You are standing in the closing meeting. The certification auditor presents their findings: a few minor nonconformities, and one major that matches the finding from last year exactly. Your internal audit reports claim the process was compliant. Clearly, your internal audits are not capturing reality.
ISO 9001 and IATF 16949 require internal audits. Every regulator and customer wants proof that you police yourself. Most manufacturers comply with a calendar in Excel: list the departments, schedule one audit per month, check the box, and archive the report. It is a compliance exercise that catches nothing.
ISO 19011:2018 — Guidelines for auditing management systems — is the mechanism to fix this. It shifts auditing from a retrospective inspection to a forward-looking, risk-based evaluation. A correctly implemented audit programme identifies systemic weaknesses before they become escapes and trains your process owners to manage quality independently.
Audit Programme vs. Audit Calendar
In most plants, an audit programme looks like a spreadsheet: columns are months, rows are departments, and the cells read "Internal Audit — Q1". That is a schedule, not a programme.
ISO 19011 defines an audit programme as a set of one or more audits planned for a specific time frame, directed toward a specific purpose. Building it requires a defined purpose, explicit risk consideration, and allocated resources. If your audit frequency does not change when a process degrades, you do not have an audit programme — you have a ritual.
Calendar-Based vs. Risk-Based Audit Programmes
Calendar-based approach
- Fixed schedule regardless of process performance or changes
- Identical checklists and depth applied to every department
- Focuses purely on verifying documented procedure compliance
- Findings are highly operational (e.g., missing a signature)
Risk-based approach
- Dynamic frequency driven by PPM rates, complaints, and capability data
- Audit depth scales with process volatility and strategic impact
- Evaluates process effectiveness, not just basic conformity
- Findings target systemic management system failures and causes

Executing the Audit: Evidence Over Checklists
ISO 19011 breaks audit execution into distinct phases: initiation, preparation, document review, on-site activities, and reporting. Most auditors fail at the on-site evidence collection phase. They sit in a conference room, flip through control plans, and check if records are signed.
The standard explicitly requires gathering evidence through interviews, observation, and document review. If your auditor never talks to operators or watches the actual cycle, the audit is noncompliant with ISO 19011. An operator following a work instruction perfectly will still produce scrap if the instruction itself is wrong.
Auditors must rigorously separate nonconformities from observations. A nonconformity is a clear breach of a defined criterion — a missing PFMEA revision, a Cpk below 1.33 on a critical safety characteristic. An observation is an area of risk that does not yet violate a requirement. Mixing the two destroys the 8D corrective action process.
ISO 19011 Evidence Collection Methodology
- 01Document ReviewVerify the control plan, routing, and work instructions are current and match the engineering baseline.
- 02Process ObservationWatch the actual cycle time, tool changes, and material handling without interfering with the operator.
- 03Operator InterviewsAsk open questions to verify they understand critical quality characteristics and safety requirements.
- 04Data TriangulationCross-reference physical reality with scrap logs, OEE data, and shift handover notes to identify gaps.
Auditor Competence: Technical Knowledge Is Not Enough
ISO 19011 defines specific auditor competencies: general knowledge, management system principles, audit techniques, and domain-specific expertise. The most overlooked requirements are the personal behaviours. An auditor must be ethical, open-minded, diplomatic, observant, and tenacious.
I have trained technically brilliant engineers who were disastrous auditors. They alienated the production team within ten minutes. Conversely, I have seen auditors with basic technical skills deliver massive value because they knew how to listen, observe the shop floor, and ask the right questions. The best auditor is not the one who writes the most nonconformities; they are the one who helps the process owner permanently eliminate a failure mode.
A successful closing meeting frames findings as business risks, not personal attacks. An experienced auditor communicates the systemic "why" so the process owner understands the impact on PPM rates or OEE, ensuring they engage fully with the subsequent 8D process.
The best auditor is not the one who writes the most nonconformities, but the one who helps eliminate a failure mode permanently.
Rebuilding a Failing Programme: A Case Study
I reviewed a Tier 1 automotive supplier (450 employees, precision powertrain components) holding IATF 16949 certification. Their internal audit programme consisted of twelve scheduled audits a year. Customer complaints were stagnant, and the cost of poor quality was climbing. Their certification body issued repeated majors for the same systemic failures.
The internal audits were flat. Every department received the same depth of scrutiny. The auditors rotated annually, preventing the development of real expertise. Their findings were purely operational: "Missing signature on the calibration log." Nobody evaluated whether the process was actually capable of meeting specifications. Crucially, corrective actions were implemented but their effectiveness was never verified.
We restructured the programme based entirely on risk. The high-pressure die-casting cell — running a new tool with high scrap variability — received three targeted audits a year. The packaging line, stable for two years, received one lightweight confirmation audit. We selected four auditors based on their interpersonal skills and trained them in evidence evaluation. Within twelve months, complaints dropped significantly, internal scrap costs fell, and they passed their IATF recertification with zero nonconformities.
Measuring Programme Effectiveness
Completing all scheduled audits on time measures schedule adherence, not effectiveness. ISO 19011 demands you evaluate the audit programme itself. If the same nonconformity appears in consecutive audits, your programme is failing to drive corrective action.
You must track the implementation of corrective actions generated by audits, verify their effectiveness over time, and measure the impact on core operational KPIs. If your audits are working, OEE should stabilise, scrap rates should fall, and customer PPM should decrease.
A digitally mature QMS can automate much of this tracking, but technology cannot replace auditor competence. Software can flag a missing signature, but an AI cannot read an operator's hesitation during an interview. Trust and observation remain the core of effective quality assurance.
Turning Audits into Strategic Assets
ISO 19011 is not a guideline for surviving a certification audit. It is a framework for building a management system that actively reduces risk. Adopt a risk-based approach to scheduling, train auditors to evaluate processes rather than just paperwork, and rigorously verify the effectiveness of every corrective action.
Ask yourself one question when planning your audit schedule: if certification bodies disappeared tomorrow, which of your planned audits would you still execute to protect your margins? Those are the only audits worth doing.
