AuditXYZ

Compliance Framework

ISO 19011:2018 Guidelines for Auditing Management Systems (ISO 19011)

ISO 19011 provides comprehensive guidance for planning, conducting, and managing audits of any management system. This guide covers audit principles, auditor competence, and best practices for internal audits.

$5,000–$30,0001–3 months2018
Issuing BodyInternational Organization for Standardization (ISO)
First Published2002-10-01
Latest Version2018
Typical Cost$5,000–$30,000
Typical Timeline1–3 months
Audit RequiredNo
Audit FrequencyISO 19011 provides guidance for conducting audits of other management systems. It is not separately auditable or certifiable.
Geographyglobal

ISO 19011: Guidelines for Auditing Management Systems

ISO 19011 is the international standard providing guidance on auditing management systems, applicable across all ISO management system standards including ISO 27001, ISO 9001, ISO 14001, ISO 42001, and others. The 2018 edition introduced a risk-based approach to auditing and expanded guidance on auditor competence, making it the essential reference for anyone planning, conducting, or managing internal or external audits.

What ISO 19011 Is and Who Issues It

ISO 19011:2018 is a guidance standard published by the International Organization for Standardization (ISO) and developed by ISO Technical Committee TC 176 (Quality Management and Quality Assurance) in collaboration with other relevant technical committees. Unlike certification standards such as ISO 27001 or ISO 9001, ISO 19011 is not a requirements standard — it provides recommendations and guidance rather than mandatory provisions. Organizations cannot be certified to ISO 19011 itself, but they can and should use it to conduct audits under any certification standard.

The standard's origins trace to the early 1990s when separate auditing guidelines existed for quality systems and environmental systems. Recognizing the redundancy, ISO published the first unified management system auditing guideline as ISO 19011 in 2002, replacing multiple separate documents. The 2011 edition expanded scope beyond quality and environmental systems to all management systems. The current 2018 edition introduced the risk-based approach as a core auditing principle — aligning the standard with the risk-based thinking embedded in the 2015-generation ISO management system standards (Annex SL).

Every ISO management system standard — ISO 27001 Clause 9.2, ISO 42001 Clause 9.2, ISO 9001 Clause 9.2, ISO 14001 Clause 9.2 — requires the organization to conduct internal audits. ISO 19011 is the universal guidance document for fulfilling that requirement across all of them.

Who Uses ISO 19011

ISO 19011 serves multiple audiences with different roles in the audit ecosystem:

Internal auditors across all industries and management system types use ISO 19011 as their primary reference. Whether auditing an ISO 27001 ISMS, an ISO 9001 QMS, an ISO 14001 EMS, or an ISO 42001 AIMS, internal auditors apply the principles, competence criteria, and process guidance from ISO 19011.

Audit programme managers responsible for designing and managing an organization's internal audit function rely on ISO 19011's guidance on audit programme objectives, resourcing, scheduling, and performance evaluation. Building an effective internal audit programme from scratch — rather than a compliance checkbox exercise — requires the structured approach ISO 19011 provides.

Lead auditors for third-party certification use ISO 19011 alongside the specific requirements of the certification standard. Certification body auditors are trained to ISO 19011 competence criteria, and Lead Auditor training courses for ISO 27001, ISO 9001, and other standards are based directly on ISO 19011's guidance.

Organizations undergoing external audits can use ISO 19011 to understand what auditors are doing and why, enabling more productive engagement during audits, better preparation of evidence, and more effective corrective action processes.

Training organizations delivering ISO Lead Auditor and Internal Auditor courses use ISO 19011 as the curriculum foundation, ensuring that auditors globally operate with consistent conceptual frameworks and practical techniques.

The Seven Audit Principles

ISO 19011 establishes seven principles that guide auditors in all management system audit contexts. These principles distinguish ethical, professional audit practice from superficial compliance checking:

Integrity — The foundation of professionalism. Auditors must perform their work honestly, diligently, and responsibly. This means reporting findings accurately, including negative findings, and not allowing relationships with auditees to compromise objectivity.

Fair Presentation — Audit findings, conclusions, and reports must accurately reflect audit activities. Auditors must report all significant findings — both conformities and nonconformities — and ensure the auditee has an opportunity to respond before findings are finalized.

Due Professional Care — Auditors must exercise care commensurate with the importance of the task and the trust placed by audit clients and stakeholders. This includes applying appropriate effort to each audit, not cutting corners on evidence gathering, and maintaining competence.

Confidentiality — Information obtained during audits must be handled with discretion. Auditors regularly encounter sensitive business, financial, and personal information. That information must be used only for audit purposes and protected from unauthorized disclosure.

Independence — Auditors must be independent of the activity being audited. For internal audits, this means auditors should not audit their own work. Audit programs should be structured to ensure that independence is maintained even when internal resource constraints exist.

Evidence-Based Approach — Audit conclusions must be based on verifiable information. The systematic nature of audit methodology — following documented trails, testing samples, observing processes — produces reproducible results that can be evaluated and improved.

Risk-Based Approach — Introduced in the 2018 edition, this principle directs auditors to focus audit effort on matters most significant to audit objectives and the organization's risk profile. Not all controls carry equal risk; not all nonconformities carry equal consequence. Effective auditors prioritize accordingly.

Audit Programme Management in Depth

Managing an audit programme is distinct from conducting individual audits — it is an operational management function requiring planning, resource allocation, monitoring, and continual improvement.

Establishing audit programme objectives: Objectives must reflect the needs of the management system standard, organizational risk, external requirements, and the interests of interested parties. Objectives should be specific and measurable — "verify conformance with Clause 9.1 controls" is an objective; "make sure things are OK" is not.

Determining the scope and risk basis: The 2018 edition requires audit programme managers to assess risks to the programme itself — risks that audits will not be conducted effectively or that audit conclusions will be unreliable. These programme risks inform how audits are scheduled, resourced, and conducted.

Selecting and assigning auditors: ISO 19011 requires that auditors have demonstrated competence. This means audit programme managers must maintain competence records, ensure auditors are trained appropriately for the management systems they audit, and assign lead auditors who can manage the audit team effectively. For ISO 42001 AI management system audits, auditors need AI-domain knowledge in addition to management system auditing skills.

Scheduling and coordinating audits: The programme schedule must ensure that all areas and processes in scope are audited at appropriate frequency. High-risk areas should be audited more frequently. Schedule coordination with operational activities minimizes disruption while ensuring audit access.

Monitoring and evaluating programme effectiveness: Audit programmes should be evaluated against their objectives. Metrics include the proportion of planned audits completed on schedule, the proportion of corrective actions closed within agreed timelines, audit finding trends over time, and auditee satisfaction. Continual improvement of the audit programme itself is explicitly required.

Conducting Individual Audits: The Audit Process

ISO 19011 describes a structured audit process applicable to any management system audit:

Initiating the audit: The lead auditor confirms the audit objective, scope, and criteria with the audit client, reviews available documentation, and establishes initial contact with the auditee. For internal audits, the audit objective is typically to verify conformance with the management system standard; for process audits it may be broader.

Preparing the audit: Auditors prepare an audit plan detailing the schedule, responsibilities, and resources. They develop audit checklists and sampling plans based on the documented scope and risk assessment. Preparation also involves reviewing prior audit findings and corrective action records.

Conducting audit activities: The audit opens with an opening meeting at which the lead auditor confirms the scope, objectives, and planned approach. Evidence is then collected through a combination of interviews (directed inquiry with process owners and practitioners), document review (policies, procedures, records, and logs), observation (watching processes operate), and reperformance (recreating an activity to verify the process works as described). Audit team members take contemporaneous notes and retain evidence samples.

Preparing and distributing audit reports: The audit report must be timely — typically within 2 weeks of the closing meeting. Reports must be factual, objective, and focused on evidence-based findings. Findings are classified as nonconformities (where a requirement is not met), observations (potential issues that do not yet rise to nonconformity), and opportunities for improvement. Reports should be distributed to appropriate parties as specified in the audit programme.

Completing the audit and following up: The audit is formally closed when the report is distributed. Follow-up on corrective actions is a critical programme management function. Audit value is realized only when nonconformities are corrected and underlying causes addressed. ISO 19011 requires that the audit programme track corrective action completion and verify effectiveness of corrections.

Auditor Competence Requirements

ISO 19011's competence framework for auditors covers personal behavior attributes and management system knowledge. Auditors should demonstrate:

  • Ethical conduct: Fairness, truthfulness, sincerity, and discretion
  • Open-mindedness: Willingness to consider alternative views and evidence
  • Diplomacy: Tact in managing difficult situations and conversations
  • Observation: Attention to physical activities and circumstances
  • Perceptiveness: Awareness of and ability to understand situations intuitively
  • Versatility: Adaptation to different situations
  • Tenacity: Persistence and focus on achieving objectives
  • Decisiveness: Ability to reach timely conclusions based on logical reasoning
  • Self-reliance: Independence and effectiveness with minimal direction
  • Cultural sensitivity: Awareness of and respect for cultural differences

In addition to personal attributes, auditors must demonstrate generic management system audit knowledge and management system-specific technical knowledge. ISO 27001 auditors must understand information security concepts; ISO 42001 auditors must understand AI systems, lifecycle management, and impact assessment methodologies.

Costs and Timeline

ActivityTypical CostTimeline
Internal auditor training (per person)$1,000 – $2,5002–3 days
Lead auditor training (per person)$2,000 – $4,0005 days
Audit programme design and documentation$3,000 – $10,0002–4 weeks
First cycle of internal audits (ISO 27001)$5,000 – $15,0004–8 weeks
Annual audit programme operation$3,000 – $10,000/yearOngoing

The standard itself does not require certification, but effective implementation significantly improves internal audit quality and directly supports external certification success.

ISO 27001 Clause 9.2 (85% overlap): Every ISO 27001-certified organization must maintain an internal audit programme. ISO 19011 is the definitive guidance for fulfilling that requirement. The overlap is near-complete for the audit process itself; ISO 27001 adds the information security-specific scope and control context. See any ISO 27001 guide for how Clause 9.2 expectations translate to practice.

ISO 42001 Clause 9.2 (85% overlap): ISO 42001 has the same internal audit requirement as all Annex SL standards. ISO 19011 provides the methodology; auditors additionally need AI governance knowledge to audit Annex A controls and AI impact assessment processes effectively. See the ISO 42001 guide.

ISAE 3000 (contextual relationship): ISAE 3000 governs external assurance practitioners performing formal assurance engagements. ISO 19011 governs internal auditors (and certification body auditors) performing management system audits. The standards serve different audiences and produce different outputs — management reports vs. assurance reports — but share many underlying principles around evidence, independence, and professional skepticism. See the ISAE 3000 guide.

How Automation Helps

Effective internal audit programmes depend on accurate, timely management information — current control documentation, evidence of recent operation, status of open corrective actions, and performance trends. When this information lives in spreadsheets and shared drives, audit preparation is slow and findings may be based on outdated documentation.

LowerPlane provides the live, organized evidence layer that internal auditors need: current control status, timestamped evidence, automated evidence collection from connected systems, and corrective action tracking across 50+ frameworks including ISO 27001 and ISO 42001. Starting at $4,000 per year with a free tier, it is rated 9.4/10 by AuditXYZ users. Organizations that implement compliance automation consistently report faster internal audits, fewer surprises in certification audits, and lower audit programme operating costs. See our compliance automation platform comparison.

Frequently Asked Questions

Is an organization required to follow ISO 19011 to satisfy its management system standard's internal audit requirement? ISO management system standards require internal audits but do not prescribe using ISO 19011. The requirement is to conduct planned audits at intervals and report results to management. ISO 19011 is a guidance document providing best-practice methodology. In practice, certification body auditors will assess whether the internal audit programme is fit for purpose — and ISO 19011 alignment is the most defensible evidence that it is.

How often should internal audits be conducted under ISO 27001 or ISO 42001? ISO management system standards require internal audits "at planned intervals" without specifying frequency. Best practice is to audit all in-scope areas at least annually, with higher-risk areas audited more frequently. A typical programme audits all clauses and Annex A control domains over 12 months, ensuring full coverage before the external surveillance or recertification audit.

What is the difference between a nonconformity and an observation in audit reporting? A nonconformity is a failure to fulfill a specified requirement of the management system standard — for example, an access review that was not completed as required by policy, or a risk assessment that was not updated following a significant change. An observation is a potential issue that does not currently constitute a nonconformity but may if not addressed — for example, a control that meets the requirement but appears fragile or dependent on a single person. Opportunities for improvement are positive suggestions that go beyond current requirements.

Can internal auditors also function as implementers of the management system they audit? ISO 19011's independence principle requires that auditors not audit their own work. An information security engineer who designed a specific control should not audit that control. However, independence does not require that internal auditors be completely segregated from the management system — they may be part of the team as long as they are not auditing areas they personally designed or implemented. Small organizations often manage this through mutual auditing between team members or by engaging external consultants for specific areas.

How does ISO 19011 address remote or virtual audits? The 2018 edition pre-dates the widespread adoption of remote auditing but acknowledges that audits can be conducted using communication technology. Subsequent IAASB guidance on remote auditing (prompted by the COVID-19 pandemic) provides detailed advice on how to adapt ISO 19011 methodology for remote contexts — using video calls for interviews, requesting screen-sharing or document sharing for record review, and addressing the challenges of remote observation. ISO 19011 principles apply regardless of whether the audit is conducted on-site or remotely.

Request a ISO 19011 consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

Related frameworks

Get matched with a ISO 19011 auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.