ISO 19011:2018
Managing an audit programme – ISO 19011:2018

ISO 19011:2018 5.2: Establishing audit programme objectives

Guidance: the audit client should see that objectives are set for the programme, so that they steer how audits are planned and carried out, and that the programme is put into effect properly. Objectives should fit the strategic direction of the client and back up the policy and objectives of the management system, and can draw on interested party needs, characteristics of and changes to processes, products, services and projects, management system requirements, the need to evaluate external providers, the auditee's performance and maturity as shown by indicators, nonconformities, incidents and complaints, identified risks and opportunities, and previous audit results. Examples of objectives: identifying improvement opportunities, evaluating the auditee's capability to determine its context and its risks and opportunities, conforming to statutory, regulatory, commitment or certification requirements, maintaining confidence in external providers, determining continuing suitability, adequacy and effectiveness, and evaluating alignment of system objectives with strategic direction.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 14 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 14004:2016 · 3 controls

  • 6.2.2 Establishing environmental objectives
  • 6.2.3 Planning actions to achieve environmental objectives
  • 8.1.3 Establishing operational controls

ISO 14001:2015 · 2 controls

  • 6.2.1 Environmental objectives
  • 6.2.2 Planning actions to achieve environmental objectives

ISO/IEC 27007:2020 · 2 controls

  • 27007-5.1 Establishing the Audit Programme
  • 27007-5.2 Audit Programme Objectives

ISO 10005:2005 · 1 control

  • 5.4 Quality objectives

ISO 13485:2016 · 1 control

ISO 22000:2018 · 1 control

  • 5.2.1 Establishing the food safety policy

ISO 27701:2019 · 1 control

  • 7.4.4 PII minimization objectives

ISO 31000:2018 · 1 control

  • 5.4.5 Establishing communication and consultation

ISO 37001:2016 · 1 control

  • 8.9 8.9 Raising concerns

ISO 37301:2021 · 1 control

  • 8.2 Establishing controls and procedures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Managing an audit programme – ISO 19011:2018

Query this from an agent

The graph holds this control, the 14 it maps to, and the evidence behind each claim, over MCP and REST.