ANSI/ASIS PAP.1-2012 Physical Asset Protection
Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection

ANSI/ASIS PAP.1-2012 Physical Asset Protection A.8.5: A.8.5 Internal audit of the PAPMS

The organization should keep procedures for PAPMS audits at planned intervals and at other times top management decides. Audits should check whether the PAPMS meets this standard, meets the legal and regulatory requirements of the jurisdiction, has been properly put in place and kept up, and has been effective in reaching the PAP policy and objectives. The audit procedures should set responsibilities and requirements for planning, conducting, reporting and keeping records; set the audit criteria and scope, how often and by what methods audits run, and the competence, accountability and responsibility of those involved; make sure results reach the management of the audited area; and keep documented evidence of results. Auditors should be chosen and audits run so the process is objective and impartial.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 28000:2022 · 2 controls

  • 9.2.1 General: internal audits
  • 9.2.2 Internal audit programme
  • 4.5.5 4.5.5 Planned internal audits by objective auditors with follow-up verification

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A: The management system (guidance for incorporation into SPC.1-2009) – ANSI/ASIS PAP.1-2012 Physical Asset Protection

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.