ISO 19011:2018
Conducting an audit – ISO 19011:2018

ISO 19011:2018 6.3.1: Performing review of documented information

Guidance: the auditee's relevant management system documented information should be reviewed to gather information for understanding its operations and preparing audit activities and work documents, and to get a picture of how extensive the documentation is so as to judge possible conformity and detect deficiencies, omissions or conflicts. It should include system documents and records and previous audit reports, and take account of the auditee's size, nature, complexity and risks and opportunities and of the audit scope, criteria and objectives.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 12 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 37301:2021 · 2 controls

  • 7.5.2 Creating and updating documented information
  • 7.5.3 Control of documented information

ISO 14001:2015 · 1 control

  • 7.5.3 Control of documented information

ISO 14004:2016 · 1 control

  • 7.5.3 Control of documented information

ISO 22000:2018 · 1 control

  • 7.5.3 Control of documented information

ISO 22301:2019 · 1 control

  • 7.5.3 Control of documented information

ISO 27002:2022 · 1 control

  • 8.33 Test information

ISO 27018:2019 · 1 control

  • 9.3.1 Use of secret authentication information

ISO 37001:2016 · 1 control

  • 7.5.3 7.5.3 Control of documented information

ISO 45001:2018 · 1 control

  • 7.5.3 Control of documented information

ISO 9001:2015 · 1 control

  • 7.5.3 Control of documented information

ISO/IEC 42001:2023 · 1 control

  • 7.5.3 Control of documented information

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Conducting an audit – ISO 19011:2018

Query this from an agent

The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.