ISO 19011:2018
Managing an audit programme – ISO 19011:2018

ISO 19011:2018 5.5.2: Defining the objectives, scope and criteria for an individual audit

Guidance: each audit should be based on defined objectives, scope and criteria consistent with the programme objectives. Audit objectives may include determining the extent of conformity with the criteria, evaluating the system's capability to meet statutory, regulatory and other requirements, evaluating effectiveness in meeting intended results, identifying improvement opportunities, evaluating suitability and adequacy against the auditee's context and strategic direction, and evaluating the capability to set and achieve objectives and deal with risks and opportunities as its context changes. The scope covers locations, functions, activities, processes and the period audited. The criteria are the reference for conformity: the auditee's policies, processes and procedures; performance criteria, objectives among them; legal and regulatory requirements; the requirements of the management system; the auditee's context and risks and opportunities, sector codes or other planned arrangements. Changes to objectives, scope or criteria should be reflected in the programme and communicated, and multi-discipline audits should keep objectives, scope and criteria consistent across the programmes concerned.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 12 controls across 7 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 14001:2015 · 2 controls

  • 6.2.2 Planning actions to achieve environmental objectives
  • 9.2 Internal audit

ISO 27701:2019 · 2 controls

  • 5.2.3 Determining the scope of the information security management system
  • 5.7.2 Internal audit

ISO 31000:2018 · 2 controls

  • 6.3.2 Defining the scope
  • 6.3.4 Defining risk criteria

ISO 37001:2016 · 2 controls

  • 4.3 4.3 Determining the scope of the anti-bribery management system
  • 9.2 9.2 Internal audit

ISO/IEC 23894:2023 · 2 controls

  • 6.3.2 Defining the scope
  • 6.3.4 Defining risk criteria

ISO 14004:2016 · 1 control

  • 9.2 Internal audit

ISO 45001:2018 · 1 control

  • 9.2 Internal audit

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Managing an audit programme – ISO 19011:2018

Query this from an agent

The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.