ISO 9001 Audit Schedule Template: How to Plan Your Annual Audit Programme

By Brian Crocker · Published 2 August 2026

ISO 9001 Clause 9.2 requires you to plan internal audits at planned intervals. What "planned intervals" means in practice — and how you document it — is where many SMBs fall short. A single spreadsheet with three dates and no scope definition is not an audit programme. This guide covers what a credible audit schedule looks like, how to build one that scales to a 5–100 person business, and what your certification body will actually check.

What Clause 9.2 requires

ISO 9001:2015 Clause 9.2.1 requires internal audits at planned intervals to confirm your QMS: (a) conforms to your own QMS requirements and to ISO 9001 requirements; and (b) is effectively implemented and maintained.

Clause 9.2.2 requires you to plan, establish, implement, and maintain an audit programme, taking into account the importance of the processes concerned, changes affecting the organisation, and the results of previous audits.

The standard does not specify frequency. "At planned intervals" means you decide — your documented audit programme is the evidence that intervals are planned and risk-based. Most certification bodies expect a minimum of one full-scope internal audit per year. Businesses with complex operations, high process risk, or recent nonconformities should audit more frequently.

What the audit programme document contains

Your audit programme is the master planning document — separate from individual audit plans (which are per-audit briefs) and audit reports (which are per-audit outputs).

Minimum content of an annual audit programme:

Element What to include
Audit objectives Why you are auditing — conformity, effectiveness, improvement
Scope Processes, clauses, sites, departments covered across the year
Audit schedule Planned dates and what each audit will cover
Auditor assignments Who audits what — with independence confirmed
Methodology Document review, interviews, observation, process walk-through
Reporting format How findings are recorded and escalated
Corrective action tracking How NCRs from audits are tracked to closure

One page is sufficient for most SMBs. Complexity should match the organisation.

Building your audit schedule

Step 1: List all processes in scope

Start with your QMS scope. Identify every process the QMS covers — production, purchasing, customer service, design, sales, HR, IT (if in scope). For each process, note:

  • Which ISO 9001 clauses apply
  • The last time it was audited
  • Any open nonconformities or customer complaints related to it
  • Its risk rating (high / medium / low based on consequence of failure)

This is your process inventory — the basis for coverage planning.

Step 2: Plan coverage across the year

All processes must be audited at least once per certification cycle (3 years). For annual programmes, the practical target is covering all processes once per year. For a 12-month schedule:

Month 1–2: Confirm programme, assign auditors, agree dates with process owners Month 3–4: First audit block — focus on core operational processes (Clauses 7–8) Month 6–7: Second audit block — management system processes (Clauses 4–6, 9–10) Month 9–10: Third audit block (optional for smaller businesses) — high-risk processes, outstanding corrective actions Month 11: Management review — audit programme results as a key input (Clause 9.3)

For a 5–20 person business, one focused annual audit covering all clauses in 1–2 days is often sufficient. For 20–100 people with distinct departments, 3–4 targeted audits per year is more manageable.

Step 3: Apply risk-based prioritisation

Clause 9.2.2 explicitly requires the programme to consider risk. Audit higher-risk processes more frequently. Risk indicators:

  • Processes with recent nonconformities or customer complaints
  • Processes that changed significantly (new equipment, new procedure, new staff)
  • Processes regulated by external requirements (COSHH, food safety, building regulations)
  • Processes with a history of recurring issues

Low-risk processes that performed well in the previous audit can be sampled rather than fully audited, or rotated across years in longer cycles.

Step 4: Assign auditors — confirm independence

Clause 9.2.2 requires you to select auditors and conduct audits to ensure objectivity and impartiality. The rule: auditors cannot audit their own work.

For SMBs with limited staff, practical options:

  • Peer auditing: Swap auditors between departments. Finance manager audits production; production manager audits admin. Train both as competent auditors.
  • External internal auditor: Engage a freelance ISO 9001 consultant to run your internal audit. Costs £400–900 per day but eliminates the independence problem and often produces higher-quality findings.
  • Certification body's observation service: Some UKAS-accredited bodies offer internal audit support outside the certification engagement — check with your certifier.

Document auditor names against each audit slot in the programme. Your certification auditor will check that independence was maintained.

Audit schedule format

A simple annual audit schedule covers:

Audit # Planned date Scope / processes Clauses covered Lead auditor Status Report ref
1 2026-09-15 Production, purchasing 7.1, 7.4, 8.1, 8.4, 8.6 J. Smith (independent — finance dept) Planned
2 2026-11-10 Management system 4, 5, 6, 9, 10 External (A. Jones Consulting) Planned

Keep it simple. Certification auditors look for: does the programme exist, does it cover all clauses over the cycle, are auditors independent, are dates planned vs reactive?

Update the Status column as audits complete: Planned → In progress → Complete → Report issued. Add the Report reference when the report is filed.

What certification bodies check

At your Stage 2 audit and subsequent surveillance audits, your certification body will:

  1. Request your audit programme. They want to see dates, scope, auditor names — evidence it was planned in advance, not improvised.
  2. Review audit reports. They will read findings, check classification (NC vs observation), and look for root cause analysis and corrective actions.
  3. Verify corrective action closure. Open NCs without evidence of corrective action are a finding — sometimes a major one if they relate to a core clause.
  4. Check management review minutes. Internal audit results must be a management review input (Clause 9.3.2 d). If the MD has never seen the audit report, that is a gap.
  5. Confirm auditor independence. If the QMS manager audited all processes including their own, expect a finding.

The most common internal audit finding in certification audits: the audit programme exists, but corrective actions from previous audits were never tracked to closure. Build corrective action follow-up into your programme from the start — either as a separate audit block or as agenda items at management reviews.

Connecting the audit schedule to the rest of your QMS

Your audit schedule is not a standalone document. It feeds:

  • Quality policy (Clause 5.2): internal audits are one of the primary mechanisms for demonstrating that the policy is implemented and maintained
  • Risk register (Clause 6.1): audit findings that reveal process risks should update the risk register — see ISO 9001 Risk Assessment Template
  • Corrective actions (Clause 10.2): every NC finding from an audit generates an NCR — see ISO 9001 Non Conformance Report Template
  • Management review (Clause 9.3): audit results summary is a mandatory input
  • Quality objectives (Clause 6.2): audit findings often identify where objectives are not being met

At management reviews, present: number of audits completed vs planned, total NCs by clause, open vs closed corrective actions, any repeat nonconformities. This is the report format that demonstrates the QMS is a live system, not a paper exercise.

Downloadable audit schedule template

An annual audit programme template covering all ISO 9001:2015 clauses — with risk-level columns, auditor assignment, finding classification, corrective action tracking, and a management review summary block — is available as a free XLSX download. It works in Microsoft Excel and Google Sheets.

For the corresponding ISO 9001 internal audit checklist with 15 questions your auditor will likely ask, see that guide for the fieldwork preparation.

If you are working towards your certification audit, the ISO 9001 Audit Readiness Checker helps you confirm your Stage 1 documents and Stage 2 evidence are complete before the certification body arrives.

This article is for general informational purposes only and does not constitute legal, regulatory, or professional compliance advice. ISO certification requirements vary by scope, sector, and certification body. Always verify requirements with your UKAS-accredited certification body or a qualified consultant before making compliance decisions.

ClauseWise is coming soon

Generate your ISO 9001 and ISO 27001 documentation without consultant fees.