Audit sampling for compliance audits: how many samples is enough?
Sample sizes for testing controls depend mainly on how often the control runs. Here are the sizes auditors commonly use, and how to handle an exception.
The auditor's side: sampling, writing findings, remote audits and certification body impartiality.
Sample sizes for testing controls depend mainly on how often the control runs. Here are the sizes auditors commonly use, and how to handle an exception.
Whether a finding is major or minor decides whether you get certified on schedule. The difference is about the management system, not the size of the mistake.
Every ISO 9001:2015 certificate must move to the 2026 edition by 30 September 2029. For certification bodies that means three years of transition audits to schedule, staff and evidence.
Under SEBI's Cybersecurity and Cyber Resilience Framework, regulated entities need cyber audits by CERT-In empanelled auditors, half-yearly or yearly depending on their category.