Exemplar Global Certified Courses from USD 99. Ending Soon!

Managing an Audit Programme Under Clause 5 of ISO 19011:2026

AW

Team @ Audit Workshop

13 min read
Managing an Audit Programme Under Clause 5 of ISO 19011:2026

What Clause 5 of ISO 19011:2026 Actually Covers

Clause 5 of ISO 19011:2026 is the section that deals with managing an audit programme. It sits between the principles in Clause 4 and the guidance on conducting individual audits in Clause 6. That positioning is deliberate. Before you can run a single audit well, you need a functioning programme that tells you what to audit, when to audit it, who will do the auditing, and how you will know whether the programme is working.

A lot of organisations treat their audit programme as a spreadsheet of dates. Clause 5 asks for something more considered than that. It asks you to think about objectives, risks, resources, competence, and outcomes, and to treat the programme itself as something that needs to be managed and improved over time.

This article walks through each element of Clause 5 in practical terms, with the kind of commentary that helps you apply it rather than just read about it.

Clause 5.1: Establishing the Audit Programme

The first step is establishing the programme, and the standard is clear that the programme needs objectives. This is not optional. An audit programme without defined objectives is just a list of appointments. Objectives give the programme purpose and give you a basis for evaluating whether it delivered anything useful.

What objectives should look like

ISO 19011:2026 gives examples of what audit programme objectives might cover. These include determining the extent of conformity with requirements, evaluating the capability of the management system to achieve its stated objectives, identifying opportunities for improvement, and assessing the suitability of the management system for the organisation's context.

In practice, your objectives should be specific enough to guide decisions. To verify conformity with ISO 9001:2015 requirements across all processes is a reasonable objective. To audit the system is not. If your objectives are vague, the programme will drift, and the audits it produces will drift with it.

Risks to the audit programme

One of the more important additions in the 2026 edition of ISO 19011 is the explicit attention given to risks that could affect the audit programme itself. These are not the risks inside the management system being audited. These are risks to the programme as a planning and delivery mechanism.

Examples include auditor unavailability, conflicts of interest that compromise independence, inadequate audit time, poor access to records or personnel, and the risk that the programme becomes routine and stops generating useful findings. The 2026 edition also introduces the concept of undue influence, where pressure from management or auditees distorts audit outcomes. A well managed programme has controls in place to identify and respond to these risks before they undermine audit integrity.

For a deeper look at how the 2026 edition addresses these programme risks specifically, see our article on undue influence and other new audit programme risks in ISO 19011:2026.

Clause 5.2: Determining and Evaluating Audit Programme Resources

Running an audit programme costs something. It costs time, money, and people. Clause 5.2 asks the person managing the programme to determine what resources are needed and to evaluate whether those resources are actually available.

What counts as a resource

Resources in this context include the number and competence of available auditors, the time allocated to each audit, travel and access arrangements for on site audits, tools and technology for documentation and remote auditing, and administrative support for scheduling and record keeping.

Organisations frequently underestimate what a programme actually requires. They schedule six internal audits across the year, assign them to one person who also has a full time role in quality management, and then wonder why audits keep being postponed or rushed. Clause 5.2 is the point where you are supposed to catch that problem before it happens.

Balancing scope with available capacity

If your programme objectives are ambitious but your auditor pool is thin, something has to give. Either you scale back the scope of individual audits, bring in additional auditors, or adjust the frequency. What you should not do is maintain an unrealistic programme on paper while the actual audits become superficial. That produces documented conformity with no actual assurance value.

Clause 5.3: Implementing the Audit Programme

Implementation is where the programme moves from planning to action. Clause 5.3 covers the scheduling of individual audits, the selection and assignment of audit teams, and the practical management of audit activities.

Scheduling audits based on risk

The standard is explicit that audit scheduling should reflect the importance of the processes being audited, changes affecting the organisation, and the results of previous audits. This is risk based scheduling, and it matters because not everything deserves equal audit attention.

A process that has generated multiple nonconformities in the past twelve months deserves more frequent scrutiny than a stable process with a clean audit history. A business unit that has undergone significant restructuring warrants a closer look than one that has been operating consistently. If your schedule treats every process and every department the same regardless of history and risk, you are not really implementing Clause 5.3 in the spirit it intends.

Our article on risk based audit scheduling covers the practical mechanics of this in detail, including how to weight different factors when setting priorities.

Selecting and assigning audit teams

Clause 5.3 also addresses the selection of auditors for specific audits. The key considerations are competence and independence. The auditor or audit team needs the right knowledge and skills for the scope being audited, and they must not audit their own work.

For internal audit programmes, independence is often the harder constraint. In a small organisation, there may be limited options. The standard acknowledges this but does not lower the bar. If the only person with the competence to audit a particular process is also responsible for running it, that is a problem that needs a creative solution, whether that is bringing in an external auditor for that specific scope, training another staff member, or restructuring the programme.

Communicating with auditees

Effective programme implementation includes communicating clearly with the people who will be audited. This means giving adequate notice, sharing the audit plan in advance, and making sure the right personnel will be available. Surprises in audit scheduling rarely produce better outcomes. They produce defensive auditees and rushed evidence gathering.

Clause 5.4: Monitoring the Audit Programme

A programme that is never reviewed is a programme that drifts. Clause 5.4 requires the person managing the programme to monitor its implementation and to track whether it is achieving its objectives.

What monitoring looks like in practice

Monitoring the audit programme means tracking whether audits are being completed as scheduled, whether the findings from audits are being acted on, whether corrective actions are being closed within agreed timeframes, and whether the programme is generating findings that are proportionate to the known risks in the system.

If your programme is consistently producing zero nonconformities across all audits, that is not necessarily a sign of a perfect management system. It may be a sign that the audits are not probing deeply enough, that the auditors lack the confidence to raise findings, or that the audit criteria are too narrow. Monitoring the programme gives you the data to ask those questions.

Tracking audit outcomes over time

One practical approach is to maintain a simple log of audit outcomes across the programme cycle. Track the number of nonconformities raised per audit, the processes or clauses where findings cluster, the time taken to close corrective actions, and any audits that were deferred or abbreviated. Over time, this data tells you a great deal about where the programme is working and where it is not.

Clause 5.5: Reviewing and Improving the Audit Programme

The final element of Clause 5 is the review and improvement of the programme itself. This is the PDCA loop applied at the programme level rather than at the individual audit level.

When to review the programme

ISO 19011:2026 suggests that the programme should be reviewed at appropriate intervals. What counts as appropriate depends on the organisation. A programme running monthly internal audits might warrant a quarterly review. A programme with annual audits might be reviewed annually alongside the management review process.

The review should consider whether the programme objectives were met, whether the resources were adequate, whether the audit criteria remained appropriate, whether the auditors performed competently, and whether the findings from audits led to genuine improvement. If the answer to any of these is no, the programme needs to change.

Feeding programme outcomes into management review

The results of the audit programme review should inform the management review. ISO 9001, ISO 14001, and ISO 45001 all require internal audit results to be an input to management review. That connection only works if the programme is producing meaningful outputs. A programme that generates superficial findings gives management nothing useful to act on.

If you are responsible for presenting internal audit results to top management, the question you should be prepared to answer is: what did the audit programme tell us about the health of the management system that we did not already know? If the honest answer is nothing, the programme needs rethinking.

The Person Managing the Audit Programme

ISO 19011:2026 refers throughout Clause 5 to the person or persons responsible for managing the audit programme. In many organisations this is the Quality Manager, the HSE Manager, or the Management Systems Manager. In some organisations it is a dedicated audit programme manager.

Regardless of title, the role requires a specific set of capabilities. The person managing the programme needs to understand the management system being audited, understand the requirements of the relevant ISO standards, be able to assess auditor competence, manage scheduling and resource constraints, and have enough organisational authority to push back when audits are being deprioritised or compromised.

This is not a purely administrative role. It requires judgement, and it requires the credibility to make decisions about the programme that may not always be convenient for the organisation.

Documented Information for the Audit Programme

Clause 5 does not prescribe a specific format for documented information, but it is clear that the programme needs to be documented in a way that supports its management and review. At a minimum, this typically means an audit schedule, records of individual audits including findings and corrective actions, records of auditor competence and assignments, and evidence of programme reviews.

The level of documentation should be proportionate to the size and complexity of the organisation and the programme. A small business running two or three internal audits per year does not need a complex programme management system. A large organisation with multiple sites, several ISO standards, and a team of internal auditors needs something more structured.

What matters is that the documentation supports continuity. If the person managing the programme is unavailable, someone else should be able to pick up the programme records and understand what has been done, what is planned, and what is outstanding.

Common Weaknesses Auditors Find in Audit Programmes

When external auditors review internal audit programmes, certain weaknesses come up repeatedly. Being aware of these helps you build a more robust programme from the start.

  • Objectives that are not defined or are too generic to provide meaningful direction for the programme.
  • Scheduling that does not reflect risk, with all processes audited at the same frequency regardless of their significance or history.
  • Auditor assignments that compromise independence, particularly in small organisations where the same person audits processes they are responsible for.
  • Corrective actions that are not tracked to closure, leaving findings open indefinitely with no follow up.
  • No evidence of programme review, meaning the programme runs year after year with no assessment of whether it is working.
  • Audit findings that are consistently minor or superficial, suggesting that the audit process is not genuinely probing the system.

If you are building or rebuilding an internal audit programme, our article on how to build an internal audit programme using ISO 19011:2026 provides a step by step practical approach.

How Clause 5 Connects to the Rest of ISO 19011:2026

Clause 5 does not operate in isolation. It connects directly to Clause 6, which covers the conduct of individual audits, and to Clause 7, which addresses auditor competence. The programme sets the context for individual audits. The competence requirements in Clause 7 feed back into the resource and assignment decisions in Clause 5.

It also connects to the principles in Clause 4. The principle of integrity, the principle of fair presentation, the principle of confidentiality, and the principle of independence all need to be reflected in how the programme is designed and managed. A programme that assigns auditors to their own work areas violates independence. A programme that never shares findings with management violates fair presentation. The principles are not decorative. They are operational requirements that should shape every decision you make about the programme.

For a solid grounding in those principles, our article on Clause 4 of ISO 19011:2026 and the principles that underpin every audit covers them in detail.

Practical Steps to Strengthen Your Audit Programme

If you are reviewing your current audit programme against Clause 5, here is a practical starting point.

  1. Write down the objectives of your programme. If you cannot do this in two or three clear sentences, the objectives need work.
  2. Map your audit schedule to your risk profile. Which processes have generated the most findings? Which have changed recently? Which are most critical to your system objectives? Let those factors drive your scheduling decisions.
  3. Review auditor assignments for independence. For every audit on your schedule, confirm that the assigned auditor does not have responsibility for the process being audited.
  4. Check your corrective action records. How many findings from the last programme cycle are still open? What is the average time to close? If the numbers are poor, the follow up process needs attention.
  5. Schedule a programme review. Set a date now to review the programme outcomes against your objectives. Make it a standing item in your management review inputs.

Conclusion

Clause 5 of ISO 19011:2026 is the backbone of a well managed audit function. It moves the conversation from individual audits to the programme that governs them, and it asks you to treat that programme with the same rigour you would apply to any other managed process. Objectives, resources, scheduling, monitoring, and review are not bureaucratic requirements. They are the conditions under which auditing produces genuine value.

If you want to deepen your understanding of how to manage and conduct audits to the standard that ISO 19011:2026 expects, Audit Workshop offers practical training at Internal Auditor and Lead Auditor level across ISO 9001, ISO 14001, and ISO 45001. The courses are built around real audit practice, not theory, and they are delivered by an auditor with over 14 years of experience and 500 external certification audits behind him. You can explore the available courses at auditworkshop.com.

Frequently Asked Questions

An audit programme is a set of one or more audits planned for a specific timeframe and directed towards a specific purpose. Under ISO 19011:2026, it includes the objectives of the programme, the schedule of individual audits, the resources required, the assignment of auditors, and the mechanisms for monitoring and reviewing programme performance. It is distinct from an individual audit plan, which covers the arrangements for a single audit event.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
ISO 45001:2018 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
ISO 14001:2026 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.