Internal Audit and Gap Assessment

ISO Internal Audit Services Australia

An independent internal audit before your surveillance audit finds the gaps before your certification body does. We audit your system, give you a clear findings report, and help you close anything out before the auditor arrives.

ISO Internal Audit taking place
What It Is

What is an ISO internal audit?

An internal audit is a requirement of every ISO management system standard - ISO 9001, ISO 45001, ISO 14001, ISO 27001, and integrated HSEQ systems. It is a structured review of your management system to check that it is being implemented as documented, meets the requirements of the standard, and is effectively maintained.

Internal audits must be conducted at planned intervals - typically annually. The results must be reported to management and any non-conformances must be addressed through your corrective action process. Evidence that internal audits have been completed is one of the first things a certification body auditor will check at your surveillance or recertification audit.

The standard requires that the internal audit process is objective and impartial. Auditors cannot audit their own work. For small and medium businesses without a dedicated compliance function, this creates a practical challenge - the same person who manages the system cannot audit it.

ISO internal audit can be stressful
- When you need it

When do you need an internal audit

Some situations are planned. Others are urgent. We handle both.

Surveillance audit is coming up

Your annual surveillance audit is 4 to 8 weeks away and your internal audit has not been done. This is the most common reason businesses call us. We can turn around an internal audit quickly.

Internal audit is overdue

Your last internal audit was more than 12 months ago. Your certification body will flag this immediately. Getting it done now protects your certification.

Annual scheduled audit

You want your internal audit conducted professionally each year without the hassle of doing it yourself. We become your outsourced internal audit function.

Preparing for initial certification

You are approaching your Stage 1 or Stage 2 audit and want to check your system is genuinely ready before the certification body does.

Independence problem

In your business, the person responsible for quality cannot audit their own work. You need an independent auditor to satisfy the standard's requirements.

System has drifted

Your management system has not been maintained properly and you want an honest assessment of where it stands before your next external audit.

- What you receive

What ComplyOn delivers after every internal audit

A complete, professional internal audit package - formatted for you, your certification body and actionable by your team.

Full written audit report

Covers every clause of your ISO standard. Findings categorised as conformances, observations, and nonconformances. Formatted for your certification body.

Corrective action plan

For every nonconformance raised, a clear corrective action with root cause analysis, required action, and target completion date.

Improvement recommendations

Observations and opportunities for improvement beyond mandatory requirements - practical suggestions your team can act on.

Debrief with your team

We walk through findings with the relevant people in your business so everyone understands what was found and what needs to happen next.

  1. 1
    Sail through your certificationfind issues and deal with them
  2. 2
    Ensure your system compliesbe ISO compliant
The businesses that sail through their surveillance audits are the ones that take their internal audits seriously. They find their own nonconformances, fix them, and arrive with evidence of a functioning improvement cycle. That is exactly what auditors want to see
- How it works

How a ComplyOn internal audit works

Straightforward from first contact to final report. Most small business audits are completed in one day.

Scope and Quote

We confirm your standard, business size, and timeline. Fixed price agreed before we start.

Document Review

We review your management system documentation before the on-site or remote audit day.

Audit Conducted

In person or remotely. We interview staff, review records, and check processes against the standard.

Report Delivered

Full written report with corrective action plan delivered within 5 business days. Debrief included.

Close out findings

Help you with corrective action or implementation of improvements

Why Us

Why Use an External Auditor for your internal audit

Independence the standard requires ISO management system standards require that internal audits are conducted impartially. If the person who built and manages your system is also conducting the audit, that independence is compromised. Certification body auditors are trained to spot this - and they will note it.

Using an external auditor removes the conflict entirely. Your internal audit is conducted by someone with no stake in the outcome other than finding what needs to be found.

We know what certification body auditors look for Our consultants have worked across implementation, auditing, and management systems extensively. We know the areas where certification body auditors focus their attention during surveillance audits. We know the findings that come up repeatedly across ISO 9001, ISO 45001, ISO 27001, and HSEQ systems. We find those things before the auditor does.

That is not the same as coaching you to hide problems. It means that by the time your surveillance audit arrives, the gaps have been identified, corrective actions have been raised, and your system can demonstrate that it responds to findings - which is exactly what the standard requires.

A clear report, not a document dump After the audit, you receive a findings report that tells you plainly what was found, how it is classified - major non-conformance, minor non-conformance, or observation - and what needs to be done before your surveillance audit. No jargon, no padding. A clear list of what requires action and by when.

You stay focused on your business Preparing for and conducting an internal audit takes time - time that most business owners and managers do not have spare. We handle the audit process from planning through to the findings report. You review the report, action what needs to be actioned, and go into your surveillance audit prepared.

What we do

Two services. Both done properly.

We don't do vague retainers. We do specific, scoped work with clear outcomes so you know what you're getting before we start.

Service 01

Get certified

Full ISO implementation - we build it with you

We work alongside your team to build an ISO management system from scratch. Clear plans, right-sized controls, support through the audit so your team keeps working while we handle the heavy lifting.

This is right for you if: You need certification to win a contract or meet a customer requirement - and want experts guiding every step.

  • Gap assessment with prioritised action plan
  • Policy and procedure development
  • Risk register and management system build
  • Staff briefing and awareness
  • Internal audit and management review
  • Certification audit support

Service 02

Stay certified

Maintenance, audits and system recovery

Already certified but struggling to maintain it? We help businesses whose systems have drifted get back on track, and put in place the habits to stay there without ongoing consultant dependency.

This is right for you if: Your surveillance audit is approaching, your internal audit is overdue, or your system hasn't been touched in months.

  • System health check and gap assessment
  • Internal audit - conducted and reported
  • Document and record update
  • Corrective action support
  • Surveillance audit preparation
  • Annual maintenance planning

Need an internal audit specifically?

Internal audit is one of the most commonly searched ISO services - and one of the things businesses most often let slip. We conduct ISO internal audits as a standalone engagement, with a full written report and corrective action plan. Works for any ISO standard.

FAQs

Frequent asked questions about ISO internal audits

- Get Started

Need an internal audit? Let us help.

Start with a free consultation. We'll tell you exactly what's involved, how long it takes, and what it costs - before you commit to anything.

Request a quote

info@complyon.com.au · Australia-wide · In person or remote

ComplyOn Logo Watermark
ComplyOn Logo

Get certified. Stay certified.

ISO 9001, ISO 45001, ISO 14001, ISO 27001, and HSEQ. Fixed price consulting for Australian businesses.

info@complyon.com.au

ComplyOn partner accreditation badge

© 2026 ComplyOn.