What this is
What is an internal audit programme?
What is an internal audit programme?
The plan governing a set of internal audits over a period: what will be audited, when, by whom, against what criteria, and how findings are handled. ISO 19011 clause 5 treats it as a managed thing in its own right, with objectives, risks, resources and a review of its own effectiveness, distinct from the individual audits it schedules.
How is it different from a schedule?
A schedule lists dates. A programme states why those areas at that frequency, who is competent to audit them, what resources it needs, and how it will know whether it worked. Most organisations have a schedule and describe it as a programme, which is why coverage tends to be even rather than risk-based.
Scope
When is an internal audit programme required?
The programme governs the audits. The audits themselves, and the findings they generate, are separate records.
Use this template when
- Planning the audit cycle across a certification period or a calendar year
- Assigning auditors against competence and independence requirements
- Recording the basis for frequency: risk, change, past performance, customer or scheme requirement
- Reviewing programme effectiveness, including whether findings are being closed and whether they surprise anyone
- Adjusting scope mid-cycle after an incident, a change or a poor external audit
Do not use it for
- The individual audit report, which records what a specific audit found
- Findings and corrective actions, which are tracked in their own records through to verified closure
- Second-party supplier audits, which are a different activity with different competence requirements
- Certification and surveillance audits, which are third party and scheduled by the certification body
- Management review, which consumes audit results rather than producing them
Compliance mapping
Which ISO 19011 cl.5 requirements does this satisfy?
Audit programme requirements are consistent across management system standards, with ISO 19011 supplying the method.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 19011 cl.5.2 | Audit programme objectives established, consistent with management direction and system objectives | Programme design |
| ISO 19011 cl.5.3 | Risks and opportunities to the audit programme determined and addressed | Programme design |
| ISO 19011 cl.5.4 | Programme established including extent, criteria, methods, resources and schedule | Schedule |
| ISO 19011 cl.5.5.4 | Audit team members selected for competence to achieve the audit objectives | Resources |
| ISO 19011 cl.5.7 | Audit programme monitored and reviewed for effectiveness and improvement | Delivery |
| ISO 45001 cl.9.2.2 | Audit programme considering importance of processes, changes and results of previous audits | Schedule |
| ISO 9001 cl.9.2.2 | Auditors selected to ensure objectivity and impartiality; auditors shall not audit their own work | Resources |
| IATF 16949 cl.9.2.2 | Layered process audits, manufacturing process audits and product audits as distinct requirements | Programme design |
What it does not cover
- The audit report, which records the conduct and findings of one audit.
- Corrective action records, which track each finding through cause analysis to verified closure.
- Auditor competence records, which evidence training, experience and calibration per auditor.
- Management review, which takes audit results as an input and allocates resource in response.
- Supplier audit planning, which is second-party activity governed by supplier risk rather than internal process risk.
How to complete it
How to complete an internal audit programme, step by step
Programme design is where the value is created or lost, and it takes about an hour a year that almost nobody spends.
Three inputs: how much the process matters, what has changed, and what previous audits and incidents found. An area with a new process, recent findings and high consequence warrants more attention than a stable area with a clean record. Record the reasoning, because it is what distinguishes a programme from a rota and it is what an auditor will ask about.
Auditors must not audit their own work, which is straightforward at scale and difficult with a team of four. Practical solutions include cross-auditing between sites, swapping between functions, using trained people from a different department, or reciprocal arrangements with a peer organisation. Whatever the approach, record it, because independence is the first thing questioned.
These are different tests and both are necessary. Auditing against procedures reveals whether people follow them; auditing against the standard reveals whether the procedures are adequate. A site can be fully compliant with procedures that do not meet the scheme, and an internal programme testing only the first will never find it.
ISO 19011 treats programme review as a requirement. The useful questions are whether findings cluster by area, by auditor or by clause, whether closure is holding, and whether anything found this year was a surprise. A programme producing no surprises across a full cycle is either auditing an exceptional operation or looking in comfortable places.
What auditors find
Most common internal audit programme findings
Programme-level findings differ from the findings the programme generates, and they are the ones external auditors examine.
| Finding | Clause | What fixes it |
|---|---|---|
| Equal-rotation schedule with no risk basis recorded. | ISO 45001 cl.9.2.2 | Record why each area receives its frequency; the standard requires the consideration, not just the coverage. |
| Auditors auditing their own area or reporting to the area owner. | ISO 9001 cl.9.2.2 | Cross-audit between sites or functions and record the independence arrangement. |
| Findings open beyond ninety days with no escalation. | ISO 45001 cl.10.2 | Age findings and escalate the tail; an old open finding is a management system problem. |
| Repeat findings across cycles indicating nominal closure. | ISO 9001 cl.10.2 | Require verified effectiveness before closure and trend repeats as a programme measure. |
| Auditor competence not evidenced for the processes audited. | ISO 19011 cl.5.5.4 | Record competence per auditor per scope, and calibrate against worked examples. |
| Programme not adjusted after an incident or a poor external audit. | ISO 19011 cl.5.7 | Treat the programme as live; a significant event should redirect scope mid-cycle. |
| Clauses of the standard never audited across the certification cycle. | ISO 45001 cl.9.2.2 | Map coverage against the standard as well as against departments. |
| Audits consistently finding nothing in certain areas. | ISO 19011 cl.5.7 | Compare findings per auditor; zero findings usually indicates depth rather than excellence. |
| Results not reported to relevant management or into management review. | ISO 45001 cl.9.2.2 | Route results to those with authority to act; an unreported audit changes nothing. |
| Programme objectives not defined, so effectiveness cannot be assessed. | ISO 19011 cl.5.2 | State what the programme is for; without objectives the review has no criteria. |
Case in point
Case in point: the year with no surprises
A manufacturing site ran twenty-four internal audits a year across a fixed rotation, closing an average of thirty findings, almost all minor and almost all closed within a month. The programme was well documented and reported monthly. Certification surveillance went smoothly for three years.
The fourth surveillance audit raised two majors in an area that internal audit had covered annually throughout: a process introduced two years earlier had never been added to the audit scope, because the rotation was organised by department and the process sat across two of them.
Reviewing the programme afterwards, the site found that findings per auditor ranged from eleven to zero across six auditors. Two auditors had raised nothing in three years.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- CMP-001
- Archetype
- Plan
- Record ID
- IAP-2026-000
- Scoring
- Coverage percent
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 19011 cl.5
- Links
- Links Clause Register, Site
- Tags
- Audit, Governance
- Sections
- 5
- Fields
- 51
- Follow up fields
- 3
- Repeating sections
- 1
- Links out
- 3
Header
13 fieldsProgramme ID*
Auto sequence. Format IAP-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Version*
Issue Date*
Next Review Due*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Owner*
Approved By*
Risk Based, Not Alphabetical
Auditing every process equally every year wastes effort. Audit more where the risk is high, where performance is poor and where things have recently changed.
Standards Covered*
Programme Period*
Audits Planned*
Programme design
9 fieldsRisk Based Frequency Applied*
- Yes3 pts
- Partly1 pt
- No0 pts
Previous Results Considered*
- Yes3 pts
- No0 pts
Changes Since Last Cycle Considered*
- Yes3 pts
- Partly1 pt
- No0 pts
All Clauses Covered Across Cycle*
Every clause of every standard must be audited at least once in the cycle. Gaps here become external findings.
- Yes3 pts
- Partly1 pt
- No0 pts
Cycle Length Months*
All Processes Covered*
- Yes3 pts
- Partly1 pt
- No0 pts
All Sites Covered*
- Yes3 pts
- Partly1 pt
- No0 pts
All Shifts Covered*
Auditing only day shift misses where most of the deviation happens.
- Yes3 pts
- Partly1 pt
- Day shift only0 pts
Contractors Included*
- Yes3 pts
- Not applicable3 pts
- No0 pts
Schedule
Repeats9 fieldsAudit Title*
Scope*
Standard And Clauses
Planned Month*
Lead Auditor*
Independent Of The Area*
Nobody audits their own work. It is a scheme requirement and a very common finding.
- Yes3 pts
- Partly1 pt
- No0 pts
Risk Rating Of Area*
- Low3 pts
- Medium2 pts
- High1 pt
- Very high0 pts
Audit Duration Days
Status*
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Resources
6 fieldsTrained Auditors Available*
Auditor Days Required
Capacity Sufficient*
- Yes3 pts
- Marginal1 pt
- No0 pts
External Support Used
Budget Allocated*
- Yes3 pts
- Partly1 pt
- No0 pts
Programme Approved*
- Yes3 pts
- No0 pts
Delivery
14 fieldsAudits Completed*
Completed On Schedule*
Completion Percent*
Audits Deferred*
Reason For Deferrals
Coverage Gap At Cycle End*
- None3 pts
- Minor1 pt
- Significant0 pts
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Compliance Lead*
Signature*
Site Manager*
Second Signature*
CMP-001 · record IDs look like IAP-2026-000 · Links Clause Register, Site
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The programme is a plan. What fails is the risk basis nobody recorded, the auditor who never finds anything, and the finding that has been open since March.
Holds the programme against clause coverage and department coverage, tracks findings by age and by auditor, and flags clauses untouched in the cycle.

Compares findings per auditor for comparable scopes and surfaces repeat findings across cycles, which is the clearest signal that closure is nominal.
Feeds incidents and inspection results into programme design, so an area with events attracts audit attention rather than waiting for its slot.
Holds auditor competence per scope and supports calibration, so grading means the same thing across the audit team.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Internal Audit Programme definitions and key terms
- Audit programme
- Arrangements for a set of audits planned for a specific time frame and directed toward a specific purpose, per ISO 19011.
- Audit criteria
- The requirements audited against: the standard, your procedures, legal obligations, customer requirements or a combination.
- Objectivity and impartiality
- The requirement that auditors are free from conflict, which at minimum means not auditing their own work.
- Layered process audit
- An IATF requirement where different management levels audit the same process, so seniority of the auditor is part of the method.
- Finding grade
- Severity classification, meaningful only where definitions are published and applied consistently between auditors.
- Repeat finding
- A finding recurring after a previous closure, indicating the corrective action did not address the cause.
- Programme review
- Assessment of whether the programme achieved its objectives, required by ISO 19011 clause 5.7.
- Coverage map
- A view of which clauses and processes have been audited within the cycle, distinct from which departments have been visited.
FAQ
Frequently asked questions about internal audit programme
How often should we audit each area?+
At planned intervals determined by the importance of the processes concerned, changes affecting the organisation, and the results of previous audits. That is deliberately not an equal rotation. An area that has changed, generated findings or carries high consequence warrants more attention than a stable one, and the reasoning should be recorded so the programme can be defended and adjusted.
Can a small site meet the independence requirement?+
Yes, with deliberate arrangements. Cross-auditing between sites, swapping between functions, training people from unrelated departments, or reciprocal arrangements with a peer organisation all work. What does not work is someone auditing their own area, which external auditors identify quickly and which produces systematically softer findings.
What does a healthy finding profile look like?+
Findings distributed across areas rather than concentrated, comparable numbers per auditor for comparable scopes, most closed within a reasonable window, and few repeats. The warning signs are an auditor who never finds anything, an area that never appears, a long tail of aged open findings, and a rising repeat rate.
Should internal audits ever raise majors?+
If they never do, that is worth examining. Internal audits that only ever raise minors while external audits raise majors indicates the internal programme is testing at a lower depth. Grading definitions should be the same for both, and internal auditors should be calibrated against worked examples so a major means the same thing regardless of who found it.
How do we ensure the whole standard gets covered?+
Map coverage against the standard's clauses as well as against departments, and track it across the certification cycle rather than the year. Department-based rotations reliably miss processes that span two departments, which is exactly where an external auditor tends to look.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Internal Audit and Certification
Internal Audit Report
Records an internal audit against a standard or process, with findings and evidence
Audit Plan
Sets out the scope, criteria, schedule and people involved for a single audit
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Auditor Competency Record
Records an internal auditor's training, experience and audits performed
Process Audit Record
Audits a specific process end to end rather than a standard clause by clause
More in Internal Audits
Internal Audit Report
Records an internal audit against a standard or process, with findings and evidence
Audit Plan
Sets out the scope, criteria, schedule and people involved for a single audit
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Auditor Competency Record
Records an internal auditor's training, experience and audits performed
Process Audit Record
Audits a specific process end to end rather than a standard clause by clause

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 19011:2018 clause 5, managing an audit programme
- ISO 45001:2018 clause 9.2, internal audit
- ISO 9001:2015 clause 9.2, internal audit
- IATF 16949:2016 clause 9.2.2, internal audit programme
- ISO 45001:2018 clause 10.2, incident, nonconformity and corrective action
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.