An internal audit checklist is the working document an auditor takes into a process: what to look at, what evidence proves it, and space to record what was actually found. Its purpose is not to confirm that everything is fine. It is to find, cheaply and early, the places where what people do and what the documents say have drifted apart.
The checklists that fail are the ones written as yes-or-no questions. "Is the procedure followed?" gets a yes every time. "Show me the last three times this was done, and let me compare them to the procedure" gets the truth, and takes about the same amount of time.
What each checklist line needs
- The requirement being tested, in plain language — from your own procedure, a contract, or a standard.
- The question the auditor asks, phrased to require evidence rather than assent.
- The evidence expected: a record, a log, a sample of outputs, an observation of the work happening.
- The sample size and how it is chosen. "Three recent examples, picked by the auditor" beats "an example", which will be the best one.
- Space for what was actually seen, including the identifiers of the records examined — a finding without a reference cannot be verified later.
- A conclusion per line: conforms, minor finding, major finding, or observation.
- Room for the auditee's comment, which often explains a finding and occasionally dissolves it.
- The follow-up: owner, agreed action and date, recorded at the time rather than reconstructed afterwards.
Audit the process, not the person. The wording of every question decides which one you get. "Why did you not follow the procedure?" produces defensiveness and a poor finding; "walk me through how this is done, and let us look at the last three" produces the real process, which is what you came for — and often reveals that the procedure is wrong rather than the person.
Running the audit
- Pick a scope narrow enough to be done properly: one process, one shift, one site. Auditing everything shallowly finds nothing.
- Read the procedure and the last audit's findings first, so you are testing against what is written and checking whether previous actions actually happened.
- Give notice. Surprise audits look rigorous and mostly measure who is in the building.
- Start by asking someone to walk you through the work as it is really done, then compare that to the document.
- Sample records yourself rather than accepting the ones offered, and note the identifiers of everything you look at.
- Raise findings against the requirement, not against a preference. If no requirement is breached, it is an observation.
- Agree actions and owners before leaving the room, with dates.
- Write the report within days while detail is fresh, and check the previous actions in the next audit — an audit programme whose findings are never followed up teaches everyone that it is theatre.
Findings that are worth raising
A good finding states the requirement, the evidence, and the gap — nothing more. "Procedure 4.2 requires calibration every six months; instrument 118 was last calibrated fourteen months ago per the calibration log" is a finding. "Calibration seems disorganised" is an opinion, and it will be argued with rather than fixed. Grade honestly: a systemic breakdown is a major finding even when it is uncomfortable, and a single lapse is a minor one even when it is annoying.
Ettex Forms is a practical way to run this: build the checklist as a form with one question per requirement, a short-answer field for what was seen, a dropdown for the conclusion, and a file-upload question for photographs or scanned records. Every completed audit lands in one searchable, timestamped inbox with a live summary and export to CSV or XLS, which means "show me every finding from the last four audits" is a filter rather than a hunt through folders. The procedures being audited live in Ettex Docs with comments and version history, the findings register with owners and due dates fits Ettex Records, and the audit schedule sits in Ettex Calendar.
Said plainly: Ettex has no audit module. There is no audit programme scheduler, no corrective-action workflow with automatic escalation, no linkage between a finding and a document, no reminder when an action falls due, and nothing here is certified against any standard. Forms gives you a structured, timestamped record of what was found; the programme is yours to run.
Why checklists produce nothing
- Yes-or-no questions, which are answered without anyone looking at anything.
- Copied wholesale from a standard, so the questions test clauses rather than your actual process.
- Samples chosen by the auditee, which measures their best work.
- No record identifiers, so a finding cannot be verified or reproduced.
- Findings graded by how awkward the conversation would be rather than by severity.
- Actions agreed and never checked, which is the fastest way to make the whole programme ceremonial.
- Reports written weeks later from memory, by which time the detail that made the finding real is gone.
Frequently asked
What is an internal audit checklist?
A structured set of questions used to test whether a process matches its documented requirements, each with the evidence expected, space for what was found, and a conclusion.
How do you write good audit questions?
Phrase them to require evidence rather than agreement — ask to be walked through the work and to see recent examples, instead of asking whether the procedure is followed.
How large should the sample be?
Small but chosen by the auditor — often three to five recent records per requirement. Who chooses matters more than how many.
What is the difference between a major and a minor finding?
A major finding is a systemic breakdown or a requirement not implemented at all; a minor one is an isolated lapse in an otherwise working process. Grade on severity, not on how the conversation will feel.
Should internal audits be announced?
Usually yes. Notice gets you the right people and records available, and surprise mainly measures attendance. Unannounced checks suit specific risks, not the general programme.
What happens after the audit?
Agreed actions with owners and dates, a report written within days, and verification at the next audit that the actions actually happened. Findings that are never followed up make the programme ceremonial.
An internal audit checklist is only as good as its questions and its evidence. Ask to be shown, sample yourself, record identifiers, grade honestly — and check last time's actions before you write this time's report.