Call Today! (800) 244-5409

Internal Audits vs Certification Audits: What’s the Difference and Why Both Matter

If your organization holds an ISO certificate, or is working toward one, two very different kinds of audit shape whether you keep it. One you run yourself. The other decides your certification. They are easy to confuse because both use the word “audit,” both check conformity against a standard, and both produce findings. But they answer different questions, involve different people, and carry very different consequences.

Understanding the distinction matters because registrars increasingly treat a weak internal audit program as evidence that a quality management system is not actually being managed. A strong internal audit function, by contrast, is one of the most reliable predictors of a smooth certification audit. Below we explain what each audit type is, what a registrar auditor expects to see from your internal audit program, why thin internal audits are one of the most common nonconformities we encounter, and how to decide between training your own auditors and bringing in outside help.


What an internal audit actually is

An internal audit is a first-party audit. Your own organization plans it, staffs it, and acts on the results. Clause 9.2 of ISO 9001, and its equivalents across ISO 14001, ISO 45001, ISO 13485, IATF 16949, AS9100, and ISO/IEC 27001, requires you to audit your management system at planned intervals to confirm two things: that the system conforms to both the standard and your own documented requirements, and that it is effectively implemented and maintained.

The purpose is not to catch people out. It is to find problems before a customer, a regulator, or a registrar does. A good internal audit tests whether your procedures reflect how work is really done, whether records exist where they should, and whether corrective actions from last time actually closed the gap. Internal auditors are typically your own employees, drawn from areas outside the process they are auditing so they can look at it with fresh eyes. In smaller organizations, or where impartiality is hard to guarantee, the internal audit is often contracted out to a third party who performs it on your behalf, which is still considered an internal audit because you own the program and the findings.

What a certification audit is

A certification audit, also called a registration or external audit, is a third-party audit performed by an accredited registrar such as an independent certification body. The registrar is not on your payroll and has no stake in the outcome beyond an honest assessment. That independence is exactly what gives an ISO certificate its market value.

Certification typically runs in stages. A Stage 1 readiness review checks whether your documented system and your internal audit and management review records are far enough along to proceed. A Stage 2 audit is the full on-site assessment of whether the system is implemented and effective. After certification, the registrar returns for surveillance audits, usually annually, and a full recertification audit every three years. Findings from a certification audit are formal. A major nonconformity can stall or suspend your certificate until it is corrected and verified; enough minors signal a system that is drifting.

The two audits are meant to reinforce each other. Your internal audit is the dress rehearsal you control. The certification audit is opening night, judged by someone who does not answer to you.


What registrar auditors expect from your internal audit program

When a registrar arrives, one of the first things the lead auditor examines is your internal audit program, because it tells them how seriously you take self-governance. Registrars are looking for specific evidence, and they know what a rubber-stamp program looks like.

They expect a documented audit program that covers the full scope of your management system over a defined cycle, not just the easy or convenient processes. They expect auditor competence and impartiality, meaning the people doing the auditing are trained and are not auditing their own work. They expect real findings. An internal audit history that reports zero nonconformities year after year is a red flag, not a badge of honor, because no functioning system is perfect and a program that never finds anything is not looking hard enough.

Above all, they expect to see the loop closed. Findings should trace to root-cause analysis, corrective actions, and verified effectiveness, with management review picking up the trends. If your internal audit surfaces the same issue three cycles running, the registrar will ask why your corrective action process is not working. A thorough internal audit program, backed by a clear-eyed gap analysis before certification, is the single best way to make sure the registrar finds nothing you did not already know about.

Why weak internal audits are a top source of nonconformities

Across implementations, clause 9.2 is one of the most frequently cited areas in certification findings, and the reasons are consistent.

The most common failure is treating the internal audit as a checklist exercise. Auditors walk the floor, tick boxes, and confirm that documents exist without testing whether the process actually works or whether the documentation matches reality. A second failure is scope gaps, where high-risk or complex processes get skipped because they are harder to audit than the straightforward ones. A third is auditor independence problems, where someone audits a process they own or manage and, understandably, does not report against themselves.

The most damaging pattern, though, is the open loop. An internal audit that raises findings but never drives them to closure, or closes them on paper without verifying the fix held, tells a registrar that your corrective action system is not functioning. When the same nonconformity reappears at the certification audit that your own internal audit “caught” months earlier, it escalates from a process problem to a systemic one. Weak internal audits do not just miss issues; they actively erode the registrar’s confidence in your entire quality management system.


Your two options: build the capability or outsource it

Once you accept that internal audits carry real weight, the practical question is how to run them well. There are two sound paths, and many organizations use a blend of both.

Train your own internal auditors

Building in-house audit capability is a strong long-term investment. Your own auditors understand your products, processes, and people, and they can audit continuously rather than once a year. The requirement is competence: internal auditors need to understand the relevant standard, know how to plan and conduct an audit, write clear and defensible findings, and evaluate root cause and effectiveness rather than symptoms. That competence comes from structured ISO 9001 internal auditor training, reinforced by mentoring on live audits. A trained internal audit team turns clause 9.2 from a compliance chore into a genuine management tool, and it is usually the more economical option once you audit more than a couple of times a year. Broader ISO training across the team raises the baseline further, so audits meet an informed workforce rather than a confused one.

Outsource the internal audit

The alternative is to have an independent firm conduct your internal audits for you. Outsourcing solves the impartiality problem outright, brings experienced auditors who have seen dozens of systems and know exactly what registrars look for, and frees your staff to run the business. It is often the right choice for smaller teams, for organizations facing their first certification, or where internal resources are stretched thin. QRC’s ISO audit services deliver registrar-grade internal audits with clear findings and practical corrective action guidance, and our consultants increasingly use AI-assisted tooling to accelerate document review and evidence-gathering while keeping a qualified human accountable for every finding. A common and effective pattern is to outsource the first cycle or two, then use those audits to train and hand off to an in-house team.

Neither path is wrong. What is wrong is running internal audits as a formality and hoping the registrar does not notice, because they will.


Internal audits and certification audits are not competing checkboxes; they are two halves of the same discipline, and clients on our full-service program consistently pass their first registrar audit because the internal work was done properly first.

To strengthen your internal audit program or arrange independent audits before your next registrar visit, contact QRC or call (800) 244-5409.