Audit programme
Prioritise processes by customer, commercial, compliance and change risk; define independence, competence and sampling.
A risk-based internal audit follows real opportunities across functions and tests whether controls improve customer commitments and outcomes.
Prioritise processes by customer, commercial, compliance and change risk; define independence, competence and sampling.
Sample opportunities from qualification through outcome; reconcile CRM, approvals, offer, contract, handover and feedback.
Interview process actors, observe work, inspect records and test consistency across samples.
Separate conformity, effectiveness, risk, opportunity and observation. Do not use guidance as audit criteria unless adopted internally.
Contain customer exposure, establish cause, implement action and verify effectiveness.
Evaluate context, objectives, customer perception, performance, audit, resources, risk and improvement decisions.
Audit guidance reference: ISO 19011:2026 (opens in a new tab).