Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Plan Plug-and-play starting point Audits & Inspection

Internal Audit Program Plan, Schedule, and Report Template

A plug-and-play internal audit (self-inspection) program pack with the risk-based annual schedule, auditor qualification and independence rules, the per-area audit plan and checklist, the audit report with critical, major, and minor findings, CAPA tracking to closure, escalation, and program effectiveness metrics, plus a filled specimen audit report.

Document type: Plan

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use internal audit program pack. It holds five linked documents in one place: the program plan, the risk-based annual schedule, the per-area audit plan and checklist, the audit report, and the CAPA tracking and effectiveness section. Replace every <<FILL: ...>> placeholder with your own specifics, set your own document numbers and dates, and route the pack through your normal document control, review, and approval. A worked filled specimen of one audit report follows the template so you can see how a completed version reads. Verify each cited regulation against the current source before you rely on it. Using this template does not by itself create compliance; the program only works if the audits actually happen on schedule, the findings are honest, and the CAPAs close with evidence.

Document control header

FieldEntry
Document titleInternal Audit (Self-Inspection) Program for <<FILL: SITE / ORGANIZATION>>
Document number<<FILL: e.g. QA-AUD-001>>
Version<<FILL: e.g. 3.0>>
Effective date<<FILL: effective date>>
Supersedes<<FILL: prior version or "New">>
Document owner<<FILL: role, e.g. Head of Quality Assurance>>
Program manager<<FILL: role, e.g. Internal Audit Lead>>
Approvers<<FILL: roles, e.g. QA Director, Site Head>>
Review frequency<<FILL: e.g. every 2 years or on regulatory change>>

1. Purpose and program objective

This program establishes how <<FILL: SITE / ORGANIZATION>> plans, performs, reports, and closes internal audits, also called self-inspections. The objective is to confirm that the quality system, the facilities, the equipment, the computerized systems, and the documented practices conform to GMP and to the company’s own procedures, and to find and fix gaps before a regulatory inspection, a customer audit, or a quality event finds them.

A self-inspection program is an explicit GMP expectation. EU GMP Chapter 9 requires self-inspections on a defined schedule to monitor implementation and compliance and to propose corrective measures. The US framework reaches the same place through 21 CFR 211.22, which makes the quality unit responsible for procedures and oversight, and through the ICH Q10 expectation of management review fed by internal audit results. The program here is risk based: areas that carry more risk to product quality, to patient safety, or to data integrity are audited more often and in more depth.

2. Scope

This program covers all GxP areas, systems, and processes at <<FILL: SITE / ORGANIZATION>>, including but not limited to: quality management system elements (deviations, CAPA, change control, complaints, recalls, training, document control, supplier management); manufacturing and packaging, including aseptic processing where applicable; quality control laboratories (chemistry, microbiology, stability); warehousing, distribution, and cold chain; computerized systems and data integrity, including audit trail review; facilities and utilities (water systems, HVAC, compressed gases, environmental monitoring); validation and qualification programs; and, for combination products, the drug-led and device-constituent controls that fall under the site’s quality system.

The program does not cover external supplier audits, which run under <<FILL: supplier audit procedure number>>, or regulatory inspections, which run under <<FILL: inspection management procedure number>>. Self-inspection findings may feed those programs.

3. Roles and responsibilities

RoleResponsibility
Head of QualityOwns the program, approves the annual schedule, ensures independence and resources, reviews program metrics, escalates critical findings.
Internal Audit Lead (Program Manager)Builds the risk-based schedule, assigns qualified auditors, maintains the auditor roster, tracks audits and CAPAs to closure, reports metrics.
Lead AuditorPlans and runs the assigned audit, classifies findings, writes the report, agrees timelines, verifies CAPA effectiveness.
Auditor / Co-auditorGathers and records objective evidence, supports finding classification, stays independent of the area audited.
Auditee (Area Manager)Provides access, people, and records; proposes root cause and CAPA; implements CAPA; provides closure evidence.
CAPA OwnerDrives the assigned CAPA to completion with evidence by the agreed date.
Senior ManagementReceives results through management review, provides resources, owns systemic risk decisions.

4. Auditor qualification and independence

An audit is only as trustworthy as the people who run it, so qualification and independence are controlled, not assumed.

4.1 Auditor qualification criteria

RequirementAcceptance criterionEvidence
GMP / GxP knowledgeDocumented training on applicable regulations for the areas auditedTraining record
Auditing techniqueCompleted an auditing course covering planning, evidence gathering, interviewing, and finding classificationCourse certificate
On-the-job trainingShadowed <<FILL: e.g. at least 2>> audits as co-auditor before leadingAudit reports listing the trainee
Area familiarityWorking knowledge of the process or system being audited, without having performed the work being auditedCV / role history
Continuing competence<<FILL: e.g. at least 1 audit per year>> plus periodic refresherAuditor log

The Internal Audit Lead maintains an approved auditor roster with the qualification status and the areas each auditor is cleared to audit. A person who falls below the continuing-competence threshold is re-qualified before leading again.

4.2 Independence rule

An auditor must not audit their own work, their own department, or any area where a reporting relationship would compromise objectivity. For small sites where independence is hard to achieve, acceptable alternatives include cross-site auditors, corporate auditors, or qualified external contract auditors. The independence basis for each audit is recorded on the audit plan. This protects the program from the most common credibility attack an inspector makes: that the auditor had a reason to look away.

5. Risk-based annual schedule

The schedule sets the audit frequency for each area by risk, then is approved before the year starts. Every GxP area is audited at least once within the defined cycle; higher-risk areas are audited more often.

5.1 Risk rating inputs

Rate each area using factors such as: direct impact on product quality and patient safety, sterility or contamination risk, data integrity exposure, complexity and degree of automation, history of deviations and findings, regulatory focus and recent guidance, time since the last audit, and significant change (new equipment, new product, reorganization).

Risk levelTypical audit frequencyExamples
HighAt least once per year, sometimes moreAseptic filling, sterility testing, data integrity in QC systems, batch release
MediumAt least once per <<FILL: e.g. 18-24 months>>Solid dose manufacturing, warehouse, change control
LowAt least once per <<FILL: e.g. 36 months>>Low-risk support functions with stable history

Unscheduled (for-cause) audits are triggered by a serious deviation, a recurring finding, a regulatory signal, a major change, or a complaint trend, and are added during the year.

5.2 Annual schedule table

Audit IDArea / systemRisk levelLast auditedPlanned monthLead auditorAuditor independence basisStatus
<<FILL>><<FILL>><<FILL: H/M/L>><<FILL: date>><<FILL: month>><<FILL>><<FILL: e.g. cross-department>><<FILL: Planned / Done / Slipped>>
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

Schedule changes are controlled. A slipped audit is documented with a reason and a new date; repeated slips of high-risk audits are escalated to the Head of Quality.

6. Audit process

Plan: scope, criteria, agenda, prior findings, notify auditee
Opening meeting: confirm scope, logistics, ground rules
Conduct: gather objective evidence against the checklist
Closing meeting: present findings, agree facts
Report: classify findings, issue within the target time
CAPA: root cause, action, due dates, implement
Verify and close: confirm effectiveness, close finding

Target timelines (adjust to your QMS):

StepTarget
Notify auditee before the audit<<FILL: e.g. 10 working days>>
Issue draft report after closing meeting<<FILL: e.g. 10 working days>>
Auditee responds with root cause and CAPA plan<<FILL: e.g. 20 working days>>
CAPA implementation (by classification, see section 8)Per finding class
Effectiveness verification and finding closure<<FILL: e.g. within 30 days of CAPA completion>>

7. Per-area audit plan and checklist (template)

Use one plan per audit. Build the checklist from the applicable regulations and SOPs for the area; the rows below are a starting frame to adapt, not a fixed list.

7.1 Audit plan header

FieldEntry
Audit ID<<FILL>>
Area / system audited<<FILL>>
Audit typeScheduled / For-cause / Follow-up
Audit criteria (standards and SOPs)<<FILL: e.g. EU GMP Ch.1, 21 CFR 211 Subpart X, SOP-xxx>>
Scope and boundaries<<FILL>>
Dates<<FILL>>
Lead auditor / co-auditor<<FILL>>
Auditees<<FILL>>
Prior open findings to verify<<FILL>>

7.2 Checklist (adapt rows per area)

#Element to verifyReferenceConform Y/NObjective evidence reviewedNote / potential finding
1Procedures are current, approved, and in use at the point of work<<FILL>><<FILL>>
2Personnel are trained and qualified for the tasks observed<<FILL>><<FILL>>
3Records are contemporaneous, attributable, legible, and complete (ALCOA+)<<FILL>><<FILL>>
4Deviations and CAPAs are raised, investigated, and closed on time<<FILL>><<FILL>>
5Equipment and instruments are qualified, calibrated, and within their interval<<FILL>><<FILL>>
6Computerized systems have access control and audit trail review evidence<<FILL>><<FILL>>
7Environmental and utility controls are monitored against limits<<FILL>><<FILL>>
8Material status, segregation, and traceability are controlled<<FILL>><<FILL>>
9Prior audit findings were corrected and stayed fixed<<FILL>><<FILL>>

Every “No” or partial answer becomes a candidate finding. Record the specific record, batch, screen, or observation so the finding rests on evidence, not opinion.

8. Finding classification

Classify each finding by its actual or potential impact on product quality, patient safety, or data integrity. Consistent classification is what lets the program prioritize and what an inspector checks for honesty.

ClassDefinitionExamplesCAPA timeframe (set yours)
CriticalA deficiency that produces, or leads to a significant risk of producing, a product that is harmful, or evidence of fraud, falsification, or a systemic data integrity failure.Released product made outside validated conditions; falsified records; sterility assurance breach.Immediate containment plus CAPA within <<FILL: e.g. 30 days>>
MajorA deficiency that may produce a product not meeting its marketing authorization, or a major departure from GMP, or several related minor findings that together show a system failure.Repeated uncontrolled deviations; missing critical calibration; weak audit trail review.CAPA within <<FILL: e.g. 60 days>>
MinorA departure from GMP or procedure that is not classified as critical or major, often isolated and with limited impact.A single missed second-check signature; a procedure due for periodic review.CAPA within <<FILL: e.g. 90 days>>
Observation / opportunityNot a deficiency, but a risk or an improvement opportunity worth recording.Suggested clarity in a form; a stronger control option.Tracked, no mandatory CAPA

A pattern of minors across areas can roll up to a major or critical systemic finding; the report must call that out rather than logging them as isolated minors.

9. Audit report template

FieldEntry
Report number<<FILL>>
Audit ID<<FILL>>
Area / system audited<<FILL>>
Audit typeScheduled / For-cause / Follow-up
Audit dates<<FILL>>
Lead auditor / co-auditor<<FILL>>
Auditees present<<FILL>>
Audit criteria<<FILL>>
Report issued date<<FILL>>
Distribution<<FILL>>

9.1 Executive summary

<<FILL: 3-6 sentences: scope covered, overall state, count of findings by class, any item needing immediate management attention.>>

9.2 Scope covered and not covered

<<FILL: what was examined, what was deliberately excluded and why, any access limitations.>>

9.3 Findings

Finding IDDescription (what was observed)Evidence (record, batch, screen, sample)Requirement breachedClassCAPA requested by
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL: Crit/Maj/Min>><<FILL: date>>
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

9.4 Positive observations

<<FILL: practices worth keeping or spreading; an honest report records strengths, not only gaps.>>

9.5 Conclusion and follow-up

<<FILL: overall conclusion, whether a follow-up audit is needed, and the date the next audit of this area is due.>>

Sign-off:

RoleNameSignatureDate
Lead auditor<<FILL>>
Area manager (acknowledgement)<<FILL>>
QA approval<<FILL>>

10. CAPA tracking to closure

Each finding above the observation class generates a CAPA tracked in the CAPA log until it is closed with effectiveness evidence. The audit is not closed while CAPAs remain open.

Finding IDClassRoot causeCorrection (immediate)Corrective / preventive actionCAPA ownerDue dateStatusEffectiveness checkClosure date
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>Open / Overdue / Closed<<FILL: how verified>><<FILL>>

Closure rule: a finding closes only when the action is complete, evidence is attached, and effectiveness is confirmed (for example, the next set of records shows the control now holds). Closing on a promise rather than on evidence is the failure mode inspectors catch most often.

11. Escalation

TriggerActionWhoWhen
Critical findingImmediate notification and containment assessmentLead auditor to Head of QualitySame day
CAPA overdueEscalate to area manager, then to senior managementAudit LeadAt due date plus <<FILL: e.g. 10 days>>
Repeat finding (same gap recurs)Re-open as systemic, broaden CAPA scopeAudit Lead and QAAt detection
Schedule slip of a high-risk auditEscalate with reason and recovery dateAudit Lead to Head of QualityAt slip

12. Program effectiveness metrics

Review these at management review. The point is to show the program finds real gaps and closes them, not to chase a clean scorecard by underreporting.

MetricTarget (set yours)Why it matters
Schedule adherence (audits done on plan)<<FILL: e.g. >=95%>>Shows the program actually runs
Reports issued within target time<<FILL: e.g. >=90%>>Timely reporting drives timely fixes
CAPAs closed on time<<FILL: e.g. >=90%>>Closure discipline
Overdue CAPAs (count and age)<<FILL: trend down>>Backlog is a leading risk signal
Repeat findings<<FILL: trend down>>Tests whether CAPAs are effective
Findings later raised by external audit or inspection that internal audit had missed<<FILL: minimize>>The hardest honesty test of the program

13. Records and retention

Audit plans, checklists, reports, CAPA records, and the auditor roster are retained per <<FILL: retention schedule, e.g. life of product plus N years>>. Records are controlled, access-restricted, and available for management review and regulatory inspection.

Worked specimen

The following is a completed audit report and its CAPA tracking, using the fictional company Acme Bio. All names, numbers, and dates are illustrative.

Audit report (filled)

FieldEntry
Report numberAUD-RPT-2026-014
Audit IDIA-2026-09
Area / system auditedQC chromatography data systems and audit trail review (CDS-01)
Audit typeScheduled (High risk)
Audit dates12-13 May 2026
Lead auditor / co-auditorR. Vance (lead, Corporate QA) / P. Okafor (co-auditor, Site B QA)
Auditees presentQC Lab Manager, two analysts, CDS Administrator
Audit criteriaEU GMP Annex 11 (2011); 21 CFR Part 11; FDA Data Integrity guidance (2018); SOP-QC-220 Audit Trail Review
Report issued date22 May 2026
DistributionHead of Quality, QC Manager, IT Quality Lead, CAPA system

Executive summary: The audit examined access control, audit trail configuration, and the routine audit trail review practice for CDS-01. Access control and system qualification were in good order. Two findings were raised: one major (audit trail review was not performed at the defined frequency for two analytical sequences) and one minor (a controlled SOP was past its periodic review date). No critical findings. No data integrity falsification was found. One finding needs management attention because it touches release data.

Scope covered: user access list and leaver removal, audit trail enablement and configuration, the documented audit trail review for ten sampled analytical sequences from Feb to Apr 2026, the review SOP, and training records. Not covered: the instrument qualification of the attached HPLCs, which is audited separately under IA-2026-11.

Findings:

Finding IDDescriptionEvidenceRequirement breachedClassCAPA requested by
F1The defined per-batch audit trail review was not documented for 2 of 10 sampled sequences supporting released results.Review log SOP-QC-220-F1; sequences SEQ-2026-0337 and SEQ-2026-0351; both linked to released lots.Annex 11 audit trail review expectation; SOP-QC-220 sec 5.3Major21 Jul 2026
F2SOP-QC-220 (Audit Trail Review) was 6 weeks past its periodic review date and still in use.Document control record for SOP-QC-220, review due 31 Mar 2026.Document control SOP-QA-010 sec 6Minor21 Aug 2026

Positive observations: leaver access was removed within one working day in all sampled cases, well inside the SOP target; the CDS administrator kept a clear configuration baseline record.

Conclusion: The system is fundamentally under control, but the audit trail review gap on release-supporting data is a real risk and must be corrected and shown effective. A follow-up verification of F1 is required. Next scheduled audit of this area: May 2027.

CAPA tracking (filled)

Finding IDClassRoot causeCorrectionCorrective / preventive actionCAPA ownerDue dateStatusEffectiveness checkClosure date
F1MajorReview was a manual end-of-week task with no per-sequence trigger; two sequences run late Friday were missed at the month boundary.Reviewed both sequences retrospectively; confirmed no data integrity issue; documented.Added a checklist gate in the sequence-release step so a result cannot be released until the audit trail review is recorded; trained all analysts; added the check to the analyst SOP.QC Lab Manager21 Jul 2026ClosedAudit of 20 sequences run 60 days after CAPA: 20/20 had documented review before release.30 Sep 2026
F2MinorPeriodic review reminder went to a role mailbox not monitored during a vacancy.Completed SOP-QC-220 periodic review and reissued.Redirected periodic review reminders to a named owner plus a backup; added an overdue-SOP report to the monthly QC review.Document Control Coordinator21 Aug 2026ClosedNo SOP in the QC area past its review date at the next monthly check.15 Aug 2026

Regulations this supports

  • EU GMP Part I, Chapter 9 (Self Inspection)
  • EU GMP Part I, Chapter 1 (Pharmaceutical Quality System) and Chapter 6 (Quality Control)
  • EU GMP Annex 11 (2011), Computerised Systems
  • 21 CFR 211.22 (responsibilities of the quality control unit) and 21 CFR 211.180 / 211.198 (records and complaint handling) where relevant to audited areas
  • 21 CFR Part 11 (electronic records and signatures)
  • ICH Q10 (Pharmaceutical Quality System), including internal audit and management review
  • ICH Q9(R1) (2022; FDA-adopted 2023), Quality Risk Management, for the risk-based schedule
  • FDA Data Integrity and Compliance with Drug CGMP guidance (2018)
  • MHRA “GxP” Data Integrity guidance (2018)
  • PIC/S PI 041, Good Practices for Data Management and Integrity
  • For combination products, 21 CFR Part 4 (current good manufacturing practice for combination products), where the audited area covers a device constituent under the drug-led quality system

This pack pairs with your CAPA record form and your deviation record form; keep finding IDs, CAPA IDs, and the audit ID linked so the trail is reconstructable from the schedule to closure.

Use madhadi.com as an app Full screen, works offline, one tap from your home screen.