ISO 19011:2018
Managing an audit programme – ISO 19011:2018

ISO 19011:2018 5.4.1: Roles and responsibilities of the individual(s) managing the audit programme

Guidance: those managing the programme should establish its extent against the objectives and constraints; identify the internal and external issues, risks and opportunities that bear on it and act on them across audit activities; ensure audit team selection and overall competence by allocating roles, responsibilities and authority and by backing leadership as needed; establish the processes for coordinating and scheduling audits, setting objectives, scope and criteria, determining methods and selecting teams, evaluating auditors, communicating internally and externally, resolving disputes and handling complaints, following up audits and reporting to the client and interested parties; determine and provide resources; prepare and maintain documented information including programme records; monitor, review and improve the programme; communicate it to the client and relevant interested parties; and request the client's approval.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 12 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 2 controls

  • 5.3 Roles, responsibilities and authorities
  • 8.5 Exercise programme

ISO 37301:2021 · 2 controls

  • 5.3 Roles, responsibilities and authorities
  • 9.2.2 Internal audit programme

ISO 14001:2015 · 1 control

  • 9.2.2 Internal audit programme

ISO 27001:2022 · 1 control

  • 9.2.2 Internal audit programme

ISO 27002:2022 · 1 control

  • 8.18 Use of privileged utility programs

ISO 27018:2019 · 1 control

  • 9.4.4 Use of privileged utility programs

ISO 27701:2019 · 1 control

  • 6.9.1 Operational procedures and responsibilities

ISO 37001:2016 · 1 control

  • 5.3.1 5.3.1 Roles and responsibilities

ISO 45001:2018 · 1 control

  • 9.2.2 Internal audit programme

ISO/IEC 42001:2023 · 1 control

  • 5.3 Roles, responsibilities and authorities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Managing an audit programme – ISO 19011:2018

Query this from an agent

The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.