ISO 14004:2016
Performance evaluation – ISO 14004:2016

ISO 14004:2016 9.2: Internal audit

Guidance: internal audits should take place at planned intervals to tell management whether the system meets the arrangements planned for it and is properly implemented and kept up, and to identify improvement opportunities. An audit programme should direct the planning and conduct of audits, with frequency based on the nature of operations, aspects and impacts, risks and opportunities, previous audit results and other factors such as changes, monitoring results and past emergencies, and should take in outsourced processes whose controls include audit provisions. The programme can span one or more years and audits need not each cover the whole system provided all units, functions, elements and the full scope are audited periodically. Audit planning and conduct should be in the hands of objective and impartial auditors or teams, aided by technical experts where appropriate, with collective competence sufficient for the audit objective and scope. Results can be reported to correct or prevent nonconformities and as input to management review. Documented information should be kept to show that the programme was implemented and what the audits found (ISO 19011 gives auditing guidance).

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 42 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 19011:2018 · 6 controls

  • 5.5.2 Defining the objectives, scope and criteria for an individual audit
  • 6.2 Initiating audit
  • 6.2.2 Establishing contact with auditee
  • 6.2.3 Determining feasibility of audit
  • 6.3.3 Assigning work to audit team
  • 6.6 Completing audit
  • 4.5.5 Internal Audit
  • SPC1-4.5.6 Internal Audit

ISO 14001:2015 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme
  • ISO-37002-9.2 Internal audit
  • ISO37002-9.2 Internal Audit

ISO 37301:2021 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme
  • ISO-39001-9.2 Internal audit
  • ISO39001-9.2 Internal Audit
  • ISO-41001-9.2 Internal audit
  • ISO41001-9.2 Internal Audit

ISO 45001:2018 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme
  • ISO-50001-9.3 Internal audit
  • 9.2 Internal audit

ISO 56002 · 2 controls

  • ISO-56002-9.2 Internal audit
  • ISO56002-9.2 Internal audit

ISO/IEC 27003:2017 · 2 controls

  • CPS220-11 Annual Audit Review of the Framework
  • AS9100D-9.2 Internal Audit

ISO 13485:2016 · 1 control

ISO 22000:2018 · 1 control

  • 9.2 Internal audit

ISO 22301:2019 · 1 control

  • 9.2 Internal audit

ISO 27001:2022 · 1 control

  • 9.2.2 Internal audit programme

ISO 27701:2019 · 1 control

  • ISO28001-4.17 Internal audit

ISO 30401 · 1 control

  • ISO30401-9.2 Internal audit

ISO 37001:2016 · 1 control

  • 9.2 9.2 Internal audit

ISO 55001:2014 · 1 control

  • 9.2 Internal audit

ISO 9001:2015 · 1 control

  • 9.2 Internal audit

ISO/IEC 27031:2011 · 1 control

  • 27031-9.2 Internal Audit

ISO/IEC 42001:2023 · 1 control

  • 9.2 Internal audit

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Performance evaluation – ISO 14004:2016

Query this from an agent

The graph holds this control, the 42 it maps to, and the evidence behind each claim, over MCP and REST.