Internal audits
Last checked on
This is where you plan your internal audits per year, record who carries them out and why they are independent, note the findings per requirement and download the report.
Why this protects your organisation
An internal audit is your own dress rehearsal. You find weak spots before a customer or an external auditor does, and you have time to fix them. Because nobody can judge their own work fairly, the auditor records why they are independent. ISO 27001 asks in clause 9.2 for an audit programme that covers everything within the cycle.
Steps
- Open Internal audits in the Improve group and click New internal audit.
- Under Plan, fill in the subject, programme year and planned date. Choose the requirements the audit covers and describe the criteria. Click Create.
- Under Auditor, choose who carries out the audit, confirm their independence and explain why they are independent.
- After the audit, record the date it was performed and the conclusion under Result.
- Add what the audit found per requirement under Findings.
- If a finding is a minor or major nonconformity, click Open nonconformity on that finding.
- Download the report with Download report at the top of the page, or with Report in the list.
The audit programme
Each audit belongs to a Programme year. The list groups audits by year, so you can see what is planned this year and what has been done. The Status column shows Planned or Performed, and Findings shows how many findings there are.
Under Subject you describe what you are auditing, such as access management or supplier management. Under Requirements you pick the requirements from your adopted standards that the audit covers. Under Criteria you record what you audit against: your own policy, a procedure or the requirement itself.
The auditor
An internal auditor may not audit their own work. Choose the auditor from the people in your organisation and explain why they are independent of what is being audited, for instance because they work in another department. An external consultant who audits for you can also update the audit as an advisor in the workspace, once the owner gives them edit rights for the Improvement module.
Findings
For each finding you choose its kind (Conformity, Observation, Minor nonconformity or Major nonconformity), the requirement it relates to and what the auditor found. You follow up a minor or major nonconformity with Open nonconformity: Trustbird creates a nonconformity with the audit subject, the requirement and the finding's description. The finding then links to that nonconformity.
The report is a PDF with the plan, the auditor, the conclusion and the findings. Everyone in the workspace can download it, and the results come back in the management review.
If it does not work
I cannot save the audit with a Performed on date
An audit only counts as performed once the auditor's independence is confirmed. Switch on The auditor is independent of what is audited and add a short explanation under Why the auditor is independent.
The Requirements list is empty
You can only choose requirements from standards your workspace has adopted. Adopt a standard first in the Prove group.
The planned date is highlighted
The planned date has passed and the audit has not been recorded as performed. Carry out the audit and fill in Performed on, or plan it again with a new date.
I cannot delete a finding
A finding that has already opened a nonconformity stays in place, so the link is kept. Owners and members can add and edit findings, as can advisors with edit rights for the Improvement module.
Screens this is about
- Internal audits