
The Quality Hub · 2026-07-01 · 16 min
Key moments - from our scoring
Substance score
27 / 100
Five dimensions, 20 points each
ISO 9001 internal audits are mandatory compliance tools, but they're most valuable when organizations shift from viewing them as checkbox exercises to embracing them as continuous improvement engines. This episode featuring experts from Core Business Solutions - including Norm Verbeck, Kate Baer, Bruce Newman, and Tracy Behr - explores how to maximize audit effectiveness by addressing organizational resistance, integrating audits across multiple ISO standards, and securing management commitment. The conversation reveals that successful internal audits depend on establishing impartiality (whether through internal auditors uninvolved in daily operations or external providers like Core Business Solutions), using audits to identify process blind spots, documenting corrective and preventative actions systematically, and reframing audits from punitive exercises into collaborative improvement opportunities. Tracy Behr emphasizes that top leadership participation transforms internal audits from administrative tasks into strategic assets that drive operational excellence, cost savings, and employee engagement. Quality managers, operations leaders, and compliance officers seeking to strengthen their ISO systems will benefit from understanding how to overcome departmental silos, leverage the PDCA cycle through corrective actions, and build organizational cultures where audits feel like valued feedback rather than unwanted scrutiny.
Yes, internal audits are a mandatory requirement of the ISO standard whether you're claiming compliance or certified. They must occur on a periodic basis, typically once per year, and must be conducted by an objective party with no conflict of interest in the processes being audited.
External auditors provide an independent perspective free from daily process involvement, ensure no conflict of interest, offer separate eyes that can identify improvements internal teams have become blind to, and are particularly valuable for smaller companies without dedicated internal audit resources.
Corrective and preventative actions drive continuous improvement by implementing the PDCA cycle in practice - planning actions, doing them, checking through verification records, and acting on results. When documented and monitored, they become the backbone of your continuous improvement process rather than one-time fixes.
Organizations should reframe audits as improvement tools rather than performance evaluations or blame exercises, maintain consistent messaging from management about the improvement intent, explain why audits are being conducted, involve employees in identifying suggestions, and demonstrate through leadership behavior that audits focus on fixing processes, not punishing people.
When top leadership participates in audits, hears employee feedback directly, and visibly prioritizes improvements, it signals organizational importance and drives a continuous improvement mindset throughout all levels. Without management engagement, audits risk becoming administrative checkbox exercises that jeopardize compliance and prevent quality objectives from being achieved.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode covers legitimate ISO internal audit concepts but at a purely introductory level - outsourcing audits, PDCA, management buy-in, and integrated standards are all well-trodden territory. There are no surprising or non-obvious claims for anyone with even basic QMS exposure.
internal audits have a special place in my heart. Um, they're really a great tool to identify improvements because you get to look at your processes through a different lens
we're not non conforming people, we're non conforming processes
Nearly every point - PDCA cycle, management tone-setting, audits as improvement tools rather than punishment, no conflict of interest - is standard ISO consulting boilerplate recycled without fresh framing or counterintuitive angles. The IRS joke is the only memorable moment and it's a cliché.
The IRS gave it a really bad name
They kind of gently nudge or, you know, force, maybe they might force, uh, the PDCA cycle
All four guests are employees of the same ISO consulting firm (Core Business Solutions) being promoted throughout the episode, making this closer to a branded content piece than an independent expert panel. No guests represent operators who have implemented these systems at scale inside complex organizations.
Coming from the internal audit team at core, uh, internal audits have a special place in my heart
if you'd like to learn more about Core Business Solutions, now proudly part of the LRQA family and how we can support you with ISO certification
The episode is almost entirely abstract - no named client companies, no data on audit frequency distributions, no dollar figures for cost savings, no concrete case studies. The only number offered is 'typically once a year,' which is itself just restating the standard requirement.
typically once a Year
There's a little bit of, sometimes it's a little bit of rivalry maybe between departments
The host asks broad, leading questions and consistently validates guest answers with agreement rather than probing. There is no pushback, no follow-up that surfaces new information, and several 'questions' are rhetorical affirmations that let guests off the hook entirely.
But once you get over those humps, they find it to be pretty good.
Yeah, it really is.
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of The Quality Hub, Chatting with ISO Experts, host Xavier Francis explores how ISO internal audits can become one of the most valuable tools in a quality management system. Featuring insights from Norm Verbeck, Kate Behr, Bruce Newman, and Tracey Bear, the discussion covers how internal audits help organizations strengthen processes, identify opportunities for improvement, support integrated management systems, and prepare for external audits. Rather than focusing on blame or paperwork, this episode highlights how audits can become a strategic tool for continuous improvement, employee engagement, and long-term business success.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Foreign.
Speaker B: Hello everyone and thanks for listening to the Quality Hub chatting with ISO experts. I'm your host, Xavier Francis. Today we're looking back at some of our best conversations about ISO internal audits. Internal audits can sometimes feel like a checklist exercise, but when it's done well, they become one of the most valuable tools in your quality management system. In this episode, we'll hear from several core experts on how ISO internal audits support compliance, drive continuous improvement, strengthen processes and help organizations prepare for long term success. Let's start with Norm Verbeck. Norm, whether a company is certified or simply trying to stay compliant, how important is the internal audit process?
Speaker C: So internal auditing, that's, it's a requirement of the standard whether you're compliant, if you're claiming compliance or if you're certified. So uh, it really should not differ between compliant companies or certified companies.
Speaker B: Okay.
Speaker C: That's your internal employees auditing your system. Or if you're a smaller company, you can actually outsource the internal audit to like a company like Core Business Solutions. So we do internal audits for companies all the time.
Speaker B: Yeah, and there's benefits to doing that where you literally have an outside source that can give you some pointers too. You know, you might not see that's one of the benefits of that, that you might not have when you have an internal auditor.
Speaker C: That's correct. So yeah, it's an outside body, it's a separate set of eyes, it's kind of, you know, not involved with the day to day activities within a process. So you don't have to worry about that. Also, part of the requirement of the standard, uh, even if you're compliant is that there's no basically conflict of interest. So you can't be auditing things that you have responsibilities or ownership of. So where again a company like us, if, if you're a smaller company and you just don't really have the time, we can do that for you. And there's no conflict of interest at all. It's also a requirement to ensure impartiality. But if you truly meet the requirements of the standard. So internal audits, even when you're compliant, it's not a one and done thing. So once you audit yourself and you say you're compliant this standard, basically, uh, it's a periodic basis, is when they occur and typically they're once a year. If you were going for official certification, you have to be audited every year anyways. And the internal audit would take place between audits with the registrar. So typically once a Year.
Speaker B: Let's turn to Kate Baer. How can internal audits become more than just a requirement and actually support continuous improvement?
Speaker A: Yeah, absolutely. Coming from the internal audit team at core, uh, internal audits have a special place in my heart. Um, they're really a great tool to identify improvements because you get to look at your processes through a different lens. We spend a lot of time working our day to day doing our job. Everything's going according to plan. But in an audit situation, you're really looking at things from a bird's eye view. Since processes should be audited by an objective party, either an outsourced internal audit, such as what we have, uh, at core, or an employee who's not directly involved in the process. You get that viewpoint of those processes and how it functions from that point of view. They may be able to identify areas for improvement that people within the process or management or leaders leadership become blind to over time.
Speaker B: Yeah, that, uh, makes a lot of sense where people, you know, they just get used to it. Again, it kind of goes back to that I know what the problem is or I know what I'm doing.
Speaker D: Exactly.
Speaker A: Well, exactly.
Speaker B: Having that, having that objective view from somebody else in the company or outside the company really, really can help.
Speaker A: Exactly.
Speaker B: Well, these are really good points. Now, often after root cause analysis or internal audience, businesses may need to do some corrective or preventative actions. How can those help strengthen an organization's ability, sustain improvements over time?
Speaker A: Yeah. So the corrective and preventative actions themselves really are the continuous improvements in practice or being implemented.
Speaker B: Okay.
Speaker A: And when you document them and you monitor them and review them, they really can become the backbone of your continuous improvement process.
Speaker B: Okay.
Speaker A: They kind of gently nudge or, you know, force, maybe they might force, uh, the PDCA cycle. When you plan your actions for your corrective or preventative actions, you implement or do them, um, and you check them through verification of corrective action records. Through verification, you can decide if the issue could use more improvement or if it's time to move on to the next thing. So that's really that act part of the pdca. So that's really the cycle in real life happening and resulting hopefully in a solved problem and an improved process.
Speaker B: Okay. Question you can run into though is, you know, you got these tools. Using them, employees can be resistant to things, especially if it's a check or we're changing a process or we're looking at out how you're doing it. How can you overcome some of that resistance as well?
Speaker A: Yeah, I think one of the biggest Challenges that you face is that they kind of get a bad rap. Right. You know, the internal audits. No one likes to hear they're being audited.
Speaker D: Oh yeah, that a word is just, just exactly.
Speaker A: The IRS gave it a really bad name. Um, well, that's the thing.
Speaker B: Well, they really did. And that was well earned.
Speaker E: They really did.
Speaker A: It wasn't 9001. They really didn't talk about continuous improvement in their processes. But, uh, um, they really can kind of get a bad rap. Audits can feel like unwanted criticism, um, root cause investigation and corrective actions can start to feel like a punishment. And they really aren't intended to be any of those things. They're tools. So it's really important for management or the team spearheading improvement initiatives to be consistent in their messaging and their approach with these tools. Again, it all kind of all kind of interconnecting. Right. Being objective, not finger pointing or placing blame where you don't need to place blame.
Speaker B: Right.
Speaker A: Have discussions surrounding that true intent. Explain what they are, explain why you're doing them. The intent being to improve. And not only to improve for customers, but to improve the day to day for everyone in the organization by making things more simple or more efficient. You know, an improvement can come not just from an issue or an audit finding, but from an employee who thinks that here's a different way to do my day to day task that I think would be a little bit better, uh, or makes a little bit more sense to me. And taking those into account, those kinds of suggestions.
Speaker B: Yeah, getting them involved.
Speaker A: Exactly.
Speaker B: It's probably a good way to get buy in and realize, hey, we're not looking at you. And this isn't a performance review. This isn't whether you're going to get a raise or not. This isn't whether you're on thin ice most. But uh, I mean occasionally that might be the case. But that's not what this purpose is for. It's to how can we improve.
Speaker A: Exactly, exactly. So it's really kind of getting rid of those preconceived notions, having people within the organization feeling like they're in trouble. Um, and again, like you said, maybe they are. But again, the intention is really for the improvement to happen, um, and to improve for everybody. Right.
Speaker B: Let's speak to Bruce Newman. Bruce, when a company integrates ISO9001 with other standards, how would they think about auditing processes?
Speaker E: Instead of just departments, they siloed certain aspects of their business. Like they've got someone in charge of safety, someone in charge of Environment, someone in charge of quality, and they don't really, uh, understand the idea that you can combine, for example, the review of all three processes at one time, or you can do, uh, an internal audit of all three of those at the same time. So there's a little bit of, sometimes it's a little bit of rivalry maybe between departments.
Speaker C: Okay.
Speaker E: Comes into play sometimes, you know, it depends on the culture of the business. But once you get over the departmental aspects of it and convince folks that we're not talking about departments here, we're talking about processes, once you convince them and school them on the idea that we're talking about processes versus departments or silos, usually they come to an understanding on the advantages of integrating the systems.
Speaker B: So it sounds like even if integration is a good idea, just let's say a company has started with ISO9001 and they're already nice and I'm certified and they add another standard or two. It's sort of like adjusting the culture. People are thinking about things being connected where before they may not have been. Sort of like when they started 9001. They're not looking at the whole business as a whole. They're looking at certain things and certain things this person does, certain things this person does, or they're not taking a holistic approach and looking at it all as one.
Speaker E: Yeah. Like you can run into problems if you've got a quality manager and a safety manager who's going to run the integrated system. Ah.
Speaker B: Ah, yeah, yeah.
Speaker E: So you can run into issues there. Again, like I said, it can, it can become a power struggle thing.
Speaker B: Right.
Speaker E: That you have to overcome.
Speaker B: But once you get over those humps, they find it to be pretty good.
Speaker E: Yeah, Usually. Usually awesome. There's a number of clauses that duplicate across the many of the standards. Like I said, corrective action, non conformances, internal audit, management review. There's a lot of documentation and record control. All these things are the same across all the standards. So you're, you're looking at a single type of management system for all.
Speaker B: Okay.
Speaker E: Which means the documentation is basically the same.
Speaker B: Okay.
Speaker E: You can do single audits for all and you can incorporate management reviews as well. So obviously it not only reduces the management documentation, but also the records can be combined. I guess the only complexity would be that in some instances, like for example, if you combine the audits, it does add a little bit of complexity to the integrated audit of the integrated system.
Speaker B: Okay. And finally, let's talk to Tracy Behr. Tracy, what role does management play in making internal audits more valuable and less like a paperwork exercise.
Speaker D: I tend to find if management isn't involved itself in the internal audit, they tend not to be overly ingrained in regards to the QMS system wide. So if they're not involved in the audit and they're not hearing those discussions that we're having and they're not hearing the feedback from their employees live, they can miss some of the crucial things that we discuss that don't necessarily get documented in a report. The leadership involvement. It sets a tone for the rest of the organization and it makes sure that the organization, if they're ingrained in the audit and they're aware of the audit and they're helping prep for the audit with their team members, they're making sure that that that feeling of how important an audit is is conveyed to the rest of the organization and they take it serious. It becomes ingrained in the organization and instead of it just being a haphazard, poorly prioritized audit activity that lack any focus, top leadership drive this and go okay, so what can we change? What can we do? Where can we improve? And that philosophy flows down through the team and instead of it just becoming a routine administrative type task, the mindset changes through to that continual improvement. Let's work on, you know, where are those corrective actions and it completely changes an organization's attitudes if it's coming driven from top management.
Speaker B: Yeah. If they're kind of laissez ver about it, why would anybody else consider its importance?
Speaker D: Absolutely. And that in itself could help jeopardize the maintenance of compliance and it stops the improving of process and it can help prevent, you know, the quality objectives being achieved. If top management aren't aware and in somewhat participating in making sure an internal audit is a valuable, you add for the organization.
Speaker B: Wonderful and wonderful take on that one. Instead of looking at internal audits as something to just check off a list, you know, the checkbox. How should a company look at it for continuous improvement?
Speaker D: Absolutely. When you've got a team or um, a group of individuals who approach an audit with the right mindset, they see that it provides for them an objective and a very structured way to show gaps, inefficiencies and potential risks within existing processes. That insight, um, helps them proactively address any issues before they cause any issues or non conformities and escalate and cause issues within an organization. Mhm. That gives a good enhancement across all the departments. Instead of fearing an audit, teams can view them as helpful feedback um, that will highlight strengths and areas for improvement. So they can step back themselves after an audit and go, okay, so we talked about this. What areas can I see after the audit for the next 12 months or six months till the next audit can I improve on to make sure that that whole philosophy of ingraining that quality perspective and internal improvement is across the organization. And if we get those employees to engage at all levels during the process, the organizations foster a sense of ownership and accountability and they encourage collaboration and open communication with everybody. So it's very inclusive. It's not this person works this process, it becomes a whole ingrained into the organization structure where they journ together towards that operational excellence where everybody feels empowered and that they have a vote to help, you know, contribute to quality the compliance objectives. And that whole continual improvement philosophy, which is a great feeling for a person to feel like that they are part of something.
Speaker C: Mhm.
Speaker E: Yeah.
Speaker B: Having those people on the ground, the boots on the ground really involved seeing your interest as a manager saying hey, this is important and I need your help. What better way could somebody feel valued and then have buy in and then continually want to work and make it more of a continuous improvement thing?
Speaker D: Absolutely. And then by doing that, it shifts the perception of internal audits from just being a compliance burden to a strategic asset. So companies then embed that continuous improvement into their culture which drives growth and resilience over time. And that's a huge benefit to an organization. And the cost savings just in making sure that it's, everyone is being ingrained and making sure that they're doing the right things and they're doing their own health checks, you know, prior to an internal audit. And they come into that audit, you know, prepared and, and ready to be proud and say, look at all the things that we've done in the last 12 months. It's a really nice feeling.
Speaker B: Yeah, it really is. Now when an internal audit finds a non conformance, how should companies think about that finding?
Speaker D: One of the big things I like to explain to um, the customers is that even if we do do that internal audit, we do find a non conformance. You know, we're not non conforming people, we're non conforming processes. So it's all part of that continual improvement of hey, look, we've looked at that process, it's not quite there yet. Uh, let's, let's fix that and work out ways to fix it. So for me, that internal audit gets people more engaged. Be open, be honest. We want all the skeletons out of the closet. We want to make sure that an internal audit sets you up for success via external auto we want to thank
Speaker B: all our guests today and really appreciate their insight when it comes to ISO internal audits. And we want to give a big thank you to everyone who's tuned into today's episode. We hope you found it helpful and walked away with something valuable. If you'd like to learn more about Core Business Solutions, now proudly part of the LRQA family and how we can support you with ISO certification, cybersecurity, customized training, we'd love to hear from you. Just email us at infohecoresolution.com or visit us online at www.thecoresolution.com. and if you haven't already, make sure to follow the Quality Hub podcast on your favorite podcast platform or on YouTube so you don't miss our next episode dropping in a week. Thanks again for listening and have an awesome.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.