Healthcare Internal Audit: Purpose, Evidence and Follow-up

How a healthcare internal audit runs in practice, from scope and criteria through evidence, findings and corrective action to verified follow-up and close-out.

Post Author:

TalentMed

Share This:
Quality coordinator checking a medicine fridge temperature log during an internal audit in an Australian hospital ward.

Quality Auditing

Healthcare internal audit: purpose, evidence and follow-up

A healthcare internal audit is a first-party audit: one the organisation initiates and conducts on itself (directly or through an internal audit function), to check that its own systems, processes or controls are working as intended, ahead of and independent from any audit carried out by an external party.

That definition has a practical consequence. Internal audit describes who runs the audit, not what the audit looks at, so the same method applies to medicines management, work health and safety, credentialing or document control. This page works through the process one stage at a time: setting scope and criteria, collecting evidence that holds up, writing findings, driving corrective action and verifying that it worked. It assumes you already have the overview of quality auditing in Australia and want the procedure. The worked example running through it is a medication storage audit, which shows the method without becoming a clinical audit.

What a healthcare internal audit examines

An internal audit examines any system the organisation relies on to deliver safe care and meet its obligations, chosen from a risk-based schedule rather than from habit.

Subject matter is a choice, not a given. Typical subject matter in an Australian health service includes medicines storage and recording, work health and safety controls such as sharps handling and chemical storage, infection prevention processes, credentialing and scope of practice records, incident management and feedback handling, document control and version currency, contractor and supplier arrangements, asset and equipment maintenance, and health record management. Each of these is a system with a written requirement behind it, which is what makes it auditable. The subject matter you pick should follow risk and coverage. Risk means the areas where a failure would harm someone, breach a legal obligation or fail a standard. Coverage means that over a full audit cycle, usually twelve months, every area the organisation is assessed against gets looked at at least once, with the higher-risk areas revisited more often. Recording why a topic was chosen matters as much as choosing it, because the reasoning is the first thing a reviewer asks about.

Where internal audit ends and clinical audit begins. Not every internal audit in a health service is a clinical audit. Internal audit is about who conducts the work; clinical audit is about what is being examined, namely patient care measured against evidence-based clinical criteria, and it can be run internally or by an outside party. If your topic is clinical care against clinical guidelines, the criteria, sampling and analysis have their own conventions, set out in clinical audit methodology in Australian healthcare. If you want the comparison between the internal and external auditor roles, including lead auditor certification, that ground is covered in internal vs external healthcare auditor.

How audit scope and criteria are set

Scope sets the boundaries of what you will examine, and criteria set the requirements you will measure against, and both are written down before any evidence is collected.

What a scope statement contains. A usable scope statement names six things: the process or activity, the physical locations or units, the time period the evidence must cover, the shifts or service hours included, anything deliberately excluded and why, and the manager who owns the process. Written out for the worked example, it reads like this:

Storage, temperature monitoring and register recording of Schedule 8 medicines in the two inpatient wards at the main campus, for the six months to 30 June, across all shifts including night duty. Excludes theatre imprest stock, which is audited separately in the March cycle. Process owner: Nurse Unit Manager, with the Director of Pharmacy as the responsible executive.

The exclusions line does the quiet work. It stops the audit sprawling, and it tells anyone reading the report later exactly what the findings do and do not cover. A finding drawn from two wards cannot be reported as a statement about the whole service, and the scope statement is what keeps the report accurate on that point.

Criteria that can actually be tested. Criteria are the set of requirements the evidence gets compared against, which is how ISO 19011:2018, the international guidance on auditing management systems published in 2018, frames them. In a health service they usually come from four places at once: the organisation’s own procedure, the relevant action in the standards the service is assessed against, the applicable state or territory legislation, and any manufacturer or supplier requirement. A criterion is only usable if two auditors reading it would collect the same evidence. “Medicines are stored safely” is not testable. “The medicine fridge temperature is recorded once per shift and falls within the range specified in procedure MM-04” is testable, because it names a frequency, a record and a limit. Write each criterion as a sentence with a verifiable requirement in it, list the source next to it, and confirm with the process owner that the procedure you are auditing against is the current version before you start. One more decision belongs at this stage: who runs the audit. An internal auditor needs to be independent of the work being examined, so nobody audits their own procedure, their own records or a process they manage, and where a small service cannot separate the two completely, note the overlap in the audit plan and have the findings reviewed by someone outside the process before the report goes out.

Evidence collection in a healthcare setting

Audit evidence is records, statements of fact and other information that relate to the criteria and can be verified by someone else, and collecting it well is most of the job.

What counts as sufficient evidence. Evidence is sufficient when it covers the scope period, comes from more than one source, and would support the same conclusion if a second auditor repeated the work. In practice that means triangulating three evidence types: documents and records, direct observation, and interviews with the people doing the work. A temperature log with entries for every shift tells you the record exists, not that the fridge was checked; observing a check tells you it happened once; asking two staff on each shift how they do it tells you whether the record matches the practice. Verifiability is the other half. Note where each piece of evidence came from, the date, the record identifier and who provided it, at the time you collect it. An observation you cannot point back to is an opinion by the time the report is written.

Choosing and recording the sample. Sampling is a decision you have to defend. Spread the sample across the units, shifts and months inside the scope, rather than taking whatever is easiest to reach on the day you visit. Weight it towards the higher-risk parts of the scope, for example night duty if that is where the handover gaps sit. Record the sample size, the method used to select it and the reason, in the working papers and again in the report. For the medication storage audit, a defensible sample looks like: temperature logs for all 26 weeks of the scope period across both wards, a physical count of Schedule 8 stock against the register on two unannounced occasions, the drug room access list as at the audit date, and interviews with two registered nurses from each of the three shifts. That is enough to say something about the period, not just the day.

Handling clinical records and staff interviews. Records and interviews both need care in a health setting. Collect the minimum patient information the criteria require, use record identifiers rather than names in working papers, and store those papers the way the organisation’s privacy procedure requires. For clinical data collection methods specifically, use the conventions in the clinical audit methodology guide rather than improvising. Interviews work best when the auditor asks people to describe and show what they do, not to confirm what the procedure says. Explain at the start that the audit examines the system rather than the individual, and keep names out of the finding. Staff who feel audited personally stop showing you the workaround, and the workaround is usually where the real finding is.

Findings, corrective actions and follow-up

A finding is the result of comparing the evidence you collected against the criteria you set, and it is written in three parts so that it can be acted on without further explanation.

Writing a finding in three parts. State the criterion, then the evidence, then the conclusion. For example: the criterion is that procedure MM-04 requires the fridge temperature to be recorded once per shift; the evidence is that Ward 2 logs for 14 to 27 May show no entry for 19 of 42 shifts, confirmed against the roster; the conclusion is that the recording requirement is not consistently met on Ward 2 during the sampled period. That structure makes the finding checkable. Anyone can go back to the same logs and reach the same conclusion, and nobody has to guess which requirement was missed. Record conformance as well as nonconformance, because an audit that only reports failures gives the executive no picture of what is working. Rate each nonconformance by the risk it carries rather than by how annoying it was to find, and keep individuals unnamed.

Correction, corrective action and verified effectiveness. Correction and corrective action are different things, and conflating them is the most common reason findings recur. A correction fixes the instance: backfill the missing entries, replace the failing fridge, restore the register. A corrective action addresses the reason the instance happened, which might be that the check sits with a role that is not always rostered, or that the log lives in a folder nobody opens on night duty. Getting to that reason properly is its own method, covered in root cause analysis in Australian healthcare. Verification is the step most often skipped. An action is not closed when the owner reports it done; it is closed when fresh evidence, collected after a defined interval, shows the criterion is now being met over a period. For the worked example, that means pulling four more weeks of logs after the change, not accepting a signed form. Record the verification date, the evidence used and the outcome in the corrective action register, and reopen anything that fails.

How internal audit supports external review readiness

Internal audit builds the evidence trail an external reviewer expects to see, which is a working improvement cycle rather than an unblemished record.

Accreditation and certification are different outcomes. Keep the two apart in your reporting. Health service organisations are accredited against the National Safety and Quality Health Service (NSQHS) Standards, and the Australian Commission on Safety and Quality in Health Care states that all public and private hospitals, day hospitals and most public dental practices are required by health regulators to be accredited to them. The Commission confirms the second edition remains the current edition to use while the third edition is developed, as at 2026 (NSQHS Standards). A management system, by contrast, is certified against a standard such as ISO 9001 by a certification body, so the health service is accredited while the quality management system it runs is certified. If you need to work out which framework applies to your service, ISO 9001 vs NSQHS sets out the difference.

What makes the trail usable. Three artefacts do the heavy lifting: an audit schedule showing that each standard was covered across the cycle, a corrective action register with verification dates and attached evidence, and reports that show findings going to the quality committee and coming back closed. Reviewers read that sequence as a system that finds and fixes its own problems. It also helps to know what tends to come up, which is set out in common healthcare audit findings in Australia.

Formal training can make that work more consistent. TalentMed (RTO 22151) delivers the BSB50920 Diploma of Quality Auditing, a nationally recognised diploma that builds the practical skills to plan, conduct and report on quality and compliance audits. BSB50920 builds a pathway toward lead auditor roles across industries by developing the underpinning audit skills; individual lead auditor certification, for example through Exemplar Global, is a separate, additional step assessed by that certifying body, not something BSB50920 confers on completion.

Frequently asked questions

Audits in healthcare are structured checks that compare what an organisation actually does against a defined set of requirements, which might be its own procedures, a standard, or legislation. They come in several types, including clinical audit, internal audit, external or certification audit, and accreditation assessment, and each is conducted by a different party for a different purpose.

Hospitals are audited from two directions. Internally, quality and safety staff or an internal audit function run scheduled audits on the organisation’s own systems. Externally, accreditation assessments against the NSQHS Standards are conducted by approved accrediting agencies, and the Australian Commission on Safety and Quality in Health Care notes that public and private hospitals are required by health regulators to be accredited to those standards.

Yes, and it is one of the main reasons organisations run them. Internal audits surface gaps while there is still time to correct them, and they produce the corrective action records and verification evidence that external reviewers ask for. The preparation value comes from closing findings properly rather than from the audit count.

Compliance work checks whether an organisation is meeting its legal, regulatory, licensing or contractual obligations, and the consequences of failing to meet them are set by law or contract, not by the organisation itself. Quality auditing is a systematic, independent, evidence-based examination of whether an organisation’s activities and results match its own planned arrangements, and whether those arrangements are being implemented effectively enough to achieve its quality objectives. The two overlap wherever a planned arrangement is also a legal requirement: a quality audit criterion and a compliance obligation can be the same document read two different ways, one asking “is this effective” and the other asking “is this lawful”.

Related healthcare audit resources

Course information pack

Share this Article