Knowella

Internal Audit Programme Template

An internal audit programme is judged by whether its findings surprise anyone. A programme that reliably confirms things are broadly fine is either auditing a very well run operation or auditing the parts that are, and the second is far more common than the first.

KnowComplyPlanCMP-001Pinned in navigationFull guide
Designed from
Risk, change and previous findings
Fails at
Ninety-day open findings

Summary

In short

  • ISO 45001 and ISO 9001 both require audits at planned intervals determined by the importance of the processes, changes affecting the organisation, and the results of previous audits. That is explicitly not an equal rotation.
  • Auditors must be objective and impartial and must not audit their own work. On small sites this usually means cross-auditing between sites, functions or shifts.
  • Findings per auditor reveals depth variation more reliably than findings per area reveals risk. Wide variation usually means some audits are not really happening.
  • An open finding at ninety days has stopped being an audit issue and become a management system issue. The age profile matters more than the count.
  • Repeat findings are the single most informative output. They indicate closure was nominal, which is worse than the original finding because it implicates the corrective action system.
  • Audit against the standard and against your own procedures separately. A site can be perfectly compliant with procedures that do not meet the standard.

What it is

What it is

What is an internal audit programme?

The plan governing a set of internal audits over a period: what will be audited, when, by whom, against what criteria, and how findings are handled. ISO 19011 clause 5 treats it as a managed thing in its own right, with objectives, risks, resources and a review of its own effectiveness, distinct from the individual audits it schedules.

How is it different from a schedule?

A schedule lists dates. A programme states why those areas at that frequency, who is competent to audit them, what resources it needs, and how it will know whether it worked. Most organisations have a schedule and describe it as a programme, which is why coverage tends to be even rather than risk-based.

When to use it

When to use it, and when not to

The programme governs the audits. The audits themselves, and the findings they generate, are separate records.

Use it for

  • Planning the audit cycle across a certification period or a calendar year
  • Assigning auditors against competence and independence requirements
  • Recording the basis for frequency: risk, change, past performance, customer or scheme requirement
  • Reviewing programme effectiveness, including whether findings are being closed and whether they surprise anyone
  • Adjusting scope mid-cycle after an incident, a change or a poor external audit

Not for

  • The individual audit report, which records what a specific audit found
  • Findings and corrective actions, which are tracked in their own records through to verified closure
  • Second-party supplier audits, which are a different activity with different competence requirements
  • Certification and surveillance audits, which are third party and scheduled by the certification body
  • Management review, which consumes audit results rather than producing them

Standards

What it is built against

Audit programme requirements are consistent across management system standards, with ISO 19011 supplying the method.

ClauseRequirementWhere it lands
ISO 19011 cl.5.2Audit programme objectives established, consistent with management direction and system objectivesProgramme design
ISO 19011 cl.5.3Risks and opportunities to the audit programme determined and addressedProgramme design
ISO 19011 cl.5.4Programme established including extent, criteria, methods, resources and scheduleSchedule
ISO 19011 cl.5.5.4Audit team members selected for competence to achieve the audit objectivesResources
ISO 19011 cl.5.7Audit programme monitored and reviewed for effectiveness and improvementDelivery
ISO 45001 cl.9.2.2Audit programme considering importance of processes, changes and results of previous auditsSchedule
ISO 9001 cl.9.2.2Auditors selected to ensure objectivity and impartiality; auditors shall not audit their own workResources
IATF 16949 cl.9.2.2Layered process audits, manufacturing process audits and product audits as distinct requirementsProgramme design

What it does not cover

  • The audit report, which records the conduct and findings of one audit.
  • Corrective action records, which track each finding through cause analysis to verified closure.
  • Auditor competence records, which evidence training, experience and calibration per auditor.
  • Management review, which takes audit results as an input and allocates resource in response.
  • Supplier audit planning, which is second-party activity governed by supplier risk rather than internal process risk.

Filling it in

Filling it in well

Programme design is where the value is created or lost, and it takes about an hour a year that almost nobody spends.

Build frequency from risk, change and history

Three inputs: how much the process matters, what has changed, and what previous audits and incidents found. An area with a new process, recent findings and high consequence warrants more attention than a stable area with a clean record. Record the reasoning, because it is what distinguishes a programme from a rota and it is what an auditor will ask about.

Solve independence explicitly on small sites

Auditors must not audit their own work, which is straightforward at scale and difficult with a team of four. Practical solutions include cross-auditing between sites, swapping between functions, using trained people from a different department, or reciprocal arrangements with a peer organisation. Whatever the approach, record it, because independence is the first thing questioned.

Audit against the standard and against your procedures

These are different tests and both are necessary. Auditing against procedures reveals whether people follow them; auditing against the standard reveals whether the procedures are adequate. A site can be fully compliant with procedures that do not meet the scheme, and an internal programme testing only the first will never find it.

Review the programme, not just the audits

ISO 19011 treats programme review as a requirement. The useful questions are whether findings cluster by area, by auditor or by clause, whether closure is holding, and whether anything found this year was a surprise. A programme producing no surprises across a full cycle is either auditing an exceptional operation or looking in comfortable places.

Audit findings

Common audit findings

Programme-level findings differ from the findings the programme generates, and they are the ones external auditors examine.

FindingClauseWhat fixes it
Equal-rotation schedule with no risk basis recorded.ISO 45001 cl.9.2.2Record why each area receives its frequency; the standard requires the consideration, not just the coverage.
Auditors auditing their own area or reporting to the area owner.ISO 9001 cl.9.2.2Cross-audit between sites or functions and record the independence arrangement.
Findings open beyond ninety days with no escalation.ISO 45001 cl.10.2Age findings and escalate the tail; an old open finding is a management system problem.
Repeat findings across cycles indicating nominal closure.ISO 9001 cl.10.2Require verified effectiveness before closure and trend repeats as a programme measure.
Auditor competence not evidenced for the processes audited.ISO 19011 cl.5.5.4Record competence per auditor per scope, and calibrate against worked examples.
Programme not adjusted after an incident or a poor external audit.ISO 19011 cl.5.7Treat the programme as live; a significant event should redirect scope mid-cycle.
Clauses of the standard never audited across the certification cycle.ISO 45001 cl.9.2.2Map coverage against the standard as well as against departments.
Audits consistently finding nothing in certain areas.ISO 19011 cl.5.7Compare findings per auditor; zero findings usually indicates depth rather than excellence.
Results not reported to relevant management or into management review.ISO 45001 cl.9.2.2Route results to those with authority to act; an unreported audit changes nothing.
Programme objectives not defined, so effectiveness cannot be assessed.ISO 19011 cl.5.2State what the programme is for; without objectives the review has no criteria.

Worked case

Case in point: the year with no surprises

A manufacturing site ran twenty-four internal audits a year across a fixed rotation, closing an average of thirty findings, almost all minor and almost all closed within a month. The programme was well documented and reported monthly. Certification surveillance went smoothly for three years.

The fourth surveillance audit raised two majors in an area that internal audit had covered annually throughout: a process introduced two years earlier had never been added to the audit scope, because the rotation was organised by department and the process sat across two of them.

Reviewing the programme afterwards, the site found that findings per auditor ranged from eleven to zero across six auditors. Two auditors had raised nothing in three years.

Definitions

Definitions and key terms

Audit programme
Arrangements for a set of audits planned for a specific time frame and directed toward a specific purpose, per ISO 19011.
Audit criteria
The requirements audited against: the standard, your procedures, legal obligations, customer requirements or a combination.
Objectivity and impartiality
The requirement that auditors are free from conflict, which at minimum means not auditing their own work.
Layered process audit
An IATF requirement where different management levels audit the same process, so seniority of the auditor is part of the method.
Finding grade
Severity classification, meaningful only where definitions are published and applied consistently between auditors.
Repeat finding
A finding recurring after a previous closure, indicating the corrective action did not address the cause.
Programme review
Assessment of whether the programme achieved its objectives, required by ISO 19011 clause 5.7.
Coverage map
A view of which clauses and processes have been audited within the cycle, distinct from which departments have been visited.

FAQ

Frequently asked questions

How often should we audit each area?+

At planned intervals determined by the importance of the processes concerned, changes affecting the organisation, and the results of previous audits. That is deliberately not an equal rotation. An area that has changed, generated findings or carries high consequence warrants more attention than a stable one, and the reasoning should be recorded so the programme can be defended and adjusted.

Can a small site meet the independence requirement?+

Yes, with deliberate arrangements. Cross-auditing between sites, swapping between functions, training people from unrelated departments, or reciprocal arrangements with a peer organisation all work. What does not work is someone auditing their own area, which external auditors identify quickly and which produces systematically softer findings.

What does a healthy finding profile look like?+

Findings distributed across areas rather than concentrated, comparable numbers per auditor for comparable scopes, most closed within a reasonable window, and few repeats. The warning signs are an auditor who never finds anything, an area that never appears, a long tail of aged open findings, and a rising repeat rate.

Should internal audits ever raise majors?+

If they never do, that is worth examining. Internal audits that only ever raise minors while external audits raise majors indicates the internal programme is testing at a lower depth. Grading definitions should be the same for both, and internal auditors should be calibrated against worked examples so a major means the same thing regardless of who found it.

How do we ensure the whole standard gets covered?+

Map coverage against the standard's clauses as well as against departments, and track it across the certification cycle rather than the year. Department-based rotations reliably miss processes that span two departments, which is exactly where an external auditor tends to look.

The agents

What the agents do with it

The programme is a plan. What fails is the risk basis nobody recorded, the auditor who never finds anything, and the finding that has been open since March.

KnowComply

Holds the programme against clause coverage and department coverage, tracks findings by age and by auditor, and flags clauses untouched in the cycle.

Ella

Compares findings per auditor for comparable scopes and surfaces repeat findings across cycles, which is the clearest signal that closure is nominal.

KnowSafe

Feeds incidents and inspection results into programme design, so an area with events attracts audit attention rather than waiting for its slot.

KnowTrain

Holds auditor competence per scope and supports calibration, so grading means the same thing across the audit team.

This template lives in KnowComplyaudit and governance. Audit programmes, legal register, management review, risk and certification.

Sources

Sources

  • ISO 19011:2018 clause 5, managing an audit programme
  • ISO 45001:2018 clause 9.2, internal audit
  • ISO 9001:2015 clause 9.2, internal audit
  • IATF 16949:2016 clause 9.2.2, internal audit programme
  • ISO 45001:2018 clause 10.2, incident, nonconformity and corrective action
Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.