Sustainability Language

ISO 19011

International guidance on audit principles, audit-programme management, conducting management-system audits and evaluating auditor competence.

Established · Version master-draft-2026-08-10

Expert review openNo editor-accepted expert review yet

Definition

International guidance on audit principles, audit-programme management, conducting management-system audits and evaluating auditor competence.

Overview

“ISO 19011 can improve an audit; it cannot turn the audit itself into certification. ”

ISO 19011 is one of the most cited audit standards and one of the most frequently misapplied. Organisations say an audit was conducted 'to ISO 19011' as though that statement certifies the subject being audited. ISO 19011 provides guidance for auditing management systems. It is not a certifiable management-system standard and does not define the substantive requirements against which conformity is judged.

ISO published the fourth edition, ISO 19011:2026, in May 2026. It addresses audit principles, managing audit programmes, conducting audits and evaluating the competence of people involved. The update replaced the 2018 edition and reflects changing audit environments, technologies and management systems.

Audit principles support trust in the process. They include integrity, fair presentation, due professional care, confidentiality, independence and evidence-based, risk-informed judgement. These principles are not decorative values. They affect whether negative evidence is reported, whether conflicts are controlled and whether the conclusion is proportionate to what was actually examined.

An audit programme is larger than an audit. It sets objectives, priorities, resources, methods, competence and review across a planned set of audits. A programme should follow risk and organisational change rather than repeat the same calendar exercise each year. Sites, processes or suppliers with greater potential consequence may require different frequency, team or method.

The audit itself begins with objectives, scope and criteria. The criteria come from laws, standards, policies, contracts or scheme requirements. ISO 19011 does not supply them. An auditor can follow excellent methodology and still produce a conclusion of limited value if the criteria omit the impact that matters.

Evidence is sampled. Interviews, records, observation and data are selected within time and access constraints. The conclusion is therefore based on available audit evidence, not complete knowledge. Remote methods can increase reach, but image, video and document access may be controlled by the auditee. Audit design should consider what cannot be seen and where independent corroboration is needed.

Competence combines knowledge, skills, behaviour and sector understanding. A team may need expertise in management systems, agriculture, labour rights, chemistry, data or local language. One auditor rarely covers every subject. Programme managers should define competence against the audit's actual risks rather than rely on generic course certificates.

First-, second- and third-party audits have different relationships. Internal audits support organisational learning. Supplier audits protect a buyer's interests and may create pressure where the commercial relationship is unequal. Third-party certification audits operate within conformity-assessment rules beyond ISO 19011 alone. Describing all three as independent obscures their incentives.

Audit culture can become performative. Michael Power's 1997 account of the audit society showed how organisations can become skilled at producing auditable evidence without necessarily improving the underlying activity. Checklists, polished records and prepared interviewees may demonstrate control of the audit encounter.

Effective auditors follow inconsistencies, triangulate evidence and examine outcomes as well as system design.

Findings should support improvement and decision, not simply populate a report. The classification of non-conformity, root-cause analysis, corrective action and verification of effectiveness need rules from the relevant system or scheme. ISO 19011 guides the audit; it does not define every consequence.

The discipline is to use ISO 19011 for what it is: internationally agreed guidance for designing and conducting better audits. Credibility still depends on appropriate criteria, competent people, access, independence, evidence and a governance system capable of acting on what the audit finds.

Practical application

Define audit objectives, criteria and intended decisions before selecting methods. Build an audit programme around risk, change and previous performance. Appoint teams whose combined competence covers the management system, sector, impacts, language and data involved.

Triangulate records, interviews, observation and external evidence. Protect confidential worker and community participation. Report limitations and uncertainty, and track corrective-action effectiveness. Do not use the phrase 'ISO 19011 compliant' as a substitute for explaining the criteria and party status of the audit.

Why it matters

Audits influence certification, supplier approval, regulation and internal improvement. Consistent guidance helps organisations plan competent, evidence-based audits while avoiding improvised methods. The guidance creates a foundation; it does not guarantee that the right question was asked or acted upon.

Common misconception

ISO 19011 is often treated as an auditable or certifiable standard. It is guidance for auditing management systems. Certification, accreditation and scheme-specific rules may incorporate or refer to it, but an audit does not become certification because the guidance was followed.

Connections

ISO/IEC 17065 and ISO/IEC 17021-1 establish requirements for certification bodies in different fields. Conformity assessment provides the wider framework. Verification and validation assess declared information, while an audit evaluates evidence against audit criteria within a defined scope.

A question worth asking

If your audit team followed ISO 19011 perfectly, would the criteria, access and evidence still allow it to detect the impact your organisation most needs to understand?

Selected references

ISO 19011:2026. Guidelines for Auditing Management Systems. ISO/IEC 17021-1:2015. Conformity Assessment - Requirements for Bodies Providing Audit and Certification of Management Systems. ISO. 2026. ISO 19011: Guidelines for Auditing Management Systems - official overview. Power, M. 1997. The Audit Society: Rituals of Verification. Pentland, B. T. 1993.

Getting Comfortable with the Numbers: Auditing and the Micro-production of Macro-order. Accounting, Organizations and Society 18(7-8): 605-620.

Review

Public comments appear only after editor acceptance. Draft comments stay in the review queue.

0
How people contribute

Reviewers choose the definition or an overview paragraph, leave a comment or replacement, and attach evidence or a source link.

How comments are used

Editors compare reviewer cards side by side. AI may help find agreement, conflicts, unsupported claims and possible source issues.

What gets published

Only an editor-accepted synthesis changes the public page. Reviewer identities are shown only with consent and verification.

No verified experts yet

Submitted reviews stay private until accepted.

Loading verified endorsements… Endorsements are not votes and never determine publication.

Endorse this definition

Endorse the exact version shown here. This is not a vote, and publication remains an editorial decision.

vmaster-draft-2026-08-10

Sign-in supplies your email for verification and necessary follow-up; it is not displayed publicly. We do not ask you to enter it again.

Sign in with a passwordless email link before submitting.

Review board

Comment on a specific line. Each reviewer stays separate until an editor accepts a merged draft.

1Separate reviewer cards

Each person comments on the definition or overview in their own draft card, with role, evidence and suggested wording kept together.

2AI comparison

AI can compare comments against the current text, flag conflicting claims, surface missing evidence and identify where reviewers agree.

3Editor synthesis

An editor merges compatible suggestions into a draft change, checks sources, records disagreements and decides what can be published.

Text to reviewChoose the exact definition or overview paragraph.
Reviewer commentDraft only. Not public until editor accepted.
Definition
Reviewer identityYour signed-in account identifies the submission. We use its email only for verification and necessary follow-up, and never display it publicly.
Before you submit

This proposal follows the editorial and AI-assistance rules. The live definition will not change until an editor accepts it.

  • Add the proposed wording or note.
  • Explain why the change is needed.
  • Ready
  • Ready

Sign in with a passwordless email link before submitting.

You can still save a draft, but completing these items makes editorial review faster. Multiple reviewers can suggest changes on the same text. Editors compare, merge, accept or decline them before any public change.