The Audit Question Catalog under ISO 19011: Questions That Produce Evidence
Ask a room full of auditors what a “question catalog” is and you will get three answers, because the term gets mixed up with the audit plan and the checklist. That confusion is why internal audits end with a stack of ticked lines and still surface nothing the organization did not already know.
The second reason is less comfortable. A large share of the catalogs I meet in projects consist of clause sentences with a question mark bolted on. Those questions test whether someone knows the standard — not whether the process holds.
Three Different Things, One Word
The audit plan, the checklist and the question catalog answer three different questions and have three different lifespans.
| Artifact | Answers | Lifespan | Typical failure |
|---|---|---|---|
| Audit plan | When, who, which area, what scope? | one audit | becomes a calendar entry with no audit criteria |
| Checklist | Which topics have to be covered? | one audit cycle | is really the table of contents of the standard |
| Question catalog | How do I ask so the answer counts as evidence? | several cycles, continuously maintained | written once and never touched again |
The checklist tells you what to look at. The catalog tells you how to ask about it. Only the second decides whether an objective record ends up on the table or an assurance does.
What ISO 19011 Is — and What It Explicitly Is Not
Clause 1 describes the scope as guidance on auditing management systems: the principles of auditing, managing an audit programme, conducting audits, and evaluating the competence of the people involved [1]. The Introduction draws the boundary: the document concentrates on internal (first-party) audits and audits of external providers (second party), while ISO/IEC 17021-1 carries the requirements for third-party certification. ISO’s own product page answers the question directly — ISO 19011 provides guidance and does not itself lead to certification [1].
That names the property most readers skim past: ISO 19011 is guidance, not a requirements standard. It appears in ISO 9001:2015 in exactly one place, a Note following 9.2.2 f) [2]. ISO/TC 176’s Auditing Practices Group is explicit about what that means: ISO 19011 is named there only as an example, Notes are not requirements, and an auditor may therefore neither cite a requirement from ISO 19011 nor raise a nonconformity against it [3]. That statement addresses the 2018 edition and has not been updated for 2026; the standard’s status has not changed.
In practice: your catalog cannot be “non-compliant”, because there is nothing for it to violate. What binds is 9.2.2 — audit criteria and scope for each audit, objectivity and impartiality of the auditors, reporting, and retained evidence of both the implementation of the programme and its results [2]. What ISO 19011 adds on top of that is laid out on the ISO 19011 guidance page; the programme level is covered in the article on planning the audit programme.
Which Edition Is On Your Desk
ISO 19011:2026 was published in May 2026 as the fourth edition, which withdraws ISO 19011:2018 [1]. The revision is a light one. The Foreword lists exactly two changes, both on the same subject: expanded guidance on remote auditing methods, imported from ISO/IEC TS 17012, and a corresponding expansion of Annex A covering remote auditing methods and virtual locations [1][4]. The step from 2011 to 2018 had seven such bullets. Terms grew from 3.1–3.26 to 3.1–3.27 and now draw on ISO 9000:2026 [1][5].
For an existing catalog that is good news: the numbering did not change at any level of clauses 5, 6 and 7 [1]. One exception matters for citation. Clause 4 gained subclauses. In 2018 the seven auditing principles were unnumbered lettered items and you simply cited “Clause 4”; in 2026 they are 4.2 integrity, 4.3 fair presentation, 4.4 due professional care, 4.5 confidentiality, 4.6 independence, 4.7 evidence-based approach and 4.8 risk-based approach [1]. Anyone documenting the independence of internal auditors has been citing 4.6 since May 2026.
The second trap is the titles. Many subclause titles picked up a definite article, and alongside those sit genuine title changes:
| Clause | 2018 | 2026 |
|---|---|---|
| 5.4.3 | Establishing extent of audit programme | Establishing the scope of the audit programme |
| 5.5.7 | Managing and maintaining audit programme records | Managing audit related records |
| 6.4.5 | Audit information availability and access | Providing access to audit information |
| A.2 | Process approach to auditing | Auditing of processes |
The rule that follows: never pair a 2018 title with a 2026 reference. The number will be right and the wording wrong.
National adoptions run behind the international edition, and that gap is worth knowing before you cite one. In Germany, DIN EN ISO 19011:2018-10 is still the standard in force; DIN EN ISO 19011:2026-09 is announced for September 2026 and only replaces it on publication, at which point the German title also changes from “Leitfaden” to “Leitlinien” [6].
Assessment: anyone who bought the standard in a national translation is holding the 2018 edition and may well not have registered that the international edition was superseded three months ago. That is not a problem inside an internal audit — you audit against ISO 9001, not against ISO 19011. It is a reason to walk through the references in your own catalog once the adoption lands.
The Fundamental Mistake: Interrogating Clause by Clause
The most common failure pattern is working through ISO 9001 numerically in front of a process owner: “show me your 7.1.5, now 7.1.6.” It produces rehearsed answers and tests whether someone has memorized the standard.
The second drawback is structural. A finding generated by a clause question is hard to assign. “Nonconformity against 7.1.5” belongs to nobody. “The measuring equipment used in incoming inspection has not been calibrated for fourteen months against a twelve-month interval” belongs to the head of goods receipt — and therefore gets worked on.
ISO 19011 gives auditing processes its own section in Annex A (A.2, “Auditing of processes” in 2026, “Process approach to auditing” in 2018) [1]. I will not paraphrase what it says there; that text sits behind the paywall. That it exists says enough about the weighting. Topic coverage, meanwhile, is the checklist’s job — see the internal audit checklist for ISO 9001. The checklist covers; the catalog conducts the conversation.
Structuring by Process: the Turtle Diagram
Derive the questions for each process and each interface from the six corners of a turtle diagram rather than from a clause list:
- Input — what triggers this process, and where does it come from?
- Output — what is produced, and how is conformity confirmed before it moves on?
- Resources — people, equipment, software: available when they are needed?
- Methods and criteria — which procedure applies, and does it match what actually happens?
- People — who does this, and what competence does it take?
- Performance — what is measured, and what happens when a value falls outside the limits?
The turtle diagram is a practitioner’s tool, not a requirement of any standard — and ISO 19011 sets no requirements in any case. That is precisely what makes it usable: six angles on the same process, with no prescribed wording.
Take incoming inspection. Instead of “do you follow work instruction WI-014?” — a closed question aimed at a document — ask: “walk me through what happens between a delivery arriving and the material being available in stock.” Then ask for the record of the last delivery that failed inspection.
Open Questions Instead of Closed Ones
Closed questions invite a rehearsed “yes.” Rewriting them is the single highest-leverage skill in building a catalog:
| Closed (weak) | Open (strong) |
|---|---|
| “Do you follow the procedure?” | “Describe what happens when a measured value falls outside tolerance.” |
| “Is the training up to date?” | “How do you know this person is qualified for this step?” |
| “Do you evaluate supplier performance?” | “Show me the last supplier evaluation and what came out of it.” |
| “Are nonconformities documented?” | “Tell me about the last nonconformity you handled here.” |
| “Is the calibration interval being met?” | “How do you notice that a gauge is coming due — and what happened the last time one slipped?” |
Open does not mean vague. “How do you ensure quality?” is not a good open question, it is an unanswerable one. Usable open questions attach to an event or an object — the last nonconformity, this gauge, this batch — and leave only the direction free, not the subject.
Triangulation: an Answer Is Not Evidence
An earlier version of this article carried a wrong reference here: 6.4.4. That was wrong in every edition, because 6.4.4 is “Communicating during the audit” in 2026 exactly as it was in 2018 [1].
The correct reference is 6.4.7, “Collecting and verifying information”, followed by 6.4.8, “Generating the audit findings” — both numbers identical across the two editions [1]. I will not reproduce what the standard recommends there; the text is paywalled. The titles alone carry the distinction that matters: collecting and verifying are two steps, not one, and the finding only comes into being afterwards, in a third. The evidence-based approach principle, numbered 4.7 in the 2026 edition, points the same way [1].
A well-built catalog forces that sequence instead of leaving it to the auditor’s memory. Every open question gets a fixed second step: “show me the last three records for that.” Not as an optional extra if time allows, but as its own line in the catalog. The interview answer is one source; the record, or the observation at the workstation, is the second and independent one.
The difference shows up later. A finding that rests on a statement can be argued away in the action meeting. A finding resting on three dated records cannot. And only the second kind supports a defensible root cause analysis — with the 5-Why method, for instance — rather than a cause line written to satisfy the auditor and nobody else. What happens from there is covered in the article on handling findings and corrective action.
Traceability: Tying Questions to Criteria
Every question should map to a specific clause or internal criterion, even when it is not asked in clause order. That is the difference between a catalog that works once and one you can analyze.
The value shows across several audits. If the question tied to 8.5.1, control of production, keeps producing findings across sites, that is a systemic signal — exactly what belongs in the management review, and exactly what a clause-blind catalog can never surface.
Right now there is a second payoff. ISO 9001:2026 moves numbers around: the combined clause 6.1 becomes separate subclauses for risks and for opportunities. A catalog whose questions are properly wired to criteria can be remapped; one where the mapping lives only in somebody’s head has to be rewritten. The consequences are set out in the article on ISO 9001:2026 and internal audits.
Letting the Catalog Mature Across Cycles
A question catalog is not a document you write once and reuse for five years. That is a maturity signal an experienced auditor picks up — “this checklist hasn’t changed since 2019” — and one of the things that genuinely gets noticed in the external audit.
Three movements keep a catalog alive. Questions that have gone several cycles without producing a finding, an improvement opportunity or even a follow-up question get cut or sharpened. New risks — a new machine, a supplier change, a complaint with its cause inside the process — generate new questions aimed precisely at them. And every finding from the last cycle becomes a follow-up question in the next.
Assessment: the most useful metric is not the length of the catalog but the share of questions that triggered anything at all in the last cycle. Below a third, you are mostly auditing documentation. No standard says this; it comes from watching audit programmes.
A Base Catalog and the Auditor’s Own Follow-Ups
Maintain a base catalog centrally — for consistency across sites and for bringing new auditors up to speed. At the same time, leave room for the follow-up questions that arise during the audit itself. The tension is real: too rigid, and the auditor stops listening; too loose, and results stop being comparable across auditors and sites.
The base catalog covers the defensible minimum. Anything beyond it is a feature of the process rather than a departure from it — provided the follow-up question ends up in the catalog afterwards, and not only in the audit report.
Where a Tool Makes the Difference
This is the point where a spreadsheet breaks. The link between question, criterion, finding and action has to survive for years before cross-audit analysis becomes possible at all. qportal therefore builds catalogs on a hierarchical audit criteria structure, so that every question stays connected to its criterion and to the findings it produced; the audit side is described under audit management.
Conclusion
A question catalog is not a retelling of the standard’s table of contents — and it is not a document ISO 19011 demands of you. None is demanded. It is the instrument that turns a conversation into evidence, and that is what it should be judged on.
Organized around the process, biased toward open questions, every question paired with a request for a record, and traceable to a criterion: built that way, it produces the kind of evidence that still holds up when the same nonconformity lands on the table six months later in the external audit.
And if you change only one thing, check the references in your catalog. Anyone citing 6.4.4 where 6.4.7 is meant has been repeating the same mistake across two editions.
Sources
First-degree sources — standardization
- ISO: ISO 19011:2026 — Guidelines for auditing management systems. Fourth edition, published 2026-05, stage 60.60, 46 pages, ISO/TMBG (prepared by ISO/PC 302 with CEN/CLC/JTC 1 under the Vienna Agreement). The same catalogue record shows ISO 19011:2018 (third edition) as withdrawn, stage 95.99. Foreword, clause 1 and the Introduction are freely available; clauses 4 to 7 are paywalled and are cited here by number and title only. https://www.iso.org/standard/19011 (accessed 2026-08-27)
- ISO 9001:2015, Quality management systems — Requirements, published as DIN EN ISO 9001:2015-11, Beuth Verlag, Berlin. Clauses used: 9.2.1 and 9.2.2 a) to f), including the Note referring to ISO 19011.
- ISO/TC 176 Auditing Practices Group: ISO 19011:2018 — Guidelines for auditing management systems. Guidance on the 2018 edition; not updated for the 2026 edition. https://committee.iso.org/files/live/sites/tc176/files/documents/ISO%209001%20Auditing%20Practices%20Group%20docs/Auditing%20General/APG-ISO_19011_2018.pdf (accessed 2026-08-27)
- ISO/IEC TS 17012:2024, Conformity assessment — Guidelines for the use of remote auditing methods in auditing management systems. The source of both changes named in the Foreword to ISO 19011:2026.
- ISO 9000:2026, Quality management — Fundamentals and vocabulary. Fifth edition, published May 2026; the terminological basis of ISO 19011:2026.
- DIN Media, catalogue records: DIN EN ISO 19011:2018-10, Leitfaden zur Auditierung von Managementsystemen, currently the German standard in force; DIN EN ISO 19011:2026-09, Leitlinien zur Auditierung von Managementsystemen, pre-publication record with a September 2026 publication date, 120 pages, bilingual (accessed 2026-08-27)
Normative text is protected by copyright; requirements and recommendations are paraphrased here rather than quoted. From the paywalled clauses 4 to 7 of ISO 19011, only numbers and titles are used. Consultancy, certification-body and content-marketing pages are not cited. Where this text goes beyond the documented evidence, it is marked as an assessment.
Frequently asked questions
- Does ISO 9001 require an audit question catalog?
- No. ISO 9001:2015 requires an audit programme in 9.2.2, defined audit criteria and scope for each audit, objective and impartial auditors, reporting to relevant management, and retained evidence. A question catalog appears nowhere in that list. It is a working tool for meeting those requirements — not a record an auditor could ask you to produce.
- Which edition of ISO 19011 is currently in force?
- Internationally, ISO 19011:2026 has been the fourth edition since May 2026, and ISO 19011:2018 is withdrawn. National adoptions lag: the German DIN EN ISO 19011:2018-10 is still the current national standard, with DIN EN ISO 19011:2026-09 announced for September 2026. Check your own national body before citing an adoption.
- Which clause of ISO 19011 covers verifying evidence?
- Clause 6.4.7, "Collecting and verifying information", followed by 6.4.8, "Generating the audit findings". Both numbers are identical in the 2018 and the 2026 editions. The frequently cited 6.4.4 is "Communicating during the audit" in both editions, and is therefore the wrong reference for anything to do with gathering and corroborating objective evidence.
- Can an auditor raise a nonconformity against ISO 19011?
- No. ISO/TC 176's Auditing Practices Group states that ISO 19011 is named in ISO 9001 only in a Note to clause 9.2, as an example. Notes carry no requirements. An auditor can therefore neither cite a requirement from ISO 19011 nor write a nonconformity against it. You may depart from its guidance — you should just be able to say why.
- How many questions should an audit question catalog contain?
- No standard names a number, and any number you are given is a guess. A more useful metric: how many of your questions have produced a finding, an improvement opportunity, or even a follow-up question across the last three audit cycles? Questions that never do cost audit time and return nothing. A short, sharp catalog beats a complete one.