Periodic inspection

How is an internal audit programme set up?

The programme sets frequency, methods, responsibilities, planning requirements and reporting. Frequency is not spread evenly: the importance of processes, the changes made and the results of previous audits all shape it. High-risk processes and those with findings last year are audited sooner; the annual calendar is the output of that reasoning, not its starting point.

What the programme sets

  • frequency — which process, how often,
  • method — interview, record review, field observation, sampling,
  • responsibility — who manages the programme, who audits,
  • planning requirements — scope, criteria, duration,
  • reporting — findings to whom, and when.

How frequency is decided

Three inputs, all written down:

  1. Importance of the processes — a process with major accident potential is not an office process.
  2. Changes — a new line, new software, a new contractor, new legislation.
  3. Results of previous audits — where findings arose last year comes round sooner this year.

Giving every process the same interval reduces the programme to a calendar and blinds it to risk.

Defining scope

The scope of an audit session is defined by three things: which process or unit, which clauses, which period. Without all three, the audit stays open to “was that in scope?” afterwards.

The programme is reviewed too

The year-end question is: did the programme surface findings? If every session came back clean, either the system is genuinely mature or the programme is looking in the wrong places. The second is more often true.

Manage this in Optifora

Optifora is not a single program but a compliance platform assembled from modules. The catalogue states which module is ready today and which is on the roadmap.

See what Optifora is