AS9100 Internal Audit Process: A Step-by-Step Guide for 2026

AS9100 Clause 9.2 requires more than an ISO 9001 internal audit program — customer and regulatory requirements have to be built into your audit criteria, and results have to reach management. This guide breaks down the six-part audit workflow, what a real internal audit checklist should cover, how findings feed into management review and AS9101 reporting, and the objectivity gap that trips up small aerospace quality teams.

AS9100 internal audit process checklist showing audit planning, conducting audits, reporting findings, and corrective action in an aerospace manufacturing facility

How aerospace suppliers plan, conduct, and close out a Clause 9.2-compliant internal audit program

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your Internal Audit Program Is What Helps Keep Your AS9100 Certification Credible

An AS9100 certificate doesn’t prove your QMS is working. Your AS9100 internal audit process helps prove that it is.

Most operations managers treat internal audits as a compliance formality — something to schedule before the registrar shows up, not something that actually finds problems. That approach works right up until a surveillance audit surfaces a nonconformance your own internal audit should have caught six months earlier. At that point, the registrar isn’t just questioning the finding. They’re questioning whether your internal audit program is real.

If you’re already certified and running audits on autopilot, or preparing for your first AS9100 certification and building this process from scratch, the standard is specific about what “real” looks like. Clause 9.2 lays out exactly what your internal audit program has to prove, and AS9100 Rev D adds requirements ISO 9001 doesn’t have.

From the Floor: I’ve sat in gap assessment meetings where the documented internal audit schedule looked airtight on paper — every process, every quarter, neatly assigned. Then you pull the actual audit records and half of them are checklist walk-throughs with no objective evidence attached, no findings, no closure dates. An auditor doesn’t need long to spot the difference between an internal audit program that’s running and one that’s just being logged.

👉 Before you build or rebuild your internal audit program, run the AS9100 Rev D Gap Assessment Checklist — a 74-item, clause-by-clause tool that shows you exactly where your current audit coverage has gaps before an external auditor finds them for you.


In This Guide

  • What Clause 9.2 actually requires, and where AS9100 goes beyond ISO 9001
  • The six-step internal audit process defined in Clause 9.2.2
  • How internal audit findings feed into management review and AS9101 reporting
  • A ready-to-use internal audit checklist structure
  • Common mistakes that turn a real audit program into a paperwork exercise
  • Where to buy the standard and where to get trained on running compliant audits


👉 Start Here (Top Resources)

  • AS9100D — ANSI Webstore — the current edition of the standard, including the exact Clause 9.2 language your audit program has to satisfy. Use coupon code CC2026 for 5% off through December 31, 2026.
  • ISO 19011:2018 — ANSI Webstore — the audit guidelines standard referenced directly by AS9100 internal audit resources; worth owning if you’re training internal auditors.
  • AS9100 Training — BSI Group — for teams that need to formally qualify internal auditors on AS9100-specific requirements, not just general ISO 9001 audit technique.

What Clause 9.2 Actually Requires

Clause 9.2.1 requires you to conduct internal audits at planned intervals to determine whether your quality management system conforms to three things: your own organization’s requirements, the AS9100 standard itself, and the QMS is effectively implemented and maintained. That’s the ISO 9001 baseline.

AS9100 Rev D builds directly on that clause text. Under the standard’s Annex L structure, the aerospace-specific language is written straight into Clause 9.2.1 itself: your organization’s requirements for internal audit purposes must explicitly include customer requirements and applicable statutory and regulatory requirements — not just your internal procedures. That’s not guidance layered on top of ISO 9001; it’s part of the clause language you’re audited against. Audit results also have to be reported to relevant management, not just filed.

Most common finding: Internal audit programs that check ISO 9001 conformance thoroughly but never verify against a specific customer’s flow-down requirements or purchase order quality clauses. That’s a Clause 9.2 gap I commonly see when aerospace suppliers transition from ISO 9001 to AS9100.

ISO 9001 Baseline (Clause 9.2)Aerospace-Specific Clause 9.2 Language (Annex L Addition)
Conformance to the organization’s own QMS requirementsMust explicitly include customer, statutory, and regulatory requirements
Conformance to the standardAS9100 Rev D requirements, including its aerospace-specific additions
Effective implementation and maintenanceResults must be reported to relevant management, feeding directly into management review

If you are preparing for your first AS9100 certification → build your audit criteria around customer and regulatory requirements from day one, not as an afterthought once ISO 9001 conformance is handled.

👉 Need to see the exact Clause 9.2 language for yourself before you build your audit program around it? Get the current AS9100D edition from the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.


The AS9100 Internal Audit Process: A Six-Part Workflow Built From Clause 9.2.2

AS9100 audit program showing risk-based planning, audit frequency, previous findings, and an annual internal audit schedule in an aerospace manufacturing facility
A risk-based AS9100 audit program considers process importance, changes, previous findings, and risk when establishing the internal audit schedule.

Clause 9.2.2 lays out the requirements your audit program has to satisfy — the audit program itself, planning and conduct, auditor objectivity, reporting, corrective action, and retained documented information. Read together, that maps cleanly onto six practical steps, and an auditor will ask about all six.

1. Audit Program

Establish, implement, and maintain an audit program that identifies frequency, methods, responsibilities, planning requirements, and reporting. This has to account for the importance of the processes involved, changes affecting your organization, and the results of previous audits — not a static calendar you set once and never revisit.

2. Audit Criteria and Scope

Define what standard, procedure, or requirement each audit is measured against, and how far that audit reaches — which processes, which shifts, which locations if you run more than one facility.

3. Auditor Selection

Select auditors and conduct audits in a way that ensures objectivity and impartiality. Nobody audits their own work. On a small quality team this is often the hardest requirement to satisfy on paper — it usually means cross-training auditors across departments so a floor supervisor never audits the process they run.

4. Reporting Results

Audit results go to relevant management — not just the quality manager’s file. If a finding touches production scheduling, engineering, or purchasing, that function’s management needs visibility into it.

5. Corrective Action

Take appropriate correction and corrective action without undue delay when nonconformities are found. “Without undue delay” is intentionally vague in the standard, but in practice, your corrective action process should establish a documented target closure date appropriate to the severity of the finding — an open-ended promise to “look into it” won’t hold up as objective evidence of an effective process.

6. Retained Documentation

Keep documented information as evidence of the audit program’s implementation and the audit results. These are among the first records an external auditor is likely to examine: not your procedure, but your actual audit records — schedules, checklists, findings, objective evidence, and closure dates.

👉 If your audit records are more calendar than evidence, that’s the gap that surfaces during a surveillance audit — not a certification audit. Run the gap assessment checklist against your current program before your next registrar visit, not after.

AS9100 internal auditor reviewing work instructions, actual work, inspection records, and objective evidence on an aerospace manufacturing floor
An effective AS9100 internal audit follows the evidence from documented procedures to actual work, inspection records, and process effectiveness.

What Should an AS9100 Internal Audit Checklist Include?

A checklist built only around ISO 9001 clause conformance misses the aerospace-specific scope Clause 9.2.1 actually requires. Use this as the framework for what each internal audit needs to cover:

Audit AreaWhat the Auditor Should Verify
Process requirementsApplicable AS9100 clauses and internal procedure requirements
Customer requirementsPurchase order and contract flow-down requirements
Regulatory requirementsApplicable statutory and regulatory obligations
Objective evidenceActual records and direct observations, not verbal confirmation
Process effectivenessWhether the process is achieving its intended result, not just running
FindingsNonconformities clearly supported by objective evidence
Corrective actionRoot cause analysis, corrective action, and verification of effectiveness
Follow-upClosure evidence and confirmation the fix actually worked

If your operation also carries program-specific deliverables under AS9145 (APQP and PPAP), extend your audit criteria to those documents too — see AS9145 Explained for what’s typically in scope. And if any of your special processes are already covered under NADCAP, coordinate your internal audit scope so you’re not duplicating external oversight — NADCAP vs AS9100 breaks down where the two programs overlap and where they don’t.

AS9100 corrective action workflow showing audit finding, containment, root cause analysis, corrective action, effectiveness verification, and closure
An AS9100 corrective action is not complete until the organization verifies that the action worked and documents the results.

How Internal Audit Results Feed Into Management Review

Internal audit findings aren’t the end of the process — Clause 9.3 requires them as an input into management review. Corrective actions from internal audits, along with trending data like recurring nonconformities, similar issues across multiple processes, and top process concerns, should show up as agenda items top management actually discusses. That requirement comes from your QMS’s management review clause, not from any external audit form.

Separately, when your registrar conducts your certification or surveillance audit, results get documented on AS9101 — the standardized audit report form referenced by SAE International and logged in the IAQG OASIS database. AS9101 doesn’t dictate what your internal management review has to look like. But an external auditor completing that form will ask to see your management review minutes, and if internal audit trends never make it into those minutes, that gap is easy to spot — not because AS9101 requires a specific format, but because the disconnect itself signals the management review process isn’t functioning as intended.

If you are already ISO 9001 certified and adding AS9100 → your internal audit process likely doesn’t need to change structurally. What changes is audit criteria — you now have to audit against customer and regulatory requirements your ISO 9001 program never had to touch, and management review needs a direct line from audit findings to those aerospace-specific requirements.


Objection: “We Don’t Have Staff to Audit Objectively”

This is the most common pushback on small aerospace shops — a 15-person quality team can’t realistically avoid people auditing processes adjacent to their own work.

It’s a real constraint, but it’s manageable without adding headcount. Cross-train two or three people across departments so each can audit outside their own process. A machinist trained as an internal auditor can objectively audit the receiving inspection process; the receiving inspector can objectively audit machining documentation. Registrars don’t require a dedicated audit department — they require evidence that whoever conducted the audit had no stake in the outcome. Document that logic in your audit program procedure, and it holds up.


Quick Internal Audit Readiness Checklist

✅ Audit program covers all applicable processes at a frequency justified by risk and past findings

✅ Audit criteria explicitly reference customer purchase order requirements, not just internal procedures

✅ Auditors are demonstrably independent of the process they’re auditing

✅ Findings include objective evidence — not just a pass/fail checkbox

✅ Corrective actions have documented target closure dates

✅ Audit results appear as a distinct agenda item in management review minutes

⚠️ If any of these are missing, that’s the gap a registrar finds before you do


Frequently Asked Questions

What does Clause 9.2 of AS9100 actually require?

Clause 9.2 requires organizations to run internal audits at planned intervals to confirm the QMS conforms to the organization’s own requirements — which under AS9100 must include customer, statutory, and regulatory requirements — conforms to the AS9100 standard itself, and is effectively implemented. Results must be reported to relevant management.

How often do AS9100 internal audits need to happen?

The standard doesn’t set a fixed interval. Frequency has to be justified by the importance of the process, the results of previous audits, and any changes affecting the organization. Higher-risk processes — special processes, product safety-critical operations — typically warrant more frequent audits than lower-risk administrative processes.

Can one person run the entire internal audit program on a small team?

Generally, yes, as long as objectivity is maintained. The requirement is independence from the process being audited, not a minimum team size. On very small teams this can require creative scheduling or occasionally bringing in an outside auditor for processes where no internal person can honestly claim independence.

Do internal audit findings have to be reported to the registrar?

No. Internal audit results are reported to your own relevant management, not to the certification body. The registrar reviews your internal audit records and evidence of corrective action during surveillance and recertification audits — they don’t need real-time reporting.

What’s the difference between an internal audit and the AS9101 certification audit?

Your internal audit program is something you run yourselves, on your own schedule, against your own and the standard’s requirements. AS9101 is the standardized form your registrar uses to document the results of your external certification and surveillance audits, which then get logged in the IAQG OASIS database. A strong internal audit program is largely what prepares you to pass the AS9101-documented external audit cleanly.

Can internal audits be conducted remotely?

The standard doesn’t prohibit it, and many quality teams do conduct document reviews and some process audits remotely. Physical, in-person audits are still strongly preferred for shop floor processes where objective evidence — traveler stamps, calibration tags, first article records — needs to be directly observed rather than described.

What happens if our internal audit program has gaps when the registrar shows up?

It depends on severity and pattern, and classification is ultimately the auditor’s call based on the evidence in front of them. An isolated missed audit interval on a low-risk process may be treated differently from a persistent systemic failure, depending on the evidence and the auditor’s assessment. A pattern of audits with no objective evidence, no findings ever recorded, or no connection to management review calls into question whether the QMS’s self-monitoring is functioning at all — which is the kind of gap that tends to draw closer scrutiny.

Is a documented procedure enough, or do we need to prove the audits actually happened?

A procedure alone isn’t enough. Registrars expect to see the records: audit schedules, completed checklists with objective evidence, documented findings, and closure evidence for corrective actions. The procedure describes what you’re supposed to do — the records prove you did it.


📥 Free Resources

  • AS9100 Rev D Gap Assessment Checklist — 74-item, clause-by-clause checklist for aerospace suppliers assessing their QMS, including internal audit coverage, before certification.
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.

Not Sure What to Do Next?

🔹 Still researching what AS9100 internal audits require? Start with the What Is AS9100? pillar guide, then read AS9100 vs ISO 9001 to see exactly which requirements are new to you if you’re already ISO 9001 certified.

🔹 Ready to build or fix your internal audit program? Run the AS9100 Rev D Gap Assessment Checklist against your current audit records, then check the AS9100 Implementation Timeline to see where audit program maturity fits into your certification schedule.

🔹 Need to buy the standard or get auditors trained? Get the current edition from the ANSI Webstore with code CC2026 for 5% off, and see AS9100 Certification Bodies: Ranked & Reviewed for AS9100 auditor training through BSI Group.


A weak internal audit program is one of the most common reasons a QMS that looks compliant on paper fails to hold up in front of a registrar. Build the six-step process the standard actually asks for, put real objective evidence behind every audit, and your surveillance audits stop being a surprise. That’s what The Standards Navigator’s AS9100 coverage is built around — the requirements as they’re actually enforced, not just as they’re written.


Before You Go

Most aerospace suppliers don’t lose points on AS9100 audits because they misunderstand Clause 9.2 — they lose points because their internal audit program looks good on paper and falls apart under objective evidence review.

Shops that treat internal audits as a real management tool catch their own nonconformances before a registrar does. Shops that treat them as a scheduling formality find out the hard way, usually during a surveillance audit, that “completed” and “effective” aren’t the same thing.

The Standards Navigator covers the AS9100 requirements aerospace suppliers actually get audited against — not just the clause text, but how registrars interpret it in practice.

👉 Get updates on AS9100 implementation and internal audit best practices

👉 Be first to access new aerospace gap assessment tools and checklists

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

Unknown's avatar

Author: Eric Franco

I’m the creator of The Standards Navigator, a resource built to simplify ISO, OSHA, ANSI, and other industry-specific standards for businesses of all sizes. With a background in operations, quality practices, and compliance-driven environments, I focus on translating complex standards into clear, practical guidance. Through detailed guides, comparisons, implementation strategies, and audit-focused content, I help organizations confidently move toward certification and stronger operational performance.

Leave a Reply

Discover more from The Standards Navigator

Subscribe now to keep reading and get access to the full archive.

Continue reading