Audit Evidence for ISO 18788 Internal Audit Compliance

1. Audit Planning Evidence

  • 3-Year Rolling Audit Plan
    • Long-term strategy ensuring every clause, process, and operational site is covered.
    • Links audits to organizational risks, human rights obligations, and VPSHR commitments.
  • Annual Audit Plan
    • Yearly breakdown of SOMS audits aligned with risk-based priorities.
    • Includes strategic themes (e.g., governance, compliance, human rights) and tactical/operational processes (e.g., weapons control, incident management).
  • Quarterly Audit Schedule
    • More detailed plan showing specific audits by quarter, often focused on tactical processes and regional operations.
  • Monthly Audit Plan
    • Specific site or process audits (e.g., patrol completion, grievance handling, OHS compliance).
  • Weekly Audit/Inspection Checklists
    • Supervisory-level checks to ensure daily operations align with SOMS requirements.
    • Evidence of proactive monitoring at the operational level.

2. Audit Execution Evidence

  • Audit Programs/Checklists
    • Clause-by-clause audit checklists aligned with ISO 18788.
    • Includes cross-links to ISO 31000 (risk), ISO 37301 (compliance), ISO 22301 (continuity), and VPSHR.
  • Audit Reports
    • Formal reports for each audit, with findings categorized (conformance, non-conformance, opportunity for improvement).
    • Reports must highlight implications for strategic, tactical, and operational objectives.
  • Audit Working Papers
    • Notes, interview records, site photos, logs reviewed, attendance registers.
    • Provides evidence trail for each audit conclusion.

3. Findings and Corrective Actions

  • Audit Findings Register
    • Consolidated list of non-conformities (major/minor), observations, and opportunities for improvement.
  • Corrective Action Plan (CAPA) Register
    • Each finding linked to corrective/preventive actions, responsible persons, deadlines, and closure status.
  • Follow-up Audit Records
    • Evidence that corrective actions have been verified as implemented.

4. Governance and Review Evidence

  • Audit Summary Reports for Management Reviews
    • Consolidated quarterly/annual reports presented to the Board, EXCO, or senior management.
  • Strategic Audit Reviews
    • Evaluations of whether audits demonstrate alignment with governance objectives and human rights obligations.
  • Tactical Audit Reviews
    • Evidence that divisional/regional management is using audit results to manage risks.
  • Operational Audit Reviews
    • Evidence that supervisors and frontline staff are being held accountable for recurring audit findings.

5. Performance and Assurance Evidence

  • Audit Trend Analysis Reports
    • Year-on-year analysis of findings by category (human rights, OHS, use of force, incident reporting).
  • Combined Assurance Matrix
    • Evidence showing integration of audit results with risk management, compliance, and assurance providers.
  • Audit KPIs and Effectiveness Metrics
    • % of planned audits completed.
    • % of corrective actions closed on time.
    • Audit coverage ratio across SOMS processes and sites.

6. Audit Evidence Hierarchy (Reliability per AERM)

  • Most Reliable: Signed audit reports, validated findings register, evidence of corrective action implementation.
  • Moderate: Auditor notes, supervisor checklists, training attendance linked to audit corrective actions.
  • Least Reliable: Verbal assurances or undocumented inspections.

Summary - The ISO 18788 Audit Evidence Ecosystem

To comply fully with Clause 9.2, organizations must produce evidence across multiple timeframes and levels:

  • Strategic: Rolling 3-Year Plan, Annual Audit Program, Strategic Audit Reviews.
  • Tactical: Quarterly Audit Plans, Divisional Audit Reports, Trend Analysis.
  • Operational: Monthly & Weekly Plans, Daily Audit Logs, Supervisor Checklists.

This layered approach ensures the entire ISO 18788 ecosystem is audited holistically and continuously, with traceable evidence for auditors, clients, and stakeholders.