Audit programme & calendar
Plan and maintain your internal-audit programme, the ISO 27001 / 9001 Clause 9.2.2 requirement, on a cadence, with a calendar that shows what’s due.
| Audit | Type | Lead | Window | Status |
|---|---|---|---|---|
| Access management review | Internal | K. Adeyemi | Mar 2026 | Complete |
| Vendor due diligence | Internal | GRC | Apr 2026 | Complete |
| Business continuity test | Internal | Ops | May 2026 | In progress |
| Surveillance audit | External | Auditor | Jun 2026 | Planned |
ISO 27001 and 9001 Clause 9.2.2 ask you to plan, establish, and maintain an audit programme, not just run the occasional audit, but a schedule that considers the importance of your processes and the results of prior audits. Keel gives you that programme: create a plan for the period, schedule audits by process or area with an assigned auditor and a planned date, set a cadence so recurring audits maintain themselves, and watch an upcoming-and-overdue calendar so nothing slips. When it’s time, launch a scheduled audit into a full internal audit in one click.
A spreadsheet audit calendar nobody maintains
Most teams keep the audit schedule in a spreadsheet that’s accurate in January and forgotten by April: no cadence, no reminders, no link to the audits actually performed. Then the certification auditor asks for the programme and its results, and it’s a scramble.
What audit programme & calendar does
A real programme, not one-off audits
Group your planned audits under a programme with a period and objectives, the Clause 9.2.2 “audit programme” the standard asks you to maintain, in one place.
Schedule by process or area
Add each planned audit with its area, framework, scope, assigned auditor, and planned date, so the year’s coverage is explicit and owned.
Cadence that maintains itself
Set a recurrence (e.g. every 12 months) and Keel rolls the next occurrence forward automatically when you launch one. Your annual plan doesn’t need re-typing each cycle.
Upcoming & overdue calendar
A single view across every programme shows what’s due next, flagging overdue and due-soon audits so the schedule stays live.
One-click launch to a full audit
Launch a scheduled audit and it becomes a full internal audit, pre-filled with the area, framework, and auditor, and linked back to the schedule, so planning and execution stay connected.
Why it matters
- Show an auditor a maintained Clause 9.2.2 audit programme, not a stale spreadsheet
- Never miss a scheduled audit: overdue and due-soon are flagged
- Let recurring audits roll forward automatically instead of re-planning each year
- Go from “scheduled” to a working internal audit in one click
Get audit-ready, and prove it
Audit programme & calendar is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.
Start freeFrequently asked questions
What does ISO 27001 / 9001 Clause 9.2.2 require?
That you plan, establish, implement, and maintain an audit programme, including frequency, methods, responsibilities, and reporting, taking into account the importance of the processes and the results of previous audits. Keel’s programme captures the schedule, cadence, and coverage that requirement asks for.
How is this different from the Internal audits module?
The audit programme is the plan: what will be audited, when, by whom, and how often. The Internal audits module is where you run an individual audit against a framework’s clauses and record findings. Launching a scheduled audit creates a linked internal audit, so the two stay connected.
How does the cadence work?
Set a recurrence in months on a scheduled audit. When you launch that audit, Keel automatically creates the next occurrence with its planned date rolled forward by the cadence, so a “every 12 months” audit keeps reappearing without manual re-entry.
Is it included in my plan?
Yes. The audit programme is available to every workspace. Clause 9.2 is shared by ISO 27001 and 9001, so it’s part of the core platform, not an add-on.
Related features: Internal audits · Nonconformities & CAPA · Management reviews
Works with: ISO/IEC 27001