Sustainability Language
ISO 19011
International guidance on audit principles, audit-programme management, conducting management-system audits and evaluating auditor competence.
Expert review openNo editor-accepted expert review yetDefinition
International guidance on audit principles, audit-programme management, conducting management-system audits and evaluating auditor competence.
Overview
“ISO 19011 can improve an audit; it cannot turn the audit itself into certification. ”
ISO 19011 is one of the most cited audit standards and one of the most frequently misapplied. Organisations say an audit was conducted 'to ISO 19011' as though that statement certifies the subject being audited. ISO 19011 provides guidance for auditing management systems. It is not a certifiable management-system standard and does not define the substantive requirements against which conformity is judged.
ISO published the fourth edition, ISO 19011:2026, in May 2026. It addresses audit principles, managing audit programmes, conducting audits and evaluating the competence of people involved. The update replaced the 2018 edition and reflects changing audit environments, technologies and management systems.
Audit principles support trust in the process. They include integrity, fair presentation, due professional care, confidentiality, independence and evidence-based, risk-informed judgement. These principles are not decorative values. They affect whether negative evidence is reported, whether conflicts are controlled and whether the conclusion is proportionate to what was actually examined.
An audit programme is larger than an audit. It sets objectives, priorities, resources, methods, competence and review across a planned set of audits. A programme should follow risk and organisational change rather than repeat the same calendar exercise each year. Sites, processes or suppliers with greater potential consequence may require different frequency, team or method.
The audit itself begins with objectives, scope and criteria. The criteria come from laws, standards, policies, contracts or scheme requirements. ISO 19011 does not supply them. An auditor can follow excellent methodology and still produce a conclusion of limited value if the criteria omit the impact that matters.
Evidence is sampled. Interviews, records, observation and data are selected within time and access constraints. The conclusion is therefore based on available audit evidence, not complete knowledge. Remote methods can increase reach, but image, video and document access may be controlled by the auditee. Audit design should consider what cannot be seen and where independent corroboration is needed.
Competence combines knowledge, skills, behaviour and sector understanding. A team may need expertise in management systems, agriculture, labour rights, chemistry, data or local language. One auditor rarely covers every subject. Programme managers should define competence against the audit's actual risks rather than rely on generic course certificates.
First-, second- and third-party audits have different relationships. Internal audits support organisational learning. Supplier audits protect a buyer's interests and may create pressure where the commercial relationship is unequal. Third-party certification audits operate within conformity-assessment rules beyond ISO 19011 alone. Describing all three as independent obscures their incentives.
Audit culture can become performative. Michael Power's 1997 account of the audit society showed how organisations can become skilled at producing auditable evidence without necessarily improving the underlying activity. Checklists, polished records and prepared interviewees may demonstrate control of the audit encounter.
Effective auditors follow inconsistencies, triangulate evidence and examine outcomes as well as system design.
Findings should support improvement and decision, not simply populate a report. The classification of non-conformity, root-cause analysis, corrective action and verification of effectiveness need rules from the relevant system or scheme. ISO 19011 guides the audit; it does not define every consequence.
The discipline is to use ISO 19011 for what it is: internationally agreed guidance for designing and conducting better audits. Credibility still depends on appropriate criteria, competent people, access, independence, evidence and a governance system capable of acting on what the audit finds.
Practical application
Define audit objectives, criteria and intended decisions before selecting methods. Build an audit programme around risk, change and previous performance. Appoint teams whose combined competence covers the management system, sector, impacts, language and data involved.
Triangulate records, interviews, observation and external evidence. Protect confidential worker and community participation. Report limitations and uncertainty, and track corrective-action effectiveness. Do not use the phrase 'ISO 19011 compliant' as a substitute for explaining the criteria and party status of the audit.
Why it matters
Audits influence certification, supplier approval, regulation and internal improvement. Consistent guidance helps organisations plan competent, evidence-based audits while avoiding improvised methods. The guidance creates a foundation; it does not guarantee that the right question was asked or acted upon.
Common misconception
ISO 19011 is often treated as an auditable or certifiable standard. It is guidance for auditing management systems. Certification, accreditation and scheme-specific rules may incorporate or refer to it, but an audit does not become certification because the guidance was followed.
Connections
ISO/IEC 17065 and ISO/IEC 17021-1 establish requirements for certification bodies in different fields. Conformity assessment provides the wider framework. Verification and validation assess declared information, while an audit evaluates evidence against audit criteria within a defined scope.
A question worth asking
If your audit team followed ISO 19011 perfectly, would the criteria, access and evidence still allow it to detect the impact your organisation most needs to understand?
Selected references
ISO 19011:2026. Guidelines for Auditing Management Systems. ISO/IEC 17021-1:2015. Conformity Assessment - Requirements for Bodies Providing Audit and Certification of Management Systems. ISO. 2026. ISO 19011: Guidelines for Auditing Management Systems - official overview. Power, M. 1997. The Audit Society: Rituals of Verification. Pentland, B. T. 1993.
Getting Comfortable with the Numbers: Auditing and the Micro-production of Macro-order. Accounting, Organizations and Society 18(7-8): 605-620.
Review
Public comments appear only after editor acceptance. Draft comments stay in the review queue.
Reviewers choose the definition or an overview paragraph, leave a comment or replacement, and attach evidence or a source link.
Editors compare reviewer cards side by side. AI may help find agreement, conflicts, unsupported claims and possible source issues.
Only an editor-accepted synthesis changes the public page. Reviewer identities are shown only with consent and verification.
Submitted reviews stay private until accepted.
Loading verified endorsements… Endorsements are not votes and never determine publication.
Endorse this definition
Endorse the exact version shown here. This is not a vote, and publication remains an editorial decision.
Review board
Comment on a specific line. Each reviewer stays separate until an editor accepts a merged draft.
Each person comments on the definition or overview in their own draft card, with role, evidence and suggested wording kept together.
AI can compare comments against the current text, flag conflicting claims, surface missing evidence and identify where reviewers agree.
An editor merges compatible suggestions into a draft change, checks sources, records disagreements and decides what can be published.