National Aerospace University «Kharkiv Aviation Institute»

Regulations on the Planning and Conducting of Internal Audit

Regulation on Planning and Conducting Internal Audit at the National Aerospace University "Kharkiv Aviation Institute"

 

QMS KhAI-NMV-P/002:2019

Date of introduction: April 20, 2019

Revision No. 3

1. Purpose and Scope of Application

1.1 This regulation establishes uniform requirements regarding the process of internal audit of the quality management system and the internal quality assurance system of the National Aerospace University "Kharkiv Aviation Institute" (hereinafter referred to as the University), namely:

- basic principles of internal audits;

- requirements for internal auditors;

- procedure for planning, organizing, conducting internal audits, and formalizing the obtained results;

- list and description of methods for conducting internal audits;

- actions regarding the analysis of audit results and the procedure for implementing subsequent actions.

1.2 This regulation has been developed in accordance with the requirements of cl. 9.2 ISO 9001, DSTU ISO 9001, cl. 1.9 of the Standards and Guidelines for Quality Assurance in the European Higher Education Area, and cl. 9.2 of the Regulation "On the Quality Management System" QMS KhAI-NMV-P/010.

1.3 The requirements of this regulation apply to the activities of the University personnel regarding the planning, organization, conduct of internal audits, formalization of obtained results, and making managerial decisions after their analysis.

1.4 The requirements of this regulation do not apply to conducting other types of audits.

2. Normative References

These regulations contain references to the following normative documents:

1) QMS KhAI-NMV-F.IA/001 Form of the internal audit program;

2) QMS KhAI-NMV-F.IA/002 Form of the internal audit plan;

3) QMS KhAI-NMV-F.IA/003 Form of the checklist;

4) QMS KhAI-NMV-F.IA/004 Form of the nonconformity report;

5) QMS KhAI-NMV-F.IA/005 Form of the internal audit report protocol;

6) QMS KhAI-NMV-F.IA/006 Form of the consolidated plan of corrective actions and measures;

7) QMS KhAI-NMV-P/008:2019 Regulation "Management of Documented Information";

8) QMS KhAI-NMV-P/013:2019 Regulation "On the Quality Management System";

9) DSTU ISO 9001:2015 Quality management systems. Requirements (ISO 9001:2015, IDT);

10) DSTU ISO 19011:2012 Guidelines for auditing management systems (ISO 19011:2011, IDT);

11) Standards and Guidelines for Quality Assurance in the European Higher Education Area (ESG).

3. Terms and Definitions of Concepts

This Regulation applies the terms and definitions of concepts given in DSTU ISO 19011, namely:

3.1 audit - systematic, independent, and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which the audit criteria are fulfilled;

3.2 audit criteria - set of policies, procedures, or requirements used as a reference against which audit evidence is compared;

3.3 audit evidence - records, statements of fact, or other information which are relevant to the audit criteria and verifiable;

3.4 audit findings - results of the evaluation of the collected audit evidence against audit criteria. Audit findings can indicate conformity or nonconformity, or opportunities for improvement;

3.5 audit conclusion - outcome of an audit, provided by the audit team after consideration of the audit objectives and all audit findings;

3.6 audit client - organization or person requesting an audit;

3.7 auditee - organization being audited;

3.8 auditor - person who has the competence to conduct an audit;

3.9 audit program - arrangements for a set of one or more audits planned for a specific time frame and directed towards a specific purpose; an audit program includes all activities necessary for planning, organizing, and conducting audits;

3.10 audit plan - description of the activities and arrangements for an audit;

3.11 audit scope - extent and boundaries of an audit; audit scope generally includes a description of physical and virtual locations, organizational units, activities and processes, as well as the time period covered;

3.12 competence - ability to apply knowledge and skills to achieve intended results, demonstrating personal attributes;

3.13 risk - effect of uncertainty on objectives.

4. Abbreviations

The regulations use the following abbreviations:

QMS - Quality Management System;

F - Form;

ESG - Standards and Guidelines for Quality Assurance in the European Higher Education Area;

IA - Internal Audit.

5. Procedure Description

5.1 Inputs and outputs of the process

The internal audit process is carried out according to the scheme provided in Appendix A.

The inputs of the process are:

- QMS scope;

- list of processes;

- level of their impact on the University's activities and the functioning of the QMS;

- results of previous internal and external processes.

The outputs of the process are:

- internal audit program;

- internal audit plan;

- auditors' records (checklists);

- nonconformity reports;

- consolidated plan of corrective/preventive actions and results of verification of their implementation;

- internal audit reports;

- information for management review of the QMS regarding internal audit results.

5.2 Responsibility and Authority

5.2.1 The University Chief Quality Manager is responsible for ensuring that University personnel fulfill the requirements of the Regulation.

5.2.2 The Chief Auditor is responsible for audit planning, ensuring the effective operation of audit teams, resolving all conflicts arising during the audit, timely formalizing audit results, and monitoring the implementation and effectiveness of corrective actions.

5.2.3 The auditor is responsible for the conscientious and effective performance of their duties during the audit.

5.2.4 The head of the structural unit/process is responsible for informing subordinates about the goals and scope of the upcoming audit; assisting the audit team; and developing and implementing corrective/preventive actions.

5.2.5 The University Chief Quality Manager and the Chief Auditor have the authority to change the composition of the audit team during the audit and to intervene in the resolution of controversial issues.

5.2.6 The Head of the Office Work and Archive Department is responsible for the timely distribution of electronic copies of approved documents regarding internal audits and orders on their enactment.

5.3 General Provisions

5.3.1 Objectives of the Internal Audit

Internal audits at the University are conducted to achieve the following objectives:

- establishing the conformity of the University's quality management system and internal quality assurance system to the requirements of DSTU ISO 9001, ESG, and internal documentation requirements;

- evaluating the effectiveness and efficiency of its implementation and maintenance;

- determining opportunities and means for improving the processes of the University's quality management system and internal quality assurance system.

5.3.2 Audit Objects

The objects of the internal audit of the quality management system and internal quality assurance system are the activities of the units regarding the implementation and ensuring the functioning of the processes of these systems.

5.3.3 Types of Audit

5.3.3.1 Planned Audits

Planned audits are conducted in accordance with the approved annual internal audit program.

5.3.3.2 Unplanned Audits

Unplanned audits are conducted on the basis of an order by the University Rector in the event of any reasons, such as:

- changes in the organizational structure;

- problems with the quality of educational services;

- changes in the requirements of regulatory and regulatory-administrative documents;

- results of inspections by external regulatory bodies/institutions;

- changes in the requirements and expectations of interested parties;

- at the initiative of process owners and others.

5.3.4 Basic Principles of QMS Internal Audit

In accordance with section 4 of the DSTU ISO 19011 standard, during internal audits of the quality management system and internal quality assurance system, auditors adhere to the following basic principles:

- integrity - the foundation of professionalism;

- fair presentation (impartiality) - the obligation to report truthfully and accurately;

- due professional care - exercising diligence and reasoned judgment in audit;

- confidentiality - security of information;

- independence - the basis for the impartiality of the audit and the objectivity of audit conclusions;

- evidence-based approach - a rational method for forming reliable and reproducible audit conclusions in a systematic audit process.

5.3.5 Requirements for Internal Auditors

5.3.5.1 The internal audit team is formed from University employees.

5.3.5.2 The composition of the internal audit team is formed annually by the Chief Auditor by January 15 of the current year, agreed upon by the Chief Quality Manager, and approved by the University Rector via a relevant order.

5.3.5.3 The qualification requirements for internal auditors take into account personal attributes and the ability to apply knowledge and skills. The qualification requirements are as follows:

1) knowledge and skills:

- higher education;

- general work experience at the University of at least two years;

- training in an amount ensuring knowledge of general quality management principles (basic principles, terminology, tools), the requirements of ISO 9000 and DSTU ISO 9000 series standards, as well as knowledge of audit methods and procedures;

- maintenance of competence - continuous professional development in the field of quality, including maintaining the ability to conduct audits through continuous participation in internal audits;

2) personal attributes, in particular, auditors must be:

- ethical, i.e., fair, truthful, sincere, honest, and discreet;

- open-minded, i.e., willing to consider alternative ideas or points of view;

- diplomatic, i.e., tactful in dealing with people;

- observant, i.e., actively observing the physical surroundings and activities;

- perceptive, i.e., instinctively aware of and understanding situations;

- versatile, i.e., able to readily adapt to different situations;

- tenacious, i.e., persistent and focused on achieving objectives;

- decisive, i.e., reaching timely conclusions based on logical reasoning and analysis;

- self-reliant, i.e., able to act and function independently while interacting effectively with others;

- steadfast, i.e., acting responsibly and ethically, even though these actions may not always be popular and may sometimes result in disagreement or confrontation;

- open to improvement, i.e., willing to learn from situations and striving for better audit results;

- collaborative, i.e., effectively interacting with others, including audit team members and the auditee's personnel.

5.3.5.4 To ensure the objectivity and quality of internal audits, the University Chief Quality Manager and the Chief Auditor evaluate internal auditors during their appointment and the formation of audit teams. The following methods are used during the evaluation:

- interview;

- observation;

- review of documentation;

- feedback review from colleagues and heads of units where the internal audit was conducted, and others.

5.3.6 Stages of Internal Audit

The internal audit process includes the following stages:

- planning the internal audit;

- conducting the internal audit;

- verifying the implementation of actions following the audit;

- improving the audit program.

The block diagram of the internal audit process is given in Appendix A.

5.3.7 Risks and Actions for Their Prevention

A list of potential risks that may arise during the stages of internal audit and actions to prevent them are given in Table 1.

Table 1 - List of Potential Risks

Risks

Actions to prevent risks

Stage 1 Planning the internal audit

The objectives and scope of the audit program do not comply with the University's strategic development plan

Before agreement and approval, the audit program must be checked for compliance with the University's strategic development plan

The audit calendar schedule is compiled incorrectly (without taking into account the educational process schedule, previous audit results, and/or the workload characteristics of structural units during the year)

Before agreement and approval, the audit program must be checked for compliance with the educational process schedule, previous audit results, and/or the workload characteristics of structural units during the year

The planned amount of resources is insufficient

When planning resources, previous experience, objectives, and the scope of the audit program should be taken into account

Violation of the audit program approval procedure

Conduct additional briefing for persons who approve the audit program, explaining its objectives and scope

The audit program has not been communicated to the personnel

Review and improve the personnel informing process

Stage 2 Conducting the internal audit

The audit plan does not comply with the audit program

Before agreement and approval, the audit plan must be checked for compliance with the audit program

The audit plan has not been communicated to the personnel

Review and improve the personnel informing process

Insufficiently competent auditors

Review and improve the criteria for selecting auditors. Conduct additional training for auditors

Obstacles from the personnel of the audited unit

Brief University personnel regarding the internal audit process, explaining the principles and objectives of the audit, as well as the functions, duties, and responsibilities of the participants in this process

Violation of the audit procedure

Brief University personnel regarding the internal audit process, explaining the principles and objectives of the audit, as well as the functions, duties, and responsibilities of the participants in this process

The obtained results are not sufficiently complete and objective

Conduct additional briefing for auditors regarding the principles and objectives of the audit

Nonconformities are not aligned with audit criteria and are unclear

Conduct additional briefing for auditors regarding the formulation of nonconformities

Causes of nonconformities and corrective actions are determined incorrectly

Conduct additional briefing for heads of University structural units regarding the rules for determining corrective actions

Stage 3 Verifying the implementation of actions following the audit

Corrective actions are not implemented or implemented with a violation of the established deadline

Monitor the implementation of corrective actions. Clarify to the unit the necessity of carrying them out.

Risks

Actions to prevent risks

Verification of the implementation of actions following the audit is conducted after the expiration of the established deadline

Develop the action plan based on audit results taking into account the educational process schedule and previous audit experience, and monitor its implementation

Stage 4 Improving the audit program

The introduced changes are insufficient

Before agreement and approval of changes to the audit program, evaluate their impact on achieving audit objectives

Violation of the approval procedure for changes to the audit program

Conduct additional briefing for persons who approve the audit program, explaining the introduced changes

Changes made to the audit program have not been communicated to the personnel

Review and improve the personnel informing process

5.4 Process Description

5.4.1 Planning of Internal Audits

5.4.1.1 Annually, by January 15 of the current year, the Lead Auditor plans the conduct of internal audits, draws up the internal audit plan (Appendix B) and program, and formats them in accordance with QMS form QMS KhAI-NMV-F.VA/001 (Appendix C).

5.4.1.2 The internal audit program contains:

- objectives of the internal audit program;

- scope of the internal audit program;

- schedule for inspecting the University's structural units;

- assignment of responsibilities for implementing the audit program measures;

- resources required to conduct internal audits.

5.4.1.3 Internal audits are planned depending on the results of previous internal and external audits, the importance of the processes being audited, and changes affecting the University's activities, but in such a way that every structural unit of the University is covered.

5.4.1.4 By January 15 of the current year, the Lead Auditor submits the formatted audit program for approval to the University's Chief Quality Manager and the heads of the structural units/processes scheduled for internal audits in the current year. The program coordination process takes five working days.

5.4.1.5 By January 25 of the current year, the Chief Quality Manager submits the agreed internal audit program to the University Rector for approval. The internal audit program is approved by the University Rector and enacted by their university-wide order.

5.4.1.6 The Chief Quality Manager communicates the approved audit program to the heads of structural units/processes at the February meeting of the University Academic Council.

5.4.1.7 Within one working day after the meeting, the Head of the Records Management and Archive Department organizes the distribution of its electronic copy and the approval order via corporate email to the heads of units/processes and interested parties determined by the Lead Auditor.

5.4.1.8 A scanned copy of the approved audit program is posted on the official website of the University within one working day after the meeting. The Head of the Educational Media and Technology Department ensures its timely posting on the University's website.

5.4.1.9 Heads of structural units/processes are required to familiarize employees with the approved internal audit program at the next meeting of the University Academic Council or unit meeting following the February one.

5.4.1.10 If necessary, the Lead Auditor makes changes to the audit program, which are coordinated with the University's Chief Quality Manager and the heads of structural units/processes scheduled for the audit, approved by the University Rector, and enacted by their order.

5.4.1.11 Changes to the audit program are communicated to the heads of structural units/processes at the meeting of the University Academic Council.

5.4.1.12 Within one working day after the meeting, the Head of the Records Management and Archive Department organizes the distribution of the electronic copy of the changes and the approval order via corporate email to the heads of units/processes and interested parties determined by the Lead Auditor.

5.4.1.13 A scanned copy of the approved changes to the audit program is posted on the official website of the University within one working day after the meeting. The Head of the Educational Media and Technology Department ensures its timely posting on the University's website.

5.4.1.14 Heads of structural units/processes are required to familiarize employees with the approved changes to the internal audit program at the next unit meeting following the relevant meeting of the University Academic Council or unit meeting.

5.4.2 Preparation for Internal Audits

5.4.2.1 Selection and Appointment of Audit Teams

5.4.2.1.1 When drafting the audit program, the Chief Quality Manager appoints the leaders of audit teams for a specific audit and, together with the Lead Auditor, selects the composition of the audit teams taking into account the necessary competence to achieve the objectives.

5.4.2.1.2 When selecting the audit team, the Chief Quality Manager and the Lead Auditor shall be guided by the recommendations set out in Clause 7 of DSTU ISO 19011, and also take into account the following:

- audits shall be conducted by personnel independent of the activity being audited to ensure the principle of independence;

- an audit may be conducted by a single auditor, in which case they perform all the duties of a team leader.

5.4.2.1.3 The composition of the audit team is determined depending on the objectives and scope of the specific audit.

5.4.2.1.4 Functions, duties, and responsibilities among the members of the audit team are distributed by the team leader.

5.4.2.2 Preparation of the Internal Audit Plan

5.4.2.2.1 The internal audit plan is drawn up by the audit team leader with the assistance of the specialists included in the team, taking into account the internal audit program within which the audit is conducted.

5.4.2.2.2 The plan shall be flexible and adaptable to the conditions of conducting the internal audit; if nonconformities in activities or documentation not subject to verification according to the plan are revealed during the audit, the scope of the audit (as well as the plan itself) may be expanded.

The audit plan is formatted in accordance with QMS form QMS KhAI-NMV-F.VA/002, the structure of which is given in Appendix C.

5.4.2.2.3 The internal audit plan contains:

- audit objectives;

- audit scope - identification of structural units, processes, and documents to be verified;

- audit criteria - a list of documents regulating the requirements for the processes being verified and references to them;

- type of audit (planned/unplanned);

- date, time, and location of audit stages, as well as their probable duration;

- composition of the audit team, data on the accompanying person/unit representative (if necessary).

5.4.2.2.4 The internal audit plan is agreed upon by the Chief Quality Manager, the Lead Auditor, and the head(s) of the respective structural unit(s)/process(es), approved by the University Rector, and enacted by their order.

5.4.2.3 Actions Prior to Audit Commencement

5.4.2.3.1 Prior to the audit, the auditors shall review the documentation regulating the processes being verified and prepare the working documents necessary for recording the audit results, including supporting materials:

- checklists (QMS KhAI-NMV-F.VA/003 - the form is given in Appendix D);

- nonconformity report forms (QMS KhAI-NMV-F.VA/004 - the form is given in Appendix E).

The use of pre-formed checklists, defined forms, and other supporting materials during the audit does not restrict the ability of auditors to change the scope of the internal audit. Therefore, depending on the data gathered during the audit, its plan may be modified.

5.4.2.3.2 No later than ten calendar days before the audit, the Lead Auditor shall arrange for the head(s) of the respective structural unit(s) to be informed of the schedule and scope of the audit. This notification is ensured by the Head of the Records Management and Archive Department by sending electronic copies of the audit order and the audit plan via corporate email to the heads of units/processes and interested parties determined by the Lead Auditor.

5.4.2.3.3 Upon receiving the notification, the head(s) of the unit(s)/process(es) to be verified:

- inform(s) the unit staff of the upcoming audit, its objectives, and scope;

- appoint(s) a responsible employee to accompany the members of the audit team (if necessary);

- provide(s) the audit team with a workspace (if necessary) and access to required information.

Note. Due to operational necessity, the process/unit head may initiate a change in the timing or date of the audit. In this regard, at least 15 calendar days prior to the scheduled audit date, they must submit a memo to the Lead Auditor explaining the reasons for changing the timing or date of the audit. The Lead Auditor must make a decision regarding the change of audit schedule within two working days and coordinate the decision with the Chief Quality Manager, which is indicated on the submitted memo. If a decision is made to change the audit schedule, the Lead Auditor shall develop changes to the audit program within one working day, coordinate them with the Chief Quality Manager, and submit them to the University Rector for approval. Changes to the internal audit program are approved by the Rector, enacted by their order, and communicated to the relevant process/unit head via corporate email correspondence.

5.4.2.4 When conducting particularly significant and critical audits, an initial joint meeting between the audit team and the management of the respective unit(s) may be held to review and confirm future arrangements according to the audit plan.

5.4.3 Conducting the Internal Audit

5.4.3.1 The audit begins with an opening meeting of the audit team with the head of the process/unit to be audited. The opening meeting is held to:

a) confirm the audit plan;

b) briefly explain the audit activities;

c) confirm communication channels;

d) provide the head of the process/unit to be audited with an opportunity to ask questions.

5.4.3.2 During the verification, the auditor's task is to obtain sufficient information to draw substantiated conclusions.

Methods for gathering information during an internal audit include:

- interviewing (surveying) personnel;

- reviewing regulatory documents;

- observing the activities of employee(s).

5.4.3.3 When nonconformities are identified, a report shall be issued for each in accordance with form QMS KhAI-NMV-F.VA/004, the structure of which is given in Appendix E. Nonconformities are classified according to their level of impact on the functioning of QMS processes as follows:

- critical nonconformity - failure to fulfill a specified requirement that is highly likely to negatively affect the quality of educational services and the functioning of the QMS. A critical nonconformity must be eliminated in the shortest possible time;

- non-critical nonconformity - failure to fulfill a specified requirement that may negatively affect the quality of educational services and the functioning ofсил the QMS. A non-critical nonconformity may subsequently lead to a major nonconformity if not eliminated;

- observation - failure to fulfill a specified requirement that does not negatively affect the quality of educational services and the functioning of the QMS (for example, typos in text or document formatting).

5.4.3.4 The nonconformity shall be analyzed jointly with the representative of the unit being verified to ensure the correctness of the conclusion and to reconcile any discrepancies; unresolved issues shall be recorded in the report.

5.4.3.5 Reports on identified nonconformities shall be agreed upon with the head of the unit being verified.

5.4.3.6 Upon identifying nonconformities, the head of the unit being verified shall immediately formulate corrective/preventive actions, determine the deadlines for their implementation, and assign responsible persons (executors). These data shall be entered into the report and agreed upon with the auditor. The report shall be submitted to the Lead Auditor, and a copy thereof shall remain at the unit being verified.

5.4.4 Completion of the Internal Audit

5.4.4.1 Upon completion of the verification of the unit/process, the audit team shall hold a closing meeting with the head of the process/unit being audited to present the audit results and conclusions drawn therefrom.

5.4.4.2 Upon completion of the audit, the Lead Auditor together with the audit team shall perform the following actions:

- analyze the data gathered during the audit regarding the achievement of the audit objectives;

- form conclusions on the degree of conformity of the verified object to the audit criteria and the effectiveness of the processes being verified;

- reconcile the obtained data;

- prepare recommendations for improving the activities of the respective unit or process;

- consider the advisability of a follow-up audit;

- determine actions regarding the form of control over the implementation of corrective/preventive actions.

5.4.4.3 Based on the results obtained, an Internal Audit Report shall be prepared in accordance with form QMS KhAI-NMV-F.VA/005, the structure of which is given in Appendix F, and, if necessary, a consolidated plan for the implementation of corrective and preventive actions (QMS KhAI-NMV-F.VA/006 - the form is given in Appendix G).

Note. Depending on the objectives and scope of the audit, the internal audit report form may be supplemented with additional information.

5.4.4.4 The internal audit report and the consolidated plan for the implementation of corrective and preventive actions shall be drawn up by the Lead Auditor, agreed upon with the head(s) of the structural unit(s) being audited, and approved by the Chief Quality Manager within five working days after the audit.

5.4.4.5 Following the approval of the internal audit report and the consolidated plan for the implementation of corrective and preventive actions, electronic copies thereof shall be subject to mandatory distribution within five working days by the Head of the Records Management and Archive Department via corporate email to all interested parties (heads of units/processes, the Chief Quality Manager, and the University Rector) determined byсил the Lead Auditor.

5.4.5 Verification of Actions Following Audit Results

5.4.5.1 Upon completion of corrective actions, the head of the respective unit shall report thereon toсил the Lead Auditor. Following the audit, the Lead Auditor shall ensure the verification of the implementation of corrective/preventive actions and the evaluation of their effectiveness. After the verification,сил the Lead Auditor shall confirm the elimination of the nonconformity by signing and dating the "Nonconformity" report and send a notification of report closure to the University's Chief Quality Manager.

5.4.5.2 Closed nonconformity reports shall be attached to the respective internal audit reports, which are kept by the Lead Auditor.

5.4.5.3 Verification of the implementation of actions to eliminate observations may be carried out during the next audit.

5.4.6 Improvement of the Audit Program

5.4.6.1 Based on audit data, the Lead Auditor shall submit a report on the implementation of the internal audit program to the University's Chief Quality Manager.

5.4.6.2 Based on audit data, the Lead Auditor and the University's Chief Quality Manager shall analyze the effectiveness of the audit process and, based on the analysis results, adjust the internal audit program.

During the analysis, the following process evaluation criteria shall be used:

- timely implementation of corrective actions;

- absence of similar observations identified during previous audits;

- number of unplanned and follow-up audits.

6. Measurement and Monitoring

Compliance with the requirements of the Regulations is monitored during internal and external QMS audits and management reviews of the quality management system.

Evaluation criteria:

- the ratio of the number of planned internal audits conducted during the year to the number of scheduled internal audits during the reporting period;

- the ratio of the number of unplanned internal audits conducted during the year toсил the number of scheduled internal audits during the reporting period;

- the total number of identified nonconformities and observations in the reporting period;

- the number of nonconformities and observations repeatedly identified in the unit/process verified during the reporting period.

7. Records

7.1 Internal Audit Program

7.1.1 Identification

Each internal audit program is assigned an identification number consisting of a sequential number and the year for which it is planned.

7.1.2 Retention

The approved internal audit program is kept by the Lead Auditor during the current year.

Upon expiration of the retention period, the internal audit program is transferred for storage to the Educational and Methodological Department, where it is kept for three years. Then, under a transfer acceptance certificate, it is handed over to the University Archive, where it is kept for five years.

7.2 Internal Audit Plan

7.2.1 Identification

Each internal audit plan is assigned an identification number consisting of a sequential number and the year for which the audit is planned.

7.2.2 Retention

The approved internal audit plan is kept by the Lead Auditor during the current year.

Upon expiration of the retention period, the internal audit plan is transferred for storage to the Educational and Methodological Department, where it is kept for three years. Then, under a transfer acceptance certificate, it is handed over to the University Archive, where it is kept for five years.

7.3 Checklist

7.3.1 Identification

The checklist is formatted in accordance with the form given in Appendix D and is assigned an identification number consisting of the abbreviated name of the unit where the audit is to be conducted, the audit date, and a sequential number.

7.3.2 Retention

The completed checklist is kept by the auditor who conducted the audit during the current year.

Upon expiration of the retention period, the checklist is transferred for storage to the Educational and Methodological Department, where it is kept for three years.

7.4 Nonconformity Report

7.4.1 Identification

The nonconformity report is formatted in accordance with the form given in Appendix E and is assigned an identification number consisting of the abbreviated name of the unit where the nonconformity was identified, the audit date, and a sequential number.

7.4.2 Retention

The approved nonconformity report is kept by the Lead Auditor during the current year.

Upon expiration of the retention period, the nonconformity report is transferred for storage to the Educational and Methodological Department, where it is kept for three years. Then, under a transfer acceptance certificate, it is handed over to the University Archive, where it is kept for five years.

7.5 Internal Audit Report

7.5.1 Identification

The internal audit report shall be formatted in accordance with the form given in Appendix F and assigned an identification number consisting of a sequential number and the year in which the audit was conducted. The identification number of the internal audit report must be identical to the identification number of the corresponding internal audit plan.

7.5.2 Retention

The approved internal audit report is kept byсил the Lead Auditor during the current year.

Upon expiration of the retention period, the internal audit report is transferred for storage to the Educational and Methodological Department, where it is kept for three years. Then, under a transfer acceptance certificate, it is handed over to the University Archive, where it is kept for five years.

7.6 Consolidated Plan for the Implementation of Corrective and Preventive Actions

7.6.1 Identification

The consolidated plan for the implementation of corrective and preventive actions shall be formatted in accordance with the form given in Appendix G and assigned an individual identification number consisting of a sequential number and the year in which the audit was conducted. The identification number of the internal audit report must be identical to the identification number of the corresponding internal audit plan. Additionally, the normative document(s) whose requirements were verified and the dates when the audit was conducted shall be indicated.

7.6.2 Retention

The approved consolidated plan for the implementation of corrective and preventive actions is kept by the Lead Auditor during the current year.

Upon expiration of the retention period, the consolidated plan for the implementation of corrective and preventive actions is transferred for storage to the Educational and Methodological Department, where it is kept for three years. Then, under a transfer acceptance certificate, it is handed over to the University Archive, where it is kept for five years.

Control over the records specified in these Regulations shall be exercised in accordance with QMS Regulations QMS KhAI-NMV-P/008.

8. Final Provisions

8.1 These Regulations shall be signed by the University Lead Auditor, approved by the University Rector, and enacted by their order.

8.2 Control over the implementation of these Regulations shall be exercised by the University Chief Quality Manager.

8.3 Amendments and additions to these Regulations shall be reviewed by the University Chief Quality Manager, approved by the University Rector, and enacted by their order.

 

Appendix A

Flowchart of the Internal Audit Process

Appendix B

Internal Audit Plan Form

Appendix C

Internal Audit Program Form

Appendix D

Checklist Form

Appendix E

Nonconformity Report Form

Appendix F

Internal Audit Report Form

 

Appendix G

Form of the Consolidated Plan for Corrective Actions and Measures