Internal audits are the EMS self-check mechanism — the systematic process for verifying that the management system conforms to both the ISO 14001:2015 standard and the organization’s own requirements, and that it is effectively implemented and maintained. Clause 9.2 requires a planned, documented audit program that covers the entire EMS at appropriate intervals.
Clause 9.2.1: General Requirements
Organizations must conduct internal audits at planned intervals to provide information on whether the EMS conforms to the organization’s own requirements for its EMS, conforms to the requirements of ISO 14001:2015, and is effectively implemented and maintained.
Clause 9.2.2: Internal Audit Program
The audit program must define audit frequency, methods, responsibilities, planning requirements, and reporting. It must take into account the environmental importance of the processes concerned, changes affecting the organization, and results of previous audits. Organizations must select auditors who ensure objectivity and impartiality, and ensure results are reported to relevant management.
Audit Program Planning Factors
- Risk-based scheduling: Higher-risk processes and significant environmental aspects audited more frequently
- Process importance: Areas with direct compliance obligations prioritized
- Change impact: Recently changed processes targeted for early audit
- Historical performance: Areas with previous nonconformities given additional attention
- Full coverage: All EMS elements covered over the audit cycle
Auditor Requirements
Auditors must be competent (see Clause 7.2) and must not audit their own work to ensure objectivity. Training in ISO 19011 (Guidelines for auditing management systems) is widely recommended. Auditor competency includes knowledge of ISO 14001:2015 requirements, auditing techniques, the organization’s processes, and applicable environmental regulations.
The Audit Process
- Planning: Define scope, criteria, schedule, and team
- Preparation: Review documented information, prepare checklists
- Execution: Conduct opening meeting, gather evidence through interviews, observation, and document review
- Reporting: Document findings, classify nonconformities, identify observations
- Follow-up: Verify corrective actions are implemented and effective
Common Pitfalls
- Audit program not risk-based, resulting in inadequate coverage of high-risk areas
- Auditors lacking independence or competence
- Superficial audits that check documents without verifying implementation
- Audit findings not driving meaningful corrective action
- Conducting audits only before external surveillance visits
Frequently Asked Questions
How often does ISO 14001 require internal audits?
The standard requires internal audits at planned intervals rather than on a fixed schedule. The audit programme must consider the environmental importance of the processes, changes affecting the organization, and the results of previous audits. Most organizations audit the full EMS across a twelve-month cycle, auditing high-risk or high-impact areas more frequently than low-risk ones.
Who can perform an ISO 14001 internal audit?
Anyone with demonstrated competence in auditing and sufficient understanding of the EMS and the processes being audited. There is no requirement for external certification as an auditor, though lead auditor training is common. Competence must be evidenced under clause 7.2, so keep records of auditor training, experience, and any calibration or shadowing exercises.
Can an internal auditor audit their own department?
No. Clause 9.2 requires auditor selection and audit conduct to ensure objectivity and impartiality, which rules out auditing your own work. Small organizations commonly solve this by cross-auditing between departments or sites, using trained staff from an unrelated function, or bringing in an external contract auditor for areas where nobody independent is available.
What is the difference between an internal audit and a certification audit?
An internal audit is conducted by or on behalf of the organization to check that the EMS conforms to its own requirements and to the standard, and that it is effectively implemented. A certification audit is conducted by an accredited third-party body to decide whether to grant or maintain certification. Internal audit results are a required input to management review and are examined by certification auditors as evidence the system is self-correcting.
Does every clause need to be audited every year?
Every requirement of the standard and every part of your EMS should be covered across the audit programme cycle, but not necessarily in a single audit or a single year if your programme justifies a longer cycle. Certification bodies generally expect full coverage within the three-year certification cycle at minimum, and most organizations find an annual full-scope cycle simpler to defend.
What documented information does clause 9.2 require?
You must retain evidence of the implementation of the audit programme and of the audit results. In practice that means the audit programme or schedule, audit plans, auditor competence records, completed audit checklists or working papers, audit reports with findings classified, and records showing findings were routed into the corrective action process under clause 10.2.
Ecesis runs your audit programme, schedules, checklists, findings, and corrective action follow-up.
Request a free 30-minute demo

