ISO 19011:2018
Managing an audit programme – ISO 19011:2018

ISO 19011:2018 5.5.7: Managing and maintaining audit programme records

Guidance: those managing the programme should ensure records of audits are created, managed and kept so that they show the programme has been put into effect, with processes addressing their information security and confidentiality. Records relate to the programme (schedule, objectives and extent, risks and opportunities and issues, effectiveness reviews), to each audit (plans and reports, findings with their evidence, reports of nonconformities, corrections, corrective actions and reports on follow-up) and to the audit team (competence and performance evaluations, selection criteria and team formation, competence maintenance). Their form and detail should demonstrate the programme's objectives were achieved.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 12 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27017:2015 · 2 controls

  • 4.4 Managing information security risks in cloud services
  • 5.1 Management direction for information security

ISO 10005:2005 · 1 control

  • 5.7 Control of records

ISO 10006:2003 · 1 control

  • 5.3 Management reviews and progress evaluations

ISO 13485:2016 · 1 control

ISO 14001:2015 · 1 control

  • 9.2.2 Internal audit programme

ISO 27001:2022 · 1 control

  • 5.21 Managing information security in the information and communication technology (ICT) supply chain

ISO 27018:2019 · 1 control

  • 5.1 Management direction for information security

ISO 27701:2019 · 1 control

  • 6.2.1 Management direction for information security

ISO 37001:2016 · 1 control

  • 8.8 8.8 Managing inadequacy of anti-bribery controls

ISO 45001:2018 · 1 control

  • 9.2.2 Internal audit programme

ISO 9001:2015 · 1 control

  • 7.1.5 Monitoring and measuring resources

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Managing an audit programme – ISO 19011:2018

Query this from an agent

The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.