Procedure · SOP-03
Internal Audit
Planning, conducting, reporting and following up internal audits of the management system and technical activities.
Purpose
To define how the Laboratory plans, performs, reports and follows up internal audits so that top management obtains objective evidence of whether the management system conforms to ISO/IEC 17025:2017 and to the Laboratory's own requirements, and whether it is effectively implemented and maintained.
What is inside
11 sections, about 4 pages when printed.
- 1. Purpose
- 2. Scope
- 3. References
- 4. Definitions
- 5. Responsibilities
- 6. Process overview
- 7. Procedure
- Records generated by this procedure
- Monitoring and performance indicators
- Assessment readiness notes
- Related documents
Records it generates
Applying this procedure produces the following records, which are the evidence an assessor samples.
- –Annual audit programme and individual audit plans
- –Completed audit checklists with sampled evidence
- –Finding and nonconformity reports with closure evidence
- –Audit summary reports and management review extracts
- –Auditor training and authorisation
What an assessor looks for
The document closes with these points, so you can check your own practice before someone else does.
- –Whether the programme demonstrably covers every clause, every discipline and every location in 12 months, and whether it was completed.
- –Whether auditors are trained, authorised and independent of the work audited.
- –Whether audits produced findings: an audit programme with no findings over a year is treated as an indicator of ineffective auditing.
- –Whether findings were classified, root-caused, actioned and verified for effectiveness, not merely corrected.
- –Whether vertical and witness audits were performed, with the specific jobs and people recorded.
Before you use it
- Replace every square-bracket token, starting with [LABORATORY NAME], [ADDRESS] and [EFFECTIVE DATE]. The full token list is in GD-01 Read Me First.
- Have the content technically reviewed against how your laboratory actually works, then approved by the responsible manager before it becomes a controlled document.
- Update the Word fields after editing so the table of contents and page numbers are correct: select all, then press F9.
- Record the document in your own document register and set its review date.
- Delete the assessment readiness notes if you do not want them in your controlled version; they are guidance for you, not requirements.
Related documents
- QM-01
Quality Manual
Top-level description of the management system against every clause of ISO/IEC 17025:2017.
- FRM-04
Internal Audit Programme and Audit Plan
Annual audit programme covering every clause and activity, plus the plan for a single audit.
- FRM-05
Internal Audit Checklist
Clause-by-clause question set with evidence and finding columns for auditing against ISO/IEC 17025.
- FRM-06
Audit Finding and Nonconformity Report
Records an audit finding with classification, objective evidence and required response.
- CHK-01
ISO/IEC 17025:2017 Gap Analysis and Self-Assessment
Clause-by-clause self-assessment with evidence, gap and action columns.
- SOP-01
Control of Documents
Creation, review, approval, issue, change and withdrawal of internal and external documents.
- SOP-02
Control of Records and Technical Records
Identification, storage, protection, retention, amendment and disposal of quality and technical records.
- SOP-04
Management Review
Annual top-management review with every input and output the standard requires.