Knowella

Audit Programme Review

An audit programme that never produces a nasty finding gets read as proof the site is clean. It is usually proof the audits are shallow, the auditors aren't independent of what they check, or both. This review exists to catch that before a certification body, a customer, or an incident does it first — by testing the programme against its own record, not its own opinion of itself.

KnowComplyReviewCMP-008Pinned in navigation49 fields across 6 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 19011 cl.5.6
Workspace
KnowComply
Form type
Review
Raised
Yearly, at the review interval, or after a trigger event
Completed by
The compliance lead

The short version

  • Zero findings is not evidence of a clean site; it is a number to be tested against Did Internal Audit Find It First, which is the one field the whole review turns on.
  • Coverage and completion are tracked as separate numbers on purpose — a programme can run every planned audit on schedule and still never touch the process or clause that actually mattered.
  • Findings Concentrated In One Area is scored so concentration counts against the programme, forcing a look at whether one function is being systematically missed rather than randomly hit.
  • Independence is reviewed at the auditor-pool level, not the individual-audit level, because a programme can pass every single audit's independence check and still be structurally compromised across the pool as a whole.

What this is

What is an audit programme review, and why isn't the audit schedule enough on its own?

What is an audit programme review, and why isn't the audit schedule enough on its own?

The schedule tells you whether audits happened. The programme review asks whether they were worth having — whether they covered what they should, found genuine issues, closed them, and would have caught what an external body eventually did. A full schedule with a hollow programme behind it is the exact failure mode this record exists to catch.

What does 'effectiveness' mean for an audit programme, specifically?

It means the programme surfaces real nonconformities before someone outside the organisation does, closes them on root cause rather than symptom, and does so consistently regardless of which auditor is assigned. A programme that produces tidy paperwork but is repeatedly beaten to its own findings by a customer or regulator is not effective, whatever its completion percentage says.

Why does the review check auditor independence separately from audit results?

Because a programme can look effective on paper — audits completed, findings closed — while every audit was conducted by someone auditing their own area, or close to it. Independence is checked as its own line so that a clean-looking result can't hide a structural reason it was always going to look clean.

Scope

When is an audit programme review required?

This review is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.

Use this template when

  • A full audit cycle has completed and its results need testing against the programme's own objectives
  • The review interval is due, or a trigger event — a bad external finding, a certification decision — forces an out-of-cycle look
  • You need to know whether the audit programme is finding real issues, not just running to schedule
  • A new record is needed; each one gets its own ID in the form APR2-2026-000
  • A linked record needs this one to exist: it links to the Audit Programme and to Findings

Do not use it for

  • Internal Audit Programme, which is the plan this review looks back on — don't rebuild the plan inside the review.
  • Process Audit Record or Internal Audit Report, which record one audit's evidence and result — this review aggregates many of them, it doesn't replace any single one.
  • Audit Finding Record, which tracks one nonconformity — this review works in counts and rates across all findings, not any individual one.
  • Auditor Competency Record, which certifies an individual auditor — use it to establish competence, and use this review to check whether the pool as a whole is independent and adequately used.
  • Anything outside the Internal Audit and Certification programme, which belongs to whichever workspace owns that system.

Compliance mapping

Which ISO 19011 cl.5.6 requirements does this satisfy?

ISO 19011's clause 5 covers the audit programme as a whole, not any single audit inside it — this record is where that requirement gets discharged. The mapping below follows the record's own sections.

ClauseRequirementWhere it lands
ISO 19011:2018 cl.5.6The audit programme is monitored against its own objectives on a defined interval, not reviewed only when someone remembers to.Header
cl.5.4.3The programme's established extent — which processes and clauses it must reach — is checked against what was actually covered.Delivery
cl.5.6Monitoring includes the pattern of results across individual audits, not just whether each one happened.Findings profile
cl.5.7The programme is reviewed to determine whether its objectives were met and where it should change for the next cycle.Effectiveness of the programme
cl.4The principles of auditing — an evidence-based approach in particular — apply to the review's own verdict on the programme, not only to the audits it reviews.Effectiveness of the programme
cl.7Auditor competence and independence are evaluated as part of managing the programme, not assumed from a qualification on file.Auditor pool
cl.5.7Conclusions from the review feed corrective action and changes to the audit programme for the next cycle.Conclusion

What it does not cover

  • A review that reports Audits Completed without checking Clause Coverage Complete or Process Coverage Complete, which hides a programme that ran on schedule but skipped the parts that mattered.
  • Audits Finding Nothing reported as a good number, which mistakes a quiet audit for a clean site.
  • Findings Concentrated In One Area marked Yes with no Area Identified entered, which loses the one signal the review is supposed to surface.
  • Did Internal Audit Find It First left as Sometimes or No with no Changes For Next Cycle recorded, which means the programme's own effectiveness test is failing and nothing is being done about it.
  • Independence Maintained marked Yes without checking who audited their own area, which is the one finding a self-report can't be trusted to catch.

Global

Audit Programme Review requirements by country

The review itself is generic to ISO 19011, but what a certification body or customer expects to see inside it varies by scheme and region.

International

ISO 19011:2018 cl.5.6–5.7

requires the programme itself, not just individual audits, to be monitored and periodically reviewed for effectiveness

This record is that review — it exists because 19011 treats the programme as something that can itself fail, separately from any audit inside it.

International (management systems)

ISO 9001:2015 / ISO 45001:2018 cl.9.2

each requires internal audits to be planned and their results reported, with management review then acting on them

This review is the evidence that requirement is being met at programme level, not just audit by audit.

United Kingdom

UKAS accreditation requirements for certification bodies

certification bodies assessing a site expect to see the internal audit programme reviewed for coverage and effectiveness, not just a stack of completed audit records

An audit programme review that is absent, or superficial, is itself commonly raised as a finding at recertification.

How to complete it

How to complete an audit programme review, step by step

The numbers in this record are simple to enter. Deciding what they actually mean about the programme is the part that takes judgement.

Distinguishing a quiet programme from a working one

Zero or low findings can reflect genuine capability or a shallow, non-independent audit pool. The judgement call is cross-checking that against Did Internal Audit Find It First before accepting either explanation.

Naming the concentrated area, even when it's your own

Findings Concentrated In One Area and Area Identified need answering honestly when that area reports to the person completing the review, not softened because it's uncomfortable to name.

Coverage claimed vs coverage proven

Clause Coverage Complete and Process Coverage Complete should reflect someone actually checking each audit reached its full stated scope, not the schedule simply being ticked off as done.

What earns an Action Required tick

Changes For Next Cycle as free text is not enough on its own when the review finds the programme itself under-performing — that calls for Action Required marked Yes and a real CAPA raised, not a note for next year.

What auditors find

Most common audit programme review findings

Patterns that surface once a run of programme reviews are compared against each other, rather than read as single documents.

FindingClauseWhat fixes it
Audits Completed reported at or near 100% of Audits Planned while Clause Coverage Complete or Process Coverage Complete are marked Partly or No.cl.5.4.3 / cl.5.6Report coverage alongside completion count, not completion count alone — a full quota of shallow audits is not full coverage.
Findings Concentrated In One Area marked Yes with Area Identified left blank.cl.5.6Make Area Identified mandatory whenever Findings Concentrated In One Area is Yes.
Did Internal Audit Find It First marked No, alongside Programme Effective marked Yes.cl.5.7Cap Programme Effective automatically when Did Internal Audit Find It First is No — it cannot read Yes when the programme's core test just failed.
Independence Maintained marked Yes with no specific instance checked against which auditor covered which area.cl.7Require the reviewer to name the specific case checked, or confirm none existed, rather than answering the single-choice field from memory.
Training Needs Identified marked No, alongside Auditors Meeting Minimum Audits well under Active Auditors.cl.7Cross-check Training Needs Identified against the gap between Active Auditors and Auditors Meeting Minimum Audits before accepting No.
Action Required marked No while Changes For Next Cycle describes a substantive change to the programme.cl.5.7Treat any non-trivial text in Changes For Next Cycle as evidence Action Required should be Yes, not a free-text afterthought that never gets a CAPA.

Case in point

Case in point: the perfect completion rate that missed the real story

A compliance lead completed the annual programme review with Audits Completed at 100% of Audits Planned, Completion Percent and Completed On Schedule Percent both high, and Programme Effective sitting toward Yes on the strength of it. The completion numbers alone made a strong case for a clean sign-off.

Working down to Effectiveness of the programme, Did Internal Audit Find It First had been marked No for the third cycle running — an external customer audit had caught a supplier-approval gap the internal programme never touched. The completed-on-schedule number was entirely real. The programme still wasn't finding what mattered, and only the field built to test that specifically caught it.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

49fields
6 sections
Reference
CMP-008
Archetype
Review
Record ID
APR2-2026-000
Scoring
Effectiveness rating
Direction
High is good
Singleton
No
Basis
ISO 19011 cl.5.6
Links
Links Audit Programme, Findings
Tags
Audit, Governance
Sections
6
Fields
49
Follow up fields
3
Repeating sections
0
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

10 fields
Text

Review ID*

Generated on save

Auto sequence. Format APR-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Cycle Reviewed*

Users

Reviewed By*

Text

Programme ID

OptionalLinked

Links to CMP-001 Programme ID

Info

Audit The Auditing

A programme that finds nothing is not evidence of a perfect system. It is usually evidence that the audits are shallow or the auditors are not independent.

Delivery

6 fields
Numeric Answer

Audits Planned*

Numeric Answer

Audits Completed*

Scored
Numeric Answer

Completion Percent*

Scored
Numeric Answer

Completed On Schedule Percent*

Scored
Single Choice

Clause Coverage Complete*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Process Coverage Complete*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Findings profile

9 fields
Numeric Answer

Total Findings*

Scored
Numeric Answer

Findings Per Audit*

Scored
Numeric Answer

Audits Finding Nothing*

Scored
Numeric Answer

Critical And Major*

Scored
Numeric Answer

Repeat Findings*

Scored
Numeric Answer

Systemic Findings*

Scored
Single Choice

Findings Concentrated In One Area*

Scored
  • No3 pts
  • Yes0 pts
Single Choice

Area Identified

Optional
ProductionPackingMaintenanceSanitationWarehouseTrainingContractor management
Single Choice

Consistent Grading Across Auditors*

Scored
  • Yes3 pts
  • Some variation1 pt
  • No0 pts

Effectiveness of the programme

6 fields
Numeric Answer

Findings Closed Percent*

Scored
Numeric Answer

Average Days To Close*

Scored
Numeric Answer

Effectiveness Verified Percent*

Scored
Single Choice

Did Internal Audit Find It First*

Scored

The best test of the programme. If the external auditor or the regulator found it first, the internal audit missed it.

  • Yes3 pts
  • Sometimes1 pt
  • No0 pts
Numeric Answer

External Findings Not Found Internally*

Scored
Numeric Answer

Incidents In Recently Audited Areas*

Scored

Auditor pool

6 fields
Numeric Answer

Active Auditors*

Scored
Numeric Answer

Auditors Meeting Minimum Audits*

Scored
Single Choice

Independence Maintained*

Scored
  • Yes3 pts
  • Mostly1 pt
  • No0 pts
Single Choice

Auditor Feedback Sought*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Auditee Feedback Sought*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Training Needs Identified*

Scored
  • Yes3 pts
  • No1 pt

Conclusion

12 fields
Single Choice

Programme Effective*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Text

Changes For Next Cycle*

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Single Choice

Reported To Management Review*

YesNo
Date & Time

Next Review Due*

Users

Compliance Lead*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

CMP-008 · record IDs look like APR2-2026-000 · Links Audit Programme, Findings

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The numbers in this review only mean something set against the individual audits behind them. Pulling that together, and making sure a quiet programme gets questioned rather than approved, is where the work actually happens.

KnowComply

Rolls up every Process Audit Record and Internal Audit Report completed in the cycle into this review's counts, so Total Findings and coverage percentages reflect what was actually run, not what someone remembers.

KnowTrain

Where Training Needs Identified points at a gap in the auditor pool itself, KnowTrain holds the record of what training was assigned and completed as a result.

KnowQuality

Systemic and repeat findings surfaced by this review usually trace back to a quality-system control; KnowQuality holds the corrective action and root-cause record that Action Required and CAPA ID point to.

Ella
Ella

Holds the full-cycle view — completion, coverage, findings and auditor independence together — and flags where the review's own conclusion doesn't match what the underlying records show, before it goes to sign-off.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Audit Programme Review definitions and key terms

Audit programme
The full set of audits planned for a cycle — what gets audited, how often, by whom — set out in the Internal Audit Programme record. This review looks back on it; it doesn't rebuild it.
Effectiveness (of an audit programme)
Whether the programme actually surfaces genuine issues before an outside party does, and whether those issues get closed on root cause. Distinct from whether the schedule was completed.
Systemic finding
A finding that reflects a gap in how a whole process or control is designed or managed, rather than a one-off lapse — the kind a programme review is specifically checking whether audits are catching.
Repeat finding
A finding that has appeared before, at the same or a related site, indicating the earlier corrective action didn't hold or wasn't followed through.
Independence (auditor pool)
Whether, across the whole pool of auditors, nobody is routinely auditing their own area — checked at programme level because it can fail even when every individual audit passed its own independence check.

FAQ

Frequently asked questions about audit programme review

Who should complete the Audit Programme Review — the same person who runs the audit schedule?+

It's built for the compliance lead, and there's a case for that being someone with enough authority over the programme to act on what the review finds, but not so close to day-to-day scheduling that they mark their own homework. Independence Maintained and Consistent Grading Across Auditors are there partly to catch that risk.

What if Audits Finding Nothing is high — is that something to flag?+

On its own, no — some processes genuinely run clean. It becomes a problem alongside a low score on Did Internal Audit Find It First or Consistent Grading Across Auditors, which is why the form asks for both rather than treating a clean findings profile as sufficient on its own.

How does this review connect to the individual Process Audit Record and Internal Audit Report entries?+

It aggregates them — Total Findings, Findings Per Audit, Repeat Findings and the coverage percentages are rolled up from the individual audit records completed across the cycle, rather than entered fresh here.

Does a 'Programme Effective: Partly' result require raising a CAPA?+

Not automatically, but Action Required should usually follow it. A Partly or No answer with Action Required left at No is asking to be checked — Priority and CAPA ID exist precisely to make that follow-up visible.

Why does the form ask about auditor feedback and auditee feedback separately?+

Because they surface different problems. Auditors report on the process — is the schedule realistic, is guidance adequate; auditees report on the experience — was the audit fair, useful, disruptive. A programme can be broken from either side without the other side noticing.

What triggers a review outside the normal yearly interval?+

Anything that calls the programme's adequacy into question before the year is up — a serious external finding, a certification decision, a significant change to the sites or processes in scope. Cycle Reviewed should record which cycle, or partial cycle, is under review either way.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 19011:2018 cl.5.6–5.7 — Monitoring, reviewing and improving the audit programme
  • ISO 9001:2015 cl.9.2 — Internal audit
  • ISO 45001:2018 cl.9.2 — Internal audit
  • ISO/IEC 17021-1 — Conformity assessment: requirements for certification bodies

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.