Internal audits
Plan an internal audit, work a clause-by-clause checklist generated from the framework, record findings, and export an auditor-ready report, the ISO 27001 / 9001 Clause 9.2 requirement.
| Audit | Scope | Auditor | Findings | Status |
|---|---|---|---|---|
| Access management | ISMS | J. Okafor | 2 minor | Complete |
| Change management | ISMS | External | 1 major | Complete |
| Supplier controls | QMS | A. Rivera | In progress | Fieldwork |
| Physical security | ISMS | IT lead | Not started | Planned |
Every ISO 27001 and ISO 9001 program has to audit itself before the certification body shows up. That’s Clause 9.2. Keel makes the internal audit a guided workflow instead of a spreadsheet: pick a framework, and Keel builds the checklist from that framework’s own clauses; work through them recording a result and a note for each; and turn any nonconformity into a tracked corrective action in a click. Then export the whole thing as an auditor-ready report.
The internal audit is a from-scratch project every time
Someone rebuilds a checklist in a spreadsheet, emails it around, and pastes findings into a doc that doesn’t connect to anything. When the external auditor asks to see your last internal audit, and its follow-up, you’re reassembling it from memory and inboxes.
What internal audits does
A checklist generated from the framework
Pick any framework you’ve enabled and Keel builds the audit checklist from that framework’s actual clauses and controls, grouped by section, so you’re auditing against the real requirements, not a hand-made list.
Record findings as you go
For each clause, capture a result (conforming, nonconformity, observation, or opportunity for improvement) with a note, in real time. A running tally shows how much you’ve reviewed and what you found.
Findings become corrective action
Promote any nonconformity finding straight into the CAPA register (pre-filled with the clause and note, and linked back to the audit), so a finding never dies in a report.
Plan and track the audit
Give the audit a scope, an auditor, and a planned date, and move it from planned → in progress → completed, so your audit programme is visible and on cadence.
Auditor-ready report
Export a branded internal audit report (PDF) with the scope, conclusion, and every finding grouped by section, the artifact your certification auditor asks to see.
Why it matters
- Audit against the framework’s real clauses, not a hand-built checklist
- Turn nonconformity findings into tracked corrective action in one click
- Keep an internal audit programme on cadence with planned dates and status
- Hand your external auditor a branded internal audit report on demand
Get audit-ready, and prove it
Internal audits is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.
Start freeFrequently asked questions
What is an internal audit under Clause 9.2?
ISO 27001 and ISO 9001 require you to audit your own management system at planned intervals to check it conforms and is effectively implemented. Keel gives you the checklist, finding capture, and report to do exactly that.
Where does the checklist come from?
From the framework itself. Choose a framework you’ve enabled and Keel derives the checklist from its clauses and controls, grouped by section, so it stays accurate to the standard.
What happens to a nonconformity I find?
You can promote it into the CAPA (corrective action) register in one click. It’s created pre-filled from the finding and linked back to the audit, so the follow-up is tracked to closure with an effectiveness check.
Can I hand the result to my external auditor?
Yes. Export a branded internal audit report (PDF) with scope, conclusion, and all findings. It’s the record a certification auditor expects to see for Clause 9.2.
Related features: Nonconformities & CAPA · Controls & crosswalk · Statement of Applicability
Works with: ISO/IEC 27001 · ISO 9001