Home · Insights · Update

ISO 19011:2026: what's changed in the auditing guidelines

The global guideline for auditing management systems has a new edition. Here is what changed, and what it means for the way your system is audited.

Key takeaways

  • ISO 19011:2026 (the fourth edition) has replaced ISO 19011:2018 as the international guideline for auditing management systems.
  • It is guidance, not a certifiable standard. There is no certificate to renew and no transition deadline, but it shapes how your audits are run.
  • Remote and hybrid auditing is now treated as a normal method, with "virtual locations" formally inside audit scope.
  • Risk-based thinking is elevated to a core principle across the whole audit programme.
  • Auditor competence now expects comfort with digital evidence and basic cybersecurity awareness.

If your business holds ISO 9001, 14001, 45001 or 27001, the way your audits are run has just changed. In May 2026, ISO published a new edition of ISO 19011 (the international guideline for auditing management systems), replacing the 2018 version that auditors have relied on for years.

ISO 19011 is guidance, not a standard you certify against, so there is no certificate to renew and no transition deadline. But it shapes how internal auditors and accredited certification bodies plan and run their audits, which means it quietly shapes what your next surveillance audit looks like. Here is what changed, and what it means for keeping your system audit-ready. If you would rather have the whole internal audit programme handled, that is part of our ISO consulting.

What ISO 19011 actually is

ISO 19011 is the reference both internal auditors and external certification bodies use to plan, conduct and report management-system audits. It sits underneath ISO 9001, 14001, 45001 and the rest: it does not tell you what your system must contain, but it tells everyone how that system should be audited. Because it is guidance, you do not get certified to it. You feel it instead in the quality and consistency of the audits performed on your business.

Remote and hybrid auditing is now the norm

The headline change is digital. The 2018 edition treated remote auditing as something of an exception; the 2026 edition treats it as a normal, planned method, with expanded guidance on when and how to use it well. It also introduces the idea of virtual locations (the cloud systems, remote-work platforms and online infrastructure where your real activity now happens) and brings them formally into audit scope. For a business with people working across sites or from home, this is a sensible catch-up with reality.

Risk-based thinking moves to the centre

Risk now runs through the whole audit lifecycle as a stated core principle, not a footnote. Audit programmes are expected to be planned around where the real risk to your management system lies, rather than walking the same checklist every year. In practice, expect certification-body auditors to ask how your internal audit programme is prioritised, and to spend their time where the consequences of failure are highest.

Auditors are expected to be more digitally capable

The competence expected of auditors has broadened. Alongside the traditional skills, the new edition points to evaluating digital evidence, a working awareness of cybersecurity, and comfort with the digital tools used to run audits. This does not turn your quality manager into an IT specialist, but it does mean audit teams need to be credible when the evidence lives in systems rather than folders.

What it does not change

It is worth being honest about the limits of this revision, because there is a lot of noise online. ISO 19011:2026 is described as a technical update that modernises and clarifies. It is not an artificial-intelligence or climate-change overhaul, whatever a webinar title might suggest. The principles that make an audit trustworthy (integrity, fair presentation, evidence-based findings and auditor independence) are unchanged. If your audits are already disciplined, this is a refinement, not a reset.

What this means for your next audit

Three practical moves cover most of it. First, update your internal audit procedure and templates so they reflect the 2026 language, especially formalised remote auditing and virtual locations. Second, refresh your auditor competence: add digital-evidence handling and basic cybersecurity awareness to your training plan. Third, plan your audit programme around risk, so your strongest scrutiny lands where it matters most. Do those three things and the new edition works in your favour. If you would like a second set of eyes on your audit programme, get in touch and we will walk it through with you.

Frequently asked questions

Do we need to be re-certified for ISO 19011:2026?
No. ISO 19011 is guidance for how audits are planned and conducted. It is not a standard you certify against. There is no certificate and no transition deadline. What changes is how internal auditors and certification bodies run their audits.
Is there a compliance deadline?
No formal transition applies because it is guidance. That said, accredited certification bodies align their own practice with the new edition quickly, so it is wise to update your internal audit approach proactively rather than wait.
Does this mean our audits can now be done remotely?
It formalises remote and hybrid auditing as legitimate methods and introduces "virtual locations" into scope. Whether a particular audit can be done remotely still depends on the risk involved and what genuinely needs to be seen on site.
Will our certification body change how they audit us?
Expect more structured remote elements, clearer risk-led planning, and questions that assume digital records. The fundamentals (evidence, independence and integrity) do not change.
What is the single most useful thing to do now?
Update your internal audit procedure, audit programme and auditor competence to reflect remote auditing, virtual locations and risk-based planning.

Reading up because you have a decision to make?

Skip ahead. An obligation-free consultation gives you the honest answer for your specific business.

087 150 3022