Internal Auditing

The audits that catch the problem before the certification body does

Every ISO and AS standard requires internal audits at planned intervals. The certification body checks that you did them — not that they were any good. The audits that matter are the ones that catch the configuration drift, the missing FAI records, or the overdue calibration before the certification body's auditor walks in. Or before your prime customer's supplier-development team does. We work alongside your team through the full audit picture — internal, supplier, and customer audits — with the discipline of defined projects: scope, milestones, status reports, and closed-out action items at every step.

ISO 9001 ISO 14001 AS9100 AS9110 AS9120 ISO 13485 Nadcap
ISO 9001:2015 Certified · Cert No. 1118558

Auditing expertise across major high-performance supply chains

Aerospace & Space
Defense & Aviation
Medical Device Mfg
Heavy Manufacturing
Environmental Compliance

The Case for Outside Eyes

Three reasons internal teams call us instead

Most quality teams can run their own internal audits. Few have the bandwidth, the independence, or the audit-bench depth to run them well. Here's when an external auditor pays for itself.

Independence the auditor’s manual requires

ISO 9001 §9.2 and equivalent clauses across AS9100, ISO 13485, and ISO 14001 require auditors to be independent of the activity being audited. In a 30-person shop, the quality manager often is the activity being audited. An external auditor closes that gap cleanly — and the certification body's auditor recognizes it.

Pattern recognition across hundreds of audits

More than 25 years of QM experience across aerospace, medical-device, and general manufacturing means we’ve seen most of the common failure modes. Founder and Principal Connie Smith built American Quality Management (AQM) in 2009 on that depth of experience and has held a parallel Lead Auditor credential at DNV since 2011 — the same kind of third-party auditing seat that audits our clients. The kind of finding that took your team six hours to investigate is often the same finding we closed at three other clients last quarter. We close findings faster because we’ve closed them before.

Bandwidth your team doesn't have

Most quality teams are short-staffed and audit cadence is the first thing that slips. We run the audit calendar on your behalf — scheduled, documented, closed-out — so the year doesn't end with three audits overdue and the certification body's surveillance audit two months out.

What We Audit

Four audit types. Pick the one your QMS needs — or all four

Most clients start with a gap audit or a mock audit and add the others as the relationship continues. The four below are the ones that come up most often. We also run combined audits (gap + mock, internal + supplier) when the scope fits.

Pre-certification

Gap Audit

We map your current state against every clause of the target standard and produce a written gap report with closure timelines. Most useful three to six months before you intend to certify, or any time you’re considering a new standard for the first time. The deliverable is a prioritized closure plan, not a list of complaints.

See the consulting lifecycle
Required by clause

Annual Internal Audit

Every ISO and AS standard requires internal audits at planned intervals — usually annually, sometimes per-process more frequently. We run them as an independent extension of your quality team, with findings tied to corrective actions and follow-through verification. Quarterly or annual cadence; defined audit calendar; named auditor on every report.

Talk to an Auditor
Pre-audit

Mock Audit

Two to four weeks before the certification body's audit, we walk your QMS the way the auditor will — interviews, document review, process observation, findings. By the time the real audit happens, there are no surprises. Most useful before an initial certification audit, a major recertification, or a prime customer's supplier audit.

See AS9100 Consulting
Customer-side

Supplier Audit

When you're holding suppliers accountable for AS9100, ISO 13485, ISO 9001, or Nadcap compliance, we audit them on your behalf. Common for aerospace primes' Tier-1 suppliers auditing their Tier-2s, medical-device manufacturers auditing contract sterilizers, and any operation flowing requirements down the supply chain. Audit report delivered in the format your supplier-development team expects.

Talk to an Auditor

Standards Portfolio

Every standard we consult on, we audit on

The same named team that implements your QMS audits against it. No handoff between an implementation consultant and an auditor who's never seen your operation.

Aerospace Manufacturing

AS9100 Consulting

The aerospace manufacturing baseline standard. Our audits verify that traceability, design control history, and First Article Inspections are completely secure.

Explore AS9100 Consulting
Aviation Maintenance

AS9110 Consulting

Engineered for FAA repair stations and maintenance operators. Our audits target airworthiness records, human factors, and return-to-service validation trails.

Explore AS9110 Consulting
Aerospace Distribution

AS9120 Consulting

Focused on aerospace logistics stockists. Auditing lot splitting control, counterfeit component prevention, and strict chain-of-custody documentation.

Explore AS9120 Consulting
General QMS Baseline

ISO 9001 Consulting

The universal baseline standard built to minimize waste, organize structural workflows, decrease business costs, and satisfy commercial contract qualification demands globally.

Explore ISO 9001 Consulting
Medical Device Sector

ISO 13485 Consulting

Designed to comply with clinical patient-safety demands. Aligns completely with European MDR/IVDR systems and FDA Quality System Regulations (QMSR).

Explore ISO 13485 Consulting
Environmental Management

ISO 14001 Consulting

The global benchmark for managing environmental impacts. Builds out systematic controls for energy management, legal adherence, and waste reduction loops.

Explore ISO 14001 Consulting
Special Processes · PRI

Nadcap Consulting

Elite process-level accreditation support for heat treating, chemical processing, welding, and NDT. We help suppliers interpret PRI checklists and deploy bulletproof RCCA frameworks.

Explore Nadcap Consulting
The Auditing Process

Five steps from "we should probably audit that" to closed findings

Whether it’s a gap audit, an annual internal, or a mock audit, the rhythm is similar. The depth and duration shift; the steps don’t. Every engagement runs as a defined project — written scope, named auditor, scheduled milestones, status reports between site visits, and a closed-out action item log at the end.

Scope & schedule

Audit type, processes in scope, sites, clause coverage, and the calendar. We send a written audit plan two weeks ahead so your team knows what’s being looked at and who needs to be available.

On-site or remote fieldwork

Interviews with process owners, document review, process observation, evidence sampling. A typical single-site audit is one to three days of fieldwork depending on scope and standard.

Findings draft

Within five business days of fieldwork, we deliver a written findings report — nonconformities (major and minor), opportunities for improvement, observations. Every finding cites the clause and the evidence. No surprise findings; everything was discussed during fieldwork.

Corrective action support

We help your team root-cause the nonconformities, draft corrective action plans, and verify implementation. The goal is closures that survive the certification body's next look, not just paper closures.

Closure verification

Once corrective actions are in place, we verify effectiveness and update the audit record. The report goes into your QMS as the evidence the standard requires.

The Steady-State Horizon

Auditing is what most of the work looks like after certification

The first engagement is usually consulting toward certification. Once you’re certified, the work doesn’t stop — it shifts into what we’ve long called the maintenance option: focused on maintaining your QMS so your team can stay focused on the business. Annual internal audits. Mock audits before each surveillance audit. Supplier audits when your customers tighten flow-down requirements. The relationship continues because the audits continue.

Most of our auditing engagements run as quarterly or annual retainers with a defined audit calendar. The auditor is named — often Founder and Principal Connie Smith herself, or another named member of the AQM consulting team — becomes part of your team for the duration, and works the same cadence the standard expects. No surprise invoices, no surprise auditors, no surprise gaps when the certification body shows up. And because each round closes findings into corrective actions and verifies them on the next visit, the QMS gets stronger year over year — continuous improvement as the byproduct, not the brochure copy.

Get Your Custom Calendar
Auditor reviewing precise technical specifications and checklists for regulatory compliance

Auditing questions, answered

Yes — and it's often the cleanest setup. Your in-house auditor runs the day-to-day cadence and the smaller audits; we run the bigger ones (annual, mock, supplier) and the audits where independence is hardest to maintain. The certification body's auditor sees the combined audit record and treats the external pieces as the independence-strengthening signal they are.

Single audits are typically scoped as fixed-fee projects based on standard, scope, and on-site days. Retainer-based auditing (quarterly or annual) is priced per the audit calendar — usually a flat annual fee with the audits scheduled across the year. We quote specifically after the first call; no platform-style pricing on the website.

A typical single-site audit is one to three days of fieldwork depending on standard, scope, and process count. A mock audit ahead of certification is usually two days. A gap audit on a greenfield QMS is often three to five. Reports follow within five business days.

Yes. We frequently audit QMS that another consultant built — sometimes because the original consultant has moved on, sometimes because the client wants an independent second look before certification. We'll be candid about what we find. If the existing system is solid, we'll say so. If it has gaps, we'll show them with citations.

Some audits, yes — document-heavy clauses, supplier-record reviews, and follow-up audits on closed findings can often run remote. Process observation, interview-heavy audits, and most aerospace special-process audits need on-site time. We'll tell you on the first call which mix makes sense for your scope.

The certification body audits whether your QMS conforms to the standard. We audit whether the QMS actually works — whether records can be retrieved, whether process owners know their procedures, whether the audit trail tells the same story across systems. Same clauses; different lens. Our audits are designed to make the certification body's audit boring.

Get Started

Tell us what needs auditing

The first call covers what audit you need, what standard you're auditing against, when it needs to happen, and which of our auditors would lead it. No quote on the call — we'll send a scoped audit plan within a week if we're the right fit.

Our Office Montebello, CA 90640
Call Us (323) 896-1803 · (323) 201-7266
Email Us info@aqmauditing.com
This field is for validation purposes and should be left unchanged.
Get Your Roadmap