Why Audit Planning Is the Most Underrated Skill in Auditing
Most auditors spend a lot of energy thinking about what happens on the audit floor. The interviews, the evidence gathering, the tricky auditees. But the quality of all of that work is largely determined before you walk through the door. ISO audit planning is where experienced auditors separate themselves from the rest.
On this page
A poorly planned audit is chaotic. You run out of time in some areas, skip others entirely, and end up with a report that feels shallow. A well planned audit is focused, efficient, and gives you the best possible chance of finding what actually matters. This guide walks through the full planning process, step by step, the way it works in practice.
Step 1: Clarify the Purpose and Type of Audit
Before you do anything else, you need to be clear on what kind of audit this is and what it is supposed to achieve. Is this an internal audit, a supplier audit, or a certification audit? Is it a full system audit or a focused audit of one process? Is it a follow up audit to verify corrective actions from a previous cycle?
The answers to these questions shape everything that follows. An internal audit of the full quality management system under ISO 9001 requires a very different plan to a targeted supplier audit of a critical subcontractor. The scope, the time allocation, the evidence you are looking for, and the people you need to speak with all change depending on the purpose.
At this stage you also need to confirm who the audit client is and what they are expecting from the audit. For internal audits, that is usually the quality manager or top management. For external audits, it is the certification body or the organisation commissioning the audit. Get this clear in writing before you proceed.
Exemplar Global Recognised Training ProviderRTP No. 310970Step 2: Define the Audit Scope and Criteria
Scope defines the boundaries of the audit. It tells you what is included and what is not. This might be defined by physical location, by process, by standard clause, by product line, or by a combination of these.
A typical scope statement might read:
Design, manufacture, and delivery of structural steel components at the Brisbane facility, audited against ISO 9001:2015.
Audit criteria are the requirements you are auditing against. For an ISO 9001 audit, that is the standard itself, plus the organisation's own documented procedures, work instructions, and any contractual or regulatory requirements that apply. For a supplier audit, it might also include your organisation's supplier requirements specification.
Be specific here. Vague scope leads to scope creep on the day. If the scope says “operations” without defining which operations, you will end up trying to cover everything and doing justice to nothing. Understanding how audit scope works is one of the most practical skills you can develop early in your auditing career.
Step 3: Conduct a Preliminary Document Review
Before writing your audit plan, spend time reviewing the relevant documented information. This is sometimes called a desktop review or document review stage, and it is not optional if you want to plan effectively.
What you are looking for at this stage:
- The organisation's quality manual or system overview, if one exists
- Previous audit reports and outstanding nonconformities
- The organisation's own procedures and work instructions for the processes in scope
- Previous corrective action records
- Any customer complaints or significant incidents that have occurred since the last audit
- Management review records
- Applicable legal and regulatory requirements
This document review does two things. First, it tells you where the risks are. If the last audit raised three nonconformities in the supplier control process and the corrective actions are still open, that area deserves more time in your plan. Second, it tells you whether the system documentation is adequate before you even arrive. If key procedures are missing or obviously out of date, that is already a planning signal.
For certification auditors, this document review is formally part of the Stage 1 audit. For internal auditors, it is simply good practice before writing the audit plan.
Step 4: Conduct a Risk Assessment to Focus Your Effort
Not all processes carry the same level of risk. A well planned audit allocates more time to higher risk areas and less to areas that have consistently performed well. This is the foundation of risk based auditing, and it is explicitly supported by ISO 19011.
When assessing risk for planning purposes, consider:
- Processes that have generated nonconformities in previous audits
- Areas where customer complaints have originated
- Processes that are safety critical or environmentally significant
- Recently changed processes, procedures, or personnel
- Outsourced or subcontracted activities that affect product or service quality
- Areas that have not been audited recently
This risk thinking directly influences your time allocation in the audit plan. If purchasing and supplier control has been a consistent problem area, give it more time. If document control has been well managed for three audit cycles, you might cover it more briefly through sampling rather than a deep dive.
This approach also helps you justify your audit plan to stakeholders. When a manager asks why you are spending three hours in their department, you can point to specific risk factors rather than just saying “because the standard requires it.”
Step 5: Write the Audit Plan
Now you have enough information to write the actual audit plan. The plan is a working document that structures the audit day or days. It does not need to be elaborate, but it does need to be clear and realistic.
A practical audit plan includes:
- Audit objectives
- Audit scope and criteria
- The date, time, and location of the audit
- The names of the audit team members and their assigned areas
- A schedule showing which processes or clauses will be covered at what time
- The names of the auditees to be interviewed and in which sessions
- Time allocated for document review, interviews, and observations
- Time for the audit team to consolidate findings
- Opening and closing meeting times
One of the most common mistakes new auditors make is writing an over ambitious plan. They try to cover twelve clauses in six hours and then wonder why the closing meeting runs late and findings are thin. Be realistic about what you can actually cover properly in the available time. It is better to audit five processes thoroughly than ten processes superficially.
If you want a practical starting point, there is a detailed audit plan template for internal audits that walks through the structure with a worked example.
Step 6: Prepare Your Audit Checklists
Checklists are planning tools, not scripts. A good checklist reminds you of the key requirements you need to verify and helps you stay on track during the audit. A bad checklist becomes a crutch that stops you from thinking and following the evidence.
Build your checklists from the audit criteria. For an ISO 9001 audit, that means working through the relevant clauses and turning the requirements into questions or evidence prompts. For example, under Clause 7.2 Competence, your checklist might include:
- Has the organisation determined the competence required for each role?
- What evidence exists that people are competent? Training records, qualifications, evaluations?
- Where competence gaps were identified, what actions were taken and were they effective?
Tailor your checklists to the specific organisation and the risks you identified in Step 4. A generic checklist downloaded from the internet is a starting point at best. The real value comes from customising it to reflect the organisation's processes, previous findings, and the specific risks in scope.
Also prepare a sampling plan. Decide in advance how many records you will sample in each area. If you are auditing training records for a team of forty people, decide whether you will look at five, ten, or fifteen records and why. Having a sampling rationale prepared means you can defend your approach if it is questioned.
Step 7: Assign Roles Within the Audit Team
If you are auditing alone, this step is simple. If you are leading a team, it requires careful thought. Each team member should be assigned to specific processes or areas based on their competence and any independence requirements.
Independence is non negotiable. Auditors must not audit their own work or areas where they have a conflict of interest. This applies equally to internal and external audits. An internal auditor from the production team should not be auditing production processes. Assign them to a different area where they can be genuinely objective.
Brief your team before the audit begins. Make sure everyone understands the scope, the objectives, the schedule, and their individual responsibilities. Agree on how you will communicate during the day if something significant comes up, and confirm when you will reconvene to consolidate findings before the closing meeting.
Step 8: Communicate the Audit Plan to Stakeholders
The audit plan should be shared with the auditee organisation in advance. How far in advance depends on the type of audit. For internal audits, one to two weeks is usually appropriate. For external certification audits, the certification body typically sends the plan several weeks ahead.
Sharing the plan in advance allows the auditee to arrange for the right people to be available, prepare relevant records, and understand what to expect. It is not about giving them time to hide problems. A well run system should be able to demonstrate conformity at any time. The advance notice is about practical logistics, not about gaming the audit.
When you send the plan, invite feedback. If the auditee flags that a key person will be unavailable at a particular time, or that a process is scheduled to be offline during your planned observation window, you want to know this before the day so you can adjust accordingly.
Step 9: Prepare Logistics and Practical Arrangements
This step is often overlooked, but poor logistics can derail even the best planned audit. Before the audit day, confirm:
- The meeting room or space for the opening and closing meetings
- Access arrangements, including any site inductions, PPE requirements, or security clearances
- Whether the audit will be conducted on site, remotely, or in a hybrid format
- Technology requirements for remote auditing, including platform access and document sharing arrangements
- Contact details for the audit coordinator at the auditee organisation
- Any confidentiality agreements that need to be signed before the audit begins
For remote audits in particular, sorting out the technology in advance is critical. Discovering that your video platform is blocked by the auditee's firewall five minutes before the opening meeting is not a good start. Remote auditing has become increasingly common and brings its own planning considerations that go beyond what traditional on site audits require.
Step 10: Review and Finalise the Plan
Before the audit begins, do a final review of your plan. Ask yourself:
- Does the time allocation reflect the risk assessment I conducted?
- Have I allowed enough time for consolidation before the closing meeting?
- Are the right people scheduled for the right sessions?
- Does the plan address all areas required by the scope?
- Is the plan realistic given the available time?
It is also worth reviewing the plan with a colleague or co auditor if possible. A fresh set of eyes often catches gaps that the person who wrote the plan cannot see. Even experienced auditors benefit from this check.
Remember that the plan is a guide, not a contract. On the day, you will follow the evidence. If an interview reveals something unexpected in an area you had allocated little time to, you may need to adjust. Good planning gives you the structure to make those adjustments intelligently rather than scrambling.
Common Audit Planning Mistakes to Avoid
After conducting hundreds of audits across multiple industries, certain planning mistakes come up repeatedly. Here are the ones that cause the most problems:
- Over scheduling: Trying to cover too much in too little time. The result is shallow coverage and missed findings.
- Skipping the document review: Arriving without understanding the system means you cannot ask targeted questions or identify where the risks sit.
- Generic checklists: Using the same checklist for every organisation in every industry misses the specific risks that matter for that audit.
- Ignoring previous findings: Not reviewing prior audit reports and corrective action status means you may miss systemic issues that have been recurring for years.
- Poor time management: Not building in consolidation time before the closing meeting. This is where findings get written up and graded. Rushing it leads to poorly worded nonconformities that are hard to defend.
- Failing to confirm auditee availability: Discovering that the production manager you needed to interview is on leave on the day of the audit is entirely preventable.
For those who are new to auditing, the article on common mistakes in your first internal audit covers many of these in more detail and is worth reading alongside this planning guide.
Exemplar Global Recognised Training ProviderRTP No. 310970How Planning Differs Across Audit Types
The planning steps above apply to all ISO audits, but the emphasis shifts depending on the type.
Internal Audits
For internal audits, the planning is usually managed by the quality or HSE manager who runs the internal audit programme. The focus is on covering the full system across the audit cycle, allocating effort based on risk, and ensuring independence. The planning of an internal audit programme is a broader exercise that sits above the individual audit plan and determines which processes get audited when across the year.
Supplier Audits
For supplier audits, the planning needs to account for the specific risks that supplier represents to your organisation. You are not auditing their entire system. You are auditing the parts that affect what you receive from them. The scope is narrower and the criteria often include your own supplier requirements in addition to any standard they are certified to.
Certification Audits
For certification audits, the certification body does the planning, but as the auditee organisation's quality manager, you need to understand what the plan covers so you can prepare your team and your records accordingly. The audit plan from the certification body should be reviewed carefully and any concerns raised before the audit day.
Building Your Planning Skills Over Time
Audit planning is a skill that improves with practice. The first time you plan an audit, it will take longer and the plan will be less refined. After ten audits, you will have developed instincts about where to focus, how much time different processes typically need, and how to read a document review to identify risk signals quickly.
Formal training accelerates this development significantly. Lead auditor courses, in particular, spend considerable time on audit planning because it is recognised as a core competency for anyone leading an audit team. If you are conducting internal audits regularly, internal auditor training gives you the structured framework to plan and execute audits with confidence.
At Audit Workshop, our internal auditor and lead auditor courses for ISO 9001, ISO 14001, and ISO 45001 include practical planning exercises built around real audit scenarios. You will work through the planning process from scope definition to checklist preparation, with feedback from trainers who have conducted hundreds of real audits. Whether you prefer live virtual training or self paced study, there is a format that fits your schedule and your learning style.













