markdowneditor

Internal Audit Program & Report

Audit schedule + report with findings

ISO & ComplianceStandardinternalauditprogram

How to use: The program covers the whole MS over the cycle; each audit produces a report. Findings must split NC vs OFI – auditors distinguish them.

Preview

Internal Audit Program & Report

Mandatory – ISO 9001/27001 cl.9.2. TWO artifacts: (a) the program (schedule covering the whole MS over the cycle) (b) the report (each audit's findings). Audit the system, not just documents.

FieldValue
YearYYYY
Standard(s)ISO XXXXX
Program ownerManagement representative
Audit criteriaStandard clauses + internal policies

Part A – Audit program (the plan)

Audit #Scope / processClausesAuditorAuditeePlanned dateStatus
A-01Document control7.5@name@teamQ1Done
A-02Risk process6.1, 8.2@name@teamQ2Planned
A-03Operations8.x@name@teamQ3
A-04Improvement/CAPA9, 10@name@teamQ4

Part B – Audit report (per audit)

FieldValue
Audit refA-NN-YYYY
DateYYYY-MM-DD
Auditor@name (independent of area audited)
Auditee@name / team

Scope & criteria

What was audited, against which clauses and internal documents.

Methodology

  • Interviews: who was spoken with
  • Sampling: records reviewed (list IDs)
  • Observation: what was witnessed

Findings

#TypeClauseFindingEvidence
F-1Major NC8.2.1requirement not metrecord ref
F-2Minor NC7.5.3document not controlledsample ref
F-3OFI–opportunity for improvementobservation
F-4Positive9.1strong practice noted–

Conclusion

Overall conformance assessment; ISMS/QMS effectiveness statement.

Agreed actions

FindingCorrective actionOwnerDue
F-1Action@nameYYYY-MM-DD

Follow-up

ActionVerifiedDateEffective?
F-1 actionyes/no

Related templates