ISO 19011:2026 is the current edition of the international guidance standard for auditing management systems. Published on 27 May 2026 as the fourth edition, it replaced ISO 19011:2018 and is used by internal auditors, supplier (second-party) auditors, and certification bodies across every major ISO standard — including ISO 9001:2015, ISO 14001, ISO 45001:2018 and ISO/IEC 27001:2022.
This guide, reviewed and updated in August 2026, explains what changed in the 2026 edition, how the seven principles of auditing apply in practice, and how to bring your internal audit program in line with the new guidance — with a practical transition checklist at the end.
Last reviewed: 11 August 2026.
What is ISO 19011?
ISO 19011 is the international standard that provides guidelines for auditing management systems. It is not a certifiable standard — organisations do not get certified against ISO 19011 itself. Instead, it provides the principles, guidance, and best practices that auditors, audit program managers, and organisations use when conducting management system audits.
ISO 19011 is used by:
- Internal auditors conducting first-party audits of their own organisation's management systems
- Supplier auditors conducting second-party audits of supplier management systems
- Certification body auditors conducting third-party certification audits
- Audit program managers responsible for planning and overseeing audit activities
- Organisations seeking to understand what to expect from a management system audit
ISO 19011:2026 — What's New?
ISO 19011:2026 is the fourth edition of the standard, succeeding ISO 19011:2018. The 2026 revision reflects the evolving landscape of management system auditing — including the growing adoption of remote and virtual auditing, the increased use of technology in audit processes, and the broader range of management system standards now in use globally.
Key updates and enhancements in ISO 19011:2026 include:
1. Enhanced Guidance on Remote and Virtual Auditing
ISO 19011:2026 significantly expands guidance on conducting audits remotely — including video conferencing, digital document review, and virtual site inspections. This reflects the widespread adoption of remote auditing methods that accelerated following the COVID-19 pandemic and are now an established part of modern audit practice.
2. Updated Competence Requirements for Auditors
The 2026 edition updates and expands the competence requirements for auditors — reflecting the broader range of management system standards now in use, including ISO/IEC 42001:2023 (AI Management), ISO 28000:2022 (Supply Chain Security), and other recently published standards. Auditors are now expected to demonstrate competence relevant to the specific standards and sectors they audit.
3. Strengthened Risk-Based Audit Planning
ISO 19011:2026 places greater emphasis on risk-based thinking in audit program management — aligning with the risk-based approach embedded in modern ISO management system standards. Audit programs should be designed to prioritise areas of greatest risk and organisational significance.
4. Guidance on Auditing Integrated Management Systems
As more Australian organisations adopt Integrated Management Systems (IMS) combining ISO 9001, ISO 14001, ISO 45001, and ISO/IEC 27001, ISO 19011:2026 provides updated guidance on planning and conducting integrated audits across multiple standards simultaneously — improving efficiency and reducing audit fatigue.
5. Updated Guidance on Audit Evidence and Sampling
The 2026 edition strengthens guidance on collecting and evaluating audit evidence — including digital records, automated system outputs, and data analytics. This reflects the increasing use of digital management systems and cloud-based platforms in modern organisations.
6. Alignment with Current ISO Management System Standards
ISO 19011:2026 is fully aligned with the current versions of all major ISO management system standards — ensuring the audit guidance remains relevant and applicable across the full suite of standards organisations are certified to today.
ISO 19011:2018 vs ISO 19011:2026 — What Actually Changed
| Area | ISO 19011:2018 | ISO 19011:2026 |
|---|---|---|
| Remote / virtual auditing | Brief mention in Annex | Full guidance on planning, evidence and technology for remote audits |
| Risk-based approach | Introduced as a principle | Strengthened — risk now drives audit program planning end to end |
| Auditor competence | Generic competence requirements | Updated for newer standards (e.g. ISO/IEC 42001:2023 for AI, ISO 28000:2022 for supply chain security) |
| Integrated audits | Limited guidance | Dedicated guidance for auditing integrated management systems in one audit |
| Audit evidence & sampling | Traditional evidence focus | Expanded methods, including electronically collected evidence |
| The 7 principles | Defined | Unchanged in substance — practical guidance expanded |
The short version: if your internal audit procedure was written against the 2018 edition, it is not wrong — but it should be reviewed. The gaps that show up most often are remote-audit protocols and risk-based audit scheduling.
The 7 Principles of Auditing — ISO 19011:2026
ISO 19011:2026 retains and refines the seven core principles of auditing that underpin all management system audits:
- Integrity — the foundation of professionalism. In practice: auditors declare any conflict of interest before accepting an audit.
- Fair presentation — report truthfully and accurately. In practice: significant obstacles met during the audit appear in the report, not only the findings.
- Due professional care — diligence and judgement. In practice: audit time is planned to match the complexity of the process being audited.
- Confidentiality — protect information acquired during audits. In practice: audit evidence is stored securely and is not shared with third parties.
- Independence — remain impartial and free of bias. In practice: internal auditors do not audit their own department's work.
- Evidence-based approach — conclusions rest on verifiable evidence. In practice: every nonconformity in the report traces to a specific record, observation or interview.
- Risk-based approach — consider risks and opportunities throughout. In practice: processes with recent failures or changes are audited more often than stable ones.
What Does ISO 19011:2026 Cover?
ISO 19011:2026 provides guidance across the full audit lifecycle:
Managing an Audit Program
Guidance for audit program managers on establishing, implementing, monitoring, reviewing, and improving an audit program — including determining audit objectives, scope, frequency, and methods based on organisational risk and significance.
Planning and Conducting Audits
Step-by-step guidance for audit team leaders and auditors on planning individual audits — including defining scope and criteria, forming the audit team, preparing audit plans, conducting opening meetings, collecting and verifying evidence, and documenting findings.
Audit Competence and Evaluation
Detailed guidance on the knowledge, skills, and personal attributes required of management system auditors — including generic competence applicable to all management systems and specific competence requirements for individual standards (ISO 9001, ISO 14001, ISO 45001, ISO/IEC 27001, etc.).
Reporting and Follow-Up
Guidance on preparing audit reports, distributing findings, and following up on corrective actions — ensuring audit outcomes drive genuine improvement in the management system.
Why ISO 19011:2026 Matters for Australian Businesses
For Australian businesses with certified management systems, ISO 19011:2026 is relevant in several important ways:
Internal Audit Programs
All ISO management system standards — including ISO 9001:2015, ISO 14001, ISO 45001:2018, and ISO/IEC 27001:2022 — require organisations to maintain an internal audit program. ISO 19011:2026 provides the guidance your internal auditors need to conduct effective, credible internal audits that genuinely assess management system performance.
Preparing for Certification Audits
Understanding how certification audits are conducted — as outlined in ISO 19011:2026 — helps Australian businesses prepare more effectively for Stage 1 and Stage 2 certification audits conducted by bodies like UCS. Knowing what auditors look for and how evidence is evaluated reduces surprises and improves audit outcomes.
Supplier Auditing
Australian businesses that audit their suppliers' management systems — particularly in construction, mining, food production, and government supply chains — benefit from the updated guidance on planning and conducting second-party supplier audits.
Building Internal Audit Capability
ISO 19011:2026 provides a clear competence model for developing internal auditor capability — helping Australian businesses invest in training and upskilling their audit teams to the current international benchmark.
ISO 19011:2026 and UCS Certification Audits
At UCS, our certification auditors operate in accordance with the principles and guidance of ISO 19011:2026 — as well as the requirements of ISO/IEC 17021-1:2015, which governs accredited certification body operations.
When UCS conducts a certification audit of your management system — whether for ISO 9001:2015, ISO 14001, ISO 45001:2018, ISO/IEC 27001:2022, or any other standard — our auditors apply the ISO 19011:2026 principles of independence, objectivity, and evidence-based assessment.
Understanding ISO 19011:2026 helps Australian organisations:
- Understand what to expect from a UCS certification audit
- Prepare internal audit programs that meet ISO standard requirements
- Build internal audit competence that strengthens management system performance
- Engage more effectively with auditors during Stage 1 and Stage 2 certification audits
How to Get ISO 19011:2026 (and What It Costs)
ISO 19011:2026 is a copyrighted standard, so the official PDF is only available for purchase:
- iso.org — the official ISO Store sells the current 2026 edition.
- Free copies circulating online are unauthorised, and are often outdated or altered. Avoid them, particularly for audit procedures your certification depends on.
You do not need to buy the standard to be certified. ISO 19011 is guidance for auditors. When UCS audits your organisation, our auditors already work to it. You only need your own copy if you run an internal audit program and want to align it word for word with the guidance.
Transition Checklist — Updating Your Audit Program from 2018 to 2026
If your internal audit program was built on ISO 19011:2018, these six steps cover the work:
- Update document references — replace "ISO 19011:2018" with "ISO 19011:2026" in your audit procedure, audit program and templates.
- Add a remote-audit protocol — define when remote auditing is acceptable, what technology is used, and how evidence is captured and verified.
- Make the audit schedule risk-based — record why each process gets the audit frequency it does, and increase frequency after failures, changes or incidents.
- Review auditor competence records — check that your auditors' training covers the standards you actually hold, and refresh anything still written against the 2018 edition.
- Consider integrated audits — if you hold more than one certification (for example ISO 9001:2015 and ISO 45001:2018), plan combined audits using the new integrated-audit guidance.
- Brief your team before your next external audit — certification auditors will themselves be working to ISO 19011:2026, so expect more questions about risk and about remote evidence.
Your next UCS surveillance or certification audit will look at exactly these areas. Request a free assessment to discuss timing with an auditor.
ISO 19011:2026 — Common Questions
What is the latest version of ISO 19011?
ISO 19011:2026 is the current, latest edition of the standard, replacing ISO 19011:2018. Australian organisations updating their internal audit programs should reference the 2026 edition going forward, particularly for guidance on remote auditing and integrated management system audits.
What changed between ISO 19011:2018 and ISO 19011:2026?
The 2026 edition strengthens guidance in several areas: remote and virtual auditing techniques, updated auditor competence requirements, more detailed risk-based audit planning, guidance for auditing integrated management systems, and revised approaches to audit evidence and sampling. The seven auditing principles remain unchanged, but the practical guidance around applying them has been significantly expanded.
Is ISO 19011 a certifiable standard?
No. ISO 19011 is a guidance standard for auditing management systems — it cannot be certified against, unlike ISO 9001, ISO 14001, or ISO 45001. Instead, ISO 19011:2026 informs how audits (both internal audits and third-party certification audits) should be planned and conducted. UCS auditors apply ISO 19011:2026 principles when conducting certification audits against certifiable standards.
Does ISO 19011 only apply to internal audits?
No. While ISO 19011:2026 is widely used to structure internal audit programs, its guidance applies equally to second-party audits (such as supplier audits) and third-party certification audits conducted by accredited bodies like UCS. Any organisation planning or conducting a management system audit of any type can apply its principles.
Is ISO 19011:2026 mandatory for ISO 9001 certification?
No. ISO 19011 is guidance, not a requirement. ISO 9001:2015 does require an internal audit program, and ISO 19011:2026 is the recognised guidance for running one, so certification auditors will expect your program to broadly reflect its principles.
When do we have to stop using ISO 19011:2018?
There is no formal deadline, because guidance standards carry no certification transition period. The 2018 edition is superseded, so procedures that reference it should be updated at your next document review.
Does ISO 19011:2026 apply to remote audits?
Yes. Expanded guidance for remote and virtual auditing is one of the main additions in the 2026 edition, covering planning, technology, and evidence collection for audits conducted partly or fully off site.
Getting ISO Certified in Australia
Whether you are pursuing initial certification or looking to strengthen your existing management system, UCS is Australia's trusted accredited certification body — offering certification across all major ISO management system standards.
Our team of experienced, industry-specific auditors applies the latest ISO 19011:2026 audit guidelines — ensuring every certification audit is conducted with independence, objectivity, and professionalism.
Quote in 3–4 hours. Certified in 7–10 days.
Ready to Get ISO Certified?
Most eligible businesses receive the certificate within 7–10 working days of the Stage 2 audit. Request a free assessment and we will send a quote for your scope within 3–4 hours.
Explore ISO Certification Standards
UCS offers 32+ ISO certifications across all industries in Australia. Get a free assessment
Related Articles
- The 4 Core ISO Management System Standards Every Australian Business Should Know
ISO 9001, ISO 14001, ISO 45001 and ISO/IEC 27001 compared side by side.
- ISO 45001:2018 Certification in Australia: Complete Guide 2026
Occupational health and safety certification requirements for Australian workplaces.
- ISO 14001 Certification in Australia: Complete Guide for 2026
Environmental management certification requirements for Australian businesses.