ISO 19011:2018
Conducting an audit – ISO 19011:2018

ISO 19011:2018 6.6: Completing audit

Guidance: an audit ends once every planned activity is done, or at another point agreed with the client, for example where an unexpected situation prevented completion. The parties should agree whether documented information is kept or disposed of, in line with the programme and any requirements that apply. Unless the law requires it, neither the team nor the programme manager should reveal audit information or the report to anyone else without the client's and, where appropriate, the auditee's explicit approval, informing them promptly if disclosure is required. Lessons learned may point to risks and opportunities for both the programme and the auditee.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 13 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 14001:2015 · 2 controls

  • 7.2 Competence
  • 9.2 Internal audit

ISO 27701:2019 · 2 controls

  • 5.7.2 Internal audit
  • 6.15 Compliance

ISO 45001:2018 · 2 controls

  • 7.2 Competence
  • 9.2 Internal audit

ISO 13485:2016 · 1 control

ISO 14004:2016 · 1 control

  • 9.2 Internal audit

ISO 22000:2018 · 1 control

  • 9.2 Internal audit

ISO 37001:2016 · 1 control

  • 9.2 9.2 Internal audit

ISO 37301:2021 · 1 control

  • 9.2 Internal audit

ISO 55001:2014 · 1 control

  • 9.2 Internal audit

ISO/IEC 27007:2020 · 1 control

  • 27007-6.5 Completing the Audit

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Conducting an audit – ISO 19011:2018

Query this from an agent

The graph holds this control, the 13 it maps to, and the evidence behind each claim, over MCP and REST.