International

ISO 19011:2018

49 controls. 29 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

49 controls 29 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

ISO 19011:2018 Auditing Management Systems Evidence & Implementation Kit

49 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
4Principles of auditing0
5.2Establishing audit programme objectives11
5.3Determining and evaluating audit programme risks and opportunities11
5.4Establishing the audit programme11
5.4.1Roles and responsibilities of the individual(s) managing the audit programme10
5.4.2Competence of individual(s) managing audit programme9
5.4.3Establishing extent of audit programme12
5.4.4Determining audit programme resources10
5.5Implementing audit programme12
5.5.2Defining the objectives, scope and criteria for an individual audit7
5.5.3Selecting and determining audit methods10
5.5.4Selecting audit team members8
5.5.5Assigning responsibility for an individual audit to the audit team leader7
5.5.6Managing audit programme results8
5.5.7Managing and maintaining audit programme records11
5.6Monitoring audit programme15
5.7Reviewing and improving audit programme10
6.2Initiating audit13
6.2.2Establishing contact with auditee9
6.2.3Determining feasibility of audit11
6.3Preparing audit activities10
6.3.1Performing review of documented information11
6.3.2Audit planning10
6.3.3Assigning work to audit team6
6.3.4Preparing documented information for audit10
6.4Conducting audit activities9
6.4.10Conducting closing meeting7
6.4.2Assigning roles and responsibilities of guides and observers9
6.4.3Conducting opening meeting11
6.4.4Communicating during audit11
6.4.5Audit information availability and access8
6.4.6Reviewing documented information while conducting audit10
6.4.7Collecting and verifying information11
6.4.8Generating audit findings9
6.4.9Determining audit conclusions8
6.5Preparing and distributing audit report10
6.5.1Preparing audit report11
6.5.2Distributing audit report9
6.6Completing audit10
6.7Conducting audit follow-up11
7.2Determining auditor competence9
7.2.2Personal behaviour6
7.2.3Knowledge and skills11
7.2.4Achieving auditor competence11
7.2.5Achieving audit team leader competence10
7.3Establishing auditor evaluation criteria8
7.4Selecting appropriate auditor evaluation method8
7.5Conducting auditor evaluation8
7.6Maintaining and improving auditor competence9

Tell me when ISO 19011:2018 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Completion record or agreement on early termination
  • Retention or disposal of audit documentation per the programme
  • Confidentiality of audit information maintained; disclosures approved or notified
  • Lessons learned captured
  • Remediation tracker
  • Mitigation verification

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO 19011:2018, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition