SlideShare a Scribd company logo
The British Standards Institutionraising standards worldwide TMIssue 1 December, 2008                   QMS-030-01-EN-GX           © 2008 BSI Management Systems
ISO Internal Auditor  Compliance ManagementPrepared &Presented by Yamin K Hajeej
15Introduction to AuditingAuditor Competence and Responsibilities2364Table of ContentThe Process Approach and Process AuditingManaging an Audit ProgramAudit ActivitiesConclusion
Introduction toAuditing
AuditingWhat is an audit?Systematic, independent and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled	        (ISO19011: 2002 clause 3.1)Why audit?Requirement of ISO 9001:2008
Monitor and measure the management system
Promote continuous improvement of the management systemPrinciples of Auditing4.0Principles relating to auditors:Ethical conduct
Fair presentation
Due professional carePrinciples relating to audit:Independence
Evidence-based approachNote: reference toISO 19011:2002Clause number
Benefits of AuditingVerifies conformity to requirementsIncreases awareness and understandingProvides a measurement of effectiveness of the management system to top managementReduces risk of management system failureIdentifies improvement opportunitiesContinuous improvement if performed regularly
Types of AuditRegistration / CertificationProductCustomer contractGap assessment / Pre-assessmentSurveillanceCombined audit / joint audit
The Process Approach and Process Auditing
Process ApproachThe process approach emphasize the importance of:Understanding and meeting requirementsLooking at processes in terms of added valueObtaining results of process performanceContinual improvement of process
PlanYourProcessActDoCheckPDCA (Plan-Do-Check-Act)The Plan-do-Check-Act (PDCA) methodology applies to all processesDeploy and conform with plan
Activities
Controls
Documentation
Resources
ObjectivesContinualImprovementAnalyze/review
Decide/change
Improve effectiveness
Measure and monitor for conformity and effectivenessManagement System Standards and the Process ApproachISO 9001:2008:Is based upon the PDCA cycle which can be applied to processes
Applies the PDCA cycle to implementing, operating, monitoring, exercising, maintaining and improving the effectiveness of a QMSISO 19011:2002 does not explicitly mention process audits, but is written for application to all management system audits
Applying the Process Approach to AuditingAuditors can apply the process approach to auditing by ensuring the auditee:Can define the objectives, inputs, outputs, activities, and resources for its processesAnalyzes, monitors, measures, and improves its processesUnderstands the sequence and interaction of its processes
Process Auditing ApproachesIndividual Process:Input / Output / Value-added ActivityPlan-Do-Check-ActResourcesRelationship with other processes:Flow / Sequence / Linkage / CombinationInteraction / CommunicationEvidenceCustomer and supplier contract(s)
Process Auditing “Turtle Diagram”With what?ResourcesWith who?PersonnelInputsFrom Whom/WhereOutputsToWhom/WhereProcess(specific value-added activities)What results?PerformanceindicatorsHow done?Methods/Documentation
Process Auditing ExampleWith what?Order processing systemWith who?Customers
Competent sales and         processing staffInputsCustomer            requirementsSales staffOutputsProduction/Service DeliveryContractReviewWhat results?Order processing timeNumber or orders
Value of orders
Contract accuracyHow done?IT system
Processing system
Terms and conditions
Contract review procedureManaging an Audit Program
Managing an Audit Program Process Flow5.1PLANDOCHECKACTAUTHORIZEMONITOR &REVIEWESTABLISHIMPLEMENTIMPROVE SCHEDULE AUDITS
 EVALUATE
  AUDITORS
 SELECT TEAMS
 DIRECT ACTIVITIES
 MAINTAIN RECORDS
 OBJECTIVES
 EXTENT
 ROLES
 RESOURCES
 PROCEDURES
 MONITOR
 REVIEW
 IDENTIFY NEED  FOR CA/PA IDENTIFY   OPPORTUNITIES  TO IMPROVEAUDITORCOMPETENCE& EVALUZATIONSPECIFIC AUDITACTIVITIES
Audit Activities
Typical Audit Activities6.1Initialing the AuditPLANConducting Document ReviewPreparing for On-site ActivitiesConducting for On-site ActivitiesDOPreparing, Approving, Distributing Audit ReportCompleting the AuditCHECKConducting Audit Follow-upACT
Audit ProgramTop management should authorize responsibility for program management to:Establish, implement, review, and improve the audit program
Identify the necessary resources and ensure they are provided
Organization should develop audit program processes
Program should be managed by a member of the organization
Keep appropriate audit records to monitor and review the audit programAudit Program ResponsibilitiesTop management should authorize responsibility for program managementThose assigned responsibility should:Establish, implement, review, and improve the audit program
Identify the necessary resources and ensure they are providedInitiating the Audit6.2Initiating the audit includes:Appointing the audit team leaderDefining audit objectives, scope, criteriaDetermining feasibility of the auditSelecting the audit teamEstablishing initial contact with the auditee
Defining Audit Objectives, Scope, Criteria6.2.2Audit Objectives may include:Determining of the extent of conformity of auditee`s QMS with audit criteriaEvaluation of capability of QMS to ensure compliance with statutory, regulatory, and contractual requirementsEvaluation of effectiveness of the QMS to meet its objectivesIdentification of areas of improvement
Selecting the Audit Team6.2.4For Team size and competence, consider:Audit objectives, scope, criteria, and durationWhether audit is combined or jointCompetence of team to meet objectivesStatutory, regulatory, contractual and accreditation/certification requirementsIndependence of the team
Auditor Competence and Responsibilities
Auditor Competence7.1Auditor competence is based on:Personal attributes
Application of knowledge and skillsCompetence is to be developed, maintained, and improved
PersonalAttributesOpen-mindedDecisivePerceptiveEthicalObservantDiplomaticVersatileTenaciousSelf-reliantAuditor CompetencePersonal Attributes7.2
Auditor CompetenceGeneric Knowledge and skills7.3.1Auditor skills and competence could include:Audit principles, procedures, and techniquesManagement system and reference documentsOrganizational situationsLaws, regulations, and other requirements
Auditor CompetenceSpecific Knowledge and skills7.3.3Specific knowledge and skills for quality auditors could include:Quality methods and techniquesQuality terminologyQuality management tools and their applicationProcesses and products/services specific to the sector being audited
Auditor ResponsibilitiesArrive on timeMaintain confidentialityBe objective and ethicalSupport the audit team and team leaderPlan and prepare work documentsInform auditees of the audit processDocument and support all findingsKeep auditee informedSafeguard all documentsPrepare the audit report
Audit Activities(Continued)
Audit PlanningDetermine the objective of the auditIdentify specified requirementsDetermine audit duration and resources neededSelect the teamContact the auditee – agree the date(s)Draw up audit planBrief the teamPrepare work documents
Conducting Document Review6.3A review of documentation:Should be conducted prior to on-site audit activities unless deferring review is not detrimental to the effectiveness of the auditMay include relevant QMS documents, records, and previous audit reportsMay include a preliminary site visit
Prepare Work DocumentsPrepare work documentsUse as a reference and for recording audit proceedingsInclude checklists, sampling plans and forms, ISO 9001:2008 standard, etc.Keep checklists flexible to allow changes resulting from information collected during the auditSafeguard any confidential and proprietary informationRetain work documents and records
Checklists PreparationOne Approach is to:Identify audit scope and process(es) within scopeIdentify applicable factors (inputs, outputs, measures, resources, etc.)Use these points and other requirements	(ISO 9001-2008, system documentation, etc.) to:Plan what to look at
Plan what to look for (audit evidence) Prepare checklist
Checklists StructureAudit checklist structure:
Conduct on-Site Audit Activities6.5Conduct opening meetingCommunicate during the auditExplain roles and responsibilities of participantsCollect and verify informationGenerate audit findingsPrepare audit conclusionsConduct closing meeting
Opening Meeting6.5.1Hold opening meeting with auditee top management and      those responsible for processes auditedMeeting may be informalChaired by team leaderAudit team presentPurpose is to confirm all prior arrangements

More Related Content

PPTX
Iso 9001:2015 internal auditor Course
PPTX
Internal Audit 03-03-16
PDF
Iso 9001 internal audit tips
PPTX
Internal auditor 9001 day 1
PDF
ISO 9001:2015 Audit Checklist Preview
PPTX
ISO9001-2015 3-25-19
PPTX
ISO 9001:2015 - Greendot Management Solutions
PDF
Iso 9001 2015 Understanding
Iso 9001:2015 internal auditor Course
Internal Audit 03-03-16
Iso 9001 internal audit tips
Internal auditor 9001 day 1
ISO 9001:2015 Audit Checklist Preview
ISO9001-2015 3-25-19
ISO 9001:2015 - Greendot Management Solutions
Iso 9001 2015 Understanding

What's hot (20)

PPT
Iso9001training slide
PDF
ISO 9001 2015 Overview presentation
PDF
ISO 9001/14001/45001 requirements comparison
PPT
Iso 9001 2015 documented information guidlines
PDF
Overview of ISO 19011:2018 Guidelines for Auditing Management Systems
PPTX
ISO 9001:2015
PPTX
The new ISO 9001:2015
PPSX
ISO 9001:2015 awareness.
PDF
Risk based thinking
PPSX
ISO Implementation Roadmap- By Motaharul Islam
PDF
ISO 9001-2015 QMS Awareness & Interpretation Training.pdf
PPTX
Risk based thinking in ms iso 9001 2015
PPTX
ISO 9001:2015 Awareness Training
PPTX
ISO 9001: 2015
PDF
ISO 9001:2015
PPTX
Integrated Management System, Training, IMS, Safety
PPT
PRESENTATION ON ISO - 9001, 14001, & 45001 Clause - 5
PPTX
A brief Introduction to ISO 9001 2015-Quality Management System
PPTX
Integrated management systems
PPTX
QMS - Quality Management System - Internal Quality Auditor - ISO 9001:2008
Iso9001training slide
ISO 9001 2015 Overview presentation
ISO 9001/14001/45001 requirements comparison
Iso 9001 2015 documented information guidlines
Overview of ISO 19011:2018 Guidelines for Auditing Management Systems
ISO 9001:2015
The new ISO 9001:2015
ISO 9001:2015 awareness.
Risk based thinking
ISO Implementation Roadmap- By Motaharul Islam
ISO 9001-2015 QMS Awareness & Interpretation Training.pdf
Risk based thinking in ms iso 9001 2015
ISO 9001:2015 Awareness Training
ISO 9001: 2015
ISO 9001:2015
Integrated Management System, Training, IMS, Safety
PRESENTATION ON ISO - 9001, 14001, & 45001 Clause - 5
A brief Introduction to ISO 9001 2015-Quality Management System
Integrated management systems
QMS - Quality Management System - Internal Quality Auditor - ISO 9001:2008
Ad

Viewers also liked (20)

PDF
Principles of accounting
PDF
Law 323 tax law (part i & ii) akhtar ali and asim zulfiqar ali
PDF
Causal Relationship between Macroeconomic Factors and Stock Prices in Pakistan
PDF
[David j. sheskin]_handbook_of_parametric_and_nonp
PPTX
Human error and secure systems - DevOpsDays Ohio 2015
PDF
US National standardization strategy
PDF
[] Medical notes_clinical_medicine_pocket_guide
PDF
Labor policy in pakistan
PPTX
Building your All-Star DevOps Team – "Planning, Process and Partners"
PDF
Usability in healthcare, general overview on new standards and metrics (Inter...
PDF
Risk management in-60601-1
DOCX
Ratios and formulas in customer financial analysis
PDF
Prospectus University of lahore 2012-13
PDF
Inside Attacker: An Overview
PDF
Exempt user guide ACCA
PDF
Evolutionary_forensic_psychology__darwinian_foundations_of_crime_and_law
PDF
2011 final fixed-seprate block_tax_regimes_updated
PPTX
2017 power fundamentals (2)
PDF
Miracles in the_quran
PDF
Miracles of the_quran
Principles of accounting
Law 323 tax law (part i & ii) akhtar ali and asim zulfiqar ali
Causal Relationship between Macroeconomic Factors and Stock Prices in Pakistan
[David j. sheskin]_handbook_of_parametric_and_nonp
Human error and secure systems - DevOpsDays Ohio 2015
US National standardization strategy
[] Medical notes_clinical_medicine_pocket_guide
Labor policy in pakistan
Building your All-Star DevOps Team – "Planning, Process and Partners"
Usability in healthcare, general overview on new standards and metrics (Inter...
Risk management in-60601-1
Ratios and formulas in customer financial analysis
Prospectus University of lahore 2012-13
Inside Attacker: An Overview
Exempt user guide ACCA
Evolutionary_forensic_psychology__darwinian_foundations_of_crime_and_law
2011 final fixed-seprate block_tax_regimes_updated
2017 power fundamentals (2)
Miracles in the_quran
Miracles of the_quran
Ad

Similar to Iso Internal Auditor (20)

PPTX
ISO 9001 2015 INTERNAL AUDIT PRESENTATION COMET PORTHARCOURT.pptx
PPTX
iso 9001 2015 interna audit presentation.pptx
PPTX
ISO INTERNAL AUDIT AWARENESS REFRESHER.pptx
PDF
Auditing Principles
PPTX
Audit Technique
PPTX
internal auditor ttttttttttttttttttraining.pptx
PPTX
Internal Audit Training with different .pptx
PPTX
ISO 9001:2008 Internal Auditing of Quality Management Systems - Introduction
PPTX
ISO 9001 Internal Auditor PPT.pptx Quality management system
PPTX
Internal Auditor Training Course QMS.pptx
PDF
Webinar-ISO-9001-Back-to-Basics-Internal-Auditing
PPTX
Core Knowledge about QMS
PPSX
QMS Audit Process June 2015
PPTX
Audit Report Writing
PPT
Introduction to Internal Quality System Auditing
PPT
Performance Based Internal Quality Audit Guide
PPTX
IMS INTERNAL AUDIT , DANGOTE FERTILIZER & CEMENT.pptx
PDF
Internal audit
PPT
BCMS-Internal-Auditor-Course-ppt [Autosaved].ppt
PPTX
Internal audit of ISO 9001 Quality management system.pptx
ISO 9001 2015 INTERNAL AUDIT PRESENTATION COMET PORTHARCOURT.pptx
iso 9001 2015 interna audit presentation.pptx
ISO INTERNAL AUDIT AWARENESS REFRESHER.pptx
Auditing Principles
Audit Technique
internal auditor ttttttttttttttttttraining.pptx
Internal Audit Training with different .pptx
ISO 9001:2008 Internal Auditing of Quality Management Systems - Introduction
ISO 9001 Internal Auditor PPT.pptx Quality management system
Internal Auditor Training Course QMS.pptx
Webinar-ISO-9001-Back-to-Basics-Internal-Auditing
Core Knowledge about QMS
QMS Audit Process June 2015
Audit Report Writing
Introduction to Internal Quality System Auditing
Performance Based Internal Quality Audit Guide
IMS INTERNAL AUDIT , DANGOTE FERTILIZER & CEMENT.pptx
Internal audit
BCMS-Internal-Auditor-Course-ppt [Autosaved].ppt
Internal audit of ISO 9001 Quality management system.pptx

Recently uploaded (20)

PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Approach and Philosophy of On baking technology
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
Big Data Technologies - Introduction.pptx
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Encapsulation theory and applications.pdf
PDF
Empathic Computing: Creating Shared Understanding
PDF
Network Security Unit 5.pdf for BCA BBA.
The Rise and Fall of 3GPP – Time for a Sabbatical?
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Understanding_Digital_Forensics_Presentation.pptx
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Approach and Philosophy of On baking technology
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Chapter 3 Spatial Domain Image Processing.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Encapsulation_ Review paper, used for researhc scholars
Reach Out and Touch Someone: Haptics and Empathic Computing
Per capita expenditure prediction using model stacking based on satellite ima...
20250228 LYD VKU AI Blended-Learning.pptx
Big Data Technologies - Introduction.pptx
Dropbox Q2 2025 Financial Results & Investor Presentation
Encapsulation theory and applications.pdf
Empathic Computing: Creating Shared Understanding
Network Security Unit 5.pdf for BCA BBA.

Iso Internal Auditor