Internal audit & self-inspection

The hardest audit is the one at home.

Self-inspection is a regulatory obligation almost everyone meets on paper. Whether it works depends on something a procedure cannot supply: the willingness to write down what you found.

An organizational boundary containing its own functions, with an independent observer node inside holding sightlines to each of them and a reporting line rising out of the boundary.

Perspective

Internal audit fails quietly, and always in the same ways. The auditor reports to the person whose area is being audited. The sample is the one that was offered. The finding is downgraded because everybody knows the team is stretched. None of this looks like a failure until an inspector applies the same scope and reaches a different conclusion.

Independence principle

Independence is structural, not personal.

An auditor’s integrity is not the control. The control is that they do not report to the area under audit, do not depend on it for their objectives, and can escalate past it. Where the organization cannot supply that internally, it has to come from outside.

Capabilities

Specialist support, connected to the whole system.

Scope is tailored to the engagement; these are the core areas in which QA4Tech can contribute.

01

Programme design

Build a risk-based schedule that justifies frequency, depth, and coverage across processes, systems, sites, and the quality system itself.

02

Independent execution

Conduct audits and self-inspections as a genuinely external party, where internal independence cannot be demonstrated.

03

Technical depth

Reach the areas a generalist internal auditor usually cannot: validation, data integrity, audit trails, cloud, security, and AI-enabled processes.

04

Honest grading

Grade findings on risk and evidence, and resist the downgrade pressure that makes an internal programme worthless.

05

CAPA challenge

Test whether corrective actions address cause, and verify closure with evidence rather than a completed form.

06

Management review inputs

Turn audit output into the trends, decisions, and escalations senior management is expected to act on.

Programme coverage

What a self-inspection programme has to reach.

Most programmes audit processes thoroughly and everything else occasionally. The gaps below are where inspection findings concentrate, precisely because the internal cycle rarely gets to them.

01

GxP operational processes

The core activities, audited against the procedures as written and as actually performed — which are frequently two different things.

02

Computerized systems

Validation status, configuration and change control, access, and whether the system in use still matches the system that was validated.

03

Data integrity

Audit trails and their review, corrections, transfers, spreadsheets, and the end-user computing nobody has inventoried.

04

Delegated activity

Your oversight of suppliers and partners — not the supplier’s own controls, but whether you are genuinely watching them.

05

The quality system itself

Deviation, CAPA, change control, training, and document control audited as processes rather than assumed to be sound.

06

Previous findings

Whether last cycle’s corrective actions held, and whether the same root cause is reappearing under a different heading.

07

Inspection readiness

A rehearsal under realistic pressure: can the organization find, explain, and defend its evidence in the time available?

What makes it credible

The tests an internal programme has to pass.

An inspector will form a view on your self-inspection programme within minutes, and it will shape everything that follows. These are the things that view is based on.

  • Auditors are demonstrably independent of the areas they audit
  • The schedule is risk-based and justified, not an equal slice of every area annually
  • Findings are graded consistently, and critical findings actually appear
  • Audits are completed when planned, and slippage is visible rather than absorbed
  • Corrective actions are verified as effective, not closed on submission of a plan
  • Repeat findings are recognized as repeat findings and escalated as such
  • Management review receives trends and decisions, not an attendance record

Approach

Context first. Evidence throughout.

A clear sequence keeps the work rigorous while avoiding unnecessary process.

  1. 01

    Assess the current programme

    Establish what is covered, how findings are graded, where independence is compromised, and what an inspector would conclude.

  2. 02

    Rebuild the schedule

    Re-base coverage on risk, with a written rationale for frequency and depth that stands up without the author present.

  3. 03

    Audit honestly

    Execute with the same discipline applied to an external party, including the samples nobody offered.

  4. 04

    Close the loop

    Verify effectiveness, surface repeat causes, and feed trends into management review as decisions rather than information.

Deliverables

What the engagement produces.

A programme the organization runs itself, and audit records that hold up when someone external reads them.

  • A risk-based internal audit and self-inspection schedule with documented rationale
  • Audit procedure, criteria, grading definitions, and report templates
  • Executed audits with written reports and graded findings
  • CAPA review, effectiveness verification, and formal closure records
  • A repeat-finding and trend analysis across the current cycle
  • A management review pack: inputs, metrics, and the decisions required

Reference frameworks

Where the obligation comes from.

The self-inspection requirement is explicit in GxP and in the ISO management-system standards. The criteria are drawn from whichever apply to the activity in scope.

EU GMP Chapter 9
Self-inspection as a defined obligation: conducted, recorded, and followed by corrective action.
ICH Q10
Internal audit as a quality-system element feeding management review and continual improvement.
ICH E6(R3)
Quality management, risk-proportionate oversight, and the sponsor’s own processes in clinical research.
ISO 9001 clause 9.2
Internal audit programme requirements, auditor objectivity, and reporting to relevant management.
ISO 19011
Auditing discipline: competence, evidence, sampling, and reporting applied to internal audits as rigorously as external ones.

These are examples, not a complete list. The frameworks and criteria that apply to a particular engagement are identified and agreed as part of defining its scope.

Typical applications

Where this work can apply.

  • Building a self-inspection programme from scratch
  • Independent audits where internal objectivity cannot be demonstrated
  • Technical internal audits beyond a generalist auditor’s reach
  • Inspection readiness and mock inspections
  • Programmes producing findings that never seem to be critical
  • Remediation after an inspection observation on self-inspection

Start a conversation

Bring the right level of assurance to the next decision.

Begin with a focused discussion about context, risk, evidence, and the outcome you need.

Discuss an Internal Audit Programme