Internal audit charter and programme
The mandate, independence, scope and schedule of the audits that test whether the documents in this register are followed.
How the register reads it
| Also called | audit charter, audit programme, audit plan |
|---|---|
| Family | Governance and the management system |
| Document type | Plan. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The head of internal audit, independent of the functions audited. |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 27001 or ISO 27701 or ISO 22301 is ticked and no line resolves to it. |
| Template | Internal audit policy. |
Which standards require it, and what each expects it to contain
3 requiring clauses, 3 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. A clause marked named is one of ISO/IEC 27001:2022's management clauses (4 to 10), named with its title and not quoted here.
ISO/IEC 27001:2022
Named, not quoted: 9.2named Internal audit.
ISO/IEC 27701:2025
ISO 27701 9.2.2 Internal audit programmeThe organization shall plan, establish, implement and maintain an audit programme or programmes including the frequency, methods, responsibilities, planning requirements and reporting, taking into consideration the importance of the processes concerned and the results of previous audits. The organization shall define the audit criteria and scope for each audit, select auditors and conduct audits that ensure objectivity and impartiality of the audit process, ensure the results are reported to relevant management, and retain documented information as evidence of the implementation of the programme and the audit results.
Common gap: Privacy lead auditing their own processes
Source: ISO/IEC 27701:2025
ISO 22301:2019
ISO 22301 9.2.2 Audit programme(s)Plan, establish, implement and maintain an audit programme covering frequency, methods, responsibilities, planning requirements and reporting, weighted by the importance of the processes concerned and the results of previous audits; define the criteria and scope of each audit, select auditors and conduct audits so the process is objective and impartial, report results to relevant managers, retain documented evidence of the programme and the audit results, ensure necessary corrective actions are taken without undue delay to eliminate detected nonconformities and their causes, and ensure follow up actions verify what was done and report the verification results.
Common gap: Programme frequency uniform across all processes, ignoring importance and prior audit results
Source: ISO 22301:2019
Also governs
ISO 27001 controls this document is expected to set the rules for, beside the ones that require it: ISO 27001 5.35.
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerInformation security roles and responsibilities · Legal and regulatory register