The organization shall establish and maintain an overall audit programme that covers both internal and, where applicable, external audits related to the business continuity management system. The audit programme shall be planned and implemented considering the criticality of processes and results from previous audits.
Each audit within the programme shall be conducted objectively against defined scope and criteria. Audit results and findings shall be documented, retained as evidence, and reported to relevant management for review.