Section 7.1: Establishing, Implementing, and Monitoring the Audit Programme (ISO 19011 Clause 5)

Key Takeaways

  • The audit programme refers to the high-level multi-audit schedule managed by the PMAP, while the audit plan is the single-audit itinerary created by the Lead Auditor.
  • Establishing the audit programme's objectives requires aligning with strategic organizational priorities and QMS performance metrics (ISO 9001:2015 Clause 9.2).
  • Managing audit programme risks involves assessing resource availability, communication gaps, and information security issues to ensure the integrity of the audit schedule.
  • Monitoring and improving the audit programme is closed-loop, requiring KPIs such as adherence to the audit schedule and corrective action closure rates.
Last updated: July 2026

Section 7.1: Establishing, Implementing, and Monitoring the Audit Programme (ISO 19011 Clause 5)

An audit programme is not merely a schedule of audit dates; it is the strategic framework that governs how an organization plans, conducts, and improves its audit activities over a specified period. According to ISO 19011:2018 Clause 5, the management of an audit programme should align directly with the organization's strategic objectives and support the Quality Management System (QMS) requirements defined in ISO 9001:2015 Clause 9.2.2.


1. Audit Programme vs. Audit Plan

A critical distinction tested on Lead Auditor exams is the difference between an Audit Programme and an Audit Plan.

  • Audit Programme (ISO 19011 Clause 3.4): The overall arrangements for a set of one or more audits planned for a specific timeframe and directed towards a specific purpose. It is managed at a high level by the Person Managing the Audit Programme (PMAP).
  • Audit Plan (ISO 19011 Clause 3.6): A detailed description of the activities and arrangements for a single, specific audit. It is authored by the appointed Lead Auditor for that specific audit.
AttributeAudit ProgrammeAudit Plan
ScopeMulti-audit (often annual or multi-year)Single audit (specific dates, times, and sites)
ResponsibilityPerson Managing the Audit Programme (PMAP)Lead Auditor of the assigned audit team
FocusStrategic alignment, resources, team competenceExecution of audit activities, audit trail, schedules
OutputCalendar of audits, auditor pool, compliance trackerAudit agenda, specific itineraries, clause allocations

2. Establishing the Audit Programme Objectives (ISO 19011 Clause 5.2)

The PMAP must establish objectives for the audit programme to direct the planning and conduct of audits. These objectives should be based on:

  1. Management Priorities: Areas of high strategic importance (e.g., launch of a new product line).
  2. QMS Requirements: The need to verify compliance with ISO 9001:2015.
  3. Statutory, Regulatory, and Contractual Requirements: Mandatory external obligations.
  4. Risk and Opportunity Management: High-risk processes (e.g., outsourced manufacturing) require more frequent auditing.
  5. Results of Previous Audits: Recurrent nonconformities require follow-up audits to verify the effectiveness of corrective actions.

Example Objective: 'Evaluate the transition of process execution to the new automated ERP system in the manufacturing and logistics departments by Q3, verifying compliance with Clause 8.5 (Production and service provision) and assessing the mitigation of operational risks.'


3. Determining and Assessing Risks and Opportunities (ISO 19011 Clause 5.3)

The PMAP must identify and evaluate the risks and opportunities associated with the audit programme. This mirrors the risk-based thinking core to ISO 9001:2015.

Audit Programme Risks

  • Planning Risks: Inadequate definition of audit objectives, inappropriate frequency, or failure to schedule around peak production periods.
  • Resource Risks: Insufficient budget, lack of qualified auditors, or failure to secure technical experts for specialized processes.
  • Communication Risks: Poor communication of audit schedules, resulting in key personnel being unavailable.
  • Implementation Risks: Ineffective coordination, failure to secure auditee cooperation, or lack of security clearances for auditors.
  • Information Security Risks: Failure to protect sensitive operational or proprietary data during the audit process.

Audit Programme Opportunities

  • Synergy and Efficiency: Combining environmental (ISO 14001) and quality (ISO 9001) audits into a single integrated audit to minimize disruption.
  • Technology Integration: Utilizing Remote Auditing Technologies (e.g., live-streaming cameras, shared document repositories) to reduce travel costs.
  • Competence Development: Pairing junior auditors with experienced lead auditors to facilitate knowledge transfer.

4. Establishing and Implementing the Programme (ISO 19011 Clause 5.4 & 5.5)

Once the objectives are set and risks are mitigated, the PMAP must build and execute the programme.

Roles and Responsibilities of the PMAP

The PMAP is responsible for:

  • Defining the scope (extent and boundaries) of the audit programme.
  • Establishing operational procedures for the programme.
  • Determining necessary resources (e.g., financial, technological, and auditor travel).
  • Selecting audit teams, ensuring they have the collective competence to achieve the audit objectives.
  • Establishing operational communication protocols with the auditees and senior leadership.

Auditor Competence and Team Selection

Under ISO 19011 Clause 7, the PMAP must evaluate auditor competence. For an ISO 9001 Lead Auditor, this includes:

  • Knowledge of quality management principles (e.g., customer focus, process approach).
  • Understanding of the ISO 9001:2015 standard clauses.
  • Knowledge of the auditee's specific industry sector, processes, and terminology.
  • Audit team leaders must possess additional leadership and management skills to coordinate the team, resolve conflicts, and represent the team to the client.

5. Monitoring and Improving the Audit Programme (ISO 19011 Clause 5.6 & 5.7)

The PMAP must continuously monitor the implementation of the audit programme to ensure objectives are met.

Key Performance Indicators (KPIs) for Audit Programmes

  • Adherence to Schedule: Percentage of planned audits completed on time.
  • Corrective Action Timeliness: Average time taken by auditees to close out nonconformities.
  • Auditor Performance: Feedback from auditees regarding the professionalism and value-add of the audit team.
  • Management Review Input: The degree to which audit findings lead to system improvements and risk mitigation.

If monitoring reveals deviations (e.g., audits are falling behind schedule due to resource constraints), the PMAP must implement corrective actions, adjust the schedule, or secure additional resources, closing the Plan-Do-Check-Act (PDCA) cycle for the audit programme itself.


6. Real-World Audit Scenario: The Overlooked Logistics Supplier

Consider a multinational manufacturer of medical devices certified to ISO 9001:2015. The PMAP established the annual audit programme but failed to assess the risks associated with outsourcing. Specifically, a newly contracted logistics provider handling sterile packaging distribution was omitted from the audit programme because they were classified as an 'administrative vendor' rather than a 'critical supplier' (violating Clause 8.4 on control of externally provided processes, products, and services).

During a surveillance audit by the registrar, a major nonconformity was issued because the organization had no records of auditing or evaluating this logistics provider. Had the PMAP applied risk-based thinking during the audit programme establishment phase (ISO 19011 Clause 5.3), they would have recognized that the logistics provider directly impacted product integrity and safety. The PMAP would have scheduled a second-party audit of the vendor, mitigating the risk before it escalated to a compliance failure.

This scenario illustrates how critical it is for the PMAP to coordinate with procurement and operations when defining the scope and boundaries of the audit programme.

Test Your Knowledge

Which of the following best describes the difference between an audit programme and an audit plan according to ISO 19011:2018?

A
B
C
D
Test Your Knowledge

During the risk assessment of an audit programme, the Person Managing the Audit Programme (PMAP) identifies that the organization's internal auditors lack the technical expertise to audit a newly installed chemical treatment line. According to ISO 19011 Clause 5.3 and 5.4, how should this risk be addressed?

A
B
C
D
Test Your Knowledge

Which of the following is a Key Performance Indicator (KPI) that a PMAP should use to monitor and evaluate the effectiveness of the overall audit programme?

A
B
C
D