Audit & management review package

Audit usefulness and effectiveness—not form completion.

A risk-based internal audit follows real opportunities across functions and tests whether controls improve customer commitments and outcomes.

PLAN

Audit programme

Prioritise processes by customer, commercial, compliance and change risk; define independence, competence and sampling.

TRACE

Process trail

Sample opportunities from qualification through outcome; reconcile CRM, approvals, offer, contract, handover and feedback.

EVIDENCE

Audit evidence

Interview process actors, observe work, inspect records and test consistency across samples.

REPORT

Findings

Separate conformity, effectiveness, risk, opportunity and observation. Do not use guidance as audit criteria unless adopted internally.

IMPROVE

Corrective action

Contain customer exposure, establish cause, implement action and verify effectiveness.

REVIEW

Management review

Evaluate context, objectives, customer perception, performance, audit, resources, risk and improvement decisions.

Minimum management-review output

  • Decisions and actions on process effectiveness
  • Customer and commercial risks requiring treatment
  • Resource, competence and system changes
  • Improvement priorities, owners and dates
  • Evidence required to verify effectiveness

Audit guidance reference: ISO 19011:2026 (opens in a new tab).

OwnerSaleQMS editorial
Expert reviewCommercial & quality method
StatusControlled · Implementation guidance
Reviewed22 Aug 2026 · event-driven
Feedback