In short: A risk-based internal audit programme allocates audit time according to the importance of processes, their performance, recent changes and previous results, as recommended by ISO 19011:2018.
Why move to a risk-based programme?
Auditing everything equally wastes resources on low-risk areas and may miss the processes where failures would hurt most.
What inputs should drive the programme?
- Process criticality to customers and compliance
- Performance data: complaints, nonconformities, KPIs
- Changes: new products, systems, sites or people
- Results of previous audits
- Interested-party concerns
How do you keep it effective?
Review the programme at least annually in management review and adjust frequency and depth as risks change.
Key takeaways
- Allocate audit effort where risk is highest.
- Use data and change as triggers for audits.
- Review the programme regularly.
Frequently asked questions
Does ISO 9001 require every clause to be audited annually?
No. It requires planned audits taking into account the importance of processes, changes and previous results.
Who approves the audit programme?
Typically the audit programme manager, with oversight from top management.
What is audit programme risk?
The risk that the audit programme fails to meet its objectives, for example due to lack of competent auditors.