Audits & Certification

Building an Audit Program: A Practical Guide to the Annual Audit Plan

ISO 9001:2015 doesn’t mandate a specific tool or format in clause 9.2 - but it does require a documented audit program aligned with the risk and importance of the processes involved. That’s exactly where many audit programs go off the rails in practice: they end up as a pure scheduling list instead of a planned, justified coverage of the organization’s most important processes and requirements.

What the standard actually requires

Under ISO 9001:2015, clause 9.2.2, an organization must establish, implement, and maintain an audit program that addresses frequency, methods, responsibilities, planning requirements, and reporting - taking into account the importance of the processes concerned, changes affecting the organization, and the results of previous audits. Two types of documented information are required: the audit program itself (scope, criteria, frequency, methods, responsibilities) and the audit results (findings, nonconformities, corrective actions).

For guidance on execution, the standard points to ISO 19011, the guideline for auditing management systems. Among other things, it offers a useful reference for effort: a full-scope internal ISO 9001 audit at a mid-sized manufacturing organization is often estimated, in line with ISO 19011:2018 clause 5.4, at around 2 to 3 auditor-days in practice - a useful benchmark for your own resource planning, though actual effort varies with process complexity.

Plan by risk, not by department

A common but, per ISO 9001 practitioner literature, suboptimal approach is to build audit plans around the org chart - department by department - rather than around the standard’s requirements. A requirement-based audit plan, one that starts from the ISO 9001 clauses and then maps them to the responsible areas, is more likely to surface interface issues between departments that a purely department-based plan misses. ISO 19011 defines audit criteria broadly on purpose: beyond the standard itself, criteria can include performance indicators, statutory and regulatory requirements, and requirements from relevant interested parties.

For prioritizing which processes get audited how often, a risk-based approach has become the norm: processes with higher risk or recent change are audited more frequently than stable, low-risk areas. That lines up with the standard’s explicit requirement to factor prior audit results and organizational change into planning.

Building the audit program step by step

  1. Define scope: which processes, sites, and standard requirements does the program cover for the planning period?
  2. Define criteria: the standard, internal procedures, and where relevant customer requirements - this becomes the reference for every individual audit.
  3. Prioritize by risk: processes with prior-year findings, recent changes, or high impact on product/service quality get audited more often.
  4. Assign resources and auditors: protect independence - nobody audits their own area of responsibility.
  5. Set dates and methods: document review, observation, interviews - weighted differently depending on the process.
  6. Get management approval and retain the program as documented information.
  7. Evaluate after completion: results feed the next program cycle and management review.

Common mistakes in practice

A recurring weak spot: the audit program is managed in isolation from corrective action tracking. Findings from an audit land in a separate list with no clear link back to the original audit plan - we cover what a properly structured handoff from finding to corrective action looks like in our article on findings and CAPA management. Equally common: auditors aren’t trained sufficiently in the audit process itself, even though ISO 19011 sets explicit competence requirements - knowing the standard isn’t enough on its own.

Why a digital audit program makes the difference

An audit program in a spreadsheet formally satisfies the standard’s requirement, but it makes two things hard to verify: first, whether prioritization is genuinely risk-based rather than a copy of last year’s list, and second, how many of the planned audits actually resulted in completed, effective corrective actions. In qportal, the audit program is the structural umbrella over every audit in a period - every individual audit, every finding, and every resulting action stays visibly linked to the program instead of disappearing into standalone documents. For details on structuring audit programs and assigning audit team roles, see the documentation and the section on the audit team.

Conclusion

An audit program is more than a calendar - it’s evidence that an organization systematically tracks its most important risks and processes. Keeping scope, criteria, and prioritization clearly separated, and linking the program consistently to individual audit results, doesn’t just satisfy clause 9.2 - it turns every audit cycle into usable insight.

Sources

  • ISO 9001:2015, clause 9.2 (Internal Audit) - summarized via iso9001help.co.uk and davidbarker.consulting
  • ISO 19011:2018 - effort estimate (2-3 auditor-days, clause 5.4) via m2yacademy.com
  • Ecesis: ISO 9001 Clause 9.2: Internal Audit / QMS Audit Program (risk-based prioritization, process- vs. clause-based approach) - ecesis.net