ISO 19011:2018
Conducting an audit – ISO 19011:2018

ISO 19011:2018 6.4.6: Reviewing documented information while conducting audit

Guidance: during the audit, the documented information of the auditee that is relevant should be examined to determine conformity of the system as documented with the criteria and to gather information for the audit activities; the review may be combined with other activities and continue throughout the audit provided it does not impair effectiveness. Where the auditee cannot supply adequate documented information within the time the plan allows, the leader should inform the programme manager and auditee and a decision made whether to continue or suspend the audit until the concern is resolved.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 12 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27018:2019 · 2 controls

  • 16.1.2 Reporting information security events
  • 5.1.2 Review of the policies for information security

ISO 37301:2021 · 2 controls

  • 7.5.2 Creating and updating documented information
  • 7.5.3 Control of documented information

ISO 13485:2016 · 1 control

ISO 14001:2015 · 1 control

  • 7.5.3 Control of documented information

ISO 14004:2016 · 1 control

  • 7.5.3 Control of documented information

ISO 22000:2018 · 1 control

  • 7.5.3 Control of documented information

ISO 22301:2019 · 1 control

  • 7.5.3 Control of documented information

ISO 27701:2019 · 1 control

  • 6.2.1 Management direction for information security

ISO 37001:2016 · 1 control

  • 7.5.3 7.5.3 Control of documented information

ISO 45001:2018 · 1 control

  • 7.5.3 Control of documented information

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Conducting an audit – ISO 19011:2018

Query this from an agent

The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.