Scope of this guide: This covers ISO 19011:2026 as it applies to management system auditing — ISO 9001, ISO 13485, ISO 14001, ISO 45001 and ISO 7101. Where this article states what the standard changed, it reports ISO's own published statement of changes. Where it goes beyond that statement, it says so and calls it MSI's reading or MSI's house standard.
Auditing Management Systems · 2026 Revision
The ISO 19011:2026 changes are narrower than almost everything written about them, and knowing exactly how narrow is what separates a focused audit program update from a wasted quarter. Published on 27 May 2026 as the fourth edition of Guidelines for auditing management systems, the revision withdrew ISO 19011:2018 the same day. ISO's own statement of what changed lists two items. Much of the commentary circulating since May lists five or six. This article reports what the ISO 19011:2026 changes actually contain, explains what those two changes contain, separates the standard's text from the interpretation layered on top of it, and sets out the concrete moves an audit team should make now.
Direct Answer: The ISO 19011:2026 changes, as stated by ISO, are two: an expansion of guidance on remote auditing methods through the introduction of guidance contained in ISO/IEC TS 17012, and an expansion of Annex A to cover remote auditing methods and virtual locations. The edition also states that it adopts the combined audit approach. The core structure and the seven principles of auditing carry forward unchanged. Because ISO 19011 is guidance rather than a requirements standard, the fourth edition took effect immediately on publication with no transition period, and no organization is certified to it.
ISO's Published Change List
What Are the ISO 19011:2026 Changes, According to ISO?
Two. Not. Six.
ISO 19011 is the international guidance standard that describes how to plan, conduct, report and follow up on management system audits, and how to evaluate the competence of the people who perform them. The ISO 19011:2026 changes matter because, although nobody certifies to ISO 19011, it sits underneath nearly every audit performed against ISO 9001, ISO 14001, ISO 45001 and ISO 13485. When this guidance moves, audit practice moves with it — which is exactly why it matters to report the movement accurately rather than generously.
The published fourth edition states the ISO 19011:2026 changes as two. The first is an expansion of guidance on remote auditing methods, achieved by introducing guidance contained in ISO/IEC TS 17012, the technical specification on the use of remote auditing methods in auditing management systems. The second is an expansion of Annex A to cover remote auditing methods and virtual locations. The edition additionally states that it adopts the combined audit approach, where two or more management systems of different disciplines are audited together.
That is the whole published change list. Everything else you have read about the ISO 19011:2026 changes is somebody's reading of what the expanded text implies — sometimes a good reading, sometimes not, but not a change ISO announced.
What sits outside the ISO 19011:2026 changes is the more consequential half of the story. The familiar four-part structure carries forward: principles of auditing, managing an audit program, conducting an audit, and evaluating auditor competence. The seven principles — integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, and risk-based approach — carry forward. Organizations that built audit programs on the 2018 edition need a focused update, not a redesign. MSI has mapped that update document by document in its companion analysis of the ISO 19011:2026 internal audit procedure — seven specific edits to a controlled document most organizations already have. The same discipline MSI brings to ISO consulting engagements applies here: read the revision, find the few places the system needs to bend, and adjust before the next audit cycle.
Separating Text From Interpretation
What Does the Commentary Get Wrong About the ISO 19011:2026 Changes?
Read. The. Source.
Direct Answer: Three claims about the ISO 19011:2026 changes circulate widely and none of them appears in ISO's statement of changes: that the revision expanded supply-chain and external-provider guidance, that it strengthened the risk-based approach, and that it added digital competence to auditor competence requirements. Each describes something the expanded text touches. None is a change ISO announced. The distinction matters because the audience for an audit program document is auditors — the one readership that will have read the source.
Search the term and you will find confident, well-written articles describing a substantial overhaul. They are not written in bad faith. They are written by people who read the expanded Annex A the ISO 19011:2026 changes delivered, noticed it discusses evidence handling, platform security, auditor capability and outsourced operations, and reasonably concluded that guidance in each of those areas had been strengthened. The trouble is the leap from “the new text discusses this” to “ISO changed this,” because the second claim invites organizations to spend effort on revisions the standard never asked for.
Three claims about the ISO 19011:2026 changes are worth naming specifically, without naming who published them.
“The revision expands supply-chain and external-provider guidance.” Auditing externally provided processes is a real subject, and remote methods are frequently how distributed supply chains get audited. But an expanded remote-methods annex that necessarily touches distributed operations is not the same as a supply-chain guidance expansion, and treating it as one leads teams to rewrite supplier audit criteria that did not move.
“The risk-based approach has been strengthened.” The risk-based approach was already one of the seven principles, and ISO 19011 has carried a published clause at 5.3 on audit program risks and opportunities since well before this edition. Both were true before May 2026. Choosing a remote method when on-site observation is essential is a genuine risk, and the expanded annex helps you think about it. That is the annex doing its job, not a strengthened principle.
“Digital competence is now a competence requirement.” This is the most useful of the three and still not a stated change. ISO 19011 carries published clauses at 7.2.3 on knowledge and skills and at 7.6 on maintaining and improving auditor competence, and neither is listed among the main changes. MSI's house standard is that auditors conducting remote audits should be competent in the specific platform the organization uses — a position MSI holds because 200+ audits attended make the case, not because the 2026 edition requires it. Labeling a house standard as a clause requirement is how consultants lose auditors' trust.
Nobody will write you a finding against ISO 19011. Any consultant who tells you otherwise is selling urgency rather than accuracy.
There is one more reason precision about the ISO 19011:2026 changes pays here. Because ISO 19011 is guidance, no clause of it can be raised as a nonconformity. The real mechanism is quieter: ISO 19011 underpins auditor training and certification schemes, so certificated auditors are retrained against the current edition and arrive with updated expectations. Where practice falls short of current good auditing practice, the finding gets written against Clause 9.2 of the standard you are certified to. Understanding that mechanism tells you where the ISO 19011:2026 changes are worth effort, and it is the same evidence-first logic MSI applies to internal audit planning and to the planning phase of internal audits.
Why Now
Why Did ISO Revise 19011 in 2026?
Reality. Caught. Up.
The 2018 edition was written for a world where audits happened in person and remote work was an awkward edge case. Then hybrid work, cloud-based quality systems, video conferencing and digital evidence repositories became ordinary. By 2026 the distance between what the guidance described and what auditors were actually doing had grown wide enough that the guidance risked becoming a historical document. The ISO 19011:2026 changes close that specific gap, and the narrowness of the change list is the point rather than a disappointment: the ISO 19011:2026 changes fixed what was broken and left alone what was working.
There is a useful way to frame the shift. The change is less about how an audit is conducted on the day and more about how it is designed long before anyone joins a call or walks a production floor. Remote auditing stops being something a team simply does when travel is inconvenient and becomes something the audit program plans for deliberately, with the method choice recorded and justified. That design-first mindset is the connective tissue running through both of the ISO 19011:2026 changes.
For leaders weighing how much attention this deserves, the honest answer is: more than a footnote, less than an emergency. There is no certificate at stake and no transition clock — with one important exception covered further down, where a 2026 requirements standard makes part of this territory mandatory in practice. But the audit is how an organization learns whether its management system actually delivers results, and the ISO 19011:2026 changes raise the bar on what a credible audit looks like. Treating the revision as a chance to sharpen the program rather than a compliance chore is the same reframe MSI argues for across the wider 2026 ISO revisions and certification strategy.
Change One · TS 17012 and Annex A
How Do the ISO 19011:2026 Changes Reshape Remote and Hybrid Audits?
Plan. Connect. Verify.
Direct Answer: Both of the ISO 19011:2026 changes concern remote auditing. The revision introduces guidance from ISO/IEC TS 17012 and expands Annex A to cover remote auditing methods and virtual locations. The practical consequence is that method selection — on-site, remote or hybrid — becomes a deliberate, recorded design decision driven by the evidence the audit objective demands, rather than a logistics choice made when travel is inconvenient.
Where a standards body puts its only two changes — and both of the ISO 19011:2026 changes are here — tells you where it thinks the attention belongs. Under the fourth edition, the decision about how an audit will be performed is made early and recorded. ISO/IEC TS 17012:2024 is the underlying document — a technical specification on the use of remote auditing methods in auditing management systems, applicable to first-, second- and third-party audits, addressing the conditions, possibilities and limitations of remote methods. It is worth naming in your audit program's reference list, because it is the source the 2026 guidance points to.
The expanded Annex A is where the practical substance of the ISO 19011:2026 changes sits: feasibility assessment, platform considerations, contingency planning for technology failure, and how to balance remote and on-site activity across a program. Auditors now have a shared reference for doing remote work well rather than improvising it, which is the difference between a method that survives scrutiny and one that merely happened.
What Counts as a Remote Auditing Method Now?
A remote auditing method is any technique that lets an auditor gather evidence and reach conclusions without being physically present at the location being audited. In practice that spans reviewing documented information through a shared portal, interviewing process owners over video, observing operations via a live camera feed, and analyzing data pulled directly from a quality management platform. The practical value of the ISO 19011:2026 changes is the recognition that these methods can be sequenced intelligently: examine documents and records remotely first, then reserve on-site time for the operational observations and process verification that genuinely require presence. The point is not to maximize remote work for its own sake but to put each method where it produces the most reliable evidence.
Virtual Locations vs. Remote Methods — What Is the Difference?
The revision sharpens a distinction that confused many teams under the prior edition. A remote method is how you audit; a virtual location is what you audit. A virtual location is a site that exists primarily in digital space — cloud infrastructure, a remote-work environment, a system with no single physical address — yet still falls within the audit scope. Expanded guidance in Annex A gives auditors direction on managing audits that span physical sites, virtual locations and the connections between them. For organizations operating across borders and time zones this clarity is the most immediately useful of the ISO 19011:2026 changes, and it pairs naturally with the architecture covered in MSI's guide to multi-site ISO certification and its work on multi-site procedure standardization.
Remote auditing is no longer something you do. It is something you design for — from the first line of the audit program to the last word of the report.
Measure Before You Edit · Free · No Email
Score Your Internal Audit Program in About Six Minutes
Before revising anything against the ISO 19011:2026 changes, find out which part of your program is actually weakest. The free Internal Audit Maturity Check rates it element by element on how it behaves during a busy week — not on how the document reads. Four levels per element, five standard paths, your band and priority order shown immediately, with nothing to enter first. Most teams find the weakest element is not the one they expected, which changes what the first edit should be.
Competence · MSI Reading
What Do the ISO 19011:2026 Changes Imply for Auditor Competence?
Skill. Judgment. Currency.
Direct Answer: ISO did not list competence among the ISO 19011:2026 changes, and the competence clauses at 7.2.3 and 7.6 were not announced as revised. What follows is MSI's reading: if remote auditing is now designed into the program deliberately, auditor competence has to cover the platform carrying the audit. That is a house standard drawn from 200+ audits attended, not a clause requirement, and your procedure should say so.
The reasoning follows from the ISO 19011:2026 changes even though the requirement is not there. A remote audit is only as reliable as the auditor's command of the platform carrying it. When an auditor fumbles a host control mid-session, evidence is lost and the audit's credibility erodes in front of the auditee. A procedure that says “auditors shall be competent in remote auditing tools” is too vague to be auditable, because the mechanics that affect evidence differ by platform.
Why Platform-Specific Competence Beats Generic Digital Skills
The differences are not cosmetic. Recording destination is the clearest example: Microsoft Teams typically routes recordings into SharePoint or OneDrive under the organization's retention rules, while Zoom may store them in its cloud or locally depending on configuration — and an audit recording can itself become a controlled record subject to your retention policy. Host and presenter roles differ, governing who can share a screen, grant remote control or admit a participant. Lobby and waiting-room settings determine who is admitted and when, which matters when sensitive evidence is on screen. File-exchange paths that IT permits on one platform may be disabled on another, changing how an auditee submits documents mid-session.
Because the mechanics the ISO 19011:2026 changes normalized affect evidence capture, retention and confidentiality, MSI's house standard names the platform the organization actually uses and requires auditors to be trained on its specifics — verified and recorded the same way any other auditor qualification is recorded. Continuing professional development should include audit methods and digital techniques so competence stays current rather than freezing at initial qualification. The supporting framework sits inside MSI's internal audit services, the discipline is taught in the ISO 9001 two-day internal auditing course, and the wider case for treating internal audit skills as a profession rather than a rotating assignment is made across MSI's ISO internal auditor training.
Where Do AI and Data Analytics Fit?
Auditors increasingly rely on technology — cloud platforms, video conferencing, data analytics, automated systems, and in some settings drones for physical observation. None of this is named in ISO's list, and it is worth being clear that the revision did not add an analytics clause. What the ISO 19011:2026 changes did was normalize remote and digitally mediated auditing, which makes the judgment question unavoidable. Data analytics can let an auditor examine an entire population of records rather than a hand-pulled sample, which strengthens evidence — but only if the auditor understands how the data was generated and whether it can be trusted.
The durable principle is proportionate, informed use: pick the technology that fits the audit objective, apply professional judgment to what it produces, and stay alert to the uncertainties automated and remote methods introduce. Embrace useful technology, never outsource judgment to it. That balance mirrors the procedure-first philosophy MSI brings to digitization in its work on ISO compliance automation and to the harder version of the same problem in auditing AI agents. The same test applies to the documents being audited: what makes an effective ISO procedure is whether practice and document still match, which is exactly what a well-designed audit sets out to determine.
Risk · What Was Already There
Do the ISO 19011:2026 Changes Strengthen Risk-Based Auditing?
Focus. Where. Risk-Lives.
Direct Answer: No — and this is the most common misreport of the ISO 19011:2026 changes. The risk-based approach was already one of the seven principles, and the standard already carried a clause on audit program risks and opportunities. Nothing about that was listed as changed. What did change is that method selection is now a design decision, which introduces a risk category most programs never considered: choosing remote when the evidence demands presence.
Start with what is citable, because it predates the ISO 19011:2026 changes entirely. ISO 9001:2015 Clause 9.2.2 a) requires the audit program to take into consideration the importance of the processes concerned, changes affecting the organization, and the results of previous audits. ISO 19011 carries a published clause at 5.3 on audit program risks and opportunities. Those are structural facts, and they were structural facts in 2018 as well. What neither document does is tell you what to do about the importance you have considered, and that is where most audit programs quietly stop.
MSI's house standard, developed across 28 years and 200+ audits attended, is that risk should change five properties of an audit. Frequency is only the first, and on its own it changes almost nothing about what the audit finds.
| What Varies | Higher Risk | Lower Risk |
|---|---|---|
| Frequency | Every cycle, re-audited early where findings recur | Longer interval, with the basis recorded |
| Depth | Walked end to end, including the handoffs | Key controls sampled |
| Sample size | Large enough to conclude about the system | Sufficient to confirm the control operates |
| Method | On-site, including the shift where supervision is thinnest | Records reviewed remotely |
| Auditor | Most experienced available | Any qualified auditor on the register |
Whatever the ISO 19011:2026 changes did or did not alter, a low-risk process and a high-risk process both audited annually, with the same checklist and the same two-hour slot, have not been differentiated in any way that changes what the audit finds. The practical move is to write those five levers into the planning section of your procedure, with the risk basis recorded per process rather than asserted for the program as a whole. MSI details the approach in its analysis of internal audit risk mitigation strategies, applies it at the aspect level in its guide to ISO 14001 environmental aspects, and transfers it outside the certified-manufacturer world in its work on government internal audit. MSI client experience suggests teams that vary all five levers get more from fewer audit days than teams that vary only the calendar.
Evidence · MSI Reading
What Do the ISO 19011:2026 Changes Mean for Evidence and Data Security?
Verify. Trace. Protect.
Direct Answer: The evidence-based approach is one of the seven principles and was not listed among the ISO 19011:2026 changes. What the revision does is make remote evidence ordinary, and remote evidence carries a reliability question that walk-through evidence does not. MSI's house standard is that auditors confirm remote evidence is verifiable and traceable to a controlled source before relying on it, and escalate to on-site verification when it is not.
ISO/IEC TS 17012, the source behind the ISO 19011:2026 changes, exists precisely because remote methods carry conditions and limitations that on-site methods do not. When evidence arrives through a screen rather than a walk-through, a new question attaches to it: can this be relied upon? A document emailed mid-audit, a screen-shared dashboard, a remotely demonstrated process — each carries a reliability question. The discipline is to evaluate whether information collected remotely is verifiable, sufficiently specific and traceable to a source, which protects the audit conclusion from resting on evidence that looked convincing on a video call but could not be confirmed afterward.
The data-security half matters just as much. When an organization grants an auditor access to live systems, records and recordings, both parties inherit a responsibility to protect that data, and the procedure should set expectations for how audit evidence and recordings are handled, stored and retained. This is where auditing meets the broader governance conversation MSI raises in its work on change management and the audit trail, and it also touches a distinction auditors are increasingly asked to hold: conformity to a standard and compliance with the law are assessed differently, which is why MSI treats evaluation of compliance as its own discipline rather than a sub-task of the internal audit. The evidence discipline extends to behavioral requirements too, as MSI sets out in its guide to auditing quality culture, and it underpins why MSI treats ISO certification as a business asset rather than a paperwork exercise.
Guidance Meets Shall
Which 2026 Requirement Turns the ISO 19011:2026 Changes Into an Obligation?
Guidance. Meets. Shall.
Direct Answer: The ISO 19011:2026 changes carry no deadline of their own — but ISO 14001:2026, published 15 April 2026, revised Clause 9.2.2 so that defining scope and criteria for each internal audit is no longer sufficient. Each audit must now also define its objectives, and three documented information items must be available, the first being the audit program itself. Environmental certificate holders have until 30 April 2029 to transition.
This is the single most practical reason to read the ISO 19011:2026 changes now rather than later. Guidance standards are easy to defer because nothing enforces them. A requirements standard is different. ISO 14001:2026 is published, in force, and its internal audit clause now asks for something most audit programs do not produce. Auditors have long recorded scope and criteria as routine. Objectives were treated as implicit: the audit happens because the schedule says it happens. That is no longer defensible in an environmental management system, and the ISO 19011:2026 changes are the reference that tells you what a well-formed objective looks like.
One correction worth making, because it is repeated widely and it is wrong: per-audit objectives are not new to the ISO catalog. ISO 7101:2023 Clause 9.2.2 a) has required audit objectives since 2023, and healthcare organizations have operated under that requirement for three years. What changed in 2026 is that the obligation arrived in ISO 14001. If you run an integrated system with a healthcare arm, the field you need may already exist in one corner of your business. MSI's ISO 7101 healthcare quality overview covers where that clause sits.
The second ISO 14001:2026 audit change sits outside the ISO 19011:2026 changes and is the harder one and the one most transition plans miss. The 2015 edition required the organization to retain documented information as evidence of the implementation of the audit program and the audit results — two items, both retrospective. The 2026 edition requires three items to be available, and the first is the audit program itself. Retained means kept: you can produce it when asked. Available means current, retrievable and under control — the version an auditor sees is the version the program is actually running to, with a revision history, an owner and a review trigger. In most organizations the audit program is an unversioned spreadsheet on the program manager's desktop, which satisfies neither test convincingly.
The effect compounds across standards. If a single audit program covers quality and environment together, the stricter requirement governs the shared procedure — which means the objectives discipline arrives on the quality side too, whether or not ISO 9001 asks for it. MSI works through that sequencing in its guide to the ISO 9001 and 14001 transition, the certificate mechanics in its ISO 14001 certification guide, and the downstream effect on the improvement loop in ISO 14001 continual improvement. The short version: write the objective once, in one integrated procedure, and both systems inherit the sharper audit.
How Do You Write an Audit Objective Clause 9.2.2 Will Accept?
A defensible objective passes three tests. It names what the audit is trying to determine, not what it will look at. It is tied to something real — a significant aspect, a prior finding, a process change, a performance question leadership has asked. And it is answerable with evidence obtainable inside the stated scope. “Audit the waste management process” fails all three: it is a scope statement wearing an objective's label. “Determine whether the corrective actions from the previous waste-segregation finding were implemented and are still holding at the point of generation” passes all three, and it tells the auditor where to stand and what to ask for.
Write the objective as a question the audit will answer. Then check whether your chosen method can answer it. An objective about whether segregation holds at the point of generation cannot be satisfied by a document review over video — and stating the objective first makes that obvious before anyone books a remote session.
That interlock is the real value of reading the ISO 19011:2026 changes alongside ISO 14001:2026. ISO 14001:2026 makes the objective mandatory; the ISO 19011:2026 changes make the method a recorded decision; and the objective is what makes the method choice defensible. Across 200+ audits attended, MSI's observation is consistent: audits with a written objective produce findings leadership acts on, and audits without one produce reports that get filed. The full set of edits this implies for your existing document is laid out in MSI's ISO 19011:2026 internal audit procedure analysis — seven edits, none of them a rewrite.
For EHS Managers on the 2029 Clock
Move Your EMS From 2015 to 2026 in a Week, Not a Quarter
The ISO 14001:2026 Procedure Templates & Guides package is the transition kit: every 2026-edition EMS procedure written to the new text — including the internal audit procedure with the Clause 9.2.2 objectives field already built in and the audit program defined as a controlled document, the new Clause 6.3 planning-of-changes requirement, and the restructured management review — plus the transition course. Built for experienced ISO 14001 managers who know their system and need the documents updated, not explained. A week of adaptation instead of a quarter of drafting.
See the ISO 14001:2026 transition package →
Need the audit team trained to the revised clauses as well? ISO 14001:2026 Internal Auditing is the two-day course built around auditing the 2026 edition rather than the old checklist, and the ISO 14001:2026 Transition Course walks the clause changes end to end, with the first module free.
Where Audit Results Land
Where Do the ISO 19011:2026 Changes Land in Your Management Review?
Feed. Decide. Record.
Direct Answer: The ISO 19011:2026 changes do not stop at the audit report. Audit results are a mandatory management review input in every standard MSI implements, so a better-designed audit program only pays off if the review record is built to receive what it produces. ISO 14001:2026 restructured Clause 9.3 into three subclauses, renamed outputs as results, and now asks for environmental performance information framed as trends — including trends in audit results.
Most conversations about the ISO 19011:2026 changes end at the audit report. That is the wrong place to stop, because an internal audit finding has no authority until leadership decides something about it. Every management system standard MSI works in treats audit results as a required input to top management's review — ISO 9001 at Clause 9.3, ISO 14001:2026 at Clause 9.3.2, ISO 45001 at Clause 9.3, and ISO 13485 at Clause 5.6.2, where the review sits inside Management Responsibility rather than Performance Evaluation. The ISO 19011:2026 changes improve what arrives at that table. They do not improve what the table does with it.
What Changed in the ISO 14001:2026 Management Review Clause?
Clause 9.3 in the 2026 edition is split three ways: 9.3.1 sets the general obligation for top management to review the system at planned intervals for continuing suitability, adequacy and effectiveness; 9.3.2 lists the inputs; and 9.3.3 lists the results. The word “outputs” is gone. The results must now include conclusions on suitability, adequacy and effectiveness, decisions on continual improvement opportunities, decisions on any need for changes including resources, actions where environmental objectives have not been achieved, opportunities to improve integration of the management system with other business processes, and any implications for the strategic direction of the organization. That last item is a meaningful escalation: the review is no longer a status meeting, it is a governance input.
The inputs moved too. Clause 9.3.2 now asks for information on environmental performance framed explicitly as trends — trends in nonconformities and corrective actions, in monitoring and measurement results, in meeting compliance obligations, and in audit results. A single-cycle number no longer satisfies the clause on its face. This is the quiet connection to the ISO 19011:2026 changes: audit results reported as a trend require an audit program designed to produce comparable results year over year, which is exactly what defined objectives and documented method choices make possible. Absent those, each audit measures something slightly different and the trend line means nothing. MSI works the whole clause through in its guide to the ISO 14001:2026 management review.
Why Do Habit-Built Review Agendas Fail Under the 2026 Editions?
Ask which clause a given section of your management review satisfies, and there is often no answer — because the agenda was assembled from what last year's review covered, in the order it covered it. That works until the review meets an auditor. The requirements an organization has never performed are precisely the ones a habit-built agenda cannot surface: if nobody ever established audit objectives, no section of the agenda asks for them, and the omission is invisible from inside the document.
Organizations running integrated systems feel this hardest, because an agenda built from the standard the quality manager knows best drops the inputs the other standards carry alone. ISO 45001 is the only one in the family that requires the results of the review to leave the room and be communicated to workers and their representatives. ISO 13485 requires both a documented procedure and a record where the harmonized-structure standards require only the record. MSI sets out the discipline in its guide to crafting an ISO management review procedure and the evidentiary standard in why the management review record must prove it.
Close the Loop the Audit Opens
Management Review Toolkits, Built From the Clause Instead of Last Year's Agenda
MSI's ISO Management Review Toolkits are eleven matched pairs — a PowerPoint deck to present from and a Word minutes form to record into — generated from the same numbered section list, with the clause reference printed under every section title. Section 12 on the slide is Section 12 on the form, so the presenter and the recorder are never on different items. Where a section is MSI practice rather than a requirement, it says so, so an auditor can tell the difference and so can you. The combined editions matter most here, because one integrated audit program is where the 2026 objectives requirement reaches standards that never asked for it.
Compare the eleven management review toolkits →
The ISO 9001 and 14001:2026 toolkit runs 29 sections; the ISO 45001 and 14001:2026 HSE toolkit runs 30 with fourteen divergences resolved; and the ISO 14001:2026 toolkit carries a ten-row comparison against 2015 showing what moved and what each change means for your record.
The Wider 2026 Wave
How Do the ISO 19011:2026 Changes Fit the Wider 2026 Standards Wave?
Aligned. Current. Connected.
The ISO 19011:2026 changes did not arrive in isolation. It arrived in the middle of a broader refresh of the management-system catalog. ISO 14001:2026 is published and in force. ISO 9001:2026 publishes on 16 September 2026, following an FDIS ballot that closed on 9 July 2026 — days away as this article is updated, which is why the preparation window that felt comfortable in the spring has closed. The revision retains the Harmonized Structure, so the auditing vocabulary and the clause architecture stay in step. That alignment matters because organizations running integrated management systems audit against several standards at once; if the auditing guidance drifted from the standards being audited, every integrated audit would inherit the mismatch.
The 2024 climate action amendment sits underneath all of this, adding climate change wording to Clauses 4.1 and 4.2 of more than thirty management system standards, with certification bodies sampling against it since March 2024. ISO 14001:2026 carries it further than most, naming environmental conditions such as pollution levels, availability of natural resources, climate change, biodiversity and ecosystem health among the issues an organization shall determine under Clause 4.1. For audit teams that means climate-related context is a legitimate line of inquiry where it bears on the system being audited. One distinction is worth writing down: ISO 13485 is not among the amended standards — it is not built on the harmonized structure and was not amended. If your audit program treats all five standards as having received it, an ISO 13485 auditor will notice.
One piece of accreditation context changed underneath all of this as well. The International Accreditation Forum and the International Laboratory Accreditation Cooperation both ceased operations on 1 January 2026 and were unified into Global Accreditation Cooperation Incorporated (Global ACI), a single international accreditation organization with one governance framework and one mutual recognition arrangement. Certificates and accreditations issued under the former arrangements remain recognized, and specified legacy documents stay valid until equivalent Global ACI documents are adopted. If your audit program or procedure still cites IAF documents by name, that reference now needs a look. Leaders tracking how the revisions interconnect will find the through-line in MSI's coverage of the ISO 9001:2026 ethics and culture update, its companion piece on ISO 9001:2026 for boardrooms, and its guide to keeping the watch list current through regulatory change management.
What Do the ISO 19011:2026 Changes Mean for Auditing Quality Culture?
Here the timing of the two revisions gets genuinely interesting. ISO 9001:2026 introduces a quality-culture expectation at Clause 5.1 — a leadership requirement with no predecessor in the 2008 or 2015 editions. Culture is exactly the kind of subject that invites impressionistic auditing: a walk around the floor, a sense that people seem engaged, a conclusion nobody can trace back to anything. The evidence-based principle carried forward intact through the ISO 19011:2026 changes makes that approach no easier to defend than it was before, and the arrival of a behavioral clause raises the stakes on getting it right.
The practical answer is that culture has observable outputs — who raised concerns and what happened to them, how long issues stayed open, whether people stopped work when they should have, what leadership actually did with what it heard. Those are records, and records can be sampled, traced and tested exactly as the principle requires. Getting this settled before the September publication is the difference between an audit program that is ready and one that improvises through its first surveillance visit. A durable quality management mindset is what makes the difference hold.
The Action List
What Should Smart Audit Teams Do About the ISO 19011:2026 Changes Now?
Read. Refresh. Re-train.
Direct Answer: Acting on the ISO 19011:2026 changes does not require rebuilding your audit program. Six focused updates cover it: record how method choices are made; add a defined-objectives field to every audit plan; bring the audit program itself under document control; update auditor competence criteria to name the platform you actually use; strengthen evidence-reliability practice for remote work; and rebuild the management review agenda so it receives audit results as a trend rather than a single number. Then train to the revised document.
Sequence matters more than speed when acting on the ISO 19011:2026 changes. Start with document control of the audit program, because that is the long-lead item — it touches your document management system and it is the ISO 14001:2026 requirement most transition plans miss. The objectives field is a same-week change and carries the other requirements-standard obligation behind it, so it comes next. Method-selection recording follows, since it is the direct consequence of both ISO 19011:2026 changes. Competence criteria, evidence-reliability practice and reporting updates can move alongside your next training cycle. The management review agenda is best timed to your next review, when you are rebuilding it anyway.
Then train to the ISO 19011:2026 changes. Your internal auditors and any supplier auditors you rely on should understand what changed, what did not, and where MSI's house standards go beyond the text — that last distinction is what keeps a well-read auditor on your side. MSI's internal audit services, its internal audit follow-up framework and its continuous-improvement follow-up guidance are built to close exactly this loop. Teams that prefer a guided path can lean on MSI's approach to certification audits, the SurePath turnkey certification program, the year-round rhythm of SureResults, or The Portrait for an independent read on where the system actually stands. The full audit lifecycle — internal, surveillance and certification — is mapped in MSI's guide to the ISO audit, and the program-level view sits in building an internal audit program. For the system-level document the procedures hang from, see the ISO manual templates and guides.
Start From a Finished Document
The Procedures This Revision Touches, Already Written
Every edit the ISO 19011:2026 changes imply lands in a document somebody has to write — the audit program, the competence criteria, the evidence rules, the management review that receives the results. MSI's ISO Procedure Templates & Guides are those documents: thirteen procedure families across ISO 9001, 13485, 14001:2026, 45001 and 7101, complete and editable in Word, written to one architecture so the set interlocks. The decisions that are genuinely yours are marked; the rest are already made from 28 years of consulting practice. Set one beside the procedure you are using now and the differences are visible in minutes — the clauses your version answers implicitly, the records it never names, the sections an auditor will ask for that were never written down. Every procedure carries a free maturity check you can score your current version against first, without buying anything.
Ready to Update Your Audit Program Without Overcorrecting?
The hardest part of a revision like this is knowing what to leave alone. If your audit program, competence criteria, management review agenda or auditor training need to catch up with the ISO 19011:2026 changes — and with the ISO 14001:2026 requirements behind them — MSI can map the few adjustments that matter for your standards and your operation, and identify the ones the commentary invented. Begin with a planning session: a working conversation, not a sales script.
Call 760-434-9141 to plan a session.
Frequently Asked Questions
Common Questions About the ISO 19011:2026 Changes
Ask. Answer. Apply.
Is it ISO 19001 or ISO 19011?
There is no ISO 19001. The auditing guidance standard is ISO 19011, and its current edition is the fourth, published 27 May 2026. The number is easy to mistype because ISO 9001 — the quality management requirements standard — is the one most people reach for first, and ISO 9001:2026 publishes on 16 September 2026. If you are looking for how to plan and conduct audits, you want ISO 19011:2026. If you are looking for what a quality management system must contain, you want ISO 9001.
What exactly are the ISO 19011:2026 changes?
ISO states two main changes: an expansion of guidance on remote auditing methods through the introduction of guidance contained in ISO/IEC TS 17012, and an expansion of Annex A to cover remote auditing methods and virtual locations. The edition also states that it adopts the combined audit approach, where two or more management systems of different disciplines are audited together. Claims that the revision expanded supply-chain guidance, strengthened the risk-based approach, or added digital competence requirements do not appear in ISO's statement of changes.
When was ISO 19011:2026 published, and is there a transition period?
It was published on 27 May 2026 as the fourth edition, withdrawing ISO 19011:2018 the same day. Because ISO 19011 is a guidance standard rather than a requirements standard, there is no transition period and no window in which both editions remain current. No organization certifies to ISO 19011, so no certificate or deadline is at stake. Audit program documents still citing the 2018 edition are citing a withdrawn standard.
Can a certification body write a finding against ISO 19011:2026?
No. ISO 19011 is guidance and contains no auditable requirements. The real mechanism is indirect: ISO 19011 underpins auditor training and certification schemes, so certificated auditors are retrained against the current edition and arrive with updated expectations. Where practice falls short of current good auditing practice, the finding is written against Clause 9.2 of the standard you are certified to.
Do the ISO 19011:2026 changes require me to redesign my audit program?
No. The structure and the seven principles carry over from the 2018 edition, so programs built on the prior guidance do not need a rebuild. The practical work is a focused refresh: record how audit methods are chosen, add defined objectives to every audit plan, bring the audit program under document control, update competence criteria to name your platform, strengthen evidence-reliability practice for remote work, and check that the management review agenda still receives what the program now produces.
Do the ISO 19011:2026 changes require an objective for every internal audit?
ISO 19011:2026 is guidance, so on its own it recommends rather than requires. The obligation comes from ISO 14001:2026, published 15 April 2026, which revised Clause 9.2.2 so each internal audit must define its objectives in addition to scope and criteria. Environmental certificate holders have until 30 April 2029 to transition. ISO 7101:2023 has required audit objectives since 2023, so the requirement is new to ISO 14001 rather than new to the standards.
Does ISO 19011:2026 make remote auditing mandatory?
No. The revision does not mandate remote auditing; it formalizes how to plan and conduct remote and hybrid audits well when you choose to use them. The decision between on-site, remote and hybrid should be driven by risk, audit scope and the quality of evidence each method can deliver — not by habit or convenience. On-site auditing remains entirely appropriate, and sometimes essential, where physical observation is the only reliable way to gather evidence.
How do the ISO 19011:2026 changes affect the management review?
Audit results are a mandatory management review input in every standard MSI implements, so improving the audit program changes what arrives at the review table. ISO 14001:2026 restructured Clause 9.3 into three subclauses, renamed outputs as results, and now asks for environmental performance information framed as trends, including trends in audit results. Reporting a trend requires audits that measure comparable things across cycles — which is what defined objectives and documented method choices deliver.
How do the ISO 19011:2026 changes relate to ISO 9001:2026?
ISO 9001:2026 publishes on 16 September 2026 after an FDIS ballot that closed 9 July 2026. The revision retains the Harmonized Structure, so terminology stays aligned with the auditing guidance. The most audit-relevant addition is the quality-culture expectation at Clause 5.1, which has no predecessor in earlier editions. Auditing something behavioral still requires verifiable records, so the practical work is identifying which existing records evidence culture.
Which management systems does ISO 19011:2026 apply to?
ISO 19011 provides generic guidance applicable to audits of any management system, which is what makes it valuable for organizations running integrated systems — and why the fourth edition's adoption of the combined audit approach matters. It underpins auditing across ISO 9001 quality, ISO 14001 environmental, ISO 45001 occupational health and safety, ISO 13485 medical device and ISO 7101 healthcare management systems. Discipline-specific competence is addressed in sector documents; ISO 19011 focuses on generic audit competence and method.
How can MSI help my organization adapt to the ISO 19011:2026 changes?
MSI translates the revision into the specific adjustments your audit program, competence criteria, management review record and training actually need — and, just as usefully, identifies the ones the commentary invented. With 28 years of experience, 80+ certifications supported, 200+ audits attended and 600+ professionals trained, MSI can refresh your program, update your auditor qualification path and align your approach with the standards you operate under. Start with the free Internal Audit Maturity Check, take the finished procedure templates, or call 760-434-9141 to plan a session.
Related Reading
Build the Program, Not Just the Procedure
Plan. Audit. Improve.
- ISO 19011:2026 Internal Audit Procedure — the seven edits this revision implies for your controlled document
- Internal Audit Planning — the program-level sequence behind the procedure
- Internal Audit Follow-Up — why most findings never close properly
- Internal Audit Risk Mitigation Strategies — where to concentrate audit days
- Management Review Procedure — where audit results are required to land
- ISO 14001:2026 Management Review — what actually moved in Clause 9.3
- Corrective Action Procedure — the document every finding hands off to
- Integrated Management Systems — auditing five standards with one program
- MSI Blog — the full library across five standards
References & Authoritative Sources
- ISO — ISO 19011:2026, Guidelines for auditing management systems
- ISO — ISO 19011:2018 (withdrawn 27 May 2026)
- ISO — ISO/IEC TS 17012:2024, Guidelines for the use of remote auditing methods
- ISO — ISO 9001 Quality management
- ISO — ISO 14001 Environmental management
- ISO — ISO 45001 Occupational health and safety
- ISO — ISO 13485 Medical devices
- ISO — ISO 7101:2023 Healthcare organization management systems
- ISO — ISO 9000 Fundamentals and vocabulary
- ISO — ISO and climate change
- ISO — ISO/IEC Directives and policies
- Global ACI — Global Accreditation Cooperation Incorporated (assumed the roles of IAF and ILAC on 1 January 2026)
- Global ACI — Global ACI documents, including valid legacy documents and the cross-reference table
- ANAB — ANSI National Accreditation Board
- ASQ — ASQ auditing resources
- eCFR — 21 CFR Part 820, Quality Management System Regulation
- EPA — Compliance and enforcement
- OSHA — Recommended practices for safety and health programs
- NIST — Cybersecurity Framework (for organizations handling audit evidence on shared platforms)
- The Institute of Internal Auditors — IIA professional guidance (a separate discipline from ISO management system auditing, referenced for contrast)
About Management Systems International (MSI)
Diana Lynn is President and Principal ISO Consultant at Management Systems International, LLC, a veteran-owned, female-owned ISO consulting firm she co-founded in 1998. Across 28 years of experience, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries.
MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.
msi-international.com · 760-434-9141