ISO 19011 maturity · Internal audit guidelines
An internal audit programme measured against ISO 19011, with the trajectory to professionalise it.
9 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 9 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
ISO 19011 maturity · Internal audit guidelines
9 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One ISO 19011:2018 assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 9 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
It is this mechanism (a level, a level above, and the action linking the two) that turns a finding into a trajectory.
Is internal auditor competence defined, evaluated and maintained?
- N1
No competence criteria defined. Auditors are appointed based on availability.
- N2
Most auditors have completed initial training, but no written criteria or evaluation confirm their suitability.
- N3
Competence criteria are formalised by audit type and applied when appointing auditors. Training is tracked.
- N4
Each auditor is evaluated periodically, including through field observation, and an individual development plan follows.
- N5
Competence criteria are revised as audited frameworks and programme findings evolve, with documented tracking of revisions.
Action to move from L2 to L3
Formalise a competence profile for each audit type (framework, training, minimum experience, sector knowledge), have it validated by the programme manager and apply it when building teams for the next annual plan.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurementon ISO 19011.
What this framework covers
ISO 19011:2018 does not set requirements: it provides guidelines for auditing management systems, whatever framework is being audited. It covers three distinct areas: audit principles (integrity, fair presentation, independence, evidence-based approach), managing an audit programme (objectives, programme risks and opportunities, resources, monitoring, review), and conducting audits, from initiation through to closing actions. It also addresses auditor competence and how to evaluate it.
In practice, the difficulty is not conducting an audit, it is sustaining a programme. Is the annual plan built from the organisation’s risks and priorities, or simply rolled over from one year to the next? Are internal auditors genuinely independent from the activities they audit, or is scope effectively self-audited? Do findings lead to actions whose effectiveness is verified, or does the report close the matter?
The 2018 version introduced a shift that is often poorly embedded: the risk-based approach to auditing. The auditor is no longer there to work through a checklist clause by clause, but to direct audit effort towards areas where the stakes are real, taking the organisation’s context into account. Another common confusion: ISO 19011 concerns the audit of management systems. It does not replace the internal financial audit framework, and it does not apply as-is to certification bodies, which fall under ISO/IEC 17021.
An audit concludes with a nonconformity or a conformity, for a given scope, at a given date. The maturity assessment asks a different question: what level of control does your audit function itself sit at, and what specific action moves it to the next level. For a federation or cooperative group auditing its members or sites, this level-based reading also allows entities to be compared against each other and progress to be tracked over time.
In Datamensio, the framework is ready to use and you can adapt it. The AI adjusts themes, rephrases questions to match your vocabulary and refines levels, or builds a variant from your audit charter and existing procedures.
Reference standard: ISO 19011:2018
The themes assessed
Audit principles
Ownership of the seven principles: integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, risk-based approach.
Establishing the audit programme
Programme objectives, scope covered, consideration of risks and opportunities, prioritisation of sites and processes, alignment with regulatory and contractual obligations.
Resources and roles
Appointment of the programme manager, effective auditor availability, budget and time allocated, tools and support, use of external auditors.
Auditor competence
Defined competence criteria, initial and ongoing training, audit experience, periodic auditor evaluation, maintenance and development of competence, knowledge of the audited sector.
Audit preparation and conduct
Initiation, prior document review, individual audit plan, allocation of work within the team, conducting interviews, gathering and verifying information.
Findings and audit report
Classification of findings, traceability of evidence, closing meeting, report timing and content, distinction between finding, improvement opportunity and recommendation.
Action follow-up
Assignment of corrective actions, deadlines, root cause analysis, effectiveness verification, formal closure, escalation of recurring actions.
Programme monitoring and review
Completion and quality indicators, tracking of plan coverage, periodic programme review, feedback from auditees.
Improving the audit function
Updating methods and checklists, harmonisation between auditors, cross-cutting use of findings, comparison over time and between entities.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Is ISO 19011 certifiable?
No. It is a guidance document, with no binding requirements, so there is no organisational certification. It is, however, routinely used by certification auditors to assess the strength of your internal audit function, itself required by most management system standards.
What is the difference between this assessment and an internal audit?
An internal audit examines a process or site against a framework and concludes with findings. This assessment looks at your audit function itself: programme, competence, findings, action follow-up. It places each theme on a maturity scale and indicates the action that drives progress.
How long does the assessment take?
The short version can be completed in one working session. The full version, run collaboratively with the programme manager, auditors and process owners, typically spans one to two weeks, with most of the time spent gathering evidence.
Can the framework be adapted to our audit charter?
Yes. Themes, questions and levels can all be modified, and the AI can build a variant from your audit charter, procedures and existing checklists. The framework remains under your control.
Can several entities or members be compared?
Yes. The same framework can be deployed across several sites, subsidiaries or member cooperatives, with a score per theme and a benchmark between entities and against previous campaigns. The AI groups converging gaps into a consolidated roadmap.
Do you need to be a qualified auditor to answer?
No. The questions concern how the programme is organised and the practices observed, not the audit technique for a particular framework. A quality or compliance manager can answer, and the collaborative mode allows competence questions to be assigned to the programme manager.
Does this assessment prepare for a certification audit?
It prepares the part of the file covering internal audit, often one of the weak points raised at certification. It issues no certificate: Datamensio measures maturity and produces the action plan, the certification body validates.
Where is the data hosted?
In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.




