Audits & Certification

Planning the Audit Programme: the Annual Plan under ISO 9001 9.2.2

In a lot of organizations the annual audit plan looks the same: twelve rows, one per department, dates spread across the year, rolled forward every December. Formally there is nothing wrong with it. It just does not answer the first question an auditor asks — why this scope, in this order, at this frequency?

ISO 9001:2015 prescribes neither a tool nor a format in 9.2, but it does require a rationale. This article takes the requirement apart item by item, separates the programme from the plan, and closes on the question where almost every article on the subject gets sloppy: how much effort an internal audit costs. The honest answer is that no standard provides a figure. There is a structural reason for that, and it teaches more than any number would.

What Clause 9.2.2 Requires, Item by Item

First a note on citation: 9.2.1 and 9.2.2 carry no headings in the standard [1]. Anyone citing “9.2.1 General” is citing something that does not exist — a reliable tell for text written from second-hand sources.

9.2.1 sets the purpose: internal audits “at planned intervals” to determine whether the quality management system conforms, first, to the organization’s own requirements and, second, to the requirements of the standard — and whether it is effectively implemented and maintained [1]. That doubling matters again further down, under audit criteria.

9.2.2 contains six items:

Item Requirement What has to be visible in the programme
a) plan, establish, implement and maintain one or more audit programmes — including frequency, methods, responsibilities, planning requirements and reporting the five named elements, plus the rationale drawn from the three factors
b) define audit criteria and scope for each audit per individual audit, not blanket for the programme
c) select auditors and conduct audits so as to ensure objectivity and impartiality auditor-to-area assignment with a documented rationale
d) report results to relevant management the reporting route and recipient, not just the report
e) take appropriate correction and corrective action without undue delay dates and status tracking on the findings
f) retain documented information as evidence of the implementation of the programme and of the audit results two records, not one

Two of these are routinely misreported.

First, the factors in a). The standard names exactly three: the importance of the processes concerned, changes affecting the organization, and the results of previous audits [1]. A striking number of checklists add “risks” as a fourth. It is not there. Substantively the prioritization is of course risk-driven — but anyone citing “risks” as a requirement out of 9.2.2 is citing an addition somebody else inserted.

Second, the evidence in f). What must be retained is evidence of the implementation of the audit programme and of the audit results. Most organizations file their audit reports carefully and have nothing for the first half: no record that the planned programme actually ran, no documentation of audits that were postponed or dropped. That is a gap against 9.2.2 f) in its own right, independent of how good the reports are.

Programme or Plan? The Distinction ISO 19011 Draws

In everyday use the two terms blur; in the structure they do not. The audit programme is the totality of audits across a period. The audit plan belongs to one audit and governs dates, interviewees and sequence.

ISO 19011 reflects the split in its own structure. Clause 5 covers managing an audit programme, with 5.2 audit programme objectives, 5.3 determining and evaluating audit programme risks and opportunities, 5.4 establishing the programme, 5.5 implementing it, 5.6 monitoring and 5.7 reviewing and improving [2]. Only clause 6 covers conducting an audit, where 6.3 handles preparation. Anyone scheduling dates is working in clause 6 — and may never have done clause 5 at all.

When citing it, check the edition. ISO 19011:2018 is withdrawn; ISO 19011:2026 was published in May 2026 as the fourth edition [2], with the numbering of clauses 5 to 7 unchanged. National adoptions run behind: in Germany, DIN EN ISO 19011:2018-10 is still the standard in force, with DIN EN ISO 19011:2026-09 due in September 2026 and bringing a changed German title with it [3].

What matters most for audit practice is the normative status: ISO 19011 is guidance, not a requirements standard. ISO 9001:2015 names it only in a Note to 9.2, as an example, and Notes contain no requirements — which is why ISO/TC 176’s Auditing Practices Group states plainly that an auditor may neither cite a requirement from ISO 19011 nor raise a nonconformity against it [4]. ISO puts it just as briefly on the product page: the document provides guidance and does not itself lead to certification [2]. Structure and scope are summarized on the ISO 19011 overview page.

Prioritize by Risk Instead of Working Through Departments

The department grid is convenient because it borrows the logic of the org chart. It has one systematic blind spot: the most expensive failures happen at handovers, and handovers belong to nobody alone. The complaint that arrives in sales, gets analyzed in production and is traced to a cause in purchasing appears in full in none of the three departmental audits.

The three factors from 9.2.2 a) give you a defensible prioritization instead. A process with a high impact on product conformity — incoming inspection, batch release, calibration of measuring equipment — belongs in the programme in every cycle. A process whose release step was rewired in the ERP system since the last audit joins it, even if it would not otherwise be due. And a process carrying open or repeated findings from the previous cycle is not just audited again but audited deeper.

This is also where the most stubborn frequency myth sits: the word “annual” does not appear once in ISO 9001:2015. “At planned intervals” occurs exactly twice in the whole standard — in 9.2.1 for the internal audit and in 9.3.1 for the management review [1]. An annual rhythm is a common and usually sensible choice. It is not a requirement, and for stable support processes it is rarely the most economical one.

Assessment: what works in practice is a two-year cycle with staggered frequency — critical processes every year, stable support processes every two years, plus one open slot each year for audits triggered by changes or clusters of complaints. That is a professional recommendation, not a requirement of the standard.

Define Audit Criteria More Broadly Than Most People Do

9.2.2 b) requires audit criteria and scope to be defined for each audit [1]. What gets entered there is almost always the same thing: “ISO 9001:2015”. That is too little, for a reason stated directly in 9.2.1.

There the standard asks for confirmation that the management system conforms to the organization’s own requirements and to the requirements of the standard [1]. An audit that tests only against the standard therefore covers half of that purpose. The organization’s own requirements are the procedures, release rules and inspection plans it gave itself — and that is where the single most common finding originates: not a wrong process, but a procedure describing a step that nobody has performed since the system changeover.

Assessment: defensible criteria for an internal audit are therefore at least fourfold — the standard, the organization’s own documented information, contractual customer requirements, and the applicable statutory and regulatory requirements for the area. How to derive questions from those without marching through clause by clause is covered in the article on the audit question catalog under ISO 19011; a clause-based starting structure is in the internal audit checklist for ISO 9001.

Auditor Independence and Competence

9.2.2 c) is the most underestimated item. It requires auditors to be selected and audits conducted so as to ensure the objectivity and impartiality of the audit process [1]. That is a requirement in the literal sense — checkable, and capable of generating a nonconformity.

The asymmetry with the guidance is worth noticing. ISO 19011 carries independence as one of its auditing principles (2026 edition: its own subclause 4.6; 2018 edition: an unnumbered lettered item in clause 4) and leaves room where full independence is not practicable [2]. ISO 9001 grants no such room: 9.2.2 c) stands without qualification — and an external auditor can write a nonconformity against that requirement, while they cannot against ISO 19011 [4].

Nowhere does the standard literally forbid auditing your own area. It requires something more effective: an objective and impartial audit process. Auditing your own responsibility is the clearest breach of that, but not the only one — whoever wrote the process description is not impartial toward it either.

On competence, ISO 9001 says nothing in 9.2. ISO 19011 devotes its entire clause 7, “Competence and evaluation of auditors”, to it, with 7.2.3 on knowledge and skills [2] — as guidance. Knowing the standard therefore does not qualify anyone. Auditing is an interviewing skill, and someone who has never practiced it conducts an interrogation or a coffee chat, but not an audit.

Estimating Effort — and Why No Standard Gives You a Figure

Now to the number everyone is looking for. What circulates online, for a full internal ISO 9001 audit in a mid-sized manufacturing organization, is “2 to 3 auditor-days”, regularly attributed to ISO 19011:2018, clause 5.4.

That reference does not exist. ISO 19011 contains no clause on audit duration whatsoever. 5.4.4 is titled “Determining audit programme resources” and treats resources qualitatively [2]. The clause text is also paywalled — anyone quoting a figure out of it could not evidence it without reproducing normative wording.

A note on this article: earlier versions carried exactly that figure, complete with the clause attribution. It came from a training provider’s blog and it was wrong. It was removed on 27 August 2026 — not replaced with a different number, but with the explanation of why there is none.

Quantified audit time does exist, just elsewhere in the system: in third-party certification, published on the accreditation side as a binding document. IAF MD 5 governs the determination of audit time for management system certification and therefore binds certification bodies, not organizations. Following the International Accreditation Forum’s cessation of operations on 1 January 2026 [5] and the transfer to the Global Accreditation Cooperation Incorporated [6], the IAF Mandatory Documents remain in force under Resolutions 2025-25 and 2025-29 until equivalent Global ACI documents are adopted [7]. The document still applies — to accredited certification audits, with a defined scope and a defined headcount.

Which gives the actual point: anyone who has read “2 to 3 auditor-days” for an internal audit has most likely seen a third-party figure smuggled into an internal-audit context. The two audit types have different purposes, sampling rules and independence requirements. A time allowance calibrated for one is not a reference for the other. How the certification cycle actually works is described in the article on the external audit and its certification cycle.

Assessment: actual effort hangs on four drivers, none of which is constant across an industry.

Driver lowers effort raises effort
Number of processes in scope few, cleanly bounded processes many processes with interfaces and special cases
Number of sites one site, one team several sites, travel time, distributed evidence
Findings position from the last cycle none, or all closed open or repeated findings that must be followed up
Auditor’s familiarity with the area experienced auditor, known evidence landscape auditor from outside the domain, every record needs explaining

The most defensible figure for your organization is your own. In the current programme, record planned and actual duration per audit, split into preparation, fieldwork and reporting. After two cycles you have an in-house value that beats any published metric, because it reflects your processes, your sites and your evidence landscape. Until that value exists, every figure is an estimate — including the one not given here.

Step by Step to a Programme

  1. Bound the scope: which processes, sites and management systems does the programme cover in the planning period, and what is deliberately excluded?
  2. Set objectives: what should the programme achieve — certification readiness, evidence of effectiveness after process changes, preparation for a standard transition? ISO 19011 deliberately puts this step first, in 5.2 [2].
  3. Prioritize: rank processes against the three factors from 9.2.2 a) and write the ranking down. That rationale is the part that makes the difference later.
  4. Define criteria and scope per audit (9.2.2 b) — the standard, your own documented information, customer and legal requirements.
  5. Assign auditors and check independence for each assignment (9.2.2 c). Where resources are tight: reciprocal auditing between areas.
  6. Choose methods and dates: document review, observation at the workplace, interview, sampling from live operations — weighted differently per process.
  7. Approve, evidence and feed back: release the programme, evidence implementation and results (9.2.2 f), feed results into the management review under 9.3.2, and derive the next programme from them. Which fields have to exist at capture for that to work is covered in from audit to management review.

That bracket — programme, individual audit, finding, action, evidence of effectiveness — is the core of audit management in qportal: each audit stays visibly linked to the programme instead of disappearing into separate documents. Structure and roles are described in the audit programme documentation and the section on the audit team.

Common Mistakes

The programme is a list of dates with no rationale. The prioritization lives in the quality manager’s head, not in the document. In the external audit the “why” question is then an open flank, even though the answer exists.

Only the reports are retained. 9.2.2 f) requires two records. Postponed, shortened or cancelled audits belong in the documentation — with a reason and a replacement date, not quietly deleted from the list.

Findings run alongside the programme. They land in a separate table with no reference back to the audit and the programme, which removes any answer to how many planned audits led to effectively closed actions. The mechanics are covered in the article on findings management, and the cause side in the article on the CAPA process and corrective action.

The programme does not respond to change. A relocation, an ERP release, a new principal supplier — each of those is the second factor from 9.2.2 a) in its purest form. A programme fixed in January and untouched until December ignores it.

The standard transition is not planned in. Anyone auditing against ISO 9001:2026 in 2027 needs questions and findings in two clause structures at once. What that means for the programme and the catalog is set out in the article on ISO 9001:2026 and internal audits.

Conclusion

An audit programme does not become compliant by being complete. It becomes compliant by being justified. The standard supplies the justification exhaustively: three factors, not four; no interval; and two records rather than one.

And on the question everyone asks, restraint is the more accurate answer. No standard quantifies the effort of an internal audit, because audit time is only quantified where an accreditation rule has to standardize it — in third-party certification. Anyone quoting you auditor-days for your internal programme is quoting either somebody else’s metric or their own estimate. The only defensible number comes out of your own second audit cycle.

Sources

First-degree sources — standardization and accreditation bodies

  1. ISO 9001:2015, Quality management systems — Requirements, published as DIN EN ISO 9001:2015-11, Beuth Verlag, Berlin. Clauses used: 9.2.1, 9.2.2 a) to f), 9.3.1 and 9.3.2.
  2. ISO: ISO 19011 — Guidelines for auditing management systems. Edition 4, published 2026-05, stage 60.60, 46 pages, ISO/TMBG (prepared by ISO/PC 302 with CEN/CLC/JTC 1 under the Vienna Agreement); the third edition, ISO 19011:2018, is withdrawn (stage 95.99). Product page with scope and FAQ. https://www.iso.org/standard/19011 (accessed 2026-08-27)
  3. DIN EN ISO 19011:2018-10, Leitfaden zur Auditierung von Managementsystemen (ISO 19011:2018), Beuth Verlag, Berlin — the German edition in force as of 2026-08-27. Successor DIN EN ISO 19011:2026-09, Leitlinien zur Auditierung von Managementsystemen, announced for September 2026 (pre-publication record in the DIN Media catalogue).
  4. ISO/TC 176 Auditing Practices Group: ISO 19011:2018 — Guidelines for auditing management systems. On the status of the document as guidance and on the Note in ISO 9001:2015, 9.2. https://committee.iso.org/files/live/sites/tc176/files/documents/ISO%209001%20Auditing%20Practices%20Group%20docs/Auditing%20General/APG-ISO_19011_2018.pdf (accessed 2026-08-27)
  5. International Accreditation Forum: notice of cessation of operations on 2026-01-01 and transfer to the Global Accreditation Cooperation Incorporated. Legacy site. https://iaf.nu/en/home/ (accessed 2026-08-27)
  6. Global Accreditation Cooperation Incorporated (Global ACI): organizational information, operational from 2026-01-01. https://global-aci.org/en/home/ (accessed 2026-08-27)
  7. Global Accreditation Cooperation Incorporated: Resolutions — Resolutions 2025-25 and 2025-29 on the continued force of the IAF Mandatory Documents until equivalent Global ACI documents are adopted, among them IAF MD 5 on determining audit time for management system certification. https://global-aci.org/en/global_aci-documents/resolutions/ (accessed 2026-08-27)

Note on verifiability

Clauses 4 to 7 of ISO 19011 are paywalled. Only clause numbers, clause titles and the freely available scope are used from that standard here; clause content is not paraphrased and normative wording is not reproduced. The same applies to ISO 9001:2015, whose requirements are restated in the author’s own words. Consultancy, certification-body and training-provider pages are not cited. Where this text goes beyond the documented evidence, it is marked as an assessment.

Frequently asked questions

How often must internal audits be conducted under ISO 9001?
The standard names no interval. ISO 9001:2015 requires internal audits "at planned intervals" in 9.2.1, and the word annual does not appear anywhere in the standard. Frequency follows from the three factors in 9.2.2 a): the importance of the processes concerned, changes affecting the organization, and the results of previous audits. Planning annually is choosing an interval, not meeting a requirement.
What must an audit programme contain under ISO 9001?
Under 9.2.2 a) the organization must plan, establish, implement and maintain one or more audit programmes covering frequency, methods, responsibilities, planning requirements and reporting, taking into account the importance of the processes concerned, changes affecting the organization, and the results of previous audits. Audit criteria and scope are set per individual audit under 9.2.2 b), not in the programme.
What is the difference between an audit programme and an audit plan?
The programme is the totality of audits over a period; the plan belongs to a single audit. ISO 19011 mirrors that in its structure: clause 5 covers managing an audit programme — 5.2 objectives, 5.3 risks and opportunities, 5.4 establishing, 5.5 implementing, 5.6 monitoring, 5.7 reviewing and improving. Clause 6 covers conducting the individual audit.
How many auditor-days does an internal ISO 9001 audit take?
There is no normative figure. ISO 19011 contains no clause on audit duration at all; 5.4.4 is titled "Determining audit programme resources" and treats resources qualitatively. Quantified audit time exists only in third-party certification, governed by the mandatory document IAF MD 5, which binds certification bodies. Those values apply to accredited certification audits and do not transfer to an internal programme.
Can someone audit their own area?
ISO 9001 does not forbid it in so many words. 9.2.2 c) requires auditors to be selected and audits conducted so as to ensure the objectivity and impartiality of the audit process. That is a requirement, not a recommendation — and auditing your own responsibility is the clearest possible breach of it. Small organizations solve this with reciprocal auditing between areas, or an external auditor for the QM process itself.