ISO 19011:2018
Managing an audit programme – ISO 19011:2018

ISO 19011:2018 5.1: General

Guidance: an audit programme should be established, addressing a single management system standard or several, or other requirements, audited separately or together, with an extent based on the auditee's size and nature and on the nature, functionality, complexity, risks and opportunities and maturity of the systems audited, paying particular attention to multiple sites and outsourced functions and scaling down for small organizations. In setting it up, account should be taken of what the auditee is trying to achieve as an organization, its external and internal issues, interested party needs and expectations, and information security and confidentiality requirements. Those managing it should protect the integrity of audits from undue influence, give priority to matters of higher inherent risk and lower performance, and be competent. The programme should record its objectives, its risks and opportunities and actions, the scope of each audit, the schedule, audit types, criteria, methods, criteria for selecting team members and relevant documented information, and should be monitored, measured and reviewed for improvement, following a Plan-Do-Check-Act flow.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 16 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 4 controls

  • 5.1 General
  • 6.1 General
  • 7.1 General
  • 8.1 General

ISO 31000:2018 · 3 controls

ISO 10005:2005 · 1 control

  • 5.1 General: what the quality plan should contain

ISO 10006:2003 · 1 control

  • 7.1 Product realization: General

ISO 10007:2017 · 1 control

ISO 13485:2016 · 1 control

  • 4.1 General requirements

ISO 14001:2015 · 1 control

ISO 14004:2016 · 1 control

  • 8.1.1 General guidance: Operational control

ISO 45001:2018 · 1 control

  • 6.1 General concepts

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Managing an audit programme – ISO 19011:2018

Query this from an agent

The graph holds this control, the 16 it maps to, and the evidence behind each claim, over MCP and REST.