How to Make Internal Audits More Risk-Based, Objective, and Useful for Continual Improvement
By Shannon Major, STP ComplianceEHS and Phil Molé, MPH, VelocityEHS
An internal audit program should be more than a calendar of audits or a requirement to satisfy before an external assessment. At its best, it is a planned and systematic way to evaluate whether an organization’s management systems are effectively implemented, maintained, and capable of achieving their intended outcomes.
In the context of ISO 14001:2016 – Environmental Management Systems and ISO 45001:2018 – Occupational Health and Safety Management Systems, the audit program provides the structure for planning, conducting, reporting, and following up on internal environment, health and safety (EHS) audits.
For EHS practitioners, the real value of internal audit is the insight it provides. Audits should give stakeholders confidence that processes are working as intended, risks and opportunities are being appropriately managed, legal and other requirements are being considered, and the management system continues to support the organization’s strategic and operational objectives. They should also reveal where controls are weak, where resources are needed, and where performance can be improved.
Ultimately, an effective internal audit program should be treated as a management tool for continuous improvement. It should help the organization understand not only whether its EHS management systems conform to requirements, but whether those systems are practical, effective, value-adding, and contributing to sustained EHS performance. The ISO 19011:2026 – Guidelines for Auditing Management Systems is a commonly referenced standard to guide an internal audit program.
Even mature audit programs can drift into habits that reduce their effectiveness. Checklists become familiar, schedules repeat year after year, findings focus on paperwork, and corrective actions are closed before anyone confirms whether risk has been reduced.
The following pitfalls are common in EHS auditing. More importantly, each one can be avoided with a deliberate, risk-based, and performance-focused approach.
Pitfall #1: Lack of Risk-Based Planning for Audits
A common weakness in internal audit programs is treating the audit schedule as a calendar exercise rather than a risk-based assurance tool. When every location, process, product, shift, or audit requirement receives the same level of attention year after year, the audit program can become predictable and low value.
EHS practitioners know that risk is not evenly distributed across an organization. Audit frequency, scope, criteria, and objectives should reflect the significance of environmental conditions, environmental aspects, occupational health and safety hazards, risks & opportunities, legal obligations, incident history, previous findings, operational performance, contractor activity, changes that impact the organization, and stakeholder concerns. Audit program managers should review these inputs when initially setting up the program, but also during regular reviews to ensure it reflects risk within the organization.
Newer guidance within ISO 14001:2026 also reinforces the importance of setting clear objectives for each audit within the program. The emphasis should be on strengthening the rationale and structure of the internal audit program, beginning with the question: “Why are we performing each particular audit?” This question can help organizations refine the audit program by identifying which audits will provide the greatest value in assessing EHS effectiveness. Clearly defined audit objectives can also enhance the value of audit findings by linking them back to the question the audit was intended to answer. In addition, they provide auditors with a common focus, supporting greater consistency in the audit process.
How to avoid it: Use risk management, management of change, performance data, legal obligations, previous findings, and stakeholder concerns to determine what gets audited, how often, and in how much depth. Set clear audit objectives that answer the “why are we performing each particular audit”. Use internal audit templates that are aligned with ISO 14001 and 45001 Standards to reduce the chance that important management system elements get missed.
Pitfall #2: Stagnant Internal Audit Programs
Even a well-designed audit program can lose relevance if it is not adjusted as the organization changes. Changes to equipment, processes, chemicals, contractors, acquisitions, organizational restructures, staffing, technology, supply chain shifts, climate-related risks, regulatory and standards requirements can make last year’s audit plan obsolete.
All of this explains why organizations should connect their internal audit program to their management of change (MOC) processes. MOC is a central part of EHS management, and organizations tend not to use formal MOC procedures as often as they should, often imposing a subjective “significance” criterion that may not reflect actual risk levels of planned changes. For example, an organization may only use MOC when planning a major facility redesign, and not when planning to adopt new uniforms, which may introduce hazards from material flammability or “caught by” risks to manual machinists, or an indoor beautification project, which may introduce airborne contaminant hazards from associated coatings and paints.
Rather than waiting for the next annual planning cycle, EHS teams should review the audit program when internal or external changes occur. Using EHS software to simplify MOC can help remove psychological and administrative barriers to using it as part of your management system and internal audit program. A practical safeguard is to build a quarterly or semi-annual audit program review into the EHS governance calendar. Ask whether the current program still reflects operational reality, emerging risks, legal changes, and recent performance trends. If it does not, revise it. An audit program should be a living management tool, not a static calendar.
It’s important to note that ISO 14001:2026 introduced Clause 6.3 (Planning of changes), which establishes the planning of changes as an explicit, auditable requirement within the environmental management system (EMS) and aligns with the ISO 45011:2018 Clause 8.1.3 Management of Change clause.
How to avoid it: Review the audit program during governance meetings and after significant operational, regulatory, organizational, or risk changes. Ensure MOC processes are transparent and easy to use across the organization to facilitate the ability for all functions and departments, including EHS and auditing, to use it as often as needed, and evaluate the ways that modern operational risk software can provide the support needed.
Pitfall #3: Lack of Auditor Independence, Objectivity, and Competence
Internal audits lose credibility when auditors are not sufficiently independent, objective, or competent for the activities being reviewed.
In smaller organizations, complete independence can be difficult, but to avoid conflicts of interest, auditors should not audit their own work or areas where they have direct responsibility. Where internal resources are limited, second-party audits or qualified third-party support can help strengthen impartiality and provide a fresh perspective.
Competence matters just as much as objectivity. EHS auditors need more than audit criteria familiarity; they need enough knowledge of the organization’s operations, hazards, environmental aspects, legal obligations, controls, and industry context to recognize when evidence is meaningful. They also need core auditing skills, including interviewing, sampling, tracing evidence, and writing clear findings.
As audit methods become more digital, auditors may also need to understand how EHS software, data integrity, remote audit tools, and technology-enabled evidence affect audit reliability.
A practical way to avoid this pitfall is to define auditor competence criteria, match auditors to audit risk and complexity, and periodically evaluate audit performance.
How to avoid it: Define auditor competence requirements, avoid assigning auditors to their own areas of responsibility, and match audit teams to the complexity and risk of the audit scope. Evaluate the ways EHS software can support better audit performance and reliability.
Pitfall #4: Focus Is on Conformance Rather than Performance
Another common pitfall is auditing only whether requirements exist and records are present that meet the specified audit criteria (i.e. conformance), without testing whether the controls are working (i.e. performance).
Conformance is important, but EHS audits should also examine performance and effectiveness. Are critical controls understood, implemented, and verified? Are procedures practical for the work being done? Are workers and supervisors able to explain how risks are controlled in real conditions? Are inspection, incident, training, maintenance, and corrective action records telling a consistent story? How well is the organization managing corrective actions, including what percentage of actions remain open, especially high-priority actions with larger associated risks?
Strong audits use multiple forms of evidence: document review, interviews, and direct observation. Relying on documents alone can make a weak system look strong. Relying on interviews alone can make a strong system look inconsistent. Observing work as performed helps auditors test whether the management system is alive in day-to-day operations.
For EHS practitioners, this is where internal audits can provide real value: not in simply confirming that a process exists, but determining whether it is preventing harm, supporting compliance, and driving continual improvement.
How to avoid it: Balance document review with interviews and field observation, so the audit tests how controls work in practice, not just whether procedures and records exist.
Pitfall #5: Weak Findings and Ineffective Corrective Actions
Findings that are vague, overly subjective, or focused only on symptoms rarely lead to meaningful improvement. For example, a finding that “records were incomplete” may be technically accurate, but it does provide enough detailed information to help management to fix the system.
A stronger finding explains the requirement, the objective evidence, the nature of the gap, and the potential consequence. It also distinguishes between an isolated error and a systemic weakness. Corrective actions should then address root cause, including the systemic reason why an incident occurred or the condition exists, not simply the immediate surface-level cause.
Consider the example of a spill kit observed to be missing supplies, such as sorbent pads. A documented finding that the supplies are missing with a corrective action to replace those supplies may correct the immediate issue, but it doesn’t address why the supplies were missing or why previous workplace inspections failed to identify the gap. To make sure the issue doesn’t reoccur, a deeper dive is required. Perhaps training to employees performing the spill kit inspections was insufficient, so those employees weren’t fully aware of all the spill kit components they should be checking on. Or perhaps the employee who once performed those inspections left the company or changed roles, and a continuity plan was not in place for ensuring that someone else could carry on that task.
Repeat findings deserve particular attention because they often signal that previous corrective actions were too narrow or were closed without confirming effectiveness. External auditors, particularly those from Registrar companies, take a special interest in repeat findings, because they’re evidence that the organization has serious gaps in its management system, which may support a major conformance finding.
EHS teams can close the loop on internal audit findings by reviewing findings for clarity before issuing reports, requiring root cause analysis where appropriate, and looking across sites or departments for similar conditions.
The effectiveness of this process also depends on ensuring that findings and corrective actions are captured within the organization’s formal management system. This can be a challenge because many organizations have issues capturing, prioritizing and tracking corrective actions from different EHS management tasks, including internal audits. When findings and corrective actions remain isolated in an audit report, spreadsheet, or other document outside the formal tracking process, they can be difficult to assign, monitor, trend, and verify for effectiveness. Good findings should not get lost between the audit report and the action-tracking process.
The use of external auditors, a necessity if pursuing or maintaining an ISO certification, tends to widen these gaps. If external auditors are used, give them appropriate access to your organization’s findings and corrective action tracking process, or ask them to provide findings in a format that can be uploaded easily into your system.
How to avoid it: Write findings that link the requirement, objective evidence, gap, and risk consequence, then require corrective actions that address root causes. Make sure you have easy, effective and sustainable ways to capture, prioritize and track corrective actions, including those from external auditors. Look into the ways that modern EHS software can improve your corrective actions management.
Pitfall #6: Premature Closure of Corrective Actions
Closing corrective actions administratively is one of the fastest ways to weaken confidence in an audit program. An action may be assigned, documented, and marked complete, but that does not necessarily mean the risk has been reduced or recurrence has been prevented.
Effective closure should include verification that the action was implemented as intended, and where practical, demonstrate it worked. This may require follow-up sampling, observation, interviews, or review of trend data after enough time has passed. The question is not, “Was the task completed?” Rather, the more important question is, “Did the action change the condition that caused the finding?” When corrective actions are verified properly, internal audit becomes more than a compliance requirement. It becomes a feedback loop that helps the organization learn where controls are weak, where resources are needed, and whether EHS performance is improving.
How to avoid it: Verify both implementation and effectiveness before closing actions, especially for significant, repeat, or systemic findings.
Turning Internal Audits into a Continual Improvement Tool
Internal audits are often described as a requirement because Clause 9.2 of ISO 14001 and 45001 states that organizations must effectively implement and maintain an internal audit program. Still, EHS practitioners know that the benefits of internal audits go beyond conformance.
When audit programs are planned around risk, have competent and objective auditors carrying them out with a focus on effectiveness, and then connect audit findings to meaningful corrective action, they become one of the most useful tools for learning and improvement. Don’t measure success by having a tidy audit schedule or a long list of findings. The goal is to generate evidence-based insight that helps your organization prevent harm, maintain compliance, strengthen controls, and improve EHS performance over time. And remember, both ISO 14001 and 45001 emphasize the importance of continual improvement as embodied by the Plan-Do-Check-Act (PDCA) cycle.
How do you make sure you have a strong internal audit program that avoids common pitfalls? Start by getting input from your internal stakeholders and by taking an honest look at where you are today, paying attention to gaps and pain points. Assess how well you’re managing your internal audits and following through on corrective actions and identify how well you’ve connected your internal audit program with MOC. Then, look for ways to streamline your audit process. Internal audit protocols aligned with ISO 14001 and 45001 are essential, and leveraging EHS software can smooth over many of the common friction points.
With the right support, you’ll be able to leverage internal audits to strengthen your management system and adopt a more risk-focused, proactive safety management approach that keeps your people safe while building resilience.
Check out our VelocityEHS Audit software can help you optimize your audit process with smart scheduling tools, configurable checklists and workflows, and real-time reporting. Uncover gaps faster, act with confidence, and simplify compliance by using audits as part of a connected EHS software platform.
We’re also integrated with STP Compliance AuditHub, a go-to platform for managing, streamlining, and optimizing your audit processes, helping you to stay on top of regulatory changes, minimize risks, and ensure your business is always audit-ready.
Set up a meeting so you can the software in action for yourself.
