What this is
What is an audit programme review, and why isn't the audit schedule enough on its own?
What is an audit programme review, and why isn't the audit schedule enough on its own?
The schedule tells you whether audits happened. The programme review asks whether they were worth having — whether they covered what they should, found genuine issues, closed them, and would have caught what an external body eventually did. A full schedule with a hollow programme behind it is the exact failure mode this record exists to catch.
What does 'effectiveness' mean for an audit programme, specifically?
It means the programme surfaces real nonconformities before someone outside the organisation does, closes them on root cause rather than symptom, and does so consistently regardless of which auditor is assigned. A programme that produces tidy paperwork but is repeatedly beaten to its own findings by a customer or regulator is not effective, whatever its completion percentage says.
Why does the review check auditor independence separately from audit results?
Because a programme can look effective on paper — audits completed, findings closed — while every audit was conducted by someone auditing their own area, or close to it. Independence is checked as its own line so that a clean-looking result can't hide a structural reason it was always going to look clean.
Scope
When is an audit programme review required?
This review is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.
Use this template when
- A full audit cycle has completed and its results need testing against the programme's own objectives
- The review interval is due, or a trigger event — a bad external finding, a certification decision — forces an out-of-cycle look
- You need to know whether the audit programme is finding real issues, not just running to schedule
- A new record is needed; each one gets its own ID in the form APR2-2026-000
- A linked record needs this one to exist: it links to the Audit Programme and to Findings
Do not use it for
- Internal Audit Programme, which is the plan this review looks back on — don't rebuild the plan inside the review.
- Process Audit Record or Internal Audit Report, which record one audit's evidence and result — this review aggregates many of them, it doesn't replace any single one.
- Audit Finding Record, which tracks one nonconformity — this review works in counts and rates across all findings, not any individual one.
- Auditor Competency Record, which certifies an individual auditor — use it to establish competence, and use this review to check whether the pool as a whole is independent and adequately used.
- Anything outside the Internal Audit and Certification programme, which belongs to whichever workspace owns that system.
Compliance mapping
Which ISO 19011 cl.5.6 requirements does this satisfy?
ISO 19011's clause 5 covers the audit programme as a whole, not any single audit inside it — this record is where that requirement gets discharged. The mapping below follows the record's own sections.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 19011:2018 cl.5.6 | The audit programme is monitored against its own objectives on a defined interval, not reviewed only when someone remembers to. | Header |
| cl.5.4.3 | The programme's established extent — which processes and clauses it must reach — is checked against what was actually covered. | Delivery |
| cl.5.6 | Monitoring includes the pattern of results across individual audits, not just whether each one happened. | Findings profile |
| cl.5.7 | The programme is reviewed to determine whether its objectives were met and where it should change for the next cycle. | Effectiveness of the programme |
| cl.4 | The principles of auditing — an evidence-based approach in particular — apply to the review's own verdict on the programme, not only to the audits it reviews. | Effectiveness of the programme |
| cl.7 | Auditor competence and independence are evaluated as part of managing the programme, not assumed from a qualification on file. | Auditor pool |
| cl.5.7 | Conclusions from the review feed corrective action and changes to the audit programme for the next cycle. | Conclusion |
What it does not cover
- A review that reports Audits Completed without checking Clause Coverage Complete or Process Coverage Complete, which hides a programme that ran on schedule but skipped the parts that mattered.
- Audits Finding Nothing reported as a good number, which mistakes a quiet audit for a clean site.
- Findings Concentrated In One Area marked Yes with no Area Identified entered, which loses the one signal the review is supposed to surface.
- Did Internal Audit Find It First left as Sometimes or No with no Changes For Next Cycle recorded, which means the programme's own effectiveness test is failing and nothing is being done about it.
- Independence Maintained marked Yes without checking who audited their own area, which is the one finding a self-report can't be trusted to catch.
Global
Audit Programme Review requirements by country
The review itself is generic to ISO 19011, but what a certification body or customer expects to see inside it varies by scheme and region.
ISO 19011:2018 cl.5.6–5.7
requires the programme itself, not just individual audits, to be monitored and periodically reviewed for effectiveness
This record is that review — it exists because 19011 treats the programme as something that can itself fail, separately from any audit inside it.
ISO 9001:2015 / ISO 45001:2018 cl.9.2
each requires internal audits to be planned and their results reported, with management review then acting on them
This review is the evidence that requirement is being met at programme level, not just audit by audit.
UKAS accreditation requirements for certification bodies
certification bodies assessing a site expect to see the internal audit programme reviewed for coverage and effectiveness, not just a stack of completed audit records
An audit programme review that is absent, or superficial, is itself commonly raised as a finding at recertification.
How to complete it
How to complete an audit programme review, step by step
The numbers in this record are simple to enter. Deciding what they actually mean about the programme is the part that takes judgement.
Zero or low findings can reflect genuine capability or a shallow, non-independent audit pool. The judgement call is cross-checking that against Did Internal Audit Find It First before accepting either explanation.
Findings Concentrated In One Area and Area Identified need answering honestly when that area reports to the person completing the review, not softened because it's uncomfortable to name.
Clause Coverage Complete and Process Coverage Complete should reflect someone actually checking each audit reached its full stated scope, not the schedule simply being ticked off as done.
Changes For Next Cycle as free text is not enough on its own when the review finds the programme itself under-performing — that calls for Action Required marked Yes and a real CAPA raised, not a note for next year.
What auditors find
Most common audit programme review findings
Patterns that surface once a run of programme reviews are compared against each other, rather than read as single documents.
| Finding | Clause | What fixes it |
|---|---|---|
| Audits Completed reported at or near 100% of Audits Planned while Clause Coverage Complete or Process Coverage Complete are marked Partly or No. | cl.5.4.3 / cl.5.6 | Report coverage alongside completion count, not completion count alone — a full quota of shallow audits is not full coverage. |
| Findings Concentrated In One Area marked Yes with Area Identified left blank. | cl.5.6 | Make Area Identified mandatory whenever Findings Concentrated In One Area is Yes. |
| Did Internal Audit Find It First marked No, alongside Programme Effective marked Yes. | cl.5.7 | Cap Programme Effective automatically when Did Internal Audit Find It First is No — it cannot read Yes when the programme's core test just failed. |
| Independence Maintained marked Yes with no specific instance checked against which auditor covered which area. | cl.7 | Require the reviewer to name the specific case checked, or confirm none existed, rather than answering the single-choice field from memory. |
| Training Needs Identified marked No, alongside Auditors Meeting Minimum Audits well under Active Auditors. | cl.7 | Cross-check Training Needs Identified against the gap between Active Auditors and Auditors Meeting Minimum Audits before accepting No. |
| Action Required marked No while Changes For Next Cycle describes a substantive change to the programme. | cl.5.7 | Treat any non-trivial text in Changes For Next Cycle as evidence Action Required should be Yes, not a free-text afterthought that never gets a CAPA. |
Case in point
Case in point: the perfect completion rate that missed the real story
A compliance lead completed the annual programme review with Audits Completed at 100% of Audits Planned, Completion Percent and Completed On Schedule Percent both high, and Programme Effective sitting toward Yes on the strength of it. The completion numbers alone made a strong case for a clean sign-off.
Working down to Effectiveness of the programme, Did Internal Audit Find It First had been marked No for the third cycle running — an external customer audit had caught a supplier-approval gap the internal programme never touched. The completed-on-schedule number was entirely real. The programme still wasn't finding what mattered, and only the field built to test that specifically caught it.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
6 sections
- Reference
- CMP-008
- Archetype
- Review
- Record ID
- APR2-2026-000
- Scoring
- Effectiveness rating
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 19011 cl.5.6
- Links
- Links Audit Programme, Findings
- Tags
- Audit, Governance
- Sections
- 6
- Fields
- 49
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 3
Header
10 fieldsReview ID*
Auto sequence. Format APR-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Cycle Reviewed*
Reviewed By*
Programme ID
Links to CMP-001 Programme ID
Audit The Auditing
A programme that finds nothing is not evidence of a perfect system. It is usually evidence that the audits are shallow or the auditors are not independent.
Delivery
6 fieldsAudits Planned*
Audits Completed*
Completion Percent*
Completed On Schedule Percent*
Clause Coverage Complete*
- Yes3 pts
- Partly1 pt
- No0 pts
Process Coverage Complete*
- Yes3 pts
- Partly1 pt
- No0 pts
Findings profile
9 fieldsTotal Findings*
Findings Per Audit*
Audits Finding Nothing*
Critical And Major*
Repeat Findings*
Systemic Findings*
Findings Concentrated In One Area*
- No3 pts
- Yes0 pts
Area Identified
Consistent Grading Across Auditors*
- Yes3 pts
- Some variation1 pt
- No0 pts
Effectiveness of the programme
6 fieldsFindings Closed Percent*
Average Days To Close*
Effectiveness Verified Percent*
Did Internal Audit Find It First*
The best test of the programme. If the external auditor or the regulator found it first, the internal audit missed it.
- Yes3 pts
- Sometimes1 pt
- No0 pts
External Findings Not Found Internally*
Incidents In Recently Audited Areas*
Auditor pool
6 fieldsActive Auditors*
Auditors Meeting Minimum Audits*
Independence Maintained*
- Yes3 pts
- Mostly1 pt
- No0 pts
Auditor Feedback Sought*
- Yes3 pts
- No0 pts
Auditee Feedback Sought*
- Yes3 pts
- No0 pts
Training Needs Identified*
- Yes3 pts
- No1 pt
Conclusion
12 fieldsProgramme Effective*
- Yes3 pts
- Partly1 pt
- No0 pts
Changes For Next Cycle*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Reported To Management Review*
Next Review Due*
Compliance Lead*
Signature*
Site Manager*
Second Signature*
CMP-008 · record IDs look like APR2-2026-000 · Links Audit Programme, Findings
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The numbers in this review only mean something set against the individual audits behind them. Pulling that together, and making sure a quiet programme gets questioned rather than approved, is where the work actually happens.
Rolls up every Process Audit Record and Internal Audit Report completed in the cycle into this review's counts, so Total Findings and coverage percentages reflect what was actually run, not what someone remembers.
Where Training Needs Identified points at a gap in the auditor pool itself, KnowTrain holds the record of what training was assigned and completed as a result.
Systemic and repeat findings surfaced by this review usually trace back to a quality-system control; KnowQuality holds the corrective action and root-cause record that Action Required and CAPA ID point to.

Holds the full-cycle view — completion, coverage, findings and auditor independence together — and flags where the review's own conclusion doesn't match what the underlying records show, before it goes to sign-off.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Audit Programme Review definitions and key terms
- Audit programme
- The full set of audits planned for a cycle — what gets audited, how often, by whom — set out in the Internal Audit Programme record. This review looks back on it; it doesn't rebuild it.
- Effectiveness (of an audit programme)
- Whether the programme actually surfaces genuine issues before an outside party does, and whether those issues get closed on root cause. Distinct from whether the schedule was completed.
- Systemic finding
- A finding that reflects a gap in how a whole process or control is designed or managed, rather than a one-off lapse — the kind a programme review is specifically checking whether audits are catching.
- Repeat finding
- A finding that has appeared before, at the same or a related site, indicating the earlier corrective action didn't hold or wasn't followed through.
- Independence (auditor pool)
- Whether, across the whole pool of auditors, nobody is routinely auditing their own area — checked at programme level because it can fail even when every individual audit passed its own independence check.
FAQ
Frequently asked questions about audit programme review
Who should complete the Audit Programme Review — the same person who runs the audit schedule?+
It's built for the compliance lead, and there's a case for that being someone with enough authority over the programme to act on what the review finds, but not so close to day-to-day scheduling that they mark their own homework. Independence Maintained and Consistent Grading Across Auditors are there partly to catch that risk.
What if Audits Finding Nothing is high — is that something to flag?+
On its own, no — some processes genuinely run clean. It becomes a problem alongside a low score on Did Internal Audit Find It First or Consistent Grading Across Auditors, which is why the form asks for both rather than treating a clean findings profile as sufficient on its own.
How does this review connect to the individual Process Audit Record and Internal Audit Report entries?+
It aggregates them — Total Findings, Findings Per Audit, Repeat Findings and the coverage percentages are rolled up from the individual audit records completed across the cycle, rather than entered fresh here.
Does a 'Programme Effective: Partly' result require raising a CAPA?+
Not automatically, but Action Required should usually follow it. A Partly or No answer with Action Required left at No is asking to be checked — Priority and CAPA ID exist precisely to make that follow-up visible.
Why does the form ask about auditor feedback and auditee feedback separately?+
Because they surface different problems. Auditors report on the process — is the schedule realistic, is guidance adequate; auditees report on the experience — was the audit fair, useful, disruptive. A programme can be broken from either side without the other side noticing.
What triggers a review outside the normal yearly interval?+
Anything that calls the programme's adequacy into question before the year is up — a serious external finding, a certification decision, a significant change to the sites or processes in scope. Cycle Reviewed should record which cycle, or partial cycle, is under review either way.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Internal Audit and Certification
Internal Audit Programme
Sets out what will be audited, when, by whom and against which standard, across the year
Internal Audit Report
Records an internal audit against a standard or process, with findings and evidence
Audit Plan
Sets out the scope, criteria, schedule and people involved for a single audit
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Auditor Competency Record
Records an internal auditor's training, experience and audits performed
More in Internal Audits
Internal Audit Programme
Sets out what will be audited, when, by whom and against which standard, across the year
Internal Audit Report
Records an internal audit against a standard or process, with findings and evidence
Audit Plan
Sets out the scope, criteria, schedule and people involved for a single audit
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Auditor Competency Record
Records an internal auditor's training, experience and audits performed

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 19011:2018 cl.5.6–5.7 — Monitoring, reviewing and improving the audit programme
- ISO 9001:2015 cl.9.2 — Internal audit
- ISO 45001:2018 cl.9.2 — Internal audit
- ISO/IEC 17021-1 — Conformity assessment: requirements for certification bodies
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.