Programme and plan

Lesson 2 of 5 in Lead Auditor Track: Auditing an AIMS with ISO 19011 Discipline.

Two words that novice auditors blur and ISO 19011 keeps rigorously apart. The audit programme is the portfolio: arrangements for a set of audits over a time frame, directed at a purpose — a CB’s three-year certification cycle for a client, or an internal audit function’s annual schedule covering every AIMS process at a frequency proportionate to its risk. The audit plan is the mission order: the description of activities and arrangements for one specific audit — who interviews whom, about what, when, against which criteria.

Programme-level thinking is where risk-based auditing actually happens. A lazy internal programme audits every process once a year regardless of anything. A risk-based programme weights frequency and depth by what changed and what could hurt: the newly deployed clinical triage model gets audited this quarter and again after its first retraining; the stable document-control process gets a light touch every eighteen months. Results feed back — a process that produced findings last time earns a heavier slot next time.

The three anchors every audit plan must fix — and how they go wrong
AnchorWhat it fixesAIMS exampleClassic failure

Audit objectives

What the audit is meant to accomplish — the question it answers

‘Determine whether the AIMS conforms to ISO/IEC 42001 and is effectively implemented, as input to the certification recommendation’

Objectives so vague (‘review AI governance’) that no evidence could ever settle them

Audit scope

Extent and boundaries: sites, functions, activities, processes, time period

The Dublin development site and the London deployment function, covering the credit-scoring and fraud models, records from the last 12 months

Scope quietly narrower than the certificate scope — sampling only the flattering site

Audit criteria

The reference the evidence is compared against — clauses, policies, legal requirements, contract terms

ISO/IEC 42001 clauses 4–10 + the applicable Annex A controls per the auditee’s SoA + the auditee’s own procedures

Auditing against the auditor’s private opinions of good practice — findings with no citable criterion collapse on challenge

Team composition is a competence calculation, not a staffing convenience. ISO 19011 has the team leader assemble competence collectively: audit-method skill, the management-system discipline, the sector, and the applicable legal context. For AIMS audits, 42006 sharpened this into an obligation on certification bodies — the previous module covered what you can demand as a client; here is the same rule from the team leader’s chair. If the AIMS in scope includes a medical-imaging model and nobody on your team can interrogate a validation protocol, you do not bluff — you bring a technical expert. The expert advises the team on technical substance; the expert does not audit alone, does not interview unaccompanied, and does not classify findings. Auditors-in-training may join and work under supervision; observers and guides may accompany but must not influence the audit.

Before fieldwork comes document review — and for certification audits, Stage 1 (mapped in the previous module) is your single best intelligence-gathering opportunity. Read the scope statement, the AI policy, the risk methodology, and the SoA the way an analyst reads an adversary’s order of battle: which controls are claimed? Which exclusions look convenient? Where do the documents contradict each other? Every tension you spot becomes a targeted line of enquiry in the plan, instead of a lucky stumble on day two.

Staff the audit team

Interactive decision tree — outcomes:

  • Team stands as composed

    Collective competence covers method, discipline, and sector; independence is clean. Document the competence rationale anyway — the accreditation body may witness this audit and will ask exactly how the team was justified.

  • Add an AI-competent auditor

    Preferred over an expert where possible: an auditor can gather evidence, interview, and classify findings in their own right. Competence is assessed collectively — not every member needs everything, but the team must cover the map.

  • Engage a technical expert

    The expert supplies specialist knowledge under an auditor’s direction: they advise on what the evidence means, but do not audit alone and do not classify findings. The auditors remain accountable for every conclusion. Brief the expert on confidentiality and impartiality before day one.

  • Replace the conflicted member

    Auditing your own advice is a self-review conflict — the independence principle, and for certification audits a 17021-1 impartiality breach the accreditation body treats as radioactive. No level of competence offsets it: recompose the team.

Key terms: audit programme, audit plan, audit criteria, technical expert, stage 1 audit

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.