IoL Workflows
Administrative   Family N · Quality and compliance  ·  IoL Administrative Affairs

AW-24 · Internal Audit and Corrective and Preventive Action

Primary KPIsnone
Contributes to
TriggerThe annual audit programme; a non-conformity raised by any procedure; an incident, complaint or external finding; a request from AW-25 or the Senior Director, IoL
EndpointAudit report issued and accepted; every CAPA verified effective and closed, or escalated; annual summary and recurrence analysis delivered to AW-25
OBEF touchpointNone. WF-04 owns OBEF corrective action plans in the MoHESR CAP template; this procedure owns every other non-conformity and corrective action

BPMN 2.0 (ISO/IEC 19510), generated from the procedure section of this document. Lanes are the roles in the RACI; a cylinder marks a capture point and the KPI it feeds; a diamond is a decision point. Click a task to jump to its step. Scroll to zoom, drag to pan.

AW-24 — Internal Audit and Corrective and Preventive Action

Workflow ID AW-24
Pack owner IoL Administrative Affairs (decision of 2 September 2026; see Architecture/04_Ownership_Model.md)
Family N — Quality and compliance
Ownership IoL. MBRU's internal audit function audits the institution and may audit IoL; this procedure covers IoL's own first-line audit of its documented procedures and the register that closes what those audits and every other procedure find [IoL to confirm]
Governing policy MBRU internal audit charter and quality assurance policy [IoL to confirm]; ISO 9001:2015 clauses 9.2 and 10.2; ISO 21001:2018 clauses 9.2 and 10.2
Interfaces Every AW and WF as auditee; AW-03 (uncontrolled documents); AW-05 and AW-10 (delegation breaches, splitting); AW-06 (control failures); AW-20 (complaints root causes); AW-25 (results and CAPA status); WF-04 boundary
OBEF touchpoint None. WF-04 owns OBEF corrective action plans in the MoHESR CAP template; this procedure owns every other non-conformity and corrective action
Process owner ______________
Version 0.1 draft
Effective
Next review

1. Purpose and scope

Purpose. To give IoL objective evidence that its procedures are followed and effective, by auditing each one on a risk-based cycle against its own controls and measures, by people who do not run it, and to ensure that every non-conformity found by audit or raised by any procedure is corrected at its root cause, verified as effective, and tracked for recurrence in one register.

Scope statement. This procedure manages the internal audit programme from annual planning to reporting, and the CAPA register from the raising of a non-conformity to verified closure.

Applies to. All 25 AW procedures and all 26 WF workflows; non-conformities raised by audit, by any procedure's control (for example AW-03 uncontrolled document in use, AW-05 approval outside delegation, AW-10 purchase splitting, AW-06 control failure, AW-17 incident root cause, AW-20 upheld complaint); observations and opportunities for improvement from any source.

Does not apply to. OBEF corrective action plans, which WF-04 owns in the MoHESR template; MBRU institutional audits, accreditation and ISO certification findings, which are tracked to closure here but graded by the external body; disciplinary matters, which follow AW-09 or WF-11.

Boundary with WF-04. A finding about a KPI value, an OBEF flag, a submission or a performance gap against an OBEF target is referred to WF-04 and closed here as referred. A finding about whether a procedure was followed, including a procedure in the academic pack, stays here. One root cause may generate both a CAP entry and a CAPA entry; each register cross-references the other.

2. Trigger, boundary and interfaces

Trigger The annual audit programme; a non-conformity raised by any procedure; an incident, complaint or external finding; a request from AW-25 or the Senior Director, IoL
Endpoint Audit report issued and accepted; every CAPA verified effective and closed, or escalated; annual summary and recurrence analysis delivered to AW-25
Upstream Every procedure's controls and measures (the checklist source); AW-06 risk scores (audit frequency); external audit and accreditation reports; AW-20 and AW-17
Downstream AW-25 (audit results, CAPA status, recurrence); AW-03 (procedure changes arising); AW-06 (risks arising); WF-04 (OBEF referrals); AW-02 (resourced actions)
Handoff to the academic pack WF-04 receives any finding that is an OBEF reporting, data-quality or performance gap, with the audit evidence. Audits of whether WF procedures were followed are conducted here and the findings stay here.

3. Roles and accountability

Process owner. IoL Quality Lead or equivalent [IoL to confirm], with authority to schedule an audit of any procedure and to refuse closure of a CAPA without effectiveness evidence.

Step Process owner (Quality Lead) Lead auditor Auditee (procedure owner) CAPA owner Senior Director, IoL IoL management committee (AW-01)
Approve the annual audit programme R I I I A C
Assign auditors and confirm independence A/R I I I I I
Plan and conduct the audit C A/R R I I I
Grade findings C A/R C I I I
Accept the audit report I R R I A I
Raise a non-conformity from a procedure A I R I I I
Root cause analysis and action plan C I C A/R I I
Approve the action plan A/R I I R C I
Verify effectiveness and close A/R C I R I I
Escalate an overdue or recurring CAPA R I I I A I
Receive annual summary R I I I R A

[CONTROL] Segregation. No one audits a procedure they own, operate or line-manage. The CAPA owner does not verify their own action. Procedures owned by the Quality Lead are audited by a trained auditor from another IoL function or by MBRU quality [IoL to confirm].

4. Procedure

  1. Build the annual programme. Every AW and WF is scheduled at least once in a cycle of ______ years [IoL to confirm; assumed three], with annual audit of procedures that are high risk (AW-06 score), handle money or personal data (AW-04, AW-05, AW-10, AW-11, AW-16), had a major non-conformity last cycle, or feed OBEF flags at WF-26's request. The Senior Director, IoL, approves the programme through AW-01. [CONTROL] No procedure goes unaudited for longer than the cycle.

  2. Assign the auditor. A trained auditor with no ownership, operating or reporting-line relationship to the procedure is assigned and the independence check recorded. Auditor training is held in AW-07 records.

  3. Plan the audit. The lead auditor builds the checklist from the procedure itself: each [CONTROL] marker, each key control, each service standard, each performance measure and the RACI segregation statement. The plan states sample size and period, records to be drawn, people to be interviewed and the date, and the auditee is notified 10 working days ahead. [CONTROL] The checklist derives from the controlled version current for the audit period, not from the auditor's understanding of it.

  4. Conduct the audit. The auditor samples records from the systems named in the procedure, tests each control against the sample, observes practice and interviews staff. Evidence is recorded against each checklist item with the record reference; a finding cites at least one specific instance.

  5. Grade findings. Each finding is one of: major non-conformity (a control absent or systematically not operating, a legal or safety requirement breached, or a repeat minor); minor non-conformity (an isolated lapse against a control that otherwise operates); observation (a risk of future non-conformity); opportunity for improvement. Findings are agreed with the auditee at a closing meeting; disagreement is recorded and the process owner decides.

  6. Report. The report states scope, sample, findings with grade and evidence, a conformity statement and positive practice. The Senior Director, IoL, accepts it and each non-conformity enters the CAPA register. Decision point. A major non-conformity is reported to the Senior Director, IoL, on the day it is found.

  7. Receive non-conformities from procedures. Any procedure owner raises a non-conformity in the register when a control in their procedure detects a breach, with the evidence. The process owner confirms the grade. [CONTROL] A breach detected by a control and not entered in the register is itself a non-conformity.

  8. Correct. The CAPA owner applies the immediate correction (withdraw the document, reverse the approval, restore the record, notify the affected party) and records it with the date.

  9. Analyse root cause. For every non-conformity the CAPA owner records the root cause using a stated method (five whys, cause and effect) and identifies whether the cause is the procedure, the training, the system, the resource or the person. [CONTROL] "Human error" is not accepted as a root cause; the register requires the condition that allowed the error.

  10. Plan corrective and preventive action. Corrective action removes the root cause so the non-conformity does not recur; preventive action addresses the same cause where it exists in other procedures. Each has an owner, a date and the evidence of completion expected. Actions needing resource go to AW-02; actions changing a procedure go through AW-03; actions creating a risk go to AW-06. The process owner approves the plan.

  11. Verify effectiveness. After the actions are complete and after an interval long enough for recurrence to show [IoL to confirm; assumed 3 months for minors, 6 for majors], someone other than the CAPA owner tests whether the non-conformity has recurred and whether the control now operates. [CONTROL] A CAPA closes only on documented effectiveness evidence; completion of the action is not closure.

  12. Track recurrence. The register links every new non-conformity to any earlier one with the same root cause or the same procedure. A recurrence within the cycle upgrades the grade to major and escalates to the Senior Director, IoL.

  13. Report to management review. Before each AW-25 review the process owner delivers audits completed against programme, findings by grade and procedure, CAPA open, overdue and closed, verification results, recurrences and external findings status.

Exception routes. An audit postponed by the auditee is rescheduled within the quarter; a second postponement is reported to AW-25. A disputed CAPA is decided by the Senior Director, IoL. A finding indicating fraud, a data breach or a safety issue is referred the same day to MBRU's relevant function, AW-16 or AW-17, and the audit trail is preserved under AW-04 legal hold.

5. Service standards

Service Standard
Annual programme approved Before the start of the audit year [IoL to confirm]
Auditee notified 10 working days before the audit
Audit report issued 10 working days after the closing meeting
Major non-conformity reported to Senior Director, IoL Same day
Non-conformity entered in register 5 working days from detection
Root cause and action plan approved 20 working days from entry
Effectiveness verification Within 20 working days of the end of the verification interval
Summary to AW-25 10 working days before the management review

6. Records, retention and controls

Record System Retention Owner
Annual audit programme and independence checks Controlled register (AW-03) [IoL to confirm system] 7 years [IoL to confirm against MBRU schedule] Process owner
Audit plans, checklists, working papers and evidence samples Quality repository 7 years Lead auditor
Audit reports Quality repository 7 years, or as long as the ISO certificate cycle requires Process owner
CAPA register with root cause, actions, verification and recurrence links Controlled register Permanent, closed items archived after 7 years Process owner
Referrals to WF-04 CAPA register and WF-04 CAP 7 years Process owner
External audit and accreditation findings tracking CAPA register 7 years Process owner

Key controls. (1) Every procedure audited within the cycle. (2) Auditor independent of the auditee. (3) Checklist derived from the controlled procedure. (4) Every finding evidenced by a specific instance. (5) Every control-detected breach reaches the register. (6) Root cause recorded, never "human error". (7) Closure only on effectiveness evidence by someone other than the CAPA owner. (8) Recurrence upgrades and escalates.

OBEF touchpoint. None. Referrals to WF-04 are recorded with the date and the WF-04 CAP reference.

7. Performance measures

Dimension Measure Target
Timeliness Audits completed against the annual programme 100%
Timeliness Audit reports issued within 10 working days 90%
Timeliness CAPA action plans approved within 20 working days 90%
Compliance Audits with a documented independence check 100%
Accuracy CAPA closed with effectiveness evidence 100%
Effectiveness Non-conformities recurring within the cycle Declining; 0 majors
Effectiveness CAPA overdue at management review Fewer than 10% of open items
Experience Auditees reporting the audit was useful to running their process, post-audit survey 80%

8. Change control

Date Version Change Reason Approved by
2026-09-02 0.1 Initial draft IoL administrative pack draft, unapproved