Internal audits and gap analyses
An internal audit should find out whether your management system delivers what it is supposed to. In practice it often turns into a box-ticking exercise: the checklist gets worked through, three minor nonconformities are recorded, and the report goes into the file.
That meets the standard, but it gets you nothing. An audit is the one occasion in the year when someone asks systematically whether your processes still fit your business. That opportunity is worth using.
We know the certification audit from both sides of the table
Before we concentrated on consultancy, our lead auditors audited on behalf of certification bodies. They led audit teams of one to ten people and certified companies with 3 to 9,000 employees.
That is the difference from external consultants who know the certification audit only from the perspective of the company being certified. We know what an auditor looks for, which evidence they want to see, and at what point well-meant documentation turns into a nonconformity. We bring that view into your internal audit, a year before it matters.
What we audit
Internal audits (1st party)
The annual obligation under almost every management system standard. We check conformity with the agreed audit criteria and back every finding with objective evidence, traceable even for those who were not there during the audit.
Supplier audits (2nd party)
Initial qualification, surveillance, requalification, or a one-off spot check. We audit against the criteria you set – ISO standards or your own requirements. The result is a defensible statement on suitability, not a gut feeling.
Gap analyses
A comparison of your processes as they are against a standard you do not yet meet. Based on a detailed checklist, with a report you can carry straight over into an action plan. The usual starting point before an initial certification.
Process audits
This is not about conformity with a standard but about performance: does a process achieve the planned results with the inputs and resources available? It uncovers systematic weak points, susceptibility to disruption and organisational friction.
Test method audits (for testing and calibration laboratories)
Is a test method carried out the way the procedure requires? We look at three areas:
Equipment – specifications, management, calibration.
People – training in the method and authorisation to release results.
Data – raw data, traceability, integrity, backup.
Plus method validation and the validation of self-written software, macros and evaluations.
Who this is for
- You have to demonstrate internal audits every year, but have nobody in-house with the professional qualification and independence needed for it
- Your internal audits do take place, but have not added any value for years
- You are facing an initial certification and want to know how far along you really are before you spend money on actions
- A customer requires a supplier audit, and you need someone independent to carry it out
- You run a laboratory and want your test methods checked before the assessment body does it
What you get
- An audit report with a prioritised action plan that you can put on the table in the certification audit – not a form, but something to work from
- Every finding backed by objective evidence: what was seen, where, and what the assessment follows from
- A ranking by urgency instead of a flat list of defects
- For gap analyses, an assessment of readiness for certification as well: what is missing before initial certification, and in what order
- Pointers to potential that goes beyond the requirements of the standard – that is the real value of an outside view
How we work
Setting the audit criteria
What is being audited against? The standard, legal requirements, compliance obligations, customer requirements – and to what extent. Without clear criteria an audit is a matter of taste.
Setting the audit objective
An audit objective can go beyond the audit criteria that have been set and put the focus on something specific that matters to you. It also lets you check afterwards how effective the audit actually was.
Preparation and audit plan
We review the documentation in advance and plan who is needed when and for which area. That keeps the load on your business manageable and predictable.
Audit on site
Conversations, observation, inspection of documented information as objective evidence of your processes. We audit independently of internal structures and strictly against the criteria and objectives, not against what somebody happens to think is important.
Report and actions
Findings with objective evidence, assessment and prioritisation, set out clearly in one report. Integrated, where several compliance obligations have been audited. The report is built so that you can work from it directly.
Follow-up
An audit without a check on the effectiveness of the actions is half an audit. On request we come back the following year and look specifically at what became of the findings.
Independence – including from us
A standard requires that nobody audits their own work. So if we helped build your management system, a different person from our team carries out the internal audit.
Our set-up is designed for that: for eight of the thirteen standards at least two people are qualified. See the competence matrix. Tell us in the first conversation who did what at your company, and we will plan accordingly.
Who handles this at our end
Marion Rammé – IRCA certified and registered QMS / EMS / OHSMS Lead Auditor #01194927
Rüdiger Rammé – IRCA certified and registered QMS / OHSMS Lead Auditor #01192806
For test method audits in the laboratory environment, Michael Bremer joins us – specialist for laboratory accreditation and measurement uncertainty, honorary member of the DKD technical committees.
How this looked in practice
Starting point: An owner-managed manufacturer of technical speciality chemicals, one production site, fewer than twenty employees, certified to ISO 9001 and ISO 14001. Internal audits were taking place, but findings from external inspections did not reliably make it into the action plan. They reappeared unchanged the following year.
Approach: For more than five years, one internal audit per year, on site, working through the business process by process. Each audit section opens with the previous year's open items, so effectiveness is tested across years rather than on a single reporting date. We look at the management review, supplier evaluation, competence matrix, inspection intervals, environmental aspects and binding obligations. Changes in the law we bring to the table ourselves rather than merely asking about them: packaging register, working time records, data processing agreements for cloud services.
Result: An inspection report with 23 recommendations, almost all of them word for word from the previous year, was the trigger to rebuild the action plan. Since then, every recommendation left unimplemented has to be justified; a tick in a box is no longer enough. The most recent external audit report contained two recommendations.
The client's name, the detailed sector and all audit reports remain confidential.
Related topics
- Building a management system – when the findings turn into a rebuild
- ISO/IEC 17025 – laboratory accreditation, the follow-on from test method audits
- VDA 6.3 – process audits in automotive supply
- Software & databases – when findings come down to gaps in record keeping
Frequently asked questions
Do you carry out the certification yourselves?
No, and we are not allowed to either. Certification is carried out solely by an accredited certification body. We prepare you for it, run your internal audits and support you through the procedure, but the certificate is issued by someone else.
What does an internal audit cost?
The drivers are the size of the scope, the number of sites and the number of standards. An audit for one site and one standard is a matter of days, a multi-site audit of an integrated system considerably more. After a short conversation about your scope we can give you a firm figure.
How much of our own time does it take?
Less than most people fear. The audit plan sets out who is needed when and for which area, usually between thirty minutes and two hours per area. The preparation is on us.
How often does an internal audit have to take place?
The common management system standards provide for an annual cycle in which all areas and clauses are covered over a defined period. Not every area has to be covered every year. The audit plan governs that.
We already have someone internal who audits. Why you?
Two reasons. First, distance: anyone who sees the business every day stops asking certain questions. Second, comparison – we see systems across different sectors and sizes, so we spot more quickly what is unusual at your company. And if your internal audit delivers good results, we will tell you that too.
Is a gap analysis the same as an audit?
Close, but the purpose is different. An audit checks an existing system against criteria and objectives it ought to meet. A gap analysis checks the current state against a standard you do not yet meet, with the aim of planning the route there. Before an initial certification, the gap analysis is the right starting point.
Let us talk about it
The first conversation is free and without obligation. It usually takes half an hour. Afterwards you know what to expect.
- Marion Rammé, Hamburg
- Rüdiger Rammé, Lüneburg – phone: +49 4131 2198634
- Email: all@bout-quality.de
Prefer to write? The contact form reaches us just as well.