ISO 19011:2018
Conducting an audit – ISO 19011:2018

ISO 19011:2018 6.3.2: Audit planning

Guidance: the team leader should plan the audit on the basis of risk, using the programme information and the auditee's documented information, considering the risks of the audit to the auditee's processes and providing the basis for agreement among client, team and auditee on the conduct of the audit. Plan detail should reflect scope, complexity and the risk of not achieving the objectives, considering team composition and competence, sampling techniques, opportunities to improve effectiveness and efficiency, the risks to the objectives from ineffective planning, and the risks to the auditee from the audit's presence (health and safety, environment, quality, contamination). Combined audits need attention to interactions and competing priorities between systems. The plan should address or reference the objectives, scope including functions and processes, criteria and reference documents, physical and virtual locations, dates and durations including management meetings, familiarisation with facilities and processes, methods including the extent of sampling, roles of team members, guides, observers and interpreters, and resource allocation against the risks of the activities audited; and as appropriate the auditee's representatives, working and reporting language, report topics, logistics and communications, actions on risks and opportunities, confidentiality and information security, follow-up from previous audits, follow-up to this audit, and coordination for joint audits. The plan should be put to the auditee, with any issues settled with the leader, auditee and programme manager.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 14 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 13485:2016 · 2 controls

  • 5.3 Quality policy
  • 7.3.2 Design and development planning

ISO 14001:2015 · 2 controls

  • 3.2 Terms related to planning
  • 6.1.4 Planning action

ISO 14004:2016 · 2 controls

  • 3.2 Terms related to planning
  • 6.1.4 Planning action

ISO 31000:2018 · 2 controls

ISO 10005:2005 · 1 control

ISO 10007:2017 · 1 control

  • 5.2 Configuration management planning

ISO 27701:2019 · 1 control

ISO 9001:2015 · 1 control

  • 8.3.2 Design and development planning

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Conducting an audit – ISO 19011:2018

Query this from an agent

The graph holds this control, the 14 it maps to, and the evidence behind each claim, over MCP and REST.