Most internal audit programs are built on a calendar. Twelve months, a list of clauses or departments, divided evenly across the year. Every area gets audited once. Coverage is complete, the schedule is defensible, and the program reliably produces a small number of low-grade findings about document control.
Then the external audit arrives and raises something significant that the internal program walked past four times.
That is not a competence problem with the internal auditor. It is a design problem with the program. A schedule that allocates equal time to unequal risk will find whatever happens to be in front of it, and nothing else.
Risk-based scheduling is a requirement, not a refinement
This is worth stating plainly because it is often treated as good practice rather than obligation. ISO 19011:2018 requires an audit program to be established on the basis of the objectives of the program and the risks and opportunities relevant to it. Food safety management system requirements likewise require the internal audit program to take into account the importance of the processes concerned, changes affecting the organisation, and the results of previous audits.
Equal coverage of unequal processes does not satisfy that. If your schedule gives the same two hours to finished goods storage as it gives to the thermal process that is your only lethality step, the program is not risk-based regardless of what the procedure says.
Building the weighting
The mechanics are straightforward. Score each auditable area against a small set of factors, then set frequency from the total. Factors worth weighting:
- Hazard significance — does the area contain a CCP or a significant operational prerequisite?
- Nonconformity history — findings raised here in the last 24 months, internal and external
- Rate of change — new products, new equipment, process modifications, new customers with new requirements
- Staff turnover and training status — a well-designed control operated by people who started last month is a different risk
- Complaint and rejection data — customer complaints attributable to this area
- Complexity — number of handovers, manual steps, and judgement calls involved
A high-scoring area might be audited quarterly and in depth. A low-scoring one might be covered annually, briefly. The schedule stops being a grid and starts being an argument about where the risk is — which is the point.
Audit the interfaces, not just the departments
Departmental audit boundaries tend to mirror the org chart, and failures do not. The recurring weak points in most operations are handovers: production to warehouse, warehouse to dispatch, QA to production, day shift to night shift, supplier to goods-in.
At a handover, each side assumes the other holds the control. Neither does. A departmental audit of either side will find nothing, because within each department the process is being followed.
Two practical additions fix this. Vertical audits trace a single batch end to end — raw material receipt through to dispatch and traceability — crossing every boundary as the product does. Interface audits take a handover as the subject in its own right and audit both sides of it together.
Audit when the risk is, not when it is convenient
Internal audits cluster on day shift, mid-week, during normal production. That is when the site is at its most representative of the procedure and least representative of its worst case.
Deliberately schedule some audit activity into the conditions where practice is most likely to diverge: night shift, weekend production, a changeover, the end of a long run, a day when the line is behind and the pressure is on. This is not about catching people out. It is about auditing the system under the load it is actually designed to withstand.
Measure the program itself
Here is the single most useful metric for an internal audit program, and very few sites track it:
What proportion of significant findings were raised internally before an external party found them?
If your external auditor or your customer is consistently finding things your internal program did not, the internal program is not working, regardless of how complete its coverage looks. That ratio — internal detection versus external detection — is a direct measure of program effectiveness and belongs in management review.
A second useful measure: finding severity distribution. A program producing only minor documentation findings year after year is either auditing a genuinely excellent system or auditing too shallowly. The nonconformance data will tell you which.
Practical takeaways
- Write the risk rationale down. The schedule should be accompanied by the scoring that produced it, so the logic is auditable and can be revisited.
- Re-score at least annually, and immediately after any significant change — new equipment, new product, a recall, a major customer finding.
- Add one vertical audit per year minimum. It crosses every interface and is usually the highest-yield audit on the schedule.
- Put one audit on a night or weekend shift. If practice diverges anywhere, it diverges there.
- Track internal versus external detection ratio and report it at management review.
- Check auditor independence. An auditor cannot audit their own work — in small teams this is the constraint that quietly breaks the program, and the fix is usually cross-training a second auditor rather than accepting the conflict.
An internal audit program that never finds anything significant is not evidence of a healthy system. It is evidence of an audit program that is not looking hard enough.