Guidance: internal audits should take place at planned intervals to tell management whether the system meets the arrangements planned for it and is properly implemented and kept up, and to identify improvement opportunities. An audit programme should direct the planning and conduct of audits, with frequency based on the nature of operations, aspects and impacts, risks and opportunities, previous audit results and other factors such as changes, monitoring results and past emergencies, and should take in outsourced processes whose controls include audit provisions. The programme can span one or more years and audits need not each cover the whole system provided all units, functions, elements and the full scope are audited periodically. Audit planning and conduct should be in the hands of objective and impartial auditors or teams, aided by technical experts where appropriate, with collective competence sufficient for the audit objective and scope. Results can be reported to correct or prevent nonconformities and as input to management review. Documented information should be kept to show that the programme was implemented and what the audits found (ISO 19011 gives auditing guidance).
This control maps to 42 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 42 it maps to, and the evidence behind each claim, over MCP and REST.