IATF 16949 Clause 9.2 Internal Audit: Complete Guide

IATF 16949 Clause 9.2 defines the requirements for internal auditing in the automotive industry. Internal audits help an organization verify whether its Quality Management System (QMS), manufacturing processes, and products conform to applicable requirements and are effectively implemented.

In the automotive industry, internal auditing is not limited to checking documents. The organization must establish a structured audit programme that covers the entire QMS, manufacturing processes, and products, with audit priorities based on risk, performance, and process criticality.

This article explains IATF 16949 Clause 9.2 Internal Audit requirements in easy-to-understand language, with practical examples, audit planning guidance, checklists, and implementation tips for automotive component manufacturers.

Table of Contents

  1. Introduction to IATF 16949 Clause 9.2
  2. Clause 9.2.1 and 9.2.2 – ISO 9001 Requirements
  3. Clause 9.2.2.1 – Internal Audit Programme
  4. Clause 9.2.2.2 – Quality Management System Audit
  5. Clause 9.2.2.3 – Manufacturing Process Audit
  6. Clause 9.2.2.4 – Product Audit
  7. Difference Between the Three Audit Types
  8. Practical Internal Audit Programme Example
  9. Internal Audit Checklist
  10. Common Audit Mistakes
  11. Frequently Asked Questions
  12. Conclusion

1. Introduction to IATF 16949 Clause 9.2 Internal Audit

IATF 16949 is a Quality Management System standard for the automotive industry. It includes additional automotive-specific requirements alongside ISO 9001 requirements.

Clause 9.2 addresses internal auditing.

The organization must establish an audit process that verifies the effectiveness of its management system and relevant manufacturing and product controls.

Why is internal audit important?

Consider an automotive component manufacturer producing machined shafts.

The company has:

  • An approved process flow (PFD)
  • A PFMEA.
  • A control plan.
  • Work instructions.
  • Inspection equipment.
  • Trained operators.

However, documents alone do not guarantee that the process is being followed correctly.

An internal audit can verify:

  1. Whether the operator is following the approved work instruction.
  2. Whether critical process parameters are controlled.
  3. Whether the control plan is implemented.
  4. Whether inspection records are maintained.
  5. Whether previous nonconformities have been effectively addressed.

Key point: Internal audit is a method of verifying actual implementation and effectiveness, not just the presence of documents.

2. Clause 9.2.1 and 9.2.2 – ISO 9001 Requirements

IATF 16949 Clause 9.2.1 and Clause 9.2.2 refer to the applicable ISO 9001:2015 internal audit requirements.

In simple terms, the organization must plan, establish, implement, and maintain an internal audit programme.

The audit programme should help determine whether the Quality Management System:

  • Conforms to applicable requirements.
  • Is effectively implemented and maintained.

The automotive-specific additions in Clause 9.2.2 expand the requirements to include QMS audits, manufacturing process audits, and product audits.

The organization should therefore consider both the ISO 9001 requirements and the additional IATF 16949 requirements when preparing its audit programme.

3. Clause 9.2.2.1 – Internal Audit Programme

What does the requirement mean?

The organization must have a documented internal audit process.

The process must include developing and implementing an internal audit programme that covers the entire Quality Management System.

The programme must include:

  1. Quality Management System audits.
  2. Manufacturing process audits.
  3. Product audits.

The programme must be prioritized based on:

  • Risk.
  • Internal performance trends.
  • External performance trends.
  • Criticality of the process.

The audit frequency must be reviewed and adjusted where appropriate based on process changes, internal and external nonconformities, and customer complaints.

The effectiveness of the audit programme must be reviewed as part of management review.

3.1 Documented Internal Audit Process

The organization should define how internal audits are planned, conducted, reported, and followed up.

A documented procedure may include:

  • Audit programme preparation.
  • Auditor competency requirements.
  • Audit planning.
  • Audit checklist preparation.
  • Audit execution.
  • Finding classification.
  • Corrective action follow-up.
  • Effectiveness verification.
  • Audit programme review.

The procedure should reflect the organization’s actual practices and applicable requirements.

3.2 Audit Programme Must Cover the Entire QMS

The audit programme must cover the entire QMS, including the three audit types specified in Clause 9.2.2.1.

For example, an automotive manufacturing company may have the following processes:

ProcessExample audit coverage
Quality planningQMS audit
PurchaseQMS / supplier-related audit
Incoming inspectionProcess audit
CNC machiningManufacturing process audit
AssemblyManufacturing process audit
Final inspectionProcess/product audit
MaintenanceQMS / process audit
TrainingQMS audit
Corrective actionQMS audit
Finished productProduct audit

The exact audit allocation should be established according to the organization’s processes, requirements, and risk.

3.3 Risk-Based Audit Prioritization

The audit programme must be prioritized based on risk, internal and external performance trends, and process criticality.

What is process risk?

Process risk refers to the possibility that a process may fail to achieve its intended results or produce nonconforming outputs.

Examples:

  • A critical machining dimension is frequently out of tolerance.
  • A welding process has repeated defects.
  • A new machine has been introduced.
  • A process has received repeated customer complaints.

What are internal performance trends?

Internal performance trends are performance patterns within the organization.

Examples:

  • Increased rejection rate.
  • Increased rework.
  • Recurring internal nonconformities.
  • Reduced process capability.
  • Frequent machine breakdowns.

What are external performance trends?

External performance trends may include information from outside the organization.

Examples:

  • Customer complaints.
  • Customer audit findings.
  • Customer rejection trends.
  • Warranty-related quality information, where available.
  • Supplier or external performance issues relevant to the process.

Example of risk-based prioritization

Suppose a company has three processes:

ProcessPerformanceAudit priority
CNC machiningRepeated dimensional rejectionIncreased priority
PackagingStable performanceBased on programme and risk
WeldingRecent customer complaintIncreased priority

The organization should use its defined evaluation method to prioritize audits. It should not automatically assume that every process must have the same audit frequency.

3.4 Software Development Capability Assessment

Where the organization is responsible for software development, the internal audit programme must include software development capability assessments.

This requirement is relevant to organizations with applicable software development responsibilities.

The organization should determine the assessment method, scope, and competency requirements based on the applicable requirements and its activities.

3.5 Review and Adjust Audit Frequency

The organization must review audit frequency and adjust it where appropriate.

The review should consider:

  • Process changes.
  • Internal nonconformities.
  • External nonconformities.
  • Customer complaints.

Practical example

A company changes the tooling and process parameters for a critical machining operation.

Following the change, the organization should review whether the existing audit schedule remains appropriate.

If quality problems occur after the change, the audit programme may need additional or earlier audit coverage.

The purpose is to ensure that audit frequency remains suitable for changing process conditions and performance.

3.6 Review of Audit Programme Effectiveness

The effectiveness of the internal audit programme must be reviewed as part of management review.

Management should consider whether the audit programme is achieving its intended purpose.

Possible inputs include:

  • Completion of planned audits.
  • Recurring audit findings.
  • Corrective action effectiveness.
  • Audit findings in critical processes.
  • Significant customer complaints.
  • Results of QMS, process, and product audits.

Important: Completing the audit schedule alone does not demonstrate that the programme is effective. The organization should evaluate the quality and usefulness of audit results and follow-up.

4. Clause 9.2.2.2 – Quality Management System Audit

What does the requirement mean?

The organization must audit all QMS processes over each three-year calendar period, according to an annual programme, using the process approach to verify compliance with IATF 16949.

The audits must also include sampling of customer-specific QMS requirements for effective implementation.

4.1 Three-Year Coverage Requirement

The organization must plan to audit all QMS processes over each three-year calendar period.

This means the audit programme should be structured so that all applicable QMS processes are covered within the required three-year period.

It does not mean that every QMS process must be audited only once in three years. The audit programme must still account for risk, performance, criticality, and other applicable requirements.

Example

A company has 12 identified QMS processes.

The organization should plan its annual audit programme so that all 12 processes are covered within the applicable three-year calendar period.

YearExample coverage
Year 1Quality planning, purchasing, production-related support
Year 2Training, maintenance, inspection, corrective action
Year 3Management review, customer-related processes, remaining QMS processes

This is an illustrative allocation only. The actual programme must cover the organization’s entire QMS and comply with applicable requirements.

4.2 Process Approach

The QMS audit must use the process approach.

A process approach means evaluating how a process works, including:

  • Inputs.
  • Activities.
  • Outputs.
  • Responsibilities.
  • Performance indicators.
  • Risks and controls.
  • Interactions with other processes.

Example: Purchasing Process Audit

Instead of checking only whether a purchasing procedure exists, the auditor should examine:

  1. How purchasing requirements are received.
  2. How suppliers are selected or approved.
  3. How purchase orders are prepared.
  4. How supplier performance is monitored.
  5. How nonconforming purchased material is handled.
  6. How the purchasing process achieves its intended results.

This helps the auditor evaluate the process in a meaningful way.

4.3 Customer-Specific Requirements (CSR)

The QMS audit must include sampling of customer-specific QMS requirements to verify effective implementation.

Customer-specific requirements may include additional requirements issued by an automotive customer.

The organization should:

  • Identify applicable customer-specific requirements.
  • Determine which requirements apply to each process.
  • Include suitable samples during QMS audits.
  • Verify actual implementation and effectiveness.

Example

A customer requires a specific reporting process or a defined quality record.

The auditor should check whether:

  • The requirement has been identified.
  • The responsible department understands it.
  • The required process is implemented.
  • Records or evidence demonstrate effective implementation.

The applicable customer’s requirements should be verified using current, authorized documents.

5. Clause 9.2.2.3 – Manufacturing Process Audit

What does the requirement mean?

The organization must audit all manufacturing processes over each three-year calendar period.

The purpose is to determine their effectiveness and efficiency, using customer-required process audit approaches where specified.

Where the customer has not defined an approach, the organization must determine the approach to be used.

Each individual audit plan must cover every shift on which the manufacturing process occurs, including appropriate sampling of shift handover.

The audit must also include effective implementation of:

  • Process risk analysis, such as PFMEA.
  • Control plan.
  • Associated process documents.

5.1 Audit All Manufacturing Processes

The audit programme must ensure that all applicable manufacturing processes are covered over the required three-year calendar period.

Manufacturing processes may include:

  • CNC machining.
  • Pressing.
  • Welding.
  • Heat treatment.
  • Surface treatment.
  • Grinding.
  • Assembly.
  • Inspection-related manufacturing activities, where applicable.

The actual manufacturing process list depends on the organization’s scope and operations as per the process audit checklist.

5.2 Effectiveness and Efficiency

The manufacturing process audit should evaluate both effectiveness and efficiency.

Effectiveness: Is the process achieving its intended results?

Examples:

  • Producing conforming products.
  • Meeting specified process requirements.
  • Controlling critical characteristics.
  • Following approved process controls.

Efficiency: Is the process achieving its results with appropriate use of resources?

Examples:

  • Excessive rework.
  • Unnecessary process delays.
  • Repeated downtime.
  • Ineffective material handling.
  • Excessive scrap.

The auditor should use appropriate evidence and process-specific criteria rather than relying on assumptions.

5.3 Customer-Specific Process Audit Approach

Where a customer specifies a required process audit approach, the organization must use that approach as applicable.

Where the customer does not define an approach, the organization must determine its own approach.

Possible sources for the defined approach include:

  • Customer requirements.
  • Applicable process audit methodology.
  • Organizational procedures.
  • Process risk assessment.
  • Manufacturing process documentation.

Practical advice: Before conducting a manufacturing process audit, verify whether the customer has specified a mandatory audit format, methodology, or checklist.

5.4 Audit All Shifts

One important requirement is that, within each individual audit plan, every manufacturing process must be audited on all shifts where it occurs.

The audit should also include appropriate sampling of shift handover.

Example

A machining process operates on three shifts:

  • Shift A: 6:00 AM – 2:00 PM.
  • Shift B: 2:00 PM – 10:00 PM.
  • Shift C: 10:00 PM – 6:00 AM.

The audit plan should cover all three shifts where the process occurs.

The auditor should assess whether shift handover controls are implemented effectively.

Possible evidence:

  • Shift handover records.
  • Information about machine problems.
  • Rejected product status.
  • Pending inspection.
  • Process parameter issues.
  • Production instructions.

The sample should be appropriate to the process and audit objectives. Auditing only the day shift does not automatically demonstrate that all shift operations are effectively implemented.

5.5 Audit PFMEA, Control Plan, and Associated Documents

The manufacturing process audit must include an audit of the effective implementation of process risk analysis, such as PFMEA, the control plan, and associated documents.

The auditor should verify the relationship between the documents and actual shop-floor practices.

Example: CNC Machining

PFMEA identifies:

Potential failure mode: Incorrect component diameter.

Potential effect: Product may fail customer dimensional requirements.

Potential controls: Defined machining parameters and dimensional inspection.

Control plan identifies:

  • Characteristic to be checked.
  • Inspection method.
  • Frequency.
  • Acceptance criteria.
  • Reaction plan.

Work instruction identifies:

  • Machine setup.
  • Operating instructions.
  • Required parameters.
  • Inspection or verification steps.

During the audit, verify that the identified controls are implemented effectively.

Practical audit questions

  1. Does the process risk analysis identify relevant process risks?
  2. Are relevant controls reflected in the control plan?
  3. Are the control plan requirements implemented on the shop floor?
  4. Are operators following the approved work instructions?
  5. Are process parameters controlled?
  6. Is the reaction plan followed when an abnormal condition occurs?
  7. Are changes to process risk analysis and associated documents managed appropriately?

The audit should evaluate the actual implementation and consistency of the documents and process controls.

6. Clause 9.2.2.4 – Product Audit

What does the requirement mean?

The organization must audit products at appropriate stages of production and delivery to verify conformity to specified requirements through a Control Plan.

Customer-specific required approaches must be used where defined.

Where the customer has not defined the approach, the organization must define the approach to be used.

6.1 Purpose of Product Audit

A product audit verifies whether the product meets specified requirements.

It may include checking:

  • Dimensions.
  • Material characteristics.
  • Functional requirements.
  • Appearance.
  • Product identification.
  • Packaging.
  • Labeling.
  • Traceability, where required.

The product audit should be based on applicable product specifications, drawings, customer requirements, and approved inspection methods.

6.2 Audit at Appropriate Stages

Product audits should be performed at appropriate stages of production and delivery.

Depending on the product and process, this may include:

  • In-process product.
  • Finished product.
  • Pre-dispatch inspection.
  • Product packaging and labeling.
  • Other stages defined by applicable requirements.

The organization should establish the stages, selection method, frequency, and audit criteria in its documented approach.

6.3 Customer-Specific Product Audit Approach

Where a customer specifies a product audit methodology, the organization must follow the applicable approach.

If no customer-specific approach is defined, the organization must establish its own approach.

The defined approach should specify:

  • What products are audited.
  • Which characteristics are checked.
  • When the audit occurs.
  • How the product is selected.
  • What acceptance criteria apply.
  • How results are recorded.
  • How nonconformities are addressed.

7. Difference Between QMS Audit, Process Audit, and Product Audit

Audit typeMain focusExample
QMS auditCompliance and effectiveness of QMS processesPurchasing process audit
Manufacturing process auditEffectiveness and efficiency of manufacturing processesCNC machining audit
Product auditConformity of products to specified requirementsDimensional product audit

8. Practical Internal Audit Programme Example

An automotive component manufacturer can prepare an audit programme that considers the requirements of Clause 9.2.2.1 through Clause 9.2.2.4.

Example Annual Programme

Audit typeSample audit coverage
QMS auditPurchasing, training, corrective action
Manufacturing process auditCNC machining, assembly, welding
Product auditSelected machined components
Follow-up auditVerification of significant findings

This table is a simplified example, not a complete three-year audit plan. The organization must ensure that its actual programme covers all applicable QMS and manufacturing processes over the required three-year calendar period and addresses applicable customer-specific requirements.

How to Prioritize the Programme

Consider:

  1. Process risk.
  2. Criticality of the process.
  3. Internal quality trends.
  4. Customer complaints.
  5. Previous audit findings.
  6. Process changes.
  7. Customer-specific requirements.

The annual programme should be reviewed and adjusted where appropriate.

9. Practical IATF 16949 Clause 9.2 Internal Audit Checklist

A. Internal Audit Programme – Clause 9.2.2.1

No.Audit questionEvidence
1Is a documented internal audit process established?Audit procedure
2Does the programme cover QMS, process, and product audits?Audit programme
3Is audit prioritization based on risk and performance trends?Risk evaluation/programme
4Is process criticality considered?Process classification
5Are software capability assessments included where applicable?Programme/assessment records
6Is audit frequency reviewed based on changes and nonconformities?Review records
7Are customer complaints considered in audit planning?Complaint trends
8Is audit programme effectiveness reviewed during management review?Management review records

B. QMS Audit – Clause 9.2.2.2

No.Audit questionEvidence
1Are all QMS processes covered over the required three-year calendar period?Three-year audit plan
2Is the annual audit programme established?Annual programme
3Is the process approach used?Audit plan/report
4Are applicable IATF 16949 requirements considered?Audit criteria
5Are customer-specific QMS requirements sampled?Audit records
6Is effective implementation verified?Objective evidence
7Are audit findings recorded and followed up?NCR / action records

C. Manufacturing Process Audit – Clause 9.2.2.3

No.Audit questionEvidence
1Are all manufacturing processes covered over the required three-year calendar period?Process audit plan
2Is the customer-required process audit approach used where specified?Customer requirements / checklist
3Is an approach defined where the customer has not specified one?Internal procedure
4Are all shifts audited within each individual audit plan where the process occurs?Shift-wise audit plan
5Is shift handover appropriately sampled?Handover records
6Is PFMEA implementation verified?PFMEA / shop-floor evidence
7Is control plan implementation verified?Control plan/observation
8Are associated process documents implemented effectively?Work instructions/records
9Are process effectiveness and efficiency evaluated?Process performance evidence

D. Product Audit – Clause 9.2.2.4

No.Audit questionEvidence
1Are products audited at appropriate stages of production and delivery?Product audit programme
2Is the customer-required approach used where specified?Customer requirements
3Is the product audit approach defined where the customer has not specified one?Product audit procedure
4Are specified product requirements verified?Drawing/inspection results
5Are product characteristics and acceptance criteria defined?Audit checklist
6Are product audit results recorded?Product audit report
7Are nonconforming products controlled?NCR / product status records

Note: This checklist is a practical implementation aid. It does not replace the full requirements of IATF 16949, ISO 9001, customer-specific requirements, or other applicable requirements.

10. Common Mistakes in Implementing Clause 9.2

Mistake 1: Auditing the Same Processes Every Year

An organization repeatedly audits selected departments but does not ensure complete QMS and manufacturing process coverage over the required three-year period.

Improvement: Maintain a documented multi-year audit plan and review coverage.

Mistake 2: Ignoring Customer-Specific Requirements

The organization uses its own checklist without verifying whether the customer requires a particular audit approach.

Improvement: Identify applicable CSRs before planning QMS, process, and product audits.

Mistake 3: Auditing Only the Day Shift

An auditor assesses one shift and assumes all shifts work in the same way.

Improvement: Plan audit coverage for all shifts where the manufacturing process occurs, including appropriate sampling of shift handover.

Mistake 4: Checking Documents Without Shop-Floor Verification

The PFMEA and control plan are available, but the auditor does not verify their implementation.

Improvement: Compare documents with actual process controls and objective evidence.

Mistake 5: Not Reviewing Audit Frequency

The audit schedule remains unchanged even after significant process changes or recurring customer complaints.

Improvement: Review audit frequency based on relevant changes, nonconformities, and complaints, and adjust where appropriate.

Mistake 6: Treating Programme Completion as Effectiveness

The organization completes all scheduled audits but does not review recurring findings or the quality of corrective actions.

Improvement: Review audit programme effectiveness during management review using relevant performance and follow-up information.

11. Frequently Asked Questions (FAQs)

Q1. What is IATF 16949 Clause 9.2?

IATF 16949 Clause 9.2 defines requirements related to internal auditing. It includes applicable ISO 9001 internal audit requirements and automotive-specific requirements for QMS, manufacturing process, and product audits.

Q2. What are the three types of audits required in the internal audit programme?

The three audit types specified in Clause 9.2.2.1 are:

  1. Quality Management System audits.
  2. Manufacturing process audits.
  3. Product audits.

Q3. What is the three-year audit requirement in IATF 16949?

The organization must audit all QMS processes and all manufacturing processes over each three-year calendar period, according to the applicable requirements and annual audit programme.

This does not mean that every process must be audited only once during the period. Audit frequency should also be considered based on risk, performance, criticality, and other applicable requirements.

Q4. Are all manufacturing shifts required to be audited?

Under Clause 9.2.2.3, within each individual audit plan, each manufacturing process must be audited on all shifts where it occurs, including appropriate sampling of shift handover.

Q5. What is the role of PFMEA in a manufacturing process audit?

PFMEA helps identify and evaluate process risks. The manufacturing process audit should verify effective implementation of the process risk analysis, control plan, and associated documents.

Q6. What if the customer has not defined a process audit approach?

The organization must determine the approach to be used, while considering applicable requirements, the manufacturing process, and the organization’s documented procedures.

Q7. What is the difference between a QMS audit and a process audit?

A QMS audit evaluates the organization’s management system processes against applicable requirements. A manufacturing process audit evaluates manufacturing process effectiveness and efficiency, including implementation of relevant process controls.

Q8. What should be reviewed during management review regarding internal audit?

The effectiveness of the internal audit programme must be reviewed as part of management review. Relevant information may include audit results, recurring findings, programme performance, and follow-up effectiveness.

Q9. Is product audit the same as final inspection?

No. Final inspection is a production or quality control activity. A product audit is an audit activity that verifies conformity to specified product requirements using an established audit approach.

Q10. Is ISO 19011 mandatory for IATF 16949 internal audits?

ISO 19011 provides guidance on auditing management systems. Its use and any specific audit methodology should be determined according to applicable IATF 16949 requirements, customer-specific requirements, and the organization’s audit process. Check the applicable requirements and certification expectations rather than assuming that every ISO 19011 recommendation is mandatory.

12. Conclusion

IATF 16949 Clause 9.2 Internal Audit requires automotive organizations to establish a documented and effective internal audit programme.

The programme must cover the entire Quality Management System, manufacturing processes, and products.

Key implementation points include:

  • Establishing a documented internal audit process.
  • Prioritizing audits based on risk, performance trends, and process criticality.
  • Reviewing audit frequency when relevant changes or quality problems occur.
  • Covering all QMS and manufacturing processes over each required three-year calendar period.
  • Auditing all relevant shifts within each manufacturing process audit plan.
  • Verifying effective implementation of PFMEA, control plans, and associated documents.
  • Including customer-specific requirements and using customer-required audit approaches where applicable.
  • Reviewing audit programme effectiveness as part of management review. (MRM)

An effective internal audit programme helps an automotive organization verify compliance, identify process risks, and improve the performance of its Quality Management System.

If you are working in automotive manufacturing, use this article as a practical learning guide and develop your audit programme according to the applicable standard requirements, customer-specific requirements, and organizational processes.

For QMS consultancy, IATF 16949 implementation, internal audit training, and automotive process audit support, contact QC Tools Solutions.

How to close IATF 16949 3rd-party (Certification Body) audit nonconformities on the NC CARA portal?