This is a ready-to-use internal audit program pack. It holds five linked documents in one place: the program plan, the risk-based annual schedule, the per-area audit plan and checklist, the audit report, and the CAPA tracking and effectiveness section. Replace every <<FILL: ...>> placeholder with your own specifics, set your own document numbers and dates, and route the pack through your normal document control, review, and approval. A worked filled specimen of one audit report follows the template so you can see how a completed version reads. Verify each cited regulation against the current source before you rely on it. Using this template does not by itself create compliance; the program only works if the audits actually happen on schedule, the findings are honest, and the CAPAs close with evidence.
Document control header
| Field | Entry |
|---|---|
| Document title | Internal Audit (Self-Inspection) Program for <<FILL: SITE / ORGANIZATION>> |
| Document number | <<FILL: e.g. QA-AUD-001>> |
| Version | <<FILL: e.g. 3.0>> |
| Effective date | <<FILL: effective date>> |
| Supersedes | <<FILL: prior version or "New">> |
| Document owner | <<FILL: role, e.g. Head of Quality Assurance>> |
| Program manager | <<FILL: role, e.g. Internal Audit Lead>> |
| Approvers | <<FILL: roles, e.g. QA Director, Site Head>> |
| Review frequency | <<FILL: e.g. every 2 years or on regulatory change>> |
1. Purpose and program objective
This program establishes how <<FILL: SITE / ORGANIZATION>> plans, performs, reports, and closes internal audits, also called self-inspections. The objective is to confirm that the quality system, the facilities, the equipment, the computerized systems, and the documented practices conform to GMP and to the company’s own procedures, and to find and fix gaps before a regulatory inspection, a customer audit, or a quality event finds them.
A self-inspection program is an explicit GMP expectation. EU GMP Chapter 9 requires self-inspections on a defined schedule to monitor implementation and compliance and to propose corrective measures. The US framework reaches the same place through 21 CFR 211.22, which makes the quality unit responsible for procedures and oversight, and through the ICH Q10 expectation of management review fed by internal audit results. The program here is risk based: areas that carry more risk to product quality, to patient safety, or to data integrity are audited more often and in more depth.
2. Scope
This program covers all GxP areas, systems, and processes at <<FILL: SITE / ORGANIZATION>>, including but not limited to: quality management system elements (deviations, CAPA, change control, complaints, recalls, training, document control, supplier management); manufacturing and packaging, including aseptic processing where applicable; quality control laboratories (chemistry, microbiology, stability); warehousing, distribution, and cold chain; computerized systems and data integrity, including audit trail review; facilities and utilities (water systems, HVAC, compressed gases, environmental monitoring); validation and qualification programs; and, for combination products, the drug-led and device-constituent controls that fall under the site’s quality system.
The program does not cover external supplier audits, which run under <<FILL: supplier audit procedure number>>, or regulatory inspections, which run under <<FILL: inspection management procedure number>>. Self-inspection findings may feed those programs.
3. Roles and responsibilities
| Role | Responsibility |
|---|---|
| Head of Quality | Owns the program, approves the annual schedule, ensures independence and resources, reviews program metrics, escalates critical findings. |
| Internal Audit Lead (Program Manager) | Builds the risk-based schedule, assigns qualified auditors, maintains the auditor roster, tracks audits and CAPAs to closure, reports metrics. |
| Lead Auditor | Plans and runs the assigned audit, classifies findings, writes the report, agrees timelines, verifies CAPA effectiveness. |
| Auditor / Co-auditor | Gathers and records objective evidence, supports finding classification, stays independent of the area audited. |
| Auditee (Area Manager) | Provides access, people, and records; proposes root cause and CAPA; implements CAPA; provides closure evidence. |
| CAPA Owner | Drives the assigned CAPA to completion with evidence by the agreed date. |
| Senior Management | Receives results through management review, provides resources, owns systemic risk decisions. |
4. Auditor qualification and independence
An audit is only as trustworthy as the people who run it, so qualification and independence are controlled, not assumed.
4.1 Auditor qualification criteria
| Requirement | Acceptance criterion | Evidence |
|---|---|---|
| GMP / GxP knowledge | Documented training on applicable regulations for the areas audited | Training record |
| Auditing technique | Completed an auditing course covering planning, evidence gathering, interviewing, and finding classification | Course certificate |
| On-the-job training | Shadowed <<FILL: e.g. at least 2>> audits as co-auditor before leading | Audit reports listing the trainee |
| Area familiarity | Working knowledge of the process or system being audited, without having performed the work being audited | CV / role history |
| Continuing competence | <<FILL: e.g. at least 1 audit per year>> plus periodic refresher | Auditor log |
The Internal Audit Lead maintains an approved auditor roster with the qualification status and the areas each auditor is cleared to audit. A person who falls below the continuing-competence threshold is re-qualified before leading again.
4.2 Independence rule
An auditor must not audit their own work, their own department, or any area where a reporting relationship would compromise objectivity. For small sites where independence is hard to achieve, acceptable alternatives include cross-site auditors, corporate auditors, or qualified external contract auditors. The independence basis for each audit is recorded on the audit plan. This protects the program from the most common credibility attack an inspector makes: that the auditor had a reason to look away.
5. Risk-based annual schedule
The schedule sets the audit frequency for each area by risk, then is approved before the year starts. Every GxP area is audited at least once within the defined cycle; higher-risk areas are audited more often.
5.1 Risk rating inputs
Rate each area using factors such as: direct impact on product quality and patient safety, sterility or contamination risk, data integrity exposure, complexity and degree of automation, history of deviations and findings, regulatory focus and recent guidance, time since the last audit, and significant change (new equipment, new product, reorganization).
| Risk level | Typical audit frequency | Examples |
|---|---|---|
| High | At least once per year, sometimes more | Aseptic filling, sterility testing, data integrity in QC systems, batch release |
| Medium | At least once per <<FILL: e.g. 18-24 months>> | Solid dose manufacturing, warehouse, change control |
| Low | At least once per <<FILL: e.g. 36 months>> | Low-risk support functions with stable history |
Unscheduled (for-cause) audits are triggered by a serious deviation, a recurring finding, a regulatory signal, a major change, or a complaint trend, and are added during the year.
5.2 Annual schedule table
| Audit ID | Area / system | Risk level | Last audited | Planned month | Lead auditor | Auditor independence basis | Status |
|---|---|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL: H/M/L>> | <<FILL: date>> | <<FILL: month>> | <<FILL>> | <<FILL: e.g. cross-department>> | <<FILL: Planned / Done / Slipped>> |
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
Schedule changes are controlled. A slipped audit is documented with a reason and a new date; repeated slips of high-risk audits are escalated to the Head of Quality.
6. Audit process
Target timelines (adjust to your QMS):
| Step | Target |
|---|---|
| Notify auditee before the audit | <<FILL: e.g. 10 working days>> |
| Issue draft report after closing meeting | <<FILL: e.g. 10 working days>> |
| Auditee responds with root cause and CAPA plan | <<FILL: e.g. 20 working days>> |
| CAPA implementation (by classification, see section 8) | Per finding class |
| Effectiveness verification and finding closure | <<FILL: e.g. within 30 days of CAPA completion>> |
7. Per-area audit plan and checklist (template)
Use one plan per audit. Build the checklist from the applicable regulations and SOPs for the area; the rows below are a starting frame to adapt, not a fixed list.
7.1 Audit plan header
| Field | Entry |
|---|---|
| Audit ID | <<FILL>> |
| Area / system audited | <<FILL>> |
| Audit type | Scheduled / For-cause / Follow-up |
| Audit criteria (standards and SOPs) | <<FILL: e.g. EU GMP Ch.1, 21 CFR 211 Subpart X, SOP-xxx>> |
| Scope and boundaries | <<FILL>> |
| Dates | <<FILL>> |
| Lead auditor / co-auditor | <<FILL>> |
| Auditees | <<FILL>> |
| Prior open findings to verify | <<FILL>> |
7.2 Checklist (adapt rows per area)
| # | Element to verify | Reference | Conform Y/N | Objective evidence reviewed | Note / potential finding |
|---|---|---|---|---|---|
| 1 | Procedures are current, approved, and in use at the point of work | <<FILL>> | <<FILL>> | ||
| 2 | Personnel are trained and qualified for the tasks observed | <<FILL>> | <<FILL>> | ||
| 3 | Records are contemporaneous, attributable, legible, and complete (ALCOA+) | <<FILL>> | <<FILL>> | ||
| 4 | Deviations and CAPAs are raised, investigated, and closed on time | <<FILL>> | <<FILL>> | ||
| 5 | Equipment and instruments are qualified, calibrated, and within their interval | <<FILL>> | <<FILL>> | ||
| 6 | Computerized systems have access control and audit trail review evidence | <<FILL>> | <<FILL>> | ||
| 7 | Environmental and utility controls are monitored against limits | <<FILL>> | <<FILL>> | ||
| 8 | Material status, segregation, and traceability are controlled | <<FILL>> | <<FILL>> | ||
| 9 | Prior audit findings were corrected and stayed fixed | <<FILL>> | <<FILL>> |
Every “No” or partial answer becomes a candidate finding. Record the specific record, batch, screen, or observation so the finding rests on evidence, not opinion.
8. Finding classification
Classify each finding by its actual or potential impact on product quality, patient safety, or data integrity. Consistent classification is what lets the program prioritize and what an inspector checks for honesty.
| Class | Definition | Examples | CAPA timeframe (set yours) |
|---|---|---|---|
| Critical | A deficiency that produces, or leads to a significant risk of producing, a product that is harmful, or evidence of fraud, falsification, or a systemic data integrity failure. | Released product made outside validated conditions; falsified records; sterility assurance breach. | Immediate containment plus CAPA within <<FILL: e.g. 30 days>> |
| Major | A deficiency that may produce a product not meeting its marketing authorization, or a major departure from GMP, or several related minor findings that together show a system failure. | Repeated uncontrolled deviations; missing critical calibration; weak audit trail review. | CAPA within <<FILL: e.g. 60 days>> |
| Minor | A departure from GMP or procedure that is not classified as critical or major, often isolated and with limited impact. | A single missed second-check signature; a procedure due for periodic review. | CAPA within <<FILL: e.g. 90 days>> |
| Observation / opportunity | Not a deficiency, but a risk or an improvement opportunity worth recording. | Suggested clarity in a form; a stronger control option. | Tracked, no mandatory CAPA |
A pattern of minors across areas can roll up to a major or critical systemic finding; the report must call that out rather than logging them as isolated minors.
9. Audit report template
| Field | Entry |
|---|---|
| Report number | <<FILL>> |
| Audit ID | <<FILL>> |
| Area / system audited | <<FILL>> |
| Audit type | Scheduled / For-cause / Follow-up |
| Audit dates | <<FILL>> |
| Lead auditor / co-auditor | <<FILL>> |
| Auditees present | <<FILL>> |
| Audit criteria | <<FILL>> |
| Report issued date | <<FILL>> |
| Distribution | <<FILL>> |
9.1 Executive summary
<<FILL: 3-6 sentences: scope covered, overall state, count of findings by class, any item needing immediate management attention.>>
9.2 Scope covered and not covered
<<FILL: what was examined, what was deliberately excluded and why, any access limitations.>>
9.3 Findings
| Finding ID | Description (what was observed) | Evidence (record, batch, screen, sample) | Requirement breached | Class | CAPA requested by |
|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL: Crit/Maj/Min>> | <<FILL: date>> |
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
9.4 Positive observations
<<FILL: practices worth keeping or spreading; an honest report records strengths, not only gaps.>>
9.5 Conclusion and follow-up
<<FILL: overall conclusion, whether a follow-up audit is needed, and the date the next audit of this area is due.>>
Sign-off:
| Role | Name | Signature | Date |
|---|---|---|---|
| Lead auditor | <<FILL>> | ||
| Area manager (acknowledgement) | <<FILL>> | ||
| QA approval | <<FILL>> |
10. CAPA tracking to closure
Each finding above the observation class generates a CAPA tracked in the CAPA log until it is closed with effectiveness evidence. The audit is not closed while CAPAs remain open.
| Finding ID | Class | Root cause | Correction (immediate) | Corrective / preventive action | CAPA owner | Due date | Status | Effectiveness check | Closure date |
|---|---|---|---|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | Open / Overdue / Closed | <<FILL: how verified>> | <<FILL>> |
Closure rule: a finding closes only when the action is complete, evidence is attached, and effectiveness is confirmed (for example, the next set of records shows the control now holds). Closing on a promise rather than on evidence is the failure mode inspectors catch most often.
11. Escalation
| Trigger | Action | Who | When |
|---|---|---|---|
| Critical finding | Immediate notification and containment assessment | Lead auditor to Head of Quality | Same day |
| CAPA overdue | Escalate to area manager, then to senior management | Audit Lead | At due date plus <<FILL: e.g. 10 days>> |
| Repeat finding (same gap recurs) | Re-open as systemic, broaden CAPA scope | Audit Lead and QA | At detection |
| Schedule slip of a high-risk audit | Escalate with reason and recovery date | Audit Lead to Head of Quality | At slip |
12. Program effectiveness metrics
Review these at management review. The point is to show the program finds real gaps and closes them, not to chase a clean scorecard by underreporting.
| Metric | Target (set yours) | Why it matters |
|---|---|---|
| Schedule adherence (audits done on plan) | <<FILL: e.g. >=95%>> | Shows the program actually runs |
| Reports issued within target time | <<FILL: e.g. >=90%>> | Timely reporting drives timely fixes |
| CAPAs closed on time | <<FILL: e.g. >=90%>> | Closure discipline |
| Overdue CAPAs (count and age) | <<FILL: trend down>> | Backlog is a leading risk signal |
| Repeat findings | <<FILL: trend down>> | Tests whether CAPAs are effective |
| Findings later raised by external audit or inspection that internal audit had missed | <<FILL: minimize>> | The hardest honesty test of the program |
13. Records and retention
Audit plans, checklists, reports, CAPA records, and the auditor roster are retained per <<FILL: retention schedule, e.g. life of product plus N years>>. Records are controlled, access-restricted, and available for management review and regulatory inspection.
Worked specimen
The following is a completed audit report and its CAPA tracking, using the fictional company Acme Bio. All names, numbers, and dates are illustrative.
Audit report (filled)
| Field | Entry |
|---|---|
| Report number | AUD-RPT-2026-014 |
| Audit ID | IA-2026-09 |
| Area / system audited | QC chromatography data systems and audit trail review (CDS-01) |
| Audit type | Scheduled (High risk) |
| Audit dates | 12-13 May 2026 |
| Lead auditor / co-auditor | R. Vance (lead, Corporate QA) / P. Okafor (co-auditor, Site B QA) |
| Auditees present | QC Lab Manager, two analysts, CDS Administrator |
| Audit criteria | EU GMP Annex 11 (2011); 21 CFR Part 11; FDA Data Integrity guidance (2018); SOP-QC-220 Audit Trail Review |
| Report issued date | 22 May 2026 |
| Distribution | Head of Quality, QC Manager, IT Quality Lead, CAPA system |
Executive summary: The audit examined access control, audit trail configuration, and the routine audit trail review practice for CDS-01. Access control and system qualification were in good order. Two findings were raised: one major (audit trail review was not performed at the defined frequency for two analytical sequences) and one minor (a controlled SOP was past its periodic review date). No critical findings. No data integrity falsification was found. One finding needs management attention because it touches release data.
Scope covered: user access list and leaver removal, audit trail enablement and configuration, the documented audit trail review for ten sampled analytical sequences from Feb to Apr 2026, the review SOP, and training records. Not covered: the instrument qualification of the attached HPLCs, which is audited separately under IA-2026-11.
Findings:
| Finding ID | Description | Evidence | Requirement breached | Class | CAPA requested by |
|---|---|---|---|---|---|
| F1 | The defined per-batch audit trail review was not documented for 2 of 10 sampled sequences supporting released results. | Review log SOP-QC-220-F1; sequences SEQ-2026-0337 and SEQ-2026-0351; both linked to released lots. | Annex 11 audit trail review expectation; SOP-QC-220 sec 5.3 | Major | 21 Jul 2026 |
| F2 | SOP-QC-220 (Audit Trail Review) was 6 weeks past its periodic review date and still in use. | Document control record for SOP-QC-220, review due 31 Mar 2026. | Document control SOP-QA-010 sec 6 | Minor | 21 Aug 2026 |
Positive observations: leaver access was removed within one working day in all sampled cases, well inside the SOP target; the CDS administrator kept a clear configuration baseline record.
Conclusion: The system is fundamentally under control, but the audit trail review gap on release-supporting data is a real risk and must be corrected and shown effective. A follow-up verification of F1 is required. Next scheduled audit of this area: May 2027.
CAPA tracking (filled)
| Finding ID | Class | Root cause | Correction | Corrective / preventive action | CAPA owner | Due date | Status | Effectiveness check | Closure date |
|---|---|---|---|---|---|---|---|---|---|
| F1 | Major | Review was a manual end-of-week task with no per-sequence trigger; two sequences run late Friday were missed at the month boundary. | Reviewed both sequences retrospectively; confirmed no data integrity issue; documented. | Added a checklist gate in the sequence-release step so a result cannot be released until the audit trail review is recorded; trained all analysts; added the check to the analyst SOP. | QC Lab Manager | 21 Jul 2026 | Closed | Audit of 20 sequences run 60 days after CAPA: 20/20 had documented review before release. | 30 Sep 2026 |
| F2 | Minor | Periodic review reminder went to a role mailbox not monitored during a vacancy. | Completed SOP-QC-220 periodic review and reissued. | Redirected periodic review reminders to a named owner plus a backup; added an overdue-SOP report to the monthly QC review. | Document Control Coordinator | 21 Aug 2026 | Closed | No SOP in the QC area past its review date at the next monthly check. | 15 Aug 2026 |
Regulations this supports
- EU GMP Part I, Chapter 9 (Self Inspection)
- EU GMP Part I, Chapter 1 (Pharmaceutical Quality System) and Chapter 6 (Quality Control)
- EU GMP Annex 11 (2011), Computerised Systems
- 21 CFR 211.22 (responsibilities of the quality control unit) and 21 CFR 211.180 / 211.198 (records and complaint handling) where relevant to audited areas
- 21 CFR Part 11 (electronic records and signatures)
- ICH Q10 (Pharmaceutical Quality System), including internal audit and management review
- ICH Q9(R1) (2022; FDA-adopted 2023), Quality Risk Management, for the risk-based schedule
- FDA Data Integrity and Compliance with Drug CGMP guidance (2018)
- MHRA “GxP” Data Integrity guidance (2018)
- PIC/S PI 041, Good Practices for Data Management and Integrity
- For combination products, 21 CFR Part 4 (current good manufacturing practice for combination products), where the audited area covers a device constituent under the drug-led quality system
This pack pairs with your CAPA record form and your deviation record form; keep finding IDs, CAPA IDs, and the audit ID linked so the trail is reconstructable from the schedule to closure.