+31 (0)73 - 220 2000 | info@brandcompliance.com
English
  • Dutch
  • English
  • Beglië
  • Dutch
  • English
  • Beglië
Brand Compliance
  • Certify
    • ISO 9001
    • ISO 22301 (BCM)
    • ISO 19770-1 (IT-assets)
    • ISO 27001
    • ISO 27017 and ISO 27018
    • BIO
    • ISO 27701 (Privacy)
    • NEN 7510
  • IT Assurance
    • SOC 2
  • Vacancies
  • Knowledge base
  • BC Academy
Contact
  • Information security
    • ISO 19770-1
    • ISO 27001
    • ISO 27017 and ISO 27018
    • ISO 27799
    • BIO
    • NEN 7510
    • SOC 2
    • ISAE 3402
  • Privacy
    • Whitepaper BC 5701
    • AVG standard BC 5701:2023 NL
    • GDPR standard BC 5701:2023 EN
    • GDPR standard BC 5701:2024 EN
    • BC 5701
    • ISO 27701
  • Quality
    • ISO 9001
    • ISO 14001
    • ISO 22301
  • Knowledge base
  • News
  • Academy
    • NIS2 training course
    • ISO 27001 training courses
    • BC 5701 training courses
  • About us
    • Start your certification journey
    • Accreditations
    • Compliment, complaint or tip
    • Privacy Statement
    • Vacancies
    • Contact

Certification process

10
  • Checklist certification
  • Do you have your first audit soon?
  • How long does ISO certification take?
  • What is a certification cycle?
  • Applying for a certification process
  • Initial audit Stage 1
  • Initial audit Stage 2
  • Nonconformities management system
  • Certificate suspended or revoked? This is how you solve it!
  • Transfer of certification

BC 5701

5
  • BC 5701 certification: where do you start?
  • Your record of processing activities and the GDPR
  • Your Data Protection Officer and the GDPR
  • Checklist for your BC 5701 certification
  • Data breach: What is it and how do you prevent it?

General

9
  • SOC 2 or ISAE 3402: which standard suits your organization?
  • The Traffic Light Protocol (TLP): what does it mean for you?
  • The Brand Compliance glossary
  • What is a management system?
  • Internal or external audit?
  • Find out more about internal audits
  • Tips to describe a proper scope
  • Accreditation versus certification
  • The use of certification logos

ISO 27001:2022

3
  • Operational Capabilities: The Backbone of Information Security
  • ISO 27001:2022 – FAQ transition
  • ISO 27001:2022 – Transition process

Whitepapers

2
  • Whitepaper management system audits
  • Whitepaper GDPR Certification Standard and Criteria BC 5701

Best practices

3
  • Mastering GDPR compliance: best practices
  • Excelling in information security: best practices
  • Quality Management: best practices for success

NEN 7510

4
  • Transition to NEN 7510-1:2024
  • NEN 7510 without healthcare institution?
  • How to expand with NEN 7510
  • The differences between ISO 27001 and NEN 7510

NIS2 Directive

2
  • NIS2 liability
  • NIS2 & the Belgian CyberFundamentals
View Categories

Find out more about internal audits

1 min read

internal auditAn unmistakable part of maintaining a management system is the performance of internal audits on the management system of your organization. But how is such an internal audit carried out? What to think about and what to take into account?

In this article we take a closer look at how an internal audit can be performed. We tell you about the steps that are taken, from preparation to follow-up.

Guidelines

The ISO 19011 standard provides guidelines for auditing management systems, including the basic principles of auditing and management of an audit programme. You can consult this standard as support for conducting internal audits. The guidelines apply to all types of organizations that need to plan and perform internal audits on management systems, or manage an audit programme.

Conducting an internal audit

Conducting an internal audit according to the ISO 19011 standard requires a structured approach to assess and improve the effectiveness of an organization’s management system.

Below we share the most important steps:

  • Preparation
    Start by establishing the audit objective, scope and criteria. This includes determining which part of the management system is audited, at what level and with what documents. Plan audit activities and communicate with relevant stakeholders.
  • Document review
    Study the documentation related to the management system, including policies, procedures, instructions and records. Collect information about the processes, objectives and performance indicators.
  • The audit
    Perform the on-site audit by conducting interviews, checking documents and making observations. Collect objective evidence to assess whether the management system meets the requirements of the standard. Conduct interviews with employees at different levels and assess compliance and effectiveness of processes.
  • Findings and analysis
    Analyse the evidence collected and evaluate the findings against the requirements of the standard. Identify deviations or opportunities for improvement. Classify the findings according to their severity and impact on the management system.
  • Reporting
    Prepare an audit report that reflects the results, findings and recommendations of the audit. Also state the scope, criteria and the audit method applied. Communicate the report to relevant stakeholders, including top management.
  • Follow-up
    Check whether the identified nonconformities and shortcomings have been adequately addressed by management. Ensure corrective actions are implemented and effective. Follow up on any action plans and monitor the progress of improvements.

Good luck!

With this article we hope to have provided insight into how to conduct an internal audit. As you have read, it requires careful planning, execution and follow-up. By following a structured approach, your organization can gain valuable insights into the performance of its management system and make the necessary improvements to achieve the set goals.

As a final tip, you can read more about internal audit requirements in chapter 9 of your chosen management system standard. Good luck with the internal audit!

Share This Article :
  • Facebook
  • X
  • LinkedIn
Updated on 30 August 2023
Internal or external audit?Tips to describe a proper scope

Accreditation

RvA C548Brand Compliance B.V. has accreditation (C548) to certify ISO 27001, ISO 27701 NEN 7510 and ISO 9001 scope 33 information technology and 35 other services.

Brand Compliance B.V.

Hambakenwetering 8D2
5231 DC ‘s-Hertogenbosch

+31 (0)73 220 2000
info@brandcompliance.com

Chamber of Commerce nr.: 32101659
VAT nr.: NL8130.78.854.B01

Brand Compliance Belgie B.V.

Uitbreidingstraat 66
2600 Berchem (Antwerpen)

+32 (0)14 48 0730
be-info@brandcompliance.com

VAT nr.: BE0735.675.516

Brand Compliance Nordics AB

Vasagatan 16 2 TR
111 20 Stockholm

+31 (0)73 220 2015
info@brandcompliance.com

Org.nr: 559238-1387

© Copyright 2025 Brand Compliance