ISO 9001:2026 Internal Auditor

Wishlist Share

About Course

ISO 9001:2026 Internal Auditor

Course code Price Duration Level
FS55 R4670 R3850
Limited period special
About 13 hours, self paced Intermediate

About this course

Last year the site planned twelve internal audits and did four. None of the four went near sales, product development or planning, which is where the complaints were coming from. Two of them were done by the manager of the department being audited. Both reports were short and both were clean. Nobody lied. They audited what they already knew, asked the questions they already had the answers to, and walked past what they walk past every day.

That is the programme most internal auditors inherit. Clause 9.2 asks for something else: audits at planned intervals that tell management whether the system conforms and whether it is effectively implemented and maintained, run by people who are not auditing their own work, with findings that somebody acts on without undue delay. The standard tells you what the programme must include. It does not tell you what to ask the managing director, how many complaint files to pull, or how to write a finding the process owner cannot argue with. This course does.

About thirteen hours, six modules, two practice exercises, and a three part assessment that is marked online, with nothing to upload. You are appointed to the audit team of a case site for its first full ISO 9001:2026 programme, and by the end you have planned two audits, conducted them on a simulated evidence pack, written the findings, reported, and decided whether two corrective action responses can be closed. The course is built on two documents, clause by clause. ISO 9001:2026 clause 9.2 is the requirement you audit for. ISO 19011:2026, Guidelines for auditing management systems, which the Note to 9.2.2 points to, is the guidance the method follows, and the course cites it by clause: 4.2 to 4.8 for the principles, clause 5 for the audit programme, clause 6 for conducting the audit, clause 7 for the competence and evaluation of auditors, and the informative Annex A for the detail. ISO 19011:2026 says “should”, not “shall”: it is guidance, not a requirement, and the course keeps that line visible.

ISO 19011:2026, the fourth edition, was published by ISO in May 2026 and cancels and replaces the third edition, ISO 19011:2018. Its foreword names two main changes: “expansion of guidance on remote auditing methods through the introduction of guidance contained in ISO/IEC TS 17012” and “expansion of Annex A to provide guidance on remote auditing methods and virtual locations”. The seven principles of auditing (4.2 to 4.8) and the three areas, managing an audit programme (clause 5), conducting an audit (clause 6) and the competence and evaluation of auditors (clause 7), are still there. Lesson 4.6, on remote and hybrid audits, virtual locations and digital tools, is new in this course because of that emphasis: when a remote audit is appropriate and when it is not, what a screen share or a live video walk can and cannot evidence, and how to control staged evidence. It draws on the definitions of remote auditing method (3.4) and audit scope (3.6, whose Note 1 names physical and virtual locations) and on A.16, Using remote auditing methods. The controls are ASC’s practical method; none of them is a requirement of ISO 19011:2026 or of ISO 9001:2026.

The ISO 19011:2026 clauses this course covers

Module ISO 19011:2026 clauses
Module 1: the internal auditor, the requirement and the principles 3 Terms and definitions (audit criteria, audit evidence, audit finding, audit conclusion); 4.2 to 4.8, the seven principles of auditing; 7.1 to 7.6, Competence and evaluation of auditors
Module 2: auditing the requirements, clauses 4 to 10 6.4.7 Collecting and verifying information; A.6 Sampling; A.8 Auditing context; A.9 Auditing leadership and commitment; A.10 Auditing risks and opportunities; A.17 Conducting interviews; 6.7 Conducting the audit follow-up
Module 3: the audit programme, clause 9.2.2 5.1 to 5.7, Managing an audit programme, including 5.3 Determining and evaluating audit programme risks and opportunities, 5.5.2 Defining the objectives, scope and criteria for an individual audit, and 5.5.4 Selecting audit team members
Module 4: planning and conducting the audit 6.2 Initiating the audit; 6.3 Preparing auditing activities; 6.4.3 Conducting the opening meeting; 6.4.7 Collecting and verifying information; A.6 Sampling; A.17 Conducting interviews; 6.4.10 Conducting the closing meeting; 3.4, 3.6 Note 1, 5.5.3, A.1 (Table A.1) and A.16 Using remote auditing methods (lesson 4.6)
Module 5: findings, reporting and follow-up 6.4.8 Generating the audit findings; A.18 Audit findings; 6.4.9 Determining the audit conclusions; 6.5 Preparing and distributing the audit report; 6.7 Conducting the audit follow-up; 5.6 Monitoring the audit programme; 5.7 Reviewing and improving the audit programme; 7.3 to 7.6, auditor evaluation
Module 6: course assessment Part C, the Audit Workbench: 5.5.2 and 6.3.2 audit planning, 6.4.3 and 6.4.10 the opening and closing meetings, 6.4.7 and 6.4.8 for the 14 exhibits, 6.4.9 and 6.5.1 the conclusion and the report, and 6.7 the follow-up of corrective action

Annex A of ISO 19011:2026 is informative. Every clause in this table is guidance: the course quotes it by number and never turns its “should” into a requirement.

What this course is, and what it is not

It is an internal auditor course for ISO 9001:2026. It teaches the requirement the internal auditor serves, clause 9.2, and how to audit against every clause from 4 to 10: what to ask, whom to ask, what evidence to see, and which answers sound right and are not evidence. It teaches the programme under 9.2.2, the audit day from plan to closing meeting, the three part nonconformity, the report and the follow-up of corrective action under 10.2. Every activity runs on one case site with the data supplied.

It is not a lead auditor course, and it is not a certification body auditor qualification. It will not qualify you to audit for a certification body, and it does not claim to. It trains you to audit your own organisation’s quality management system and to run the programme that does it. It does not re-teach implementation: if you need to build the system, that is the Implementation course. The classification it teaches for findings, nonconformity, observation and opportunity for improvement, is ASC’s recommended practice for an internal programme and the course says so. Major and minor grading is certification body practice, not a requirement of ISO 9001.

Who it is for

  • Internal auditors who audit against ISO 9001, and people who are about to become one.
  • QMS coordinators and QA managers who own and run the internal audit programme.
  • Supervisors and process owners who will be audited, and who want to know what the auditor is looking for and why.
  • Consultants who audit on a client’s behalf, which clause 3.18 Note 2 allows, or who train a client’s audit team.
  • Food safety internal auditors on sites adding ISO 9001 to a GFSI benchmarked scheme, who know how to audit and need the quality clauses.

What you need before you start

The Introduction to ISO 9001:2026, or equivalent familiarity with ISO 9001: you should know what each clause is about before you learn to audit it. The Implementation course is recommended but not required. The auditor course does not re-teach how to build the system; it teaches how to test it.

Who it is not for

  • Someone who needs to know what the system is and what their part in it is. Do the Introduction instead, at R1495.
  • Someone who has to build the system from nothing. Do the Implementation course, at R4800, and come back to this one when there is a system to audit.
  • Anyone who wants to audit for a certification body. This is not that qualification.
  • Anyone wanting a certificate without doing the assignment. The assignment is marked, and the pass mark is 70.

What you will be able to do afterwards

  • Explain what 9.2.1 asks an internal audit to establish, and tell an audit apart from an inspection, a GMP walk and a management review.
  • Apply the seven principles of auditing in ISO 19011:2026 to decisions on a real audit, including the objectivity and impartiality that 9.2.2 b) requires.
  • Sort what you see and hear into objective evidence, opinion and hearsay, and use audit criteria, evidence, findings and conclusion correctly.
  • Distinguish conformity, nonconformity, correction and corrective action using 3.15 to 3.17, and name the requirement behind a finding.
  • For every clause from 4 to 10, state the requirement in short, the question to ask and whom to ask it of, and the evidence to see before you record conformity.
  • Interview top management against 5.1.1 a) to l), 5.1.2, 5.2 and 5.3 without reading the clause aloud, and test the answers on the floor.
  • Audit risks and opportunities as two separate trails, run a calibration trail and a floor awareness interview under 7.3 a) to e), and trace forward and backward through clause 8.
  • Build an audit programme whose frequencies follow from the importance of the processes, the results of previous audits and changes, as 9.2.2 requires.
  • Write the objectives, criteria and scope for a process audit, a clause audit, a follow-up audit and a second party supplier audit.
  • Select an auditor for each audit, test the choice for objectivity and impartiality, and record the decision and any declared conflict on an auditor register.
  • Write an audit plan and a checklist that follows the process rather than the clause order, and run an opening meeting in five items.
  • Ask questions that produce objective evidence, including on the floor in the site’s languages with a colleague as interpreter, and keep notes that record who, what, where, when and the record reference.
  • Select a sample and record what was sampled so that a finding survives challenge.
  • Handle hostility, pressure to soften a finding, a safety hazard and a food safety matter outside scope without losing objectivity.
  • Write a nonconformity in three parts, requirement, evidence and statement, that a stranger could use to find the record and see the gap, and repair the ten most common bad findings.
  • Write an audit report with a summary and a conclusion against the audit objectives, and carry audit results into management review under 9.3.2 d) 3).
  • Review a corrective action response against 10.2.1 a) to f), reject a root cause of “retrain”, and verify implementation and effectiveness before closing.
  • Evaluate the audit programme and its auditors, and explain what a certification body does with internal audit records at stage 1 and stage 2.

What is inside

Six modules, 26 lessons and 2 practice exercises, 380 minutes of lesson time, five knowledge checks, five games, and a three part assessment in Module 6. About thirteen hours in total.

Module 1: The internal auditor, the requirement and the principles (58 minutes)

Lesson Minutes
1.1 Why 9.2 exists, and what an internal audit is and is not 12
1.2 The seven principles of auditing and what each one costs you 16
1.3 Audit vocabulary: criteria, evidence, findings, conclusions, and the words the standard uses 14
1.4 Auditor competence, behaviour and the 7.2 record 16
Knowledge check and game included

Module 2: Auditing the requirements, clauses 4 to 10 (84 minutes)

Lesson Minutes
2.1 Auditing context, interested parties, scope and processes (clause 4) 14
2.2 Auditing leadership: the top management interview, the policy on the floor, roles (clause 5) 14
2.3 Auditing planning: risks and opportunities as two trails, objectives, planning of changes (clause 6) 14
2.4 Auditing support: resources, calibration, knowledge, competence, awareness, communication and documents (clause 7) 14
2.5 Auditing operation: the order to delivery trail, design, suppliers, production, traceability, customer property and nonconforming outputs (clause 8) 16
2.6 Auditing performance evaluation and improvement: KPIs, customer satisfaction, the audit programme, management review, corrective action (clauses 9 and 10) 12
Knowledge check and game included

Module 3: The audit programme, clause 9.2.2 (58 minutes)

Lesson Minutes
3.1 What 9.2.2 requires of the programme, and the risk-based frequency 14
3.2 Audit objectives, criteria and scope for each audit (9.2.2 a) 14
3.3 Selecting auditors, objectivity and impartiality (9.2.2 b) 14
3.4 Reporting results, management review, and correction without undue delay (9.2.2 c) and d) 16
Knowledge check and game included

Module 4: Planning and conducting the audit (108 minutes)

Lesson Minutes
4.1 The audit plan and the document review 16
4.2 The opening meeting and managing the day 12
4.3 Interviewing: questions that get evidence 18
4.4 Sampling and audit trails 16
4.5 Difficult situations and the auditor’s conduct 14
4.6 Remote and hybrid audits, virtual locations and digital tools. New in this course for the ISO 19011:2026 emphasis on remote auditing methods (A.16) 14
4.7 The closing meeting: presenting findings so they are accepted 18
Practice exercise: planning and opening an internal audit (unmarked, interactive) 20
Knowledge check and game included

Module 5: Findings, reporting and follow-up (72 minutes)

Lesson Minutes
5.1 Writing a nonconformity: requirement, evidence, statement 16
5.2 Classification: nonconformity, observation, opportunity for improvement, and positive practice 14
5.3 The audit report and the audit conclusion 14
5.4 Corrective action follow-up and closure verification (10.2) 14
5.5 Evaluating the audit programme and the auditors, and preparing for the certification body 14
Practice exercise: findings and what follows (unmarked, interactive) 25
Knowledge check and game included

Module 6: Course assessment (about 7 hours)

Item What you do Time
Course assessment: instructions How the three parts work, and the Audit Workbench 10 minutes
Part A: Auditing Knowledge Check 20 questions drawn from a bank of 75 across Modules 1 to 5, 45 seconds each 15 minutes
Part B: Case Study Classification 15 questions on five short cases: classify the finding, name the clause, choose the justification and the corrective action 23 minutes
Part C: Mzansi Fresh Meals internal audit In the Audit Workbench: observations, the 2027 programme, two audit plans, two opening meetings, the 14 exhibit evidence pack, two closing meetings, the report and two corrective action decisions. 100 marks About 6 hours
Course feedback A short form. Not marked 5 minutes

The tools you walk away with

Every activity runs on a real tool, inside the lesson, on a phone or a laptop.

Tool Clauses What it does
Internal Audit Programme Builder 9.2.2 The same tool the Implementation course uses. Every process scored for importance, previous results and changes, the frequency that follows, method, auditor with an objectivity check, a twelve month schedule, report recipients and the corrective action route. Yours to use on your own site afterwards
Two practice exercises 9.2.2, 10.2 At the end of Modules 4 and 5, on two other case sites: build a programme, sequence a plan and run an opening meeting; then classify findings, build a three part nonconformity, sort correction from corrective action and work five whys. Instant feedback, unmarked, as many tries as you like
Audit Workbench 9.2, clauses 7 to 10 Part C of the assessment. The whole audit in eight steps, saved on your device as you go: observations, programme, plans, meetings, the 14 exhibit evidence pack, report and corrective action review. Submit it and it is marked on the ASC server within a minute, and your audit document is emailed to you as a spreadsheet

The case site and the evidence pack

26 case packs run through the course, each with tasks, the data you need and a model answer to compare your work against. They are built on one site, so the facts you learn in Module 1 are the facts you audit in the assessment.

  • Mzansi Fresh Meals (Pty) Ltd, Kempton Park, Gauteng. Chilled ready meals, 38 products, about 1.2 million meals a month, 400 people on two shifts. Certified to a GFSI benchmarked food safety scheme, not certified to ISO 9001, stage 2 targeted for September 2027. Complaints up from 12 to 18 a month, median complaint close-out 21 days against an objective of 10, 41 corrective actions open. You join the audit team for the site’s first full programme: 19 audits a year across ten processes, each frequency justified by importance, previous results and changes.

Part C of the assessment gives you two audits from that programme, Procurement and Customer complaints and feedback. You plan them, then conduct them on the evidence pack in the Audit Workbench: 14 exhibits of the kind an auditor sees on the day, from a supplier register and a purchase order to an interview note and a set of management review minutes. Some exhibits show a nonconformity. Some look wrong and conform. The marker gives marks for each nonconformity you find against the right clause, and none for a finding raised on an exhibit that conforms, because a false finding costs an auditor credibility on the floor.

The case is a training scenario built from real audit patterns. No real company is named.

How it is assessed

Everything is marked online, day or night, and nothing needs a person to mark it. There is nothing to upload.

  • Five knowledge checks, one per teaching module: 15 questions drawn from a bank of 24, covering every lesson in that module.
  • Five games, one per teaching module: a scenario stem and a single decision, 10 questions drawn from a bank of 14. The titles are Evidence or not?, Which clause is the finding against?, Who can audit it?, Good question or bad question? and Fix the finding.
  • Part A, Auditing Knowledge Check: 20 questions drawn from a bank of 75 across Modules 1 to 5, 45 seconds a question, 15 minutes.
  • Part B, Case Study Classification: 15 questions drawn from a bank of 21 on five short cases, 90 seconds a question. Classify the finding, name the clause, choose the justification and the right corrective action.
  • Part C, the Mzansi Fresh Meals internal audit: completed in the Audit Workbench and submitted from it, out of 100. Your mark and feedback appear on screen within a minute and arrive by email with your audit document attached, and the mark goes onto your course record by itself.
  • Pass mark 70 percent in each part. Three attempts on every assessment. If an attempt falls short, the feedback says what to change and which lesson to go back to.

How Part C is marked

The marking scheme is published in the workbench before you start. Every section is checked against the case and the answer key held on the ASC server: whether your frequencies follow the site’s own rule, whether your auditors are objective, whether your plans, meetings and report describe the same audits against the same criteria, which of the 14 exhibits you raise a nonconformity on and against which clause, the record numbers and dates in your evidence, and your decisions on the two corrective action responses.

Section Marks
Observations on the case 8
Audit programme 8
Audit plans 8
Opening meetings 4
Evidence pack: findings, evidence and statements 40
Closing meetings 4
Report and corrective action review 18
Consistency across the documents 10

Three conditions apply to every pass, whatever the other sections score: at least 8 of the 10 nonconformities found, the corrective action response that blames operator error rejected, and no process owner auditing her or his own process in your programme.

Your own work only. A submission with no detail from the case, or that reads as machine written, is returned unmarked and still uses an attempt; a second one ends the enrolment without a certificate.

The QR verified certificate carrying the document code FS55 is released when you have passed every knowledge check at 70 percent, completed every game, passed Parts A, B and C at 70 percent each, and submitted a short course review. Anyone can then scan the code and confirm the certificate.

Where this course sits

ASC’s ISO 9001:2026 material runs at three depths. The Introduction explains what a clause asks for. The Implementation course shows how to build it and what record proves it. This course shows how to test it: what to ask, what to see, and how to write what you find so that it gets fixed.

Questions people ask before they enrol

Is this a lead auditor course?

No. It is an internal auditor course. It trains you to audit your own organisation’s system and to run its programme under 9.2.2. It is not a lead auditor course and it is not a certification body auditor qualification, and the certificate says what it is.

Do I need the Implementation course first?

No. You need the Introduction or equivalent familiarity with ISO 9001, because you cannot audit a clause you have never read. The Implementation course is recommended, because an auditor who has built a register finds the gaps in one faster, but it is not required.

What is ISO 19011:2026, and do we have to follow it?

ISO 19011:2026, Guidelines for auditing management systems, fourth edition, May 2026, is the guidance the Note to 9.2.2 points to: “See ISO 19011 for guidance on auditing management systems.” Its clause 1 says it “gives guidance on auditing management systems, including the principles of auditing, managing an audit programme and conducting management system audits, as well as guidance on the evaluation of competence of individuals involved in the audit process.” Its introduction says it “concentrates on internal audits (first party)” and second party audits. It is guidance, not requirements: it says “should”, and an internal audit programme that departs from it is not a nonconformity against ISO 9001:2026. The course is built on it clause by clause, and it tells you each time whether you are looking at a requirement of ISO 9001:2026 or at guidance from ISO 19011:2026.

What changed in ISO 19011:2026, and does the course cover remote audits?

ISO 19011:2026, the fourth edition, was published in May 2026 and cancels and replaces ISO 19011:2018. Its foreword names two main changes: “expansion of guidance on remote auditing methods through the introduction of guidance contained in ISO/IEC TS 17012” and “expansion of Annex A to provide guidance on remote auditing methods and virtual locations”. The seven principles and the three areas, the audit programme, conducting an audit and auditor competence, are still there. The course covers remote and hybrid audits in lesson 4.6, new in this course for the 2026 edition’s emphasis: when to audit remotely and when to go on site, how to audit a virtual location such as a shared drive, the ERP or a complaints app, what a screen share and a live video walk can and cannot evidence, and how to control staged evidence, drawing on A.16, Using remote auditing methods. You apply it to a remote audit plan for the case site’s complaints process. That method is ASC’s practice, not a requirement.

After this course, can I audit my own department?

No, and no course can change that. Clause 9.2.2 b) requires auditors to be selected to ensure objectivity and the impartiality of the audit process, and 3.18 Note 5 says: “Independence can be demonstrated by the freedom from responsibility for the activity being audited.” Module 3 teaches the function rule, the auditor register and the conflict declaration that make this workable on a small site.

Do I need a site of my own?

No. The programme, the process data and the evidence pack are all supplied. If you have a site and permission to use its data, the tools work on it afterwards.

We already run internal audits for a food safety scheme. Is this worth it?

Yes, if ISO 9001 is coming. You already know how to audit. What changes is the criteria: contract review, design and development, supplier evaluation, customer satisfaction, management review inputs and corrective action against quality nonconformities. Clause 3.18 Note 1 recognises a combined audit, covering two or more disciplines, so one programme can serve both systems if it is planned that way.

When do we have to move off ISO 9001:2015?

ISO 9001:2026 was published on 16 September 2026. The IAF transition period is three years from publication, so ISO 9001:2015 certificates are expected to remain valid until 30 September 2029, after which they lapse. Certification bodies will stop conducting initial certifications to the 2015 edition some time before that. Confirm the exact cut-off dates with your own certification body, because the certification bodies publish their own timetables inside the IAF window.

What does the certificate say?

ISO 9001:2026 Internal Auditor, document code FS55, your name and the date, with a QR code that verifies it. It is a certificate from ASC Food Safety Consultants attesting to your training. Your programme owner can file it as evidence of training under 7.2; evidence that you can audit comes from witnessed audits and report reviews, which Module 5 covers. It is not a lead auditor qualification and it is not a certification of your organisation.

How long do I have, and what does it need?

Lifetime access, self paced, on any phone or laptop, although the Audit Workbench is easier on a laptop. Your workbench saves on the device you use, so finish Part C on one device. Prices are in rand and there is a currency converter on this page.

Can we enrol an audit team?

Yes. For teams of five or more, contact ASC for a group arrangement. A common pattern is the programme owner on this course and the Implementation course, the auditors on this course, and the process owners they will audit on the Introduction.

About the trainer

ASC Food Safety Consultants write and review every course in this catalogue. The practitioners who wrote this one implement and audit management systems on South African sites: food manufacturing, packhouses, catering and retail supply. Every clause reference and every quotation was checked against the published text of ISO 9001:2026 and of ISO 19011:2026, and the course was reviewed by a panel of ASC practitioners before it was published. No individual is named, because the course is ASC’s work and ASC stands behind it.

ISO 9001:2026 and ISO 19011:2026 are standards published by ISO. This course is an independent training product. It is not affiliated with, approved or endorsed by ISO or by any certification body.

Enrol

ISO 9001:2026 Internal Auditor, FS55, R3850 on a limited period special (normally R4670). About thirteen hours. Intermediate. Six modules, 26 lessons, two practice exercises, 26 case packs, a simulated audit of 14 exhibits in the Audit Workbench, and a three part assessment marked online with nothing to upload. Self paced, lifetime access, three attempts on every assessment, and a QR verified certificate once every assessment and the review are complete.

Enrol now, or read the free material first at ISO 9001:2026 training, including How to run an ISO 9001:2026 internal audit programme that a certification body respects.

What Will You Learn?

  • Audit ISO 9001:2026 clause by clause, from 4 to 10: the question, whom to ask and the evidence to see
  • Build a risk-based internal audit programme under 9.2.2, with objective and impartial auditors
  • Plan an audit: objectives, criteria, scope, sampling and a timetable
  • Run the opening meeting, interview for evidence and hold a closing meeting that is accepted
  • Write nonconformities in three parts: requirement, evidence and statement
  • Report the audit and verify corrective action to effectiveness under 10.2
  • Apply ISO 19011:2026 as guidance, including remote and hybrid audits

Course Content

Module 1: The internal auditor, the requirement and the principles

  • Lesson 1.1: Why 9.2 exists, and what an internal audit is and is not
  • Lesson 1.2: The seven principles of auditing and what each one costs you
  • Lesson 1.3: Audit vocabulary: criteria, evidence, findings, conclusions, and the words the standard uses
  • Lesson 1.4: Auditor competence, behaviour and the 7.2 record
  • Module 1 knowledge check
  • Evidence or not?
  • Activities: the principles, the evidence and the auditor

Module 2: Auditing the requirements, clause by clause

Module 3: The audit programme (9.2.2)

Module 4: Planning and conducting the audit

Module 5: Findings, reporting and follow-up

Module 6: Course assessment and feedback

Student Ratings & Reviews

No Review Yet
No Review Yet

Want to receive push notifications for all major on-site activities?

✕