Guidance: each audit should be based on defined objectives, scope and criteria consistent with the programme objectives. Audit objectives may include determining the extent of conformity with the criteria, evaluating the system's capability to meet statutory, regulatory and other requirements, evaluating effectiveness in meeting intended results, identifying improvement opportunities, evaluating suitability and adequacy against the auditee's context and strategic direction, and evaluating the capability to set and achieve objectives and deal with risks and opportunities as its context changes. The scope covers locations, functions, activities, processes and the period audited. The criteria are the reference for conformity: the auditee's policies, processes and procedures; performance criteria, objectives among them; legal and regulatory requirements; the requirements of the management system; the auditee's context and risks and opportunities, sector codes or other planned arrangements. Changes to objectives, scope or criteria should be reflected in the programme and communicated, and multi-discipline audits should keep objectives, scope and criteria consistent across the programmes concerned.
This control maps to 12 controls across 7 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.