17.1 Audit Program Records — Archival, Maintenance & Protection

Key Takeaways

  • PECB Domain 7 expects competence in managing audit program records — especially archival, maintenance, and protection — and in protecting integrity, availability, and confidentiality
  • ISO 19011 groups records into three families: audit-programme records, individual-audit records, and audit-personnel competence/performance records
  • The form and detail of records should demonstrate that audit programme objectives were achieved — not merely that files exist
  • Record management sits alongside environmental (EMS) and complaint management as a component of the management system that supports an audit programme
  • Retention, access control, secure storage, backup, and controlled disposal are the operational controls that turn CIA principles into practice
Last updated: July 2026

17.1 Audit Program Records — Archival, Maintenance & Protection

Quick Answer: PECB Domain 7 requires you to manage audit programme records and apply best practices for archival, maintenance, and protection. Under ISO 19011, the person managing the audit programme must generate, manage, and maintain records that demonstrate programme implementation while addressing integrity, availability, and confidentiality (information security and confidentiality needs).

Managing an ISO 14001 audit programme is not only about scheduling audits and assigning teams. Domain 7 of the PECB ISO 14001 Lead Auditor scheme explicitly tests whether you can manage audit programme records and whether you know best practices for archival, maintenance, and protection. The older PECB handbook wording is equally useful for exam framing: auditors must understand responsibilities to protect the integrity, availability, and confidentiality of audit records, and must understand that record management is one of the management-system components supporting an audit programme — alongside environmental management and complaint management.

Why records matter in an EMS audit programme

Audit records are the evidence trail that the programme itself was planned, risk-based, resourced, executed, and reviewed. Certification bodies, internal audit functions, and supplier-audit programmes all rely on records to:

  • Demonstrate that audit programme objectives were achieved
  • Support consistent decisions (team selection, scope changes, follow-up intensity)
  • Enable competence evaluation of auditors and team leaders
  • Defend conclusions if findings are challenged
  • Feed monitoring, review, and continual improvement of the programme

ISO 19011 emphasizes that the form and level of detail of records should be sufficient to show that programme objectives have been achieved. A cluttered drive of incomplete drafts fails that test; a lean, controlled set of complete, retrievable records passes it.

Three families of audit programme records (ISO 19011)

ISO 19011 structures typical records into three practical families. Memorize the categories and representative examples — exam items often ask which family a given document belongs to.

1) Records related to the audit programme

These describe the programme as a managed system, not a single visit:

  • Schedule of audits (annual/rolling plan)
  • Audit programme objectives and extent
  • Records addressing programme risks and opportunities, and relevant external/internal issues
  • Reviews of audit programme effectiveness

For an EMS context, programme-level records should reflect environmental risk priorities — for example, more frequent coverage of high-impact processes (wastewater, chemical storage, air emissions) versus low-risk office activities.

2) Records related to each individual audit

These are the engagement file for one audit:

  • Audit plans and audit reports
  • Nonconformity reports
  • Corrective-action / follow-up related records (and preventive-action history where still used in legacy systems)
  • Audit follow-up reports, where applicable
  • Supporting working papers (checklists, sampling notes, interview logs, photo logs, test plans) retained under the programme’s control rules

Lead auditors should treat working papers as controlled records, not personal notebooks that disappear when a contractor leaves.

3) Records related to audit personnel

These support competence and assignment decisions:

  • Competence and performance evaluation of audit team members
  • Selection of audit teams and members
  • Maintenance and improvement of competence (training, mentoring, witnessing, CPD)

Without personnel records, a programme cannot objectively justify why a particular lead auditor was assigned to a complex multi-site ISO 14001 Stage 2.

Archival — what “good” looks like

Archival means records are retained in a durable, retrievable, authentic form for the defined retention period — then disposed of under control.

Best practices PECB expects you to reason about:

PracticeExam-ready point
Defined retention periodsAligned to legal, contractual, accreditation, and client requirements — not “keep forever” by default
Authenticity & completenessFinal signed/approved versions clearly distinguished from drafts
Indexing & retrievabilitySearchable identifiers (client, site, date, standard, audit type, lead auditor)
Media durabilityPaper + electronic media both protected from deterioration and format obsolescence
Separation of duties where neededArchives not solely controlled by the person whose performance is being evidenced

For third-party certification programmes, accreditation rules and ISO/IEC 17021-1 expectations reinforce long enough retention to support certification decisions, complaints, and appeals. Internal programmes should still define retention — often tied to management-review cycles and regulatory evidence needs.

Maintenance — keeping records usable and current

Maintenance is the ongoing care of the record system while audits continue:

  • Version control and approval status
  • Timely filing after each audit (plans, reports, NCs, follow-up closure evidence)
  • Updating competence files after witnessing, training, or performance reviews
  • Correcting errors through controlled amendment (who changed what, when, why)
  • Migrating content when tools change (new eQMS, new cloud tenant) without losing auditability

A common programme failure is excellent fieldwork with delayed or incomplete filing. From a Domain 7 perspective, that is a record-management weakness that undermines programme evaluation — because monitoring KPIs cannot be calculated from missing data.

Protection — integrity, availability, confidentiality

PECB’s Domain 7 language maps cleanly to the classic information-security triad applied to audit records:

Integrity

Records must not be altered undetectably. Controls include access rights, write-protection of finals, checksums/audit logs in electronic systems, and controlled paper file rooms. Integrity also means findings remain factual — working papers should support what the report claims.

Availability

Authorized people must retrieve records when needed — for surveillance planning, complaint handling, accreditation assessment, or legal hold. Backups, tested restore procedures, and business-continuity arrangements matter. “Available” does not mean “open to everyone.”

Confidentiality

Audit evidence often includes commercially sensitive process data, environmental incident details, regulatory correspondence, and personally identifiable information about interviewees. ISO 19011 expects processes that address information security and confidentiality needs associated with audit records. Practical controls: need-to-know access, NDAs for team members and technical experts, secure transmission, redaction rules for shared extracts, and secure disposal (shredding / certified destruction / crypto-erase).

Confidentiality obligations continue after the audit ends and after an auditor leaves the organization.

Record management within the audit programme’s management system

Domain 7 also frames the audit programme as having management-system components. Besides record management, PECB highlights:

  • Environmental management — the programme itself should consider environmental aspects of how audits are run (travel, sampling waste, remote vs on-site choices) where relevant, and must remain competent regarding EMS subject matter
  • Complaint management — complaints about auditors, conduct, conclusions, or programme fairness must be recorded, evaluated, and used as inputs to improvement

On the exam, if a scenario describes lost working papers, uncontrolled emailing of draft NCs, or an auditor keeping sole copies on a personal laptop, classify it as a protection/maintenance failure of audit records — not merely a “soft skills” issue.

Practical control set Lead Auditors should expect

Whether you manage an internal EMS audit programme or work inside a certification body’s system, expect documented controls covering:

  1. What records are mandatory for each audit type (internal, supplier, certification Stage 1/2, surveillance, recertification)
  2. Who owns filing completeness (team leader vs programme manager)
  3. Retention and legal-hold rules
  4. Access matrices (auditors, programme manager, certification decision makers, accreditation body under controlled conditions)
  5. Backup, encryption, and secure destruction
  6. Linkage from records to competence evaluation and programme KPIs

Key exam anchors

  • Domain 7 knowledge statement: best practices regarding archival, maintenance, and protection of audit records
  • Domain 7 ability: manage audit programme records
  • CIA responsibilities: integrity, availability, confidentiality
  • ISO 19011: generate, manage, maintain records to demonstrate programme implementation; address information security/confidentiality
  • Three record families: programme / individual audit / personnel
Test Your Knowledge

According to PECB Domain 7 knowledge statements for ISO 14001 Lead Auditor, which trio of best practices is specifically called out for audit records?

A
B
C
D
Test Your Knowledge

Under ISO 19011, which item is classified as a record related to the audit programme (not a single engagement file)?

A
B
C
D
Test Your Knowledge

PECB Domain 7 emphasizes protecting which three properties of audit records?

A
B
C
D
Test Your Knowledge

Besides record management, which pair does PECB Domain 7 cite as components of the management system of an audit programme?

A
B
C
D