Auditing Management Systems · 2026 Procedure Revisions
Revising your internal audit procedure is the single most practical move an organization can make in response to the 2026 wave of ISO updates, and most teams need a handful of targeted edits rather than a rewrite. Three documents are driving the work at once: ISO 19011:2026, the newly published guidance on how management system audits are designed and delivered, and two requirements standards — ISO 14001:2026 in April and ISO 9001:2026 on 16 September — that now both require every internal audit to have defined objectives. This article walks through the seven essential edits your procedure needs, what authority sits behind each one, and how to roll them out without disrupting a program that already works.
Direct Answer: Your internal audit procedure needs seven essential edits for the 2026 ISO cycle: (1) make audit objectives a required field for every audit, now a normative requirement of both ISO 9001:2026 and ISO 14001:2026 Clause 9.2.2 a); (2) add a method-selection step that records the on-site, remote, or hybrid choice and its rationale; (3) require platform-specific auditor competence for remote audits; (4) build in an evidence-reliability and data-security check, including a remote-audit protocol; (5) make risk change five things about an audit, not just its frequency; (6) update competence records, continuing development, and audit reporting; and (7) bring the audit program itself under document control, because ISO 14001:2026 now requires it to be available as documented information. None of the seven demands a rewrite — they are precise insertions into the procedure you already run.
Free Download · PDF Checksheet
ISO 9001 / ISO 19011:2026 Internal Audit Program Checksheet
Check your audit program against the 2026 changes in one pass: per-audit objectives, method selection, remote-audit controls, and the program under document control. Enter your details and the checksheet opens instantly. We will email you a copy too.
The Three Drivers
Why Your Internal Audit Procedure Needs Revising in 2026
Three Drivers. One Document.
For most organizations the internal audit procedure is a single controlled document serving every management system the company runs — quality, environmental, safety, healthcare, and medical device alike. That makes it the natural place to absorb the 2026 changes once, cleanly, rather than scattering edits across separate systems. Three forces are pushing on that document this year: one piece of guidance and two hard requirements, and they carry very different weight.
The first driver is guidance. ISO 19011:2026 was published on 27 May 2026 as the fourth edition, withdrawing ISO 19011:2018 on the same day. ISO’s own list names exactly two: remote-auditing guidance brought in from ISO/IEC TS 17012, and a wider Annex A covering remote methods and virtual locations. Because ISO 19011 is guidance rather than a requirements standard, it applies immediately, with no transition period, and no clause of it can be raised as a nonconformity. The full picture of what shifted is covered in MSI’s companion analysis of the ISO 19011:2026 changes; this article translates the guidance into the specific procedure edits it implies.
Guidance does not generate findings. It changes the person who writes them.
Certificated auditors are retrained against the current edition of ISO 19011, so the auditor across the table arrives with updated expectations even where no requirement moved. When practice falls short of that good practice, the gap is written up against Clause 9.2 of the standard you hold a certificate to — which is why the guidance deserves a place in your procedure even though nobody certifies to it.
The second driver is a hard requirement. ISO 14001:2026, published 15 April 2026, revised the internal audit clause so that defining scope and criteria for each audit is no longer enough — each internal audit must now also state defined objectives, and the audit program itself must be available as documented information. This is a normative “shall,” and certified organizations are working against a transition deadline of 30 April 2029. MSI’s ISO 9001 and 14001 transition guide sets the wider sequencing out, and the ISO 14001 standard overview covers the certificate mechanics.
The third driver arrived on 16 September 2026, when ISO announced the publication of ISO 9001:2026. Its Clause 9.2.2 now asks the organization to plan the audit program as well as establish and maintain it, and item a) requires the audit objectives, criteria and scope to be defined for each audit. Evidence of the program’s implementation and of audit results must now be available rather than retained. Correction and corrective action without undue delay stay in the clause, now as item d).
Beneath the clause, ISO 9001:2026 now cross-refers readers to ISO 19011 — so the guidance behind Edits 2, 3 and 4 is no longer a separate document your quality auditors can ignore. ISO 9001:2015 certificates cease to be valid after 30 September 2029; MSI’s ISO 9001:2026 executive briefing translates the wider revision for leadership.
One correction still worth making: per-audit objectives are not a new idea in the ISO standards. ISO 7101:2023 Clause 9.2.2 a) has required audit objectives since 2023, and healthcare organizations have operated under that requirement for three years. What changed in 2026 is that the obligation reached the two standards most organizations actually hold. If you run an integrated system with a healthcare arm, the field you need may already exist in one corner of your business, as MSI’s ISO 7101 healthcare quality overview explains. MSI’s read on how the 2026 revisions interlock is set out in its overview of the 2026 revisions and certification strategy.
Now Available · Editable Word · $149 Single Standard · $249 Combined
All Seven Edits, Already Made — Your 2026-Ready Internal Audit Procedure
Skip the redrafting. Each template is a complete, editable internal audit procedure with all seven edits in this article already made: a mandatory per-audit objectives field, an on-site / remote / hybrid method-selection step with the rationale captured, platform-specific competence criteria, an evidence-reliability and data-security check, the five risk levers written into program planning, competence and reporting records, and the audit program itself defined as a controlled document. Written as a finished working document rather than an outline — the decisions already made and explained, with bracketed placeholders everywhere a value is genuinely yours to set. Set it beside your current procedure and the missing pieces show up in minutes.
ISO 9001 internal audit procedure · ISO 13485 · ISO 14001:2026 · ISO 45001 · ISO 7101
Combined: ISO 9001 + 13485 · ISO 14001 + 45001 · ISO 9001 + 14001 + 45001
Edit 1 · ISO 9001:2026 and ISO 14001:2026 Clause 9.2.2
Edit 1 — Make Audit Objectives a Required Field in Your Internal Audit Procedure
Define. Document. Deliver.
Direct Answer: The first edit to your internal audit procedure is the most concrete: add a mandatory audit-objectives field to every audit plan. ISO 9001:2026 and ISO 14001:2026 Clause 9.2.2 a) both now require each internal audit to define its objectives alongside the scope and criteria that were already required. The objective answers why this audit is happening — what question it is meant to answer — not just what it covers.
Under the prior editions of both standards, an internal audit plan defined two things for each audit: the scope, meaning which processes, sites and activities are included, and the criteria, meaning the requirements being audited against. The 2026 revisions add a third. An objective is the purpose of the specific audit — “confirm that corrective actions from the previous environmental audit were effectively implemented,” or “verify that the new change-management process is operating as designed.” Scope tells the auditor where to look; criteria tell the auditor what to measure against; the objective tells the auditor what the audit is trying to learn.
In practice this edit is small but exacting. Your internal audit procedure should require that every audit plan, schedule entry and audit report carries an explicit objective, and that the objective drives the audit design rather than being backfilled afterward. The discipline pays off: audits with a clear objective are sharper, shorter and more useful, because the auditor knows exactly what conclusion the audit is meant to support. This is the same outcome-focused thinking MSI applies in its guide to internal audit planning and in the planning phase of internal audits, where a well-framed objective is what separates a meaningful audit from a checklist traversal.
Write the objective as a question the audit will answer. “Audit the calibration process” is a scope statement wearing an objective’s job title. “Determine whether equipment found out of tolerance triggers a retrospective validity assessment of prior results” is an objective — and it tells the auditor what evidence would settle it.
For organizations running an integrated system, building the objectives field into the shared internal audit procedure once means every standard inherits the requirement at the same time — including ISO 45001 and ISO 13485, which do not yet ask for it. That is the structural efficiency MSI describes in its guide to integrated management system implementation and across the wider integrated management systems family. The equivalent equipment-side discipline is set out in MSI’s guide to control of monitoring and measuring equipment, where the same “what would settle this” logic applies.
Edit 2 · Method Selection
Edit 2 — Add a Method-Selection Step to Your Internal Audit Procedure
Choose. Justify. Record.
Direct Answer: The second edit to your internal audit procedure is a method-selection step. ISO 19011:2026 Clause 5.5.3 says audit methods are selected depending on the defined audit objectives, scope and criteria, and Clause 5.3 lists method selection among audit program risks, judged by whether the chosen method can achieve the defined objective. Your procedure should require auditors to choose on-site, remote or hybrid deliberately, record which one, and record why.
Before this edition, remote auditing tended to sit awkwardly outside the procedure — something teams did when travel was inconvenient, without a documented basis. Both of the headline ISO 19011:2026 changes concern remote auditing, which tells you where the attention has moved. Your internal audit procedure should add a step recording, for each audit, whether it will be conducted on-site, remotely, or as a hybrid, and the rationale for that choice. A review of records may be done remotely; observing a high-risk operational process may require physical presence. The method is chosen to fit the evidence the objective demands.
What ISO 19011:2026 Says About Choosing the Method
The fourth edition gives your internal audit procedure three things to cite. Clause 5.5.3 asks for on-site and remote methods to be suitably balanced, based on their risks and opportunities. Annex A.1 says remote feasibility depends on how much risk the method poses to meeting the audit objectives, how much trust exists between the auditor and the auditee’s people, and what regulators expect. And the edition adds a defined term, remote auditing method, taken from ISO/IEC TS 17012 — any method used from a place other than the auditee’s location, regardless of the distance.
That last point changes how most procedures should be written. A quality engineer at headquarters watching an inspection bench two buildings away through a tablet camera is using a remote method. A procedure that treats “remote” as meaning “off-site travel we avoided” will undercount the choices it is supposed to record.
Turning Annex A.1 Into a Method-Selection Record
Annex A.1 classifies methods by two questions: is the auditor at the auditee’s location, and does the method involve talking with the auditee’s people? Those two questions make a clean method-selection record for each audit in your plan:
| Record in the audit plan | Example entry |
|---|---|
| Objective the method must serve | Determine whether out-of-tolerance equipment triggers a review of earlier results |
| Location of the auditor | Remote for calibration records; on-site for the metrology lab walk-through |
| Human interaction | Video interview with the metrology lead; record review without interaction |
| Why this method can meet the objective | Records are held in the eQMS; physical segregation of suspect gauges can only be confirmed in person |
| Fallback if the remote session fails | Extend by half a day on-site at the next scheduled visit |
Two further details belong in the internal audit procedure. Annex A.1 allows a multi-person team to split, with one auditor on site while another works remotely. It also accepts observation through surveillance equipment only where privacy and legal limits are respected, so agree the rules with HR and legal before anyone points a camera at a workstation. ISO/IEC TS 17012:2024 is worth naming in your procedure’s reference list, because it is the source the 2026 guidance points to. For multi-site and dispersed organizations this is where the internal audit procedure earns its keep, a theme MSI explores in its guide to multi-site ISO certification. A procedure that documents method choice against the objective gives your certification body a defensible record of why each audit was run the way it was.
Edit 3 · MSI House Standard, Anchored in Annex A.16
Edit 3 — Require Platform-Specific Auditor Competence
Train. On. The-Tool.
Direct Answer: The third edit to your internal audit procedure is the one most teams overlook: require auditors to be competent in the specific platform your organization uses for remote audits — not in “remote tools” generally. ISO 19011:2026 Annex A.16 already lists technical skill with the audit technology as part of auditor competence. Naming the platform is MSI’s house standard, and it turns that guidance into something you can verify.
A procedure that says “auditors shall be competent in remote auditing tools” is too vague to be auditable. Competence has to be platform-specific, because a remote audit is only as reliable as the auditor’s command of the platform carrying it. MSI’s house standard, drawn from 200+ audits attended, is that the internal audit procedure names the platform the organization actually uses and requires auditors to be trained on its mechanics: host and presenter controls, screen-sharing and remote-control permissions, recording behavior and where recordings are stored, admission controls, and secure file exchange. When an auditor fumbles a control mid-session, evidence is lost and the audit’s credibility erodes.
Teams vs. Zoom — Why the Mechanics Differ for Auditors
The differences are not cosmetic; they change how evidence is gathered and retained. Recording destination is the clearest example. Microsoft Teams typically routes recordings into SharePoint or OneDrive under the organization’s retention rules, while Zoom may store them in its cloud or locally depending on configuration — and an audit recording can itself become a controlled record subject to your retention policy. Host and presenter roles differ too, governing who can share a screen, grant remote control, or admit a participant. Lobby and waiting-room settings determine who is admitted and when, which matters when sensitive evidence is on screen. File-exchange paths that IT permits on one platform may be disabled on another, changing how an auditee submits documents mid-session.
What the Standard Text Already Says
ISO 19011:2026 does not use the word “platform,” but it comes close enough to anchor this part of your internal audit procedure. Annex A.16 expects auditors to be able to operate the technology in use and to know how to run an audit at a distance. Clause 7.2.3 lists understanding the appropriateness and consequences of using information and communications technology and emerging technology to conduct audits, with artificial-intelligence-based evaluation tools named as the example. Certification bodies face a harder rule: under IAF MD 4:2025, a legacy document still valid under Global ACI, conformance is mandatory whenever ICT is used, and the Standards Council of Canada summary notes that team members must be competent in the ICT used. Your internal auditors should not be held to a lower standard than the auditor who arrives for surveillance.
Because these mechanics affect evidence capture, retention and confidentiality, MSI’s house standard treats platform competence as a prerequisite for conducting remote audits — verified and recorded the same way you record any other auditor qualification. The supporting framework sits inside MSI’s internal audit services; the skills are taught in the ISO 9001 two-day internal auditing course, the ISO 13485 two-day internal auditor training, the ISO 9001 and 13485 two-day training for combined programs, and the ISO 14001:2026 internal auditing course. The case for treating internal audit skills as a profession rather than a rotating assignment runs through MSI’s ISO internal auditor training and its live ISO internal auditor workshop.
Edit 4 · MSI House Standard, Anchored in Annex A.16
Edit 4 — Build In an Evidence-Reliability and Data-Security Check
Verify. Trace. Protect.
Direct Answer: The fourth edit to your internal audit procedure adds an explicit evidence-reliability and data-security check for remote and digital evidence, plus a short remote-audit protocol drawn from ISO 19011:2026 Annex A.16. MSI’s house standard requires auditors to trace remote evidence back to a controlled source before using it, to obtain permission before capturing screenshots or recordings, and to escalate to on-site verification when evidence cannot be confirmed.
When evidence arrives through a screen rather than a walk-through, a new question attaches to it: can this be relied upon? A document emailed mid-audit, a screen-shared dashboard, or a remotely demonstrated process each carries a reliability question. Your internal audit procedure should instruct auditors to evaluate whether information collected remotely is verifiable, sufficiently specific and traceable to a source. This protects the audit conclusion from resting on evidence that looked convincing on a video call but could not be confirmed afterward.
The Remote-Audit Protocol Annex A.16 Already Wrote
Annex A.16 reads like a pre-audit checklist, and most of it can go into your internal audit procedure almost as written. It makes effective remote auditing a joint responsibility of auditee and auditors. Paraphrased as procedure steps:
- Confirm the agreed remote access protocols, devices and software with the auditee before the audit.
- Run a technical check in advance so connection problems are solved before evidence is at stake.
- Have a contingency plan for lost access or a failed platform, including provision for extra audit time.
- Ask permission in advance before taking screenshots of documented information or recording any part of the audit.
- Use floor plans or diagrams to orient the auditor to remote locations and electronic information.
- Protect confidentiality and privacy during breaks by muting microphones and pausing cameras.
Add two more lines to the internal audit procedure from the surrounding text. The interview guidance in A.17 adds that non-verbal cues carry less weight in virtual settings, so auditors should rely on well-chosen questions. The audit-preparation guidance also treats photos, screen captures and video from the audit as confidential material the audit team must protect throughout. The ISO 9001 Auditing Practices Group remote-audit guidance is a useful practitioner companion.
The data-security half of the edit matters just as much. When an organization grants an auditor access to live systems, records and recordings, both parties inherit a responsibility to protect that data. The procedure should set expectations for how audit evidence and recordings are handled, stored, retained and destroyed. It connects to MSI’s work on change management and the audit trail, with its procedure-first view of ISO compliance automation, and with the harder version of the problem in auditing AI agents and AI process controls, where reliable, traceable evidence is designed in rather than reconstructed later.
Edit 5 · The Conformity Anchor
Edit 5 — Make Risk Change Five Things, Not Just Frequency
Focus. Where. Risk-Lives.
Direct Answer: The fifth edit to your internal audit procedure is the one with a long-standing clause behind it. Every standard in the family requires the audit program to take into consideration the importance of the processes concerned — that is what makes risk-based prioritization mandatory rather than a preference. Most programs answer it by adjusting frequency alone, which is the least useful of the five things risk should change.
Start with what is citable. ISO 9001:2026 Clause 9.2.2, like the 2015 edition before it, requires the organization to consider the importance of the processes concerned, changes affecting the organization, and the results of previous audits when establishing the audit program. ISO 19011:2026 carries a published clause at 5.3 on audit program risks and opportunities. Those are structural facts about where the topic lives. What neither document does is tell you what to do about the importance you have considered — and that is where most audit programs quietly stop.
MSI’s house standard, developed across 28 years and 200+ audits attended, is that risk should change five properties of an audit. Frequency is only the first, and on its own it changes almost nothing about what the audit finds.
| What Varies | Higher Risk | Lower Risk |
|---|---|---|
| Frequency | Every cycle, re-audited early where findings recur | Longer interval, with the basis recorded |
| Depth | Walked end to end, including the handoffs | Key controls sampled |
| Sample size | Large enough to conclude about the system | Sufficient to confirm the control operates |
| Method | On-site, including the shift where supervision is thinnest | Records reviewed remotely |
| Auditor | Most experienced available | Any qualified auditor on the register |
A low-risk process and a high-risk process both audited annually, with the same checklist and the same two-hour slot, have not been differentiated in any way that changes what the audit finds.
The practical edit is to write those five levers into the planning section of your internal audit procedure, with the risk basis recorded per process rather than asserted for the program as a whole. Mature teams already concentrate effort where exposure is greatest rather than auditing everything on a flat cycle — a discipline MSI details in its analysis of internal audit risk mitigation strategies and applies at the aspect level in its guide to ISO 14001 environmental aspects. MSI client experience suggests teams that vary all five levers get more from fewer audit days than teams that vary only the calendar.
Free · No Sign-Up · About Six Minutes
Which Edit Should Come First? Six Minutes Will Tell You.
The five levers only help if you aim them at the right weakness. The free Internal Audit Maturity Check scores your program the way it actually runs under pressure, element by element, and hands back a maturity band and a priority order in a few minutes, with no sign-up. Use the result to decide which of the seven edits to make first in your internal audit procedure — for many teams it is not the one they would have guessed.
Edit 6 · Competence and Reporting
Edit 6 — Update Competence Records, CPD, and Reporting in Your Internal Audit Procedure
Record. Renew. Report.
Direct Answer: The sixth edit to your internal audit procedure updates how competence, continuing development and reporting are documented. ISO 19011:2026 Clause 7.2.3 on knowledge and skills now names AI-based evaluation tools and data protection among the things auditors should understand, and Clause 7.6 covers maintaining and improving competence. MSI’s house standard is that qualification records name the remote-audit platform, and that every audit report records the objective, the method used, and whether the objective was met.
Many auditor competence frameworks were built around discipline knowledge alone — what the auditor knows about the standard and the processes being audited. MSI’s house standard broadens that to include the platform competencies covered in Edit 3 and the evidence judgment covered in Edit 4, and requires that auditor qualification records reflect them explicitly rather than by implication. Clause 7.2.3 adds data protection and information security to the knowledge list, and its note draws a firm line between a management system audit and a legal compliance audit. Continuing professional development should include audit methods and digital techniques, so competence stays current rather than freezing at the point of initial qualification. Auditing a culture-and-behavior requirement takes the same evidence discipline, as MSI sets out in its guide to auditing quality culture.
Reporting closes the loop. Because objectives and methods are now first-class elements of audit design, your report template should record them: what the audit set out to learn, how it was conducted, and whether the objective was met. That makes the audit program self-documenting and gives management review a cleaner read on how the system is performing. The 2026 editions raise the stakes: ISO 14001:2026 now asks for audit results framed as trends, which only works if audits measure comparable things across cycles, and ISO 9001:2026 asks top management to review the system’s alignment with strategic direction.
MSI covers the record in its management review procedure guide and the 14001 clause in its ISO 14001:2026 management review guide. Strong reporting also feeds the follow-up that turns findings into improvement, covered in MSI’s guide to internal audit follow-up; ISO 19011:2026 carries a published clause at 6.7 on audit follow-up, and every finding eventually hands off to a corrective action procedure.
Where Audit Reports Land
Management Review Toolkits, Built From the Clause Instead of Last Year’s Agenda
An audit objective only pays off when leadership decides something about the result. MSI’s ISO Management Review Toolkits pair a presentation deck with a minutes form that follow one shared, clause-referenced section list, so the audit results your revised procedure produces arrive as a trend leadership can act on rather than a line item it skims. The combined editions, including the ISO 9001 and 14001:2026 toolkit and the ISO 45001 and 14001:2026 HSE toolkit, resolve the inputs that differ across standards.
Edit 7 · The Harder 2026 Change
Edit 7 — Bring the Audit Program Itself Under Document Control
Available. Not. Retained.
Direct Answer: The seventh edit to your internal audit procedure is the harder of the two ISO 14001:2026 changes and the one most transition plans miss. ISO 14001:2015 required the organization to retain documented information as evidence of the implementation of the audit program and the audit results — two items, both retrospective. ISO 14001:2026 requires three things to be available, and the first of them is the audit program itself. ISO 9001:2026 also moved from retained to available, but lists only the evidence, not the program.
In most organizations the audit program is a spreadsheet on the program manager’s desktop: uncontrolled, unversioned, and not in the document system at all. Making it available as documented information means bringing it under document control. That takes planning, where adding an objectives field takes ten minutes — which is exactly why this edit belongs on the plan early and the objectives edit does not.
The two words also carry different tests. Retained means kept — you can produce it when asked. Available means current, retrievable and under control: the version an auditor sees is the version the program is actually running to, with a revision history, an owner and a review trigger. A spreadsheet with four people’s edits and no version number satisfies neither test convincingly, and it is the single most common piece of an internal audit procedure that never made it into the document management system. If a single program serves ISO 9001 and ISO 14001 together, the stricter ISO 14001 wording governs the shared document.
The tell: ask who owns the current version of your audit program and how you would know if someone changed it. If the answer involves an email thread, this edit is your longest-lead item.
The edit itself is a cross-reference: your internal audit procedure names the audit program as a controlled document, assigns its owner, states its revision trigger, and points at your document control procedure for the mechanics. Organizations that already run a mature document control process will find this a half-day change. Organizations whose program lives in one person’s files will find it is the change the 2029 deadline was really about. MSI’s guide to evaluation of compliance covers the parallel available-versus-retained distinction on the compliance side of ISO 14001, the ISO 14001 continual improvement guide shows where the audit program feeds the wider loop, and building an internal audit program covers the program document itself.
Every Procedure the System Needs
Your Audit Procedure Points to Six Others. Make Them Agree.
Edit 7 sends your internal audit procedure to document control, and every finding it produces lands in corrective action, competence records and management review. The expensive part of documenting a management system is not writing any single procedure — it is making them agree with each other: the same records referenced the same way, the same review triggers, interfaces named on both sides. MSI’s ISO Procedure Templates & Guides cover the full set across five standards and their combinations, every one built to the same section architecture, editable in Word, with the judgment calls already made from 28 years of practice. If you later bring MSI in, what you paid for templates counts in full toward consulting, SurePath or SureResults.
One Procedure · Five Standards
What Each Standard Requires of Your Internal Audit Procedure
Same Clause. Different Teeth.
Direct Answer: A shared internal audit procedure must satisfy the strictest requirement in the set, not the average. ISO 13485 is the only one that mandates a documented procedure by name and requires conformity to be measured against applicable regulatory requirements. ISO 45001 puts worker consultation inside the program. ISO 7101 sets a twelve-month maximum interval. ISO 9001:2026 and ISO 14001:2026 both add per-audit objectives, and ISO 14001:2026 adds document control of the program. ISO 45001:2018 is now the least prescriptive on audit design, which is why building the shared procedure to any single standard’s baseline leaves gaps.
This is the part most integrated versions of an internal audit procedure get subtly wrong. The clause numbers line up neatly, which creates the impression the requirements do too. They do not, and each standard has one requirement that quietly vanishes when a procedure is written from another standard’s template.
| Standard | The Requirement Your Procedure Must Carry |
|---|---|
| ISO 9001:2026 9.2.2 | New: the program is planned as well as established. New: audit objectives, criteria and scope defined for each audit. Evidence of implementation and results must be available. Clause 9.2.2 d) keeps correction and corrective action without undue delay — two obligations, not one. A note points to ISO 19011. |
| ISO 13485:2016 8.2.4 | Mandates a documented procedure by name. Conformity measured against applicable regulatory requirements. Interval and methods recorded. Auditors shall not audit their own work. Records identify areas audited and the conclusions. Follow-up includes verification and the reporting of verification results. |
| ISO 14001:2026 9.2.2 | New: audit objectives required per audit. New: three documented information items must be available, the first being the audit program itself. No corrective action requirement sits inside Clause 9.2. |
| ISO 45001:2018 9.2.1 – 9.2.2 | Consultation sits inside the program. OH&S policy and objectives are conformity criteria. Relevant results are reported to workers and workers’ representatives. Action cross-references Clause 10 by name. Criteria and scope per audit; objectives not yet required. |
| ISO 7101:2023 9.2.2 | Audits at a minimum of once every twelve months. Conducted by trained and qualified individuals. Results reported in a timely manner. Audit objectives required since 2023. |
One more distinction worth writing down, because assuming otherwise is a common error. In February 2024 ISO amended the context clauses of dozens of harmonized-structure standards to mention climate change, among them ISO 9001:2015, ISO 14001:2015 and ISO 45001:2018, and ISO 9001:2026 and ISO 14001:2026 carry that wording into the new editions. ISO 13485 is not among them — it is not built on the harmonized structure and was not amended. A shared procedure that applies climate criteria to the ISO 13485 scope is auditing against a requirement that standard does not contain.
ISO 14001:2026 · Built for Experienced EHS Managers
Update Every EMS Procedure From 2015 to 2026 in a Week
The internal audit procedure is one of the documents ISO 14001:2026 touches; context, planning of changes and management review are the others. If you already run a working EMS, you do not need the 2026 edition explained — you need the documents changed. The ISO 14001:2026 Procedure Templates & Guides give you the full EMS procedure set rewritten to the new text, the internal audit procedure included with its objectives field and controlled program, along with the transition course. Experienced EHS managers use them to move a 2015 system to 2026 in about a week.
US Device Manufacturers
Why QMSR Changes the Stakes on Your Internal Audit Procedure
Inspectable. Now. Not-Later.
Direct Answer: For US medical device manufacturers, the internal audit procedure now governs records an FDA investigator can ask to see. Since 2 February 2026, ISO 13485:2016 is incorporated by reference into 21 CFR Part 820, and the former § 820.180(c) exemption was not carried across. FDA’s own QMSR guidance confirms the agency has authority to review management review, quality audit and supplier audit reports.
For twenty-five years, internal audit reports sat behind an exemption. A device manufacturer could audit itself honestly, write findings plainly, and know the report would not be read across the table during an inspection. That changed with the Quality Management System Regulation final rule, and the practical consequence lands squarely on the internal audit procedure: the report template, the language convention for findings, and the retention rule are now decisions with regulatory weight.
The wrong response is to soften the findings. An internal audit program that stops writing honest nonconformities stops working, and an investigator reading a year of clean audits in a facility with open complaint trends draws exactly the conclusion you were trying to avoid. MSI’s house standard is the opposite: write the finding precisely, close it with evidence, and let the closure record carry the weight. That is the discipline MSI teaches throughout its ISO consulting engagements, and it is what makes an audit trail defensible rather than merely tidy.
Seven Edits · One Audit
What Does a 2026-Ready Internal Audit Procedure Look Like in Practice?
One Audit. Seven Edits.
The seven edits are easiest to understand when you watch them work together across a single audit. Picture a mid-sized manufacturer running an integrated management system, preparing to audit its corrective-action process. Under a 2026-ready internal audit procedure the audit begins not with a checklist but with an objective: confirm that corrective actions raised in the last cycle were implemented and proved effective. That objective — now required under ISO 9001:2026 and ISO 14001:2026, and under ISO 7101 since 2023 — immediately shapes every decision that follows.
With the objective set, the auditor chooses a method and records why. Much of this audit is document and record review, which can be done remotely, so the auditor schedules a remote session for the corrective-action records and reserves a short on-site visit to verify that one physical control was actually installed. The method-selection step captures that reasoning. Before the remote session the platform-competence prerequisite applies: the auditor is confirmed competent on the organization’s chosen platform, has run the technical check, knows where the session recording will be stored under the retention policy, and has agreed in advance which screens may be captured.
During the session the evidence-reliability check shapes how the auditor treats what appears on screen. A screen-shared corrective-action log is useful, but the auditor confirms it is the controlled version, traceable to the document management system, before relying on it — and notes where a remote view was insufficient and on-site confirmation was needed. The five risk levers had already done their work upstream: this process carried elevated risk after a recent change, so it earned a deeper sample, the most experienced auditor available, and an on-site component rather than simply an earlier date on the calendar.
Under the revised internal audit procedure, the report records the objective, the method used and whether the objective was met, feeding cleanly into management review as part of a trend. And the schedule that placed this audit where it sits is itself a controlled document with an owner and a revision history — which is what lets the auditor demonstrate, without opening a spreadsheet nobody can version, that the program was planned rather than assembled. Every one of the seven edits played a visible role, and none required a new document.
That is the practical test of a good revision: not whether the internal audit procedure reads well, but whether it produces audits that deliver reliable conclusions in the way organizations actually work. Across 200+ audits attended, the procedures that hold up are the ones written for how the work really happens.
Organizations that want to benchmark their own document against this standard will find the supporting context in MSI’s guide to ISO 14001 certification, its view of why a durable quality management mindset outperforms compliance theater, and its account of how a government internal audit program matures from event to intelligence. The wider audit lifecycle — internal, surveillance and certification — is mapped in MSI’s guide to the ISO audit.
Rollout
How to Roll These Internal Audit Procedure Edits Out Without Disruption
Edit. Approve. Train.
None of the seven edits requires rebuilding your internal audit procedure from scratch. They are targeted insertions into a document that already works: an objectives field, a method-selection step, a platform-competence prerequisite, an evidence-reliability check and remote-audit protocol, five risk levers in the planning section, updated competence and reporting records, and the audit program brought under document control. Treat the revision the way you would any controlled-document change — draft the edits, route them through your normal review and approval, update the version, and communicate what changed.
Sequence matters more than speed. Edit 7 is the long-lead item because it touches document control; start it first. Edit 1 is a same-week change and, with ISO 9001:2026 now published, the one with the widest reach, so it follows immediately, with Edit 2 alongside it. Edits 3, 4 and 6 land in your competence and reporting records and can move alongside your next training cycle. Edit 5 is a planning-section rewrite best timed to your next program cycle, when you are setting the schedule anyway.
Then train to the revised procedure. Your internal auditors and any supplier auditors you rely on should understand the objectives field, the method-selection logic, the remote-audit protocol and the platform-competence expectation before their next scheduled audit. For ISO 9001 and ISO 14001 certificate holders, the objectives field is a requirement rather than guidance, and ISO 14001 adds document control of the program, so both belong in place well before the transition audit. Teams that prefer a guided path can lean on MSI’s approach to certification audits, its SurePath turnkey certification program, or the year-round maintenance rhythm of SureResults. For an independent read on where the system actually stands, The Portrait is MSI’s operational assessment.
Free Download · Check Your Program Before You Edit It
ISO 9001 / ISO 19011:2026 Internal Audit Program Checksheet
Check your audit program against the 2026 changes in one pass: per-audit objectives, method selection, remote-audit controls, and the program under document control. Enter your details and the checksheet opens instantly. We will email you a copy too.
Revise the Procedure Once, for Every Standard You Hold
If your internal audit procedure, competence criteria or auditor training need to catch up with ISO 19011:2026, ISO 9001:2026 and ISO 14001:2026, MSI will map the exact edits that matter for your standards and your operation, and leave alone what already works. The first step is a planning session — a practical hour with a consultant who has sat through 200+ audits, focused on your document rather than a pitch.
Call 760-434-9141 to plan a session.
Frequently Asked Questions
Revising Your Internal Audit Procedure for 2026
Ask. Answer. Apply.
Does ISO 14001:2026 really require objectives for every internal audit?
Yes. ISO 14001:2026 revised Clause 9.2.2 so that defining scope and criteria for each audit is no longer sufficient — each internal audit must also state defined objectives. This is a normative requirement, and certified organizations should build a mandatory objectives field into the internal audit procedure ahead of their transition audit, within a window closing 30 April 2029. ISO 9001:2026 made the same change in September 2026, and ISO 7101:2023 has required audit objectives since 2023.
Does ISO 9001:2026 also require audit objectives?
Yes. ISO 9001:2026, published 16 September 2026, revised Clause 9.2.2 a) so the audit objectives, criteria and scope are defined for each audit. It also asks the organization to plan the audit program and makes evidence of implementation and results available rather than retained. A note under the clause points to ISO 19011 for guidance. ISO 9001:2015 certificates cease to be valid after 30 September 2029, so the objectives field belongs in the shared internal audit procedure now.
Can a certification body write a finding against ISO 19011:2026?
No. ISO 19011 is guidance, so it cannot be the basis of a nonconformity and there is no transition period. Its influence runs through people: auditors are trained and certified against the current edition, and when your audit practice falls short of it, the gap is recorded against Clause 9.2 of the standard you are certified to.
What actually changed in ISO 19011:2026?
ISO lists two main changes in the fourth edition, published 27 May 2026: expanded guidance on remote auditing methods drawn from ISO/IEC TS 17012, and an expanded Annex A covering remote methods and virtual locations. For the full breakdown, including what commentary overstates, see MSI’s analysis of the ISO 19011:2026 changes. For an internal audit procedure, the practical effect is Edits 2, 3 and 4 in this article.
Do I need to rewrite my internal audit procedure for these changes?
No. The seven edits are targeted insertions into your existing internal audit procedure: an objectives field, a method-selection step, a platform-specific competence prerequisite, an evidence-reliability check with a remote-audit protocol, five risk levers in program planning, updated competence and reporting records, and the audit program brought under document control. Route them through your normal controlled-document review, update the version, and train your auditors to the revised procedure.
What does “available” mean compared with “retained” for the audit program?
Retained means kept — you can produce it when asked. Available means current, retrievable and under control: the version an auditor sees is the version the program is running to, with a revision history, a named owner and a review trigger. ISO 14001:2026 requires three items to be available, the first of which is the audit program itself. ISO 9001:2026 also moved to available, but only for evidence of implementation and results.
Can auditors take screenshots or record a remote internal audit?
Yes, with permission obtained in advance. Annex A.16 of ISO 19011:2026 recommends agreeing in advance before any screen capture or recording, with confidentiality and security in mind, and the audit team is expected to protect captured images and video throughout. Your internal audit procedure should say who grants that permission, where captures are kept and when they are deleted.
Why does the platform matter for remote audits — isn’t competence in remote tools enough?
Generic “remote tools” competence is too vague to be auditable, because the mechanics that affect evidence differ by platform. Recording destination and retention, host and presenter controls, admission settings and file-exchange paths all behave differently between Microsoft Teams and Zoom. ISO 19011:2026 Annex A.16 already says auditor competence should include technical skills to use the technology; naming the specific platform is MSI’s house standard, and it makes the expectation concrete and verifiable.
Are internal audit reports now inspectable by FDA?
For US medical device manufacturers, yes. Since 2 February 2026 ISO 13485:2016 has been incorporated by reference into 21 CFR Part 820, and the former § 820.180(c) exemption that shielded quality audit reports was not carried across. FDA’s QMSR guidance confirms the agency has authority to review management review, quality audit and supplier audit reports. The right response is a sharper internal audit procedure and better closure records — not softer findings.
Which management systems does a single internal audit procedure cover?
Most organizations run one internal audit procedure across every management system they hold — ISO 9001 quality, ISO 14001 environmental, ISO 45001 occupational health and safety, ISO 13485 medical device and ISO 7101 healthcare. The shared procedure has to satisfy the strictest requirement in the set rather than the average: ISO 13485 mandates a documented procedure by name, ISO 45001 puts worker consultation inside the program, ISO 7101 sets a twelve-month maximum interval, and ISO 9001:2026 and ISO 14001:2026 require per-audit objectives.
How can MSI help us revise our internal audit procedure?
MSI translates the 2026 updates into the specific edits your internal audit procedure, competence criteria and training actually need — without overcorrecting. With 28 years of experience, 80+ certifications supported, 200+ audits attended and 600+ professionals trained, MSI can revise your procedure, update your auditor qualification path and prepare your team ahead of a transition audit. Take the finished internal audit procedure template for your standard, download the free Internal Audit Program Checksheet, start with the free Internal Audit Maturity Check, or call 760-434-9141 to plan a session.
Related Reading
Build the Program, Not Just the Procedure
Plan. Audit. Improve.
- ISO 19011:2026 Changes — what the new edition actually says, and what it does not
- ISO 9001:2026 Executive Briefing — explaining the new edition to leadership
- Internal Audit Program — the program document Edit 7 brings under control
- Internal Audit Planning — scheduling the year before writing the plan
- Internal Audit Follow-Up — closing findings with evidence, not signatures
- Internal Audit Risk Mitigation Strategies — putting the five levers to work
- Corrective Action Procedure — the document every finding hands off to
- Management Review Procedure — the meeting your audit reports feed
- ISO 9001 and 14001 Transition — sequencing two revisions with one plan
- MSI Blog — the full library across five standards
References & Authoritative Sources
- ISO — ISO 19011:2026, Guidelines for auditing management systems
- ISO — ISO/IEC TS 17012:2024, Guidelines for the use of remote auditing methods
- ISO — ISO 9001:2026, Quality management systems — Requirements
- ISO — ISO launch announcement for ISO 9001:2026 (16 September 2026)
- ISO — ISO 14001 Environmental management
- ISO — ISO 45001 Occupational health and safety
- ISO — ISO 13485 Medical devices
- ISO — ISO 7101:2023 Healthcare organization management systems
- ISO — ISO 9000:2026, Quality management — Fundamentals and vocabulary
- ISO — ISO/IEC 17021-1, Requirements for bodies providing audit and certification of management systems
- ISO/TC 176 — ISO 9001 Auditing Practices Group guidance on remote audits
- ISO — ISO and climate change
- Global ACI — Global Accreditation Cooperation Incorporated (assumed the coordination role formerly held by IAF and ILAC on 1 January 2026)
- Standards Council of Canada — IAF MD 4:2025, use of ICT for conformity assessment
- ANAB — ANSI National Accreditation Board
- eCFR — 21 CFR Part 820, Quality Management System Regulation
- FDA — QMSR final rule, frequently asked questions
- Federal Register — Medical Devices; Quality System Regulation Amendments
- ASQ — Auditing resources
- EPA — Compliance and enforcement
- OSHA — Recommended practices for safety and health programs
- NIST — Cybersecurity Framework (for organizations handling audit evidence on shared platforms)
- The Institute of Internal Auditors — IIA (a separate discipline from ISO management system auditing, referenced for contrast)
About Management Systems International (MSI)
Diana Lynn is President and Principal ISO Consultant at Management Systems International, LLC, a veteran-owned, female-owned ISO consulting firm she founded in 1998. Across 28 years of experience, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries.
MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.
msi-international.com · 760-434-9141
