ISO 19011
ISO 19011: the guidance for conducting audits
ISO 9001 says that you must audit. ISO 19011 says how — and it contains exactly the points where internal audit programmes fail in practice.
The points that make the difference in practice
The process approach instead of clause order. ISO 19011 suggests running audits along real processes rather than the structure of the standard. A question catalog that works through clauses 4 to 10 reliably produces yes answers. A catalog that follows a process from enquiry to delivery finds the breaks. More in the article on the audit question catalog.
Risk-based programme planning. What binds here is not ISO 19011 but ISO 9001 9.2.2 a) — and it names exactly three factors: the importance of the processes concerned, changes affecting the organization, and the results of previous audits. ISO 19011 gives audit programme risks and opportunities a subclause of their own, 5.3 (“Determining and evaluating audit programme risks and opportunities”), as guidance. The most common failure is copying last year’s plan.
Independence as a system property. ISO 19011 carries independence as one of its auditing principles (2026 edition: its own subclause 4.6; 2018 edition: an unnumbered lettered item in clause 4) and, being guidance, leaves room where full independence is not practicable. ISO 9001 9.2.2 c) requires objectivity and impartiality to be ensured without any such qualifier. If the check only happens during the certification audit, it is too late — which is why qportal warns automatically when auditor and audited org unit coincide.
Confirmation by the auditee. Generating audit findings has its own subclause in ISO 19011, 6.4.8 (“Generating the audit findings”); the normative text is paywalled and is not reproduced here. qportal models confirmation by the audited organisation as its own state in the lifecycle of a finding, so that the step cannot quietly disappear.
Competence as an ongoing process. Clause 7 spreads auditor evaluation across four subclauses (7.3 to 7.6) and closes on “Maintaining and improving auditor competence” — as guidance, not as a requirement. A 2019 certificate in a personnel file still does not amount to an ongoing process.
Link to the implementation
How the audit programme, question catalogs, independence check and auditee confirmation work together is described on the audit management page.
Frequently asked questions
- Can you be certified against ISO 19011?
- No. ISO 19011 is guidance, not a requirements standard. Organisations are not certified against it, but certification auditors refer to it and internal audit programmes are regularly measured against it.
- What does ISO 19011 say about auditor independence?
- Independence is one of ISO 19011's auditing principles — numbered as its own subclause 4.6 in the 2026 edition, and an unnumbered lettered item in clause 4 in the 2018 edition. Being guidance, ISO 19011 leaves room where full independence is not practicable. ISO 9001 grants no such room: 9.2.2 c) requires the objectivity and impartiality of the audit process to be ensured, without qualification — and an external auditor can raise a nonconformity against that requirement, but not against ISO 19011.
- Is knowledge of the standard sufficient auditor competence?
- No — the structure of clause 7 ("Competence and evaluation of auditors") already shows it. Personal behaviour sits there as its own subclause, 7.2.2, alongside 7.2.3 "Knowledge and skills", and within knowledge and skills the standard separates 7.2.3.2 "Generic knowledge and skills of management system auditors" from 7.2.3.3 "Discipline-specific and sector-specific competence of auditors". Nor is competence a one-off: 7.3 to 7.5 cover the evaluation criteria, the evaluation method and conducting the evaluation, and 7.6 covers maintaining and improving it. Clauses 4 to 7 are paywalled; only numbers and titles are given here.