06 / INTERNAL AUDIT & ASSURANCEAUDIT & ASSURANCE

Find out whether the system works. Not just whether the documentation exists.

Independent internal audits for technology, deeptech and other organisations that need an experienced external view of their management system.

We assess conformity with applicable requirements, but also whether processes, controls, responsibilities and risk management actually work in practice.

An internal audit should tell you more than whether you comply.

A management system can be compliant on paper and still create very little value.

Processes may exist without clear ownership. Risks may be recorded without influencing decisions. Corrective actions may close without solving the underlying problem. Management reviews may happen without giving leadership useful visibility.

Our audits look beyond documentation to understand whether the management system is implemented, effective and supporting the way the organisation needs to operate.

Compliance. Effectiveness. Risk. Improvement.


INTERNAL AUDITS WE PROVIDE

ISO 9001 Quality Management

Process effectiveness, customer and product requirements, operational controls, performance, risk, corrective action and continual improvement.

ISO/IEC 27001 Information Security

ISMS implementation, information security risks, controls, governance, responsibilities and evidence of effective operation.

ISO 14001 Environmental Management

Environmental aspects and obligations, operational controls, objectives, performance and continual improvement.

ISO 45001 Occupational Health & Safety

OH&S risks, operational controls, worker participation, responsibilities, incident management and system effectiveness.

AQAP 2110 Defence Quality Assurance

Internal audits against AQAP 2110 requirements and their integration with the organisation's ISO 9001 quality management system, including contractual quality requirements, quality planning, risk, configuration management, supplier controls and product assurance.

Integrated Management Systems

Combined audits across multiple management-system requirements to evaluate the organisation as one integrated system rather than several parallel compliance systems.


What we assess

Requirements & conformity
Applicable standard, regulatory, contractual and internal requirements.

Process effectiveness
Whether processes achieve their intended outcomes and support business objectives.

Risk & controls
Whether significant risks are understood, controlled, monitored and escalated appropriately.

Ownership & governance
Whether responsibilities, authorities and decision-making are clear.

Implementation & evidence
Whether documented arrangements reflect what actually happens in practice.

Improvement & management visibility
Whether issues, performance and trends create meaningful management action and continual improvement.

Need an independent view of your management system?

Whether you're preparing for an external audit, reviewing an integrated management system or want to understand whether your processes and controls actually work, let's start with the scope and objective of the audit.

We audit the system as it operates, not as a collection of clauses.

We assess conformity with applicable requirements, but go beyond clause-by-clause auditing to understand whether processes, controls, responsibilities and risk management actually work in practice.


Internal audit vs certification

Internal audits evaluate whether your management system conforms to defined requirements and is effectively implemented. They help the organisation identify gaps and improvement opportunities before external certification or surveillance audits.

Quality Agency provides independent internal audit and assurance services. Certification decisions are made by accredited certification bodies.

When this service makes sense

01 . You need an independent internal audit before certification or surveillance.

02. You don't have sufficient internal competence or capacity to conduct the audit objectively.

03. You operate an integrated management system across ISO and/or AQAP requirements.

04. Your existing audits have become checklist exercises and provide little management insight.

05. The organisation has changed significantly and you want to understand whether the management system has kept pace.

06. You want an experienced external view of whether the system is actually effective, not simply documented.

What you receive

Audit plan and scope
Clear objectives, applicable criteria, functions and processes to be assessed.

Independent audit
Interviews, process review, evidence sampling and evaluation of implementation.

Audit report
Clear findings supported by evidence, including nonconformities and relevant observations.

Management-level perspective
Identification of systemic themes, dependencies and areas where management attention may be required.

Practical improvement priorities
Where appropriate, recommendations focused on effectiveness rather than additional administration.

I would be careful with “recommendations” because independence matters. You can identify improvement opportunities without designing the corrective action during the audit itself.