
Internal audit and management review are the organisation's own oversight machinery. One tests whether the management system does what its documents say it does, and the other is top management looking at that result and deciding what to change. Between certification visits they are the two processes that look at the system as a whole.
The certification rules take both as given. IAF MD 1:2023, Issue 3, issued on 18 October 2023, sets the conditions for certifying a management system operated across several sites. Clause 5.4: "The organization's single management system shall be subject to a centralized management review." Clause 5.5: "All sites shall be subject to the organization's internal audit programme." Each is a condition of eligibility, written on the assumption that a certified organisation already runs both, and the sampling rules sit on top of that assumption.
Internal audit is the organisation examining its own management system, on a plan, against the standard it is certified to and its own documented arrangements. The ISO 9001 Auditing Practices Group, whose guidance was published jointly by ISO/TC 176 and the IAF, calls it "a feedback mechanism for the top management".
Management review is what top management does with that feedback. The same group describes the requirement as top management reviewing the system "at planned intervals, to ensure its continuing suitability, adequacy and effectiveness".
ISO 27001 and ISO 9001 both place these two processes in the performance evaluation part of the system. What internal audit and management review look like at a surveillance audit sets out where they land in the certification cycle.
The internal audit programme requirements fit into one sentence. ISO 9001:2015 clause 9.2.2, reproduced in the Auditing Practices Group paper on internal audits, states:
"The organization shall plan, establish, implement and maintain an audit program(s) including the frequency, methods, responsibilities, planning requirements and reporting, which shall take into consideration the importance of the processes concerned, changes affecting the organization, and the results of previous audits"
Five things go in the programme, three things shape it, and no number appears anywhere in it. The Auditing Practices Group is explicit: the organisation defines "the audit program, the frequency, duration, and scope of internal audits, as 9001 does not specify these criteria." The programme states its own frequency, which makes an annual burst in August a decision the organisation made and one it can be asked to justify.
Risk sets the order of work. The same paper puts it directly: "The processes with higher levels of risk or nonconformities should have priority in the internal audit programme." An organisation auditing the same three well-run processes each cycle has a programme in name, covering none of the places that have caused it trouble.
On who does the auditing, the guidance is softer than most people assume. ISO 9004:2018 clause 10.5, quoted in the same paper, says audits "should be conducted by people who are not involved in the activity being examined", and the paper notes that this ISO 9004 guidance is not an auditable requirement for an ISO 9001 audit. What a third-party auditor does examine is the objectivity and impartiality of the process, the competencies applied and the use made of the outcome. That list mentions ISO 19011 with a parenthesis worth keeping: "but note that ISO 9001 does not require the organization to use ISO 19011".
The meeting is optional. From the Auditing Practices Group: "The review could be carried out at a separate meeting but this is not a requirement of the standard." A report to top management counts. So does a regular management meeting.
Outputs are where reviews usually fail, and the paper looks for evidence of decisions regarding "changes to the quality policy and objectives", "plans and possible actions for improvements", "change of resources", "revised business plans" and "budgets". A record saying the system was reviewed and found adequate contains no decision, and the auditor reading it can tell.
The test applied to all of it is proportionate. The management review paper says an auditor "should look for evidence that the inputs and outputs of the management review process are relevant to the organization's size and complexity and that they are used to improve the business". A twelve-person company producing a forty-page review pack fails that test from the other direction.
The certification body is expected to say so in writing. The Auditing Practices Group paper on audit reports, Edition 1, says the report section covering internal audit, management review and continual improvement "should provide comment on the timeliness and effectiveness" of those processes. Timeliness carries as much weight there as effectiveness.
Sequencing makes it visible, and the internal audits paper calls it good practice "to audit internal audits processes of the organization toward the end of the third-party audit", so the auditor reads your internal results with their own findings already on the table.
Then there is the structural version. ISO 9001:2015 clause 9.2.2 requires the programme to take into consideration "the results of previous audits". A programme that ran once in the year has nothing to plan the next round from, so year two repeats year one. The document set is what gives it away: audit report, corrective actions and review record all dated inside the same fortnight, with nothing from the months before it. The planning material is the record of what has actually gone wrong, and how a risk register is actually run covers keeping that current.
For a group, these are the two processes that have to be genuinely single. Clause 5.6 of IAF MD 1:2023 attaches them to a named central function responsible for ensuring that data "is collected and analyzed from all sites", with authority to initiate change across a list that includes management review as well as internal audit planning and evaluation of the results. The Note to that clause is worth reading if you hold the job without the title: "There is no requirement for the central function to be located in a single site."
How well both run then decides how much auditing the group receives. Clause 6.1.2.4 lists "results of internal audits of sites, management reviews and/or previous certification audits" among the aspects site selection shall consider, and clause 6.1.3.5 names "results of internal audits and management review" among the factors that can increase the size or frequency of the sample. More on that structure in compliance across multiple entities and products.
Holding two standards puts the level of integration into the calculation. IAF MD 11:2023, Issue 3, Annex 1 says an integrated management system is characterised by, among other things, "Management Reviews that consider the overall business strategy and plan" and "An integrated approach to internal audits". Clause 2.1.1 makes the extent of integration a factor in reducing audit time, and clause 2.1.2 states that an integrated audit could result in increased time and caps any reduction at 20% of the starting point. Both audits then run on evidence that serves more than one framework.
The programme document comes first, because ISO 9001:2015 clause 9.2.2 names what it contains. A date in the calendar covers one of those five items and leaves the other four undocumented.
Competence has to be written down, and the Auditing Practices Group looks for evidence that an organisation has identified the competence requirements for its internal auditors, engages auditors with appropriate training and monitors how they perform.
Findings need a destination, and the audit reports paper expects comment on "the sufficiency of the organization's formal processes for corrective action" as well as on the actions themselves. The review needs the least ceremony: inputs assembled for the period it covers, decisions written so somebody could act on them, and a named person with a date against each.
Naq gets an organisation audit-ready and keeps the record between visits. ISO 27001 and ISO 9001 certificates are issued by a certification body accredited by UKAS.
The evidence both processes run on is already in the platform, and it is already dated. Every control has a named owner, and its status is set from the evidence attached to it, with the owner able to override. Evidence is tied to the specific requirements it proves, so replacing a file leaves it uncounted until that owner re-confirms it. Documents run owner to approver with mandatory comments, semantic versioning and a review schedule set at approval. Every record carries a chronological activity stream, and field edits on it show the previous value and the new one. Records are archived instead of deleted.
An internal audit finding goes into the CAPA register against the source type Other, with a finding type of Minor, Major or an opportunity for improvement, and a root cause has to be written before it can move to In Progress. Each framework instance carries its own scope and schedule, and a control satisfying requirements in more than one of them is recorded once.
The ISO 9001 and ISO 27001 framework pages carry the requirement detail. If internal audit and management review are the two things your calendar keeps pushing into August, book a fifteen-minute demo and bring last year's audit programme.