8.2 Managing an Audit Programme: Planning, Risks & Resources
Key Takeaways
- An audit programme comprises arrangements for a set of one or more audits planned for a specific timeframe and directed toward a specific purpose (ISO 19011 Clause 5).
- An audit programme must be strictly differentiated from an audit plan: the programme governs the strategic, multi-audit architecture, whereas the audit plan details the operational schedule for a single audit.
- ISO 19011:2018 Clause 5.3 introduces a mandatory requirement to identify and evaluate risks and opportunities associated with the audit programme, including planning, resource, competence, and communication risks.
- The person managing the audit programme must possess verified competence to determine programme scope, select qualified audit teams, allocate adequate resources, and monitor performance.
- Programme evaluation under Clauses 5.6 and 5.7 closes the PDCA loop by assessing schedule adherence, auditor consistency, auditee feedback, and driving continual improvement.
8.2 Managing an Audit Programme: Planning, Risks & Resources
Lead Auditor Core Concept: Under ISO 19011:2018 Clause 5 and ISO 45001:2018 Clause 9.2.2, an audit programme is an organization's strategic governance framework for evaluating management system performance over time. The programme manager must proactively evaluate risks that could undermine execution—such as insufficient competence, management resistance, or resource deficits—while leveraging opportunities like combined audits to maximize system maturity.
1. Audit Programme Architecture and Clause 9.2.2 Integration
ISO 19011:2018 defines an audit programme as arrangements for a set of one or more audits planned for a specific timeframe and directed towards a specific purpose. ISO 45001 Clause 9.2.2 mandates that organizations establish, implement, and maintain internal audit programmes considering:
- The importance of the processes concerned;
- Significant changes affecting organizational structure or operations;
- Historical performance and results of previous audits;
- Non-managerial worker consultation under Clause 5.4.
The programme operates across the Plan-Do-Check-Act (PDCA) cycle in ISO 19011 Clause 5:
- Plan (Clauses 5.2 & 5.3): Establish programme objectives and evaluate programme risks and opportunities.
- Do (Clauses 5.4 & 5.5): Establish governance, procedures, and resources, then implement individual audits.
- Check (Clause 5.6): Monitor execution, schedule compliance, and auditor performance.
- Act (Clause 5.7): Review results, identify improvements, and update management review (Clause 9.3).
2. Establishing Programme Objectives and Extent
Audit programmes must align with strategic business direction and OH&S policy. Objectives typically include:
- Verifying conformity with ISO 45001:2018 and statutory safety legislation.
- Evaluating the effectiveness of critical operational controls (e.g., lockout/tagout, chemical ventilation).
- Assessing worker participation maturity under Clause 5.4.
- Facilitating continual improvement across high-hazard operations.
Determining Programme Extent (Clause 5.4.3)
The scale and breadth of the programme depend on:
- Operational Complexity: Multi-site networks, remote field units, and shift rosters.
- Risk Profile: Inherent hazard levels (e.g., petrochemical refining vs. warehouse distribution).
- System Maturity: Newly implemented systems require more frequent, rigorous audits than mature systems.
- Internal Changes: Modifications to production technology, organizational restructuring, or regulatory changes.
3. Evaluating Audit Programme Risks and Opportunities (Clause 5.3)
Clause 5.3 mandates identifying and mitigating risks and opportunities that affect programme objectives:
Programme Risk Categories
- Planning Risks: Setting unachievable objectives, allocating unrealistic durations, or scheduling during seasonal production peaks.
- Resource Risks: Inadequate budgets, insufficient travel time, or lacking essential inspection tools (e.g., personal gas monitors, PPE).
- Auditor Competence Risks: Deploying auditors who lack technical familiarity with specialized operational hazards (e.g., explosive dusts, high-voltage equipment) or statutory safety mandates.
- Communication Risks: Poor stakeholder notification, delayed audit plan distribution, or language barriers across international operations.
- Implementation & Safety Risks: Access permit delays, coordination failures across rotating shifts, and physical OH&S hazards threatening the audit team during field inspections.
- Security & Confidentiality Risks: Cybersecurity vulnerabilities exposing proprietary designs or employee health surveillance records.
Programme Opportunities
- Combined Audits: Integrating ISO 45001 with ISO 9001 and ISO 14001 to reduce duplication and audit fatigue.
- Remote Auditing: Employing secure video streaming and electronic sampling to audit remote or low-hazard sites efficiently.
- Internal Competence Cultivation: Training frontline supervisors as internal auditors to elevate daily safety culture.
4. Operational Implementation: From Programme to Audits (Clause 5.5)
The programme manager translates strategic frameworks into operational execution by:
- Defining individual audit objectives, scope, and criteria.
- Appointing an Audit Team Leader (Lead Auditor) and qualified, independent audit team members.
- Allocating necessary resources, travel support, and technical experts.
- Ensuring the lead auditor prepares and distributes an individualized Audit Plan (Clause 6.3.2).
- Engaging non-managerial worker representatives throughout the audit process.
5. Programme vs. Plan: The Critical Distinction
| Dimension | Audit Programme (ISO 19011 Clause 5) | Audit Plan (ISO 19011 Clause 6.3.2) |
|---|---|---|
| Strategic Scope | Overarching multi-audit governance framework | Tactical schedule for a single specific audit |
| Time Horizon | Long-term duration (1 to 3 years) | Short-term timeframe (hours to several days) |
| Responsibility | Person managing the audit programme | Audit Team Leader (Lead Auditor) |
| Key Content | Objectives, risk evaluations, annual schedules, budgets | Hourly timetable, audited clauses, interviewees, work sites |
| Primary Purpose | Systematic evaluation of the entire management system | Guiding on-site team execution and auditee coordination |
| Flexibility | Formally revised periodically based on performance data | Dynamically adapted on site if new hazards or delays arise |
6. Monitoring, Reviewing, and Improving (Clauses 5.6 & 5.7)
Under Clause 5.6, the programme manager monitors schedule adherence, report quality, auditee feedback, and corrective action closeouts. Under Clause 5.7, the programme is formally reviewed to assess lessons learned, emerging safety risks, and auditor competence. Review outputs feed directly into Top Management Review under Clause 9.3, closing the continual improvement loop.
7. Real-World Audit Scenario: The Overextended Programme
Audit Context: During a Stage 2 surveillance audit of a heavy machinery plant, the Lead Auditor examines the internal audit programme under Clause 9.2.2.
Audit Findings:
- The annual programme scheduled 24 departmental audits, but 10 were cancelled because the sole internal auditor was reassigned to meet production quotas.
- Audits in high-hazard foundry and robotic welding areas lasted under two hours each.
- The internal auditor lacked technical training in machinery functional safety and industrial hygiene.
- The programme manager failed to assess programme risks or report execution failures during management review.
Lead Auditor Evaluation: The auditor issues a Major Nonconformity against ISO 45001 Clause 9.2.2, citing leadership failure (Clause 5.1) and inadequate management review (Clause 9.3). The organization failed to maintain an effective programme based on process importance, allocate adequate resources, and report audit performance to top management.
8. Common Exam Traps & Candidate Pitfalls
- Annual Audit Week Fallacy: Assuming internal audits must occur during a single annual event. Effective programmes distribute audits continuously, increasing frequency for high-hazard areas.
- Worker Exclusion Trap: Overlooking mandatory worker consultation under Clause 5.4 when developing the audit programme.
- Auditor Safety Blindspot: Failing to identify physical hazards to the audit team as an audit programme risk under Clause 5.3.
- Static Plan Assumption: Treating the audit plan as an inflexible contract rather than a dynamic operational guide that can be adjusted when critical hazards emerge.
What is the key structural distinction between an 'audit programme' under ISO 19011:2018 Clause 5 and an 'audit plan' under ISO 19011:2018 Clause 6.3.2?
When establishing and managing an OH&S audit programme under ISO 19011:2018 Clause 5.3, which of the following represents a 'competence risk' that the programme manager must evaluate and mitigate?
An audit programme manager evaluates the performance of the annual OH&S internal audit programme under ISO 19011:2018 Clause 5.6. The review reveals that 40% of scheduled internal audits were cancelled or postponed due to plant production quotas, leaving several high-hazard maintenance processes unaudited. What action must the programme manager take under Clause 5.7?