An audit programme is the backbone of your internal audit function. Without one, you end up with a loose collection of audits that cover the same comfortable areas every year, miss critical processes, and fail to impress certification bodies. Building an audit programme that actually works means moving beyond a spreadsheet with dates on it and creating something that is risk based, properly resourced, and connected to what matters in your organisation. This article walks you through how to do exactly that.
On this page
What an Audit Programme Actually Is
It is worth being precise about this because the terminology trips people up. An audit programme is the overarching arrangement for a set of audits planned over a defined period, typically a year. It is not an audit plan, which is the detailed document for a single audit event. It is not an audit checklist, which is the tool an auditor uses on the day.
Your audit programme answers questions like: How many audits will we conduct this year? Which processes and clauses will each audit cover? Who will conduct them? When will they happen? What criteria will be used? ISO 19011 dedicates an entire clause to managing the audit programme, and for good reason. The programme shapes everything that follows.
A poorly designed programme produces audits that are superficial, repetitive, or disconnected from risk. A well designed programme produces a body of evidence across the year that tells you, your leadership team, and your certification body that the management system is functioning as intended.
Exemplar Global Recognised Training ProviderRTP No. 310970Start With the Purpose, Not the Schedule
Most quality managers make the mistake of opening a blank calendar and starting to fill in audit dates. That is the wrong starting point. Before you schedule anything, you need to define what the programme is trying to achieve.
ISO 9001 Clause 9.2 requires that your internal audit programme takes into account the importance of the processes concerned, changes affecting the organisation, and the results of previous audits. That is not just a compliance checkbox. It is genuinely useful guidance about where to direct your attention.
Ask yourself these questions before you open the calendar:
- Which processes carry the highest risk if they fail?
- Where have nonconformities been raised in previous audits, whether internal or external?
- What has changed in the organisation since the last audit cycle? New sites, new services, new staff, new equipment?
- Are there processes that have never been audited, or not audited in several years?
- What does the certification body expect to see covered before the next surveillance audit?
The answers to these questions should directly shape your programme. If your purchasing process has had three nonconformities in the last two years, it needs more audit attention than a stable, low risk administrative process that has never had a finding.
Risk Based Scheduling: The Core of a Credible Programme
Risk based thinking is not just a phrase to drop into your documentation. It should genuinely drive which processes you audit, how often, and with what depth.
A simple and practical approach is to score your processes against two factors: the consequence of failure, and the confidence you have in the process based on past performance. Processes that score high on consequence and low on confidence get scheduled first and most frequently. Processes that score low on consequence and high on confidence can be scheduled less frequently, or covered lightly as part of a broader process audit.
For example, in a construction company certified to ISO 9001 and ISO 45001, the subcontractor management process probably scores high on both consequence and complexity. You would want to audit it at least annually, possibly more often if the organisation uses a large number of subcontractors. By contrast, the document control process in the same organisation might be well established and rarely problematic. A lighter touch every eighteen months may be entirely appropriate.
This kind of thinking produces a programme that is defensible. When a certification body auditor asks why you scheduled audits the way you did, you can explain your reasoning. That is a much stronger position than saying you divided the clauses evenly across the year.
For a deeper look at how risk should shape your scheduling decisions, the article on risk based audit scheduling covers the practical mechanics in detail.
Coverage: Processes, Clauses, and Sites
One of the most common gaps in audit programmes is incomplete coverage. ISO 9001 Clause 9.2 requires that the audit programme covers all processes relevant to the quality management system. That does not mean every process needs its own dedicated audit. It does mean that over the course of the programme period, every significant process should be examined.
Process Based vs Clause Based Coverage
There is an ongoing debate in the auditing community about whether to organise audits by process or by clause. The honest answer is that process based auditing tends to produce more useful findings, because it reflects how work actually happens rather than how a standard is structured. Auditing the order fulfilment process from customer enquiry through to delivery will naturally touch Clauses 8.2, 8.4, 8.5, and 8.6 without you having to force the structure.
That said, your programme does need to demonstrate clause coverage to satisfy certification body requirements. A simple coverage matrix, showing which processes map to which clauses, solves this neatly. You audit by process, and the matrix shows which clauses each audit addresses.
Multi Site Considerations
If your organisation operates across multiple sites, your programme needs to address each site over the certification cycle. You do not necessarily need to audit every site every year. A risk based approach might mean you audit the highest risk or least mature site annually, and rotate through lower risk sites on a longer cycle. Whatever your approach, document the rationale. Certification bodies will ask.
Building the Audit Schedule
Once you know what needs to be covered and roughly how much attention each area deserves, you can build the schedule. A few practical points that experienced auditors have learned the hard way:
Avoid Clustering Audits Before Surveillance
It is tempting to schedule most of your internal audits in the weeks before a certification body surveillance audit. Resist this. It creates a last minute scramble, produces superficial audits because everyone is under pressure, and actually raises questions with certification body auditors about whether your programme is genuinely continuous or just a compliance exercise. Spread audits across the year.
Allow Enough Time Between Audit and Corrective Action Closure
If you raise a nonconformity in October and your surveillance audit is in November, there is almost no time for a genuine corrective action to be implemented and verified as effective. Build your schedule so that audits of higher risk areas happen early enough in the year for corrective actions to be properly addressed before any external audit.
Account for Organisational Rhythms
Avoid scheduling audits during periods when key personnel will be unavailable or when the business is at its busiest. A manufacturing plant during its annual shutdown is not a good time to audit production processes. A professional services firm in the middle of end of financial year reporting has limited capacity to support an audit. Work with the business calendar, not against it.
Build in Flexibility
Things change. Projects get delayed, people leave, processes are restructured. Your programme should have some buffer built in, either unscheduled slots that can be used if something significant changes, or a formal process for reviewing and updating the programme mid year. ISO 19011 explicitly recognises that audit programmes need to be reviewed and adjusted based on findings and changing circumstances.
Selecting and Preparing Your Auditors
An audit programme is only as good as the people conducting the audits. ISO 9001 Clause 9.2 requires that auditors are selected to ensure objectivity and impartiality. That means an auditor cannot audit their own work. Beyond that basic requirement, you need to think about competence.
Competence for internal auditors means understanding the standard being audited against, understanding the processes being examined, and having the practical skills to conduct an audit, gather evidence, and write findings. A person who understands the standard but has never conducted an audit will struggle. A person who knows the process well but has no auditing training will miss things that a trained auditor would catch.
For organisations that are serious about their internal audit function, investing in proper internal auditor training is not optional. It is the difference between audits that find real issues and audits that produce a clean report that gives management false confidence. The guide to becoming an ISO internal auditor covers the competence requirements and training pathways in detail.
When assigning auditors to specific audits, consider not just independence but also technical familiarity. An auditor with a background in operations will typically conduct a more incisive audit of a production process than one whose background is entirely administrative. Match auditor strengths to audit assignments where you can.
Documenting the Programme
ISO 9001 requires that the audit programme and its results are retained as documented information. That does not mean you need a complex system. What you do need is clear documentation of:
- The programme objectives for the period
- The scope and criteria for each planned audit
- The scheduled dates and assigned auditors
- The status of each audit as the year progresses
- Any revisions made to the programme and the reasons for them
A well structured programme document, combined with individual audit plans and reports, gives you a complete picture of your internal audit activity. This is exactly what a certification body auditor will want to review during a surveillance or recertification audit.
Keep records of audit findings, nonconformity reports, and corrective actions in a way that allows you to track trends over time. If the same type of finding keeps appearing in different parts of the organisation, that is a systemic issue that needs management attention, not just individual corrective actions.
Connecting the Programme to Management Review
Internal audit results are a mandatory input to management review under ISO 9001 Clause 9.3. This is not a formality. The management review is where leadership should be engaging with what the audit programme has found, asking why certain issues keep recurring, and making decisions about resources and priorities.
If your audit programme is producing findings that management never acts on, the programme is not working. Not because the audits are poor, but because the link between audit findings and organisational decision making is broken. Part of designing an effective programme is ensuring that results are reported in a way that management can engage with, and that there is a clear mechanism for escalating significant findings.
A summary report at the end of each audit, followed by a consolidated programme review at the end of the year, gives management what they need without overwhelming them with detail. The consolidated review should highlight trends, areas of persistent weakness, and any processes that performed consistently well and might warrant less intensive audit attention in the next cycle.
Reviewing and Improving the Programme Itself
The audit programme is not a set and forget document. It needs to be reviewed periodically, and adjusted based on what you are learning. ISO 19011 is clear that the person managing the audit programme should monitor its implementation, review its effectiveness, and identify improvement opportunities.
At the end of each audit cycle, ask these questions:
- Did the programme cover everything it needed to?
- Were audits completed on schedule? If not, why not?
- Did the audits produce findings that were genuinely useful, or were they superficial?
- Were corrective actions raised and closed in a timely way?
- Did the programme reflect the actual risk profile of the organisation?
- What feedback did auditors and auditees provide?
The answers should directly feed into how you design the next programme cycle. An audit programme that improves year on year is a sign of a maturing management system. One that stays the same regardless of what it finds is a sign that the programme is being managed as a compliance exercise rather than a genuine improvement tool.
The article on how to build an internal audit programme from scratch provides additional practical guidance on the setup phase, which complements the ongoing management approach covered here.
Common Mistakes That Undermine Audit Programmes
After conducting hundreds of external audits, certain patterns appear repeatedly in organisations whose internal audit programmes are not delivering value. Here are the most common ones:
Auditing the Easy Areas
Some processes are easier to audit than others. Document control is straightforward. Purchasing is harder. Production quality controls require technical knowledge. Auditors, especially those who are not fully trained, gravitate toward the comfortable areas. The result is a programme that produces findings in low risk areas while high risk processes go unexamined. Risk based scheduling, enforced at the programme level, is the remedy.
Treating Audits as Inspections
An audit is not an inspection. The goal is not to catch people doing the wrong thing. It is to gather objective evidence about whether the system is working as intended. Auditors who approach internal audits with an adversarial mindset produce defensive auditees and superficial evidence. The programme should be designed and communicated in a way that positions audits as a tool for improvement, not punishment.
Letting Corrective Actions Drift
Raising a nonconformity and then failing to follow up on the corrective action is one of the most common failures in internal audit programmes. It signals to the organisation that audits do not have real consequences, which undermines the entire function. Your programme should include a formal corrective action tracking process, with assigned owners and due dates, and a verification step to confirm that actions have been effective.
Insufficient Auditor Competence
Assigning internal audits to people who have not been properly trained, on the assumption that they will figure it out, is a false economy. Undertrained auditors miss findings, write weak nonconformity reports, and sometimes create conflict with auditees by handling sensitive situations poorly. Proper training pays for itself quickly in the quality of findings produced.
Exemplar Global Recognised Training ProviderRTP No. 310970Integrating the Programme Across Multiple Standards
Many organisations in Australia are certified to more than one ISO standard. ISO 9001, ISO 14001, and ISO 45001 are frequently held together, particularly in construction, manufacturing, and resources sectors. If your organisation holds multiple certifications, an integrated audit programme can significantly reduce the burden on the business compared to running three separate programmes.
The high level structure shared across these standards means that many clauses map directly to each other. Context of the organisation, leadership, planning, support, performance evaluation, and improvement are all common. An integrated audit of a process can examine quality, environmental, and safety requirements simultaneously, reducing the number of audit days required and the disruption to operational staff.
The key to making integrated audits work is having auditors who are competent across all three standards, or assembling audit teams that collectively cover the required competencies. A single auditor attempting to cover ISO 9001, ISO 14001, and ISO 45001 in depth across a complex process without adequate preparation will produce a superficial result across all three.
Getting the Most From Your Programme
An audit programme that genuinely works is one that leadership trusts, auditors take seriously, and auditees see as useful rather than threatening. That takes time to build. In the early years of a management system, programmes are often more compliance focused. As the system matures, the programme can become more sophisticated, targeting systemic issues, testing the effectiveness of previous corrective actions, and probing areas where the organisation is trying to improve.
The organisations that get the most from their internal audit programmes are those where the quality manager or HSE manager has invested in building genuine auditing capability, not just ticking the box of having conducted a certain number of audits each year. That capability starts with proper training.
At Audit Workshop, the Internal Auditor courses across ISO 9001, ISO 14001, and ISO 45001 are designed to give practitioners the practical skills they need to conduct audits that produce real findings and real improvement. Whether you are building your first audit programme or looking to lift the quality of an existing one, having trained auditors is the foundation everything else rests on.













