ISO 19011:2026 Auditing Guidelines: Complete UK Guide
A practical UK guide to ISO 19011:2026 — the seven audit principles, what changed in the 2026 revision, audit programme planning, remote and hybrid auditing, and auditor competence.
ISO 19011:2026 provides internationally recognised guidance for auditing management systems, managing audit programmes, conducting audits, and evaluating auditor competence. It is not a certifiable management system standard — organisations do not become "certified to ISO 19011". Internal audit teams, second-party auditors, consultants, and management professionals use it to make audits more consistent, credible, and useful. This UK guide summarises the seven audit principles, what changed in the 2026 revision, how to plan an audit programme, and how remote and hybrid auditing should be approached in practice. For related training pathways, see our ISO training programmes.
ISO 19011:2026 at a Glance
- ISO 19011:2026 is guidance, not a certifiable standard. Organisations cannot obtain "ISO 19011 certification".
- It is the fourth edition and replaces the withdrawn ISO 19011:2018.
- Published in May 2026 by ISO (see the official ISO 19011 page).
- Scope: auditing principles, audit programme management, conducting audits, and evaluating auditor competence.
- The 2026 revision gives increased attention to technology, digitalisation, virtual environments, and risk analysis and mitigation (per the ISO/TC 176 news update).
Table of Contents
What Are the ISO 19011 Guidelines?
ISO 19011 is an internationally recognised guidance document that describes how to plan, conduct, report, and improve audits of management systems. It applies across standards such as ISO 9001, ISO 14001, ISO/IEC 27001, and ISO 45001, but does not itself define requirements for a management system.
Using ISO 19011 does not, by itself, lead to certification. Certification against a specific management system standard (for example ISO 9001) is delivered by an independent certification body under its accreditation scope. ISO 19011 supports first-party (internal) and second-party (supplier/customer) audits, and provides useful reference material for other audit contexts. When preparing for an external assessment, our companion piece How to Prepare for an ISO 9001 Audit in the UK shows how internal audit practice supports certification readiness.
What Are the Seven Principles of Auditing Under ISO 19011?
ISO 19011 defines seven principles that underpin trustworthy audit findings: integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, and risk-based approach. Together they help ensure audits produce objective, verifiable, and useful conclusions.
The seven principles
- Integrity — auditors act honestly, ethically, and only accept assignments where they are competent.
- Fair presentation — reports reflect audit activities truthfully, including disagreements and unresolved issues.
- Due professional care — auditors apply reasonable diligence and judgement proportionate to the task.
- Confidentiality — information obtained during audits is protected and not misused.
- Independence — auditors remain free from bias and conflicts of interest as far as reasonably possible.
- Evidence-based approach — conclusions are supported by verifiable evidence drawn from appropriate sampling.
- Risk-based approach — planning and execution consider the risks and opportunities relevant to the audit objectives.
What each principle means in practice
| Principle | What it means in practice | Example audit behaviour |
|---|---|---|
| Integrity | Honest, ethical conduct within your competence | Declining an audit outside your technical scope |
| Fair presentation | Reports reflect reality, not preferences | Recording an unresolved disagreement in the report |
| Due professional care | Diligence proportionate to risk | Extending sampling where evidence is inconsistent |
| Confidentiality | Protect audit information | Storing evidence in access-controlled systems |
| Independence | Freedom from conflicts of interest | Not auditing a process you personally manage |
| Evidence-based approach | Findings supported by verifiable data | Referencing records, interviews, and observations |
| Risk-based approach | Focus effort where it matters most | Prioritising higher-risk processes and sites |
What Changed in ISO 19011:2026?
ISO 19011:2026 is the fourth edition and replaces the withdrawn 2018 edition. Unlike a revision to a certifiable management system standard, ISO 19011:2026 does not create a certification transition deadline. Organisations can nevertheless review their existing audit programmes against the updated guidance and decide how and when to incorporate relevant changes. According to the official ISO page and the ISO/TC 176 committee news, the revision places increased attention on technology, digitalisation, virtual environments, and risk analysis and mitigation.
The table below summarises the areas of emphasis and the practical implications for UK audit teams. Where an item is an operational interpretation rather than an explicit clause change, it is labelled as a practical implication.
| Area | Previous context (2018) | 2026 emphasis | Practical action |
|---|---|---|---|
| Technology & digitalisation | Technology and ICT-supported audit methods were already addressed | Technology and digitalisation receive greater prominence across the audit lifecycle | Review digital audit tools, evidence-handling methods, security controls, and auditor competence |
| Virtual environments | Remote audit methods and virtual locations were already addressed in the guidance | Greater attention is given to auditing in virtual and technology-enabled environments | Document when remote, on-site, or hybrid methods are appropriate and why |
| Risk analysis & mitigation | Risk-based approach introduced | Reinforced across programme and audit level | Document programme-level and audit-level risk considerations |
| Auditor competence (practical implication) | Traditional audit skills with some ICT awareness | Greater relevance of competence for handling evidence in digital and virtual environments | Extend competence criteria and evaluation records |
| Information handling (practical implication) | General confidentiality expectations | Greater relevance of information security across audit activities | Align with the organisation's information security controls |
Full clause-by-clause detail is only available in the published ISO document; this guide summarises the emphasis in original language and does not reproduce protected ISO text.
How Does ISO 19011 Apply to UK Internal Audits?
ISO 19011:2026 provides a structured, internationally recognised way for UK organisations to plan and conduct internal management system audits. It is not UK legislation and does not replace legal, regulatory, contractual, or sector-specific audit requirements — for example, it does not by itself demonstrate compliance with HSE requirements.
A credible internal audit programme aligned with ISO 19011 can support the effective maintenance of certifiable standards such as ISO 9001, ISO 14001, ISO/IEC 27001, and ISO 45001. Findings graded as nonconformities should be addressed through documented corrective action — our guide Can You Fail an ISO Audit in the UK? explains how minor and major findings differ. A credible internal audit programme may also support the effective maintenance of the management system certifications requested in some public and private procurement processes, but ISO 19011 itself is not a tender qualification.
How Do You Build an Audit Programme Under ISO 19011:2026?
An audit programme is the overall set of audits planned for a specific time frame and directed towards defined objectives. An individual audit plan describes the arrangements for a single audit within that programme. Building an effective programme is a repeatable, evidence-based process.
Suggested steps:
- Define audit programme objectives aligned with organisational priorities.
- Determine the relevant scope, criteria, locations, functions, and processes.
- Identify audit programme risks and opportunities.
- Prioritise significant, higher-risk, and higher-impact activities.
- Select competent and impartial auditors.
- Determine audit frequency and appropriate methods (on-site, remote, hybrid).
- Prepare individual audit plans for each audit.
- Collect and evaluate verifiable evidence during the audit.
- Report findings and conclusions clearly and traceably.
- Assign and monitor corrective actions where applicable.
- Review audit programme performance against its objectives.
- Continually improve the programme based on results and lessons learned.
Illustrative Example: A Risk-Based Internal Audit Programme
The following is an illustrative example, not a UniCert client case study. The company, processes, and priorities are fictional and shown only to demonstrate how audit frequency and methods may be chosen from risk rather than applied uniformly. Your own programme must be built from your organisation's context, risks, and applicable standards.
Consider a fictional UK precision engineering company with a single manufacturing site and one small satellite office. Its integrated management system covers ISO 9001, ISO 14001, and ISO 45001. Rather than auditing every process on the same annual cycle, the audit programme owner uses ISO 19011 principles to prioritise effort where risk and previous performance suggest it is most needed.
| Process | Risk considerations | Previous performance | Suggested audit priority | Suitable method | Reason |
|---|---|---|---|---|---|
| Production control | Direct impact on product conformity | Two minor findings last cycle | High | On-site | Live observation of controls and operator practice is essential |
| Calibration | Measurement accuracy is safety- and quality-critical | Stable, no recent findings | High | On-site | Physical verification of equipment status and records |
| Supplier control | Repeated hypothetical supplier-related nonconformities | Recurring issues over two cycles | High | Hybrid | Remote record review plus targeted on-site visits |
| Health & safety operational controls | Worker safety and legal duty of care | Improving trend | Medium–High | On-site | Direct observation of behaviours, PPE, and controls |
| Document control | Low direct risk when the system is mature | Stable | Medium | Remote | Evidence is largely digital and centrally accessible |
| Human resources | Limited product/safety impact; supports competence | Stable, no recurring findings | Lower | Remote / interview-based | Record sampling and short interviews are sufficient |
The programme owner records why each priority and method was chosen, and reviews the schedule again after each cycle. This approach reflects ISO 19011's risk-based approach and evidence-based approach without implying that every organisation should follow the same pattern.
How Should Remote and Hybrid Audits Be Planned?
Remote and hybrid audits are an accepted option under ISO 19011:2026, but they are not a default requirement. The choice of method should fit the audit objective, scope, criteria, and risks — some activities still require physical observation.
Key planning considerations:
- Technology readiness of the auditee (connectivity, tools, endpoint access).
- Access to relevant records, systems, and process data.
- Reliability, integrity, and traceability of remote evidence.
- Confidentiality and data security when sharing screens or files.
- Suitability for interviews, virtual site tours, and live process observation.
- Recording restrictions and consent for any captured material.
- Contingency arrangements for connectivity or platform failure.
| Situation | On-site suitability | Remote suitability | Hybrid suitability | Key consideration |
|---|---|---|---|---|
| Document and record review | Medium | High | High | Secure access to controlled documents |
| Interviews with process owners | High | High | High | Interview environment and confidentiality |
| Physical process observation | High | Low | Medium | Ability to observe real conditions |
| Field / site inspections | High | Low | Medium | Safety, sampling, and physical verification |
| Remote / branch offices | Medium | High | High | Consistency of evidence across sites |
| High-risk or safety-critical activities | High | Low | Medium | Direct verification and worker interaction |
Internal Auditor vs Lead Auditor
Internal auditor and lead auditor roles differ in scope, responsibility, and typical training path. The table below compares them at a practical level. Course formats and durations shown are typical; exact requirements vary by provider and scheme.
| Criterion | Internal Auditor | Lead Auditor |
|---|---|---|
| Typical role | Audits within their own organisation | Leads audit teams, including second-party audits |
| Main responsibilities | Executing individual audits and reporting findings | Planning audits, leading teams, reaching audit conclusions |
| Training focus | Audit principles, evidence, reporting | Advanced audit management, team leadership, complex reporting |
| Typical course format | 1–2 days (typical) | Approximately 5 days (typical) |
| Suitable participants | Quality, EHS, or IT staff auditing internally | Senior auditors, consultants, or those pursuing certification-body work |
| Audit-team leadership | Not typically expected | Typically expected for those leading audit teams; exact competence criteria depend on the organisation, certification body, or scheme |
| Additional experience | Familiarity with the management system standard | Typically documented audit experience across multiple audits; exact requirements vary by scheme and certification body |
Completing a lead auditor course does not, on its own, qualify someone to work as a certification-body auditor. Certification bodies assess education, sector competence, documented audit experience, personal behaviours, and scheme-specific requirements before appointing auditors.
What Competence and Training Do Auditors Need?
Auditor competence combines knowledge of the audit discipline, the relevant management system standard, sector context, and personal behaviours (such as objectivity and analytical thinking). ISO 19011:2026 encourages organisations to define, evaluate, and maintain competence for those managing audit programmes and conducting audits.
A credible ISO 19011-aligned course should cover:
- Audit principles and terminology
- Audit programme planning and management
- Audit preparation and opening arrangements
- Evidence collection and sampling
- Interview techniques
- Reporting findings and writing nonconformities
- Corrective action follow-up
- Auditor competence and evaluation
- Remote and hybrid audit methods
Training outcomes are usually described as a course completion certificate, an auditor training certificate, or evidence of completed training — not "ISO 19011 certification". Only describe a course as "accredited" where a specific, independent training or personnel-certification scheme actually accredits it. For UniCert's own auditor training pathways, see our ISO training programmes.
What Are the Limitations of ISO 19011?
ISO 19011 is a guidance standard, not a set of certifiable requirements. It must be applied proportionately to the organisation's size, sector, and risk profile, and it does not replace scheme-specific certification rules or legal and regulatory requirements.
Digital tools can support planning, evidence capture, corrective-action tracking, and reporting, but they do not replace competent professional judgement. Small organisations should avoid over-engineering their audit systems; a simple, well-used programme aligned with ISO 19011 usually produces more value than an elaborate but unused framework.
ISO 19011:2026 Implementation Checklist
Use this checklist to review the maturity of your audit programme. It is written in original language and does not reproduce protected ISO wording.
- Audit programme objectives are documented and reviewed.
- Scope and audit criteria are defined for each audit.
- Relevant risks and opportunities are considered at programme level.
- Higher-risk and higher-impact processes receive appropriate audit attention.
- Auditor competence criteria are established and maintained.
- Independence and conflicts of interest are evaluated for each audit.
- Audit methods (on-site, remote, hybrid) are selected and justified.
- Remote audit technology and information security are considered.
- Sampling decisions are documented.
- Findings are supported by verifiable evidence.
- Reports clearly distinguish evidence, findings, and conclusions.
- Corrective actions have owners and target dates.
- Follow-up is completed and recorded where applicable.
- Audit programme performance is periodically reviewed.
- Lessons learned feed continual improvement.
Applying ISO 19011:2026 in Practice
ISO 19011:2026 gives UK organisations a shared vocabulary and a proven structure for auditing management systems. It is most effective when applied proportionately: clear objectives, defined competence, a risk-informed programme, and audit methods chosen to match the work being examined.
Need to strengthen your internal audit capability? Explore UniCert's ISO training programmes and compare course outcomes to identify the appropriate route for your team.
UniCert Certification Ltd provides management system certification under its applicable UAF accreditation scope. Organisations should use the official UAF directory of accredited certification bodies to verify the current scope applicable to the requested standard and sector.
Sources and Further Reading
- ISO 19011:2026 — Guidelines for auditing management systems (official ISO page)
- ISO/PC 302 — Guidelines for auditing management systems (committee page)
- ISO — Certification and conformity (overview)
- ISO/TC 176 — News and revision updates
- Official UAF directory of accredited certification bodies — verify current UniCert scope
This guide is intended for general information and does not replace the full ISO 19011:2026 publication, applicable accreditation requirements, contractual obligations, or professional advice.
Frequently Asked Questions
Is ISO 19011:2026 a certifiable standard?
No. ISO 19011:2026 is a guidance standard for auditing management systems. Organisations do not become certified to ISO 19011 itself. Internal teams, second-party auditors, and consultants use it to structure and improve audit programmes across standards such as ISO 9001, ISO 14001, ISO/IEC 27001, and ISO 45001.
What are the seven principles of auditing?
The seven principles are integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, and risk-based approach. Together they help ensure that audit findings are objective, verifiable, and useful for management decision-making.
What replaced ISO 19011:2018?
ISO 19011:2026 replaced the withdrawn ISO 19011:2018 edition. It is the fourth edition of the standard and was published in May 2026 by ISO. Full details are available on the official ISO 19011 page at iso.org.
Is ISO 19011 mandatory in the UK?
No. ISO 19011 is voluntary guidance. It is not UK legislation and does not replace legal, regulatory, contractual, or sector-specific audit requirements. Many UK organisations still choose to align with it because it supports credible and consistent management system audits.
What is the difference between an audit programme and an audit plan?
An audit programme is the overall set of audits planned for a period of time with defined objectives. An audit plan describes the arrangements for a single audit within that programme, including scope, criteria, dates, auditors, and methods.
How often should internal audits be conducted?
ISO 19011 does not prescribe a universal audit frequency. The audit schedule should reflect process importance, risks, organisational changes, performance trends, previous audit results, and any requirements of the management system standard being audited. Higher-risk or poorly performing areas may need more frequent attention.
Can an auditor audit their own work?
Auditors should not normally audit work for which they are directly responsible, because this can compromise objectivity and impartiality. In smaller organisations, suitable safeguards may include cross-functional audits, auditor rotation, independent review, or the use of a competent external auditor.
What is the difference between internal auditor and lead auditor training?
Internal auditor training typically lasts one to two days and prepares staff to audit within their own organisation. Lead auditor training is more advanced, often around five days, and covers audit management, team leadership, and complex reporting for those leading audits or pursuing senior audit roles.
Does completing a lead auditor course make someone a certification-body auditor?
No. A lead auditor course is one input into competence. Certification bodies assess education, sector experience, documented audit experience, personal behaviours, and scheme-specific requirements before appointing auditors. Course completion on its own does not guarantee eligibility to work as a certification-body auditor.
Does ISO 19011:2026 require remote auditing?
No. ISO 19011:2026 recognises remote and hybrid auditing as an option alongside on-site audits, but does not require them. Audit methods should be selected to match the objective, scope, risks, and the availability of reliable evidence.
How should remote audit evidence be protected?
Remote audit evidence should be handled under the same confidentiality expectations as on-site evidence. That includes secure sharing platforms, controlled access to records, clear rules on recording and screenshots, and alignment with the auditee's information security requirements.
Related certifications:

Take the Next Step with UniCert
From ISO 9001 quality management to cyber security and supply chain assurance – UniCert provides the management system certification you need to unlock global markets.







