Knowella

Internal Audit Programme Template

An internal audit programme is judged by whether its findings surprise anyone. A programme that reliably confirms things are broadly fine is either auditing a very well run operation or auditing the parts that are, and the second is far more common than the first.

KnowComplyPlanCMP-001Pinned in navigation51 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 19011 cl.5
Workspace
KnowComply
Form type
Plan
Designed from
Risk, change and previous findings
Fails at
Ninety-day open findings

The short version

  • ISO 45001 and ISO 9001 both require audits at planned intervals determined by the importance of the processes, changes affecting the organisation, and the results of previous audits. That is explicitly not an equal rotation.
  • Auditors must be objective and impartial and must not audit their own work. On small sites this usually means cross-auditing between sites, functions or shifts.
  • Findings per auditor reveals depth variation more reliably than findings per area reveals risk. Wide variation usually means some audits are not really happening.
  • An open finding at ninety days has stopped being an audit issue and become a management system issue. The age profile matters more than the count.
  • Repeat findings are the single most informative output. They indicate closure was nominal, which is worse than the original finding because it implicates the corrective action system.
  • Audit against the standard and against your own procedures separately. A site can be perfectly compliant with procedures that do not meet the standard.

What this is

What is an internal audit programme?

What is an internal audit programme?

The plan governing a set of internal audits over a period: what will be audited, when, by whom, against what criteria, and how findings are handled. ISO 19011 clause 5 treats it as a managed thing in its own right, with objectives, risks, resources and a review of its own effectiveness, distinct from the individual audits it schedules.

How is it different from a schedule?

A schedule lists dates. A programme states why those areas at that frequency, who is competent to audit them, what resources it needs, and how it will know whether it worked. Most organisations have a schedule and describe it as a programme, which is why coverage tends to be even rather than risk-based.

Scope

When is an internal audit programme required?

The programme governs the audits. The audits themselves, and the findings they generate, are separate records.

Use this template when

  • Planning the audit cycle across a certification period or a calendar year
  • Assigning auditors against competence and independence requirements
  • Recording the basis for frequency: risk, change, past performance, customer or scheme requirement
  • Reviewing programme effectiveness, including whether findings are being closed and whether they surprise anyone
  • Adjusting scope mid-cycle after an incident, a change or a poor external audit

Do not use it for

  • The individual audit report, which records what a specific audit found
  • Findings and corrective actions, which are tracked in their own records through to verified closure
  • Second-party supplier audits, which are a different activity with different competence requirements
  • Certification and surveillance audits, which are third party and scheduled by the certification body
  • Management review, which consumes audit results rather than producing them

Compliance mapping

Which ISO 19011 cl.5 requirements does this satisfy?

Audit programme requirements are consistent across management system standards, with ISO 19011 supplying the method.

ClauseRequirementWhere it lands
ISO 19011 cl.5.2Audit programme objectives established, consistent with management direction and system objectivesProgramme design
ISO 19011 cl.5.3Risks and opportunities to the audit programme determined and addressedProgramme design
ISO 19011 cl.5.4Programme established including extent, criteria, methods, resources and scheduleSchedule
ISO 19011 cl.5.5.4Audit team members selected for competence to achieve the audit objectivesResources
ISO 19011 cl.5.7Audit programme monitored and reviewed for effectiveness and improvementDelivery
ISO 45001 cl.9.2.2Audit programme considering importance of processes, changes and results of previous auditsSchedule
ISO 9001 cl.9.2.2Auditors selected to ensure objectivity and impartiality; auditors shall not audit their own workResources
IATF 16949 cl.9.2.2Layered process audits, manufacturing process audits and product audits as distinct requirementsProgramme design

What it does not cover

  • The audit report, which records the conduct and findings of one audit.
  • Corrective action records, which track each finding through cause analysis to verified closure.
  • Auditor competence records, which evidence training, experience and calibration per auditor.
  • Management review, which takes audit results as an input and allocates resource in response.
  • Supplier audit planning, which is second-party activity governed by supplier risk rather than internal process risk.

How to complete it

How to complete an internal audit programme, step by step

Programme design is where the value is created or lost, and it takes about an hour a year that almost nobody spends.

Build frequency from risk, change and history

Three inputs: how much the process matters, what has changed, and what previous audits and incidents found. An area with a new process, recent findings and high consequence warrants more attention than a stable area with a clean record. Record the reasoning, because it is what distinguishes a programme from a rota and it is what an auditor will ask about.

Solve independence explicitly on small sites

Auditors must not audit their own work, which is straightforward at scale and difficult with a team of four. Practical solutions include cross-auditing between sites, swapping between functions, using trained people from a different department, or reciprocal arrangements with a peer organisation. Whatever the approach, record it, because independence is the first thing questioned.

Audit against the standard and against your procedures

These are different tests and both are necessary. Auditing against procedures reveals whether people follow them; auditing against the standard reveals whether the procedures are adequate. A site can be fully compliant with procedures that do not meet the scheme, and an internal programme testing only the first will never find it.

Review the programme, not just the audits

ISO 19011 treats programme review as a requirement. The useful questions are whether findings cluster by area, by auditor or by clause, whether closure is holding, and whether anything found this year was a surprise. A programme producing no surprises across a full cycle is either auditing an exceptional operation or looking in comfortable places.

What auditors find

Most common internal audit programme findings

Programme-level findings differ from the findings the programme generates, and they are the ones external auditors examine.

FindingClauseWhat fixes it
Equal-rotation schedule with no risk basis recorded.ISO 45001 cl.9.2.2Record why each area receives its frequency; the standard requires the consideration, not just the coverage.
Auditors auditing their own area or reporting to the area owner.ISO 9001 cl.9.2.2Cross-audit between sites or functions and record the independence arrangement.
Findings open beyond ninety days with no escalation.ISO 45001 cl.10.2Age findings and escalate the tail; an old open finding is a management system problem.
Repeat findings across cycles indicating nominal closure.ISO 9001 cl.10.2Require verified effectiveness before closure and trend repeats as a programme measure.
Auditor competence not evidenced for the processes audited.ISO 19011 cl.5.5.4Record competence per auditor per scope, and calibrate against worked examples.
Programme not adjusted after an incident or a poor external audit.ISO 19011 cl.5.7Treat the programme as live; a significant event should redirect scope mid-cycle.
Clauses of the standard never audited across the certification cycle.ISO 45001 cl.9.2.2Map coverage against the standard as well as against departments.
Audits consistently finding nothing in certain areas.ISO 19011 cl.5.7Compare findings per auditor; zero findings usually indicates depth rather than excellence.
Results not reported to relevant management or into management review.ISO 45001 cl.9.2.2Route results to those with authority to act; an unreported audit changes nothing.
Programme objectives not defined, so effectiveness cannot be assessed.ISO 19011 cl.5.2State what the programme is for; without objectives the review has no criteria.

Case in point

Case in point: the year with no surprises

A manufacturing site ran twenty-four internal audits a year across a fixed rotation, closing an average of thirty findings, almost all minor and almost all closed within a month. The programme was well documented and reported monthly. Certification surveillance went smoothly for three years.

The fourth surveillance audit raised two majors in an area that internal audit had covered annually throughout: a process introduced two years earlier had never been added to the audit scope, because the rotation was organised by department and the process sat across two of them.

Reviewing the programme afterwards, the site found that findings per auditor ranged from eleven to zero across six auditors. Two auditors had raised nothing in three years.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

51fields
5 sections
Reference
CMP-001
Archetype
Plan
Record ID
IAP-2026-000
Scoring
Coverage percent
Direction
High is good
Singleton
No
Basis
ISO 19011 cl.5
Links
Links Clause Register, Site
Tags
Audit, Governance
Sections
5
Fields
51
Follow up fields
3
Repeating sections
1
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

13 fields
Text

Programme ID*

Generated on save

Auto sequence. Format IAP-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Text

Version*

Date & Time

Issue Date*

Date & Time

Next Review Due*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Users

Owner*

Users

Approved By*

Info

Risk Based, Not Alphabetical

Auditing every process equally every year wastes effort. Audit more where the risk is high, where performance is poor and where things have recently changed.

Pick List (multi)

Standards Covered*

From FDN-009 StandardFilter: Status is Active
Text

Programme Period*

Numeric Answer

Audits Planned*

Programme design

9 fields
Single Choice

Risk Based Frequency Applied*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Previous Results Considered*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Changes Since Last Cycle Considered*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

All Clauses Covered Across Cycle*

Scored

Every clause of every standard must be audited at least once in the cycle. Gaps here become external findings.

  • Yes3 pts
  • Partly1 pt
  • No0 pts
Numeric Answer

Cycle Length Months*

Single Choice

All Processes Covered*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

All Sites Covered*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

All Shifts Covered*

Scored

Auditing only day shift misses where most of the deviation happens.

  • Yes3 pts
  • Partly1 pt
  • Day shift only0 pts
Single Choice

Contractors Included*

Scored
  • Yes3 pts
  • Not applicable3 pts
  • No0 pts

Schedule

Repeats9 fields
Text

Audit Title*

Text

Scope*

Pick List (multi)

Standard And Clauses

OptionalFrom FDN-009 Clause ReferenceFilter: Status is Active
Single Choice

Planned Month*

JanuaryFebruaryMarchAprilMayJuneJulyAugustSeptemberOctoberNovemberDecember
Users

Lead Auditor*

Single Choice

Independent Of The Area*

Scored

Nobody audits their own work. It is a scheme requirement and a very common finding.

  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Risk Rating Of Area*

Scored
  • Low3 pts
  • Medium2 pts
  • High1 pt
  • Very high0 pts
Numeric Answer

Audit Duration Days

Optional
Single Choice

Status*

Scored
  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts

Resources

6 fields
Numeric Answer

Trained Auditors Available*

Scored
Numeric Answer

Auditor Days Required

Optional
Single Choice

Capacity Sufficient*

Scored
  • Yes3 pts
  • Marginal1 pt
  • No0 pts
Single Choice

External Support Used

Optional
YesNo
Single Choice

Budget Allocated*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Programme Approved*

Scored
  • Yes3 pts
  • No0 pts

Delivery

14 fields
Numeric Answer

Audits Completed*

Scored
Numeric Answer

Completed On Schedule*

Scored
Numeric Answer

Completion Percent*

Scored
Numeric Answer

Audits Deferred*

Scored
Single Choice

Reason For Deferrals

Optional
NoneResourceProduction pressureAuditor unavailableArea shut down
Single Choice

Coverage Gap At Cycle End*

Scored
  • None3 pts
  • Minor1 pt
  • Significant0 pts
Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Compliance Lead*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

CMP-001 · record IDs look like IAP-2026-000 · Links Clause Register, Site

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The programme is a plan. What fails is the risk basis nobody recorded, the auditor who never finds anything, and the finding that has been open since March.

KnowComply

Holds the programme against clause coverage and department coverage, tracks findings by age and by auditor, and flags clauses untouched in the cycle.

Ella
Ella

Compares findings per auditor for comparable scopes and surfaces repeat findings across cycles, which is the clearest signal that closure is nominal.

KnowSafe

Feeds incidents and inspection results into programme design, so an area with events attracts audit attention rather than waiting for its slot.

KnowTrain

Holds auditor competence per scope and supports calibration, so grading means the same thing across the audit team.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Internal Audit Programme definitions and key terms

Audit programme
Arrangements for a set of audits planned for a specific time frame and directed toward a specific purpose, per ISO 19011.
Audit criteria
The requirements audited against: the standard, your procedures, legal obligations, customer requirements or a combination.
Objectivity and impartiality
The requirement that auditors are free from conflict, which at minimum means not auditing their own work.
Layered process audit
An IATF requirement where different management levels audit the same process, so seniority of the auditor is part of the method.
Finding grade
Severity classification, meaningful only where definitions are published and applied consistently between auditors.
Repeat finding
A finding recurring after a previous closure, indicating the corrective action did not address the cause.
Programme review
Assessment of whether the programme achieved its objectives, required by ISO 19011 clause 5.7.
Coverage map
A view of which clauses and processes have been audited within the cycle, distinct from which departments have been visited.

FAQ

Frequently asked questions about internal audit programme

How often should we audit each area?+

At planned intervals determined by the importance of the processes concerned, changes affecting the organisation, and the results of previous audits. That is deliberately not an equal rotation. An area that has changed, generated findings or carries high consequence warrants more attention than a stable one, and the reasoning should be recorded so the programme can be defended and adjusted.

Can a small site meet the independence requirement?+

Yes, with deliberate arrangements. Cross-auditing between sites, swapping between functions, training people from unrelated departments, or reciprocal arrangements with a peer organisation all work. What does not work is someone auditing their own area, which external auditors identify quickly and which produces systematically softer findings.

What does a healthy finding profile look like?+

Findings distributed across areas rather than concentrated, comparable numbers per auditor for comparable scopes, most closed within a reasonable window, and few repeats. The warning signs are an auditor who never finds anything, an area that never appears, a long tail of aged open findings, and a rising repeat rate.

Should internal audits ever raise majors?+

If they never do, that is worth examining. Internal audits that only ever raise minors while external audits raise majors indicates the internal programme is testing at a lower depth. Grading definitions should be the same for both, and internal auditors should be calibrated against worked examples so a major means the same thing regardless of who found it.

How do we ensure the whole standard gets covered?+

Map coverage against the standard's clauses as well as against departments, and track it across the certification cycle rather than the year. Department-based rotations reliably miss processes that span two departments, which is exactly where an external auditor tends to look.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 19011:2018 clause 5, managing an audit programme
  • ISO 45001:2018 clause 9.2, internal audit
  • ISO 9001:2015 clause 9.2, internal audit
  • IATF 16949:2016 clause 9.2.2, internal audit programme
  • ISO 45001:2018 clause 10.2, incident, nonconformity and corrective action

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.