What this is
What is an audit plan?
What is an audit plan?
An audit plan is the document that fixes an audit's objectives, scope, criteria, sampling approach and schedule before any auditor arrives on site. It is prepared by the lead auditor, issued to the auditee in advance, and accepted before the audit starts. Under ISO 19011 cl.6.2 it is the single artefact that turns one line of the annual audit programme into a workable, defensible exercise.
What's the difference between an audit plan and an audit programme?
The programme (CMP-001) is the year's schedule: which processes, sites and standards get audited, when, and by whom, set once and reviewed periodically. The plan (this template) is a single instance of that schedule turned into a working document — the specific objectives, sample size, unannounced element and logistics for one audit visit. A programme can generate a dozen plans; a plan cannot exist without a programme line behind it.
What does ISO 19011 clause 6.2 actually require in an audit plan?
Clause 6.2 requires the lead auditor to establish objectives, confirm scope and criteria, decide the audit method including sampling and any unannounced elements, assign roles to the audit team, and allocate resources — access, escort, PPE, interpreters — needed to run the audit. It also expects the plan to be reviewed by the auditee before use, which is why acceptance is recorded rather than assumed.
Scope
When is an audit plan required?
This plan is one step inside a larger audit programme. Using it for work that belongs to a neighbouring template produces plans that look complete but cannot be reconciled against what the programme actually scheduled, or against what the audit later reported.
Use this template when
- A specific audit has been scheduled and needs documented scope, criteria and a schedule before the auditor arrives
- The audit sits inside a certifiable standard (ISO 45001, 14001, 9001, 50001) or a scheme such as BRCGS, SQF or FSSC 22000, where evidence of planning is itself checked
- The annual audit programme (CMP-001) has already set out what will be audited this year, and this plan turns one line of it into a working schedule
- The audit needs a fixed sample size, a trace exercise or an unannounced element decided in advance rather than negotiated with the auditee on the day
- The plan needs to be issued to and accepted by the auditee ahead of time, with that acceptance kept as a record
Do not use it for
- Internal Audit Programme, which sets out what will be audited, when, by whom and against which standard, across the whole year rather than one visit.
- Internal Audit Report, which records what actually happened during the audit and the findings raised, once it is over.
- Audit Finding Record, which records a single nonconformity with its evidence and clause reference — a plan has no findings of its own.
- Process Audit Record, which is a narrower, single-process audit tool rather than a full scheduled audit with its own plan.
- Unannounced Audit Readiness Check, which tests whether a site could pass an audit with no notice at all, rather than planning one that has notice by design.
Compliance mapping
Which ISO 19011 cl.6.2 requirements does this satisfy?
ISO 19011 cl.6.2 sets out what an audit plan has to fix before the audit begins: objectives, scope, criteria, method and the practical logistics of getting auditors onto site and in front of the right people.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 19011 cl.6.2.2 | Establish the audit objectives — what the audit is meant to determine | Objectives and scope |
| ISO 19011 cl.6.2.3 | Confirm audit scope: the sites, areas, processes and clauses actually covered | Objectives and scope |
| ISO 19011 cl.6.2.4 | Determine audit criteria — the management system standard and clauses the audit is run against | Header |
| ISO 19011 cl.6.2.5 | Select the audit method, including sampling basis, trace exercise and any unannounced element | Approach |
| ISO 19011 cl.6.2.6 | Assign auditors and, where relevant, auditees to each planned activity and time slot | Schedule |
| ISO 19011 cl.6.2.7 | Allocate resources: access and escort, PPE and induction, and interpreters where needed | Logistics |
| ISO 19011 cl.6.2.9 | Communicate the plan to the auditee with adequate notice and record its acceptance | Logistics |
What it does not cover
- Areas In Scope left blank, which means the auditor decides on the day what counts as in scope, and the plan cannot later be checked against what was actually covered.
- Sampling Basis marked Convenience, which scores lowest for a reason — it tells you the sample was chosen for ease of access rather than risk, and the audit's conclusions inherit that weakness.
- Unannounced Element set to No on every plan for a site, which means every audit there is announced and the site always has time to tidy up before the auditor arrives.
- Plan Accepted left unanswered, which leaves no record that the auditee ever saw or agreed the scope and schedule before the audit took place.
- Days Notice Given recorded without a matching Documents Requested In Advance answer, which leaves no way to check whether the notice period given actually matched what was asked of the site.
Global
Audit Plan requirements by country
ISO 19011 is guidance, not a certifiable standard in its own right, so what actually has teeth depends on which certifiable standard or customer scheme the audit is run against — and that varies sharply by sector and region.
ISO 19011:2018 cl.6.2
The clause is the common method every accredited auditor uses regardless of which management system standard is being audited, or which national body accredits the certification body.
A plan built to this clause satisfies planning evidence requests from any certification body auditor, on any scheme, anywhere — it never needs localising.
UKAS-accredited certification, ISO/IEC 17021-1
UKAS-accredited bodies auditing against ISO 9001, 14001 or 45001 expect the plan issued in advance and accepted, under the certification body's own accreditation obligations.
A missing or unaccepted plan becomes a finding against the certification body as much as the site — one of the first documents a UKAS assessor asks to see.
GFSI-benchmarked schemes (SQF, BRCGS) and second-party customer audits
Much of the pressure here comes not from a regulator but from retail customers and GFSI-benchmarked schemes, which set explicit notice-period rules and require a genuine unannounced component in a defined share of audits.
Marking Unannounced Element as No across a whole certification cycle can put scheme compliance itself at risk, independent of any single finding raised on the visit.
How to complete it
How to complete an audit plan, step by step
Filling in every field is the easy part. The plan is only as defensible as the four judgement calls behind it, and those are the ones an assessor or a customer auditor will actually probe.
Sample Size Planned and Sampling Basis are easy to complete with a plausible-looking number and 'risk based' selected. The defensible version can point to what made each sampled area, shift or record higher risk than the ones left out — prior findings, complaint history, or a process change — not just a round number chosen to look thorough.
Marking Unannounced Element as Yes only holds up if the auditee genuinely does not know which slot is unannounced. If Days Notice Given already covers the whole visit, or the schedule leaks informally before the plan is issued, the field is true on the form and false in practice.
Documents Requested In Advance and Days Notice Given both score higher for more preparation time, but there is a point past which advance notice defeats the purpose of the visit. The judgement call is where that line sits for this site, this standard and this history of findings — not simply maximising the score.
A With changes acceptance scores above outright rejection but below full acceptance, and needs a real answer to what changed. If every plan for a site ends up accepted with changes that quietly narrow scope or drop the unannounced element, the score is hiding a pattern worth its own review.
What auditors find
Most common audit plan findings
These are the patterns that actually show up when audit plans are reviewed after the fact, not hypothetical gaps in the form.
| Finding | Clause | What fixes it |
|---|---|---|
| Plan issued and accepted the same day as the audit itself | ISO 19011 cl.6.2.9 | Set a minimum notice period in the audit programme and hold Days Notice Given against it; a same-day acceptance should trigger a review, not just a pass-through. |
| Sample Size Planned recorded but Sampling Basis marked Convenience with no rationale | ISO 19011 cl.6.2.5 | Require a one-line justification whenever Convenience is selected, and route it to the lead auditor's manager before the plan is accepted. |
| No plan in the last twelve months carries Unannounced Element as Yes | ISO 19011 cl.6.2.5 / scheme-specific unannounced requirements | Track Unannounced Element at the programme level (CMP-001), not just per plan, so a site cannot quietly opt out of surprise visits across a whole cycle. |
| Areas In Scope excludes a process that a later audit finds to be the source of a major nonconformity | ISO 19011 cl.6.2.3 | Cross-check Areas In Scope against the risk register or prior findings before the plan is accepted, not only against what was audited last time. |
| Interpreter Needed marked No at a site where the majority working language differs from the auditor's | ISO 19011 cl.6.2.7 | Default Interpreter Needed to the site's recorded working language rather than leaving it to the auditor's assumption on the day. |
| Programme ID left blank, breaking the link back to the annual audit programme | ISO 19011 cl.6.2.1 | Make Programme ID required wherever the audit is scheduled work, so every plan traces to a programme line. |
Case in point
Case in point: the plan that arrived with the auditor
A site preparing for BRCGS recertification produced fully completed audit plans for every internal audit that quarter, all showing Plan Accepted as Yes. When the certification body auditor asked for the notice given on the most recent one, Days Notice Given read zero — the plan had been created and accepted the same calendar day as the audit, alongside it rather than ahead of it.
The finding was not against any single audit's content. It was that the site's own planning evidence showed no gap between plan and execution across a whole cycle, meaning no internal audit that quarter had genuinely tested anything the site had not already chosen to show. The fix was a minimum five-day notice rule written into the programme, checked against Days Notice Given before a plan could move to Accepted.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- CMP-003
- Archetype
- Plan
- Record ID
- APLAN-2026-000
- Scoring
- Not scored
- Direction
- n/a
- Singleton
- No
- Basis
- ISO 19011 cl.6.2
- Links
- Links Audit Programme
- Tags
- Audit, Planning
- Sections
- 5
- Fields
- 42
- Follow up fields
- 0
- Repeating sections
- 1
- Links out
- 3
Header
13 fieldsPlan ID*
Auto sequence. Format APL-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Audit Title*
Programme ID
Links to CMP-001 Programme ID
Planned Dates*
Management System Standard*
ISO 45001, ISO 14001, ISO 9001, ISO 50001, BRCGS, SQF, FSSC 22000 or an internal standard.
Clause Or Requirement
Clause ID
Links to FDN-009 Clause ID
Plan It Or Wander
An auditor without a plan follows whatever the auditee shows them. The plan decides in advance what will be sampled and who will be spoken to.
Objectives and scope
7 fieldsAudit Objective*
Processes In Scope*
Areas In Scope*
Sites In Scope
Clauses In Scope
Period Covered By Sampling*
Exclusions
Approach
6 fieldsSample Size Planned*
Sampling Basis*
- Risk based3 pts
- Random3 pts
- Statistical4 pts
- Convenience0 pts
Trace Exercise Planned*
- Yes3 pts
- No1 pt
Shifts To Be Audited*
Unannounced Element*
An announced audit shows you the tidied version. Keep part of it unannounced.
- Yes3 pts
- No0 pts
Documents Requested In Advance*
- Yes3 pts
- No1 pt
Schedule
Repeats6 fieldsTime Slot*
Activity*
Auditor*
Auditee
Location
Clause Or Process
Logistics
10 fieldsPlan Issued To Auditee*
- Yes3 pts
- No0 pts
Days Notice Given*
Access And Escort Arranged*
- Yes3 pts
- No0 pts
PPE And Induction Arranged For Auditors*
- Yes3 pts
- No0 pts
Interpreter Needed
Plan Accepted*
- Yes3 pts
- With changes2 pts
- No0 pts
Lead Auditor*
Signature*
Auditee Representative*
Second Signature*
CMP-003 · record IDs look like APLAN-2026-000 · Links Audit Programme
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The form is the easy part. Keeping the plan tied to the right programme line, chasing acceptance before the visit, and holding the unannounced element genuinely unannounced is the work that actually slips.
Holds the audit plan against the annual programme, tracks Plan Accepted status across every scheduled audit, and flags any site where the unannounced element hasn't been used in a full cycle.
Feeds ISO 45001-scoped audit plans from the site's live risk register, so Areas In Scope reflects current hazards rather than last year's list.
Links ISO 9001 process audit plans to nonconformity trends, so Sampling Basis can point to an actual pattern of prior findings instead of a generic risk statement.

Chases Plan Accepted before the audit date arrives, rolls notice periods and acceptance status into one view across every open plan, and holds every write for your approval before it touches a record.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Audit Plan definitions and key terms
- Audit criteria
- The set of requirements — a standard, clause, policy or procedure — that the audit evidence is measured against. Recorded here as Management System Standard and Clause Or Requirement.
- Audit scope
- The boundaries of the audit: which sites, areas, processes and time period are actually covered, and what is explicitly excluded.
- Trace exercise
- A sampling technique that follows one record or product forward and back through a process — for example from raw material receipt to finished goods dispatch — to test whether the paperwork matches what actually happened.
- Sampling basis
- The logic used to choose what gets audited: risk-based, random, statistical or convenience. Risk-based and statistical sampling can be defended under challenge; convenience sampling generally cannot.
- Unannounced element
- A portion of an audit — a shift, a location or an activity — that the auditee is not told about in advance, built into an otherwise scheduled and announced audit to test what a fully prepared visit would not show.
FAQ
Frequently asked questions about audit plan
What is the audit plan template based on?+
It is built against ISO 19011 cl.6.2, which covers preparing audit activities — objectives, scope, criteria, method, roles and logistics — ahead of the audit itself.
What sections does the audit plan contain?+
Five sections: Header, Objectives and scope, Approach, Schedule, and Logistics. The Schedule section repeats for each planned activity or time slot.
How often is an audit plan raised?+
One plan per scheduled audit, created when the audit programme calls for it and issued to the auditee before the audit runs. Each gets its own ID in the form APLAN-2026-000.
Does the audit plan need to be accepted before the audit starts?+
Yes. Plan Accepted is a required, scored field, and ISO 19011 cl.6.2.9 expects the plan to be communicated to and reviewed by the auditee in advance rather than presented on arrival.
How does the audit plan connect to the rest of the audit programme?+
Programme ID links back to the Internal Audit Programme (CMP-001), and the schedule and scope set here become what the later Internal Audit Report (CMP-002) is written against.
Can the audit plan template be changed?+
Yes. Every field, option and score is editable, including the standards under Management System Standard and the scoring on Sampling Basis. Most teams install it as it is, run one cycle, then adjust.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Internal Audit and Certification
Internal Audit Programme
Sets out what will be audited, when, by whom and against which standard, across the year
Internal Audit Report
Records an internal audit against a standard or process, with findings and evidence
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Auditor Competency Record
Records an internal auditor's training, experience and audits performed
Process Audit Record
Audits a specific process end to end rather than a standard clause by clause
More in Internal Audits
Internal Audit Programme
Sets out what will be audited, when, by whom and against which standard, across the year
Internal Audit Report
Records an internal audit against a standard or process, with findings and evidence
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Auditor Competency Record
Records an internal auditor's training, experience and audits performed
Process Audit Record
Audits a specific process end to end rather than a standard clause by clause

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 19011:2018 cl.6.2 — Preparing audit activities
- ISO 9001:2015 cl.9.2 — Internal audit
- ISO 45001:2018 cl.9.2 — Internal audit
- BRCGS Food Safety Issue 9 — unannounced audit protocol
- ISO/IEC 17021-1:2015 — Requirements for certification bodies
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.