8.1 Audit Programme Establishment & Management
Key Takeaways
- ISO 19011 Clause 5 and ISO/IEC 17021-1 Clause 9.1.3 dictate that an audit programme manages one or more audits (internal or external) aligned with organizational objectives, risk profiles, and certification cycles.
- Applying the Plan-Do-Check-Act (PDCA) cycle to the audit programme ensures continuous alignment, resource optimization, procedure standardization, and systemic improvement.
- Programme objectives must consider management priorities, risk assessment findings, regulatory obligations, past audit outcomes, and ISMS scope changes.
- Monitoring and performance evaluation rely on Key Performance Indicators (KPIs) such as schedule variance, nonconformity closure rates, auditor competency alignment, and auditee feedback.
8.1 Audit Programme Establishment & Management
An audit programme consists of arrangements for a set of one or more audits planned for a specific timeframe and directed toward a specific purpose. Whether managing an internal audit function within an enterprise or overseeing third-party certification audits for a Certification Body (CB), audit programme management provides the overarching governance structure. ISO 19011:2018 (Clause 5) provides guidance for internal (1st party) and supplier (2nd party) audit programmes, while ISO/IEC 17021-1:2015 (Clause 9.1.3) defines mandatory requirements for third-party certification audit programmes.
Establishing and managing an effective ISO/IEC 27001 audit programme ensures that an Information Security Management System (ISMS) is systematically evaluated, risks are continuously monitored, and management is provided with objective evidence regarding control performance and compliance.
Applying the PDCA Cycle to Audit Programme Management
An audit programme should not be treated as a static annual schedule. Instead, it must operate as a dynamic management system driven by the Plan-Do-Check-Act (PDCA) cycle:
+-------------------------------------------------------------------+
| 1. PLAN |
| - Define audit programme objectives and extent |
| - Identify & evaluate programme risks and opportunities |
| - Establish procedures, resources, and team competency requirements|
+-------------------------------------------------------------------+
|
v
+-------------------------------------------------------------------+
| 2. DO |
| - Implement audit programme & schedule individual audits |
| - Assign competence-matched audit teams and lead auditors |
| - Manage audit operational logistics & work documents |
+-------------------------------------------------------------------+
|
v
+-------------------------------------------------------------------+
| 3. CHECK |
| - Monitor programme implementation against KPIs |
| - Evaluate auditor performance & team feedback |
| - Assess nonconformity trend reporting & schedule adherence |
+-------------------------------------------------------------------+
|
v
+-------------------------------------------------------------------+
| 4. ACT |
| - Review audit programme performance with top management |
| - Modify programme scope, resources, or auditor selection |
| - Drive continuous improvement of audit governance |
+-------------------------------------------------------------------+
1. Plan: Setting Programme Objectives & Establishing Boundaries
Defining Audit Programme Objectives
The person(s) managing the audit programme must establish objectives that align with the organization's strategic direction, ISMS policy, and risk context. Objectives may focus on:
- ISMS Conformance: Verifying compliance with ISO/IEC 27001:2022 Clauses 4–10 and selected Annex A controls.
- Risk Mitigation: Evaluating controls covering high-risk assets, emerging threats, or recent security incident root causes.
- Legal & Contractual Compliance: Assessing adherence to regulatory mandates (e.g., GDPR, HIPAA, NIS2) and customer Service Level Agreements (SLAs).
- Provider Oversight: Evaluating the security posture of critical cloud service providers and supply chain vendors (2nd-party audits).
- Continual Improvement: Assessing the maturity and effectiveness of corrective action mechanisms.
Determining the Extent (Scope & Scale)
The extent of an audit programme varies based on organizational size, geographical distribution, business complexity, and risk level. Factors influencing extent include:
- Multi-Site Architecture: Number of physical facilities, remote data centers, and cloud regions included in the ISMS scope.
- Operational Complexity: Interdependencies between business processes, outsourcing arrangements, and proprietary technologies.
- Previous Audit Results: High-risk areas or departments with past nonconformities require increased audit frequency and sample sizes.
- Organizational Changes: Mergers, acquisitions, system migrations, or restructuring demand targeted programme adjustments.
| Programme Element | Internal Audit Programme (ISO 19011) | Certification Body Programme (ISO/IEC 17021-1) |
|---|---|---|
| Governance Standard | ISO 19011:2018 Clause 5 | ISO/IEC 17021-1:2015 Clause 9.1.3 & ISO/IEC 27006 |
| Primary Objective | Internal evaluation & continuous improvement | Independent 3rd-party certification assessment |
| Cycle Horizon | Typically 1-year annual plan, multi-year coverage | Fixed 3-year certification cycle |
| Flexibility | Highly flexible based on management priority | Strictly regulated by accreditation body rules |
| Resource Base | Internal auditors or co-sourced consultants | Qualified 3rd-party Lead Auditors & Technical Experts |
2. Do: Implementation, Resources & Operational Procedures
Resource Allocation
The audit programme manager must secure adequate resources to execute the plan efficiently:
- Financial Resources: Budget for travel, specialized auditing tools, training, and external consultant fees.
- Human Capital: Selection of qualified Lead Auditors, technical experts, and translators tailored to specific domain technologies (e.g., Kubernetes security, industrial control systems).
- Time & Scheduling: Allocating sufficient audit person-days based on ISO/IEC 27006 calculation tables, accounting for effective headcount and risk factors.
Audit Programme Procedures
Formal procedures must be established to govern the audit program:
- Audit Planning & Scheduling: Defining lead time, pre-audit questionnaires, and notification protocols.
- Information Security & Confidentiality: Protecting sensitive audit evidence, sampling data, and vulnerability details in compliance with Annex A 5.10 and organizational data handling rules.
- Auditor Competence Evaluation: Assessing and monitoring auditor qualifications, independence, and technical skills.
- Reporting & Nonconformity Escalation: Standardizing finding classifications (Major NC, Minor NC, Opportunity for Improvement) and reporting workflows.
3. Check: Monitoring & Evaluating Programme Performance
To ensure the audit programme achieves its defined objectives, performance must be continuously tracked using Key Performance Indicators (KPIs):
- Schedule Adherence: Percentage of planned audits executed within target timeframes.
- Audit Reporting Timeliness: Days elapsed between audit completion and final report publication (target typically <= 10 business days).
- Corrective Action Velocity: Percentage of nonconformities closed within agreed remediation timelines.
- Auditee & Management Feedback: Post-audit survey scores measuring auditor professionalism, value creation, and process clarity.
- Repeat Findings: Frequency of identical nonconformities recurring across audit cycles, indicating ineffective root cause analysis.
4. Act: Programme Review & Continuous Improvement
The audit programme manager must report programme outcomes to top management during the annual Management Review (Clause 9.3). Based on performance metrics and organizational changes, the manager acts to improve governance by:
- Reallocating audit days from mature, low-risk areas to high-risk or newly integrated business units.
- Replacing auditors or providing targeted training where competency gaps are identified.
- Updating audit procedures to incorporate remote auditing methodologies or automated evidence-gathering tools.
Worked Scenario: Managing a Multi-Site Audit Programme at FinTech Corp
Context: FinTech Corp operates a cloud-based payment gateway across four global locations: Headquarters (New York), R&D Center (Tel Aviv), Cloud Operations (London), and Customer Support BPO (Manila). The ISMS scope encompasses all four sites under a unified ISO/IEC 27001 certificate.
Audit Programme Strategy:
- Plan: The Audit Programme Manager establishes a 3-year audit plan. Given that Manila was added recently and experienced high staff turnover, its internal audit frequency is set to bi-annual, while London and New York undergo annual reviews.
- Do: The manager assigns a specialized Lead Auditor with cloud architecture expertise to audit London's AWS controls (Annex A 8.20–8.24) and an auditor with human resource security expertise to audit Manila (Annex A Theme 6).
- Check: During the mid-year review, the manager discovers that nonconformity closures in Manila are delayed by an average of 45 days due to unclear management ownership.
- Act: The manager escalates the bottleneck to the Chief Information Security Officer (CISO), adjusts the audit programme procedure to mandate executive sign-off on corrective action plans, and schedules a follow-up verification audit for Manila in Q3.
According to ISO 19011 Clause 5, which phase of the audit programme PDCA cycle includes evaluating auditor performance, monitoring schedule adherence, and tracking report delivery timelines?
Which standard specifies the mandatory requirements for third-party certification bodies when managing an ISO/IEC 27001 audit programme?
When establishing the extent and frequency of an internal audit programme, which factor justifies increasing the audit frequency and sample size for a specific business unit?