ISO 19011:2026 – Guidelines for auditing management systems #
1 Scope #
This document gives guidance on auditing management systems, including the principles of auditing, managing an audit programme and conducting management system audits, as well as guidance on the evaluation of competence of individuals involved in the audit process. These individuals include those managing the audit programme, auditors and audit teams. It is applicable to all organizations that need to plan and conduct audits of management systems or manage an audit programme. The application of this document to other types of audits is possible, provided that special consideration is given to the specific competence needed and the objectives to be achieved.
2 Normative references #
There are no normative references in this document.
3 Terms and definitions #
For the purposes of this document, the following terms and definitions apply. ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https://www.iso.org/obp
— IEC Electropedia: available at https://www.electropedia.org/
3.1 audit #
systematic, independent and documented process (3.25) for obtaining objective evidence (3.9) and evaluating it objectively to determine the extent to which the audit criteria (3.8) are fulfilled
3.2 combined audit #
audit (3.1) carried out together at a single auditee (3.14) on two or more management systems (3.19)
3.3 joint audit #
audit (3.1) carried out at a single auditee (3.14) by two or more auditing organizations
3.4 remote auditing method #
method used for conducting audit activities from any place other than the location of the auditee (3.14)
3.5 audit programme #
arrangements for a set of one or more audits (3.1) planned for a specific time frame and directed towards a specific purpose
3.6 audit scope #
extent and boundaries of an audit (3.1)
3.7 audit plan #
description of the activities and arrangements for an audit (3.1)
3.8 audit criteria #
set of requirements (3.24) used as a reference against which objective evidence (3.9) is compared
3.9 objective evidence #
data supporting the existence or verity of something
3.10 audit evidence #
records, statements of fact or other information, which are relevant to the audit criteria (3.8) and verifiable
3.11 audit finding #
results of the evaluation of the collected audit evidence (3.10) against audit criteria (3.8)
3.12 audit conclusion #
result of an audit (3.1), after consideration of the audit objectives and all audit findings (3.11)
3.13 audit client #
organization or person requesting an audit (3.1)
3.14 auditee #
organization as a whole or parts thereof being audited
3.15 audit team #
one or more persons conducting an audit (3.1), supported if needed by technical experts (3.17)
3.16 auditor #
person who conducts an audit (3.1)
3.17 technical expert #
<audit> person who provides specific knowledge or expertise to the audit team (3.15)
3.18 observer #
individual who accompanies the audit team (3.15) but does not act as an auditor (3.16) nor a technical expert (3.17)
3.19 management system #
set of interrelated or interacting elements of an organization to establish policies and objectives, as well as processes (3.25) to achieve those objectives
3.20 risk #
effect of uncertainty
3.21 conformity #
fulfilment of a requirement (3.24)
3.22 nonconformity #
non-fulfilment of a requirement (3.24)
3.23 competence #
ability to apply knowledge and skills to achieve intended results
3.24 requirement #
need or expectation that is stated, generally implied or obligatory
3.25 process #
set of interrelated or interacting activities that use inputs to deliver an intended result
3.26 performance #
measurable result
3.27 effectiveness #
extent to which planned activities are realized and planned results are achieved
4 Principles of auditing #
4.1 General #
Auditing is characterized by reliance on a number of principles. These principles should help to make the audit an effective and reliable tool in support of management policies and controls, by providing information on which an organization can act in order to improve its performance. Adherence to these principles is fundamental to provide audit conclusions that are relevant and sufficient, and for enabling auditors, working independently from one another, to reach similar conclusions in similar circumstances. The guidance given in Clauses 5 to 7 is based on the seven principles outlined in 4.2 to 4.8.
4.2 Integrity #
Integrity is the foundation of professionalism. Auditors and the individual(s) managing an audit programme should:
a) perform their work ethically, with honesty and responsibility;
b) only undertake auditing activities if they are competent to do so;
c) perform their work in an impartial manner, i.e. remain fair and unbiased in all their dealings;
d) be sensitive to any influences that can be exerted on their judgement while carrying out an audit.
4.3 Fair presentation #
Fair presentation is the obligation to report truthfully and accurately. Audit findings, audit conclusions and audit reports should reflect truthfully and accurately the auditing activities. Significant obstacles encountered during the audit and unresolved diverging opinions between the audit team and the auditee should be reported. The communication should be truthful, accurate, objective, timely, clear and complete.
4.4 Due professional care #
Due professional care is the application of diligence and judgement in auditing. Auditors should exercise due care irrespective of the importance of the task they perform, and the confidence placed in them by the audit client and other interested parties. An important factor in carrying out their work with due professional care is having the ability to make reasoned judgements in all audit situations.
4.5 Confidentiality #
Confidentiality is security and privacy of information. Auditors should exercise discretion in the use and protection of information acquired in the course of their auditing activities. Audit information should not be used inappropriately for personal gain by the auditor or the audit client, or in a manner detrimental to the legitimate interests of the auditee. This principle includes the proper handling of sensitive or confidential information.
4.6 Independence #
Independence is the basis for the impartiality of the audit and objectivity of the audit conclusions. Auditors should be independent of the activity being audited wherever practicable and should in all cases act in a manner that is free from bias and conflict of interest. Auditors should maintain objectivity throughout the audit process to ensure that the audit findings and conclusions are based only on the audit evidence. When it is not possible for internal auditors to be independent of the activity being audited, every effort should be made to remove bias and encourage objectivity.
4.7 Evidence-based approach #
Evidence-based approach is the rational method for reaching reliable and reproducible audit conclusions in a systematic audit process. Audit evidence should be verifiable. It should be based on samples of the information available, since an audit is conducted during a specified duration and with finite resources. An appropriate use of sampling should be applied, since this is closely related to the confidence that can be placed in the audit conclusions.
4.8 Risk-based approach #
Risk-based approach is an audit approach that considers risks and opportunities. The risk-based approach should substantively influence the planning and implementation of the audit programme, and the planning, conducting and reporting of audits in order to ensure that audits are focused on matters that are significant for the audit client, and for achieving the audit programme objectives.
5 Managing an audit programme #
5.1 General #
An audit programme should be established. It can include audits addressing one or more management system standards or other requirements, conducted either separately or in combination (combined audit). The extent of an audit programme should be based on the size and nature of the auditee, as well as on the functionality, complexity, the type of risks and opportunities, the scope, and the level of maturity of the management system(s) to be audited. The functionality of the management system can be even more complex in the case of multiple locations or when important functions are sourced externally. Particular attention should be paid to where important decisions are made and to the design, planning and review of the audit programme. The audit programme should be scaled in accordance with the size and complexity of the organization. In order to understand the context of the auditee, the audit programme should take into account the organization’s:
— organizational objectives;
— relevant external and internal issues;
— needs and expectations of relevant interested parties;
— application of technology such as digital tools;
— information security and confidentiality requirements.
When allocating resources and methods to the audit programme, priority should be given to matters in the management system with higher inherent risk and lower levels of performance. Competent individuals should be assigned to manage the audit programme (see 5.4.2). The audit programme should include information and identify resources to enable the audits to be conducted effectively within the specified time frames. The information should include:
a) objectives for the audit programme (see 5.2);
b) risks and opportunities associated with the audit programme (see 5.3) and the actions to address them;
c) scope (extent, boundaries, locations) of each audit within the audit programme;
d) schedule (number/duration/frequency) of the audits;
e) audit types, such as internal or external;
f) audit criteria;
g) auditing methods to be employed, including remote auditing methods (see Clause A.16);
h) criteria for selecting the audit team (audit team leader, auditors and, if needed, technical experts);
i) criteria for participation of observers, where relevant;
j) the organization’s context based on external and internal issues;
k) relevant documented information.
Some of this information is not always available until more detailed audit planning is completed. The implementation of the audit programme should be monitored and assessed on an ongoing basis (see 5.6) to ensure its audit programme objectives have been achieved. The audit programme should be reviewed in order to determine the need for changes and possible opportunities for improvements (see 5.7).
5.2 Establishing audit programme objectives #
The audit client should ensure that the audit programme objectives are established to direct the planning and conducting of audits and should ensure the audit programme is implemented effectively. Audit programme objectives should be consistent with the audit client’s strategic direction, its context, and support its management system policies and objectives. These objectives can be based on consideration of the following:
a) needs and expectations of relevant interested parties, both external and internal;
b) characteristics of and requirements for processes, products, services and projects, and any changes to them;
c) management system requirements, including differing specific requirements covered during a combined audit;
d) need for evaluation of organizations that are part of the supply chain;
e) auditee’s level of performance and level of maturity of the management system(s), as reflected in relevant performance indicators, the occurrence of nonconformities or incidents or complaints from interested parties;
f) identified risks and opportunities to the auditee;
g) results of previous audits.
Examples of audit programme objectives can include the following:
— identifying opportunities for the improvement of a management system and its performance;
— evaluating the capability of the auditee to determine its context;
— evaluating the capability of the auditee to determine risks and opportunities and to identify and implement effective actions to address them;
— determining the conformance to all relevant requirements (e.g. statutory and regulatory requirements, compliance commitments, requirements for certification to a management system standard);
— establishing the level of confidence in the capability of an organization in the supply chain;
— determining the continuing suitability, adequacy and effectiveness of the auditee’s management system;
— evaluating the compatibility and alignment of the management system objectives with the strategic direction of the organization.
5.3 Determining and evaluating audit programme risks and opportunities #
There are risks and opportunities related to the context of the auditee that can be associated with an audit programme and can affect the achievement of its objectives. The individual(s) managing the audit programme should identify risks and opportunities and present them to the audit client when developing the audit programme and resource requirements, so that they can be addressed appropriately. Risks can be associated with the following:
a) planning (e.g. failure to set relevant and appropriate audit objectives and determine the extent, number, duration, locations and schedule of the audits);
b) resources (e.g. allowing insufficient time, equipment and/or training for developing the audit programme or conducting an audit; lack of competent auditors; loss of auditors or availability of auditors);
c) selection of the audit team (e.g. insufficient overall competence to conduct audits effectively, lack of independence and impartiality of the auditors);
d) selection of the audit method (e.g. on-site, remote, taking into account the capability of the selected method to achieve the defined audit objective) (see Clause A.1, A.15 and A.16);
e) communication (e.g. ineffective communication processes/channels);
f) implementation (e.g. ineffective coordination of the audits within the audit programme, not conducting the audits in accordance with the audit programme or not considering information security and confidentiality);
g) control of documented information (e.g. ineffective determination of the necessary documented information required by auditors and relevant interested parties, failure to adequately protect audit records);
h) monitoring, reviewing and improving the audit programme (e.g. ineffective monitoring of audit programme outcomes);
i) sponsorship (e.g. failure to engage leadership to enable an effective audit programme implementation);
j) availability and cooperation of the auditee and availability of evidence to be sampled;
k) security of information communication technology methods (e.g. ineffective or unsecured platform selection).
Opportunities for improving the audit programme can include:
— allowing multiple audits to be conducted in a single visit;
— minimizing time and distances for the travel to locations;
— matching the audit team’s competence to the level required to achieve the audit objectives;
— selecting the audit method to be used to align with the capability and availability of information and communication technologies.
5.4 Establishing the audit programme #
5.4.1 Roles and responsibilities of individual(s) managing the audit programme #
The individual(s) managing the audit programme should:
a) ensure that the integrity of the audit programme is maintained and that there is no undue influence exerted over the audit programme;
b) establish the extent of the audit programme according to the relevant objectives (see 5.2) and any known constraints;
c) determine the external and internal issues, and risks and opportunities that can affect the audit programme, and implement actions to address them, integrating these actions in all relevant auditing activities, as appropriate;
d) ensure the selection of audit teams and the overall competence for the auditing activities by assigning roles, responsibilities and authorities, and supporting leadership, as appropriate;
e) establish all relevant processes including for:
1) the audit objectives, scope(s) and criteria of the audits, determination of auditing methods and selection of the audit team;
2) the coordination and scheduling of all audits within the audit programme;
3) the evaluation of auditor(s) competence (see 7.2);
4) the external and internal communications, as appropriate;
5) the resolution of disputes and handling of complaints;
6) the audit follow-up, if applicable;
7) reporting to the audit client and relevant interested parties, as appropriate;
f) determine and ensure provision of all necessary resources;
g) ensure that appropriate documented information is prepared and maintained, including audit programme records;
h) monitor, review and improve the audit programme;
i) communicate the audit programme to the audit client and, as appropriate, relevant interested parties.
The individual(s) managing the audit programme should request its approval by the audit client.
5.4.2 Competence of individual(s) managing the audit programme #
The individual(s) managing the audit programme should have the necessary competence to manage the programme, effectively and efficiently, including knowledge of:
a) audit principles (see Clause 4), methods and processes (see Clauses A.1 and A.2);
b) management system standards, other relevant standards and reference/guidance documents;
c) information regarding the auditee and its context (e.g. external/internal issues, relevant interested parties and their needs and expectations, business activities, products, services and processes of the auditee);
d) applicable statutory and regulatory requirements and other requirements relevant to the business activities of the auditee.
As appropriate, knowledge of risk management, project and process management, and information and communications technology can be considered. The individual(s) managing the audit programme should be engaged in appropriate continual professional development activities to maintain the necessary competence to manage the audit programme.
5.4.3 Establishing the scope of the audit programme #
The individual(s) managing the audit programme should determine the scope of the audit programme. This can vary depending on the information provided by the audit client or the auditee regarding its context (see 5.3).
Other factors impacting the scope of an audit programme can include the following:
a) the objective, scope and duration of each audit and the number of audits to be conducted, reporting method and, if applicable, audit follow up;
b) the management system standards;
c) the number, importance, complexity, similarity and locations of the activities to be audited;
d) factors influencing the effectiveness of the management system;
e) applicable audit criteria, such as planned arrangements for the relevant management system standards, statutory and regulatory requirements and other requirements to which the organization is committed;
f) results of previous internal or external audits and management reviews, if appropriate;
g) results of a previous audit programme review;
h) language, cultural and social issues;
i) the concerns of interested parties, such as customer complaints, non-compliance with statutory and regulatory requirements and other requirements to which the organization is committed, or supply chain issues;
j) significant changes to the auditee’s context or its operations and related risks and opportunities;
k) availability of information and communication technologies (e.g. adequate network bandwidth, computer and network hardware and software) to support auditing activities, in particular the use of remote auditing methods (see Clause A.16);
l) the occurrence of external and internal events (e.g. nonconformities of products or services, or incidents impacting information security, health and safety or the environment);
m) business risks and opportunities, including actions to address them.
5.4.4 Determining audit programme resources #
When determining resources for the audit programme, the individual(s) managing the audit programme should consider:
a) the financial and time resources necessary to develop, implement, manage and improve auditing activities;
b) auditing methods (see Clause A.1);
c) the individual and overall availability of auditors and technical experts having competence appropriate to the particular audit programme objectives (e.g. including interpreters);
d) the extent of the audit programme (see 5.4.3) and audit programme risks and opportunities (see 5.3);
e) travel time, travel cost, accommodation and other auditing needs;
f) the impact of different time zones and languages;
g) the availability of information and communication technologies (e.g. technical resources required to set up an audit using technologies that support remote collaboration);
h) the availability of any tools, technology and equipment required;
i) the availability of necessary documented information, as determined during the establishment of the audit programme (see Clause A.5);
j) requirements related to the facility, including any security clearances and equipment (e.g. background checks, personal protective equipment, ability to wear industry appropriate attire).
5.5 Implementing the audit programme #
5.5.1 General #
Once the audit programme has been established (see 5.4.3) and related resources have been determined (see 5.4.4), the operational planning and the coordination of all the activities within the programme should be implemented. The individual(s) managing the audit programme should:
a) communicate the relevant parts of the audit programme, including the risks and opportunities involved, to relevant interested parties and inform them periodically of its progress, using established external and internal communication channels;
b) define objectives, scope and criteria for each individual audit;
c) select auditing methods (see Clause A.1);
d) coordinate and schedule audits and other activities relevant to the audit programme;
e) ensure the audit teams have the necessary competence (see 5.5.4);
f) provide necessary individual and overall resources to the audit teams (see 5.4.4);
g) ensure that audits are conducted in accordance with the audit programme, managing operational risks, opportunities and issues as they arise during the deployment of the programme;
h) ensure relevant documented information regarding the auditing activities is properly managed and maintained (see 5.5.7);
i) define and implement the operational controls (see 5.6) necessary for audit programme monitoring;
j) review the audit programme in order to identify opportunities for its improvement (see 5.7).
5.5.2 Defining the objectives, scope and criteria for an individual audit #
Each individual audit should be based on defined audit objectives, scope and criteria. These should be consistent with the overall audit programme objectives. The audit objectives define what is to be accomplished by the individual audit and can include the following:
a) determination of the extent of conformity of the management system to be audited, or parts of it, with audit criteria;
b) evaluation of the capability of the management system to assist the organization in meeting relevant statutory and regulatory requirements and other requirements to which the organization is committed;
c) evaluation of the effectiveness of the management system in meeting its intended results;
d) finding opportunities for improvement of the management system;
e) evaluation of the suitability and adequacy of the management system with respect to the context and strategic direction of the organization;
f) evaluation of the capability of the management system to establish and achieve objectives and effectively address risks and opportunities, in a changing context, including the implementation of the related actions;
g) consideration of any sector-specific management system auditing standards.
The audit scope should be consistent with the audit programme and audit objectives. It includes factors such as locations, functions, activities and processes to be audited, as well as the time period covered by the audit. The audit criteria are used as a reference against which conformity is determined. These can include one or more of the following: applicable policies, processes, procedures, performance criteria including objectives, statutory and regulatory requirements, management system requirements, information regarding the context and the risks and opportunities as determined by the audit client (including relevant external/ internal interested parties requirements), sector codes of conduct or other planned arrangements. In the event of any changes to the audit objectives, scope or criteria, the audit programme should be modified if necessary and communicated to interested parties for approval, if appropriate. When more than one discipline is being audited at the same time, it is important that the audit objectives, scope and criteria are consistent with the relevant audit programmes for each discipline. Some disciplines can have a scope that covers the whole organization and others can have a scope that covers a subset of the whole organization.
5.5.3 Selecting and determining auditing methods #
The individual(s) managing the audit programme should select and determine the methods for effectively and efficiently conducting an audit, depending on the defined audit objectives, scope and criteria. Audits can be performed on-site, remotely or as a combination. The use of these methods should be suitably balanced, based on, among other things, consideration of associated risks and opportunities. Where two or more auditing organizations conduct a joint audit of the same auditee, the individuals managing the different audit programmes should agree on the auditing methods and consider implications for resourcing and planning the audit, including the impact on the organization. If an auditee operates two or more management systems of different disciplines, combined audits can be included in the audit programme. Annex A provides additional guidance on audit methods. The methods can include interviews, the use of checklists and questionnaires, document review, sampling, observing work, analysing data, and on-site review.
5.5.4 Selecting audit team members #
The individual(s) managing the audit programme should appoint the members of the audit team, including the audit team leader and any technical experts needed for the specific audit. An audit team should be selected, taking into account the competence needed to achieve the objectives of the individual audit within the defined scope. If there is only one auditor, the auditor should perform all applicable duties of an audit team leader.
To ensure the overall competence of the audit team, the following steps should be performed:
— identification of the competence needed to achieve the objectives of the audit;
— selection of the audit team members so that the necessary competence is present in the audit team.
In deciding the size and composition of the audit team for the specific audit, consideration should be given to the following:
a) Determination of the competence needed to achieve the objectives of the audit.
b) The complexity of the audit.
c) Whether the audit is combined or joint.
d) The selected auditing methods.
e) The audit process is carried out in an objective and impartial manner.
f) The ability of the audit team members to work and interact effectively with the representatives of the auditee and relevant interested parties.
g) The relevant external/internal issues, such as the language of the audit, and the auditee’s social and cultural characteristics. These issues can be addressed either by the auditor’s own skills or through the support of a technical expert. There can be a need for an interpreter.
h) The type and complexity of the audit (e.g. time zones, number of locations, processes to be audited).
i) Travel permissions (e.g. security clearances, health permits, visas, as applicable).
Where appropriate, the individual(s) managing the audit programme should consult the audit team leader on the composition of the audit team. If the necessary competence is not covered by the auditors in the audit team, technical experts with complementary competence should be made available to support the team.
Auditors-in-training can be included in the audit team but should participate under the direction and guidance of an auditor. Changes to the composition of the audit team can be necessary during the audit (e.g. if a conflict of interest or competence issue arises). If such a situation arises, it should be resolved with the appropriate parties (e.g. audit team leader, the individual(s) managing the audit programme, audit client or auditee) before any changes are made.
5.5.5 Assigning responsibility for an individual audit to the audit team leader #
The individual(s) managing the audit programme should assign the responsibility for conducting the individual audit to an audit team leader. The assignment should be made in sufficient time before the scheduled date of the audit, in order to ensure the effective planning of the audit. To ensure effective conduct of the individual audit, the following information should be provided to the audit team leader:
a) audit objectives;
b) audit criteria and any relevant documented information;
c) audit scope, including identification of the organization and its functions and processes to be audited;
d) audit processes and associated methods;
e) composition of the audit team;
f) contact details of the auditee, and the locations, time frame and duration of the auditing activities to be conducted;
g) resources necessary to conduct the audit;
h) information needed for evaluating and addressing identified risks and opportunities to the achievement of the audit objectives;
i) information which supports the audit team leader in their interactions with the auditee for the effectiveness of the audit programme.
The assignment information should also cover the following, as appropriate:
— working and reporting language of the audit where this is different from the language of the auditor or the auditee, or both;
— audit conclusions required and to whom they are to be distributed;
— matters related to confidentiality and information security, as required by the audit programme;
— any health, safety and environmental arrangements for the auditors;
— requirements for travel or access to remote locations;
— any confidentiality, security, access and authorization requirements;
— any actions to be reviewed (e.g. follow-up activities from a previous audit);
— coordination with other auditing activities (e.g. when different teams are auditing similar or related processes at different locations or in the case of a joint audit).
Where a joint audit is conducted, it is important to reach agreement among the organizations conducting the audits, before the audit commences, on the specific responsibilities of each party, particularly with regard to the authority of the audit team leader appointed for the audit.
5.5.6 Managing audit programme results #
The individual(s) managing the audit programme should ensure that the following activities are performed:
a) evaluation of the achievement of the objectives for each audit within the audit programme;
b) review and approval of audit reports regarding the fulfilment of the audit scope and objectives;
c) review of the effectiveness of actions taken to address audit findings;
d) distribution of audit reports to the previously determined parties;
e) determination of the necessity for any follow-up audit.
The individual managing the audit programme should consider, where appropriate, communicating the audit conclusions and good practices to other areas of the organization.
5.5.7 Managing audit related records #
The individual(s) managing the audit programme should ensure that audit records are generated, managed and retained to demonstrate the implementation of the audit programme. Processes should be established to ensure that any information security and confidentiality needs associated with the audit records are addressed. Records can include the following:
a) Records related to the audit programme, such as:
1) schedule of audits;
2) audit programme objectives and extent;
3) those addressing audit programme risks and opportunities, and relevant external and internal issues;
4) reviews of the audit programme effectiveness.
b) Records related to each audit, such as:
1) audit plans and audit reports;
2) audit evidence and audit findings;
3) relevant feedback from the auditee, auditor(s) and interested parties;
4) nonconformity reports;
5) corrections and corrective action reports;
6) audit follow-up activities.
c) Records related to the audit team covering topics such as:
1) competence and performance evaluation of the audit team members;
2) criteria for the selection of audit teams and team members and formation of audit teams;
3) maintenance and improvement of competence.
The form and level of detail of the records should demonstrate that the objectives of the audit programme have been achieved.
5.6 Monitoring the audit programme #
The individual(s) managing the audit programme should ensure the evaluation of:
a) whether audit schedules are being met and audit programme objectives are being achieved;
b) the performance of the audit team members including the audit team leader and the technical experts;
c) the ability of the audit teams to implement the audit plan;
d) feedback from audit clients, auditees, auditors, technical experts and other relevant parties;
e) sufficiency and adequacy of documented information in the audit process.
Some factors can indicate the need to modify the audit programme. These can include changes to:
— audit findings;
— demonstrated level of the auditee’s management system effectiveness and maturity;
— effectiveness of the audit programme;
— audit scope or audit programme extent;
— the auditee’s management system;
— standards and other requirements to which the organization is committed;
— organizations that are part of the supply chain;
— identified conflicts of interest;
— the audit client’s requirements.
5.7 Reviewing and improving the audit programme #
The individual(s) managing the audit programme and the audit client should review the audit programme to assess whether its objectives have been achieved. Lessons learned from the audit programme review should be used as inputs for the improvement of the programme. The individual(s) managing the audit programme should ensure the following:
— review of the overall implementation of the audit programme;
— identification of areas with opportunities for improvement;
— implementation of changes to the audit programme if necessary;
— review of the continual professional development of auditors, in accordance with 7.6;
— reporting of the results of the audit programme and review of them with the audit client and relevant interested parties, as appropriate.
The audit programme review should consider the following:
a) results and trends from audit programme monitoring;
b) conformity to audit programme processes and relevant documented information;
c) evolving needs and expectations of relevant interested parties;
d) audit programme records;
e) alternative or new auditing methods;
f) alternative or new methods to evaluate auditors;
g) effectiveness of the actions to address the risks and opportunities, and external and internal issues associated with the audit programme;
h) confidentiality and information security issues relating to the audit programme.
6 Conducting an audit #
6.1 General #
This clause contains guidance on preparing and conducting a specific audit as part of an audit programme. provisions of this clause are applicable depends on the objectives and scope of the specific audit.
6.2 Initiating the audit #
6.2.1 General #
The responsibility for conducting the audit should remain with the assigned audit team leader (see 5.5.5) until the audit is completed (see 6.6). To initiate an audit, the steps in Figure 1 should be considered; however, the sequence can differ depending on the auditee, processes and specific circumstances of the audit.
6.2.2 Establishing contact with the auditee #
The audit team leader should ensure that contact is made with the auditee within an appropriate time frame to:
a) confirm communication channels with the auditee’s representatives;
b) confirm the authority to conduct the audit;
c) provide relevant information on the audit objectives, scope, criteria, methods and audit team composition, including any technical experts;
d) request access to relevant information for planning purposes, including information on the risks and opportunities the organization has identified and how they are addressed;
e) confirm applicable statutory and regulatory requirements and other requirements relevant to the activities, processes, products and services of the auditee;
f) confirm the agreement with the auditee regarding the extent of the disclosure and the treatment (e.g. storage, transfer and release) of confidential information;
g) make arrangements for the audit including the audit plan;
h) determine any location-specific arrangements for access, health and safety, security, confidentiality or other issues;
i) agree on the attendance of observers and the need for guides or interpreters for the audit team;
j) determine any areas of interest, concern or risks to the auditee in relation to the specific audit;
k) resolve issues regarding composition of the audit team with the auditee or audit client.
6.2.3 Determining the feasibility of the audit #
The feasibility of the audit should be determined to provide reasonable confidence that the audit objectives can be achieved. The determination of feasibility should take into consideration factors such as the following:
a) sufficient and appropriate information for planning and conducting the audit;
b) adequate cooperation from the auditee;
c) adequate time and other resources for conducting the audit;
d) local, regional, or world events or circumstances that would affect the scheduled audit.
Where the audit is not feasible, an alternative should be proposed to the audit client, in agreement with the auditee.
6.3 Preparing auditing activities #
6.3.1 Performing the review of documented information #
The documented information for the relevant management system should be reviewed by audit team member(s) to:
— gather information to understand the auditee’s operations, inherent risks, and to prepare auditing activities and applicable audit working documents (see 6.3.4) (e.g. on processes or functions);
— establish an overview of the extent of the documented information to determine potential conformity to the audit criteria and detect possible areas of concern, such as deficiencies, omissions or conflicts.
The documented information should include, but is not limited to, management system documents and records, as well as previous audit reports. The review should take into account the context of the organization, including its size, nature and complexity, and its related risks and opportunities. It should also take into account the audit scope, criteria and objectives.
6.3.2 Audit planning #
6.3.2.1 Risk-based approach to planning #
The audit team leader should adopt a risk-based approach to plan the audit based on the information in the audit programme and the documented information provided by the auditee. Planning should facilitate the efficient scheduling and coordination of the auditing activities in order to achieve the objectives effectively. Practical application of the risk-based approach can include prioritizing audit focus based on factors such as product/process complexity, customer complaints, past audit findings, and changes in regulatory or operational environments. The amount of detail provided in the audit plan should reflect the scope and complexity of the audit. In planning the audit, the audit team leader should consider the following:
a) the composition of the audit team and its overall competence;
b) the appropriate sampling techniques (see Clause A.6);
c) the risks to achieving the audit objectives created by ineffective audit planning;
d) opportunities to improve the effectiveness and efficiency of the auditing activities;
e) the risks to the auditee created by performing the audit.
Risks to the auditee can result from the presence of the audit team members adversely influencing the auditee’s arrangements for health and safety, environment and quality, and its products, services, personnel or infrastructure (e.g. contamination in clean room facilities). For combined audits, particular attention should be given to the interactions between operational processes and any competing objectives and priorities of the various management system requirements. When identifying potential risks in joint audits, particular attention should be given to the coordination of different audit teams, including sampling and audit time arrangement, to ensure the achievement of the audit objectives.
6.3.2.2 Audit planning details #
Audit planning should consider the risks of the auditing activities on the auditee’s processes and provide the basis for the agreement among the audit client, the audit team and the auditee regarding the conduct of the audit. The scope and content of the audit planning can differ, for example, between initial and subsequent audits, as well as between external and internal audits. Audit planning should be sufficiently flexible to permit changes that can become necessary as the auditing activities progress. Audit planning should address or reference the following:
a) the audit objectives;
b) the audit scope, including identification of the organization and its functions, as well as processes to be audited;
c) the audit criteria and any reference documented information;
d) the locations (physical and virtual), dates, expected time and duration of auditing activities to be conducted, including meetings with the auditee’s management, breaks and audit team meetings;
e) the need for the audit team to familiarize themselves with the auditee’s facilities and processes (e.g. by conducting a tour of physical location(s) or reviewing information and communication technology);
f) the auditing methods to be used, including the extent to which audit sampling is needed to obtain sufficient audit evidence;
g) the roles and responsibilities of the audit team members, as well as guides and observers or interpreters;
h) the allocation of appropriate resources based upon consideration of the risks and opportunities related to the activities that are to be audited.
Audit planning should take into account, as appropriate:
— identification of the auditee’s representative(s) for the audit;
— the working and reporting language of the audit, where this is different from the language of the auditor or the auditee, or both;
— the expected contents of the audit report;
— logistics and communications arrangements, including specific arrangements for the locations to be audited;
— any specific actions to be taken to address risks to achieving the audit objectives;
— any specific actions to be taken to address opportunities arising;
— matters related to confidentiality and information security;
— any follow-up activities from a previous audit or other source(s) (e.g. lessons learned, project reviews);
— any follow-up activities to the planned audit, as required;
— coordination with other auditing activities, in the case of a joint audit.
Audit plans should be presented to the auditee and the audit client, as required. Any issues with the audit plans should be resolved between the audit team leader, the auditee and, if necessary, the individual(s) managing the audit programme.
6.3.3 Assigning work to the audit team #
The audit team leader, in consultation with the audit team, should assign to each team member responsibility for auditing specific processes, activities, functions or locations and, as appropriate, authority for decision- making. Such assignments should take into account the impartiality and objectivity and competence of auditors and the effective use of resources, as well as the different roles and responsibilities of auditors, auditors-in-training and technical experts. Audit team meetings should be held, as appropriate, by the audit team leader in order to allocate work assignments and decide possible changes. Changes to the work assignments can be made as the audit progresses in order to ensure the achievement of the audit objectives.
6.3.4 Preparing documented information for the audit #
The audit team members should collect and review the information relevant to their audit assignments and prepare documented information for the audit, using any appropriate media. The documented information for the audit can include, but is not limited to:
a) checklists;
b) audit sampling details;
c) audiovisual information.
The use of these media should not restrict the extent of auditing activities, which can change as a result of information collected during the audit.
Documented information prepared for, and resulting from, the audit should be retained at least until audit completion, or as specified in the audit programme. Retention of documented information after audit completion is described in 6.6. Documented information created during the audit process involving confidential or proprietary information, including images and audiovisual recordings, should be suitably safeguarded at all times by the audit team members.
6.4 Conducting auditing activities #
6.4.1 General #
Auditing activities are normally conducted in a defined sequence as indicated in Figure 1. This sequence can be varied to suit the circumstances of specific audits. Audit activities can be conducted concurrently and can be dependent on the result of previous audit activities.
6.4.2 Assigning the roles and responsibilities of guides and observers #
Guides and observers can accompany the audit team with approvals from the audit team leader, audit client and/or auditee, if required. They should not influence or interfere with the conduct of the audit. If this cannot be ensured, the audit team leader should have the right to deny observers from being present during certain auditing activities.
For observers, any arrangements for access, health and safety, environmental, security and confidentiality should be managed between the audit client and the auditee. Guides, appointed by the auditee, should assist the audit team and act on the request of the audit team leader or the auditor to whom they have been assigned. Their responsibilities should include the following:
a) assisting the auditors in identifying individuals to participate in interviews and confirming timings and locations;
b) arranging access to specific locations of the auditee;
c) ensuring that rules concerning location-specific arrangements for access, health and safety, environmental, security, confidentiality and other issues are known and respected by the audit team members and observers and any risks are addressed;
d) witnessing the audit on behalf of the auditee, when appropriate;
e) providing clarification or assisting in collecting information, when needed.
6.4.3 Conducting the opening meeting #
The purpose of the opening meeting is to:
a) confirm the agreement of all participants (e.g. auditee, audit team) to the audit plan;
b) introduce the audit team and their roles;
c) ensure that all planned auditing activities can be performed.
An opening meeting should be held with the auditee’s management and, where appropriate, those responsible for the functions or processes to be audited. During the meeting, a contingency for asking questions should be provided. The degree of detail should be consistent with the familiarity of the auditee with the audit process. In many instances (e.g. for internal audits in a small organization), the opening meeting can simply consist of communicating that an audit is being conducted and explaining the nature of the audit. For other audit situations, the meeting can be formal and records of attendance should be retained. The meeting should be chaired by the audit team leader. Other participants, including observers, guides, technical experts and interpreters should be introduced and their roles explained. The following items should be confirmed or explained, as appropriate:
— the audit objectives, scope and criteria;
— the audit plan and other relevant arrangements with the auditee, such as the date and time for the closing meeting, any interim meetings between the audit team and the auditee’s management, and any change(s) needed;
— formal communication channels between the audit team and the auditee;
— the language to be used during the audit;
— the auditing methods to manage risks to the organization which can result from the presence of the audit team members;
— audit evidence to be collected through a sampling process;
— the auditee being kept informed of audit progress during the audit;
— the availability of the resources and facilities needed by the audit team;
— matters relating to confidentiality and information security;
— relevant access, health and safety, security, emergency and other arrangements for the audit team;
— activities on-site that can impact the conduct of the audit.
The presentation of information on the following items should be considered, as appropriate:
— the method of reporting audit findings including criteria for grading of nonconformities, if any;
— conditions under which the audit can be terminated;
— how to deal with possible audit findings during the audit;
— any plan for feedback from the auditee on the audit findings or conclusions of the audit, including complaints or appeals.
6.4.4 Communicating during the audit #
During the audit, it can be necessary to make formal arrangements for communication within the audit team, as well as with the auditee, the audit client and potentially with external interested parties (e.g. regulatory authorities), especially where statutory and regulatory requirements require mandatory reporting of nonconformities. The audit team should communicate periodically to exchange information, assess audit progress and reassign work between the audit team members, as needed. During the audit, the audit team leader should periodically communicate the progress, any significant audit findings and any concerns to the organization and, as appropriate, the audit client. Evidence collected during the audit that suggests an immediate and significant risk should be reported without delay to the auditee and, as appropriate, to the audit client and the individual(s) managing the audit programme. Any concern about an issue outside the audit scope should be noted and reported to the audit team leader, for possible communication to the audit client and auditee. Where the available audit evidence indicates that the audit objectives are unattainable, the audit team leader should report the reasons to the audit client, the auditee and the individual(s) managing the audit programme to determine appropriate actions. Such actions can include changes to the audit plan, the audit objectives or audit scope, or termination of the audit. Any need for changes to the audit plan which become apparent as audit activities progress should be reviewed and accepted, as appropriate, by both the individual(s) managing the audit programme and the audit client, and presented to the auditee. These changes should be documented.
6.4.5 Providing access to audit information #
The auditing methods chosen for an audit depend on the defined audit objectives, scope and criteria, as well as duration and location. The location is where the information needed for the specific audit activity is available to the audit team. This can include physical and virtual locations. Where, when and how to access information is crucial to the audit. This is independent of where the information is created, used and/or stored. Based on these issues, the auditing methods need to be determined (see Clause A.1). The audit can use a mixture of methods. Also, audit circumstances can mean that the methods need to change during the audit.
6.4.6 Reviewing documented information while conducting the audit #
The auditee’s relevant documented information should be reviewed to:
— determine the conformity of the management system, as far as documented, with audit criteria;
— gather information to support the auditing activities.
The review can be combined with the other auditing activities (e.g. interviewing relevant auditee’s personnel, observing auditee’s activities) and can continue throughout the audit, providing this is not detrimental to the effectiveness of the conduct of the audit. If adequate documented information cannot be provided within the time frame given in the audit plan, the audit team leader should inform both the individual(s) managing the audit programme and the auditee. Depending on the audit objectives and scope, a decision should be made as to whether the audit should be continued or suspended until documented information concerns are resolved.
6.4.7 Collecting and verifying information #
During the audit, information relevant to the audit objectives, scope and criteria, including information relating to interfaces among functions, activities and processes should be collected by means of appropriate sampling and should be verified, as far as practicable.
Only information that can be subject to some degree of verification should be accepted as audit evidence. Where the degree of verification is low, the auditor should use their professional judgement to determine the degree of reliance that can be placed on it as evidence. Audit evidence leading to audit findings should be recorded. If, during the collection of objective evidence, the audit team becomes aware of any new or changed circumstances, or risks or opportunities, these should be addressed by the audit team accordingly.
Methods of collecting information include, but are not limited to, the following:
— interviews;
— observations;
— review of documented information (see Clauses A.5 and A.14).
6.4.8 Generating the audit findings #
Audit evidence should be evaluated against the audit criteria in order to determine audit findings. Audit findings can indicate conformity or nonconformity to the audit criteria. When specified by the audit plan, individual audit findings should include conformity to audit criteria and good practices in the organization along with their supporting evidence, opportunities for improvement, and any recommendations to the auditee, and should be recorded. Nonconformities and their supporting audit evidence should be recorded. Nonconformities can be graded depending on the context of the organization and its risks. This grading can be quantitative (e.g. 1 to 5) or qualitative (e.g. minor, major). When nonconformities are graded, the criteria used by the auditing organization should be defined and communicated. Nonconformities should be reviewed with the auditee in order to obtain acknowledgement that the audit evidence is accurate and that the nonconformities are understood. Every attempt should be made to resolve any diverging opinions concerning the audit evidence or audit findings. Unresolved issues should be recorded in the audit report. The audit team should meet as needed to review the audit findings at appropriate stages during the audit.
6.4.9 Determining the audit conclusions #
6.4.9.1 Preparing for the closing meeting #
The audit team should confer prior to the closing meeting in order to:
a) review the audit findings, and any other appropriate information collected during the audit, against the audit objectives;
b) agree on the audit conclusions, taking into account the uncertainty inherent in the audit process;
c) prepare recommendations, if specified by the audit plan;
d) discuss audit follow-up activities, as applicable.
6.4.9.2 Determining the content of the audit conclusions #
Audit conclusions should address issues such as the following:
a) the extent of conformity to the audit criteria and robustness of the management system, including:
1) the effectiveness of the management system in meeting the intended results;
2) the identification of risks;
3) the effectiveness of actions taken by the auditee to address risks;
b) the effective implementation, maintenance and improvement of the management system;
c) achievement of audit objectives, coverage of audit scope and fulfilment of audit criteria;
d) similar audit findings made in different areas that were audited or from a joint or previous audit for the purpose of identifying trends.
If specified by the audit plan, audit conclusions can lead to recommendations for improvement or future audit activities. Caution should be used when making recommendations to avoid negative impact on impartiality of audits.
6.4.10 Conducting the closing meeting #
A closing meeting should be held to present the audit findings and conclusions. The closing meeting should be chaired by the audit team leader and attended by the top management of the auditee and include, as applicable:
— those responsible for the functions or processes which have been audited;
— representatives from the audit client;
— other members of the audit team;
— other relevant interested parties as determined by the audit client and/or auditee.
If applicable, the audit team leader should advise the auditee of situations encountered during the audit that can decrease the confidence that can be placed in the audit conclusions. If defined in the management system or by agreement with the audit client, the participants should agree on the time frame for an action plan to address audit findings. The degree of detail should take into account the effectiveness of the management system in achieving the auditee’s objectives, including consideration of its context and risks and opportunities. The familiarity of the auditee with the audit process should also be taken into consideration during the closing meeting, to ensure the correct level of detail is provided to participants. For some audit situations, the meeting can be formal and minutes, including records of attendance, should be kept. In other instances, the closing meeting can be less formal and consist solely of communicating the audit findings and audit conclusions. As appropriate, the following should be explained to the auditee in the closing meeting:
a) advising that the audit evidence collected was based on a sample of the information available and is not necessarily fully representative of the overall effectiveness of the auditee’s processes;
b) the method of reporting;
c) how the audit findings should be addressed based on the agreed process;
d) possible consequences of not adequately addressing the audit findings;
e) presentation of the audit findings and conclusions in such a manner that they are understood and acknowledged by the auditee’s management;
f) any related audit follow-up activities (e.g. implementation and review of corrective actions, addressing audit complaints, appeal process).
Any diverging opinions regarding the audit findings or conclusions between the audit team and the auditee should be discussed and, if possible, resolved. If not resolved, this should be recorded. If specified by the audit objectives, opportunities for improvement can be presented as recommendations. It should be emphasized that recommendations are not binding.
6.5 Preparing and distributing the audit report #
6.5.1 Preparing the audit report #
The audit team leader should report the audit conclusions in accordance with the audit programme. The audit report should provide a complete, accurate, concise and clear record of the audit, using specific reporting formats when required, and should include or refer to the following:
a) audit objectives;
b) audit scope, particularly identification of the organization (the auditee) and the functions or processes audited;
c) identification of the audit client;
d) identification of the audit team and auditee’s participants in the audit;
e) dates and locations where the auditing activities were conducted;
f) audit criteria;
g) audit findings and related audit evidence;
h) audit conclusions;
i) a statement on the degree to which the audit criteria have been fulfilled;
j) any unresolved diverging opinions between the audit team and the auditee;
k) a statement that audits by nature are a sampling exercise; as such there is a risk that the audit evidence examined is not representative.
The audit report can also include or refer to the following, as appropriate:
— the audit plan, including the time schedule;
— a summary of the audit process, including any obstacles encountered that can decrease the reliability of the audit conclusions;
— confirmation that the audit objectives have been achieved within the audit scope in accordance with the audit plan;
— any areas within the audit scope that were not covered, including any issues of availability of audit evidence, resources or confidentiality, with related justifications;
— any identified auditee’s good practices;
— follow-up activities related to agreed action plan, if any;
— a statement of the confidential nature of the contents;
— any implications for the audit programme or subsequent audits.
Nonconformities that have not been presented and discussed during the audit or the closing meeting should not be included in the audit report.
6.5.2 Distributing the audit report #
The audit report should be issued within an agreed period of time. If it is delayed, the reasons should be communicated to the auditee and the individual(s) managing the audit programme. The audit report should be dated, reviewed and, as appropriate, accepted, in accordance with the audit programme.
The audit report should then be distributed to the relevant interested parties defined in the audit programme or audit plan. When distributing the audit report, appropriate measures to ensure confidentiality should be considered.
6.6 Completing the audit #
The audit is completed when all planned auditing activities have been carried out, or as otherwise agreed with the audit client (e.g. there is a possibility that an unexpected situation prevents the audit from being completed according to the audit plan). Documented information pertaining to the audit should be retained or disposed of as agreed between the participating parties and in accordance with the audit programme and applicable requirements. The audit team and the individual(s) managing the audit programme should not disclose any information obtained during the audit, or the audit report, to any other party without the explicit approval of the audit client and, where appropriate, the approval of the auditee. If disclosure of the contents of an audit document is required (e.g. by law), the audit client and auditee should be informed as soon as possible. Lessons learned from the audit can identify risks and opportunities for the audit programme and the auditee.
6.7 Conducting the audit follow-up #
The outcome of the audit can, depending on the audit objectives, indicate the need for corrections, or for corrective actions, or opportunities for improvement. Such actions are usually decided and undertaken by the auditee within an agreed time frame. As appropriate, the auditee should keep the individual(s) managing the audit programme and/or the audit team informed of the status of these actions. The completion and effectiveness of these actions should be verified. This verification can be part of a subsequent audit. Outcomes should be reported to the individual managing the audit programme and reported to the audit client for management review.
7 Competence and evaluation of auditors #
7.1 General #
Confidence in the audit process and the ability to achieve its objectives depend on the competence of individuals involved, including auditors and audit team leaders. Competence should be evaluated regularly through a process that considers personal behaviour and the ability to apply the knowledge and skills gained through education, work experience, auditor training and audit experience. This process should take into consideration the needs of the audit programme and its objectives. Some of the knowledge and skills described in 7.2.3 are common to auditors of any management system discipline; others are specific to individual management system disciplines. It is not necessary for each auditor in the audit team to have the same competence. However, the overall competence of the audit team should be sufficient to achieve the audit objectives. The evaluation of auditor competence should be planned, implemented and documented to provide an outcome that is objective, consistent, fair and reliable. The evaluation process should include four main steps, as follows:
a) determine the required competence to fulfil the needs of the audit programme;
b) establish the evaluation criteria;
c) select the appropriate evaluation method;
d) conduct the evaluation.
The outcome of the evaluation process should provide a basis for the following:
— selecting audit team members (as described in 5.5.4);
— determining the need for improved competence (e.g. additional training);
— conducting ongoing performance evaluations of auditors.
Auditors should develop, maintain and improve their competence through continual professional development and regular participation in audits (see 7.6). A process for evaluating auditors and audit team leaders is described in 7.3, 7.4 and 7.5. Auditors and audit team leaders should be evaluated against the criteria established in 7.2.1, 7.2.2 and 7.2.3. The competence required of the individual(s) managing the audit programme is described in 5.4.2.
7.2 Determining auditor competence #
7.2.1 General #
In determining the necessary competence to perform or participate in an audit, an auditor’s knowledge and skills related to the following should be considered:
a) the size, nature and complexity of the organization and its products, services and processes;
b) methods for auditing including the application of emerging technology to facilitate the conducting of the audit, or to audit emerging technology-based processes;
c) the management system disciplines to be audited;
d) the complexity of the management system(s) to be audited;
e) methods for evaluating risks and opportunities;
f) the objectives and extent of the audit programme;
g) the uncertainty in achieving audit objectives;
h) other requirements, such as those imposed by the audit client or other relevant interested parties, where appropriate.
This information should be matched against that listed in 7.2.3.
7.2.2 Personal behaviour #
Auditors should possess the necessary attributes to enable them to act in accordance with the principles of auditing as described in Clause 4. Auditors should exhibit professional behaviour during the performance of auditing activities. Desired professional behaviours include being:
a) ethical, i.e. fair, truthful, sincere, honest and discreet;
b) open-minded, i.e. willing to consider alternative ideas or points of view;
c) diplomatic, i.e. tactful in dealing with individuals;
d) observant, i.e. actively observing physical surroundings and activities;
e) perceptive, i.e. aware of and able to understand situations;
f) versatile, i.e. able to readily adapt to different situations;
g) determined, i.e. persistent and focused on achieving objectives;
h) decisive, i.e. able to reach timely conclusions based on logical reasoning and analysis;
i) self-reliant, i.e. able to act and function independently while interacting effectively with others;
j) open to improvement, i.e. willing to learn from situations;
k) culturally sensitive, i.e. observant and respectful to the culture of the auditee;
l) collaborative, i.e. effectively interacting with others, including audit team members and the auditee’s personnel.
7.2.3 Knowledge and skills #
7.2.3.1 General #
Auditors should possess:
a) the knowledge and skills necessary to achieve the intended results of the audits they are expected to perform;
b) generic competence and a level of discipline-specific and sector-specific knowledge and skills.
Audit team leaders should have the additional knowledge and skills necessary to provide leadership to the audit team (refer to 7.2.3.4).
7.2.3.2 Generic knowledge and skills of management system auditors #
Auditors should have knowledge and skills in the areas outlined as follows:
a) Audit principles, processes and methods: knowledge and skills in this area enable the auditor to ensure audits are performed in a consistent and systematic manner. An auditor should be able to:
1) understand the types of risks and opportunities associated with auditing and the principles of the risk-based approach to auditing;
2) plan and organize the work effectively;
3) conduct the audit within the agreed time schedule;
4) prioritize and focus on matters of significance;
5) communicate effectively, both orally and in writing (either personally, or through the use of interpreters);
6) collect information through effective interviewing, listening, observing and reviewing documented information, including records and data;
7) understand the appropriateness and consequences of using sampling techniques for auditing;
8) understand and consider technical experts’ opinions;
9) audit a process from start to finish, including the interrelations with other processes and different functions, where applicable;
10) understand the appropriateness and consequences of using information and communications technology tools, and emerging technology to conduct audits (e.g. artificial-intelligence-based evaluation tools);
11) verify the relevance and accuracy of collected information;
12) confirm the sufficiency and appropriateness of audit evidence to support audit findings and conclusions;
13) assess those factors that can affect the reliability of the audit findings and conclusions;
14) document auditing activities and audit findings, and prepare audit reports;
15) maintain the confidentiality and security of information;
16) achieve the intended results of the audit.
b) Management system standards and other references: knowledge and skills in this area enable the auditor to understand the audit scope and apply audit criteria. Knowledge and skills should include the following:
1) management system standards or other normative or guidance/supporting documents used to establish audit criteria or methods;
2) the application of management system standards by the auditee and other organizations;
3) relationships and interactions between the management system(s) processes;
4) understanding the importance and priority of multiple standards or references;
5) the application of standards or references to different audit situations.
c) The organization and its context: knowledge and skills in this area enable the auditor to understand the auditee’s structure, purpose and management practices. Knowledge and skills should include the following:
1) the needs and expectations of relevant interested parties that impact the management system;
2) the type of organization, and its governance, size, structure, functions and relationships;
3) general business and management concepts, processes and related terminology, including planning, budgeting and management of individuals;
4) the cultural and social aspects of the auditee.
d) Applicable statutory and regulatory requirements and other requirements: knowledge and skills in this area enable the auditor to be aware of, and work within, the organization’s requirements. Knowledge and skills specific to the jurisdiction or to the auditee’s activities, processes, products and services should include the following:
1) statutory and regulatory requirements and their governmental agencies and regulatory authorities;
2) basic legal terminology;
3) contracting and liability;
4) data protection and information security.
7.2.3.3 Discipline-specific and sector-specific competence of auditors #
Audit teams should have the collective discipline-specific and sector-specific competence appropriate for auditing the particular types of management systems and sectors. The discipline-specific and sector-specific competence of auditors should include the following:
a) management system requirements and principles, and their application;
b) fundamentals of the discipline(s) and sector(s) related to the management system standards as applied by the auditee;
c) application of discipline-specific and sector-specific methods, techniques, processes and practices to enable the audit team to assess conformity within the defined audit scope and generate appropriate audit findings and conclusions;
d) principles, methods and techniques relevant to the discipline and sector, such that the auditor can determine and evaluate the risks and opportunities associated with the audit objectives.
7.2.3.4 Generic competence of the audit team leader #
In order to facilitate the efficient and effective conduct of the audit, an audit team leader should have the competence to:
a) plan the audit and assign audit tasks according to the specific competence of individual audit team members;
b) discuss strategic issues with top management of the auditee to determine whether they have considered these issues when evaluating their risks and opportunities;
c) develop and maintain a collaborative working relationship among the audit team members;
d) manage the audit process, including:
1) making effective use of resources during the audit;
2) managing the uncertainty of achieving audit objectives;
3) taking into account the health and safety of the audit team members during the audit, including ensuring that they meet the relevant health, safety and security arrangements;
4) directing the audit team members;
5) providing direction and guidance to auditors-in-training;
6) preventing and resolving conflicts and problems that can occur during the audit, including those within the audit team, as necessary;
e) represent the audit team in communications with the individual(s) managing the audit programme, the audit client and the auditee;
f) lead the audit team to reach the audit conclusions;
g) prepare and complete the audit report.
7.2.3.5 Knowledge and skills for auditing multiple disciplines #
When auditing multiple discipline management systems, the audit team member should have an understanding of the interactions and synergy among the different management systems. Audit team leaders should understand the requirements of each of the management system standards being audited and recognize the limits of their competence in each of the disciplines.
7.2.4 Achieving auditor competence #
Auditor competence can be acquired using a combination of the following:
a) successfully completing training programmes that cover generic auditor knowledge and skills;
b) experience in a relevant technical, managerial or professional position involving the exercise of judgement, decision-making, problem solving and communication with managers, professionals, peers, customers and other relevant interested parties;
c) education/training and experience in a specific management system discipline and sector;
d) audit experience acquired under the supervision of an auditor competent in the same discipline.
7.2.5 Achieving audit team leader competence #
An audit team leader should have acquired additional audit experience to develop the competence described in 7.2.3.4. This additional experience should have been gained by working under the direction and guidance of a different audit team leader.
7.3 Establishing the auditor evaluation criteria #
The criteria used to evaluate auditors should be qualitative (e.g. demonstrating desired behaviour, knowledge or the performance of skills, in training or in the workplace) and quantitative (e.g. years of work experience and education, number of audits conducted, hours of audit training).
7.4 Selecting the appropriate auditor evaluation method #
The evaluation should be conducted using two or more of the methods given in Table 2. When using Table 2, the following should be noted:
a) the methods outlined represent a range of options and do not always apply in all situations;
b) the various methods outlined can differ in their reliability;
c) a combination of methods should be used to ensure an outcome that is objective, consistent, fair and reliable.
Table 2 — Auditor evaluation methods
| Evaluation method | Objectives | Examples |
|---|---|---|
| Review of records | To verify the background of the auditor | Analysis of records of education, training, employment, professional credentials and auditing experience |
| Feedback | To provide information about how the performance of the auditor is perceived | Surveys, questionnaires, personal references, testimonials, complaints, performance evaluation, peer review |
| Interview | To evaluate desired professional behaviour and communication skills, to verify information and test knowledge and to acquire additional information | Personal interviews |
| Observation | To evaluate desired professional behaviour and the ability to apply knowledge and skills | Role playing, witnessed audits, on-the-job performance |
| Testing | To evaluate desired professional behaviour and knowledge and skills and their application | Oral and written exams, psychometric testing |
| Post-audit review | To provide information on the auditor’s performance during the auditing activities, identifying strengths and opportunities for improvement | Review of the audit report, interviews with the audit team leader, the audit team and, if appropriate, feedback from the auditee |
7.5 Conducting the auditor evaluation #
The information collected about the auditor under evaluation should be compared against the criteria set in 7.2.3. When an auditor under evaluation who is expected to participate in the audit programme does not fulfil the criteria, additional training, work or audit experience should be undertaken and a subsequent re- evaluation should be performed.
7.6 Maintaining and improving auditor competence #
Auditors and audit team leaders should continually improve their competence. Auditors should maintain their auditing competence through regular participation in management system audits and continual professional development. This can be achieved through means such as additional work experience, training, personal study, coaching, attendance at meetings, seminars and conferences, or other relevant activities. The individual(s) managing the audit programme should establish suitable mechanisms for the continual evaluation of the performance of the auditors and audit team leaders. The continual professional development activities should take into account the following:
a) changes in the needs of the individual and the organization responsible for the conduct of the audit;
b) developments in the practice of auditing including the use of technology;
c) relevant standards including guidance/supporting documents and other requirements;
d) changes in disciplines or sectors;
e) analysis of feedback from auditees and stakeholders.