Free kit
Internal Auditor Toolkit: Audit Programme and Report
A risk-based annual audit programme, an audit report template with a pre-issue check, and an auditor competence matrix with evaluation and independence records.
Clause checklists tell you what to look at during an audit. This toolkit covers the rest of the internal auditor's job: deciding what to audit and when, reporting what you found so that it leads to action, and showing that your auditors are competent and impartial. It follows ISO 19011:2018, Guidelines for auditing management systems, and works for ISO 9001, ISO 14001, ISO 45001, ISO/IEC 27001 or an integrated system.
What is inside
Annual Audit Programme — guidance on a risk-based programme, plus five templates: programme objectives and scope, a priority rating guide, the annual programme, programme monitoring and an end-of-year programme review.
Audit Report Template — six report sections: audit details; summary and conclusion; nonconformities by requirement, evidence and grade; positive observations; opportunities for improvement; and follow-up. It ends with a 12-point check to run before you issue the report.
Auditor Competence Matrix — guidance on auditor competence, plus four templates: an auditor register, a 14-line competence matrix, an auditor evaluation record and an auditor independence check.
All three documents as a designed, print-ready PDF and as an editable Word file.
Who it is for
Audit programme owners, quality and HSE managers, lead and internal auditors, and consultants who run internal audit programmes for their clients.
How to use it
Start with the programme. List your processes, rate each one for importance, change and previous results, and let the rating decide how often and how deeply you audit it. Assign auditors only after the independence check, because nobody should audit their own work. After each audit, write the report in the template, run the 12-point check, and issue it while the closing meeting is still fresh. Update the monitoring sheet as audits are completed, and review the whole programme before management review so that its results go in as an input. Evaluate each auditor at a defined interval, record the result in the matrix and plan the training it points to.
Pair the toolkit with a clause checklist for the standard you are auditing, and check which edition of that standard applies to you.
What is in the kit
- Annual Audit Programme (PDF)Risk-based programme guidance plus five templates: objectives and scope, priority rating guide, annual programme, monitoring and programme review.625 KB
- Audit Report Template (PDF)Six report sections — details, conclusion, nonconformities, positive observations, opportunities for improvement, follow-up — and a 12-point check before you issue it.692 KB
- Auditor Competence Matrix (PDF)Guidance on auditor competence plus four templates: auditor register, 14-line competence matrix, evaluation record and independence check.609 KB
- Annual Audit Programme (editable Word)The same document in Word, so you can adapt it and fill it in on screen.29 KB
- Audit Report Template (editable Word)The same document in Word, so you can adapt it and fill it in on screen.29 KB
- Auditor Competence Matrix (editable Word)The same document in Word, so you can adapt it and fill it in on screen.29 KB
A look inside
The first pages of Annual Audit Programme (PDF). The full document downloads from the list above.
Questions people ask
Is the Internal Auditor Toolkit: Audit Programme and Report really free?
Yes. There is no payment and no trial. Tell us your name, work email and company once, and every document in the Free Zone is yours to download.
What format are the documents in?
This kit has 6 documents in PDF and DOCX format. The Word, Excel or PowerPoint files are fully editable, so you can adapt them to your organisation.
Can I use it inside my company?
Yes. The licence covers one organisation with unlimited internal use — print it, share it with colleagues and adapt it. Please do not resell it or republish it as your own.
Does this make us compliant with ISO 19011?
No document can do that on its own. It is a practical working tool to help you prepare, check and improve. Conformity with ISO 19011 is decided by an audit of your actual system, and the standard itself remains the authoritative text.
Do you offer training on this topic?
Yes. Skedmia runs online courses with certificates on the standards and topics these kits cover — the matching courses are listed on this page.
More from the Free Zone
FreeNewEditableCyber Security Risk Mitigation Checklist
80 controls in 10 risk areas, each with the reason it matters — plus a 5 × 5 cyber risk register template.
FreeNewEditableAWS Security Checklist
90 checks to review an AWS account — root user, IAM, network, S3 and databases, encryption, logging, detection and recovery.
FreeNewEditableIT Security Audit Checklist
120 audit checks across 12 control areas, plus an audit plan and findings log — ready for your next internal IT audit.


