AIMS Field Guides

ISO 19011:2026  ·  ISO/PC 302  ·  Implementation guide

The Management System
Audit, Assembled

The fourth edition, clause by clause — the seven principles, the programme, the audit itself, auditor competence, and what changed now that remote auditing is in the standard.

Designation
ISO 19011:2026
Title
Guidelines for auditing management systems
Edition
Fourth — May 2026
Committee
ISO/PC 302, with CEN/CLC/JTC 1
Replaces
ISO 19011:2018
Transition
None — guidance, effective on publication
How this document was built

The clause structure, scope, introduction, foreword statement of changes, all 27 defined terms and the bibliography below come from the publicly viewable sections of ISO 19011:2026 on the ISO Online Browsing Platform, with the full contents list confirmed against the publisher's document preview. The guidance text of clauses 4 to 7 and Annex A is not public, and none of it is reproduced here. Everything under “What it covers” and “In practice” is an implementation reading written to the clause title and to established audit practice. Buy the standard for the authoritative wording.

01What it is

ISO 19011 is the standard that tells you how to audit a management system — any management system — without turning the exercise into either a formality or an inquisition.

It is guidance, not requirements. There is no certification against it and no “shall” to fail. Its authority comes from being cited: nearly every management system standard requires internal audit, and nearly every one of them points here for how. ISO/IEC 42001 clause 9.2, ISO 27001 clause 9.2, ISO 9001 clause 9.2 — all require an internal audit programme, none explain how to run one, all defer to this document.

The 2026 edition is deliberately generic, and the introduction says why: since 2018 a wave of management system standards has arrived in new fields — AI, whistleblowing, occupational health, compliance, privacy — most sharing the harmonized structure. Rather than write auditing guidance per discipline, ISO wrote one document that audits against criteria, whatever those criteria happen to be. You can point it at a standard, at your own policies, at statutory requirements, at a project or quality plan, or at any combination.

Three structural ideas carry the whole document, and they are worth stating before the clause detail:

  • The programme is a thing, separate from the audits. Clause 5 governs the portfolio — objectives, risks, resourcing, scheduling, monitoring, improvement. Clause 6 governs a single audit. Organisations that skip clause 5 end up with a calendar of audits and no view of whether the calendar is covering the right things.
  • Evidence, then findings, then conclusions. Three defined terms in a strict chain, and most weak audits break the chain by starting from an opinion.
  • Risk-based. A principle in its own right since 2018 — depth, frequency and sampling should follow risk, not equal treatment of every process.

The document is explicitly aimed at first-party audits (internal) and second-party audits (of your suppliers and other external interested parties). For third-party certification, requirements sit in ISO/IEC 17021-1 — but 19011 remains useful additional guidance even there.

02What changed in 2026

The foreword is unusually specific. This is a technical revision, not a restructure — if you know the 2018 edition, the shape is intact and you are looking for two things.

ChangeWhereWhy it matters
Remote auditing methods brought into the standard, drawing on ISO/IEC TS 17012 Definitions, clause 5.5.3, clause 6 Remote auditing is now defined vocabulary with its own guidance, rather than an improvisation the pandemic forced on everyone. 3.4 remote auditing method is a new defined term, sourced from ISO/IEC TS 17012:2024.
Annex A expanded to cover remote auditing methods and virtual locations Annex A The practical how-to: what you can and cannot verify remotely, and how to audit an organisation whose work happens in an online environment with no site to visit.
Definitions realigned to ISO 9000:2026 Clause 3 Most terms are now sourced from the current quality vocabulary. The definition of audit itself gains “documented” and “objective” — a small edit that closes the gap where an undocumented walkaround could be called an audit.
Audit scope now names virtual locations 3.6, Note 1 Scope statements are expected to describe physical and virtual locations. For a distributed or cloud-native auditee this is the difference between a scope that means something and one that does not.
If you are updating from 2018

There is no transition period — guidance standards take effect on publication. The practical work is small: refresh your audit procedure's terminology against clause 3, add remote and hybrid method selection to your planning step (5.5.3), make sure audit scopes name virtual locations, and revisit auditor competence for anyone leading remote audits. Programmes that already ran remote audits well will find the standard has caught up with them rather than the reverse.

03Scope and the three parties

The scope covers four things: the principles of auditing, managing an audit programme, conducting audits, and evaluating the competence of everyone involved — programme managers, auditors and audit teams alike. It applies to any organisation that needs to plan and conduct management system audits or run a programme, and it can be stretched to other kinds of audit provided you think carefully about the competence needed.

The introduction sets out who audits whom. Table 1 of the standard distinguishes three:

PartyWho auditsTypical formGoverned by
First partyThe organisation audits itselfInternal auditISO 19011
Second partyThe organisation audits an external provider, or an interested party audits the organisationSupplier audit; customer auditISO 19011
Third partyAn independent body audits the organisationCertification audit; accreditation assessment; statutory and regulatory auditISO/IEC 17021-1 — 19011 useful in addition

The document also names two other uses that get overlooked: self-declaration — where you assert conformity without certification, and the audit is the evidence base for that assertion — and as a reference for organisations that train, qualify or certify auditors, which is why clause 7 is more detailed than an internal programme strictly needs.

Finally, it adopts the combined audit approach explicitly: two or more management systems of different disciplines audited together. Where those systems are already integrated into one, the principles and processes are the same. For an organisation running 9001, 27001 and 42001, this is the clause that authorises a single audit rather than three.

04The vocabulary

Twenty-seven terms, most now sourced from ISO 9000:2026. There are no normative references in this standard — clause 2 says so outright — so clause 3 is self-contained and worth reading properly.

The chain that decides audit quality

Five terms form a strict sequence. Getting them in the right order is most of what separates a rigorous audit from an opinionated one.

RefTermIn plain terms
3.8Audit criteriaThe set of requirements you compare against. Policies, procedures, work instructions, legal requirements, contractual obligations, industry standards. Where the criteria are legal, findings are phrased as compliance or non-compliance rather than conformity.
3.9Objective evidenceData supporting the existence or truth of something — obtained by observation, measurement, test or other means.
3.10Audit evidenceRecords, statements of fact or other information relevant to the criteria and verifiable. Verifiability is the gate: if nobody else could check it, it is not audit evidence.
3.11Audit findingThe result of evaluating collected evidence against the criteria. Findings indicate conformity or nonconformity — and may also identify risks, opportunities for improvement, or good practice worth recording.
3.12Audit conclusionThe result of the audit as a whole, after considering the objectives and all the findings. One conclusion per audit, not one per finding.

The rest, grouped

RefTermIn plain terms
3.1AuditA systematic, independent and documented process for obtaining objective evidence and evaluating it objectively against the criteria. Both “documented” and “objective” were added in this edition.
3.2Combined auditTwo or more management systems audited together at one auditee.
3.3Joint auditOne auditee, two or more auditing organisations. Distinct from combined — combined is about disciplines, joint is about who is doing the auditing.
3.4Remote auditing method NewConducting audit activities from anywhere other than the auditee's location. The notes are the useful part: remote methods can be mixed with on-site methods to make a full audit; they serve virtual locations, where work happens in an online environment irrespective of physical place; and an auditor at one of the auditee's sites can use them to audit another.
3.5Audit programmeArrangements for one or more audits planned for a specific time frame and directed at a specific purpose. Note it can be a programme of one.
3.6Audit scopeExtent and boundaries — physical and virtual locations, functions, organisational units, activities, processes, and the time period covered.
3.7Audit planDescription of the activities and arrangements for an audit.
3.13Audit clientThe organisation or person requesting the audit. For an internal audit this may be the auditee itself or the person managing the programme.
3.14AuditeeThe organisation, or the part of it, being audited.
3.15–3.16Audit team, auditorOne or more people conducting the audit, supported by technical experts if needed; one is appointed team leader. The team may include auditors-in-training.
3.17Technical expertSomeone providing specific knowledge — of the organisation, activity, process, product, service, discipline, language or culture. Explicitly does not act as an auditor.
3.18ObserverAccompanies the team but is neither auditor nor technical expert.
3.19Management systemInterrelated elements establishing policies, objectives and processes to achieve them. Can be one discipline or several; can span part of an organisation or several organisations.
3.20–3.27Risk, conformity, nonconformity, competence, requirement, process, performance, effectivenessThe harmonized-structure core, aligned to ISO 9000:2026 so that an auditor and an auditee are using words the same way.
Technical expert vs auditor

Clause 3.17's note is enforced in practice and catches people out. When you bring a data scientist into an AI management system audit because nobody on the team can evaluate model validation evidence, that person is a technical expert. They advise; they do not raise findings, and they do not count toward audit team competence for auditing. If you need them to audit, they need auditor competence under clause 7.

05Document map

PartTitleWhat it gives you
1–3Scope, normative references, termsNo normative references; 27 self-contained definitions
4Principles of auditingSeven principles (4.2–4.8) plus general
5Managing an audit programmeObjectives, risks and opportunities, establishing, implementing, monitoring, improving
6Conducting an auditInitiating, preparing, conducting, reporting, completing, following up
7Competence and evaluation of auditorsDetermining, establishing criteria, selecting method, evaluating, maintaining
AAdditional guidance for auditors for planning and conducting audits InformativeThe practical annex — expanded in this edition for remote methods and virtual locations
Reading order

Clause 4 first, and slowly — the principles are what you fall back on when the standard does not answer the question in front of you, which happens constantly in a real audit. Then clause 6 if you are about to audit, or clause 5 if you are about to design a programme. Clause 7 when you are selecting or evaluating auditors. Annex A is a working reference to keep open during planning, not something you read end to end.

06Clause 4 — The principles

Seven principles. They are not preamble: they are the resolution mechanism for every judgement call the guidance does not cover, and experienced auditors reason from them explicitly.

4.2

Integrity

The foundation of professionalism. Auditors work honestly, competently and within the law, and do not let pressure — commercial, hierarchical or social — change what they report. It is the principle that costs something to apply, which is why it is listed first.

4.3

Fair presentation

Report truthfully and accurately: findings, conclusions and the report itself reflect the audit as it happened, including significant obstacles, unresolved disagreements and matters left unverified. If you could not get to something, the report says so rather than passing over it.

4.4

Due professional care

Diligence and judgement proportionate to the importance of the task and the confidence placed in the audit by the client and other interested parties. It is the licence to go deeper where it matters and lighter where it does not — and the obligation to know which is which.

4.5

Confidentiality

Information acquired during the audit is used with discretion and protected. Auditors see commercially sensitive material, personal data and internal disagreement; none of it travels beyond the audit's legitimate purpose.

4.6

Independence

The basis for impartiality and objectivity. Auditors should be independent of the activity being audited wherever practicable, and free from bias and conflict of interest throughout. In a small organisation full independence is often impossible — the standard's expectation is then that you manage and disclose the compromise, not that you pretend it away.

4.7

Evidence-based approach

The rational method for reaching reliable and reproducible conclusions in a systematic audit process. Evidence is verifiable, and because auditing works by sampling, confidence is a function of how the sample was chosen — which is where this principle and the next meet.

4.8

Risk-based approach

Consider risks and opportunities throughout — in the programme, in what you audit, in how deeply, in what you sample. The principle that turns an audit from uniform coverage into a purposeful one, and the one most often honoured only in the programme document.

Where the principles get tested

Independence and integrity in internal audit at small organisations. The person best qualified to audit a process usually built it. There is no clean answer, and the standard does not pretend otherwise — what it expects is that the conflict is identified, managed (a second reviewer, a rotation, an external pair of eyes on the highest-risk areas), and recorded, rather than resolved by declaring the auditor objective and moving on.

07Clause 5 — Managing the audit programme

The portfolio view. Established once, run continuously, and reviewed like anything else that has objectives.

5.1

General

A programme can cover one or more audits, one or more standards, and multiple sites — and it should be planned as a whole rather than as a series of separately negotiated events.

5.2

Establishing audit programme objectives

What the programme is for, in terms that could fail. Not “audit everything annually” but something like: verify conformity, evaluate effectiveness, identify improvement opportunities, satisfy a contractual or regulatory expectation, prepare for certification.

In practice  Objectives should be traceable to management priorities and to risk, and revisited when either shifts.

5.3

Determining and evaluating audit programme risks and opportunities

Risks to the programme, distinct from the risks it examines: insufficient resource, auditors who lack competence, schedules repeatedly deferred, sampling that never reaches a difficult area, loss of independence, poor communication with the auditee. And the opportunities — combining audits, using remote methods to reach places you could not afford to visit, sharing findings across disciplines.

5.4

Establishing the audit programme

Four parts. 5.4.1 roles and responsibilities of the person or people managing the programme. 5.4.2 their competence — a distinct requirement from auditor competence, and one that is regularly overlooked. 5.4.3 the programme's extent: standards, sites, functions, processes, time frames, and how frequency follows risk. 5.4.4 resources — people, time, travel, tools, and the technology that remote methods depend on.

In practice  5.4.3 is where the risk-based principle either bites or does not. If every process gets the same slot every year regardless of exposure, the programme is a calendar.

5.5

Implementing the audit programme

Seven parts, and the operational heart of clause 5.

5.5.1 general. 5.5.2 defining the objectives, scope and criteria for each individual audit — the three that must be settled before anyone plans anything. 5.5.3 selecting and determining auditing methods, now including remote and hybrid combinations. 5.5.4 selecting the team, for collective competence and impartiality. 5.5.5 assigning responsibility to the team leader. 5.5.6 managing programme results. 5.5.7 managing audit records.

In practice  5.5.2 is the step most often skipped. Objectives, scope and criteria written down and agreed with the auditee in advance prevent nearly every downstream argument about whether something was in scope.

5.6

Monitoring the audit programme

Is it delivering against its objectives? Track completion against plan, finding patterns, auditor performance, feedback from auditees and the audit client. Deferrals are the leading indicator worth watching — a programme that slips repeatedly in one area is telling you something about that area.

5.7

Reviewing and improving the audit programme

Feed results back: adjust scope, frequency, methods, team composition and competence. This is the loop, and it is what makes the programme a managed thing rather than a recurring obligation.

08Clause 6 — Conducting an audit

A single audit, start to finish. Six stages after the general clause, and clause 6.4 alone has ten sub-steps — the standard is unusually granular here because this is where audits actually go wrong.

6.2

Initiating the audit

6.2.1 general. 6.2.2 establishing contact with the auditee — confirming authority, communication channels, arrangements, confidentiality, access, and any guides or observers. 6.2.3 determining the feasibility of the audit: is there enough information, cooperation, resource and time to do it properly? If not, propose an alternative rather than proceed to a weak audit.

In practice  6.2.3 is a permission most auditors forget they have. Declaring an audit infeasible is a legitimate outcome, and far more useful than a report that had to hedge every conclusion.

6.3

Preparing auditing activities

6.3.1 reviewing documented information to understand the system and prepare — and to spot gaps before you arrive. 6.3.2 audit planning: risk-based, sized to the scope, covering timing, locations both physical and virtual, methods and roles. 6.3.3 assigning work to the team. 6.3.4 preparing the documented information you will use — checklists, sampling plans, forms.

In practice  A checklist is a memory aid, not a script. Auditors who cannot leave it when the evidence points elsewhere find only what the checklist already anticipated.

6.4

Conducting auditing activities

The ten steps that make up the audit itself:

6.4.1 general  ·  6.4.2 assigning roles and responsibilities of guides and observers  ·  6.4.3 the opening meeting  ·  6.4.4 communicating during the audit  ·  6.4.5 providing access to audit information  ·  6.4.6 reviewing documented information while conducting the audit  ·  6.4.7 collecting and verifying information  ·  6.4.8 generating the audit findings  ·  6.4.9 determining the audit conclusions  ·  6.4.10 the closing meeting.

Note the sequence at 6.4.7 → 6.4.8 → 6.4.9: collect and verify, then evaluate against criteria to generate findings, then consider all findings together to reach conclusions. Unverified information never becomes a finding, and a single finding never becomes the conclusion.

In practice  6.4.4 is what prevents surprises at the closing meeting. Potential findings raised as they emerge give the auditee a chance to produce evidence you had not seen — which is the point, not a concession.

6.5

Preparing and distributing the audit report

6.5.1 preparing it — a complete, accurate, concise and clear record of the audit. 6.5.2 distributing it, to the agreed recipients within the agreed period.

In practice  Late reports lose most of their value. Findings act on decisions being made now; a report arriving weeks later arrives after them.

6.6

Completing the audit

The audit is complete when planned activities are done or otherwise agreed with the client. Retain or dispose of documents per agreement; handle lessons learned; feed them into 5.7.

6.7

Conducting the audit follow-up

Conclusions may require correction, corrective action or improvement. The auditee owns those actions; the audit programme verifies completion and effectiveness. Note the word: effectiveness, not completion. An action closed but ineffective is still an open finding.

In practice  Follow-up is where internal audit programmes most commonly decay — findings raised, actions logged, effectiveness never checked. Build verification into the next audit's scope rather than treating it as an administrative task.

09Clause 7 — Competence and evaluation of auditors

Confidence in an audit rests on the competence of whoever performed it. Clause 7 makes that assessable rather than assumed.

7.1

General

Competence should be evaluated through a process that considers personal behaviour and the ability to apply knowledge and skills — gained through education, work experience, auditor training and audit experience.

7.2

Determining auditor competence

7.2.1 general — determine competence against the programme's needs and the specific audits. 7.2.2 personal behaviour: ethical, open-minded, diplomatic, observant, perceptive, versatile, tenacious, decisive, self-reliant, open to improvement, culturally sensitive, collaborative. This is a real and enforceable part of the standard, not a soft list — a technically excellent auditor who cannot get people to speak candidly will not find anything.

7.2.3 knowledge and skills — of audit principles and methods, of management system standards, of the organisation and its context, of applicable legal and other requirements, and of the discipline and sector. 7.2.4 how auditor competence is achieved. 7.2.5 the additional competence an audit team leader needs, which is largely about managing a team, a client relationship and a difficult closing meeting.

In practice  Sector and discipline knowledge is where teams are usually thin. An auditor who does not understand the process being audited will accept a plausible explanation, and plausible explanations are exactly what a weak process produces.

7.3

Establishing the auditor evaluation criteria

Qualitative and quantitative criteria against which auditors are assessed — behaviour, knowledge and skills, education, experience, training, audits performed.

7.4

Selecting the appropriate auditor evaluation method

Records review, feedback, interview, observation, testing, post-audit review. More than one, since none alone tells you much.

7.5

Conducting the auditor evaluation

Apply the criteria using the chosen methods and record the result — including where the answer is that the auditor is not yet competent for a particular audit.

7.6

Maintaining and improving auditor competence

Continual development: participating in audits, training, updating on standards and sector change, coaching. Competence lapses — an auditor who has not audited in two years has decayed regardless of what the certificate says.

10Annex A

Annex A (informative) — Additional guidance for auditors for planning and conducting audits. The practical companion to clauses 5 and 6, and the annex the foreword singles out as expanded in this edition to cover remote auditing methods and virtual locations.

It is where the standard gets concrete about technique rather than structure — how to apply a process approach, how to exercise professional judgement, how to sample, how to audit against different kinds of criteria, and now how to do all of that when there is no site to walk. If you are training auditors, this is the section that translates most directly into practice.

11Remote and hybrid auditing

The headline change of the fourth edition. Remote auditing is now a defined method with a home in the standard, drawing on ISO/IEC TS 17012:2024.

The definition at 3.4 is broad: conducting audit activities from any place other than the auditee's location. Its three notes carry the practical implications, and each is doing work.

  • Remote combines with on-site. Explicitly. A hybrid audit is not a compromise or a degraded audit — it is a legitimate design, and for many auditees the best one.
  • Virtual locations are auditable places. Where an organisation performs work or provides a service in an online environment, that environment is a location within scope, whatever the geography of the people executing the processes. For SaaS, distributed engineering and remote-first organisations, this closes a gap the 2018 edition left open.
  • Site-to-site remote counts. An auditor physically at one of the auditee's sites can use remote methods to audit another. Useful in multi-site programmes where travel budget is the binding constraint on coverage.

Choosing the method

Method selection sits at 5.5.3, and the honest question is what each method can actually verify.

Remote does well

  • Documented information review
  • Records and system data sampling — often better than on-site, with live access to the real system
  • Interviews with dispersed people
  • Configuration, logging, access control and other things that are digital
  • Auditing an organisation whose work has no physical location
  • Reaching sites a travel budget would never cover

Remote does badly

  • Observing physical process, plant and conditions
  • Reading the room — the unprompted aside, the hesitation, the thing someone mentions in a corridor
  • Following an unplanned thread; screen-shares tend to show what was prepared
  • Verifying that what is documented matches what is done, where doing is physical
  • Culture and tone, which are much of what tells an experienced auditor where to look
Practical constraints to plan for

Connectivity and the technology on both sides — 5.4.4 resources now has to account for it. Confidentiality when screens are shared and sessions may be recorded: agree recording, retention and consent before the opening meeting, not during it. Evidence integrity, since you are seeing a screen rather than a record. Time zones and audit fatigue — remote days should be shorter than on-site days, and programmes that transplant an eight-hour schedule onto video get thin evidence in the afternoon. And decide in advance what you will do when something cannot be verified remotely: fair presentation (4.3) requires the report to say so rather than quietly conclude anyway.

12Writing findings that hold

Not a clause of the standard, but the practical distillation of 3.8 through 3.12 and clause 6.4.8. A finding that cannot survive being questioned is worse than no finding — it costs the programme credibility it will need later.

Every finding needs four parts, and it is worth checking each explicitly before it goes in the report.

1

The requirement

  • The specific criterion, cited precisely — clause, policy section, contractual term, statutory provision
  • Quoted or paraphrased accurately enough that the auditee can find it
  • Weak version: “good practice would suggest…” — if it is not in the criteria, it is an opportunity, not a nonconformity
2

The evidence

  • What you saw, with identifiers — document reference and version, record ID, date, system, who said it and in what role
  • Verifiable: someone else could go and look at the same thing
  • Weak version: “several records were found to be incomplete” — which records?
3

The gap

  • The plain statement of how the evidence fails to meet the requirement
  • One sentence, no hedging, no adjectives
  • Weak version: a paragraph of context that never quite says what is wrong
4

The classification

  • Nonconformity, or opportunity for improvement, or good practice worth recording — 3.11 admits all three
  • Where criteria are legal, the vocabulary changes to compliance / non-compliance
  • Consistent across the programme, so severity means the same thing in every report
Two habits worth keeping

Do not write the fix. The finding states the gap; the auditee determines the cause and the action. An auditor who prescribes the remedy has taken ownership of a problem that is not theirs, and has made themselves un-independent for the follow-up.

Record good practice. 3.11's second note allows it and few programmes use it. A report containing only nonconformities trains the organisation to treat audit as a threat, and an audit people are defending against yields much less than one they are helping.

13Programme and plan templates

Two artefacts, built from clauses 5 and 6.3.2. Keep them short — the value is in the thinking they force, not in their length.

The audit programme

5.2

Objectives

  • What this programme is for, in terms that could fail
  • Traceable to management priorities, risk, and any contractual or regulatory driver
  • Period covered
5.3

Programme risks and opportunities

  • Risks to the programme itself, with treatment
  • Opportunities: combined audits, remote methods extending coverage, shared findings
5.4

Extent and resources

  • Standards and criteria in scope; sites, functions, processes, virtual locations
  • Schedule, with frequency justified by risk — say why a high-risk process is audited more often
  • Person managing the programme, their authority and their competence
  • Resources: auditor days, travel, tools, technology for remote methods
5.5–5.7

Operation and review

  • How individual audit objectives, scope and criteria get set
  • Method selection: on-site, remote, hybrid — and on what basis
  • Team selection and impartiality safeguards
  • Records: what is kept, where, for how long
  • Monitoring measures, and when the programme is reviewed

The audit plan

6.3.2

Per audit

  • Objectives — what this audit is to establish
  • Scope — units, functions, processes, physical and virtual locations, period covered
  • Criteria — the exact requirements being audited against, with references
  • Team members and roles; technical experts; observers; guides
  • Dates, times, durations, locations, and the methods for each activity
  • Opening and closing meeting arrangements
  • Communication arrangements during the audit, including how potential findings are raised
  • Access arrangements: systems, records, people, sites; confidentiality and any recording consent
  • Risks to achieving the audit, and contingencies
  • Reporting: format, recipients, date
  • Follow-up arrangements and who verifies effectiveness

14Auditing an AI management system

Where this guide meets its companions. ISO/IEC 42001 clause 9.2 requires internal audit; ISO 19011 is how you run it; and an AI management system puts specific pressure on three parts of this standard.

Competence (7.2.3) is the binding constraint

Auditing an AIMS demands discipline knowledge that most internal audit functions do not have: enough understanding of model development, evaluation and monitoring to know whether validation evidence is meaningful, and enough of the impact side to know whether an assessment has actually reasoned about harm to people. Two routes, and both are legitimate — build the competence in the audit team, or bring a technical expert under 3.17 who advises while the auditor audits. What does not work is an auditor who accepts “the model was validated” as evidence because they have no basis to ask what that meant.

Criteria (3.8) are broader than the standard

An AIMS audit's criteria include ISO/IEC 42001 clauses 4–10, plus every Annex A control marked applicable in the Statement of Applicability, plus your own AI policy, plus applicable legal requirements. The SoA is the natural spine for the audit plan: each applicable control is a criterion with an implementation claim attached, and each claim is a thread to pull.

Sampling (4.7, 4.8) has to reach the systems

The characteristic failure is auditing the paperwork about AI rather than the AI. A risk-based sample should reach into actual AI systems: pick a deployed system, then trace it — is it on the inventory, does it have a current impact assessment, does that assessment name the version running, were the mitigations implemented, is the monitoring live, did anything happen when a threshold was crossed, was the last model change re-assessed under clause 6.3?

A thread that usually finds something

Take the AI system inventory from clause 4, pick the system with the highest impact rating, and walk it end to end against its own records. Then take a system that was changed in the last quarter and ask what re-assessment the change triggered. The gap between the governance documentation and the deployed reality — the model that was retrained, the oversight step dropped for throughput, the review date that passed — is almost always found this way, and almost never found by reading policies.

Two of these companion guides cover the standards on the other side of that audit: ISO/IEC 42001 — the AI management system and ISO/IEC 42005 — AI system impact assessment.

15Where it goes wrong

A calendar instead of a programme

Every process audited annually, regardless of risk, change or history. It satisfies clause 9.2 of whatever standard requires internal audit and it discharges none of clause 5 here. The risk-based principle exists precisely to break this pattern.

Conclusions ahead of evidence

The auditor knows what is wrong before arriving and collects evidence that confirms it. The chain runs criteria → evidence → findings → conclusions; run in reverse it is an inspection with a predetermined answer.

Independence declared rather than managed

The process owner audits their own process because nobody else understands it. The standard's expectation is not that this never happens — it is that when it does, the conflict is identified, mitigated and recorded.

Findings with no verifiable evidence

“Records were inconsistent.” Which records, on what date, inconsistent with what requirement? An unverifiable finding cannot be argued with, which sounds like a strength and is a fatal weakness — it will be dismissed the moment it becomes inconvenient.

Follow-up that checks closure, not effectiveness

Clause 6.7 asks whether the action worked. A log full of actions marked complete, with the same nonconformity recurring the following year, is the visible symptom.

Auditors trained once

Clause 7.6 asks for maintenance and improvement. Competence decays — through disuse, through standards being revised, through the organisation changing around the auditor.

Reports too late to act on

Weeks after the closing meeting, into a decision cycle that has already moved. Agree the reporting date in the plan and treat it as a commitment.

Remote by default, without asking what it can verify

The new material makes remote auditing legitimate; it does not make it universally sufficient. Where the evidence is physical, remote methods will produce a confident report about things nobody actually saw.

16What it will not do

  • It is not certifiable, and it is not a competence scheme. Guidance only. Auditor certification schemes are run by other bodies against their own criteria.
  • It does not govern third-party certification. Requirements for certification bodies are in ISO/IEC 17021-1. 19011 is useful additional guidance, not the rulebook.
  • It does not tell you what “good” looks like in your discipline. It tells you how to audit against criteria. The criteria and the domain judgement come from elsewhere.
  • It does not make an audit find anything. Audits sample. A clean report means the sample was clean, and a well-run programme is honest about that in the way it words conclusions.
  • It will not fix a system nobody wants audited. Where leadership treats findings as an attack, the programme degrades into findings nobody minds — and the standard has no mechanism for that. Clause 5.1 of whatever management system you are auditing does.

17Sources

  • ISO 19011:2026 on the ISO Online Browsing Platform — foreword (including the statement of changes), introduction, scope, all 27 terms and the bibliography are publicly viewable. Clauses 4–7 and Annex A are not.
  • ISO catalogue entry — ISO 19011:2026. Full contents list including all subclause numbering and Annex A confirmed against the publisher's document preview.
  • Cited in the standard's bibliography: ISO 9000:2026 (quality management vocabulary — the source of most definitions), ISO/IEC TS 17012:2024 (remote auditing methods), ISO/IEC 17021-1 (requirements for certification bodies), and the ISO 9001 Auditing Practices Group papers.
  • Publication date and edition confirmed via the CQI/IRCA Knowledge Hub.
  • Companion guides in this series: ISO/IEC 42001 and ISO/IEC 42005.
Copyright

ISO 19011:2026 is a copyrighted work of ISO. Nothing here reproduces its guidance text; clause titles are cited as references, and the publicly viewable scope and definitions are paraphrased. This is an independent implementation reading, not a substitute for the standard, and not endorsed by ISO. Purchase the standard before relying on it for audit programme work.