ISO 14001 internal audit process, environmental compliance audit checklist, and what changed under the 2026 revision
Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.
Your Internal Audit Is the Real Test — Not the Certification Visit
Most companies find out their EMS has a gap the hard way: during the certification audit, in front of the registrar, with a nonconformity on the record.
That’s backwards. The internal audit is where you’re supposed to find that gap. Environmental audits don’t fail companies. Skipped ones do. If your internal audit program is doing its job, very few surprises should remain by the time the certification audit rolls around.
Under ISO 14001:2026, that internal audit process just got more specific. Auditors now have to define audit objectives — not just scope and criteria. Management review has been restructured into three distinct pieces: inputs, process, and results. And Clause 10.1 is gone, folded into corrective action and continual improvement. If your internal audit program hasn’t been updated to reflect that, you’re auditing against a standard that no longer exists.
What Is an ISO 14001 Internal Audit?
An ISO 14001 internal audit is a systematic review of an organization’s environmental management system (EMS) to verify conformity with ISO 14001 requirements, applicable legal obligations, and internal procedures. The purpose is to identify gaps and drive corrective action before an external certification or surveillance audit — not after one flags them for you.
From the Floor: I’ve sat in enough surveillance audits to know the pattern — the finding the registrar flags is almost never a surprise to the people running the plant. Someone knew about it. It just never made it into a documented internal audit finding, so nothing forced a corrective action before the external auditor walked in. The internal audit isn’t paperwork. It’s the only thing standing between “we knew about that” and a major nonconformity on your certificate.
👉 Most EMS gaps get found six weeks too late. Run the Manufacturing Compliance Checklist against your current environmental controls before you schedule your next audit — not after.
In This Guide:
- What an ISO 14001 environmental audit actually covers
- Internal audits vs. certification audits — what’s different
- What changed for internal audits under ISO 14001:2026
- The audit process, step by step
- Common findings and how to catch them early
- Who should conduct your audit (and why it can’t be the EMS owner)
- Preparing for your next audit
Table of Contents
👉 Start Here (Top Resources)
- ISO 14001:2026 — ANSI Webstore — the current edition; audit criteria has to be checked against this text, not the 2015 version
- ISO 19011:2018 — Guidelines for Auditing Management Systems (ANSI Webstore) — the actual audit methodology standard; most internal auditors have never read it
- ISO 14001 Internal Auditor Training (BSI Group) — structured training for whoever owns your audit program
- ISO 14001 Training (ISOQAR) — second training option, useful if you’re also weighing certification bodies
What an ISO 14001 Environmental Audit Actually Covers
An environmental management system audit isn’t a plant walkthrough with a clipboard. It’s a documented, evidence-based comparison of what your EMS says you do against what’s actually happening on-site — the core of any legitimate EMS internal audit.

That means checking:
- Legal and other compliance obligations — do your environmental permits, discharge limits, and EPA reporting obligations match what’s actually being tracked?
- Aspects and impacts — is the register current, or is it the same list from your last certification cycle?
- Objectives and targets — are they being measured, or just listed?
- Operational controls — spill response, waste handling, emissions controls — are they followed as written, or as remembered?
- Nonconformity and corrective action — is there a closed loop, or do findings sit open for months?
If you’re integrating this with a quality or safety audit, the Integrated Management Systems guide walks through how ISO 9001, ISO 14001, and ISO 45001 share enough clause structure to run a combined audit efficiently — worth reading before you build a standalone EMS-only audit program from scratch.
Internal Audits vs. Certification Audits
| Category | Internal Audit | Certification (External) Audit |
|---|---|---|
| Who conducts it | Trained internal staff or a contracted third party | Accredited registrar auditor |
| Purpose | Find gaps before they become findings | Verify conformance for the certificate |
| Frequency | Planned intervals — typically annual, often more frequent for high-risk areas | Annually (surveillance) or every 3 years (recertification) |
| Consequence of a miss | Corrective action, no external record | Nonconformity on your certification record |
| Standard governing method | ISO 19011:2018 | ISO/IEC 17021-1 (registrar accreditation) |
If you are preparing for your first EMS certification → run at least one full internal audit cycle before you schedule the certification visit. A registrar auditor should never be the first person to see your gaps.
Before you select a registrar, confirm they’re actually accredited. ANAB accredits certification bodies operating in the U.S., and the IAF maintains the broader international framework accreditation bodies operate under — worth checking either before you commit to a certification audit date.
ISO 14001:2026 Internal Audit Requirements and Changes
Three changes matter most for how you run your audit program:
1. Audit objectives are now required, not just scope and criteria. Your audit plan has to state why you’re auditing a given area — risk exposure, a prior finding, a process change — not just what you’re covering and against what criteria.
2. Management review is restructured into three sub-clauses. Inputs, process, and results are now distinct. If your management review meeting minutes still run as one long list, they no longer map cleanly to the clause structure a registrar auditor will be checking against.
3. Clause 10.1 is gone. Its content is folded into 10.2 (nonconformity and corrective action) and 10.3 (continual improvement). That’s not a cosmetic change — it changes how your corrective action records need to be structured to trace back to a clause.
For the full breakdown of what changed at the standard level, see ISO 14001:2026 vs. 2015: What’s New at a Glance. If your documentation hasn’t been updated to match, start with ISO 14001 Documentation Requirements before your next internal audit — auditing against outdated document structure just produces findings you’ll have to redo.
If you are still certified to ISO 14001:2015 → you have until April 14, 2029 before that certificate stops being valid. That sounds like plenty of runway until you count backward through gap analysis, documentation updates, training, and at least one internal audit cycle before the certification audit itself.
👉 Not sure your internal audit program actually catches what a registrar will flag?
Get the Manufacturing Compliance Checklist and compare it against your current audit scope in under 45 minutes.
ISO 14001 Internal Audit Process: Step-by-Step Guide

- Define objectives, scope, and criteria. Under 2026, objectives are a separate, required element — don’t skip straight to scope.
- Assign an independent auditor. Someone who doesn’t own the process being audited. Small operations often rotate this across departments or bring in outside help.
- Review documentation first. Permits, legal obligations, aspects and impacts, training records, and prior corrective actions should all be reviewed before stepping onto the shop floor.
- Conduct the on-site audit. Interviews, physical observation, records sampling — not just one or the other.
- Document findings against clause references. Every finding should trace to a specific clause, not a general impression.
- Close the loop. Corrective actions get assigned, tracked, and verified — not just logged and forgotten.
- Feed results into management review. Under the restructured clause, audit results are now an explicit input, not an assumed one.
Most common finding: aspects and impacts registers that were current at the last certification cycle and haven’t been touched since. Auditors catch this fast — new equipment, new chemicals, or a process change with no corresponding register update is one of the most frequent nonconformities in EMS audits.
👉 Want to know what auditors miss most often before it costs you a nonconformity? Compare the Manufacturing Compliance Checklist against your current EMS before your next internal audit.
Common Findings in Environmental Audits

- Objectives without measurement. A target exists on paper but nobody’s tracking progress against it.
- Corrective actions that never closed. Opened after the last audit, never verified as effective.
- Legal register gaps. A permit renewed or a regulation changed, and the register wasn’t updated.
- Training records that don’t match current roles. Someone changed positions; their environmental training record didn’t follow them.
- Operational controls that exist in the procedure but not in practice. The spill kit is where the SOP says it should be — six months ago. It’s since been moved, borrowed, or depleted.
If you are already ISO 9001 certified → your nonconformity and corrective action process likely already exists in a form the EMS can reuse. Don’t build a parallel CAPA system — extend the one you have. What Happens If You Fail an ISO 9001 Audit? covers how registrars evaluate corrective action effectiveness, and the same logic applies almost directly to EMS findings.
Who Should Conduct Your Internal Audit
The auditor has to be independent of the area being audited — that’s non-negotiable under ISO 19011. In practice, that means one of three models:
- Cross-trained internal staff, rotated so nobody audits their own department
- A shared internal audit function, common in integrated ISO 9001/14001/45001 programs
- A contracted third-party auditor, useful for smaller operations without the headcount to rotate
At the Baker Hughes facility in Jacksonville, with roughly 500 employees across the site, we rotated internal auditors across departments every cycle specifically so no one ever audited their own area — a small operations team doesn’t always have that luxury, which is exactly why the third-party option exists.
If you are under customer pressure to certify quickly → don’t skip the independence requirement to save time. A registrar will flag a self-audited process immediately, and it becomes a finding of its own.
Objection: “We don’t have the resources for a full internal audit cycle.”
This is the most common reason internal audits get skipped or rushed — and it’s the wrong place to cut corners. A partial audit that misses aspects and impacts or corrective action tracking doesn’t save time. It just moves the gap to the certification visit, where it costs more — in registrar fees, in corrective action deadlines, and in the credibility hit of a nonconformity on record.
A properly scoped internal audit, run against a current checklist, typically takes less time than most operations managers assume. That’s especially true once objectives and criteria are clearly defined up front instead of improvised on-site.
Preparing for Your Next Audit — Quick Checklist
✅ Legal register updated within the last 12 months
✅ Aspects and impacts register reflects current operations — not last cycle’s ✅ All prior corrective actions closed and verified
✅ Objectives have measurable, tracked progress
✅ Audit objectives defined — not just scope and criteria
✅ Management review documentation split into inputs / process / results
✅ Auditor independence confirmed for every area covered
If you’re building or refreshing your audit documentation from the ground up, the ISO 14001 Certification Guide and ISO Implementation Timeline for Manufacturers both map out where an internal audit cycle fits into the broader certification timeline.
If you’re evaluating training or certification bodies to support your audit program, Best ISO Certification Bodies compares options side by side. And if you’re weighing whether to purchase ISO 9001, ISO 14001, and ISO 45001 together for an integrated audit program, buying the standards as a bundle saves meaningfully compared to purchasing each one separately — worth checking before you buy individually.
FAQ
How often does ISO 14001 require internal audits?
The standard requires audits at “planned intervals” — it doesn’t dictate a fixed frequency. Most certified organizations run internal audits annually at minimum, with higher-risk areas audited more frequently.
Can the same person who manages the EMS conduct the internal audit?
No. ISO 19011 requires auditor independence from the area being audited. The EMS owner can coordinate the audit program but shouldn’t audit their own processes.
What’s the difference between an internal audit and a management review?
The internal audit evaluates conformance and effectiveness at the process level. Management review is a higher-level evaluation by top management that now takes audit results as a required input under the restructured 2026 clause.
Do I need to redo my internal audit program for ISO 14001:2026?
Not from scratch, but your audit plan needs to explicitly define objectives, your management review documentation needs to reflect the three-part structure, and your corrective action records need to trace to Clause 10.2/10.3 instead of the now-removed 10.1.
What happens if my internal audit finds a major issue right before a certification audit?
Address it. A documented internal audit finding with an active corrective action in progress is normal EMS operation — registrars expect to see open corrective actions occasionally. What damages you is a finding that should have been caught internally and wasn’t.
Is ISO 19011 a certifiable standard?
No. ISO 19011 is a guidance standard for auditing management systems generally — it’s not something you get certified against, but it’s the reference most competent internal auditors are trained on.
Is an environmental compliance audit the same as an ISO 14001 internal audit?
Not quite. A general environmental compliance audit checks against regulatory requirements — permits, discharge limits, reporting obligations. An ISO 14001 internal audit checks against those plus your EMS’s own documented procedures, objectives, and conformance to the standard itself. Most organizations run them together, since the underlying evidence overlaps heavily.
Can I combine my ISO 14001 audit with my ISO 9001 or ISO 45001 audit?
Yes, and many organizations do, given the shared high-level structure across the three standards. See the Integrated Management Systems guide for how to structure it.
How long does an ISO 14001:2015 certificate stay valid after the 2026 edition published?
Until April 14, 2029. After that, ISO 14001:2015 certificates are no longer valid — organizations must transition to ISO 14001:2026.
📥 Free Resources
- ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
- Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
- Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts
Not Sure What to Do Next?
🔹 Still researching what an EMS audit actually requires? Read the ISO 14001 Certification Guide for the full certification path before you build an audit program around it.
🔹 Ready to strengthen your internal audit program? ISO 14001 Internal Auditor Training through BSI Group or the equivalent ISOQAR course will get your team auditing against the current clause structure.
🔹 Need the standard itself to audit against? ISO 14001:2026 — ANSI Webstore is the current edition — auditing against the 2015 text after April 2026 means checking your EMS against requirements that no longer apply.
Don’t Let the Next Audit Be the One That Catches You Off Guard
Environmental audits don’t fail companies. Skipped ones do. The gap that shows up in a surveillance audit was almost always visible internally months earlier — it just never made it into a documented finding with a corrective action attached. Build the audit cycle now, and the certification visit stops being an event you dread. That’s the standard The Standards Navigator holds every EMS article to — clear, practitioner-level guidance, not theory.
Most operations managers don’t lose sleep over the audit itself. They lose sleep over what they don’t know is broken until a registrar finds it. Organizations that run a disciplined internal audit cycle walk into certification visits with confidence. Organizations that treat the internal audit as a formality walk in exposed — and find out in front of the one person whose findings go on the record.
The Standards Navigator tracks every clause-level change to ISO 14001 as it happens, so your audit program is never built against an outdated standard.
👉 Get updates on ISO 14001 audit and certification changes
👉 Be first to access new EMS audit checklists and gap assessment tools
Subscribe below to stay ahead.
The Standards Navigator — Industrial Compliance. Clearly Explained.
