Your Frequency Criteria Are Not a Mechanism
Most audit procedures already say that audit frequency and depth get revisited against defined criteria. Far fewer programs can produce a decision that used them. That gap is not carelessness, and it is usually not disagreement about whether the criteria are right. It is what happens when a criterion is written in one place and the work happens in another.
Why doesn't audit frequency change even when the criteria allow it?
Because the criteria are stated somewhere nobody is working from at the moment the decision would be made.
I run into this while auditing. The procedure describes conditions under which the schedule moves — performance against objectives, the pattern of findings, changes in the operation. Then I ask about previous audit programs and compare them against the current one, and nothing has shifted. Nobody is hiding anything. The step is read as something for consideration by someone else, at some point, and it never resolves to a person or a moment.
That is what makes a criterion boilerplate, and boilerplate is not a quality of the writing. A criterion is boilerplate when nobody expects it to produce hard evidence. The same sentence, in a program that expects evidence from it, is a working control.
What makes a documented criterion actually function?
Something has to carry it into execution. In practice there are three routes, and one is usually enough.
It is structured into the artifact people work from, so the step arrives at the person doing the work.
It is covered in training, so the person carries it without being prompted.
It is professionally expected, so the person would be surprised not to do it.
Where any of those is in place, you get evidence that the step happened. Where the procedure genuinely does drive execution, you will see it in the records, and consistent outputs arriving through professional habit are a fine result. Nobody needs a new form for that.
What does not work is a criterion with none of the three behind it — no communication, no training, no structuring, no evidencing, no monitoring. Evidence has to demonstrate that requirements are satisfied. Consistent outputs are what demonstrate that a process is in control, and documented information placed along the steps of a process is a risk control for that consistency. Training is a control too, and documentation is one of its key inputs. Where a documented requirement is not producing consistency and is not satisfying anything, its presence is the thing to question.
Where should audit frequency criteria live?
A procedure is written to train from and to reference — at onboarding, during process reviews, when somebody needs to know how the process is supposed to work. That is a real job and procedures do it well. But unless the document is a work instruction, it is not open in front of anyone during execution.
The forms are. Most audit programs already carry forms for the stages of the audit lifecycle: planning, notification, checklists, findings, reports, follow-up. Those are what an auditor engages with, and they are where the key elements of the procedure should be reproduced rather than referenced. In many cases the form should hold the criteria and the instructions outright. This is the ordinary distinction between a procedure and a work instruction applied to a step people keep leaving out.
The gain is not compliance theater. It is that the operator is much less likely to skip the step, and that you have reduced what the auditor has to hold in their mind. Sufficiency and consistency then track how much instruction sits in the form, the procedure, and the training, and how clearly expectations were set. A field is a floor, not a guarantee.
Who decides whether the audit schedule changes?
Not the auditor alone, and this is where a well-intentioned version of the fix goes wrong.
Deciding that an element's condition warrants a longer interval is a program-level judgment. It weighs one element against the others, against what changed in the business this year, and against where auditor capacity is short. An auditor sees one element on one day and is not positioned to make that call.
So the step is a handoff, and the criteria sit at the handoff — at one end at minimum, at both where consensus puts them there. The auditor's job is to supply what the decision needs, and much of that is already structured in the report: the number of findings, their classification, their severity, and the condition of the process as observed. The program manager's job is to run that against the broader program context and its criteria, and reach an informed conclusion. Then approval and action follow — updating the internal audit schedule, and communicating the change and its implications to the people it lands on, the auditee and the assigned auditor among them.
The conclusion should be documented, even if it is one cell in a table row.
What does the determination step actually buy?
Be careful here, because the honest answer is narrower than the one people want.
It does not shrink your schedule. Frequency comes down through system and process improvement — the operation gets better, and the evidence of that shows up at a scheduled audit precisely because nothing triggered an audit in between. A clean calendar audit is where a condition satisfying reduction criteria arrives. The determination step is what notices it and acts on it. Anyone selling the step as a route to auditing less has the causation backwards.
What you get instead is concrete. Audit resource moves toward the elements that need it, rather than sitting evenly across an operation where exposure is not. On the triggered side, problems resolve faster and more completely, because the audit is aimed at the solution, and you get layered assurance that the problem closed — for some organizations a contractual or regulatory expectation rather than a discretionary practice. And the reasoning transfers.
That last one is the durable benefit. A conclusion is derivable from findings, in principle. In practice it erodes the further it travels from the person who reached it, and it erodes in your own memory too. A successor reading four years of corrective action records and audit findings will infer a set of decisions, and it will not be the set you made. Either your method is worth carrying forward, in which case hand it over, or it is not, in which case it does not matter how the next person does it. Most program owners do not actually believe the second one.
Is a static audit schedule a problem?
No. An organization can run a stable annual program that does not adjust intervals from audit results, and that can be an acceptable design — particularly at smaller scale or in a stable operation.
This is only a finding against the process as defined. If your procedure describes a dynamic schedule and your records show a schedule that has never moved, that gap is the issue, and an external reviewer can see it as easily as you can. If your procedure describes a fixed annual cycle and your schedule is a fixed annual cycle, there is nothing here to fix.
There is also a middle route worth knowing about. If you want the practice available without the obligation, write the conclusion as optional. Then a record without one is not a departure from your own process. Limiting exposure while keeping a discretionary practice is a drafting decision, and it costs nothing.
And the governing rule: build this only where you think it delivers value and improvement. Where there is inherent resistance to it, do not.
How do you check whether your own program does this?
Start with the audit process itself. Is the determination of impact to the program and schedule defined at all, and where does the process say it gets recorded? That tells you what to look for and where it should be, instead of guessing at an artifact.
Then go to the individual audit reports and conclusions — or the schedule notes, which is where many programs actually keep this — and read two things separately. Whether the step is present, which is a count. And whether it is producing value for the program, which is a judgment and the harder read. Value belongs to the organization: is the program surfacing issues and opportunities, and is there evidence, objective or subjective, that it is delivering.
If you own the program you have all of it available — the program definition, the schedule, auditor assignments, findings, notes, and reports. The comparison that returns a fact fastest is the procedure against the execution artifact: find the clause stating your frequency criteria, then look at the form or report where the process says the determination is recorded, and see whether the criteria appear anywhere near it. If they live only in the procedure, the step is being left to whoever remembers it exists.
Where the picture is unclear, audit program design and auditor development are the two places this usually gets settled, and neither is a documentation exercise. It is a question about system architecture and governance — where a decision lives, who makes it, and what it leaves behind.
Frequently asked questions
Does documenting the conclusion create a conformance obligation we didn't have?
Only if you write it as mandatory. If you want the practice without committing to it, state in the procedure that the conclusion is recorded at the program manager's discretion. A record without one is then consistent with your process. The exposure people worry about here comes from the drafting, not from the practice.
What should the record say when nothing changes?
As little as possible. Documenting reasoning is for the unexpected or non-normal decision. A status quo entry should be low-lift — no change to schedule, or the equivalent — and it should take seconds. The record exists to carry the call that would not be obvious later, not to generate volume.
Doesn't this just mean we end up auditing less?
Not on its own, and that is not the objective. The step does not improve anything; it registers improvement that already happened and redirects effort accordingly. Sometimes that means a longer interval on one element. Sometimes it means a shorter one, because the audit found the process still moving.
Should the auditor make the determination, or the program manager?
The auditor supplies the information the decision needs, and can be involved in the call or not at all beyond reporting the relevant context. The program manager holds the decision, because only they see the whole program. What matters is that the handoff is defined and the criteria sit at it, rather than the step existing in a procedure with no owner at either end.