ISO 19011
Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Audit Principles
Auditors perform work with honesty, diligence and responsibility forming the foundation of professionalism.
- Signed code of conduct
- Audit observation notes
- Stakeholder feedback
- No periodic refresh of code
- Behavioural lapses not addressed
Audit findings, conclusions and reports reflect truthfully and accurately the audit activities.
- Audit reports with evidence references
- Reviewer sign-off
- Auditee responses
- Findings without evidence cited
- No second-pair review
Auditors apply diligence and judgement appropriate to importance of task and confidence placed in audit by clients.
- Competence matrix
- Audit planning workload
- Reasoned judgements
- Overloaded auditor schedules
- Insufficient planning time
Auditors exercise discretion in use and protection of information acquired during audits.
- NDA signed by auditors
- Secure storage of audit files
- Disposal records
- Files retained beyond need
- NDA missing for contractor auditors
Auditors are independent of activity being audited and free from bias and conflict of interest.
- Independence statements per audit
- Auditor rotation log
- COI checks
- Auditing own area within prior 12 months
- Family or financial conflicts undeclared
Audit conclusions are based on verifiable evidence drawn from samples of available information.
- Sample plans
- Evidence files
- Cross-check records
- Sampling not representative
- Single-source evidence accepted
Audit approach considers risks and opportunities to ensure audits focus on matters significant to client.
- Risk-based audit plan
- Risk scoring records
- Programme change log
- Risk inputs static
- No re-assessment mid-cycle
Audit Process
Audit team leader prepares audit report and distributes it within agreed time to defined recipients.
- Final audit report
- Distribution log
- Lead time KPI
- Reports late
- Distribution incomplete
Follow-up activities verify completion of corrective actions and effectiveness in addressing audit findings.
- Follow-up checklist
- Verification records
- Effectiveness report
- Follow-ups close on promise not evidence
- No effectiveness check
Audit Programme
Audit programme is established including scope, schedules, methods, resources and procedures.
- Programme manual
- Resource allocation
- Annual schedule
- Resources allocated only at start of year
- No method statement
Audit programme manager implements programme by defining audit objectives, assigning teams and managing outcomes.
- Audit assignment letters
- Team competence summary
- Outcome tracker
- Assignments late
- Team competence not matched to scope
Audit programme manager monitors implementation considering need to evaluate conformity to programme and effectiveness.
- Programme KPIs
- Review minutes
- Adjustment log
- KPIs not defined
- Reviews not minuted
ISO 19011: Improvement
Continual improvement methodology. Control from ISO 19011 framework, domain: ISO 19011: Improvement.
- corrective action register
- customer satisfaction survey results
- quality policy
- missing nonconformity closure evidence
- insufficient customer satisfaction tracking
- gaps in management review inputs
- weak risk-based planning
- incomplete audit programme coverage
Corrective and preventive actions. Control from ISO 19011 framework, domain: ISO 19011: Improvement.
- risk register
- internal audit programme
- management review minutes
- corrective action register
- customer satisfaction survey results
- quality policy
- missing nonconformity closure evidence
- insufficient customer satisfaction tracking
- gaps in management review inputs
Innovation and change management. Control from ISO 19011 framework, domain: ISO 19011: Improvement.
- internal audit programme
- management review minutes
- corrective action register
- customer satisfaction survey results
- quality policy
- weak risk-based planning
- incomplete audit programme coverage
- missing nonconformity closure evidence
ISO 19011: Leadership & Planning
Quality policy and objectives. Control from ISO 19011 framework, domain: ISO 19011: Leadership & Planning.
- management review minutes
- corrective action register
- customer satisfaction survey results
- quality policy
- risk register
- internal audit programme
- insufficient customer satisfaction tracking
- gaps in management review inputs
- weak risk-based planning
- incomplete audit programme coverage
- missing nonconformity closure evidence
Leadership commitment to quality. Control from ISO 19011 framework, domain: ISO 19011: Leadership & Planning.
- quality policy
- risk register
- internal audit programme
- missing nonconformity closure evidence
- insufficient customer satisfaction tracking
- gaps in management review inputs
Risk-based thinking and planning. Control from ISO 19011 framework, domain: ISO 19011: Leadership & Planning.
- corrective action register
- customer satisfaction survey results
- quality policy
- risk register
- internal audit programme
- management review minutes
- incomplete audit programme coverage
- missing nonconformity closure evidence
- insufficient customer satisfaction tracking
Resource management for quality. Control from ISO 19011 framework, domain: ISO 19011: Leadership & Planning.
- quality policy
- risk register
- internal audit programme
- management review minutes
- corrective action register
- incomplete audit programme coverage
- missing nonconformity closure evidence
- insufficient customer satisfaction tracking
- gaps in management review inputs
Organizational roles and responsibilities. Control from ISO 19011 framework, domain: ISO 19011: Leadership & Planning.
- quality policy
- risk register
- internal audit programme
- missing nonconformity closure evidence
- insufficient customer satisfaction tracking
- gaps in management review inputs
- weak risk-based planning
- incomplete audit programme coverage
ISO 19011: Operational Controls
Operational planning and control. Control from ISO 19011 framework, domain: ISO 19011: Operational Controls.
- risk register
- internal audit programme
- management review minutes
- corrective action register
- weak risk-based planning
- incomplete audit programme coverage
- missing nonconformity closure evidence
Requirements for products and services. Control from ISO 19011 framework, domain: ISO 19011: Operational Controls.
- corrective action register
- customer satisfaction survey results
- quality policy
- risk register
- internal audit programme
- gaps in management review inputs
- weak risk-based planning
- incomplete audit programme coverage
- missing nonconformity closure evidence
Design and development controls. Control from ISO 19011 framework, domain: ISO 19011: Operational Controls.
- internal audit programme
- management review minutes
- corrective action register
- customer satisfaction survey results
- quality policy
- risk register
- gaps in management review inputs
- weak risk-based planning
- incomplete audit programme coverage
- missing nonconformity closure evidence
- insufficient customer satisfaction tracking
Control of externally provided processes. Control from ISO 19011 framework, domain: ISO 19011: Operational Controls.
- risk register
- internal audit programme
- management review minutes
- corrective action register
- customer satisfaction survey results
- quality policy
- weak risk-based planning
- incomplete audit programme coverage
- missing nonconformity closure evidence
- insufficient customer satisfaction tracking
Production and service provision controls. Control from ISO 19011 framework, domain: ISO 19011: Operational Controls.
- quality policy
- risk register
- internal audit programme
- management review minutes
- insufficient customer satisfaction tracking
- gaps in management review inputs
- weak risk-based planning
- incomplete audit programme coverage
ISO 19011: Performance Evaluation
Monitoring, measurement, and analysis. Control from ISO 19011 framework, domain: ISO 19011: Performance Evaluation.
- management review minutes
- corrective action register
- customer satisfaction survey results
- missing nonconformity closure evidence
- insufficient customer satisfaction tracking
- gaps in management review inputs
- weak risk-based planning
- incomplete audit programme coverage
Internal audit program. Control from ISO 19011 framework, domain: ISO 19011: Performance Evaluation.
- customer satisfaction survey results
- quality policy
- risk register
- internal audit programme
- management review minutes
- weak risk-based planning
- incomplete audit programme coverage
- missing nonconformity closure evidence
- insufficient customer satisfaction tracking
Management review process. Control from ISO 19011 framework, domain: ISO 19011: Performance Evaluation.
- management review minutes
- corrective action register
- customer satisfaction survey results
- incomplete audit programme coverage
- missing nonconformity closure evidence
- insufficient customer satisfaction tracking
Customer satisfaction measurement. Control from ISO 19011 framework, domain: ISO 19011: Performance Evaluation.
- management review minutes
- corrective action register
- customer satisfaction survey results
- quality policy
- risk register
- internal audit programme
- incomplete audit programme coverage
- missing nonconformity closure evidence
- insufficient customer satisfaction tracking
Nonconformity and corrective action. Control from ISO 19011 framework, domain: ISO 19011: Performance Evaluation.
- customer satisfaction survey results
- quality policy
- risk register
- weak risk-based planning
- incomplete audit programme coverage
- missing nonconformity closure evidence
- insufficient customer satisfaction tracking
- gaps in management review inputs
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 19011 framework page.