Audit Evidence for ISO 18788 Internal Audit Compliance
1. Audit Planning Evidence
- 3-Year Rolling Audit Plan
- Long-term strategy ensuring every clause, process, and operational site is covered.
- Links audits to organizational risks, human rights obligations, and VPSHR commitments.
- Annual Audit Plan
- Yearly breakdown of SOMS audits aligned with risk-based priorities.
- Includes strategic themes (e.g., governance, compliance, human rights) and tactical/operational processes (e.g., weapons control, incident management).
- Quarterly Audit Schedule
- More detailed plan showing specific audits by quarter, often focused on tactical processes and regional operations.
- Monthly Audit Plan
- Specific site or process audits (e.g., patrol completion, grievance handling, OHS compliance).
- Weekly Audit/Inspection Checklists
- Supervisory-level checks to ensure daily operations align with SOMS requirements.
- Evidence of proactive monitoring at the operational level.
2. Audit Execution Evidence
- Audit Programs/Checklists
- Clause-by-clause audit checklists aligned with ISO 18788.
- Includes cross-links to ISO 31000 (risk), ISO 37301 (compliance), ISO 22301 (continuity), and VPSHR.
- Audit Reports
- Formal reports for each audit, with findings categorized (conformance, non-conformance, opportunity for improvement).
- Reports must highlight implications for strategic, tactical, and operational objectives.
- Audit Working Papers
- Notes, interview records, site photos, logs reviewed, attendance registers.
- Provides evidence trail for each audit conclusion.
3. Findings and Corrective Actions
- Audit Findings Register
- Consolidated list of non-conformities (major/minor), observations, and opportunities for improvement.
- Corrective Action Plan (CAPA) Register
- Each finding linked to corrective/preventive actions, responsible persons, deadlines, and closure status.
- Follow-up Audit Records
- Evidence that corrective actions have been verified as implemented.
4. Governance and Review Evidence
- Audit Summary Reports for Management Reviews
- Consolidated quarterly/annual reports presented to the Board, EXCO, or senior management.
- Strategic Audit Reviews
- Evaluations of whether audits demonstrate alignment with governance objectives and human rights obligations.
- Tactical Audit Reviews
- Evidence that divisional/regional management is using audit results to manage risks.
- Operational Audit Reviews
- Evidence that supervisors and frontline staff are being held accountable for recurring audit findings.
5. Performance and Assurance Evidence
- Audit Trend Analysis Reports
- Year-on-year analysis of findings by category (human rights, OHS, use of force, incident reporting).
- Combined Assurance Matrix
- Evidence showing integration of audit results with risk management, compliance, and assurance providers.
- Audit KPIs and Effectiveness Metrics
- % of planned audits completed.
- % of corrective actions closed on time.
- Audit coverage ratio across SOMS processes and sites.
6. Audit Evidence Hierarchy (Reliability per AERM)
- Most Reliable: Signed audit reports, validated findings register, evidence of corrective action implementation.
- Moderate: Auditor notes, supervisor checklists, training attendance linked to audit corrective actions.
- Least Reliable: Verbal assurances or undocumented inspections.
Summary - The ISO 18788 Audit Evidence Ecosystem
To comply fully with Clause 9.2, organizations must produce evidence across multiple timeframes and levels:
- Strategic: Rolling 3-Year Plan, Annual Audit Program, Strategic Audit Reviews.
- Tactical: Quarterly Audit Plans, Divisional Audit Reports, Trend Analysis.
- Operational: Monthly & Weekly Plans, Daily Audit Logs, Supervisor Checklists.
This layered approach ensures the entire ISO 18788 ecosystem is audited holistically and continuously, with traceable evidence for auditors, clients, and stakeholders.