture

If you need any advice or have any questions, then please get in touch - [email protected]

Don't forget to share this blog to help others with get great free advice

Picture
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
  • Business Articles
    • New Business Tips >
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Quality Management
    • ISO 14001 Environmental Management
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Anti-Bribery Management
    • ISO 22000: Food Safety Management
    • ISO 37301: Compliance Management
    • ISO 27701: Privacy Information Management That Goes Beyond GDPR Paperwork
    • ISO 20000 Tips: IT Service Management Made Simple.
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting