Curriculum
- 2 Sections
- 35 Lessons
- 26 Weeks
- ISO3100010
- 1.1Introduction to ISO31000 and Risk Management Concepts
- 1.2ISO31000 Principles and Understanding Organizational Context
- 1.3Risk Management Framework and Leadership Responsibilities
- 1.4Risk Assessment – Identification, Analysis, and Evaluation
- 1.5Risk Treatment and Control Measures
- 1.6Monitoring, Review, and Communication of Risks
- 1.7Integration of Risk Management into Governance and Organizational Processes
- 1.8Risk Culture, Human Factors, and Competence Requirements
- 1.9Documentation, Record-Keeping, and Evidence Requirements
- 1.10Internal Audit, Management Review, and Continual Improvement
- ISO 19011: Guidelines for auditing management systems26
- 2.1Introduction to ISO19011
- 2.2Principles of Auditing
- 2.3Managing an Audit Program
- 2.4Establishing Audit Program Objectives
- 2.5Determining Audit Program Risks and Opportunities
- 2.6Establishing the Audit Program
- 2.7Implementing the Audit Program
- 2.8Monitoring the Audit Program
- 2.9Reviewing and Improving the Audit Program
- 2.10Initiating the Audit
- 2.11Determining Audit Feasibility
- 2.12Preparing Audit Activities
- 2.13Reviewing Documented Information
- 2.14Preparing the Audit Plan
- 2.15Assigning Work to the Audit Team
- 2.16Preparing Working Documents
- 2.17Opening Meeting
- 2.18Communication During the Audit
- 2.19Collecting and Verifying Information
- 2.20Generating Audit Findings
- 2.21Preparing Audit Conclusions
- 2.22Closing Meeting
- 2.23Preparing the Audit Report
- 2.24Completing the Audit
- 2.25Follow-Up Activities
- 2.26ISO31000 EXAM120 Minutes40 Questions
Collecting and Verifying Information
Collecting and Verifying Information
Auditors collect information through several methods, each of which provides different types of evidence. The most commonly used methods include:
1. Interviews:
Interviews involve direct communication with personnel at all levels of the organization, including management, supervisors, and operational staff. The purpose of interviews is to understand how processes are implemented in practice, verify knowledge of procedures, and confirm that responsibilities are clearly understood. Effective interviewing requires auditors to ask clear, open-ended questions and to listen carefully to responses. Interviews should be conducted in a professional and respectful manner to encourage honest and accurate information.
2. Observation:
Observation allows auditors to witness processes and activities as they occur in real time. By observing employees performing tasks, auditors can verify that procedures are being followed correctly and that operations are conducted in accordance with documented requirements. Observation is particularly valuable for evaluating practical application, work practices, and compliance with safety or quality standards.
3. Document Review:
Reviewing documents and records is essential to verify that processes are planned, documented, and properly controlled. Examples of documents include procedures, work instructions, policies, regulatory compliance records, previous audit reports, and performance data. Document review helps auditors understand the intended processes and identify any gaps between the documented procedures and actual practices.
4. Sampling:
In most audits, it is not practical to examine every record, activity, or transaction. Auditors use sampling methods to select representative examples that provide sufficient evidence for evaluation. Sampling must be systematic, unbiased, and appropriate to the scale and risk level of the processes being audited. The results of the sampled items are then used to draw conclusions about the broader process.
Ensuring Evidence is Relevant
Verifying the Accuracy of Information
Verification of information is a critical step in ensuring that audit findings are based on reliable evidence. Auditors should check the authenticity, accuracy, and consistency of the information collected.
Verification techniques may include:
- Cross-checking information from multiple sources (e.g., comparing records, observations, and interviews)
- Confirming dates, signatures, and documentation accuracy
- Comparing evidence against audit criteria, such as standards, regulatory requirements, or internal procedures
- Discussing discrepancies with process owners or supervisors for clarification
Verification ensures that the evidence is credible, objective, and can be confidently used to support audit conclusions.
Supporting Audit Effectiveness
Collecting and verifying information is the foundation for all subsequent audit activities, including generating findings, preparing conclusions, and reporting results. Effective evidence collection ensures that audit results are accurate, actionable, and valuable for the organization. By systematically gathering and verifying information, auditors can provide an objective evaluation of the management system and support continual improvement initiatives.
The careful and structured approach to collecting and verifying information ultimately strengthens the credibility, reliability, and usefulness of the audit process.