Simulated workplaceCAQA Meridian Business Group is a fictional business created by CAQA for training and assessment. It is not a real company and no person, client or record here is real.About this simulation
BSBCAQA MeridianSimulated workplace
Back to library
CAQA Meridian Business Group · Simulated workplace

Internal Audit Procedure

ProcedureControlled document
MER-PRO-013
v2.1
Document ownerQuality, Risk and Compliance Manager
Version2.1
Approved9 September 2025
Next review9 September 2026
StatusCurrent

Purpose. Sets out how internal audits of Meridian's quality management system and compliance obligations are planned, conducted, reported and followed up.

1.Audit program

The Quality, Risk and Compliance Manager will prepare an annual audit program that covers every process and compliance obligation at least once a year, with higher risk areas audited more often. The program will be approved by the General Manager and recorded in the projects system as a project with each audit as a milestone.

2.Planning an audit

For each audit, the lead auditor must define the scope, the criteria (the policies, procedures, standards and laws being audited against), the auditee and the schedule, and must prepare an audit plan and checklist. Auditors must be independent of the area being audited. The auditee must be notified at least five business days before the audit.

3.Conducting the audit

Open the audit with a short meeting to confirm scope and method. Gather objective evidence by interviewing staff, observing work, sampling records and checking systems. Record every finding with the evidence, the criterion and the location. Close with a meeting that presents the findings so there are no surprises in the report.

  • Opening meeting
  • Interviews, observation and record sampling
  • Findings recorded with objective evidence
  • Closing meeting with the auditee

4.Classifying findings

Findings are classified as major non-conformance (a requirement is not met in a way that affects the client, the law or the integrity of the system), minor non-conformance (an isolated lapse) or opportunity for improvement. Each non-conformance must be recorded in the risk and compliance register with an owner.

5.Reporting

Issue the audit report within ten business days of the closing meeting using the standard format: scope, criteria, method, summary, findings with evidence, and conclusions. The report goes to the auditee's manager, the Quality, Risk and Compliance Manager and the General Manager.

6.Corrective action and follow up

The auditee must propose a root cause and a corrective action for each non-conformance within ten business days. The lead auditor will verify the action is complete and effective before closing the finding. Open findings are reviewed at the quarterly quality management review.

MER-PRO-013 v2.1 · CAQA Meridian Business GroupUncontrolled when printed. Simulated document created by CAQA for training and assessment.