Policy Register

Internal audit charter and programme

The mandate, independence, scope and schedule of the audits that test whether the documents in this register are followed.

How the register reads it

Also calledaudit charter, audit programme, audit plan
FamilyGovernance and the management system
Document typePlan. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe head of internal audit, independent of the functions audited.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 27001 or ISO 27701 or ISO 22301 is ticked and no line resolves to it.
TemplateInternal audit policy.

Which standards require it, and what each expects it to contain

3 requiring clauses, 3 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. A clause marked named is one of ISO/IEC 27001:2022's management clauses (4 to 10), named with its title and not quoted here.

ISO/IEC 27001:2022

Named, not quoted: 9.2named Internal audit.

ISO/IEC 27701:2025

ISO 27701 9.2.2 Internal audit programme

The organization shall plan, establish, implement and maintain an audit programme or programmes including the frequency, methods, responsibilities, planning requirements and reporting, taking into consideration the importance of the processes concerned and the results of previous audits. The organization shall define the audit criteria and scope for each audit, select auditors and conduct audits that ensure objectivity and impartiality of the audit process, ensure the results are reported to relevant management, and retain documented information as evidence of the implementation of the programme and the audit results.

Evidence an auditor accepts: Audit programme with frequency, methods, responsibilities and reporting; audit criteria and scope per audit; auditor independence from the areas audited
Common gap: Privacy lead auditing their own processes
Source: ISO/IEC 27701:2025

ISO 22301:2019

ISO 22301 9.2.2 Audit programme(s)

Plan, establish, implement and maintain an audit programme covering frequency, methods, responsibilities, planning requirements and reporting, weighted by the importance of the processes concerned and the results of previous audits; define the criteria and scope of each audit, select auditors and conduct audits so the process is objective and impartial, report results to relevant managers, retain documented evidence of the programme and the audit results, ensure necessary corrective actions are taken without undue delay to eliminate detected nonconformities and their causes, and ensure follow up actions verify what was done and report the verification results.

Evidence an auditor accepts: Documented audit programme with frequency, method and responsibility, risk weighted; per audit criteria and scope statements; auditor selection records evidencing objectivity and impartiality
Common gap: Programme frequency uniform across all processes, ignoring importance and prior audit results
Source: ISO 22301:2019

Also governs

ISO 27001 controls this document is expected to set the rules for, beside the ones that require it: ISO 27001 5.35.

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Information security roles and responsibilities · Legal and regulatory register