ISO 19011:2018
Managing an audit programme – ISO 19011:2018

ISO 19011:2018 5.5.3: Selecting and determining audit methods

Guidance: the people running the programme should choose methods that let each audit be carried out efficiently and effectively in line with what it sets out to do, what it covers and what it audits against. An audit may be carried out on site, remotely, or in a mix of the two, balanced with regard to the associated risks and opportunities. For joint audits by two or more auditing organizations the programme managers should agree the methods and their resourcing and planning implications; combined audits may be included where an auditee runs systems of different disciplines.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 12 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 31000:2018 · 2 controls

  • 5.5 Implementation
  • 6.5.2 Selection of risk treatment options

ISO 37301:2021 · 2 controls

  • 5.1.1 Governing body and top management
  • 7.5.2 Creating and updating documented information

ISO 10007:2017 · 1 control

ISO 13485:2016 · 1 control

  • 7.3.3 Design and development inputs

ISO 22000:2018 · 1 control

  • 8.4.2 Handling of emergencies and incidents

ISO 22301:2019 · 1 control

  • 8.3.3 Selection of strategies and solutions

ISO 27002:2022 · 1 control

  • 5.3 Segregation of duties

ISO 27005:2022 · 1 control

  • 6.5 Choosing an appropriate method

ISO 27018:2019 · 1 control

  • 6.1.2 Segregation of duties

ISO/IEC 23894:2023 · 1 control

  • 6.5.2 Selection of risk treatment options

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Managing an audit programme – ISO 19011:2018

Query this from an agent

The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.