WCapsuleM8

Internal Audit Checklist

$19

Run ISO-style internal audits of your management system and processes — record each check with objective evidence, grade findings from OFI to major nonconformity, track corrective actions to verified closure and watch the conformity trend; for hazard walkrounds or workplace-organisation scoring use

Version 1.0.0 · Updated Aug 7, 2026

Overview

Run ISO-style internal audits of your management system and processes — record each check with objective evidence, grade findings from OFI to major nonconformity, track corrective actions to verified closure and watch the conformity trend; for hazard walkrounds or workplace-organisation scoring use the safety inspection or 5S audit tools instead. Nothing is uploaded.

Frequently asked questions

How does the Internal Audit Checklist licence work?

It is a one-time purchase for a downloadable tool — no subscription. You buy it once and the file is yours to keep and use.

Can I try the Internal Audit Checklist before buying?

Yes. Use the Try online button for a fully interactive demo with sample data already loaded — nothing to install and nothing is saved.

Does my data stay private?

Yes. The tool is a single HTML file that runs entirely on your computer and makes no network requests, so nothing you enter is ever uploaded or shared.

Do I need Excel or any other software?

No. It replaces the spreadsheet template entirely: open the file in your browser (Chrome, Edge, Firefox or Safari) on Windows, Mac, Linux or a tablet, and start working.

How to use Internal Audit Checklist

The complete in-tool guidance, reproduced here so you can read it before you download.

What this tool does

CM8-243 is a working internal audit checklist and finding tracker. One row is one audit question: what you checked, against which requirement, what evidence you examined, what result you graded, and — where the check found a gap — the finding, the corrective action, its owner and its verified closure. From that it shows the conformity rate of every audit, the trend across audits, the open findings by area, and prints a report fit for a management review or an external assessment.

This is the general tool for management-system and process audits in the ISO style — purchasing, goods-in, document control, training, any process with a procedure behind it. It is deliberately not a hazard walkround and not a workplace-organisation score: for physical safety inspections use the Safety Inspection Checklist, and for sort-set-shine workplace scoring use the 5S Audit — those tools grade conditions; this one audits whether a defined process is actually being followed.

Everything runs inside this single file. No account, no upload, no network request of any kind — your audit findings, which name processes that are failing and people who own them, never leave the computer you are using.

What internal auditing is for

An internal audit exists to answer one question: does the system we say we operate actually operate? It verifies that the procedure and the practice are the same thing, and finds the places where they have drifted apart before a customer, a regulator or a certification body does. It is not for catching people. The moment an audit becomes an instrument of blame, people manage the audit instead of the process — records get tidied the week before, answers get rehearsed, and the audit stops telling you anything true. A good auditor assumes the person doing the job knows things the procedure's author did not, asks to be shown rather than told, and treats every gap found as information about the system, not a verdict on the person standing in it.

Planning an audit

Three decisions before you ask a single question:

  • Scope — which process, which site, which period. "Goods-in receiving, main warehouse, the last three months" can be audited in a morning. "Operations" cannot be audited at all.
  • Criteria — what you are auditing against: the clause of the standard, the section of your own procedure, the contract term. Put it in the requirement field on every row. A check with no stated criteria produces an opinion, not a finding.
  • Sample — how many records, which people, which days. Small samples are legitimate — auditing is sampling by design — but decide the sample before you start, and record its size in the evidence so the reader knows what "all conformed" is worth. Ten purchase orders picked by the auditor tell you more than fifty picked by the auditee.

Enter every question you plan to ask as a row, then work through them on the day. Questions you could not reach get "Not checked" and carry forward — they are excluded from the conformity rate rather than counted as passes, which is the honest treatment.

Objective evidence

Evidence is what makes an audit an audit rather than a conversation. It comes from three places: records (the PO file, the inspection log, the training card), interviews (what the people doing the work say happens — especially when two people say different things), and observation (what you watched happen while you stood there). Assertions are not evidence: "the supervisor confirmed inspections are always done" verifies nothing; "sampled 8 deliveries, inspection records found for 5" verifies something and quantifies it.

Write the evidence so that a reader could re-verify it: what you examined, how many, over what period, and what you found. That standard applies to conformities as much as to findings — "sampled 10 POs, all 10 approved per the matrix" makes a clean result mean something. A conformity with no recorded evidence is a box ticked, and a register of ticked boxes convinces nobody, including an external assessor reading your internal audit records.

Grading honestly

The grade is a claim about the system, so the distinction that matters is not "how bad does it look" but "how far does it reach":

  • Minor nonconformity — an isolated lapse in a control that otherwise operates. Three suppliers out of forty-two past their re-evaluation date, where the schedule exists and is followed.
  • Major nonconformity — a systemic failure or an absent requirement: the control is not operating, or was never implemented. Inspection records missing for three of eight deliveries because staff skip them under time pressure is major even though the arithmetic looks similar — the control has failed as a control.

The crisp test: would a different person on a different day hit the same gap? If yes, it is systemic — grade it major. If it took one person on one bad day, it is minor. Several minors in the same clause across audits are a major wearing a disguise.

An opportunity for improvement conforms. It is a requirement met in a way that could be better — duplicated effort, a clumsy route, an ageing method. It is not a finding-lite dumping ground for nonconformities the auditor lacked the nerve to grade: if a requirement is not met, grade it, however awkward the conversation. An OFI raised to spare someone a minor corrupts both categories.

Writing findings

A finding has exactly three parts, and this tool will not save a minor or major without them written down: the requirement (which clause, quoted or referenced), the evidence (what you examined and what you found), and the gap (the difference between the two). No adjectives — "poor", "inadequate" and "unacceptable" are opinions, and they age badly when the finding is read back in a disagreement. "Procedure §2.1 requires a recorded inspection for every delivery; 3 of 8 deliveries sampled had no record; the control is not operating" needs no adjectives, cannot be argued with, and tells the process owner exactly what to fix.

Corrective action and effectiveness verification

A corrective action addresses the cause, not just the instance: completing the three overdue re-evaluations fixes the instance; the monthly due-date report fixes the cause. Give every action one named owner and a due date, and track it through the statuses — open, action agreed, in progress.

The last status is the one that matters: Closed — effectiveness verified means someone went back and confirmed the action worked, not merely that it was done. "Action taken" and "action worked" are different claims — a briefing delivered to a team that still skips the record is an action taken and a problem intact. The verified-closed date field records when that check happened, and the tool will not accept the closed status without it. The average-days-to-close tile measures audit date to verified closure, because that is the interval the organisation actually experienced the gap.

The trend and the repeat signal

Conformity rate = conforms ÷ (checked − not checked) × 100 “Conforms” counts both Conforms and OFI results — an OFI conforms by definition. “Not checked” rows are excluded from the denominator, not counted as passes.

One audit's rate is a snapshot of one sample. The trend across audits is the system-health signal: a line drifting down over three or four audits means the system is losing to daily pressure, whatever each individual audit report said. Do not chase decimal differences between audits of different processes with different sample sizes — compare each process with its own history.

The repeat areas tile watches for the other systemic signal: an area with nonconformities in two or more separate audits. One finding is a lapse; the same area failing across audits means the corrective actions are treating instances, not causes — which is a finding about your corrective action process itself.

Independence

Auditors should not audit their own work — not because they would lie, but because they share the assumptions that created any gap and will look straight past it. In a small organisation full independence is impossible and honesty about it beats pretence: swap audits between department heads, borrow an auditor from a sister site, or at minimum have someone uninvolved pick the sample. Record the auditor's name on every row; who audited what, and whether they were independent of it, is one of the first things an external assessor checks.

FAQ

How many questions should an audit have? Enough to cover the scope's key controls — typically eight to twenty for a single process. Fifty questions answered superficially verify less than twelve answered with real evidence.

Should I record the checks that passed? Yes — with evidence. The conformities are what make the report credible and the conformity rate meaningful. An audit file containing only findings reads as a grievance list.

Who should own a corrective action? The owner of the process that failed — never the auditor. The auditor found the gap; the process owner closes it; the auditor (or another independent person) verifies effectiveness.

Can I close a finding when the action is done? Move it to "in progress" or leave it at "action agreed" until someone has verified the action worked — then close it with the verification date. Closing on completion rather than effectiveness is the single most common audit-programme failure.

What if the auditee disagrees with a finding? Re-examine the evidence together. If the evidence stands, the finding stands; if it does not, withdraw it without embarrassment. A withdrawn weak finding buys credibility for every finding you keep.

Is this enough for certification? It is a record of your internal audits, which every management-system standard requires. Whether your audit programme — coverage, frequency, auditor competence, independence — satisfies a certification body is a separate question this tool cannot answer.

Saving your work

Checks, settings and the report header are written to this browser's local storage as you type, and the toolbar shows the time of the last save. That storage belongs to one browser on one computer: another browser, a private window, a second machine or a clean-up tool that clears site data will not have it.

Treat Export .json as the real save — one file containing everything, which Import .json restores anywhere. Export CSV gives you the register for spreadsheet work. Reset asks twice, then erases everything this tool has stored. There is no undo. Audit records are typically retained for years — export after every audit and file the export with the audit report.

Accuracy & disclaimer

The arithmetic here is simple and shown in full. Everything that matters sits underneath it: whether the sample was fair, whether the evidence was really examined, and whether the grades reflect the reach of each gap rather than the comfort of the room. An internal audit samples — a clean audit is evidence of conformity in the sample examined, not proof of perfection, and an external assessor sampling differently may find what you did not.

Management-system standards, certification rules and record-retention expectations differ by standard, by industry and by country. This is an internal record-keeping and analysis aid, not a certification audit, not legal or regulatory advice, and not a substitute for auditor competence and independence.

Link incoming material batches to the batches you make and the customers you send them to, so a recall can be scoped in minutes instead of days. Runs entirely in your browser — nothing is uploaded.

DownloadView

Track corrective and preventive actions from problem to verified fix: root causes, owners, due dates, effectiveness checks and an aging view for management review. Runs entirely in your browser — nothing is uploaded.

Download Runs in browserView

Track customer complaints from intake to closure — acknowledgement and resolution times, justified rate, complaint costs and category trends, with a customer-ready report. Nothing is uploaded.

Download Runs in browserView

Log every delivery as it arrives, compare what turned up against what was promised and ordered, and measure on-time, in-full and on-time-in-full by supplier with the discrepancies still open. Runs entirely in your browser. Nothing is uploaded.

DownloadView