Back to InsightsAuditing

    ISO 19011:2026 Auditing Guidelines: Complete UK Guide

    A practical UK guide to ISO 19011:2026 — the seven audit principles, what changed in the 2026 revision, audit programme planning, remote and hybrid auditing, and auditor competence.

    By UniCert Certification LtdPublished Last updated

    ISO 19011:2026 provides internationally recognised guidance for auditing management systems, managing audit programmes, conducting audits, and evaluating auditor competence. It is not a certifiable management system standard — organisations do not become "certified to ISO 19011". Internal audit teams, second-party auditors, consultants, and management professionals use it to make audits more consistent, credible, and useful. This UK guide summarises the seven audit principles, what changed in the 2026 revision, how to plan an audit programme, and how remote and hybrid auditing should be approached in practice. For related training pathways, see our ISO training programmes.

    Two auditors reviewing tablet data and a process map on a factory floor in a UK manufacturing environment.

    ISO 19011:2026 at a Glance

    • ISO 19011:2026 is guidance, not a certifiable standard. Organisations cannot obtain "ISO 19011 certification".
    • It is the fourth edition and replaces the withdrawn ISO 19011:2018.
    • Published in May 2026 by ISO (see the official ISO 19011 page).
    • Scope: auditing principles, audit programme management, conducting audits, and evaluating auditor competence.
    • The 2026 revision gives increased attention to technology, digitalisation, virtual environments, and risk analysis and mitigation (per the ISO/TC 176 news update).

    Table of Contents

    What Are the ISO 19011 Guidelines?

    ISO 19011 is an internationally recognised guidance document that describes how to plan, conduct, report, and improve audits of management systems. It applies across standards such as ISO 9001, ISO 14001, ISO/IEC 27001, and ISO 45001, but does not itself define requirements for a management system.

    Open compliance manual, magnifying glass and notebook arranged on a concrete desk for audit planning.

    Using ISO 19011 does not, by itself, lead to certification. Certification against a specific management system standard (for example ISO 9001) is delivered by an independent certification body under its accreditation scope. ISO 19011 supports first-party (internal) and second-party (supplier/customer) audits, and provides useful reference material for other audit contexts. When preparing for an external assessment, our companion piece How to Prepare for an ISO 9001 Audit in the UK shows how internal audit practice supports certification readiness.

    What Are the Seven Principles of Auditing Under ISO 19011?

    ISO 19011 defines seven principles that underpin trustworthy audit findings: integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, and risk-based approach. Together they help ensure audits produce objective, verifiable, and useful conclusions.

    Seven stacked balancing stones representing the seven principles of auditing.

    The seven principles

    1. Integrity — auditors act honestly, ethically, and only accept assignments where they are competent.
    2. Fair presentation — reports reflect audit activities truthfully, including disagreements and unresolved issues.
    3. Due professional care — auditors apply reasonable diligence and judgement proportionate to the task.
    4. Confidentiality — information obtained during audits is protected and not misused.
    5. Independence — auditors remain free from bias and conflicts of interest as far as reasonably possible.
    6. Evidence-based approach — conclusions are supported by verifiable evidence drawn from appropriate sampling.
    7. Risk-based approach — planning and execution consider the risks and opportunities relevant to the audit objectives.

    What each principle means in practice

    PrincipleWhat it means in practiceExample audit behaviour
    IntegrityHonest, ethical conduct within your competenceDeclining an audit outside your technical scope
    Fair presentationReports reflect reality, not preferencesRecording an unresolved disagreement in the report
    Due professional careDiligence proportionate to riskExtending sampling where evidence is inconsistent
    ConfidentialityProtect audit informationStoring evidence in access-controlled systems
    IndependenceFreedom from conflicts of interestNot auditing a process you personally manage
    Evidence-based approachFindings supported by verifiable dataReferencing records, interviews, and observations
    Risk-based approachFocus effort where it matters mostPrioritising higher-risk processes and sites

    What Changed in ISO 19011:2026?

    ISO 19011:2026 is the fourth edition and replaces the withdrawn 2018 edition. Unlike a revision to a certifiable management system standard, ISO 19011:2026 does not create a certification transition deadline. Organisations can nevertheless review their existing audit programmes against the updated guidance and decide how and when to incorporate relevant changes. According to the official ISO page and the ISO/TC 176 committee news, the revision places increased attention on technology, digitalisation, virtual environments, and risk analysis and mitigation.

    Laptop showing a remote audit workspace with blue dashboard panels in a home office.

    The table below summarises the areas of emphasis and the practical implications for UK audit teams. Where an item is an operational interpretation rather than an explicit clause change, it is labelled as a practical implication.

    AreaPrevious context (2018)2026 emphasisPractical action
    Technology & digitalisationTechnology and ICT-supported audit methods were already addressedTechnology and digitalisation receive greater prominence across the audit lifecycleReview digital audit tools, evidence-handling methods, security controls, and auditor competence
    Virtual environmentsRemote audit methods and virtual locations were already addressed in the guidanceGreater attention is given to auditing in virtual and technology-enabled environmentsDocument when remote, on-site, or hybrid methods are appropriate and why
    Risk analysis & mitigationRisk-based approach introducedReinforced across programme and audit levelDocument programme-level and audit-level risk considerations
    Auditor competence (practical implication)Traditional audit skills with some ICT awarenessGreater relevance of competence for handling evidence in digital and virtual environmentsExtend competence criteria and evaluation records
    Information handling (practical implication)General confidentiality expectationsGreater relevance of information security across audit activitiesAlign with the organisation's information security controls

    Full clause-by-clause detail is only available in the published ISO document; this guide summarises the emphasis in original language and does not reproduce protected ISO text.

    How Does ISO 19011 Apply to UK Internal Audits?

    ISO 19011:2026 provides a structured, internationally recognised way for UK organisations to plan and conduct internal management system audits. It is not UK legislation and does not replace legal, regulatory, contractual, or sector-specific audit requirements — for example, it does not by itself demonstrate compliance with HSE requirements.

    Female quality inspector measuring a machined cylinder with a caliper on a factory floor.

    A credible internal audit programme aligned with ISO 19011 can support the effective maintenance of certifiable standards such as ISO 9001, ISO 14001, ISO/IEC 27001, and ISO 45001. Findings graded as nonconformities should be addressed through documented corrective action — our guide Can You Fail an ISO Audit in the UK? explains how minor and major findings differ. A credible internal audit programme may also support the effective maintenance of the management system certifications requested in some public and private procurement processes, but ISO 19011 itself is not a tender qualification.

    How Do You Build an Audit Programme Under ISO 19011:2026?

    An audit programme is the overall set of audits planned for a specific time frame and directed towards defined objectives. An individual audit plan describes the arrangements for a single audit within that programme. Building an effective programme is a repeatable, evidence-based process.

    Suggested steps:

    1. Define audit programme objectives aligned with organisational priorities.
    2. Determine the relevant scope, criteria, locations, functions, and processes.
    3. Identify audit programme risks and opportunities.
    4. Prioritise significant, higher-risk, and higher-impact activities.
    5. Select competent and impartial auditors.
    6. Determine audit frequency and appropriate methods (on-site, remote, hybrid).
    7. Prepare individual audit plans for each audit.
    8. Collect and evaluate verifiable evidence during the audit.
    9. Report findings and conclusions clearly and traceably.
    10. Assign and monitor corrective actions where applicable.
    11. Review audit programme performance against its objectives.
    12. Continually improve the programme based on results and lessons learned.

    Illustrative Example: A Risk-Based Internal Audit Programme

    The following is an illustrative example, not a UniCert client case study. The company, processes, and priorities are fictional and shown only to demonstrate how audit frequency and methods may be chosen from risk rather than applied uniformly. Your own programme must be built from your organisation's context, risks, and applicable standards.

    Consider a fictional UK precision engineering company with a single manufacturing site and one small satellite office. Its integrated management system covers ISO 9001, ISO 14001, and ISO 45001. Rather than auditing every process on the same annual cycle, the audit programme owner uses ISO 19011 principles to prioritise effort where risk and previous performance suggest it is most needed.

    ProcessRisk considerationsPrevious performanceSuggested audit prioritySuitable methodReason
    Production controlDirect impact on product conformityTwo minor findings last cycleHighOn-siteLive observation of controls and operator practice is essential
    CalibrationMeasurement accuracy is safety- and quality-criticalStable, no recent findingsHighOn-sitePhysical verification of equipment status and records
    Supplier controlRepeated hypothetical supplier-related nonconformitiesRecurring issues over two cyclesHighHybridRemote record review plus targeted on-site visits
    Health & safety operational controlsWorker safety and legal duty of careImproving trendMedium–HighOn-siteDirect observation of behaviours, PPE, and controls
    Document controlLow direct risk when the system is matureStableMediumRemoteEvidence is largely digital and centrally accessible
    Human resourcesLimited product/safety impact; supports competenceStable, no recurring findingsLowerRemote / interview-basedRecord sampling and short interviews are sufficient

    The programme owner records why each priority and method was chosen, and reviews the schedule again after each cycle. This approach reflects ISO 19011's risk-based approach and evidence-based approach without implying that every organisation should follow the same pattern.

    How Should Remote and Hybrid Audits Be Planned?

    Remote and hybrid audits are an accepted option under ISO 19011:2026, but they are not a default requirement. The choice of method should fit the audit objective, scope, criteria, and risks — some activities still require physical observation.

    Key planning considerations:

    • Technology readiness of the auditee (connectivity, tools, endpoint access).
    • Access to relevant records, systems, and process data.
    • Reliability, integrity, and traceability of remote evidence.
    • Confidentiality and data security when sharing screens or files.
    • Suitability for interviews, virtual site tours, and live process observation.
    • Recording restrictions and consent for any captured material.
    • Contingency arrangements for connectivity or platform failure.
    SituationOn-site suitabilityRemote suitabilityHybrid suitabilityKey consideration
    Document and record reviewMediumHighHighSecure access to controlled documents
    Interviews with process ownersHighHighHighInterview environment and confidentiality
    Physical process observationHighLowMediumAbility to observe real conditions
    Field / site inspectionsHighLowMediumSafety, sampling, and physical verification
    Remote / branch officesMediumHighHighConsistency of evidence across sites
    High-risk or safety-critical activitiesHighLowMediumDirect verification and worker interaction

    Internal Auditor vs Lead Auditor

    Internal auditor and lead auditor roles differ in scope, responsibility, and typical training path. The table below compares them at a practical level. Course formats and durations shown are typical; exact requirements vary by provider and scheme.

    CriterionInternal AuditorLead Auditor
    Typical roleAudits within their own organisationLeads audit teams, including second-party audits
    Main responsibilitiesExecuting individual audits and reporting findingsPlanning audits, leading teams, reaching audit conclusions
    Training focusAudit principles, evidence, reportingAdvanced audit management, team leadership, complex reporting
    Typical course format1–2 days (typical)Approximately 5 days (typical)
    Suitable participantsQuality, EHS, or IT staff auditing internallySenior auditors, consultants, or those pursuing certification-body work
    Audit-team leadershipNot typically expectedTypically expected for those leading audit teams; exact competence criteria depend on the organisation, certification body, or scheme
    Additional experienceFamiliarity with the management system standardTypically documented audit experience across multiple audits; exact requirements vary by scheme and certification body

    Completing a lead auditor course does not, on its own, qualify someone to work as a certification-body auditor. Certification bodies assess education, sector competence, documented audit experience, personal behaviours, and scheme-specific requirements before appointing auditors.

    What Competence and Training Do Auditors Need?

    Auditor competence combines knowledge of the audit discipline, the relevant management system standard, sector context, and personal behaviours (such as objectivity and analytical thinking). ISO 19011:2026 encourages organisations to define, evaluate, and maintain competence for those managing audit programmes and conducting audits.

    Tablet showing a modular training dashboard with coloured blocks and progress indicators.

    A credible ISO 19011-aligned course should cover:

    • Audit principles and terminology
    • Audit programme planning and management
    • Audit preparation and opening arrangements
    • Evidence collection and sampling
    • Interview techniques
    • Reporting findings and writing nonconformities
    • Corrective action follow-up
    • Auditor competence and evaluation
    • Remote and hybrid audit methods

    Training outcomes are usually described as a course completion certificate, an auditor training certificate, or evidence of completed training — not "ISO 19011 certification". Only describe a course as "accredited" where a specific, independent training or personnel-certification scheme actually accredits it. For UniCert's own auditor training pathways, see our ISO training programmes.

    What Are the Limitations of ISO 19011?

    ISO 19011 is a guidance standard, not a set of certifiable requirements. It must be applied proportionately to the organisation's size, sector, and risk profile, and it does not replace scheme-specific certification rules or legal and regulatory requirements.

    Glowing fibre optic cables in a server rack symbolising digital audit data flow and connected QMS systems.

    Digital tools can support planning, evidence capture, corrective-action tracking, and reporting, but they do not replace competent professional judgement. Small organisations should avoid over-engineering their audit systems; a simple, well-used programme aligned with ISO 19011 usually produces more value than an elaborate but unused framework.

    ISO 19011:2026 Implementation Checklist

    Use this checklist to review the maturity of your audit programme. It is written in original language and does not reproduce protected ISO wording.

    • Audit programme objectives are documented and reviewed.
    • Scope and audit criteria are defined for each audit.
    • Relevant risks and opportunities are considered at programme level.
    • Higher-risk and higher-impact processes receive appropriate audit attention.
    • Auditor competence criteria are established and maintained.
    • Independence and conflicts of interest are evaluated for each audit.
    • Audit methods (on-site, remote, hybrid) are selected and justified.
    • Remote audit technology and information security are considered.
    • Sampling decisions are documented.
    • Findings are supported by verifiable evidence.
    • Reports clearly distinguish evidence, findings, and conclusions.
    • Corrective actions have owners and target dates.
    • Follow-up is completed and recorded where applicable.
    • Audit programme performance is periodically reviewed.
    • Lessons learned feed continual improvement.

    Applying ISO 19011:2026 in Practice

    ISO 19011:2026 gives UK organisations a shared vocabulary and a proven structure for auditing management systems. It is most effective when applied proportionately: clear objectives, defined competence, a risk-informed programme, and audit methods chosen to match the work being examined.

    Need to strengthen your internal audit capability? Explore UniCert's ISO training programmes and compare course outcomes to identify the appropriate route for your team.

    UniCert Certification Ltd provides management system certification under its applicable UAF accreditation scope. Organisations should use the official UAF directory of accredited certification bodies to verify the current scope applicable to the requested standard and sector.

    Sources and Further Reading

    This guide is intended for general information and does not replace the full ISO 19011:2026 publication, applicable accreditation requirements, contractual obligations, or professional advice.

    Frequently Asked Questions

    Is ISO 19011:2026 a certifiable standard?

    No. ISO 19011:2026 is a guidance standard for auditing management systems. Organisations do not become certified to ISO 19011 itself. Internal teams, second-party auditors, and consultants use it to structure and improve audit programmes across standards such as ISO 9001, ISO 14001, ISO/IEC 27001, and ISO 45001.

    What are the seven principles of auditing?

    The seven principles are integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, and risk-based approach. Together they help ensure that audit findings are objective, verifiable, and useful for management decision-making.

    What replaced ISO 19011:2018?

    ISO 19011:2026 replaced the withdrawn ISO 19011:2018 edition. It is the fourth edition of the standard and was published in May 2026 by ISO. Full details are available on the official ISO 19011 page at iso.org.

    Is ISO 19011 mandatory in the UK?

    No. ISO 19011 is voluntary guidance. It is not UK legislation and does not replace legal, regulatory, contractual, or sector-specific audit requirements. Many UK organisations still choose to align with it because it supports credible and consistent management system audits.

    What is the difference between an audit programme and an audit plan?

    An audit programme is the overall set of audits planned for a period of time with defined objectives. An audit plan describes the arrangements for a single audit within that programme, including scope, criteria, dates, auditors, and methods.

    How often should internal audits be conducted?

    ISO 19011 does not prescribe a universal audit frequency. The audit schedule should reflect process importance, risks, organisational changes, performance trends, previous audit results, and any requirements of the management system standard being audited. Higher-risk or poorly performing areas may need more frequent attention.

    Can an auditor audit their own work?

    Auditors should not normally audit work for which they are directly responsible, because this can compromise objectivity and impartiality. In smaller organisations, suitable safeguards may include cross-functional audits, auditor rotation, independent review, or the use of a competent external auditor.

    What is the difference between internal auditor and lead auditor training?

    Internal auditor training typically lasts one to two days and prepares staff to audit within their own organisation. Lead auditor training is more advanced, often around five days, and covers audit management, team leadership, and complex reporting for those leading audits or pursuing senior audit roles.

    Does completing a lead auditor course make someone a certification-body auditor?

    No. A lead auditor course is one input into competence. Certification bodies assess education, sector experience, documented audit experience, personal behaviours, and scheme-specific requirements before appointing auditors. Course completion on its own does not guarantee eligibility to work as a certification-body auditor.

    Does ISO 19011:2026 require remote auditing?

    No. ISO 19011:2026 recognises remote and hybrid auditing as an option alongside on-site audits, but does not require them. Audit methods should be selected to match the objective, scope, risks, and the availability of reliable evidence.

    How should remote audit evidence be protected?

    Remote audit evidence should be handled under the same confidentiality expectations as on-site evidence. That includes secure sharing platforms, controlled access to records, clear rules on recording and screenshots, and alignment with the auditee's information security requirements.

    UniCert certification services background

    Take the Next Step with UniCert

    From ISO 9001 quality management to cyber security and supply chain assurance – UniCert provides the management system certification you need to unlock global markets.

    Consent to Cookies & Data Processing

    We use cookies for analytics and improving your experience. This consent is voluntary and can be revoked at any time.