Internal Audit Programme
Plan the year's internal audits — one row per planned audit, with risk-based frequency, auditor independence, planned against actual dates, deferral reasons and a coverage check that shows which high-risk processes are under-audited; for conducting the audits themselves use the internal audit checkl
Version 1.0.0 · Updated Aug 7, 2026
Overview
Frequently asked questions
How does the Internal Audit Programme licence work?
It is a one-time purchase for a downloadable tool — no subscription. You buy it once and the file is yours to keep and use.
Can I try the Internal Audit Programme before buying?
Yes. Use the Try online button for a fully interactive demo with sample data already loaded — nothing to install and nothing is saved.
Can I import my data from a spreadsheet?
Yes. Use the Spreadsheet template button to save a CSV with the right headings, fill it in Excel or any spreadsheet, then Import spreadsheet to load it back. The file is read in your browser — nothing is uploaded.
Does my data stay private?
Yes. The tool is a single HTML file that runs entirely on your computer and makes no network requests, so nothing you enter is ever uploaded or shared.
Do I need Excel or any other software?
No. It replaces the spreadsheet template entirely: open the file in your browser (Chrome, Edge, Firefox or Safari) on Windows, Mac, Linux or a tablet, and start working.
How to use Internal Audit Programme
The complete in-tool guidance, reproduced here so you can read it before you download.
What this tool does
CM8-293 holds the annual internal audit programme. One row is one planned audit: which process, what type, how risky it is, which month it falls in, who will do it, whether that person is independent of the area, and — once it has happened — the actual date and what it found. From that it works out how much of the programme is complete against what was due by now, which audits have slipped past their month, and which high-risk processes have fewer audits planned than your own minimum.
Everything runs inside this single file. No account, no upload, no network request of any kind, so a document naming the processes you consider risky never leaves this computer.
Programme, not audit
This tool plans audits. It does not conduct them, and the two are genuinely different disciplines.
Conducting an audit is a skill: asking the right question, sampling honestly, recognising evidence, grading a finding by its reach rather than by how awkward the conversation will be. The Internal Audit Checklist tool is where that work lives — one row per question asked, with evidence, grade and corrective action tracked to verified closure.
The programme is a management decision made months earlier, and it settles three things the auditor cannot: what gets looked at, how often, and by whom. A very good auditor working to a bad programme audits the same three comfortable areas every year, writes excellent reports, and never goes near the process that is about to fail. Nothing in the audit records reveals that. Only the programme does — which is why external assessors ask to see it.
Risk-based frequency
Auditing everything equally often is the same as auditing nothing in particular. Frequency should follow risk, and the risk rating on each row is what drives the minimum coverage. A process earns a high rating for reasons like these:
- Regulatory or contractual exposure — a failure breaches something you signed or something a regulator enforces.
- Customer impact — the customer sees the failure directly, or receives the defect.
- Safety consequence — a lapse hurts somebody rather than costing money.
- Complexity — many handoffs and exceptions, so many chances for procedure and practice to drift apart.
- Recent problems — nonconformities, complaints, returns or incidents in the last year. Recency is a legitimate risk factor: let it move a process up for a year, then let it move back.
- New people or new equipment — competence has not been demonstrated yet, and the procedure has not been tested by somebody who did not help write it.
Set the minimum for high-risk processes on the Settings tab — twice a year is a common working standard, and having a number you apply matters more than which number it is. Medium and low risk processes get no automatic minimum here, because a sensible programme covers them annually or biennially depending on the size of the system, and inventing a rule for that would produce false shortfalls.
Auditor independence, honestly
Auditors should not audit their own work — not because they would lie, but because they share the assumptions that created the gap and will look straight past it. The tick box records whether the planned auditor is independent of the area; the exceptions tile counts the ones who are not.
In a small firm full independence is often impossible: there may be exactly one person who understands the planned-maintenance schedule well enough to audit it, and that person runs maintenance. Do not pretend. Leave the box unticked, write the reason and the mitigation in the notes, and let it stand as an exception. Three honest exceptions with mitigations recorded read far better to an assessor than none — because none, in a firm of thirty people, is not credible.
Mitigations worth recording: have someone uninvolved pick the sample, swap audits between department heads, borrow an auditor from a sister site, or put a second person in the closing meeting. System audits are the one place the tool insists — it will not save a management system audit with the box unticked, because an audit of the system by the person who owns the system verifies nothing at all.
A schedule that survives production
Plan to a month, not a day. The programme commits to auditing goods-in in March; the exact morning is agreed with the area a fortnight beforehand. That is why the planned date field wants the first of the month — it is a month marker, not an appointment.
Then read the shape of the year chart before the year starts. Four audits in one month and none either side is a programme written against a spreadsheet rather than a production calendar, and it fails in the first busy week. Spread them, clear of your peak season, stock count, shutdown and the month the certification body visits. An audit that has to be squeezed in gets squeezed — the sample shrinks, the questions get easier, and the record says it happened.
Deferral discipline
Audits will move. That is not the failure — the failure is the audit that quietly does not happen and is never mentioned again.
Deferring properly is a management act: set the status to deferred, record why, and say what it moved to. The tool will not accept a deferral without a reason, and the sample shows what a real one looks like — a surveillance visit landed in the same month, so the internal audit was rescheduled rather than run alongside it. That is a decision anyone can review. "Deferred" with an empty reason field is drift wearing a status.
The overdue flag catches the other failure mode: an audit still marked planned or scheduled when its month has passed. Nothing is overdue during its own month — it becomes overdue the moment the month ends without being done, deferred with a reason, or cancelled with one.
Letting findings steer next year
Record how many findings each completed audit raised and how many were major. Over a year that becomes the most useful input to the next programme. Processes that keep producing findings are telling you where the system is weak and deserve more frequency, not easier questions. Processes clean three years running are candidates for a lighter touch — or a harder auditor, because a run of clean audits sometimes means the questions have gone stale rather than the process has gone right. A major finding is the strongest signal here: a control is not operating, and that process belongs in next year's programme twice, the second visit booked as a follow-up audit.
The coverage check
The coverage table is the annual review evidence. One row per process: risk rating, audits planned, audits complete, the minimum required if it is high risk, the shortfall, the last audit date and the next planned month. Rows with a shortfall sort to the top.
Take it to the management review and to the external assessment. It answers on one page the question both ask: did the programme cover what the risk said it should? A shortfall shown and explained is a managed programme. A shortfall found by the assessor is a finding.
The formulas
Programme completion = audits complete ÷ audits planned to date × 100 Coverage shortfall = minimum required − audits planned Slipped days = 0 if the audit was done inside its planned month, otherwise the days beyond the last day of that month
Completion is measured against audits due by now — those whose planned month has started — not against the whole year, because dividing by the full programme in February reports a failing number for a programme running perfectly to plan. Cancelled audits are excluded from both sides, and findings are summed only where you entered them: a blank findings box contributes nothing rather than counting as zero findings found.
The spreadsheet workflow
A programme is usually drafted in a spreadsheet, and there is no reason to retype it.
- Spreadsheet template saves a CSV whose headings are exactly this tool's column names, with a guidance row explaining what each expects — the date format and the accepted values for the audit type, risk rating and status lists.
- Draft the year there, one row per planned audit, then delete the guidance row and save as CSV.
- Import spreadsheet reads it back. Columns match by heading, so order does not matter and extra columns are ignored. Rows failing validation — a deferral with no reason — are skipped and reported by row number.
The file is read in your browser: nothing is uploaded, and importing adds to what is already here.
FAQ
How many audits should a year's programme contain? Enough to cover every process at least once and the high-risk ones at your minimum. For a small firm that is often eight to fifteen. Twenty superficial audits verify less than ten done properly.
One system audit or many process audits? Many. A single audit of "the system" cannot be scoped or sampled. Audit processes, and add one or two system-level audits for the clauses belonging to no single process — management review, corrective action, document control.
What counts as complete? The audit was conducted and reported. Closing the findings it raised is tracked in the audit checklist tool, not here — a programme can be complete while corrective actions are still open, and conflating the two hides both.
Why is there no auditor competence field? Competence is evidence — training, qualifications, witnessed audits — and it belongs in a training record, not a tick box on a schedule.
What if I am not confident about a risk rating? Rate it medium and revisit it at the annual review with a year of findings, complaints and incidents in front of you. Ratings should move.
Saving your work
The programme, settings and report header are written to this browser's local storage as you type, and the toolbar shows the time of the last save. That storage belongs to one browser on one computer: another browser, a private window, a second machine or a clean-up tool that clears site data will not have it.
Treat Export .json as the real save — one file containing everything, which Import .json restores anywhere. Export CSV gives you the programme for spreadsheet work. Reset asks twice, then erases everything stored. There is no undo. Export at the end of each programme year and file it with the management review pack.
Accuracy & disclaimer
The arithmetic here is simple and shown in full. What it cannot see is the thing that matters: a programme reported as 100% complete proves the audits took place, not that they were any good. It says nothing about whether the sample was fair, the auditor competent, the questions still sharp, or the areas chosen the ones that needed looking at. Only reading the audit reports tells you that.
Risk ratings, minimum frequencies and independence judgements are yours, and certification rules and record-retention expectations differ by standard, by industry and by country. This is an internal record-keeping and planning aid, not a certification audit, not an audit report, and not legal or regulatory advice.
Related tools
Keep a register of improvement ideas, track each one from suggestion to verified saving, and see honest payback figures that never mix claimed savings with measured ones. Nothing is uploaded.
Link incoming material batches to the batches you make and the customers you send them to, so a recall can be scoped in minutes instead of days. Runs entirely in your browser — nothing is uploaded.
CAPA Tracker
Track corrective and preventive actions from problem to verified fix: root causes, owners, due dates, effectiveness checks and an aging view for management review. Runs entirely in your browser — nothing is uploaded.
Classify stock items into A, B and C by annual usage value, see the Pareto curve, flag dead stock and overstocked A items, and set a control policy per class. Runs entirely in your browser — nothing is uploaded.