Skip to content

Evidence request lists

ISO 19011

Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Audit Principles

4.a
Integrity Principle

Auditors perform work with honesty, diligence and responsibility forming the foundation of professionalism.

Artefacts an auditor will ask for
  • Signed code of conduct
  • Audit observation notes
  • Stakeholder feedback
Where this commonly fails
  • No periodic refresh of code
  • Behavioural lapses not addressed
4.b
Fair Presentation

Audit findings, conclusions and reports reflect truthfully and accurately the audit activities.

Artefacts an auditor will ask for
  • Audit reports with evidence references
  • Reviewer sign-off
  • Auditee responses
Where this commonly fails
  • Findings without evidence cited
  • No second-pair review
4.c
Due Professional Care

Auditors apply diligence and judgement appropriate to importance of task and confidence placed in audit by clients.

Artefacts an auditor will ask for
  • Competence matrix
  • Audit planning workload
  • Reasoned judgements
Where this commonly fails
  • Overloaded auditor schedules
  • Insufficient planning time
4.d
Confidentiality

Auditors exercise discretion in use and protection of information acquired during audits.

Artefacts an auditor will ask for
  • NDA signed by auditors
  • Secure storage of audit files
  • Disposal records
Where this commonly fails
  • Files retained beyond need
  • NDA missing for contractor auditors
4.e
Independence

Auditors are independent of activity being audited and free from bias and conflict of interest.

Artefacts an auditor will ask for
  • Independence statements per audit
  • Auditor rotation log
  • COI checks
Where this commonly fails
  • Auditing own area within prior 12 months
  • Family or financial conflicts undeclared
4.f
Evidence-Based Approach

Audit conclusions are based on verifiable evidence drawn from samples of available information.

Artefacts an auditor will ask for
  • Sample plans
  • Evidence files
  • Cross-check records
Where this commonly fails
  • Sampling not representative
  • Single-source evidence accepted
4.g
Risk-Based Approach

Audit approach considers risks and opportunities to ensure audits focus on matters significant to client.

Artefacts an auditor will ask for
  • Risk-based audit plan
  • Risk scoring records
  • Programme change log
Where this commonly fails
  • Risk inputs static
  • No re-assessment mid-cycle

Audit Process

6.5
Preparing and Distributing Audit Report

Audit team leader prepares audit report and distributes it within agreed time to defined recipients.

Artefacts an auditor will ask for
  • Final audit report
  • Distribution log
  • Lead time KPI
Where this commonly fails
  • Reports late
  • Distribution incomplete
6.7
Conducting Audit Follow-up

Follow-up activities verify completion of corrective actions and effectiveness in addressing audit findings.

Artefacts an auditor will ask for
  • Follow-up checklist
  • Verification records
  • Effectiveness report
Where this commonly fails
  • Follow-ups close on promise not evidence
  • No effectiveness check

Audit Programme

5.4
Establishing Audit Programme

Audit programme is established including scope, schedules, methods, resources and procedures.

Artefacts an auditor will ask for
  • Programme manual
  • Resource allocation
  • Annual schedule
Where this commonly fails
  • Resources allocated only at start of year
  • No method statement
5.5
Implementing Audit Programme

Audit programme manager implements programme by defining audit objectives, assigning teams and managing outcomes.

Artefacts an auditor will ask for
  • Audit assignment letters
  • Team competence summary
  • Outcome tracker
Where this commonly fails
  • Assignments late
  • Team competence not matched to scope
5.6
Monitoring Audit Programme

Audit programme manager monitors implementation considering need to evaluate conformity to programme and effectiveness.

Artefacts an auditor will ask for
  • Programme KPIs
  • Review minutes
  • Adjustment log
Where this commonly fails
  • KPIs not defined
  • Reviews not minuted

ISO 19011: Improvement

ISO19011-16
Continual improvement methodology

Continual improvement methodology. Control from ISO 19011 framework, domain: ISO 19011: Improvement.

Artefacts an auditor will ask for
  • corrective action register
  • customer satisfaction survey results
  • quality policy
Where this commonly fails
  • missing nonconformity closure evidence
  • insufficient customer satisfaction tracking
  • gaps in management review inputs
  • weak risk-based planning
  • incomplete audit programme coverage
ISO19011-17
Corrective and preventive actions

Corrective and preventive actions. Control from ISO 19011 framework, domain: ISO 19011: Improvement.

Artefacts an auditor will ask for
  • risk register
  • internal audit programme
  • management review minutes
  • corrective action register
  • customer satisfaction survey results
  • quality policy
Where this commonly fails
  • missing nonconformity closure evidence
  • insufficient customer satisfaction tracking
  • gaps in management review inputs
ISO19011-18
Innovation and change management

Innovation and change management. Control from ISO 19011 framework, domain: ISO 19011: Improvement.

Artefacts an auditor will ask for
  • internal audit programme
  • management review minutes
  • corrective action register
  • customer satisfaction survey results
  • quality policy
Where this commonly fails
  • weak risk-based planning
  • incomplete audit programme coverage
  • missing nonconformity closure evidence

ISO 19011: Leadership & Planning

ISO19011-01
Quality policy and objectives

Quality policy and objectives. Control from ISO 19011 framework, domain: ISO 19011: Leadership & Planning.

Artefacts an auditor will ask for
  • management review minutes
  • corrective action register
  • customer satisfaction survey results
  • quality policy
  • risk register
  • internal audit programme
Where this commonly fails
  • insufficient customer satisfaction tracking
  • gaps in management review inputs
  • weak risk-based planning
  • incomplete audit programme coverage
  • missing nonconformity closure evidence
ISO19011-02
Leadership commitment to quality

Leadership commitment to quality. Control from ISO 19011 framework, domain: ISO 19011: Leadership & Planning.

Artefacts an auditor will ask for
  • quality policy
  • risk register
  • internal audit programme
Where this commonly fails
  • missing nonconformity closure evidence
  • insufficient customer satisfaction tracking
  • gaps in management review inputs
ISO19011-03
Risk-based thinking and planning

Risk-based thinking and planning. Control from ISO 19011 framework, domain: ISO 19011: Leadership & Planning.

Artefacts an auditor will ask for
  • corrective action register
  • customer satisfaction survey results
  • quality policy
  • risk register
  • internal audit programme
  • management review minutes
Where this commonly fails
  • incomplete audit programme coverage
  • missing nonconformity closure evidence
  • insufficient customer satisfaction tracking
ISO19011-04
Resource management for quality

Resource management for quality. Control from ISO 19011 framework, domain: ISO 19011: Leadership & Planning.

Artefacts an auditor will ask for
  • quality policy
  • risk register
  • internal audit programme
  • management review minutes
  • corrective action register
Where this commonly fails
  • incomplete audit programme coverage
  • missing nonconformity closure evidence
  • insufficient customer satisfaction tracking
  • gaps in management review inputs
ISO19011-05
Organizational roles and responsibilities

Organizational roles and responsibilities. Control from ISO 19011 framework, domain: ISO 19011: Leadership & Planning.

Artefacts an auditor will ask for
  • quality policy
  • risk register
  • internal audit programme
Where this commonly fails
  • missing nonconformity closure evidence
  • insufficient customer satisfaction tracking
  • gaps in management review inputs
  • weak risk-based planning
  • incomplete audit programme coverage

ISO 19011: Operational Controls

ISO19011-06
Operational planning and control

Operational planning and control. Control from ISO 19011 framework, domain: ISO 19011: Operational Controls.

Artefacts an auditor will ask for
  • risk register
  • internal audit programme
  • management review minutes
  • corrective action register
Where this commonly fails
  • weak risk-based planning
  • incomplete audit programme coverage
  • missing nonconformity closure evidence
ISO19011-07
Requirements for products and services

Requirements for products and services. Control from ISO 19011 framework, domain: ISO 19011: Operational Controls.

Artefacts an auditor will ask for
  • corrective action register
  • customer satisfaction survey results
  • quality policy
  • risk register
  • internal audit programme
Where this commonly fails
  • gaps in management review inputs
  • weak risk-based planning
  • incomplete audit programme coverage
  • missing nonconformity closure evidence
ISO19011-08
Design and development controls

Design and development controls. Control from ISO 19011 framework, domain: ISO 19011: Operational Controls.

Artefacts an auditor will ask for
  • internal audit programme
  • management review minutes
  • corrective action register
  • customer satisfaction survey results
  • quality policy
  • risk register
Where this commonly fails
  • gaps in management review inputs
  • weak risk-based planning
  • incomplete audit programme coverage
  • missing nonconformity closure evidence
  • insufficient customer satisfaction tracking
ISO19011-09
Control of externally provided processes

Control of externally provided processes. Control from ISO 19011 framework, domain: ISO 19011: Operational Controls.

Artefacts an auditor will ask for
  • risk register
  • internal audit programme
  • management review minutes
  • corrective action register
  • customer satisfaction survey results
  • quality policy
Where this commonly fails
  • weak risk-based planning
  • incomplete audit programme coverage
  • missing nonconformity closure evidence
  • insufficient customer satisfaction tracking
ISO19011-10
Production and service provision controls

Production and service provision controls. Control from ISO 19011 framework, domain: ISO 19011: Operational Controls.

Artefacts an auditor will ask for
  • quality policy
  • risk register
  • internal audit programme
  • management review minutes
Where this commonly fails
  • insufficient customer satisfaction tracking
  • gaps in management review inputs
  • weak risk-based planning
  • incomplete audit programme coverage

ISO 19011: Performance Evaluation

ISO19011-11
Monitoring, measurement, and analysis

Monitoring, measurement, and analysis. Control from ISO 19011 framework, domain: ISO 19011: Performance Evaluation.

Artefacts an auditor will ask for
  • management review minutes
  • corrective action register
  • customer satisfaction survey results
Where this commonly fails
  • missing nonconformity closure evidence
  • insufficient customer satisfaction tracking
  • gaps in management review inputs
  • weak risk-based planning
  • incomplete audit programme coverage
ISO19011-12
Internal audit program

Internal audit program. Control from ISO 19011 framework, domain: ISO 19011: Performance Evaluation.

Artefacts an auditor will ask for
  • customer satisfaction survey results
  • quality policy
  • risk register
  • internal audit programme
  • management review minutes
Where this commonly fails
  • weak risk-based planning
  • incomplete audit programme coverage
  • missing nonconformity closure evidence
  • insufficient customer satisfaction tracking
ISO19011-13
Management review process

Management review process. Control from ISO 19011 framework, domain: ISO 19011: Performance Evaluation.

Artefacts an auditor will ask for
  • management review minutes
  • corrective action register
  • customer satisfaction survey results
Where this commonly fails
  • incomplete audit programme coverage
  • missing nonconformity closure evidence
  • insufficient customer satisfaction tracking
ISO19011-14
Customer satisfaction measurement

Customer satisfaction measurement. Control from ISO 19011 framework, domain: ISO 19011: Performance Evaluation.

Artefacts an auditor will ask for
  • management review minutes
  • corrective action register
  • customer satisfaction survey results
  • quality policy
  • risk register
  • internal audit programme
Where this commonly fails
  • incomplete audit programme coverage
  • missing nonconformity closure evidence
  • insufficient customer satisfaction tracking
ISO19011-15
Nonconformity and corrective action

Nonconformity and corrective action. Control from ISO 19011 framework, domain: ISO 19011: Performance Evaluation.

Artefacts an auditor will ask for
  • customer satisfaction survey results
  • quality policy
  • risk register
Where this commonly fails
  • weak risk-based planning
  • incomplete audit programme coverage
  • missing nonconformity closure evidence
  • insufficient customer satisfaction tracking
  • gaps in management review inputs
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 19011 framework page.