Risk based audit scheduling is one of those concepts that sounds straightforward until you actually have to do it. You have a list of processes, a handful of available audit days, and a management team that wants maximum value from every audit. The question is not simply what to audit, it is what to audit first, and why. Getting that decision right is the difference between an audit programme that genuinely reduces risk and one that just ticks boxes on a schedule.
On this page
This article walks through the practical side of risk based scheduling: how to assess which areas deserve the most attention, what factors drive prioritisation, and how to build a defensible, flexible schedule that satisfies both your internal needs and the requirements of ISO 9001, ISO 14001, and ISO 45001.
Why Risk Based Scheduling Matters
ISO 9001 Clause 9.2 is clear that the internal audit programme must take into account the importance of the processes concerned and the results of previous audits. ISO 14001 and ISO 45001 carry the same expectation. None of these standards tell you to audit every clause every year with equal frequency. They expect you to use judgement.
The problem is that many organisations default to a flat schedule. Every department gets one audit per year, every clause gets ticked off, and the schedule looks neat on paper. But this approach treats a low risk administrative process the same as a high consequence operational one. It wastes audit time on areas that are performing well and under-invests in areas that could cause serious harm or nonconformity.
Risk based scheduling fixes this by directing audit effort toward areas where the consequences of failure are greatest, where evidence of past problems exists, or where the system is least mature. It is not about being alarmist. It is about being rational with limited time and resources.
Exemplar Global Recognised Training ProviderRTP No. 310970The Core Factors in Risk Based Prioritisation
When deciding what to audit first, you are essentially scoring each process or area against a set of risk factors. There is no single universal formula, but the following factors appear consistently in well run audit programmes.
Consequence of Failure
Ask yourself what happens if this process breaks down. A nonconformance in a final inspection process could mean defective product reaching a customer. A failure in a chemical storage procedure could cause an environmental incident. A gap in hazard identification could leave workers exposed to serious injury.
High consequence areas should be audited more frequently and with greater depth. This is not complicated logic, but it requires honest assessment of what each process actually controls and what the downstream effects of failure would be.
Results of Previous Audits
This is explicitly called out in ISO 9001 Clause 9.2 and its equivalents. If a previous audit raised a major nonconformity in a particular area, that area deserves earlier and closer attention in the next cycle. The same applies to areas where corrective actions were raised but effectiveness was never properly verified.
One pattern worth watching for is the repeat finding. If the same issue appears in successive audits, that is not just a process problem. It may indicate a systemic issue with how root cause analysis is being conducted or how management is responding to findings. Scheduling a follow up audit specifically targeting that area sends a clear signal that the organisation takes effectiveness seriously.
Process Complexity and Change
A process that has recently changed, whether through new equipment, a new procedure, a new team, or a new contractor, carries higher risk than a stable, well established one. Change introduces the possibility that controls have not been properly transferred, that new staff have not been adequately trained, or that the updated procedure does not reflect what is actually happening on the floor.
Build a mechanism into your scheduling process to flag recent changes. When you review the audit programme at the start of each cycle, check what has changed in the organisation since the last round of audits. Those changed areas often deserve to move up the queue.
Regulatory and Legal Exposure
Processes that sit under significant legal or regulatory obligations carry inherent risk. Under ISO 14001, this means processes tied to your compliance obligations, particularly where environmental licences, permits, or statutory reporting are involved. Under ISO 45001, it means processes where WHS legislation imposes specific duties, such as high risk work, plant management, or contractor control.
Regulatory exposure raises the stakes considerably. A gap in a low risk administrative process might result in an internal finding. A gap in a legally mandated control could result in a prosecution, a prohibition notice, or suspension of certification. These areas belong near the top of your audit schedule.
Significant Aspects, Hazards, and Quality Risks
Each standard has its own mechanism for identifying significant risks. ISO 14001 uses the aspects and impacts process to identify significant environmental aspects. ISO 45001 uses hazard identification and risk assessment. ISO 9001 uses risk based thinking applied to processes and their outputs.
The outputs of these risk assessments should feed directly into your audit scheduling decisions. If your aspects and impacts register identifies three significant environmental aspects, the processes that generate or control those aspects should receive priority audit attention. If your risk register identifies five critical OH&S risks, the controls for those risks need to be verified regularly.
If your audit programme is not connected to your risk registers and hazard registers, you are missing the most important input you have. Risk based thinking with practical examples covers how this connection works in practice across the ISO standards.
Audit History and Coverage Gaps
Even in a risk based programme, you cannot ignore areas entirely. If a process has not been audited for two years because it has historically been low risk, that itself becomes a risk. Conditions change. People change. What was low risk two years ago may not be now.
A practical approach is to set a maximum interval for any process, regardless of its risk rating. Some organisations use two years as the outer limit. Others use three. The point is that no area should fall completely off the radar indefinitely.
Building the Risk Matrix for Your Audit Programme
Once you have identified your risk factors, the next step is to create a simple scoring mechanism. You do not need sophisticated software for this. A spreadsheet works fine.
List each process or area in your scope. For each one, score it against your chosen risk factors. A simple three point scale works well in practice: low, medium, and high, or one, two, and three. Then add the scores and rank the processes by total score.
Your highest scoring processes get the earliest audit slots and the most audit time. Your lowest scoring ones can be scheduled later in the cycle or combined with higher priority areas if they share process interfaces.
The specific factors you score against should reflect your organisation. A construction company might weight regulatory exposure and contractor management heavily. A food manufacturer might weight product safety controls and traceability. A professional services firm might weight document control and customer complaint handling. The framework is the same. The weighting reflects your context.
Practical Scheduling: Turning the Risk Assessment Into a Calendar
Once you have your risk ranked list, you need to translate it into an actual schedule. This is where many audit programmes lose their way. The risk assessment gets done, the list gets filed, and the schedule ends up being driven by auditor availability and departmental convenience rather than risk priority.
Allocate Time Proportionally
High risk areas should receive more audit time, not just earlier scheduling. If you have ten audit days available across the year, do not split them evenly across ten processes. Allocate three or four days to your top two or three risk areas and distribute the remainder proportionally. This is what it actually means to take a risk based approach.
Build in Flexibility
No audit programme survives contact with the year entirely intact. Incidents happen. Key personnel go on leave. New risks emerge. Build contingency into your schedule from the start. Reserve at least one or two unallocated audit days per year for reactive audits triggered by incidents, significant nonconformities, or unexpected changes.
This flexibility also allows you to respond when a surveillance audit or certification audit is approaching and you need to verify a particular area is ready. Having spare capacity in your programme means you can act without disrupting everything else.
Sequence Audits Logically
Think about process flow when sequencing your audits. If you are auditing a production process, it often makes sense to audit supplier control and incoming inspection in the same cycle, since weaknesses upstream tend to create problems downstream. Similarly, auditing your management review process makes more sense after you have completed several operational audits, because the management review should be drawing on that operational data.
Process based auditing, rather than clause by clause auditing, lends itself naturally to this kind of sequencing. Process based vs clause based auditing explores why this approach tends to produce more useful findings.
Document Your Rationale
When a certification auditor reviews your internal audit programme, they will want to understand how you determined the frequency and scope of audits. If your schedule is simply a calendar with names on it, that is a weak answer. If you can point to a risk assessment that drove the scheduling decisions, with clear links to your risk registers, aspects registers, and previous audit results, that is a strong answer.
Document the rationale for each scheduling decision. It does not need to be lengthy. A brief note explaining why a particular process was scheduled early or given more audit time is sufficient. This documentation also helps when you review and update the programme at the start of each new cycle.
Reviewing and Updating the Schedule
A risk based audit programme is not a set and forget document. It needs to be reviewed at least annually, and more frequently if significant changes occur. The review should consider the following:
- Have new processes or activities been added to scope?
- Have any significant incidents, complaints, or nonconformities occurred since the last review?
- Have risk assessments, aspects registers, or hazard registers been updated?
- Have previous audit findings been closed and verified as effective?
- Are there any upcoming regulatory changes that affect the risk profile of particular processes?
- Has the organisation undergone significant change, such as new sites, new contracts, or restructuring?
The management review is the natural home for this kind of programme review. Audit results feed into the management review, and the management review outputs should include decisions about the audit programme for the next cycle. If your management review is not addressing the audit programme, that is itself a gap worth noting.
For a deeper look at how audit programme planning connects to the management system as a whole, how to plan an internal audit programme provides a practical walkthrough of the planning process.
Exemplar Global Recognised Training ProviderRTP No. 310970Common Mistakes in Risk Based Scheduling
Even organisations that understand the concept often fall into predictable traps when implementing it.
Treating Risk Assessment as a One Off Exercise
The risk assessment that drives your audit schedule needs to be a living document, not something produced once and never revisited. If your organisation's risk profile changes and your audit schedule does not, you are not actually doing risk based scheduling. You are doing risk based scheduling as it was understood two years ago.
Scheduling Around Convenience Rather Than Risk
It is tempting to schedule audits when it is convenient for the auditee department or when the auditor happens to be available. Convenience is a legitimate consideration, but it should not override risk priority. If your highest risk process keeps getting pushed back because the manager is busy, that is a problem that needs to be escalated, not accommodated.
Ignoring Interfaces Between Processes
Processes do not operate in isolation. A risk in one process often manifests as a problem in another. If you audit each process in complete isolation, you may miss systemic issues that only become visible when you look at how processes connect. Build some cross process auditing into your programme, particularly for high risk interfaces such as design to production, procurement to incoming inspection, or operations to maintenance.
Failing to Verify Corrective Action Effectiveness
Risk based scheduling should include follow up audits for significant findings. If you raised a major nonconformity last year and the corrective action was implemented, you need to verify that the action actually fixed the underlying problem. Scheduling a targeted follow up audit in the affected area is not optional. It is how you close the loop.
Risk Based Scheduling Across Multiple Standards
Many organisations operate integrated management systems covering ISO 9001, ISO 14001, and ISO 45001 simultaneously. Risk based scheduling becomes more complex in this context, but also more powerful.
A single process, such as contractor management, may carry quality risks under ISO 9001, environmental risks under ISO 14001, and safety risks under ISO 45001. Auditing that process once with all three lenses applied is more efficient than scheduling three separate audits. It also gives you a richer picture of how the process is performing across all three dimensions.
When building an integrated audit programme, map each process against the standards it touches. Processes that appear across all three standards are natural candidates for integrated audits and often warrant higher priority because the consequences of failure are broader.
Building and managing an internal audit programme is a skill that develops with practice. If you are looking to formalise your approach, the internal auditor and lead auditor training courses at Audit Workshop cover audit programme planning, risk based scheduling, and practical audit execution across ISO 9001, ISO 14001, and ISO 45001. The training is built around real audit practice, not textbook theory, which means you can apply what you learn immediately.













