Implementing ISO standards? Don't overlook GDPR. Try Cookiebot free →

ISO 19011

Guidelines for Auditing Management Systems

Management Systems Published: 2026

ISO 19011:2026 at a glance

Current edition
ISO 19011:2026 - Guidelines for auditing management systems
Published
2026
Status
Published
Type of standard
Guidance
Certifiable
No — used for reference and implementation, not certification
Previous edition
ISO 19011:2018
Official ISO page
View ISO 19011:2026 on iso.org
Last verified

Overview

The reference guidance for auditing management systems — audit principles, managing an audit programme, conducting audits, and evaluating auditor competence. The fourth edition, ISO 19011:2026, replaces ISO 19011:2018.

ISO 19011:2026, Guidelines for auditing management systems, is the fourth edition and cancels and replaces ISO 19011:2018, which it technically revised. It is the standard auditors use for internal (first-party) audits and for supplier (second-party) audits of any management system — quality, environmental, occupational health and safety, information security, energy, business continuity and others.

Its content is organised around four things: the principles of auditing; managing an audit programme; conducting an audit; and the competence and evaluation of auditors. An extensive annex gives practical guidance on audit methods and on auditing particular subjects, such as context, leadership, risk, compliance obligations and supply chains.

The audit principles — integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach and risk-based approach — carry over from the previous edition. They are what makes an audit an audit rather than an inspection: conclusions must follow from verifiable evidence, the auditor must be independent of the activity being audited, and the audit programme must be shaped by risk and by the significance of the processes involved.

The 2026 edition's most visible change is expanded guidance on remote and hybrid auditing. The annex now deals directly with remote audit methods and with auditing virtual locations, including how to judge the sufficiency of electronic evidence and how to plan an audit that mixes on-site and remote activity. Auditor competence has been updated in the same direction: competence in digital tools, judgement about electronic evidence, and information security awareness are now treated as part of the auditor's skill set.

The edition also sharpens the distinction between audit programme management, which is strategic, and conducting an individual audit, which is operational, and gives more attention to the design step in between. Programme managers are expected to think deliberately about objectives, scope, methods and resources before assigning audits, rather than simply scheduling them against a calendar.

ISO 19011 is guidance and is not certifiable. It is also not the standard used for accredited certification audits: requirements for bodies providing audit and certification of management systems are in ISO/IEC 17021-1, and ISO 19011 is intended to complement it. Because it is guidance, the 2026 edition takes effect on publication and there is no transition period; organizations update their audit procedures, auditor competence criteria and training material at their own pace.

Purpose

To give guidance on auditing management systems, covering the principles of auditing, managing an audit programme, conducting management system audits, and evaluating the competence of the individuals involved in the audit process.

Key Benefits

  • Provides a single, recognised method for internal and supplier audits of any management system
  • Establishes audit principles that keep conclusions evidence-based and defensible
  • Gives practical guidance on planning and resourcing an audit programme by risk
  • Covers remote and hybrid auditing, including auditing virtual locations and electronic evidence
  • Defines competence criteria and evaluation methods for auditors and audit team leaders
  • Supports integrated audits covering several management system standards at once
  • Improves the quality and consistency of internal audit findings feeding management review
  • Complements ISO/IEC 17021-1 for organizations that also undergo certification audits

Key Requirements

  • Guidance only — ISO 19011 contains recommendations, not auditable requirements
  • Apply the audit principles: integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach and risk-based approach
  • Establish audit programme objectives and determine and evaluate programme risks and opportunities
  • Determine the extent, resources, methods and criteria of the audit programme
  • Design individual audits: objectives, scope, criteria, methods and team composition
  • Initiate the audit, prepare audit activities and conduct the opening meeting
  • Collect and verify information, generate findings and prepare audit conclusions
  • Conduct the closing meeting, distribute the audit report and complete the audit
  • Follow up on audit findings and corrective actions where required
  • Determine auditor competence criteria and evaluate, maintain and improve auditor competence
  • Address remote and hybrid audit methods, virtual locations and electronic evidence
  • Monitor, review and improve the audit programme

Who Needs This Standard?

Internal auditors and audit programme managers in any organization operating a management system; second-party auditors assessing suppliers; audit team leaders and lead auditor trainers; quality, environmental, safety and information security managers responsible for the internal audit schedule; and consultants who design audit programmes. Certification body auditors use it as complementary guidance alongside ISO/IEC 17021-1.

Where to get ISO 19011

The full text of ISO 19011 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 19011 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.

Get our free implementation resources

Send me the implementation checklist for ISO 19011, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.

We'll only email you about this standard. Unsubscribe anytime.

Looking to get certified?

You cannot be certified to ISO 19011 — it is guidance, and no accredited scheme exists for it. The closest standards you can certify against are ISO 9001 (Quality Management Systems), ISO 14001 (Environmental Management Systems), ISO 45001 (Occupational Health and Safety Management Systems), ISO 27001 (Information Security Management Systems) and ISO 22000 (Food Safety Management Systems).

If that is the direction you are heading, tell us what stage you are at and we will put you in touch with people who work with them. Free and no obligation.

Get help with certification

In a hurry? You can also compare quotes from verified providers on CertBetter (affiliate link — we earn a commission, and it stays free for you).

Related Standards