MSI site analytics pixel

Internal Audit Mistakes: Why Even Seasoned Auditors Slip

ISO 19011:2026 · Auditor Competence

By Diana Lynn, President and Principal ISO Consultant, MSI · Updated September 29, 2026

Direct Answer: Internal audit mistakes occur at every career stage. Novice auditors accept unverified evidence and hide behind checklists. Developing auditors audit clauses instead of processes. Seasoned auditors drift into familiarity bias, stale technical skills and softened reporting. ISO 19011:2026 names a remedy for each, in Clauses 4, 6, 7 and Annex A.

Internal audit mistakes are the points where an audit stops producing reliable conclusions, whether the auditor is on a first audit or a fortieth.

Picture two auditors walking the same production floor on the same morning. One finished internal auditor training last month and is clutching a checklist. The other has twenty years of audits behind her and has not opened a checklist since 2012. By lunch, both have missed the same nonconformity, for completely different reasons. That is the uncomfortable truth this article is about: experience changes which internal audit mistakes an auditor makes, not whether they make them.

The fourth edition of the auditing guidance, ISO 19011:2026 , published on May 27, 2026 and withdrew the 2018 edition with no transition period. Read closely, it is a map of where audits break down, from the evidence rules in Clause 6.4.7 to the leadership competence in Clause 7.2.3.4. This guide walks that map stage by stage, and then applies it to ISO 9001, ISO 14001, ISO 13485 and ISO 7101 audit programs. It is written from 28 years of ISO consulting, 200+ audits attended and 600+ professionals trained, because the pattern is consistent enough to name.

Key Takeaways

  • ISO 19011:2026 is guidance written with “should”; the audit requirements themselves sit in Clause 9.2 of ISO 9001, ISO 14001 and ISO 7101, and in Clause 8.2.4 of ISO 13485.
  • Novice auditors most often accept evidence that cannot be verified, which ISO 19011:2026 Clause 6.4.7 says should not be accepted as audit evidence.
  • Seasoned auditors most often slip through familiarity bias, which conflicts with the independence principle in ISO 19011:2026 Clause 4.6.
  • ISO 19011:2026 Clause 7.4 recommends evaluating every auditor with two or more methods, such as a witnessed audit plus a post-audit report review.
  • Since February 2, 2026, the FDA can inspect ISO 13485 internal audit reports under the Quality Management System Regulation.
  • ISO 9001:2026 Clause 9.2.2 a) now requires audit objectives, criteria and scope to be defined for each audit.

The Definition

What Are Internal Audit Mistakes Under ISO 19011:2026?

Plan. Probe. Prove.

Direct Answer: Under ISO 19011:2026, internal audit mistakes are departures from the seven audit principles in Clause 4: integrity, fair presentation, due professional care, confidentiality, independence, an evidence-based approach and a risk-based approach. Clause 4.1 says these principles let auditors working independently reach similar conclusions in similar circumstances. A mistake is any habit that breaks that reproducibility.

ISO 19011:2026 defines an audit, in Clause 3.1, as a systematic, independent and documented process for obtaining objective evidence and evaluating it objectively. Every one of those adjectives is a place an audit can go wrong. An audit that is not systematic misses processes. One that is not independent drifts toward the auditee’s view. One that is not documented cannot be reconstructed, and one without objective evidence is opinion with a report template around it.

This is the lens MSI uses: internal audit mistakes are not about whether an organization passes a certification visit. They are about whether the audit told leadership the truth about the management system. A clean internal audit report over a system that does not work in practice is the costliest outcome of all, because it hides the problem from the people who could fix it. MSI’s guide to internal audit risk mitigation covers the program-level consequences, and the ISO 19011:2026 changes article covers what the fourth edition revised.

The foreword of ISO 19011:2026 names only two main changes: expanded guidance on remote auditing methods drawn from ISO/IEC TS 17012, and an expanded Annex A covering remote methods and virtual locations. Everything else in this article comes from guidance that carried forward, which is exactly why the same internal audit mistakes keep appearing. The guidance was there. The habits did not follow it, and the internal audit mistakes followed the habits.


Stage One: Novice Auditors

Which Internal Audit Mistakes Do Novice Auditors Make?

Verify. Question. Record.

Direct Answer: The internal audit mistakes novice auditors make cluster around evidence: accepting statements that cannot be verified, reading the checklist aloud instead of observing work, asking leading questions, sampling whatever is handed to them, and writing findings that never state why the criteria were not met. ISO 19011:2026 Clause 6.4.7 and Annex A.5, A.6, A.17 and A.18 address each one.

Novice auditors, roughly their first five audits, are usually diligent. Their internal audit mistakes come from not yet knowing what evidence looks like. MSI’s internal audit skills guide covers how to build the foundation; this section covers where that foundation cracks.

Accepting evidence that cannot be verified

ISO 19011:2026 Clause 6.4.7 is direct: only information that can be subject to some degree of verification should be accepted as audit evidence. The novice hears “we always check that” and writes it down as conformity. The competent auditor asks to see the last three checks, which prevents one of the most common internal audit mistakes before it reaches the report. Annex A.5 gives a four-part test for documented information: complete, correct, consistent and current. A training record that exists but predates the procedure revision fails the “current” test, and a novice rarely thinks to compare dates.

Letting the checklist run the audit

Checklists are useful. ISO 19011:2026 Clause 6.3.4 lists them as audit documented information, then adds that their use should not restrict the extent of auditing activities. Annex A.3 goes further, warning auditors not to concentrate on each clause at the expense of the intended outcome of the management system. The novice who reads the checklist aloud, question by question, gets checklist answers. The process itself goes unobserved, and the internal audit mistakes that matter most never surface.

Asking leading questions

“You calibrate this gauge before each shift, right?” is a question with only one comfortable answer. Annex A.17 of ISO 19011:2026 recommends starting interviews by asking people to describe their work, choosing question types deliberately, and summarizing the results back to the person interviewed. Open questions produce evidence. Leading questions produce agreement, and agreement is one of the quietest internal audit mistakes because the report looks perfectly fine.

Sampling whatever is handed over

When the auditee picks the sample, the auditee picks the finding. Annex A.6.1 sets out six sampling steps, starting with establishing the objectives of sampling and selecting the population. Annex A.6.2 says judgement-based sampling should have some justification. The fix for these internal audit mistakes is simple: the auditor chooses the records, from the full population, and writes down how they were chosen.

Writing a nonconformity without the “why”

Annex A.18.3 recommends that a nonconformity record include the audit criteria, the audit evidence, and a declaration explaining why the criteria are not fulfilled. Novice findings often stop at “procedure not followed.” Without the why, the process owner cannot find the root cause, and MSI’s corrective action procedure guide shows how weak findings produce weak corrective actions that return a cycle later.

Auditing their own work

Small organizations stretch thin, and the novice auditor is often asked to audit the process they run. ISO 19011:2026 Clause 4.6 says auditors should be independent of the activity wherever practicable. ISO 13485:2016 Clause 8.2.4 turns that into a requirement: auditors shall not audit their own work. The ISO 9001 Auditing Practices Group paper on impartiality describes the familiarity and self-review threats behind this rule in useful detail.

ISO Procedure Templates and Guides

Stop Rebuilding Your Audit Procedure From a Blank Page

Most internal audit mistakes are written into the procedure before the first audit starts: no evidence rule, no sampling rule, no independence test. MSI’s ISO Procedure Templates and Guides are finished, editable Microsoft Word procedures for ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 and ISO 7101, with the judgment calls already made and annotated from 200+ audits attended.

Browse the Procedure Templates →


Stage Two: Developing Auditors

Which Internal Audit Mistakes Do Developing Auditors Make?

Trace. Connect. Confirm.

Direct Answer: Developing auditors, roughly five to twenty audits in, make structural internal audit mistakes: auditing clause by clause instead of following a process, missing the interfaces between functions, letting scope creep, skipping the review of findings with the auditee, and offering recommendations that compromise impartiality. ISO 19011:2026 Annex A.2, Clause 6.4.7, Clause 6.4.8 and Clause 6.4.9.2 speak to each.

By this stage the auditor verifies evidence and samples properly. The internal audit mistakes shift from the finding to the audit design, and they are harder to spot because each individual finding still looks sound. MSI’s internal audit planning guide covers the design discipline in depth.

Auditing the standard instead of the process

Annex A.2 of ISO 19011:2026 states that auditing a management system is largely auditing an organization’s processes and their interactions. The developing auditor who audits “Clause 7.5” in document control and “Clause 8.4” in purchasing never follows a purchase order from requisition to receiving inspection. Clause 7.2.3.2 a) 9) names the skill directly: audit a process from start to finish, including its interrelations with other processes and functions.

Missing the interfaces

Clause 6.4.7 asks auditors to collect information on interfaces among functions, activities and processes. Handoffs are where management systems leak: engineering to production, sales to planning, a clinic to a laboratory. A developing auditor who audits each department in isolation reports each department as conforming, while the handoff between them is where the customer complaint started.

Letting scope creep

Scope creep feels like diligence. It is one of the internal audit mistakes that hollows out a program, because the audit that wandered into three extra areas did not finish the one it was assigned. Clause 6.4.4 says a concern outside the audit scope should be noted and reported to the audit team leader for possible communication. Note it, report it, and return to the plan.

Skipping the review of findings with the auditee

Clause 6.4.8 recommends reviewing nonconformities with the auditee to obtain acknowledgement that the evidence is accurate and the nonconformities are understood. Unresolved diverging opinions should be recorded in the audit report. A finding the process owner first reads in the final report is a finding that gets argued rather than fixed, which makes this one of the costliest internal audit mistakes at this stage.

Turning recommendations into consulting

Developing auditors are eager to help, and a solution offered mid-audit feels generous. Clause 6.4.9.2 cautions that recommendations should be made carefully to avoid a negative impact on the impartiality of audits, and Clause 6.4.10 adds that recommendations are not binding. An auditor who designed the fix cannot objectively audit it next cycle. MSI’s guide to internal audit follow-up explains how to keep verification separate from solution design.


Stage Three: Seasoned Auditors

Why Do Seasoned Auditors Still Make Internal Audit Mistakes?

Question. Refresh. Report.

Direct Answer: Seasoned auditors make internal audit mistakes that experience itself creates: familiarity bias that confirms what they expected, technical competence that stopped updating before remote and digital evidence arrived, judgement-based sampling that is never justified, and closing meetings that soften findings. ISO 19011:2026 Clauses 4.3, 4.6, 7.2.2 and 7.6 are the correction.

These are the internal audit mistakes nobody writes about, because the people who make them are the people who train everyone else. They are also the most expensive, since a seasoned auditor’s conclusion is rarely questioned. The qualified auditor shortage makes this worse: organizations lean harder on their most experienced auditors precisely when fresh eyes are scarce.

Familiarity bias and pattern-matching

Pattern recognition is the seasoned auditor’s greatest asset and most dangerous habit. After enough audits, the auditor walks in already knowing where the problems are, and finds exactly those problems. Clause 7.2.2 lists open-mindedness, meaning a willingness to consider alternative ideas or points of view, as a desired professional behaviour. Clause 4.6 asks auditors to remain free from bias throughout the audit process. The same department audited by the same auditor for five years is a familiarity threat, however skilled the auditor, and it produces internal audit mistakes that look like clean results.

Stale technical competence

Clause 7.2.1 b) names methods for auditing, including the application of emerging technology to conduct audits or to audit technology-based processes. Clause 7.2.3.2 a) 10) asks auditors to understand the appropriateness and consequences of using information and communications technology and emerging technology, with artificial-intelligence-based evaluation tools named as an example. A veteran who has never pulled a system log, verified a screenshot’s origin or questioned an electronic signature will make internal audit mistakes in any process that runs on software. MSI’s article on auditing AI agents covers the new evidence types.

Unjustified judgement-based sampling

Experienced auditors sample by instinct, and the instinct is often good. But Annex A.6.2 says judgement-based sampling should have some justification, and notes its drawback: there can be no statistical estimate of uncertainty in the conclusions. The seasoned auditor who cannot explain why those five records were chosen has made a conclusion no one else can reproduce, which breaks the reproducibility standard Clause 4.1 sets.

Softening the closing meeting

After years of relationships with process owners, it gets harder to say the difficult thing plainly. Clause 4.3 defines fair presentation as the obligation to report truthfully and accurately, including significant obstacles and unresolved diverging opinions. Clause 6.4.10 recommends explaining that the evidence was based on a sample and is not necessarily fully representative. A finding downgraded to an “observation” to keep the peace is one of the most common internal audit mistakes MSI sees at the seasoned level.

Auditing leadership only at the top

Annex A.9 recommends interviewing top management to confirm they acknowledge accountability for the management system. It then adds that auditors should also audit leadership and commitment at other levels of management. Seasoned auditors often have one conversation with the executive team and treat that as leadership covered. The supervisor who quietly overrides the procedure on night shift is also leadership.

“I have always felt that integrity is at the center of all ISO standards. The auditor who has seen everything has to work hardest to keep seeing what is actually there.”

— Diana Lynn, President and Principal ISO Consultant, Management Systems International (MSI)


Stages Four and Five: Leading the Audit

Where Do Audit Team Leaders and Program Managers Go Wrong?

Lead. Balance. Evaluate.

Direct Answer: Audit team leaders make internal audit mistakes by assigning work without matching competence, leaving auditors-in-training unsupervised, and skipping the pre-closing team conference. Audit program managers make them by never evaluating auditors, scheduling by calendar rather than risk, and ignoring the program risks listed in ISO 19011:2026 Clause 5.3. Clauses 6.4.9.1, 7.2.3.4 and 7.4 set the standard.

The highest-leverage internal audit mistakes are made above the individual auditor. ISO 19011:2026 Clause 7.2.3.4 describes what an audit team leader should be competent to do: assign tasks by individual competence, manage the uncertainty of achieving audit objectives, direct auditors-in-training, and lead the team to its conclusions. Clause 7.2.5 adds that this competence should come from experience gained under a different audit team leader.

Clause 6.4.9.1 recommends that the team confer before the closing meeting to review findings against the audit objectives and agree conclusions, taking into account the uncertainty inherent in the audit process. When a single auditor runs the whole audit, Clause 5.5.4 says that auditor should perform all the applicable duties of an audit team leader. In a small organization, that means the lone internal auditor still needs a conclusion step before walking into the closing meeting.

At the program level, Clause 5.3 lists where audit programs typically break down, including insufficient time, a lack of competent auditors, insufficient independence, poor method selection and failure to engage leadership. Clause 5.1 says priority should be given to matters with higher inherent risk and lower levels of performance. A program that audits every process once a year for two hours is not risk-based, however neat the schedule looks, and it spreads internal audit mistakes evenly across the system. MSI’s internal audit program guide and the government internal audit article show what maturity looks like at this level.

Most programs never evaluate their auditors at all. Clause 7.4 recommends two or more methods from Table 2 of ISO 19011:2026, which lists review of records, feedback, interview, observation, testing and post-audit review. Clause 7.6 adds that the program manager should establish mechanisms for continual evaluation of auditor performance. An auditor who is never observed never learns which internal audit mistakes they are making.

Leading an audit program is a leadership job, not only an auditing one. Clause 7.2.3.4 b) expects audit team leaders to discuss strategic issues with top management, and Clause 5.3 i) lists failure to engage leadership among the audit program’s own risks. ISO 9001:2026 Clause 5.1.1 now adds promoting quality culture and ethical behaviour to leadership and commitment. Program leaders who cannot speak that language make internal audit mistakes at the top of the program, where findings lose their sponsor.

New Course · Launching October 21, 2026

Lead the Audit Program the Way ISO 9001:2026 Expects Leaders to Lead

The ISO 9001:2026 Leadership Commitment Workshop is built for the people who own the system, including the managers who run internal audit programs. It covers what Clause 5 now asks of leaders, from quality culture and ethical behaviour to accountability for effectiveness, so program leaders can secure sponsorship, present audit trends to top management with authority, and turn findings into leadership decisions.

See the Leadership Workshop →


Remote and Hybrid Methods

How Do Remote Audits Create New Internal Audit Mistakes?

Check. Connect. Confirm.

Remote auditing is the one area ISO 19011:2026 expanded most, drawing on ISO/IEC TS 17012:2024. Clause 3.4 now defines a remote auditing method as one used from any place other than the auditee’s location, and Annex A.16 says remote methods can introduce additional risks and opportunities. Remote work does not create new principles. It creates new internal audit mistakes that break the old ones.

The internal audit mistakes MSI sees most often in remote audits are practical. Auditors accept a document shared on screen without asking where it lives or who last edited it, which fails the Annex A.5 integrity check for information provided through alternate media. They skip the technical check ahead of the audit that Annex A.16 recommends, then lose a third of the interview time to connection problems. They also forget that Annex A.17 g) warns non-verbal cues are harder to read virtually, so question selection matters more.

Annex A.16 lists two competence items for remote auditing: technical skills to use the technology, and the knowledge to conduct the audit effectively at a distance. MSI adds a house standard in its procedures: platform-specific competence, because host controls, recording destinations and file-sharing paths differ between video platforms. The ISO 19011:2026 internal audit procedure article explains how to write that into your procedure.


Standard by Standard

How Do Internal Audit Mistakes Differ Across ISO 9001, 14001, 13485 and 7101?

Know. Apply. Adapt.

Direct Answer: Internal audit mistakes differ by standard because the requirements differ. ISO 9001:2026 and ISO 14001:2026 require per-audit objectives, criteria and scope in Clause 9.2.2 a). ISO 13485:2016 Clause 8.2.4 requires a documented procedure, bars auditors from auditing their own work, and requires reporting of verification results. ISO 7101:2023 applies the same harmonized audit structure to clinical care.

ISO 19011:2026 Clause 7.2.3.3 recommends that audit teams hold collective discipline-specific and sector-specific competence. That is the bridge between generic auditor mistakes and standard-specific ones. An auditor fluent in ISO 9001 who audits a device manufacturer or a hospital without learning the sector will make internal audit mistakes the generic guidance cannot catch.

ISO 9001:2026: objectives for every audit

ISO 9001:2026 was published on September 16, 2026, and Clause 9.2.2 a) now asks organizations to define the audit objectives, criteria and scope for each audit. Programs built on the 2015 text defined criteria and scope only, so an audit plan with no stated objective is now a gap. Clause 9.2.2 d) keeps the duty to take appropriate correction and corrective actions without undue delay. As of September 29, 2026, Global ACI’s transition requirements give certified organizations until September 30, 2029 to complete the transition.

ISO 14001:2026: environmental importance and an available program

ISO 14001:2026 Clause 9.2.2 asks the program to consider the environmental importance of the processes concerned, changes affecting the organization and the results of previous audits, and it requires the audit program itself to be available as documented information. A common internal audit mistake in EMS audits is sampling only paperwork, such as permits and training logs, instead of observing operational controls at the point where significant aspects occur. As of September 29, 2026, certified organizations have until April 30, 2029 to transition. MSI’s ISO 9001 and 14001 transition guide covers running both transitions together.

ISO 14001:2026 Procedure Templates and Guides

Update Your EMS From 2015 to 2026 in a Week

Built for experienced EHS managers who already run an ISO 14001:2015 system and need to update it to the 2026 edition without rewriting it from scratch. Every procedure is a finished, editable Word document with the 2026 clause changes written in, including the internal audit program requirements, so your next audit cycle is built on the current standard.

Get the ISO 14001:2026 Templates →

ISO 13485:2016: the audit report is now a regulatory record

ISO 13485 predates the harmonized structure and handles internal audit at Clause 8.2.4, not 9.2. It requires a documented procedure for planning, conducting, recording and reporting audits, and it states plainly that auditors shall not audit their own work. It includes applicable regulatory requirements in the audit criteria, and it requires follow-up that includes verification of actions taken and the reporting of verification results. That last step, reporting the verification, is one of the most frequently missed requirements MSI sees in device systems, and one of the internal audit mistakes an FDA investigator can now read directly.

The stakes changed in 2026. The FDA’s Quality Management System Regulation took effect on February 2, 2026 and incorporates ISO 13485:2016 by reference. The FDA’s QMSR FAQ confirms the agency can now inspect internal quality audit reports, supplier audit reports and management review, because the old 21 CFR 820.180(c) exemption was not carried forward. As of September 29, 2026, a vague finding in a device internal audit report is a record an investigator can read. MSI’s ISO 13485 risk management and ISO 13485 design and development articles cover what investigators are looking at.

ISO 13485 Internal Audit Procedure Template

Write Device Audit Reports You Would Hand an FDA Investigator

An editable ISO 13485 Clause 8.2.4 procedure with the documented-procedure mandate discharged, regulatory requirements built into the audit criteria, a decision test for auditor independence, and the verification-reporting step most device systems omit.

See the ISO 13485 Audit Procedure →

ISO 7101:2023: auditing clinical care without clinical blind spots

ISO 7101:2023 is the first international standard for healthcare quality management, and it uses the harmonized structure, with internal audit at Clause 9.2 and management review at Clause 9.3. Its definitions point to ISO 19011 for audit evidence and audit criteria. The internal audit mistakes MSI sees in healthcare settings are sector mistakes: auditing the policy binder instead of observing care at the point of delivery, sampling only the charts a unit offers, and missing handoffs between departments where patient risk concentrates.

Clause 7.2.3.3 of ISO 19011:2026 and the technical expert role in Clause 3.17 are the remedy. An auditor without clinical background should pair with a technical expert, who provides knowledge but does not act as an auditor. MSI’s ISO 7101 healthcare consulting page and the ISO 7101 documentation guide explain how audit evidence lines up with the accreditation obligations healthcare organizations already carry.

ISO 7101:2023 Procedure Templates and Guides

Give Your Healthcare Auditors a System Built for Care

Every procedure a healthcare organization needs to run an ISO 7101:2023 quality management system, written as working documents rather than outlines. Leadership launching the standard for the first time can start with the Executive ISO 7101 HealthCare Quality Launch Program.

Explore the ISO 7101 Package →


Requirement or Guidance?

Which Audit Rules Are Requirements and Which Are Guidance?

Read. Label. Apply.

One of the quieter internal audit mistakes is writing a nonconformity against guidance. ISO 19011:2026 uses “should” throughout, so an auditee cannot be nonconforming to it. The table below separates what each document requires from what it recommends.

Required versus recommended: internal audit sources
ItemSourceStatus
Conduct internal audits at planned intervalsISO 9001:2026 9.2.1; ISO 14001:2026 9.2.1; ISO 7101:2023 9.2; ISO 13485:2016 8.2.4Requirement (“shall”)
Define audit objectives, criteria and scope for each auditISO 9001:2026 9.2.2 a); ISO 14001:2026 9.2.2 a)Requirement
Select auditors to ensure objectivity and impartialityISO 9001:2026 9.2.2 b); ISO 14001:2026 9.2.2 b)Requirement
Auditors shall not audit their own workISO 13485:2016 8.2.4Requirement
Documented procedure for internal auditISO 13485:2016 8.2.4Requirement
Report verification results of follow-up actionsISO 13485:2016 8.2.4Requirement
Audit program available as documented informationISO 14001:2026 9.2.2Requirement
Audit results as a management review inputISO 9001:2026 9.3.2 d) 3); ISO 13485:2016 5.6.2Requirement
Accept only verifiable information as audit evidenceISO 19011:2026 6.4.7Guidance (“should”)
Evaluate auditors with two or more methodsISO 19011:2026 7.4Guidance
Audit leadership below top managementISO 19011:2026 Annex A.9Informative annex
Nonconformities subject to corrective actionISO 14001:2026 Annex A.9.2Informative annex, no new requirement
See ISO 19011 for auditing guidanceISO 9001:2026 9.2.2 NOTENOTE, no obligation
Platform-specific competence for remote auditsMSI house standardMSI recommendation
Rotate auditors off the same process after three cyclesMSI practiceMSI recommendation

MSI Original Asset

The MSI Auditor Failure-Point Ladder

Score. Spot. Strengthen.

The ladder below condenses the internal audit mistakes in this article into one self-assessment. For each stage, score your program 0, 1 or 2: 0 if the early-warning sign is present, 1 if it is partly addressed, 2 if the fix is in place and evidenced. It is built from patterns across 200+ audits attended and 80+ certifications supported.

MSI Auditor Failure-Point Ladder
StageTypical failure pointISO 19011:2026Early-warning signFixScore
NoviceAccepts unverified statements6.4.7; A.5Findings cite what people said, not records seenRequire a record reference for every conformity0 / 1 / 2
NoviceAuditee chooses the sampleA.6Sample selection not recordedAuditor selects from full population and records method0 / 1 / 2
DevelopingAudits clauses, not processesA.2; 7.2.3.2 a) 9)No audit follows one transaction end to endAdd at least one process trail per audit0 / 1 / 2
DevelopingOffers solutions mid-audit6.4.9.2Auditor’s fix appears in the corrective actionSeparate recommendation from finding in the report0 / 1 / 2
SeasonedFamiliarity bias4.6; 7.2.2 b)Same auditor, same process, 3+ cyclesRotate auditors or pair with a fresh reviewer0 / 1 / 2
SeasonedStale technical competence7.2.1 b); A.16No CPD on digital evidence in 2 yearsAdd digital-evidence CPD to the competence plan0 / 1 / 2
Team leaderNo pre-closing conference6.4.9.1Conclusions drafted during the closing meetingSchedule a team conference before every closing0 / 1 / 2
Program managerAuditors never evaluated7.4; 7.6No witnessed audit on file for any auditorWitnessed audit plus report review each year0 / 1 / 2

Read the total out of 16. MSI client experience suggests that programs scoring 12 or above produce findings leadership acts on, programs between 7 and 11 produce findings that recur, and programs below 7 produce reports that describe the procedure rather than the practice. The two rows scoring lowest are where your internal audit mistakes concentrate, and where to invest first.

Internal Audit Procedure Template and Guide

Build the Fixes Into the Procedure, Not the Auditor’s Memory

One internal audit procedure for ISO 9001, ISO 14001:2026 and ISO 45001, with an evidence-reliability check, an independence decision test, a finding classification scheme and an eight-element maturity ladder. It encodes the ladder above so the fixes survive auditor turnover.

Get the Internal Audit Procedure →


Closing the Loop

How Do Internal Audit Mistakes Reach Management Review?

Audit. Review. Decide.

An audit that stops at the report has not finished its job. ISO 19011:2026 Clause 6.7 recommends that follow-up outcomes be reported to the audit client for management review. ISO 9001:2026 Clause 9.3.2 d) 3) requires trends in audit results as a management review input, ISO 13485:2016 Clause 5.6.2 lists audits as an input, and ISO 14001:2026 and ISO 7101:2023 carry audit results into Clause 9.3.

This is where internal audit mistakes compound. A softened finding becomes a softened management review input, and top management makes resource decisions on a picture that is better than reality. Clause 6.4.9.2 d) of ISO 19011:2026 recommends that audit conclusions address similar findings across areas and previous audits to identify trends, and those trends are exactly what management review needs. MSI’s guide to continual improvement shows how audit trends drive improvement decisions.

ISO Management Review Toolkits

Turn Audit Results Into Decisions, Not Minutes

MSI’s Management Review Toolkits give top management an agenda, input record and decision log built to each standard’s review clause, so audit trends arrive in a form leadership can act on. Device manufacturers can go straight to the Medical Device ISO 13485 Management Review Tool Kit, built to Clause 5.6 and its twelve inputs.

See the Management Review Toolkits →


Measuring Improvement

How Can You Measure Whether Internal Audit Mistakes Are Declining?

Measure. Compare. Improve.

ISO 19011:2026 Clause 7.3 recommends evaluation criteria that are both qualitative, such as demonstrated behaviour, and quantitative, such as the number of audits conducted and hours of audit training. Clause 5.6 recommends monitoring whether schedules are met, auditor performance, and feedback from auditees. Together, they give a program a way to measure whether internal audit mistakes are declining over time.

MSI recommends five indicators, reviewed at each audit program review under Clause 5.7:

  • Finding acceptance rate. The share of nonconformities acknowledged by process owners at the closing meeting. Low acceptance usually points to weak evidence or missing criteria.
  • Recurrence rate. Findings that reappear within two cycles. Recurrence points to findings that never stated the why.
  • External-before-internal rate. Issues a certification body raised that internal audits missed. This is the clearest single signal of internal audit mistakes.
  • Witnessed-audit coverage. The share of auditors observed at least once a year, per Clause 7.4.
  • Process-trail coverage. The share of audits that followed at least one transaction end to end, per Annex A.2.

Training is the fastest lever on all five. As of September 29, 2026, MSI’s internal auditor courses are being rebuilt around ISO 19011:2026 and the 2026 editions of the standards, and the updated versions are coming soon. They include the ISO 9001 2-Day Internal Auditing Training, the lower-commitment ISO Internal Auditor Online Workshop, ISO 14001:2026 Internal Auditing, ISO 13485 2-Day Internal Auditor Training and ISO 9001 and 13485 2-Day Internal Auditor Training for combined systems. MSI’s internal auditor training and internal audit services pages compare the options, and the ISO internal auditor guide covers the role itself.

Internal Auditor Training · 2026 Editions Coming Soon

Train Auditors on the 2026 Rules, Not the 2018 Habits

MSI’s internal auditor courses and online workshop are being updated to ISO 19011:2026, ISO 9001:2026 and ISO 14001:2026 content, including per-audit objectives, remote auditing methods and digital evidence. Each course walks auditors through the failure points on the ladder above, so your team learns to catch internal audit mistakes before they reach the report. See the course page for the 2026 release.

See the 2026 Internal Auditing Course →


Frequently Asked Questions

Internal Audit Mistakes: Frequently Asked Questions

Ask. Answer. Act.

What are the most common internal audit mistakes?

The most common internal audit mistakes are accepting evidence that cannot be verified, letting the checklist replace professional judgement, sampling whatever is convenient, and writing nonconformities that do not explain why the audit criteria were not met. ISO 19011:2026 addresses each one in Clause 6.4.7, Annex A.3, Annex A.6 and Annex A.18.3. Seasoned auditors add a different set: familiarity bias, stale technical competence and softened reporting.

Does ISO 19011:2026 require internal auditors to be certified?

No. ISO 19011:2026 is guidance, written with “should,” and no one certifies to it. Clause 7.2.4 describes competence as a combination of auditor training, relevant work experience, discipline and sector knowledge, and audit experience gained under the supervision of a competent auditor. Many internal audit mistakes trace to treating a training certificate as the finish line rather than the starting point.

How many audits does it take before an internal auditor is competent?

ISO 19011:2026 sets no number. Clause 7.3 recommends evaluating auditors against both qualitative criteria, such as demonstrated behaviour and skill, and quantitative criteria, such as the number of audits conducted. MSI client experience suggests most new internal auditors stop making beginner internal audit mistakes somewhere around their third or fourth supervised audit, and that the seasoned-auditor blind spots appear years later.

Can an internal auditor audit their own department?

Not their own work. ISO 13485:2016 Clause 8.2.4 states that auditors shall not audit their own work, and ISO 9001:2026 and ISO 14001:2026 Clause 9.2.2 b) require auditor selection that ensures objectivity and impartiality. ISO 19011:2026 Clause 4.6 adds that when internal auditors cannot be fully independent of the activity, every effort should be made to remove bias.

Are internal audit reports still confidential from the FDA?

No. As of September 29, 2026, the FDA’s Quality Management System Regulation, effective February 2, 2026, does not carry forward the old 21 CFR 820.180(c) exemption, and the FDA states it can inspect internal quality audit reports, supplier audit reports and management review records. For device manufacturers, vague or softened findings are now internal audit mistakes a regulator can read.

How should an organization evaluate internal auditor performance?

ISO 19011:2026 Clause 7.4 recommends using two or more evaluation methods from Table 2: review of records, feedback, interview, observation, testing and post-audit review. Clause 5.6 b) adds monitoring the performance of audit team members as part of monitoring the audit program. Combining a witnessed audit with a post-audit report review catches most internal audit mistakes that a records review alone misses.

Do internal audit results have to go to management review?

Yes, in every certifiable standard covered here. ISO 9001:2026 Clause 9.3.2 d) 3) lists audit results as a management review input, ISO 13485:2016 Clause 5.6.2 lists audits, and ISO 14001:2026 and ISO 7101:2023 carry audit results into Clause 9.3. ISO 19011:2026 Clause 6.7 says follow-up outcomes should be reported to the audit client for management review.


Next Step

Where Should You Start?

Assess. Plan. Act.

Every stage of auditor experience brings its own internal audit mistakes, and ISO 19011:2026 already names the fix for each. Start with the Failure-Point Ladder, pick the two lowest rows, and write the fix into your procedure rather than relying on any one auditor’s habits. If you want a second set of eyes, a planning session with MSI takes an hour and ends with a prioritized list. Call 760-434-9141, or learn how MSI’s ISO consulting team works alongside your auditors. Organizations building from scratch can look at SurePath, and certified organizations that want year-round support can look at SureResults.

Planning Session

Find Your Two Weakest Audit Rungs in One Hour

Talk through your audit program with an ISO consultant who has attended 200+ certification and surveillance audits. You leave with the two ladder rungs to fix first and the order to fix them in. No slides, no pitch.

Call 760-434-9141 →

References

About Management Systems International (MSI)

Diana Lynn, President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she founded in 1998. With 28 years of experience, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

Veteran-owned and female-owned · msi-international.com · 760-434-9141


Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 15 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply