PDCA in Audit Program Management
In ISO/IEC 27001 audit program management, the Plan-Do-Check-Act (PDCA) cycle gives the audit program a continual improvement structure. It mirrors the improvement logic of the ISMS itself. ISO 19011, supported by ISO/IEC 27007 for ISMS-specific guidance, organizes audit program management around t… In ISO/IEC 27001 audit program management, the Plan-Do-Check-Act (PDCA) cycle gives the audit program a continual improvement structure. It mirrors the improvement logic of the ISMS itself. ISO 19011, supported by ISO/IEC 27007 for ISMS-specific guidance, organizes audit program management around this cycle. PLAN: The individual managing the audit program sets objectives aligned with the organization's strategic direction, information security policy, legal and contractual requirements, and stakeholder needs. Risks and opportunities affecting the program are identified and evaluated, such as insufficient resources, auditor competence gaps, scheduling conflicts, or confidentiality of sensitive information. The program is then established. This means defining its extent, number, types, duration, locations, and schedule of audits, as well as roles and responsibilities, auditor competence requirements, audit methods, and needed resources. For an ISMS, planning also considers the scope of the ISMS, the results of the information security risk assessment, the Statement of Applicability, and previous audit findings. DO: The program is implemented. Activities include communicating the program to relevant parties, defining objectives, scope, and criteria for each individual audit, and selecting audit methods. Competent audit teams are assigned, with attention to technical security expertise, and audit team leaders are made responsible for conducting audits. Records such as plans, reports, nonconformities, and corrective actions are managed and protected. CHECK: The program is monitored to evaluate whether schedules and objectives are being met. This involves assessing audit team performance, auditee feedback, the effectiveness of risk treatment within the program, and the adequacy of records. Trends and deviations are analyzed to see whether the program is delivering value. ACT: The program is reviewed and improved. Results feed into management review, and changes are made to objectives, resources, methods, or auditor competence development. Lessons learned are incorporated. Examples include adjusting audit frequency for high-risk controls or responding to emerging threats. Applying PDCA keeps the audit program dynamic, risk-based, and continually improving, rather than a static annual checklist.
PDCA in Audit Program Management: A Complete Guide for ISO/IEC 27001 Lead Auditors
Introduction
Managing an audit programme is one of the core competencies of an ISO/IEC 27001 Lead Auditor. ISO 19011:2018 (Guidelines for auditing management systems) and ISO/IEC 27007 (Guidelines for ISMS auditing) both structure audit programme management around the Plan-Do-Check-Act (PDCA) cycle. Understanding how PDCA maps onto each stage of audit programme management is essential for real-world practice and for passing the Lead Auditor exam.
Why PDCA in Audit Program Management Is Important
1. It brings structure and consistency. An audit programme may cover many audits across multiple sites, processes, years and auditors. PDCA gives a repeatable framework so that audits are planned, executed, evaluated and improved in a controlled way.
2. It drives continual improvement. The same philosophy that underpins management systems is applied to the audit function itself. An audit programme that is never reviewed becomes stale, misses emerging risks and wastes resources.
3. It supports a risk-based approach. ISO 19011:2018 requires the audit programme manager to determine and evaluate risks and opportunities to the programme. PDCA ensures these are considered in planning and revisited during monitoring and review.
4. It ensures the programme meets its objectives. Monitoring and review (Check and Act) verify whether the programme is actually achieving what top management and interested parties expect.
5. It provides accountability and evidence. Each phase produces records (programme plans, audit plans, reports, monitoring results, review outputs) that demonstrate effective management of the programme to certification bodies, accreditation bodies or top management.
6. It aligns with ISO/IEC 27001 requirements. Clause 9.2 of ISO/IEC 27001:2022 requires the organization to plan, establish, implement and maintain an audit programme, and clause 10 requires continual improvement. PDCA is the natural way to satisfy both.
What PDCA in Audit Program Management Is
An audit programme is defined in ISO 19011 as arrangements for a set of one or more audits planned for a specific time frame and directed towards a specific purpose. Note the difference: an audit programme covers multiple audits over time, whereas an audit plan describes the activities and arrangements for a single audit.
PDCA in this context is the application of the Plan-Do-Check-Act cycle to the management of the audit programme as a whole. ISO 19011:2018 Clause 5 (Managing an audit programme) and its Figure 1 explicitly show this mapping:
PLAN
- 5.2 Establishing audit programme objectives
- 5.3 Determining and evaluating audit programme risks and opportunities
- 5.4 Establishing the audit programme (roles and responsibilities, competence of the programme manager, extent of the programme, resources)
DO
- 5.5 Implementing the audit programme (defining objectives, scope and criteria for individual audits; selecting audit methods; selecting audit team members; assigning responsibility to the audit team leader; managing audit outcomes; managing and maintaining records)
- Clause 6 Conducting an audit (the individual audits themselves)
CHECK
- 5.6 Monitoring the audit programme
ACT
- 5.7 Reviewing and improving the audit programme
How It Works: Each Phase in Detail
1. PLAN - Establishing the Audit Programme
a) Establish objectives (5.2): Objectives are set by the individual(s) managing the programme, considering the needs and expectations of interested parties, the organization's direction, management system requirements, the need to evaluate external providers, the level of performance and maturity of the ISMS, information security risks, and the results of previous audits. Example objectives: verify conformity with ISO/IEC 27001, prepare for certification, evaluate a supplier, assess control effectiveness for high-risk processes.
b) Determine and evaluate risks and opportunities (5.3): Risks to the programme include poor planning (unrealistic objectives, insufficient time), insufficient resources, wrong audit team selection or competence gaps, ineffective communication, poor implementation, inadequate records control, and lack of cooperation from the auditee. Opportunities include combining audits, using remote audit techniques, reducing travel, and aligning audits with business cycles.
c) Establish the programme (5.4): Define roles and responsibilities of the audit programme manager; ensure the manager is competent (audit principles, methods, ISMS standards, information security risk, context of the auditee); determine the extent of the programme (number, duration, frequency, locations, and scope of audits); and identify resources (financial, time, competent auditors and technical experts, logistics, information and communication technology).
For ISMS audits, ISO/IEC 27007 adds that the programme should reflect the organization's information security risks, the Statement of Applicability, and the results of risk treatment.
2. DO - Implementing the Audit Programme
The programme manager:
- Communicates the programme to relevant parties
- Defines objectives, scope and criteria for each individual audit
- Selects and determines audit methods (on-site, remote, combined; interviews, observation, document review, sampling)
- Selects the audit team members based on competence, independence and objectivity, and appoints an audit team leader
- Assigns responsibility for each audit to the team leader, providing necessary information (previous reports, contact details, confidentiality and information security requirements)
- Manages audit programme outcomes: ensures reports are reviewed, approved and distributed; ensures corrections and corrective actions are followed up; evaluates whether audit objectives were achieved
- Manages and maintains audit programme records (programme records, individual audit records, auditor competence and performance records)
The individual audits are then carried out following ISO 19011 Clause 6: initiating the audit, preparing, conducting, preparing and distributing the report, completing the audit, and follow-up.
3. CHECK - Monitoring the Audit Programme
The programme manager evaluates:
- Whether schedules are being met and audit objectives achieved
- Performance of audit team members, including the audit team leader and technical experts
- The ability of audit teams to implement the audit plan
- Feedback from top management, auditees, auditors and other interested parties
- The sufficiency and adequacy of documented information throughout the audit process
Monitoring may trigger changes to the programme, for example due to audit findings, demonstrated levels of ISMS effectiveness and maturity, changes to the auditee's context, or new information security risks and incidents.
4. ACT - Reviewing and Improving the Audit Programme
The programme manager and top management review whether the programme objectives have been achieved. Inputs to the review include results and trends from monitoring, conformity with procedures, evolving needs of interested parties, records, alternative or new auditing methods, auditor competence, effectiveness of measures to address programme risks, and confidentiality and information security issues.
Outputs include actions to improve the programme, such as adjusting audit frequency, changing scope, developing auditor competence, revising methods, or updating objectives. The review results are reported to top management, and the improved programme feeds back into the next PLAN phase, completing the cycle.
Practical Example
An organization plans an annual ISMS internal audit programme covering all Annex A themes over 12 months (PLAN). Audits are carried out by trained internal auditors with an appointed lead (DO). Monitoring shows that the cloud services audit overran by two days and auditors lacked cloud security knowledge (CHECK). The review decides to add a technical expert, increase audit duration for cloud processes, and schedule auditor training (ACT). The next year's programme reflects these changes (back to PLAN).
Key Distinctions to Remember
- Audit programme vs audit plan: programme = multiple audits over a time frame; plan = one audit.
- Programme manager vs audit team leader: the programme manager manages the overall programme (all PDCA phases); the audit team leader manages an individual audit.
- Monitoring vs reviewing: monitoring (Check) is ongoing evaluation of implementation and performance; reviewing (Act) is a periodic evaluation of whether objectives are met, leading to improvement decisions.
- Risks to the programme vs risks of the auditee: programme risks concern the ability to achieve programme objectives; auditee information security risks are an input to setting priorities and scope.
Exam Tips: Answering Questions on PDCA in Audit Program Management
1. Memorize the mapping. Plan = 5.2, 5.3, 5.4 (objectives, risks and opportunities, establishing). Do = 5.5 (implementing) and Clause 6 audits. Check = 5.6 (monitoring). Act = 5.7 (reviewing and improving). Many questions simply ask which phase an activity belongs to.
2. Use keyword triggers. Words like establish, define objectives, determine extent, identify resources, evaluate risks point to PLAN. Select audit team, assign team leader, conduct, communicate, manage records point to DO. Monitor, evaluate auditor performance, track schedules, collect feedback point to CHECK. Review, improve, adjust, update the programme point to ACT.
3. Watch for the programme-vs-plan trap. If a question describes activities for a single audit (agenda, timing of interviews), it is about the audit plan, not the programme.
4. Identify who is responsible. Questions about setting objectives, selecting auditors, monitoring and reviewing usually point to the audit programme manager, often with top management involvement in approving objectives and reviewing results. Conducting the audit and writing the report point to the audit team leader.
5. Remember risk-based thinking. If asked what must be considered when establishing a programme, include risks and opportunities to the programme, the auditee's information security risks, ISMS maturity, previous audit results and interested party needs.
6. Link Check to Act explicitly. In scenario or essay questions, show that monitoring results are inputs to the review, and that the review produces improvement actions that feed the next planning cycle. Examiners reward demonstrating the cycle, not just listing phases.
7. Cite references. In written answers, cite ISO 19011:2018 Clause 5, ISO/IEC 27007 for ISMS-specific guidance, and ISO/IEC 27001:2022 Clause 9.2 for the internal audit requirement. For certification audits, mention ISO/IEC 17021-1 and ISO/IEC 27006-1 for the three-year certification cycle (initial certification, surveillance, recertification).
8. Structure scenario answers by phase. When asked how to manage or fix a failing programme, organize your answer as Plan, Do, Check, Act with one or two concrete actions under each. This shows clarity and full coverage.
9. Identify the missing phase. A common scenario describes an organization that plans and conducts audits but never evaluates them. The correct answer is usually that Check and/or Act are missing, so there is no continual improvement of the programme.
10. Do not confuse with ISMS PDCA. ISO/IEC 27001:2022 no longer explicitly mandates PDCA for the ISMS, but ISO 19011 still uses PDCA for audit programme management. Read carefully whether the question concerns the ISMS or the audit programme.
11. Eliminate distractors. Options that place corrective action follow-up in PLAN, or auditor selection in ACT, are typically wrong. Managing audit outcomes and follow-up belongs to DO (5.5), while improvement of the programme itself belongs to ACT (5.7).
Summary
PDCA provides the backbone for managing an ISO/IEC 27001 audit programme: PLAN by setting objectives, assessing risks and opportunities and establishing the programme; DO by implementing the programme and conducting audits; CHECK by monitoring performance and progress; and ACT by reviewing results and improving the programme. Mastering this mapping, the key roles, and the distinctions between programme and plan will allow you to answer exam questions confidently and manage audit programmes effectively in practice.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!