The Workbench · Craft
What an internal audit plan has to decide before the auditor walks in
The easiest internal audit program to build is a rotation: twelve clauses, twelve months, everyone gets their turn. It's also one of the weakest, because ISO 13485:2016 Clause 8.2.4 doesn't ask for even coverage — it asks for a program that weighs the status and importance of each process and the results of previous audits before deciding where to look next. A rotation is compliant on paper and blind to exactly the process that's been quietly degrading since last year's clean report.
Clause 8.2.4 requires internal audits at planned intervals to determine whether the quality management system conforms to the standard, to the organization's own requirements, and to applicable regulatory requirements — and whether it's effectively implemented and maintained. The clause is explicit that the audit program has to be built, not just scheduled: it has to account for the importance of the processes and areas involved, and for what previous audits already found there.
A rotation isn't a risk assessment
A calendar that gives design controls one week every March and purchasing controls one week every September, regardless of what happened last year, treats every process as equally likely to fail. They aren't. A process that changed suppliers, changed software, or turned over its lead this year carries more risk than one that's been stable for five. Clause 8.2.4's language about weighing status and importance is the standard telling programs to spend audit time where the risk actually moved, not where the calendar says it's due.
Independence is structural, not a courtesy
The clause also requires that auditors be selected to ensure objectivity and impartiality of the audit process, and specifically that no one audit their own work. In a small quality function this is a real constraint, not a formality: if the same person owns document control and is also the only internal auditor, that person cannot be the one who signs off on document control's audit, however capable they are. A working audit plan names who is structurally excluded from which audits before the year starts, not after someone notices the conflict mid-audit.
Criteria, scope, and method decided in advance
An audit plan has to fix, ahead of the audit itself, what's being checked against (the criteria — which procedure, which clause, which regulation), how far it reaches (the scope), and how it will be checked (the method — document review, interview, observation, sampling). Deciding these mid-audit turns the exercise into whatever the auditor happens to notice that day, which is closer to a walkthrough than an audit. Many programs lean on ISO 19011's guidance for structuring this, though 19011 is referenced as practical guidance rather than something Clause 8.2.4 itself mandates.
The plan isn't finished until the finding closes
Clause 8.2.4 doesn't end at the audit report. It requires follow-up activities that verify the actions taken and record the results of that verification, and it points nonconformities toward corrective action under Clause 8.5.2. An internal audit program that reopens the same finding every year isn't an audit problem — it's the same broken effectiveness-check loop a CAPA tracker misses when it treats a completed action as a verified one. The audit plan and the CAPA tracker are supposed to close the same loop from opposite ends; a program that doesn't route its findings into a tracker built to verify effectiveness is just producing reports.
An internal audit program template built around risk-weighted scheduling, documented independence, and a defined follow-up path is previewed in the launch catalog. If your program has a rule for surfacing risk that this one is missing, the shelf takes that kind of correction directly.
The Regulatory Toolkit launches soon — a free shelf of source-mapped templates, checklists and browser-only tools for regulatory teams. Get one email when it opens, or contribute a template.