56% of ISO 19011:2018 you already have
ISO 55001 already covers about 56% of ISO 19011:2018, leaving
21 of 48 controls as genuinely new work.
Already covered 0
Likely covered 27
New work 21
No control in ISO 55001
maps directly to one in ISO 19011:2018. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in ISO 55001 reaches these. This is the list to scope.
5.2Establishing audit programme objectives
5.5.3Selecting and determining audit methods
5.5.4Selecting audit team members
5.5.5Assigning responsibility for an individual audit to the audit team leader
6.3Preparing audit activities
6.3.1Performing review of documented information
6.3.4Preparing documented information for audit
6.4Conducting audit activities
6.4.3Conducting opening meeting
6.4.4Communicating during audit
6.4.5Audit information availability and access
6.4.6Reviewing documented information while conducting audit
6.4.8Generating audit findings
6.5.1Preparing audit report
6.5.2Distributing audit report
6.7Conducting audit follow-up
7.2.3Knowledge and skills
7.2.4Achieving auditor competence
7.2.5Achieving audit team leader competence
7.3Establishing auditor evaluation criteria
Show the 27 you already have
5.3Determining and evaluating audit programme risks and opportunities
5.4Establishing the audit programme
5.4.1Roles and responsibilities of the individual(s) managing the audit programme
5.4.2Competence of individual(s) managing audit programme
5.4.3Establishing extent of audit programme
5.4.4Determining audit programme resources
5.5Implementing audit programme
5.5.2Defining the objectives, scope and criteria for an individual audit
5.5.6Managing audit programme results
5.5.7Managing and maintaining audit programme records
5.6Monitoring audit programme
5.7Reviewing and improving audit programme
6.2.2Establishing contact with auditee
6.2.3Determining feasibility of audit
6.3.3Assigning work to audit team
6.4.10Conducting closing meeting
6.4.2Assigning roles and responsibilities of guides and observers
6.4.7Collecting and verifying information
6.4.9Determining audit conclusions
6.5Preparing and distributing audit report
7.2Determining auditor competence
7.4Selecting appropriate auditor evaluation method
7.5Conducting auditor evaluation
7.6Maintaining and improving auditor competence
How this is calculated
Already covered means a mapping runs from a control in ISO 55001 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition