What Is an Audit Programme?

An audit programme is the set of audits planned for a specific time frame and directed towards a specific purpose. It differs from an audit plan, which is the plan for a single audit.

What does it cover?

  • Processes, departments and locations to be audited
  • Audit frequency and calendar
  • Audit criteria and scope
  • Auditor assignments and competence requirements
  • Method: on-site, remote or hybrid
  • Resources
  • Reporting and follow-up mechanism

Risk-based planning

Auditing all processes at the same frequency is neither efficient nor realistic. ISO 19011:2026 emphasizes planning the audit programme with the organization’s objectives, processes, changes and priorities in mind. Audits are positioned as a strategic tool rather than a routine calendar activity.

Prioritization criteria: process criticality, past nonconformities, customer complaints, organizational changes and the introduction of new products or processes.

Elements added with the 2026 edition

It is stated that topics such as information security, data protection, the use of digital tools and climate change should also be considered when establishing the programme. In addition, virtual locations without a physical address are expected to be included in the programme.

The programme covers supplier audits as well as internal audits.

Audit programme management is a competence independent of which standard you implement. Building a risk-based programme and the new elements introduced by the 2026 edition are addressed hands-on in the ISO 19011:2026 training. For standard-specific audit requirements, see our related training topics.