Knowella

Audit Plan

The recurring failure is the plan written after the audit already happened — a document produced to justify a walk-through that was never really planned, with sample size, sampling basis and the unannounced element filled in as an afterthought. Once the plan follows the visit instead of leading it, the auditee decides what gets shown, and the audit stops testing anything the site did not already choose to reveal.

KnowComplyPlanCMP-003Pinned in navigation42 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 19011 cl.6.2
Workspace
KnowComply
Form type
Plan
Completed by
Lead auditor, before the audit begins
Review trigger
One plan per scheduled audit, issued in advance

The short version

  • An audit plan fixes scope, criteria, sample size and schedule before an auditor sets foot on the floor, so the auditee cannot steer the audit once it has started.
  • ISO 19011 cl.6.2 expects the plan to be communicated and reviewed before use; this template records that as Plan Accepted rather than leaving it implied.
  • Sampling Basis scores Statistical and Risk based well above Convenience, and Unannounced Element scores Yes at 3 against No at 0 — the form is built to reward planning that cannot be gamed by the auditee.
  • The plan connects forward into the audit record and back into the programme: Programme ID links to CMP-001 and the schedule block feeds directly into what CMP-002 later reports against.

What this is

What is an audit plan?

What is an audit plan?

An audit plan is the document that fixes an audit's objectives, scope, criteria, sampling approach and schedule before any auditor arrives on site. It is prepared by the lead auditor, issued to the auditee in advance, and accepted before the audit starts. Under ISO 19011 cl.6.2 it is the single artefact that turns one line of the annual audit programme into a workable, defensible exercise.

What's the difference between an audit plan and an audit programme?

The programme (CMP-001) is the year's schedule: which processes, sites and standards get audited, when, and by whom, set once and reviewed periodically. The plan (this template) is a single instance of that schedule turned into a working document — the specific objectives, sample size, unannounced element and logistics for one audit visit. A programme can generate a dozen plans; a plan cannot exist without a programme line behind it.

What does ISO 19011 clause 6.2 actually require in an audit plan?

Clause 6.2 requires the lead auditor to establish objectives, confirm scope and criteria, decide the audit method including sampling and any unannounced elements, assign roles to the audit team, and allocate resources — access, escort, PPE, interpreters — needed to run the audit. It also expects the plan to be reviewed by the auditee before use, which is why acceptance is recorded rather than assumed.

Scope

When is an audit plan required?

This plan is one step inside a larger audit programme. Using it for work that belongs to a neighbouring template produces plans that look complete but cannot be reconciled against what the programme actually scheduled, or against what the audit later reported.

Use this template when

  • A specific audit has been scheduled and needs documented scope, criteria and a schedule before the auditor arrives
  • The audit sits inside a certifiable standard (ISO 45001, 14001, 9001, 50001) or a scheme such as BRCGS, SQF or FSSC 22000, where evidence of planning is itself checked
  • The annual audit programme (CMP-001) has already set out what will be audited this year, and this plan turns one line of it into a working schedule
  • The audit needs a fixed sample size, a trace exercise or an unannounced element decided in advance rather than negotiated with the auditee on the day
  • The plan needs to be issued to and accepted by the auditee ahead of time, with that acceptance kept as a record

Do not use it for

  • Internal Audit Programme, which sets out what will be audited, when, by whom and against which standard, across the whole year rather than one visit.
  • Internal Audit Report, which records what actually happened during the audit and the findings raised, once it is over.
  • Audit Finding Record, which records a single nonconformity with its evidence and clause reference — a plan has no findings of its own.
  • Process Audit Record, which is a narrower, single-process audit tool rather than a full scheduled audit with its own plan.
  • Unannounced Audit Readiness Check, which tests whether a site could pass an audit with no notice at all, rather than planning one that has notice by design.

Compliance mapping

Which ISO 19011 cl.6.2 requirements does this satisfy?

ISO 19011 cl.6.2 sets out what an audit plan has to fix before the audit begins: objectives, scope, criteria, method and the practical logistics of getting auditors onto site and in front of the right people.

ClauseRequirementWhere it lands
ISO 19011 cl.6.2.2Establish the audit objectives — what the audit is meant to determineObjectives and scope
ISO 19011 cl.6.2.3Confirm audit scope: the sites, areas, processes and clauses actually coveredObjectives and scope
ISO 19011 cl.6.2.4Determine audit criteria — the management system standard and clauses the audit is run againstHeader
ISO 19011 cl.6.2.5Select the audit method, including sampling basis, trace exercise and any unannounced elementApproach
ISO 19011 cl.6.2.6Assign auditors and, where relevant, auditees to each planned activity and time slotSchedule
ISO 19011 cl.6.2.7Allocate resources: access and escort, PPE and induction, and interpreters where neededLogistics
ISO 19011 cl.6.2.9Communicate the plan to the auditee with adequate notice and record its acceptanceLogistics

What it does not cover

  • Areas In Scope left blank, which means the auditor decides on the day what counts as in scope, and the plan cannot later be checked against what was actually covered.
  • Sampling Basis marked Convenience, which scores lowest for a reason — it tells you the sample was chosen for ease of access rather than risk, and the audit's conclusions inherit that weakness.
  • Unannounced Element set to No on every plan for a site, which means every audit there is announced and the site always has time to tidy up before the auditor arrives.
  • Plan Accepted left unanswered, which leaves no record that the auditee ever saw or agreed the scope and schedule before the audit took place.
  • Days Notice Given recorded without a matching Documents Requested In Advance answer, which leaves no way to check whether the notice period given actually matched what was asked of the site.

Global

Audit Plan requirements by country

ISO 19011 is guidance, not a certifiable standard in its own right, so what actually has teeth depends on which certifiable standard or customer scheme the audit is run against — and that varies sharply by sector and region.

International

ISO 19011:2018 cl.6.2

The clause is the common method every accredited auditor uses regardless of which management system standard is being audited, or which national body accredits the certification body.

A plan built to this clause satisfies planning evidence requests from any certification body auditor, on any scheme, anywhere — it never needs localising.

UK

UKAS-accredited certification, ISO/IEC 17021-1

UKAS-accredited bodies auditing against ISO 9001, 14001 or 45001 expect the plan issued in advance and accepted, under the certification body's own accreditation obligations.

A missing or unaccepted plan becomes a finding against the certification body as much as the site — one of the first documents a UKAS assessor asks to see.

United States

GFSI-benchmarked schemes (SQF, BRCGS) and second-party customer audits

Much of the pressure here comes not from a regulator but from retail customers and GFSI-benchmarked schemes, which set explicit notice-period rules and require a genuine unannounced component in a defined share of audits.

Marking Unannounced Element as No across a whole certification cycle can put scheme compliance itself at risk, independent of any single finding raised on the visit.

How to complete it

How to complete an audit plan, step by step

Filling in every field is the easy part. The plan is only as defensible as the four judgement calls behind it, and those are the ones an assessor or a customer auditor will actually probe.

How much of the sample is genuinely risk-based

Sample Size Planned and Sampling Basis are easy to complete with a plausible-looking number and 'risk based' selected. The defensible version can point to what made each sampled area, shift or record higher risk than the ones left out — prior findings, complaint history, or a process change — not just a round number chosen to look thorough.

Whether the unannounced element is real or theatre

Marking Unannounced Element as Yes only holds up if the auditee genuinely does not know which slot is unannounced. If Days Notice Given already covers the whole visit, or the schedule leaks informally before the plan is issued, the field is true on the form and false in practice.

How much notice is too much notice

Documents Requested In Advance and Days Notice Given both score higher for more preparation time, but there is a point past which advance notice defeats the purpose of the visit. The judgement call is where that line sits for this site, this standard and this history of findings — not simply maximising the score.

What 'Plan Accepted: With changes' actually means

A With changes acceptance scores above outright rejection but below full acceptance, and needs a real answer to what changed. If every plan for a site ends up accepted with changes that quietly narrow scope or drop the unannounced element, the score is hiding a pattern worth its own review.

What auditors find

Most common audit plan findings

These are the patterns that actually show up when audit plans are reviewed after the fact, not hypothetical gaps in the form.

FindingClauseWhat fixes it
Plan issued and accepted the same day as the audit itselfISO 19011 cl.6.2.9Set a minimum notice period in the audit programme and hold Days Notice Given against it; a same-day acceptance should trigger a review, not just a pass-through.
Sample Size Planned recorded but Sampling Basis marked Convenience with no rationaleISO 19011 cl.6.2.5Require a one-line justification whenever Convenience is selected, and route it to the lead auditor's manager before the plan is accepted.
No plan in the last twelve months carries Unannounced Element as YesISO 19011 cl.6.2.5 / scheme-specific unannounced requirementsTrack Unannounced Element at the programme level (CMP-001), not just per plan, so a site cannot quietly opt out of surprise visits across a whole cycle.
Areas In Scope excludes a process that a later audit finds to be the source of a major nonconformityISO 19011 cl.6.2.3Cross-check Areas In Scope against the risk register or prior findings before the plan is accepted, not only against what was audited last time.
Interpreter Needed marked No at a site where the majority working language differs from the auditor'sISO 19011 cl.6.2.7Default Interpreter Needed to the site's recorded working language rather than leaving it to the auditor's assumption on the day.
Programme ID left blank, breaking the link back to the annual audit programmeISO 19011 cl.6.2.1Make Programme ID required wherever the audit is scheduled work, so every plan traces to a programme line.

Case in point

Case in point: the plan that arrived with the auditor

A site preparing for BRCGS recertification produced fully completed audit plans for every internal audit that quarter, all showing Plan Accepted as Yes. When the certification body auditor asked for the notice given on the most recent one, Days Notice Given read zero — the plan had been created and accepted the same calendar day as the audit, alongside it rather than ahead of it.

The finding was not against any single audit's content. It was that the site's own planning evidence showed no gap between plan and execution across a whole cycle, meaning no internal audit that quarter had genuinely tested anything the site had not already chosen to show. The fix was a minimum five-day notice rule written into the programme, checked against Days Notice Given before a plan could move to Accepted.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

42fields
5 sections
Reference
CMP-003
Archetype
Plan
Record ID
APLAN-2026-000
Scoring
Not scored
Direction
n/a
Singleton
No
Basis
ISO 19011 cl.6.2
Links
Links Audit Programme
Tags
Audit, Planning
Sections
5
Fields
42
Follow up fields
0
Repeating sections
1
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

13 fields
Text

Plan ID*

Generated on save

Auto sequence. Format APL-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Audit Title*

Text

Programme ID

OptionalLinked

Links to CMP-001 Programme ID

Text

Planned Dates*

Single Choice

Management System Standard*

ISO 45001, ISO 14001, ISO 9001, ISO 50001, BRCGS, SQF, FSSC 22000 or an internal standard.

ISO 45001ISO 14001ISO 9001ISO 50001BRCGSSQFFSSC 22000Internal standard
Text

Clause Or Requirement

Optional
Text

Clause ID

OptionalLinked

Links to FDN-009 Clause ID

Info

Plan It Or Wander

An auditor without a plan follows whatever the auditee shows them. The plan decides in advance what will be sampled and who will be spoken to.

Objectives and scope

7 fields
Text

Audit Objective*

Multi Choice

Processes In Scope*

Incident managementRisk assessmentPermit to workTraining and competenceMaintenanceSanitationSupplier managementContractor managementDocument controlCorrective action
Pick List (multi)

Areas In Scope*

From FDN-001 Site NameFilter: Status is Active, Level is Area
Pick List (multi)

Sites In Scope

OptionalFrom FDN-001 Site NameFilter: Status is Active
Text

Clauses In Scope

Optional
Text

Period Covered By Sampling*

Text

Exclusions

Optional

Approach

6 fields
Numeric Answer

Sample Size Planned*

Scored
Single Choice

Sampling Basis*

Scored
  • Risk based3 pts
  • Random3 pts
  • Statistical4 pts
  • Convenience0 pts
Single Choice

Trace Exercise Planned*

Scored
  • Yes3 pts
  • No1 pt
Multi Choice

Shifts To Be Audited*

DaysAfternoonsNightsWeekend
Single Choice

Unannounced Element*

Scored

An announced audit shows you the tidied version. Keep part of it unannounced.

  • Yes3 pts
  • No0 pts
Single Choice

Documents Requested In Advance*

Scored
  • Yes3 pts
  • No1 pt

Schedule

Repeats6 fields
Text

Time Slot*

Text

Activity*

Users

Auditor*

Users

Auditee

Optional
Single Choice

Location

Optional
OfficeProduction officeHomeShared deskMeeting room
Text

Clause Or Process

Optional

Logistics

10 fields
Single Choice

Plan Issued To Auditee*

Scored
  • Yes3 pts
  • No0 pts
Numeric Answer

Days Notice Given*

Scored
Single Choice

Access And Escort Arranged*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

PPE And Induction Arranged For Auditors*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Interpreter Needed

Optional
YesNo
Single Choice

Plan Accepted*

Scored
  • Yes3 pts
  • With changes2 pts
  • No0 pts
Users

Lead Auditor*

Signature

Signature*

Users

Auditee Representative*

Signature

Second Signature*

CMP-003 · record IDs look like APLAN-2026-000 · Links Audit Programme

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The form is the easy part. Keeping the plan tied to the right programme line, chasing acceptance before the visit, and holding the unannounced element genuinely unannounced is the work that actually slips.

KnowComply

Holds the audit plan against the annual programme, tracks Plan Accepted status across every scheduled audit, and flags any site where the unannounced element hasn't been used in a full cycle.

KnowSafe

Feeds ISO 45001-scoped audit plans from the site's live risk register, so Areas In Scope reflects current hazards rather than last year's list.

KnowQuality

Links ISO 9001 process audit plans to nonconformity trends, so Sampling Basis can point to an actual pattern of prior findings instead of a generic risk statement.

Ella
Ella

Chases Plan Accepted before the audit date arrives, rolls notice periods and acceptance status into one view across every open plan, and holds every write for your approval before it touches a record.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Audit Plan definitions and key terms

Audit criteria
The set of requirements — a standard, clause, policy or procedure — that the audit evidence is measured against. Recorded here as Management System Standard and Clause Or Requirement.
Audit scope
The boundaries of the audit: which sites, areas, processes and time period are actually covered, and what is explicitly excluded.
Trace exercise
A sampling technique that follows one record or product forward and back through a process — for example from raw material receipt to finished goods dispatch — to test whether the paperwork matches what actually happened.
Sampling basis
The logic used to choose what gets audited: risk-based, random, statistical or convenience. Risk-based and statistical sampling can be defended under challenge; convenience sampling generally cannot.
Unannounced element
A portion of an audit — a shift, a location or an activity — that the auditee is not told about in advance, built into an otherwise scheduled and announced audit to test what a fully prepared visit would not show.

FAQ

Frequently asked questions about audit plan

What is the audit plan template based on?+

It is built against ISO 19011 cl.6.2, which covers preparing audit activities — objectives, scope, criteria, method, roles and logistics — ahead of the audit itself.

What sections does the audit plan contain?+

Five sections: Header, Objectives and scope, Approach, Schedule, and Logistics. The Schedule section repeats for each planned activity or time slot.

How often is an audit plan raised?+

One plan per scheduled audit, created when the audit programme calls for it and issued to the auditee before the audit runs. Each gets its own ID in the form APLAN-2026-000.

Does the audit plan need to be accepted before the audit starts?+

Yes. Plan Accepted is a required, scored field, and ISO 19011 cl.6.2.9 expects the plan to be communicated to and reviewed by the auditee in advance rather than presented on arrival.

How does the audit plan connect to the rest of the audit programme?+

Programme ID links back to the Internal Audit Programme (CMP-001), and the schedule and scope set here become what the later Internal Audit Report (CMP-002) is written against.

Can the audit plan template be changed?+

Yes. Every field, option and score is editable, including the standards under Management System Standard and the scoring on Sampling Basis. Most teams install it as it is, run one cycle, then adjust.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 19011:2018 cl.6.2 — Preparing audit activities
  • ISO 9001:2015 cl.9.2 — Internal audit
  • ISO 45001:2018 cl.9.2 — Internal audit
  • BRCGS Food Safety Issue 9 — unannounced audit protocol
  • ISO/IEC 17021-1:2015 — Requirements for certification bodies

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.