Guidance: the audit client should see that objectives are set for the programme, so that they steer how audits are planned and carried out, and that the programme is put into effect properly. Objectives should fit the strategic direction of the client and back up the policy and objectives of the management system, and can draw on interested party needs, characteristics of and changes to processes, products, services and projects, management system requirements, the need to evaluate external providers, the auditee's performance and maturity as shown by indicators, nonconformities, incidents and complaints, identified risks and opportunities, and previous audit results. Examples of objectives: identifying improvement opportunities, evaluating the auditee's capability to determine its context and its risks and opportunities, conforming to statutory, regulatory, commitment or certification requirements, maintaining confidence in external providers, determining continuing suitability, adequacy and effectiveness, and evaluating alignment of system objectives with strategic direction.
This control maps to 14 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 14 it maps to, and the evidence behind each claim, over MCP and REST.