Why a flat annual schedule wastes effort
The default internal-audit schedule is a flat rotation: every process audited once a year, in a tidy calendar that gives each area the same slot regardless of what it is or how it behaves. It is simple to plan and easy to defend as “we audit everything” — and it is quietly wasteful at both ends. The stable, low-risk process that has not produced a finding in three years gets the same attention as the volatile, safety-critical one that generates non-conformances every cycle. You over-audit what is fine and under-audit what is not.
Since ISO 9001:2015 built risk-based thinking into the standard, the flat rotation is not just inefficient — it is out of step with what a registrar expects. Clause 9.2 asks that the audit programme take into account the status and importance of the processes concerned and the results of previous audits. In plain terms: audit more where it matters and where you have found problems, less where you have not. This guide is a practical method for risk-based audit scheduling, grounded in how a real audit management system sets frequency and coverage.
What drives audit risk
Risk-based scheduling starts by scoring each process on a small set of factors that predict where a problem is most likely and most costly. You do not need a complex model — a few dimensions, honestly rated, are enough to separate the processes that need frequent attention from those that do not.
| Risk factor | What raises it | Effect on frequency |
|---|---|---|
| Process criticality | Safety, regulatory or customer-critical characteristics; special processes | More often |
| Past NC history | A record of findings, especially majors or repeats | More often |
| Change & instability | New process, new equipment, recent design or supplier change | More often |
| Customer / OEM pressure | Customer complaints, warranty, a customer-specific requirement | More often |
| Complexity | Many steps, tight tolerances, manual dependence | Somewhat more |
| Stability & maturity | Long track record, no findings, strong controls | Less often |
The two factors that should move the schedule most are criticality and past NC history — and the second is exactly what a flat schedule ignores. A process that produced three majors last year is telling you, in the clearest possible terms, where to look next; scheduling that does not respond to that signal is not really risk-based at all. This is why closing the loop between findings data and the next plan matters so much.
Auditing everything once a year, regardless of risk?
See how a risk tier becomes an audit calendar — short frequency for critical processes, past-NC history driving the next plan — in a 30-minute demo on your own processes.
Turning risk scores into a schedule
Once processes are scored, group them into a few tiers and assign each tier a frequency. The exact bands are yours to set, but the shape is consistent: a small number of high-risk processes audited often, a larger middle band on a normal cycle, and a stable tail audited lightly.
The mechanics are straightforward in a system that generates audits from a start date, a frequency in days and a count: a Tier A process is simply a plan with a short frequency and a high count, a Tier C process a plan with a long one. The judgement is in the tiering; the calendar generation follows from it. See audit planning and calendar.
Balancing risk with coverage
Risk-based does not mean abandoning the low-risk tail. A certification body still expects the whole management system to be covered over a defined period — typically the certification cycle — so every process must appear on the plan even if only annually. The art is in the distribution: concentrate frequency and your best auditors where risk is high, while guaranteeing baseline coverage everywhere. A schedule that audits the critical processes four times a year but forgets a low-risk one entirely fails clause 9.2 just as surely as a flat rotation wastes effort.
Coverage also has to account for auditor competency: the high-risk, high-frequency tier needs your most qualified, authorised auditors, and the schedule should not assign more audits than your competent pool can genuinely conduct well. Risk-based scheduling and competency planning are two halves of the same decision.
The same auditor-hours, aimed better
A supplier has a fixed number of auditor-days a year and had been spreading them evenly across 30 processes. Re-tiered by risk, six safety- and customer-critical processes — including two with recent majors — move to quarterly audits, eighteen sit on a half-yearly cycle, and six mature processes drop to annual. The total audit count barely changes, but the distribution transforms: the processes most likely to fail now get four looks a year instead of one, the stable tail stops consuming time it did not need, and when a new major appears mid-year, that process is promoted to Tier A for the next cycle automatically. Same effort, far more assurance — and a plan a registrar recognises as genuinely risk-based.
How Fast Audit Software supports risk-based scheduling
Fast Audit Software generates the annual and monthly plan from a start date, an audit frequency in days and a number of audits, so a risk tier translates directly into a schedule: a short frequency and high count for critical processes, a long one for stable ones. Because findings, NC categories and the fresh-versus-repetitive flag are captured against each process, the reporting that should drive re-tiering — past NC history by process and clause — comes from the same system, closing the loop between what you found and where you audit next. Assignment respects auditor competency, so the high-frequency tier gets qualified auditors.
The plan routes for the plant quality head’s approval and appears on the calendar and dashboards, and the whole thing runs on the shared Fast Suite platform, so a major finding that promotes a process can also escalate into Fast Quality’s 8D / CAPA. Indicative INR pricing depends on users and plants — see pricing and confirm your risk model with your certification body. For where scheduling sits in the full lifecycle, start with what audit management software is.
Frequently asked questions
What is risk-based audit scheduling?
Risk-based audit scheduling sets internal-audit frequency according to each process's risk rather than a flat annual rotation. Processes are scored on factors such as criticality, past non-conformance history, recent change, and customer pressure, then grouped into tiers with different frequencies: high-risk processes audited often, a stable middle band on a normal cycle, and mature low-risk processes audited lightly. The aim is to concentrate auditor time where a problem is most likely and most costly, and to reduce it where a process is proven, so the same effort produces far more assurance. ISO 9001:2015 makes this an expectation, not an option.
What does ISO 9001 say about audit frequency?
ISO 9001:2015 clause 9.2 requires that the internal-audit programme take into account the status and importance of the processes concerned and the results of previous audits when deciding frequency and scope. In practice that means auditing more where processes are important or have a history of findings, and less where they are stable and proven — the essence of risk-based thinking that the 2015 revision built into the standard. A flat annual rotation that gives every process the same slot regardless of criticality or past NCs does not reflect that expectation, even though it covers everything.
Which factors should raise audit frequency?
The two factors that should move the schedule most are process criticality — safety, regulatory or customer-critical characteristics and special processes — and past NC history, especially majors or repeats. Recent change or instability, such as new equipment or a design or supplier change, and customer or OEM pressure from complaints or warranty should also raise frequency, while complexity raises it somewhat. Conversely, a long track record with no findings and strong controls justifies auditing less often. Past NC history matters particularly because it is the signal a flat schedule ignores: a process that failed repeatedly last year is telling you where to look next.
Does risk-based scheduling mean skipping low-risk processes?
No. A certification body still expects the whole management system to be covered over a defined period, typically the certification cycle, so every process must appear on the plan even if only annually. Risk-based scheduling is about distribution, not omission: concentrate frequency and your most qualified auditors where risk is high while guaranteeing baseline coverage everywhere. A schedule that audits critical processes four times a year but forgets a low-risk one entirely fails clause 9.2 just as surely as a flat rotation wastes effort. Coverage must also respect auditor competency, so the high-frequency tier gets your best-qualified people.
How does Fast Audit Software implement risk-based scheduling?
Fast Audit Software generates the annual and monthly plan from a start date, an audit frequency in days and a number of audits, so a risk tier translates directly into a schedule — a short frequency and high count for critical processes, a long one for stable ones. Because findings, NC categories and the fresh-versus-repetitive flag are captured against each process, the reporting that should drive re-tiering comes from the same system, closing the loop between what you found and where you audit next. Assignment respects auditor competency so the high-frequency tier gets qualified auditors, and the plan routes for approval and appears on the calendar and dashboards. Indicative INR pricing depends on users and plants.
