<br />
<b>Deprecated</b>:  Non-canonical cast (double) is deprecated, use the (float) cast instead in <b>/var/www/aec.llc/html/blog/wp-content/plugins/wordfence/vendor/wordfence/wf-waf/src/lib/xmlrpc.php</b> on line <b>216</b><br />
<br />
<b>Deprecated</b>:  Non-canonical cast (boolean) is deprecated, use the (bool) cast instead in <b>/var/www/aec.llc/html/blog/wp-content/plugins/wordfence/vendor/wordfence/wf-waf/src/lib/xmlrpc.php</b> on line <b>235</b><br />
<br />
<b>Deprecated</b>:  Non-canonical cast (double) is deprecated, use the (float) cast instead in <b>/var/www/aec.llc/html/blog/wp-content/plugins/wordfence/lib/wfConfig.php</b> on line <b>2096</b><br />
<br />
<b>Deprecated</b>:  Non-canonical cast (binary) is deprecated, use the (string) cast instead in <b>/var/www/aec.llc/html/blog/wp-content/plugins/wordfence/lib/wfMD5BloomFilter.php</b> on line <b>79</b><br />
{"id":91,"date":"2026-04-03T21:40:52","date_gmt":"2026-04-03T21:40:52","guid":{"rendered":"https:\/\/aec.llc\/blog\/?p=91"},"modified":"2026-04-03T21:40:53","modified_gmt":"2026-04-03T21:40:53","slug":"risk-based-internal-audit-programme-iso-9001","status":"publish","type":"post","link":"https:\/\/aec.llc\/blog\/risk-based-internal-audit-programme-iso-9001\/","title":{"rendered":"Your Internal Audit Programme Isn&#8217;t Risk-Based \u2014 And ISO 9001&#8217;s Revision Will Prove It"},"content":{"rendered":"\n<p>A risk-based internal audit programme is what ISO 9001 Clause 9.2.2 has required since 2015 \u2014 and most certified organisations have never built one. Every process audited once a year. Same scope. Same checklist. No documented rationale connecting audit frequency to process risk, corrective action trends, or performance data. The programme satisfies the clause. It produces nothing useful. A genuinely risk-based internal audit programme under ISO 9001 requires something most certified organisations have never built: a documented, data-driven frequency logic that connects audit planning to process performance.<\/p>\n\n\n\n<p>ISO 9001:2015 Clause 9.2.2(b) already requires audit programmes to account for &#8220;the importance of the processes concerned.&#8221; Clause 9.2.2(d) requires them to account for &#8220;the results of previous audits.&#8221; These are not scheduling instructions. They are performance data obligations \u2014 and most certified organisations have never satisfied them in substance.<\/p>\n\n\n\n<p>ISO DIS 9001:2025, published in August 2025, adds an explicit requirement for defined objectives per audit. That addition targets the documented pattern of compliance-mode audits that satisfy clause text but generate no actionable insight. Organisations running fixed-rotation programmes with no per-audit objectives face a structural gap the incoming revision was designed to expose.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Clause 9.2.2 Actually Requires<\/h2>\n\n\n\n<p><a href=\"https:\/\/aec.llc\/certifications\/quality-and-sector-qms\/iso-9001.html\">ISO 9001<\/a>:2015 Clause 9.2.1 establishes the baseline: the organisation shall conduct internal audits at planned intervals to provide information on whether the QMS conforms to requirements and is effectively implemented and maintained. The phrase &#8220;effectively implemented and maintained&#8221; is a performance test. An audit that confirms a procedure exists but does not evaluate whether it works fails this test.<\/p>\n\n\n\n<p>Clause 9.2.2 then specifies what the audit programme must account for. Four inputs are mandatory:<\/p>\n\n\n\n<p>Clause 9.2.2(a) requires the programme to be planned, established, implemented, and maintained \u2014 with &#8220;maintained&#8221; implying documented programme management against performance inputs, not annual date renewal.<\/p>\n\n\n\n<p>Clause 9.2.2(b) requires the programme to consider &#8220;the importance of the processes concerned.&#8221; This is the risk-calibration requirement. A programme that audits document control and production at the same frequency, regardless of nonconformity history or product risk, does not satisfy it. The CB question this clause generates is direct: why is this process audited at this interval? The answer must reference process-specific data.<\/p>\n\n\n\n<p>Clause 9.2.2(d) requires the programme to consider &#8220;the results of previous audits.&#8221; This creates a mandatory feedback loop. If a process produced three minor nonconformities in the previous cycle, the current programme should show increased frequency or scope focus for that process. If it doesn&#8217;t, the feedback loop the clause requires does not exist.<\/p>\n\n\n\n<p>These requirements are not new. They have been in ISO 9001 since the 2015 edition. The gap is not in the standard \u2014 it&#8217;s in enforcement.<\/p>\n\n\n\n<p><em>Clause references reflect mapped standard requirements confirmed via certification body guidance. Verify against the current edition before audit use.<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_34-PM-1024x683.png\" alt=\"ISO 9001 Clause 9.2.2 audit programme inputs for risk-based frequency and feedback loop\" class=\"wp-image-93\" srcset=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_34-PM-1024x683.png 1024w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_34-PM-300x200.png 300w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_34-PM-768x512.png 768w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_34-PM-600x400.png 600w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_34-PM.png 1536w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Why Fixed-Rotation Schedules Persist<\/h2>\n\n\n\n<p>The structural failure has three root causes.<\/p>\n\n\n\n<p>First, path dependency from initial certification. The audit programme designed for Stage 1 and Stage 2 \u2014 typically a uniform annual rotation covering all processes \u2014 becomes the permanent programme. It worked for certification. Nobody revisits it. The schedule is copied forward year after year with updated dates and no other changes.<\/p>\n\n\n\n<p>Second, certification body acceptance patterns. No IAF mandatory document, CB guidance publication, or ISO Auditing Practices Group document defines what evidence constitutes a valid risk-based frequency determination under Clause 9.2.2(b). IAF MD 11:2023 governs CB audit duration calculations \u2014 it does not address <a href=\"https:\/\/aec.llc\/consulting-pages\/internal-audit.html\">internal audit<\/a> programme frequency logic. ISO 19011:2018 Clause 5.4 requires a risk-based approach to audit programme management but provides no minimum evidence threshold for frequency adequacy. Without a prescriptive benchmark, CBs accept a written procedure that cites Clause 9.2.2(b) as conformity evidence. The procedure exists. Whether the logic was applied is not verified.<\/p>\n\n\n\n<p>This is not a CB failure \u2014 it&#8217;s a structural gap in the normative framework. Auditors assess against requirements. Where the requirement says &#8220;take into account the importance of the processes&#8221; but no guidance defines what taking it into account looks like in evidence terms, a documented procedure is a defensible conformity finding.<\/p>\n\n\n\n<p>Third, the absence of programme review culture. Clause 9.2.2(a) requires the programme to be maintained. Most organisations interpret &#8220;maintained&#8221; as &#8220;dates updated.&#8221; A genuine programme review would cross-reference the next cycle&#8217;s schedule against corrective action volumes by process, customer complaint trends, supplier nonconformity data, management review outputs, and any changes to the organisation&#8217;s risk profile. That review almost never happens. The data exists in the management system. The connection to the audit programme does not.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_32-PM-1024x683.png\" alt=\"Process risk profile matrix scoring corrective action volume and KPI trends for audit frequency\" class=\"wp-image-94\" srcset=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_32-PM-1024x683.png 1024w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_32-PM-300x200.png 300w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_32-PM-768x512.png 768w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_32-PM-600x400.png 600w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_32-PM.png 1536w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">What Auditors Actually Find<\/h2>\n\n\n\n<p>The audit pattern is consistent across sources, though no IAF or CB statistical report quantifying nonconformity frequency at Clause 9.2.2 was identified during research.<\/p>\n\n\n\n<p>Programmes show identical audit scope year-on-year with no documented frequency rationale. Audit scheduling runs independently of process KPI data, corrective action volumes, or customer complaint trends. Audit reports restate clause text rather than presenting process performance evidence \u2014 &#8220;the organisation has a procedure for X&#8221; rather than &#8220;the procedure for X was effective at preventing Y in the assessed period.&#8221; Corrective action records and internal audit planning operate in separate systems with no cross-reference.<\/p>\n\n\n\n<p>The most telling indicator is the absence of per-audit objectives. Audit programmes define scope and criteria \u2014 which process, against which clause \u2014 but not what the audit is designed to determine. Without an objective, the audit cannot produce a directed finding. It confirms clause presence. It does not evaluate process effectiveness. The audit function becomes a compliance event, not a performance intelligence tool.<\/p>\n\n\n\n<p>Ideagen&#8217;s 2025 analysis of internal audit programme failures identifies inconsistent data collection across sites and reactive compliance-checking \u2014 rather than proactive quality intelligence \u2014 as the dominant failure pattern in pre-transition programmes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What ISO DIS 9001:2025 Changes<\/h2>\n\n\n\n<p>The draft international standard, published August 2025, adds an explicit requirement at Clause 9.2.2 for defined objectives per audit. Under the current 2015 edition, the programme must define scope and criteria. Under the DIS, it must also define what each audit is specifically designed to determine.<\/p>\n\n\n\n<p>T\u00dcV Austria Hellas confirmed in November 2025 that internal audit quality is a key change driver in the DIS, identifying the need for organisations to confirm audit objectives and review criteria to meet the new requirements. Quality Austria flagged the defined-objectives addition immediately upon DIS publication in August 2025.<\/p>\n\n\n\n<p>None of this is conceptually new. ISO 19011:2018 Clause 5.4 already describes audit programme objectives as a foundational element. What the DIS does is convert a guideline-level expectation into a normative requirement within ISO 9001 itself \u2014 creating an evidence test that CB auditors must assess during transition audits.<\/p>\n\n\n\n<p>The practical consequence is significant. An organisation running a fixed-rotation programme where every audit carries the same implicit objective \u2014 &#8220;verify conformance to Clause X&#8221; \u2014 now has a documentable gap. Identical objectives across all audits are evidence that the programme is not differentiated by process risk. The defined-objectives requirement becomes a probe for frequency logic adequacy: if objectives don&#8217;t vary, the programme wasn&#8217;t built from process performance data.<\/p>\n\n\n\n<p><em>ISO DIS 9001:2025 content reflects the draft international standard published August 2025. Requirements may change before final publication.<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_29-PM-1024x683.png\" alt=\"Fixed-rotation versus risk-based internal audit schedule comparison for ISO 9001\" class=\"wp-image-95\" srcset=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_29-PM-1024x683.png 1024w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_29-PM-300x200.png 300w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_29-PM-768x512.png 768w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_29-PM-600x400.png 600w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_29-PM.png 1536w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">The Coverage Gap That Created This Problem<\/h2>\n\n\n\n<p>The persistence of fixed-rotation programmes is not primarily an organisational failure. It&#8217;s a normative framework gap.<\/p>\n\n\n\n<p>ISO 9001:2015 Clause 9.2.2(b) requires frequency to reflect process importance. It does not define how. ISO 19011:2018 Clause 5.4 provides a risk-based programme management framework. It does not define what evidence threshold separates a defensible frequency from a default one. No IAF mandatory document addresses internal audit programme frequency methodology. No major CB \u2014 BSI, LRQA, SGS, T\u00dcV, Bureau Veritas \u2014 has published guidance defining what data inputs, scoring methodology, or evidence standard constitute an adequate risk-based frequency determination.<\/p>\n\n\n\n<p>The result is a structural enforcement vacuum. A quality manager presenting a procedure that references Clause 9.2.2(b) satisfies most CB audit teams. No risk score, frequency matrix, or performance data record is required. The clause is technically assessed. The intent behind it \u2014 that high-risk processes receive more audit attention than low-risk ones \u2014 is not verified.<\/p>\n\n\n\n<p>ISO DIS 9001:2025&#8217;s defined-objectives requirement partially addresses this gap by creating a per-audit evidence test. But the underlying methodology gap remains: even after the revision, no normative document will define what a risk-based internal audit programme must contain. Organisations that want a defensible programme will need to build the methodology themselves.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Converting a Fixed-Rotation Audit Programme to Risk-Based Design<\/h2>\n\n\n\n<p>The conversion is not a documentation exercise. It requires rebuilding the frequency logic from process performance data.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Build the Process Risk Profile<\/h3>\n\n\n\n<p>Map every process in the audit programme against three data streams: corrective action volume and severity over the previous two cycles, process KPI trends (scrap rates, customer complaints, delivery failures, incident rates \u2014 whatever the process measures), and changes to the process since the last audit (new equipment, personnel changes, scope expansion, supplier changes). Score each process on a simple scale \u2014 high, medium, low. The scoring methodology matters less than the fact that it exists and is documented.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Calibrate Frequency to Risk<\/h3>\n\n\n\n<p>High-risk processes get audited more frequently \u2014 twice per year or quarterly, depending on severity. Medium-risk processes maintain annual frequency. Low-risk processes extend to 18-month or two-year intervals, provided no triggers (nonconformities, complaints, changes) activate an earlier audit. Document the frequency rationale per process. The rationale is the evidence Clause 9.2.2(b) requires.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Define Per-Audit Objectives<\/h3>\n\n\n\n<p>For each scheduled audit, document a specific objective beyond &#8220;verify conformance.&#8221; Objectives should be performance questions: &#8220;Determine whether the revised supplier evaluation process has reduced incoming inspection reject rates since Q2 implementation.&#8221; &#8220;Evaluate whether corrective actions from the March audit have prevented recurrence of the packaging nonconformity pattern.&#8221; &#8220;Assess whether the new production line&#8217;s process controls are producing output within specification at the volumes planned.&#8221; The point is that someone reading the objective knows exactly what the auditor was sent to evaluate. Each objective is unique to the process context and the current risk profile. Identical objectives across audits are a programme design failure.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Build the Feedback Loop<\/h3>\n\n\n\n<p>After each audit cycle, cross-reference results against the risk profile. Processes where audits identified nonconformities or where objectives were not met escalate in frequency or scope for the next cycle. Processes with clean results and stable KPIs may reduce frequency. Document the programme review decision \u2014 this is the evidence trail for Clause 9.2.2(d) and the &#8220;maintained&#8221; requirement in Clause 9.2.2(a). Present the programme review output at management review under Clause 9.3.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Test Against the DIS Requirement<\/h3>\n\n\n\n<p>Before the transition audit, review the programme against the ISO DIS 9001:2025 defined-objectives requirement. Can each scheduled audit in the current cycle show a documented, differentiated objective? Does the objective connect to process performance data or risk profile? If the answer is no for any audit, the programme has a <a href=\"https:\/\/aec.llc\/consulting-pages\/gap-assessment.html\">gap<\/a> the transition auditor will find.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_23-PM-1024x683.png\" alt=\"risk-based internal audit programme ISO 9001\" class=\"wp-image-96\" srcset=\"https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_23-PM-1024x683.png 1024w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_23-PM-300x200.png 300w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_23-PM-768x512.png 768w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_23-PM-600x400.png 600w, https:\/\/aec.llc\/blog\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-Apr-3-2026-02_31_23-PM.png 1536w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">What This Means for the Transition<\/h2>\n\n\n\n<p>The final edition of the revised standard is expected in 2026. The transition period will follow IAF standard practice \u2014 typically three years from publication, though the exact timeline will be confirmed by IAF resolution after final publication. Organisations preparing for the <a href=\"https:\/\/aec.llc\/blog\/iso-9001-clause-4-transition-risk\/\">ISO 9001 Clause 4 transition<\/a> should recognise that Clause 9.2 carries comparable transition exposure.<\/p>\n\n\n\n<p>There is no reason to wait. The current 2015 edition already requires risk-based frequency and feedback-loop integration at Clause 9.2.2. Rebuilding the programme now satisfies the existing requirement more defensibly and eliminates the structural gap before the transition auditor arrives.<\/p>\n\n\n\n<p>The risk is not that the revision introduces something organisations haven&#8217;t seen. The risk is that it creates an evidence test for something they&#8217;ve been failing to do since 2015 \u2014 and their current programme structure cannot produce the evidence the test requires.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Key Takeaway<\/h2>\n\n\n\n<p>A fixed-rotation internal audit programme with no per-audit objectives is not a risk-based programme under ISO 9001:2015 Clause 9.2.2 \u2014 it&#8217;s a scheduling exercise that CBs have accepted in the absence of an enforcement benchmark. ISO DIS 9001:2025 supplies that benchmark by requiring defined objectives per audit. Organisations that rebuild frequency logic from process performance data and document differentiated objectives now will satisfy both the 2015 requirement as intended and the incoming revision. Those that add an &#8220;objectives&#8221; field to an unchanged annual template will find the transition auditor asking the question their programme was never designed to answer. What was this audit trying to determine \u2014 and why was this process audited at this frequency?<\/p>\n\n\n\n<p><em>Clause mapping reflects common audit practice. Verify with your certification body for specific expectations.<\/em><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">About AEC International<\/h2>\n\n\n\n<p>AEC International provides ISO certification, training, and consultancy services at the intersection of quality management, audit programme design, and management system performance. We support organisations across industries in achieving and maintaining ISO certification \u2014 from gap analysis and implementation through audit preparation and continual improvement.<\/p>\n\n\n\n<p>Learn more: <a href=\"https:\/\/aec.llc\/\">www.aec.llc<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<p><strong>Q: What does ISO 9001 Clause 9.2.2 require for audit programme frequency?<\/strong><\/p>\n\n\n\n<p>A: Clause 9.2.2(b) requires the audit programme to account for the importance of the processes concerned, and Clause 9.2.2(d) requires it to consider the results of previous audits. Together, these create an obligation to calibrate audit frequency to process risk and corrective action history \u2014 not run a uniform annual rotation.<\/p>\n\n\n\n<p><strong>Q: What changes does ISO DIS 9001:2025 make to internal audit requirements?<\/strong><\/p>\n\n\n\n<p>A: The draft international standard adds an explicit requirement for defined objectives per audit. Under the current 2015 edition, programmes must define scope and criteria. Under the DIS, each audit must also document what it is specifically designed to determine, creating a per-audit evidence test.<\/p>\n\n\n\n<p><strong>Q: How do I convert a fixed-rotation audit schedule to a risk-based programme?<\/strong><\/p>\n\n\n\n<p>A: Build a process risk profile using corrective action data, KPI trends, and process change history. Score each process, calibrate frequency to risk level, define unique per-audit objectives tied to process performance questions, and build a documented feedback loop that adjusts frequency after each cycle.<\/p>\n\n\n\n<p><strong>Q: Will certification bodies reject fixed-rotation audit programmes during transition?<\/strong><\/p>\n\n\n\n<p>A: The DIS defined-objectives requirement creates an evidence test that CB auditors must assess. A programme with identical objectives across all audits provides documentable evidence that frequency was not differentiated by process risk \u2014 which is the gap the revision was designed to expose.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most ISO 9001 audit programmes run fixed-rotation schedules with no risk-based frequency rationale. ISO DIS 9001:2025 adds defined per-audit objectives \u2014 exposing the structural gap. Here&#8217;s how to rebuild before transition.<\/p>\n","protected":false},"author":1,"featured_media":92,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[26,36,13,12],"class_list":["post-91","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-audit-preparation","tag-certification-process","tag-corrective-action","tag-internal-audit","tag-risk-management"],"reading_time":"10 min read","_links":{"self":[{"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/posts\/91","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/comments?post=91"}],"version-history":[{"count":2,"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/posts\/91\/revisions"}],"predecessor-version":[{"id":98,"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/posts\/91\/revisions\/98"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/media\/92"}],"wp:attachment":[{"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/media?parent=91"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/categories?post=91"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aec.llc\/blog\/wp-json\/wp\/v2\/tags?post=91"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}