跳到主要内容
知仓学习社ZHICANG

iso-9001-internal-audit

>-

不碰外部(只输出文字)无严重或高危命中hashgraph-online/awesome-codex-plugins

它会碰到什么

扫了多少2 个文本文件,30 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

ISO 9001:2015 Internal Audit

Goal

Plan, conduct, and document an ISO 9001:2015 internal audit using objective evidence, correct finding classification, and clear audit reporting. Use this skill for planning an audit programme, conducting process-based or clause-based audits, preparing for third-party certification, or training internal auditors.


When to use

  • Planning an internal audit programme
  • Conducting an internal audit (process-based or clause-based approach)
  • Preparing for a third-party surveillance or recertification audit
  • Training an internal auditor

Required Internal Audit Checklist

☐ Define audit scope, criteria, and objectives before starting

☐ Verify auditor competence and independence (not auditing own work)

☐ Audit the process flow first — map evidence to ISO clauses afterwards

☐ Use open questions throughout — no leading questions, no yes/no questions

☐ Verify every answer with objective evidence ("show me", "let me see")

☐ Use sampling: interview multiple people, review multiple records, different time periods

☐ Classify findings correctly (Major / Minor / OFI) — do not downgrade under pressure

☐ Record objective evidence clearly and traceably for every finding

☐ Check effectiveness of previous corrective actions from prior audit cycles

☐ Confirm process performance against KPIs

☐ Issue a balanced audit report (findings + strengths)

☐ Track all Major and Minor NCs to closure with owner, due date, and effectiveness verification


Audit approach — process-based first

Preferred audit method: audit the process flow first, then map evidence to ISO clauses.

Follow the process: inputs → activities → outputs → performance indicators. Find where requirements are addressed in practice. Only then link findings to specific clauses. This avoids "checklist auditing" and produces more useful, systemic findings.

Use sampling throughout: interview at least 2–3 people, review at least 2–3 records, and cover different time periods. One record is not enough to confirm systemic conformity.


Audit finding classification

| Grade | Definition |

|-------|-----------|

| Major non-conformance | Complete absence of a required element; systemic failure of a process; direct failure to achieve the intended result of the QMS |

| Minor non-conformance | Isolated or single occurrence of a requirement not being met; partial implementation; one piece of objective evidence missing |

| OFI (Observation / Opportunity for Improvement) | Technically conforming, but auditor sees risk or a better approach — no immediate action required |

Guidance: A major NC directly threatens the QMS intent; a minor NC is a gap that could become major if not addressed. Downgrading a major to minor to avoid customer concern is an audit integrity failure.

Repeated minor non-conformances in the same process may constitute a major non-conformance due to systemic failure — treat patterns as systemic, not isolated.

Writing findings: Each finding must include:

  1. Requirement (the ISO clause or procedure that was not met)
  2. Objective evidence (what was observed, measured, or reviewed)
  3. Statement of non-conformity (what the gap is)

Avoid conclusions without linking evidence to the specific requirement.


Clause-by-clause key questions

§4 — Context of the Organisation

§4.1 — Understanding the organisation and its context

  • Is the context of the organisation documented (internal and external issues affecting the QMS)?
  • Are strategic direction and relevant interested parties considered?
  • Is the analysis reviewed and updated? When was it last updated?
  • Evidence: SWOT, PEST analysis, or equivalent strategic analysis document

§4.2 — Understanding needs and expectations of interested parties

  • Is there a list of interested parties (customers, regulators, employees, suppliers)?
  • Are their relevant needs and expectations identified?
  • Which of these have become QMS requirements?
  • Evidence: stakeholder register, customer requirements register

§4.3 — Scope of the QMS

  • Is the scope documented?
  • Is it justified (exclusions explained if any)?
  • Is it available to interested parties?
  • Evidence: scope statement in Quality Manual or equivalent

§4.4 — QMS and its processes

  • Are QMS processes identified with their inputs and outputs?
  • Are process sequence and interactions defined (process map)?
  • Are resources, responsibilities, and monitoring defined for each process?
  • Are process risks, KPIs, and owners defined for each QMS process?
  • Evidence: process map or turtle diagrams

§5 — Leadership

§5.1 — Leadership and commitment

  • Can top management demonstrate involvement in the QMS? (not just sign the policy)
  • Is customer focus promoted at the leadership level?
  • Are quality objectives integrated into business processes?
  • Can top management explain current quality objectives, major risks, and customer performance issues without relying on the quality manager?
  • Evidence: management review records, objective tracking, signed policies

§5.2 — Policy

  • Is the quality policy documented, signed by top management?
  • Does it provide a framework for quality objectives?
  • Is it communicated and understood by employees? (test: ask a random employee)
  • Is it available to interested parties?
  • Evidence: quality policy document + evidence of communication (intranet, notice boards, training)

§5.3 — Roles, responsibilities and authorities

  • Are QMS-relevant roles defined with clear responsibilities?
  • Is there a designated management representative (or equivalent)?
  • Are responsibilities for customer focus assigned?
  • Evidence: organisation chart, job descriptions, quality roles matrix

§6 — Planning

§6.1 — Actions to address risks and opportunities

  • Are risks and opportunities identified from the §4.1 and §4.2 analysis?
  • Are actions defined to address significant risks?
  • For each significant risk: is there a defined action, owner, due date, and follow-up evidence?
  • Are actions integrated into QMS processes?
  • Evidence: risk register, risk-based thinking documented in process documents

§6.2 — Quality objectives and planning

  • Are quality objectives established at relevant functions and levels?
  • Are they SMART? (Specific, Measurable, Achievable, Relevant, Time-bound)
  • Are there plans to achieve each objective (resource, responsible, timeline)?
  • Are they monitored and communicated?
  • Evidence: quality objectives document with current KPI data

§6.3 — Planning of changes

  • When changes to the QMS are planned, is there a structured approach?
  • Are purpose and potential consequences assessed before the change?
  • Is integrity of the QMS maintained through changes?
  • Evidence: change management records, MOC (Management of Change) procedure

§7 — Support

§7.1.1 — Resources (general)

  • Does the organisation determine and provide necessary resources?
  • Are resource constraints documented and addressed?

§7.1.2 — People

  • Are sufficient competent people available for QMS processes?

§7.1.3 — Infrastructure

  • Is infrastructure (buildings, equipment, IT) identified and maintained?
  • Is maintenance documented?
  • Evidence: equipment list, maintenance schedule and records

§7.1.4 — Environment for the operation of processes

  • Are process environment requirements identified and maintained?
  • (Temperature, humidity, cleanliness, noise — as applicable)

§7.1.5 — Monitoring and measurement resources

  • Is all monitoring and measurement equipment identified?
  • Is calibration / verification performed at defined intervals?
  • Are calibration records maintained?
  • Is equipment identified with calibration status?
  • What happens when a gauge is found out-of-calibration? (suspect product assessment)
  • Evidence: calibration master list, calibration certificates, out-of-cal procedure

§7.2 — Competence

  • Are competence requirements defined for all quality-affecting roles?
  • Are training records maintained for all relevant personnel?
  • Is effectiveness of training evaluated?
  • Are personnel aware of their contribution to quality objectives?
  • Can sampled employees explain what they do if they detect a non-conforming output?
  • Evidence: competence matrix, training records, evaluation results

§7.3 — Awareness

  • Are personnel aware of the quality policy?
  • Do they know their contribution to achieving quality objectives?
  • Do they know the implications of non-conforming output?
  • Can sampled employees explain what they do if they detect a non-conformance?
  • Evidence: induction training records, toolbox talks, awareness campaign evidence

§7.4 — Communication

  • Is internal and external communication relevant to the QMS defined?
  • What is communicated? By whom? To whom? When? How?

§7.5 — Documented information

  • Is documented information required by the standard available and current?
  • Is organisation-specific documented information identified?
  • Is document control defined (review, approval, version control, distribution)?
  • Is access controlled — only current versions at point of use?
  • Is obsolete documentation prevented from unintended use?
  • Are records protected from modification and kept for defined periods?
  • Evidence: document control procedure, master document list, sample controlled documents

§8 — Operation

§8.1 — Operational planning and control

  • Are operational processes planned and controlled?
  • Are process criteria established?
  • Are controls implemented to meet criteria?
  • Is documented information maintained to confirm processes were carried out as planned?

§8.2 — Requirements for products and services

  • Are customer requirements determined (including legal/regulatory)?
  • Are requirements reviewed before commitment (order review)?
  • Are customer communications processes defined?
  • Evidence: order review records, customer requirement register

§8.4 — Control of externally provided processes/products/services

  • Is there an approved supplier list?
  • Are supplier evaluation criteria defined?
  • Are suppliers monitored (performance data, audits)?
  • Are purchasing controls appropriate to the risk?
  • Evidence: approved supplier list, supplier evaluation records, supplier KPIs

§8.5.1 — Control of production and service provision

  • Are work instructions available at the point of use?
  • Are product/service characteristics and acceptance criteria defined?
  • Are process controls defined and maintained in alignment with Control Plan / work instructions?
  • Is suitable monitoring/measurement equipment available and used?
  • Is qualified personnel used? Are qualification records available?
  • Are outputs identified and traceable?
  • Evidence: work instructions at workstations, control plans, batch records

§8.5.2 — Identification and traceability

  • Can product be traced from raw material to delivery?
  • Is traceability documented throughout the process?
  • Can suspect material be isolated when needed?

§8.7 — Control of nonconforming outputs

  • Is there a documented process for controlling non-conforming product?
  • Is non-conforming product identified and segregated?
  • Are dispositions documented with approval?
  • Is corrective action initiated for significant NCs?
  • Evidence: NCR log, NCR records, quarantine area, disposition approvals

§9 — Performance Evaluation

§9.1 — Monitoring, measurement, analysis and evaluation

  • Are quality KPIs defined and monitored?
  • Is customer satisfaction measured and monitored?
  • Is the data analysed and used for decision-making?
  • Evidence: KPI dashboard, customer satisfaction data, trend analysis

§9.2 — Internal audit

  • Is there an internal audit programme covering all QMS processes?
  • Is the audit programme based on process importance, prior results, and risk?
  • Are auditors competent and independent of the area being audited?
  • Are audit findings documented and corrective actions followed up?
  • Are audit records maintained?
  • Evidence: audit programme, audit reports, CAPA from audit findings

§9.3 — Management review

  • Is management review conducted at planned intervals?
  • Does the agenda cover all required inputs? (§9.3.2)
  • Are outputs documented (decisions and actions)?
  • Are action items followed up from previous reviews?
  • Evidence: management review minutes with all required inputs and action tracking

§10 — Improvement

§10.1 — General

  • Is there evidence of continual improvement activity?
  • Are opportunities for improvement being identified and acted upon?

§10.2 — Nonconformity and corrective action

  • Is there a documented process for corrective action?
  • Are root causes investigated for significant NCs?
  • Are corrective actions proportionate to the effect of the non-conformity?
  • Are corrective actions reviewed for effectiveness?
  • Are actions taken to prevent similar NCs in other areas?
  • Are records maintained? (§10.2.2)
  • Evidence: CAPA register, CAR records, VOE evidence

§10.3 — Continual improvement

  • Are quality objectives driving improvement?
  • Is performance data used to identify improvement opportunities?
  • Are improvement tools (8D, PDCA, lean, Six Sigma) used systematically?

Audit report structure

INTERNAL AUDIT REPORT
Standard: ISO 9001:2015
Audit criteria: ISO 9001:2015 clauses, internal procedures, customer-specific requirements (if applicable)
Scope: [Process or clause range]
Date: [Audit date]
Auditor: [Name, qualification]
Auditee: [Department/process owner]

FINDINGS SUMMARY:
Major NC: [count]
Minor NC: [count]
OFI: [count]

FINDINGS:

Finding 1 — MAJOR NC
Clause: §9.3 Management Review
Requirement: ISO 9001 §9.3.2 requires management review to include analysis of 
quality objectives performance.
Evidence: Management review minutes dated 2026-03-15 reviewed. Quality objective 
tracking data was not included or referenced. Quality manager confirmed no objectives 
were discussed at the last two management reviews.
Finding: Systemic absence of quality objectives review in management review process.

[Repeat for each finding]

STRENGTHS:
[Positive observations — balanced audit report]

REQUIRED ACTIONS:
[List major and minor findings requiring CAPA with target dates]

Corrective action follow-up

All Major and Minor NCs must enter corrective action tracking with:

  • Owner (named person)
  • Target due date
  • Effectiveness verification (evidence that the action worked, not just that it was done)

The audit programme must follow up on all prior CARs — open CARs from previous audits must be reviewed in the next cycle.


Common audit mistakes

  • Leading questions: "You do have a calibration procedure, right?" → ask open questions: "How do you manage measurement equipment calibration?"
  • Accepting verbal answers: always ask for objective evidence (show me, let me see)
  • Clause-hunting vs. process approach: audit the process first, then map to clauses — not the other way round
  • Downgrading findings under pressure: if the evidence supports a Major NC, write a Major NC
  • Not following up previous findings: the audit programme must track closure of prior CARs
  • Single-record sampling: one conforming record does not confirm systemic conformity — always sample multiple records and people

Output Format

At the start of each use, ask the user:

> "How would you like to receive the output?

> A — Structured Markdown (formatted tables and sections, ready to copy)

> B — Plain tables (simplified structure for Excel or Word)

> C — Narrative report (flowing text for a formal document or email)

>

> Default: A."

Adapt all output sections to the chosen format. If the platform or session context already defines a format preference, skip this question.

Reference files

  • [Clause-by-clause question bank](references/clause-questions.md)

Changelog

| Version | Date | Author | Change |

|---------|------|--------|--------|

| 1.0 | 2026-06-01 | @RBraga01 | Initial release |

| 1.1 | 2026-06-03 | @migmcc | Expanded clause-by-clause question bank and evidence anchors |

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 1,027
本站分层T1
该仓技能数1910
原文件路径plugins/RBraga01/Quality-Engineering-Skills/skills/audit/iso-9001-internal-audit/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 1910 个技能