At planned intervals, the organization carries out internal audits to establish whether the quality management system meets the planned and documented arrangements, the requirements of the standard, the requirements the organization has set for its own system, and the applicable regulatory requirements, and whether it is implemented and maintained effectively. A documented procedure sets out who is responsible for planning and carrying out audits and for recording and reporting their results, and what those activities involve. The audit programme is planned taking into account how important and how sound the processes and areas to be audited are, and what earlier audits found. The criteria, scope, frequency and methods of each audit are defined and recorded. Auditors are chosen, and audits are carried out, in a way that keeps the audit process objective and impartial, and no auditor audits their own work. Audit records and results are kept, and they identify which processes and areas were audited and what was concluded. The management responsible for the area audited makes sure any corrections and corrective actions needed are taken promptly, and follow-up activities check the actions taken and report the results of that check.
This control maps to 38 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 38 it maps to, and the evidence behind each claim, over MCP and REST.