ISO 19011:2018
Conducting an audit – ISO 19011:2018

ISO 19011:2018 6.4.7: Collecting and verifying information

Guidance: while the audit is running, information that bears on its objectives, scope and criteria, including where functions, activities and processes meet, should be gathered through suitable sampling and verified as far as practicable. Information can be accepted as audit evidence only if it has been verified to some extent, with professional judgement on the reliance placed on weakly verified information; evidence leading to findings should be recorded; and new or changed circumstances, risks or opportunities discovered should be addressed. Methods of collection include interviews, observations and review of documented information, following the typical process from sources of information through collection, verification, evaluation against criteria, findings and conclusions.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 12 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 37301:2021 · 2 controls

  • 7.5.2 Creating and updating documented information
  • 7.5.3 Control of documented information

ISO 13485:2016 · 1 control

  • 7.4.2 Purchasing information

ISO 14001:2015 · 1 control

  • 7.5.3 Control of documented information

ISO 14004:2016 · 1 control

  • 7.5.3 Control of documented information

ISO 22000:2018 · 1 control

  • 7.5.3 Control of documented information

ISO 22301:2019 · 1 control

  • 7.5.3 Control of documented information

ISO 27002:2022 · 1 control

  • 5.13 Labelling of information

ISO 27018:2019 · 1 control

  • 12.4.2 Protection of log information

ISO 37001:2016 · 1 control

  • 7.5.3 7.5.3 Control of documented information

ISO 45001:2018 · 1 control

  • 7.5.3 Control of documented information

ISO 9001:2015 · 1 control

  • 7.5 Documented information

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Conducting an audit – ISO 19011:2018

Query this from an agent

The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.