Skip to main content

ISO 9001 internal audit · Australia

Independent. Clause 9.2 conformant. Ready for ISO 9001:2026.

An ISO 19011-aligned audit of your quality management system, evidenced from operational records—not a checklist somebody ticked.

Melbourne-based and delivered across Australia. We test exportable quality records at population level where practical and trace process controls end to end.

Delivered across Australia — all states and territories — with remote delivery and onsite attendance by arrangement. New Zealand and wider Asia Pacific engagements may be available by arrangement.

Quality auditor reviewing process evidence while a manufactured component is measured

/ 2026 transition

Your next internal audit should already account for it.

ISO/TC 176 has scheduled the sixth edition for 16 September 2026. Formal transition arrangements will be confirmed through the accreditation and certification system; projected deadlines remain provisional.

Scheduled publication16 September 2026
TransitionAwait formal confirmation
Current certificateDoes not expire on publication day

The revision is expected to retain the familiar management-system architecture. For a functioning QMS, transition should be managed as an evidence-led update rather than an overnight rebuild.

Before publication, we separate confirmed requirements from draft-stage expectations. After publication, the transition review can test the final changed requirements directly.

/ Why it matters

Clause 9.2 should test the system—not decorate it.

Weak audit programmes tend to expose the same faults: unclear criteria, checklist-only fieldwork, poor evidence references, self-review threats and corrective actions never tested for effectiveness.

Impartiality

The person who designed or operates a process should not audit their own work.

Process evidence

Follow real work and records end to end instead of accepting verbal assurance.

Management action

Give findings owners, dates, cause evaluation and effectiveness checks.

/ Evidence-led testing

Whole populations where the data supports it.

Where quality records are exportable, we can test the population rather than a handful of selected files: overdue nonconformities, recurring suppliers, lapsed evaluations, calibration dates, complaints and objectives.

Leadership, awareness, knowledge and risk-based thinking remain evidence-and-interview tests. A finding must rest on evidence that existed independently of the audit.

Quality specialists analysing operational records while verifying a precision component
Records → exceptions → evidence → finding

/ Audit coverage

What an ISO 9001 internal audit covers

Clause 4: Context of the organisation

We test whether context, interested parties, scope and process interactions reflect the organisation operating today—including the climate-change consideration introduced by Amendment 1:2024.

Clause 5: Leadership

We test leadership commitment, customer focus, the quality policy, resourcing and whether named people understand their responsibilities and authorities.

Clause 6: Planning, risks and opportunities

We test whether risks, opportunities, measurable quality objectives and organisational changes are planned, owned and evaluated for effectiveness.

Clause 7: Support, competence and documented information

We test resources, infrastructure, calibration, knowledge, competence, awareness, communication and document control against operating evidence.

Clause 8: Operation

We trace work end to end through requirements, design where applicable, suppliers, production or service delivery, release, changes and nonconforming outputs.

Clause 9: Performance evaluation

We test monitoring, customer satisfaction, analysis, the internal-audit programme itself and every required management-review input and output.

Clause 10: Improvement

We test correction, cause evaluation, corrective action, effectiveness review and continual improvement as an operating process—not merely a register.

Qualified delivery matched to your scope

Our team combines implementation, audit, security-governance and technical expertise. Across their professional careers, team members have delivered 2,000+ hours of ISO, ISM and GRC audit work across 70+ organisations.

Team qualifications and credentials

Qualifications, professional credentials and formal training held across Aegentra’s delivery team.

Management systems and audit

  • ISO/IEC 27001 Lead Implementer
  • PECB ISO/IEC 27001 Lead Auditor
  • ISO/IEC 42001 Lead Auditor
  • CISA — Certified Information Systems Auditor
  • ISM Auditor

Cybersecurity and cloud

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • Certificate of Cloud Security Knowledge (CCSK)
  • OSCP+ — OffSec Certified Professional Plus

Service delivery and specialist training

  • ITIL Expert
  • PRINCE2
  • Mastering Generative AI for Cybersecurity Certificate
  • Essential Eight Assessment Course certificate — TAFEcyber

Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.

Personnel security clearance

NV1 Security Clearance

NV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.

Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.

View our delivery-team capability

/ Method

How the audit runs

The work moves from an agreed scope to evidence, interviews and findings, then closes with action owners and verification.

  1. Scope, criteria and audit programme

    We agree sites, processes, clauses, objectives, exclusions, schedule, people and records in writing before fieldwork.

  2. Records and data extraction

    We request read-only exports from ERP, project, CRM, complaints, nonconformance, calibration and supplier systems.

  3. Process tracing and interviews

    We follow work from enquiry through delivery and compare the documented process with the process people actually operate.

  4. Findings and closing meeting

    Every finding is classified, cited to a clause and tied to objective evidence before the report is issued.

  5. Report, corrective actions and follow-up

    You receive the report, findings register and clause 10.2 corrective-action structure, with optional follow-up verification.

Scope evidence testing findings follow-up

/ Competence boundary

Sectors—and where we bring in a specialist.

We are strongest in professional and technical services, software, technology, wholesale, distribution, workforce services, education, healthcare administration and integrated ISO 9001–ISO 27001 systems.

Clause 8 is where sector knowledge matters. Heavy manufacturing, food processing, aerospace, automotive and technically complex production require competence in the process—not only the clause.

Where specialist competence is required, we scope a sector-qualified lead auditor rather than overstate capability.

/ Independence

We do not audit what we built.

Clause 9.2.2 requires objectivity and impartiality. Where Aegentra implemented or materially designed a QMS, we do not present the same work as an independent internal audit. We scope an independent auditor or tell you plainly to take the audit elsewhere.

Implementation, internal audit and accredited certification remain distinct responsibilities.

/ Outputs

What you receive

  • Audit plan with agreed scope, criteria, objectives and schedule
  • ISO 19011-aligned internal-audit report written for your organisation
  • Findings register cited to clauses and objective evidence
  • Evidence index with timestamped extracts and population references
  • Clause 10.2 corrective-action plan with owners and effectiveness review
  • ISO 9001:2026 transition-readiness assessment against confirmed changes
  • Audit results formatted for management review under clause 9.3
  • Multi-year audit-programme schedule where required
  • Closing meeting and findings walkthrough
  • Optional verification of closed corrective actions

/ Commercials

Scope, timeline and fee

Engagements are fixed-fee and quoted after a short scoping call. Effort depends on sites, process complexity, applicable design requirements, record accessibility and audit-programme maturity.

FeeFixed after scope
TimelineConfirmed in writing
AccessRead-only evidence

/ Comparison

How this compares to the alternatives

OptionWhat you getWhere it falls short
Your quality managerDeep QMS familiarity and no external feeObjectivity can fail where they built or operate the process.
Your implementation consultantConvenient and already familiarCreates a self-review threat when they audit their own work.
Checklist and available staff memberA low-cost audit recordA ticked template does not demonstrate process auditing or competence.
Large firmRecognised name and enterprise capacityMay be priced and staffed for a larger engagement than your scope needs.
AegentraIndependent evidence-led testing, fixed scope and transition reviewWe do not audit a QMS we built; specialist operations may need a sector-qualified auditor.

/ Practitioner evidence

Credentials and recent engagements

Delivery is principal-led and informed by governance and audit work across Australian government and regulated environments. Aegentra is a PECB Authorised Training Partner; audit work remains separately scoped.

/ Questions answered

ISO 9001 internal audit questions

Is an internal audit mandatory for ISO 9001?

Yes. Clause 9.2 requires internal audits at planned intervals to determine whether the QMS conforms to the organisation’s requirements and ISO 9001, and whether it is effectively implemented and maintained.

When is ISO 9001:2026 published, and when do we have to transition?

ISO/TC 176 has scheduled the sixth edition for publication on 16 September 2026. A transition period will apply, but the formal arrangements and deadline must be confirmed by the relevant accreditation and certification bodies.

What is actually changing in ISO 9001:2026?

The revision retains the familiar management-system structure while updating emphasis and guidance. Final transition planning should be based on the published edition and confirmed certification-body arrangements.

Do we need to rush to transition?

No. Use the planning window to identify changes, test them through the internal-audit programme and build evidence before the formal transition audit.

Does the climate-change amendment apply already?

Yes. ISO 9001:2015/Amd 1:2024 is published. Organisations must determine whether climate change is relevant under clause 4.1; clause 4.2 notes that interested parties can have climate-related requirements.

Can we do our own ISO 9001 internal audit?

Yes, provided auditors are selected to preserve objectivity and impartiality and do not audit their own work.

How often do we need an ISO 9001 internal audit?

At planned intervals. Frequency should reflect process importance, organisational changes and previous audit results.

What is the difference between an internal audit and a certification audit?

An internal audit is performed by or for the organisation. A certification audit is performed by an accredited certification body, and only that body can issue the certificate. Aegentra does not issue certification.

Can you audit ISO 9001 and ISO 27001 together?

Yes, where independence and scope permit. Shared governance processes can be tested together while discipline-specific requirements remain separate.

What records do you need from us?

Read-only exports and documented information relevant to scope—commonly job records, complaints, nonconformities, calibration, suppliers, competence, management review and previous audits.

How long does an ISO 9001 internal audit take?

The timeline is confirmed after scoping and depends on sites, processes, applicable design requirements, record quality and process-owner availability.

Do you audit manufacturers?

It depends on the process. Technically complex or sector-specific production may require a suitably qualified sector auditor.

Do you work outside Melbourne?

Yes. Aegentra delivers remotely across Australia, with onsite attendance by arrangement. New Zealand engagements may be available by arrangement.

/ Scope the audit

Find the problems before your assessor does.

A twenty-minute call is enough to establish scope, evidence needs and whether a single audit or multi-year programme fits. You receive a fixed fee in writing—or an honest recommendation to use a different specialist.

Book an ISO 9001 audit scoping call