MSI site analytics pixel

ISO 19011:2026 Changes: Why Smart Audit Teams Adapt Now

Scope of this guide: This covers ISO 19011:2026 as it applies to management system auditing — ISO 9001, ISO 13485, ISO 14001, ISO 45001 and ISO 7101. Where this article states what the standard changed, it reports ISO’s own published statement of changes. Where it goes beyond that statement, it says so and calls it MSI’s reading or MSI’s house standard.

Auditing Management Systems · 2026 Revision

The ISO 19011:2026 changes are narrower than almost everything written about them, and knowing exactly how narrow is what separates a focused audit program update from a wasted quarter. Published on 27 May 2026 as the fourth edition of Guidelines for auditing management systems, the revision withdrew ISO 19011:2018 the same day. ISO’s own statement of what changed lists two items. Much of the commentary circulating since May lists five or six.

Then, on 16 September 2026, the ground moved again. ISO 9001:2026 published with a revised Clause 9.2.2 that now asks every internal audit to define its objectives — the same requirement ISO 14001:2026 introduced in April. Two requirements standards now point at the guidance. This article reports what the ISO 19011:2026 changes actually contain, surfaces the details inside the fourth edition that most summaries skip, separates the standard’s text from the interpretation layered on top of it, and sets out the concrete moves an audit team should make now. It draws on 28 years of MSI practice, 200+ audits attended, 80+ certifications supported and 600+ professionals trained.

Direct Answer: The ISO 19011:2026 changes, as stated by ISO, are two: an expansion of guidance on remote auditing methods through the introduction of guidance contained in ISO/IEC TS 17012, and an expansion of Annex A to cover remote auditing methods and virtual locations. The edition also states that it adopts the combined audit approach. The core structure and the seven principles of auditing carry forward unchanged. Because ISO 19011 is guidance rather than a requirements standard, the fourth edition took effect immediately on publication with no transition period, and no organization is certified to it.

Free Download · PDF Checksheet

ISO 9001 / ISO 19011:2026 Internal Audit Program Checksheet

Check your audit program against the 2026 changes in one pass: per-audit objectives, method selection, remote-audit controls, and the program under document control. Enter your details and the checksheet opens instantly. We will email you a copy too.

ISO 19011:2026 Internal Audit Program Checksheet Download

ISO’s Published Change List

What Are the ISO 19011:2026 Changes, According to ISO?

Two. Not. Six.

ISO 19011 is the international guidance standard that describes how to plan, conduct, report and follow up on management system audits, and how to evaluate the competence of the people who perform them. The ISO 19011:2026 changes matter because, although nobody certifies to ISO 19011, it sits underneath nearly every audit performed against ISO 9001, ISO 14001, ISO 45001 and ISO 13485. When this guidance moves, audit practice moves with it — which is exactly why it matters to report the movement accurately rather than generously.

The published fourth edition states the ISO 19011:2026 changes as two. The first is an expansion of guidance on remote auditing methods, achieved by introducing guidance contained in ISO/IEC TS 17012, the technical specification on the use of remote auditing methods in auditing management systems. The second is an expansion of Annex A to cover remote auditing methods and virtual locations. The edition additionally states that it adopts the combined audit approach, where two or more management systems of different disciplines are audited together, and it now draws its core audit definitions from ISO 9000:2026, the vocabulary standard revised alongside ISO 9001.

That is the whole published change list. Everything else you have read about the ISO 19011:2026 changes is somebody’s reading of what the expanded text implies — sometimes a good reading, sometimes not, but not a change ISO announced.

What sits outside the ISO 19011:2026 changes is the more consequential half of the story. The familiar four-part structure carries forward: principles of auditing, managing an audit program, conducting an audit, and evaluating auditor competence. The seven principles — integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, and risk-based approach — carry forward. Organizations that built audit programs on the 2018 edition need a focused update, not a redesign. MSI has mapped that update document by document in its companion analysis of the ISO 19011:2026 internal audit procedure — seven specific edits to a controlled document most organizations already have. The same discipline MSI brings to ISO consulting engagements applies here: read the revision, find the few places the system needs to bend, and adjust before the next audit cycle.


Separating Text From Interpretation

What Does the Commentary Get Wrong About the ISO 19011:2026 Changes?

Read. The. Source.

Direct Answer: Three claims about the ISO 19011:2026 changes circulate widely and none of them appears in ISO’s statement of changes: that the revision expanded supply-chain and external-provider guidance, that it strengthened the risk-based approach, and that it added digital competence requirements. Each describes something the expanded text touches. None is a change ISO announced. The distinction matters because the audience for an audit program document is auditors — the one readership that will have read the source.

Search the term and you will find confident articles describing a substantial overhaul. They are written by people who read the expanded Annex A the ISO 19011:2026 changes delivered, saw it discuss evidence handling, platform security and auditor capability, and concluded each area had been strengthened. The trouble is the leap from “the new text discusses this” to “ISO changed this,” which sends organizations after revisions the standard never asked for.

“The revision expands supply-chain and external-provider guidance.” Auditing externally provided processes is a real subject, and remote methods are frequently how distributed supply chains get audited. But an expanded remote-methods annex that necessarily touches distributed operations is not the same as a supply-chain guidance expansion, and treating it as one leads teams to rewrite supplier audit criteria that did not move.

“The risk-based approach has been strengthened.” The risk-based approach was already one of the seven principles, and ISO 19011 has carried a published clause at 5.3 on audit program risks and opportunities since well before this edition. Both were true before May 2026. Choosing a remote method when on-site observation is essential is a genuine risk, and the expanded annex helps you think about it. That is the annex doing its job, not a strengthened principle.

“Digital competence is now a competence requirement.” This is the most useful of the three and still overstated. ISO 19011 is guidance, so nothing in it is a requirement. The fourth edition’s text does say auditor competence should include the technical skills to use the technology carrying a remote audit, and its knowledge-and-skills clause at 7.2.3 names artificial-intelligence-based evaluation tools as an example of emerging technology auditors should understand. But competence is not listed among the main changes, and “should” in a guidance standard is not “shall.” MSI’s house standard goes further than the text — auditors should be competent in the specific platform the organization uses — a position MSI holds because 200+ audits attended make the case. Labeling a house standard as a clause requirement is how consultants lose auditors’ trust.

Nobody will write you a finding against ISO 19011. Any consultant who tells you otherwise is selling urgency rather than accuracy.

There is one more reason precision about the ISO 19011:2026 changes pays here. Because ISO 19011 is guidance, no clause of it can be raised as a nonconformity. The real mechanism is quieter: ISO 19011 underpins auditor training and certification schemes, so certificated auditors are retrained against the current edition and arrive with updated expectations. Where practice falls short of current good auditing practice, the finding gets written against Clause 9.2 of the standard you are certified to — and ISO 9001:2026 now points to ISO 19011 by name in a note under that clause. Understanding that mechanism tells you where the ISO 19011:2026 changes are worth effort, and it is the same evidence-first logic MSI applies to internal audit planning and to the planning phase of internal audits.

Start From a Finished Document

Seven Edits or a Finished Document? Compare Yours in Minutes.

Every edit the ISO 19011:2026 changes imply lands in a document somebody has to write — the audit program, the per-audit objectives, the method-selection record, the competence criteria, the rules for screenshots and recordings. MSI’s ISO Procedure Templates & Guides are those documents already written: procedure families across ISO 9001, 13485, 14001:2026, 45001 and 7101, complete and editable in Word, built on one architecture so the set interlocks. The decisions that are genuinely yours are marked; the rest are already made from 28 years of consulting practice.

Set one beside the procedure you run today and the differences show up in minutes — the clauses your version answers only implicitly, the records it never names, the sections an auditor will ask for that were never written down. Every procedure carries a free maturity check you can score your current version against before you buy anything, and any template package purchase is credited in full toward an MSI consulting project, SurePath or SureResults.

See the ISO procedure templates and guides →


Why Now

Why Did ISO Revise 19011 in 2026?

Reality. Caught. Up.

The 2018 edition was written for a world where audits happened in person and remote work was an awkward edge case. Then hybrid work, cloud-based quality systems, video conferencing and digital evidence repositories became ordinary. By 2026 the distance between what the guidance described and what auditors were actually doing had grown wide enough that the guidance risked becoming a historical document. The ISO 19011:2026 changes close that specific distance, and the narrowness of the change list is the point rather than a disappointment: the ISO 19011:2026 changes fixed what was broken and left alone what was working.

The fourth edition’s own introduction gives a second reason for the ISO 19011:2026 changes. Since 2018, a wave of new management system standards has been published, most sharing a common structure, identical core requirements and common terms. That calls for auditing guidance that is broader and more generic — which is why the edition adopts the combined audit approach and treats an integrated system as a combined audit for auditing purposes.

There is a useful way to frame the shift. The change is less about how an audit is conducted on the day and more about how it is designed long before anyone joins a call or walks a production floor. Remote auditing stops being something a team simply does when travel is inconvenient and becomes something the audit program plans for deliberately, with the method choice recorded and justified. That design-first mindset is the connective tissue running through both of the ISO 19011:2026 changes.

For leaders weighing how much attention the ISO 19011:2026 changes deserve: more than a footnote, less than an emergency. There is no certificate at stake for the guidance itself, but two 2026 requirements standards make part of this territory mandatory in practice. The audit is how an organization learns whether its management system actually delivers results, and the ISO 19011:2026 changes raise the bar on what a credible audit looks like. Treating the revision as a chance to sharpen the program rather than a compliance chore is the same reframe MSI argues for across the wider 2026 ISO revisions and certification strategy.


Change One · TS 17012 and Annex A

How Do the ISO 19011:2026 Changes Reshape Remote and Hybrid Audits?

Plan. Connect. Verify.

Direct Answer: Both of the ISO 19011:2026 changes concern remote auditing. The revision introduces guidance from ISO/IEC TS 17012 and expands Annex A to cover remote auditing methods and virtual locations. The practical consequence is that method selection — on-site, remote or hybrid — becomes a deliberate, recorded design decision driven by the evidence the audit objective demands, rather than a logistics choice made when travel is inconvenient.

Where a standards body puts its only two changes — and both of the ISO 19011:2026 changes are here — tells you where it thinks the attention belongs. Under the fourth edition, the decision about how an audit will be performed is made early and recorded. ISO/IEC TS 17012:2024 is the underlying document — a technical specification on the use of remote auditing methods, applicable to first-, second- and third-party audits, addressing the conditions, possibilities and limitations of remote methods. It is worth naming in your audit program’s reference list, because it is the source the 2026 guidance points to.

The expanded Annex A is where the practical substance of the ISO 19011:2026 changes sits: feasibility, platform considerations, contingency planning for technology failure, and how to balance remote and on-site activity across a program. Auditors now have a shared reference for doing remote work well rather than improvising it, which is the difference between a method that survives scrutiny and one that merely happened.

What Counts as a Remote Auditing Method Now?

A remote auditing method is any technique that lets an auditor gather evidence and reach conclusions without being physically present at the location being audited. That spans document review through a shared portal, video interviews, live camera observation and data pulled from a quality platform. The practical value of the ISO 19011:2026 changes is sequencing: review records remotely first, then reserve on-site time for the observations that genuinely require presence. The goal is not maximum remote work but each method where it produces the most reliable evidence.

Virtual Locations vs. Remote Methods — What Is the Difference?

The revision sharpens a distinction that confused many teams under the prior edition. A remote method is how you audit; a virtual location is what you audit. A virtual location is where an organization performs work or provides a service in an online environment, so people can execute processes regardless of where they physically sit — cloud infrastructure, a remote-work environment, a system with no single physical address. The fourth edition’s audit scope definition now expects a description of both physical and virtual locations. For organizations operating across borders and time zones this clarity is the most immediately useful of the ISO 19011:2026 changes, and it pairs naturally with MSI’s guide to multi-site ISO certification and its work on multi-site procedure standardization.

Remote auditing is no longer something you do. It is something you design for — from the first line of the audit program to the last word of the report.

Measure Before You Edit · Free · No Email

Score Your Internal Audit Program in About Six Minutes

Before revising anything against the ISO 19011:2026 changes, find out which part of your program is actually weakest. The free Internal Audit Maturity Check rates it element by element on how it behaves during a busy week — not on how the document reads. Four levels per element, five standard paths, your band and priority order shown immediately, with nothing to enter first. Most teams find the weakest element is not the one they expected, which changes what the first edit should be.

Take the Internal Audit Maturity Check →


Inside the Fourth Edition

What Does the ISO 19011:2026 Text Say That Most Summaries Miss?

Define. Balance. Safeguard.

Direct Answer: Beyond the two headline ISO 19011:2026 changes, the fourth edition carries details most summaries skip: a formal definition of a remote auditing method that applies regardless of distance, a Table A.1 that sorts every audit method by location and human interaction, method-selection risk tied directly to whether a method can achieve the defined audit objective, a practical remote-audit checklist in Annex A.16, and a competence clause that names AI-based evaluation tools. All of it is guidance, and all of it is usable in your procedure this quarter.

MSI read the licensed fourth edition line by line rather than working from summaries of the ISO 19011:2026 changes. Five details stand out because each one changes a sentence in a real audit procedure. None is a requirement — ISO 19011 has none — but each is text a retrained certification auditor will carry into your next audit.

1. “Remote” Now Has a Definition — and Distance Does Not Matter

The fourth edition adds a defined term, remote auditing method, taken from ISO/IEC TS 17012: a method used for conducting audit activities from any place other than the auditee’s location. Its notes carry three consequences. Remote methods can be combined with on-site methods to achieve a full audit. They can be used for virtual locations. And they can be used by an auditor at one site of the auditee to audit another site. The footnote to Table A.1 closes the loop: remote means anywhere other than the auditee’s location, regardless of the distance.

That last point surprises most teams. An auditor reviewing a live camera feed from the warehouse across the parking lot is using a remote method. Programs that log “remote” only when an audit crosses state lines understate exactly the choice the ISO 19011:2026 changes ask them to justify.

2. Table A.1 Sorts Every Method Into Four Quadrants

Annex A.1 organizes auditing methods on two axes: where the auditor is, and whether the method involves human interaction with the auditee’s people. It is the most practical planning tool among the ISO 19011:2026 changes. A paraphrased version:

On-siteRemote
With human interactionInterviews, observing work, checklists and document review with the auditee, samplingThe same activities via interactive communication, including observing work performed with a remote guide
Without human interactionReviewing records and data, observing work, a site visit, samplingReviewing records and data, analyzing data, observing work via surveillance means with regard for social, statutory and regulatory requirements

Two details are worth lifting into your procedure. A multi-member team can run on-site and remote methods simultaneously — one auditor on the floor, one reviewing records elsewhere. And observing work through surveillance equipment counts as a remote method only with regard for social and legal constraints, a privacy conversation to have with HR and legal before the first camera-based observation.

3. Method Choice Is Tied to the Audit Objective in the Text Itself

This is the detail that connects the ISO 19011:2026 changes to the new requirements. Clause 5.3 now lists the selection of the audit method among audit program risks, and frames that risk around whether the chosen method is capable of achieving the defined audit objective. Clause 5.5.3 says methods are selected depending on the defined audit objectives, scope and criteria, and that on-site and remote methods should be suitably balanced. Annex A.1 adds the feasibility factors: the level of risk to achieving the audit objectives, the level of confidence between auditor and auditee’s personnel, and regulatory requirements.

Read together, the chain is explicit: no defined objective, no defensible method choice — which is why the per-audit objectives now required by ISO 14001:2026 and ISO 9001:2026 matter so much. The planning clauses reinforce it from the resource side, naming network bandwidth, hardware and software, time zones and languages as program considerations.

4. Annex A.16 Is a Remote-Audit Checklist Hiding in Plain Sight

Annex A.16, Using remote auditing methods, reads like a pre-audit checklist. It makes effectiveness a joint responsibility of the auditee and the auditors. It asks both sides to confirm the agreed remote access protocols, devices and software; run technical checks ahead of the audit; and have contingency plans for interrupted access, including provision for extra audit time. Its further considerations include data security, using floor plans or diagrams of remote locations to orient the auditor, controlling background noise and interruptions, asking permission in advance before taking screenshots or recordings, and protecting privacy during breaks by muting microphones or pausing cameras.

Two companion passages round it out. The interview guidance in A.17 notes that non-verbal cues carry less weight in virtual settings, so the auditor should lean on well-chosen questions. And confidential audit material — explicitly including images and audiovisual recordings — should be safeguarded by the audit team at all times. Most internal audit procedures say nothing about any of this; a one-page remote-audit protocol drawn from these ISO 19011:2026 changes fixes that in an afternoon.

5. AI Is Named in the Auditor Knowledge Clause

Clause 7.2.3 lists the knowledge and skills auditors should have, and the 2026 text includes understanding the appropriateness and consequences of using information and communications technology tools and emerging technology to conduct audits, with artificial-intelligence-based evaluation tools given as the example. The same clause lists data protection and information security as knowledge auditors should bring, with a note that a management system audit cannot be treated as a legal compliance audit. Annex A.16 adds that auditor competence should include the technical skills to use the technology and the skills to conduct the audit remotely.

None of that is among the ISO 19011:2026 changes ISO announced, and all of it is “should.” But it gives a credible external anchor to what MSI has argued from practice: an auditor who does not understand how an AI-assisted analysis reached its output cannot evaluate it objectively. MSI works that problem in depth in AI process controls and in auditing AI agents.

Certification audits sit under a different rulebook. The fourth edition’s introduction says it concentrates on first- and second-party audits and points to ISO/IEC 17021-1 for third-party certification. For certification bodies using remote technology, the Global ACI legacy document IAF MD 4:2025 applies; the Standards Council of Canada summary of IAF MD 4:2025 notes that conformance is mandatory whenever ICT is used and that team members must be competent in the ICT used. The ISO 9001 Auditing Practices Group remote-audit guidance is a useful companion.


Competence · MSI Reading

What Do the ISO 19011:2026 Changes Imply for Auditor Competence?

Skill. Judgment. Currency.

Direct Answer: ISO did not list competence among the ISO 19011:2026 changes, and the competence clauses at 7.2.3 and 7.6 were not announced as revised. The fourth edition’s text does say auditor competence should include the technical skills to use remote-audit technology. MSI’s reading goes one step further: competence should cover the specific platform carrying the audit. That is a house standard drawn from 200+ audits attended, not a clause requirement, and your procedure should say so.

The logic runs straight from the ISO 19011:2026 changes. Once remote methods are planned rather than improvised, the tool carrying the audit becomes part of the evidence chain, and an auditor who cannot operate it confidently loses evidence in real time. Competence stated in general terms gives nobody anything to verify.

Why Platform-Specific Competence Beats Generic Digital Skills

The platform details matter because they decide where evidence goes and who controls it: where a session recording is saved and under whose retention rules, who can share a screen or admit a participant, and which file-exchange routes IT has left open. Those details differ between the common meeting tools, and an audit recording can itself become a controlled record. MSI’s internal audit procedure analysis walks through the platform differences edit by edit.

MSI’s house standard is therefore to name the organization’s platform in the competence criteria and to record platform training exactly like any other auditor qualification, refreshed as the tool and the audit methods evolve. The supporting framework sits inside MSI’s internal audit services; the discipline is taught in the ISO 9001 two-day internal auditing course, in the ISO 9001 and 13485 two-day internal auditor training for combined programs, and in the live ISO internal auditor workshop. MSI’s ISO internal auditor training and its guide to internal audit skills make the case that auditing is a craft to be developed, not a duty to be rotated.

Where Do AI and Data Analytics Fit?

Auditors increasingly rely on technology — cloud platforms, video conferencing, data analytics, automated systems, and in some settings drones for physical observation. The revision did not add an analytics clause. What the ISO 19011:2026 changes did was normalize remote and digitally mediated auditing, which makes the judgment question unavoidable. Data analytics can let an auditor examine an entire population of records rather than a hand-pulled sample, which strengthens evidence — but only if the auditor understands how the data was generated and whether it can be trusted.

The durable principle is proportionate, informed use: pick the technology that fits the audit objective, apply professional judgment to what it produces, and stay alert to the uncertainties automated and remote methods introduce. Embrace useful technology, never outsource judgment to it. That balance mirrors the procedure-first philosophy MSI brings to digitization in its work on ISO compliance automation. The same test applies to the documents being audited: what makes an effective ISO procedure is whether practice and document still match, which is exactly what a well-designed audit sets out to determine.


Risk · What Was Already There

Do the ISO 19011:2026 Changes Strengthen Risk-Based Auditing?

Focus. Where. Risk-Lives.

Direct Answer: No — and this is the most common misreport of the ISO 19011:2026 changes. The risk-based approach was already one of the seven principles, and the standard already carried a clause on audit program risks and opportunities. Nothing about that was listed as changed. What did change is that method selection is now a design decision, which introduces a risk category most programs never considered: choosing remote when the evidence demands presence.

The citable part predates the ISO 19011:2026 changes entirely. ISO 9001 has long asked the audit program to weigh how important each process is, what has changed, and what earlier audits found, and the 2026 edition keeps that expectation. ISO 19011 has carried a clause on audit program risks and opportunities, at 5.3, since before this edition. Neither text says what the weighting should actually alter, which is the gap most programs never close.

MSI’s answer, built over 28 years and 200+ audits attended, is that risk should move five dials at once — how often a process is audited, how deeply, how large the sample, whether the method is on-site or remote, and which auditor is assigned — rather than the calendar alone. The full five-lever model, with a higher-risk and lower-risk setting for each dial, is set out in MSI’s internal audit procedure guide as Edit 5. The same thinking runs through its analysis of internal audit risk mitigation strategies, its guide to ISO 14001 environmental aspects, and its work on government internal audit. The ISO 19011:2026 changes add one new dial to watch: a remote method chosen for a process whose risk demands someone standing on the floor.


Evidence · MSI Reading

What Do the ISO 19011:2026 Changes Mean for Evidence and Data Security?

Verify. Trace. Protect.

Direct Answer: The evidence-based approach is one of the seven principles and was not listed among the ISO 19011:2026 changes. What the revision does is make remote evidence ordinary, and remote evidence carries a reliability question that walk-through evidence does not. MSI’s house standard is that auditors treat unconfirmed remote evidence as provisional until it can be tied to a controlled record, get permission before capturing screenshots or recordings, and escalate to on-site verification when evidence cannot be confirmed.

ISO/IEC TS 17012, the source behind the ISO 19011:2026 changes, was written because remote methods have limits that on-site methods do not. A record shown on a shared screen, a file sent during the session, or a process demonstrated over video can each look conclusive and still fail to hold up later. The test is simple to state: can the auditor trace what was seen back to a controlled source, and would it survive being checked after the call ends?

Protecting the evidence is the other half. Access to live systems and recordings creates obligations for auditor and auditee alike, and the fourth edition’s advance-permission expectation for screenshots and recordings belongs in the procedure, along with where captured evidence is stored and when it is destroyed.

This is where the ISO 19011:2026 changes touch MSI’s broader thinking on change management and the audit trail, and it also touches a distinction the 2026 text states outright: conformity to a standard and compliance with the law are assessed differently, which is why MSI treats evaluation of compliance as its own discipline rather than a sub-task of the internal audit. The evidence discipline extends to behavioral requirements too, as MSI sets out in its guide to auditing quality culture, and it underpins why MSI treats ISO certification as a business asset rather than a paperwork exercise.


Guidance Meets Shall

Which 2026 Requirements Turn the ISO 19011:2026 Changes Into an Obligation?

Guidance. Meets. Shall.

Direct Answer: The ISO 19011:2026 changes carry no deadline of their own, but two 2026 requirements standards now do. ISO 14001:2026, published 15 April 2026, and ISO 9001:2026, published 16 September 2026, both revised Clause 9.2.2 a) so every internal audit must define its objectives as well as its criteria and scope. ISO 14001:2026 also requires the audit program itself to be available as documented information. Environmental certificate holders have until 30 April 2029 to transition; ISO 9001:2015 certificates cease to be valid after 30 September 2029.

This is the most practical reason to act on the ISO 19011:2026 changes now. Guidance is easy to defer because nothing enforces it, but in 2026 the two most widely certified management system standards changed their internal audit clauses in the same direction. Objectives used to be implicit — the audit happens because the schedule says so. That is no longer defensible in a quality or an environmental management system, and the ISO 19011:2026 changes are the reference for what a well-formed objective looks like.

What Changed in ISO 9001:2026 Clause 9.2.2?

The ISO 9001:2026 internal audit clause now asks the organization to plan, establish, implement and maintain the audit program, and item a) adds objectives to the criteria and scope already required for each audit. Documented information shall now be available as evidence of the implementation of the audit program and the audit results, where the 2015 edition said retain. And a note under the clause points directly to ISO 19011 for guidance on auditing management systems — the clearest signal yet that the ISO 19011:2026 changes are the reference certification auditors will carry into ISO 9001 audits. ISO announced the launch in its 16 September 2026 release; MSI’s ISO 9001:2026 executive briefing translates the wider revision for leadership.

What Changed in ISO 14001:2026 Clause 9.2.2?

ISO 14001:2026 made the same objectives change and went further on documentation. The 2015 wording looked backward: keep proof that the program ran and what it found. The 2026 wording looks at the present tense: three items must be available, and the audit program itself heads the list. That turns the program from a working file into a controlled document with an owner, a revision history and a review trigger — a real change for the many organizations whose program lives in one person’s spreadsheet.

StandardPer-audit objectivesAudit documentationTransition
ISO 9001:2026Required, Clause 9.2.2 a)Evidence of implementation and results must be availableISO 9001:2015 certificates valid until 30 Sept 2029
ISO 14001:2026Required, Clause 9.2.2 a)The audit program itself, plus evidence of implementation and results, must be available30 April 2029
ISO 7101:2023Required since 2023, Clause 9.2.2 a)Per the standard’s own Clause 9.2.2Current edition
ISO 45001:2018 and ISO 13485:2016Not required in either clausePer each standard’s own clauseCurrent editions

Per-audit objectives are not new to the ISO catalog, whatever some commentary says. ISO 7101:2023 has asked for them in Clause 9.2.2 a) since its first edition, so healthcare quality systems have been writing audit objectives for three years. The 2026 news is that the requirement reached the two most widely held standards. MSI’s ISO 7101 healthcare quality overview covers the clause.

The effect compounds across standards. If a single audit program covers quality and environment together, the stricter requirement governs the shared procedure — which means the documented-program discipline from ISO 14001 reaches the quality side too, and if ISO 45001 or ISO 13485 share the program, the objectives field reaches them as well. MSI works through that sequencing in its guide to the ISO 9001 and 14001 transition, the certificate mechanics in its ISO 14001 certification guide, the role that owns it in its environmental manager job description, and the downstream effect on the improvement loop in ISO 14001 continual improvement. The short version: write the objective once, in one integrated procedure, and every system inherits the sharper audit.

How Do You Write an Audit Objective Clause 9.2.2 Will Accept?

A defensible objective passes three tests. It names what the audit is trying to determine, not what it will look at. It is tied to something real — a significant aspect, a prior finding, a process change, a performance question leadership has asked. And it is answerable with evidence obtainable inside the stated scope. “Audit the waste management process” fails all three: it is a scope statement wearing an objective’s label. “Determine whether the corrective actions from the previous waste-segregation finding were implemented and are still holding at the point of generation” passes all three, and it tells the auditor where to stand and what to ask for.

Write the objective as a question the audit will answer. Then check whether your chosen method can answer it. An objective about whether segregation holds at the point of generation cannot be satisfied by a document review over video — and stating the objective first makes that obvious before anyone books a remote session. That is exactly the method-selection risk ISO 19011:2026 Clause 5.3 describes.

That interlock is the real value: ISO 9001:2026 and ISO 14001:2026 make the objective mandatory, the ISO 19011:2026 changes make the method a recorded decision, and the objective makes the method choice defensible. Across 200+ audits attended, MSI’s observation is consistent: audits with a written objective produce findings leadership acts on, and audits without one produce reports that get filed. The full set of edits this implies for your existing document is laid out in MSI’s ISO 19011:2026 internal audit procedure analysis — seven edits, none of them a rewrite.

For EHS Managers on the 2029 Clock

Move Your EMS From 2015 to 2026 in a Week, Not a Quarter

The ISO 14001:2026 Procedure Templates & Guides package was built for experienced EHS managers who already run a working system and need it current — every 2026-edition EMS procedure written to the new text, including the internal audit procedure with the Clause 9.2.2 objectives field built in and the audit program defined as a controlled document, the Clause 6.3 planning-of-changes clause, and the restructured management review, plus the transition course. You know your system; these documents let you spend a week adapting instead of a quarter drafting.

See the ISO 14001:2026 transition package →

Need the audit team trained to the revised clauses as well? ISO 14001:2026 Internal Auditing is the two-day course built around auditing the 2026 edition rather than the old checklist, and the ISO 14001:2026 Transition Course walks the clause changes end to end, with the first module free.


Where Audit Results Land

Where Do the ISO 19011:2026 Changes Land in Your Management Review?

Feed. Decide. Record.

Direct Answer: The ISO 19011:2026 changes do not stop at the audit report. Audit results are a mandatory management review input in every standard MSI implements, so a better-designed audit program only pays off if the review record is built to receive what it produces. ISO 14001:2026 restructured Clause 9.3 into three subclauses, renamed outputs as results, and now asks for environmental performance information framed as trends — including trends in audit results. ISO 9001:2026 adds alignment with strategic direction to the purpose of the review.

Most conversations about the ISO 19011:2026 changes end at the audit report, but a finding has no authority until leadership decides something about it. Every management system standard MSI works in treats audit results as a required input to top management’s review — ISO 9001 at Clause 9.3, ISO 14001:2026 at Clause 9.3.2, ISO 45001 at Clause 9.3, and ISO 13485 at Clause 5.6.2, where the review sits inside Management Responsibility rather than Performance Evaluation. The ISO 19011:2026 changes improve what arrives at that table. They do not improve what the table does with it.

What Changed in the 2026 Management Review Clauses?

Clause 9.3 in ISO 14001:2026 is split three ways: 9.3.1 sets the general obligation for top management to review the system at planned intervals for continuing suitability, adequacy and effectiveness; 9.3.2 lists the inputs; and 9.3.3 lists the results. The word “outputs” is gone. The results must now include, among other items, opportunities to improve integration with other business processes and any implications for the strategic direction of the organization. ISO 9001:2026 moves the same way from the other end: Clause 9.3.1 now asks top management to review the system for its alignment with the strategic direction of the organization, not only its suitability, adequacy and effectiveness. The review is no longer a status meeting; it is a governance input.

The ISO 14001:2026 inputs moved too. Clause 9.3.2 now asks for information on environmental performance framed explicitly as trends — in nonconformities and corrective actions, in monitoring and measurement results, in meeting compliance obligations, and in audit results. A single-cycle number no longer satisfies the clause on its face. This is the quiet connection to the ISO 19011:2026 changes: audit results reported as a trend require an audit program designed to produce comparable results year over year, which is exactly what defined objectives and documented method choices make possible. MSI works the whole clause through in its guide to the ISO 14001:2026 management review.

Why Do Habit-Built Review Agendas Fail Under the 2026 Editions?

Ask which clause a given section of your management review satisfies, and there is often no answer — because the agenda was assembled from what last year’s review covered, in the order it covered it. That works until someone asks the agenda to prove it covers every required input. The requirements an organization has never performed are precisely the ones a habit-built agenda cannot surface: if nobody ever established audit objectives, no section of the agenda asks for them, and the omission stays invisible from inside the document, however well the ISO 19011:2026 changes are applied upstream.

Organizations running integrated systems feel this hardest, because an agenda built from the standard the quality manager knows best drops the inputs the other standards carry alone. ISO 45001 is the only one in the family that requires the results of the review to leave the room and be communicated to workers and their representatives. ISO 13485 requires both a documented procedure and a record where the harmonized-structure standards require only the record. MSI sets out the discipline in its guide to crafting an ISO management review procedure and the evidentiary standard in why the management review record must prove it.

Close the Loop the Audit Opens

Management Review Toolkits, Built From the Clause Instead of Last Year’s Agenda

MSI’s ISO Management Review Toolkits are eleven matched pairs — a PowerPoint deck to present from and a Word minutes form to record into — generated from the same numbered section list, with the clause reference printed under every section title. Section 12 on the slide is Section 12 on the form, so the presenter and the recorder are never on different items. Where a section is MSI practice rather than a requirement, it says so, so an auditor can tell the difference and so can you. The combined editions matter most here, because one integrated audit program is where the 2026 objectives requirement reaches every standard in the room.

The ISO 9001 and 14001:2026 toolkit runs 29 sections; the ISO 45001 and 14001:2026 HSE toolkit runs 30 with fourteen divergences resolved; and the ISO 14001:2026 toolkit carries a ten-row comparison against 2015 showing what moved and what each change means for your record.

Compare the eleven management review toolkits →


The Wider 2026 Wave

How Do the ISO 19011:2026 Changes Fit the Wider 2026 Standards Wave?

Aligned. Current. Connected.

The ISO 19011:2026 changes did not arrive in isolation. They arrived in the middle of the broadest refresh of the management-system catalog in a decade. ISO 14001:2026 published in April. ISO 9000:2026, the vocabulary standard, published in May, and ISO 19011:2026 now takes its definitions of audit, combined audit and joint audit from it. ISO 9001:2026 published on 16 September 2026 as the sixth edition, replacing ISO 9001:2015 and its 2024 climate amendment. It retains the Harmonized Structure, so the auditing vocabulary and the clause architecture stay in step. That alignment matters because organizations running integrated management systems audit against several standards at once; if the auditing guidance drifted from the standards being audited, every integrated audit would inherit the mismatch.

The 2024 climate action amendment sits underneath all of this, adding climate change wording to Clauses 4.1 and 4.2 of more than thirty management system standards; ISO 9001:2026 folds that wording into the new edition, and ISO 14001:2026 carries it further by naming environmental conditions such as climate change and biodiversity under Clause 4.1. Climate-related context is a legitimate line of audit inquiry where it bears on the system being audited. One distinction is worth writing down: ISO 13485 is not among the amended standards — it is not built on the harmonized structure and was not amended.

One piece of accreditation context changed underneath all of this as well. The International Accreditation Forum and the International Laboratory Accreditation Cooperation both ceased operations on 1 January 2026 and were unified into Global Accreditation Cooperation Incorporated (Global ACI), a single international accreditation organization with one mutual recognition arrangement. Certificates and accreditations issued under the former arrangements remain recognized, and specified legacy documents — IAF MD 4 on remote technology among them — stay valid until equivalent Global ACI documents are adopted. Global ACI has set a three-year ISO 9001:2026 transition, with 2015-edition certificates ceasing to be valid after 30 September 2029. If your audit program or procedure still cites IAF documents without noting the change, that reference now needs a look.

Leaders tracking how the revisions interconnect will find the through-line in MSI’s coverage of the ISO 9001:2026 ethics and culture update, its companion piece on ISO 9001:2026 for boardrooms, and its guide to keeping the watch list current through regulatory change management.

What Do the ISO 19011:2026 Changes Mean for Auditing Quality Culture?

Here the timing of the two revisions gets genuinely interesting. ISO 9001:2026 Clause 5.1.1 i) now requires top management to promote quality culture and ethical behavior — a leadership requirement with no predecessor in the 2008 or 2015 editions — and Clause 7.3 e) requires people to be aware of both. Culture is exactly the kind of subject that invites impressionistic auditing: a walk around the floor, a sense that people seem engaged, a conclusion nobody can trace back to anything. The evidence-based principle carried forward intact through the ISO 19011:2026 changes makes that approach no easier to defend than it was before, and the arrival of a behavioral clause raises the stakes on getting it right.

The practical answer is that culture has observable outputs — who raised concerns and what happened to them, how long issues stayed open, whether people stopped work when they should have, what leadership actually did with what it heard. Those are records, and records can be sampled, traced and tested exactly as the principle requires. MSI’s catalog of unethical business practices gives auditors a concrete list of what the absence of ethical behavior looks like in practice, its guide to engagement of people shows which existing records evidence it, and its piece on the ISO 9001 quality policy shows where culture and ethics can be written into the policy itself. For leadership teams, the ISO 9001:2026 Leadership Commitment Workshop launches October 21, 2026. A durable quality management mindset is what makes the difference hold.

Free Download · Check Your Program Before You Edit It

ISO 9001 / ISO 19011:2026 Internal Audit Program Checksheet

Check your audit program against the 2026 changes in one pass: per-audit objectives, method selection, remote-audit controls, and the program under document control. Enter your details and the checksheet opens instantly. We will email you a copy too.

ISO 19011:2026 Internal Audit Program Checksheet Download

The Action List

What Should Smart Audit Teams Do About the ISO 19011:2026 Changes Now?

Read. Refresh. Re-train.

Direct Answer: Acting on the ISO 19011:2026 changes does not require rebuilding your audit program. Six focused updates cover it: add a defined-objectives field to every audit plan; bring the audit program itself under document control; record how method choices are made against each objective; adopt a one-page remote-audit protocol covering technical checks, contingency time and permission for screenshots and recordings; update auditor competence criteria to name the platform you actually use; and rebuild the management review agenda so it receives audit results as a trend. Then train to the revised document.

Sequence matters more than speed when acting on the ISO 19011:2026 changes. With ISO 9001:2026 now published, the objectives field comes first: it is a same-week change and it now carries the obligation of two requirements standards. Document control of the audit program comes next, because it is the long-lead item — it touches your document management system and it is the ISO 14001:2026 requirement most transition plans miss. Method-selection recording follows, since it is the direct consequence of both ISO 19011:2026 changes and it depends on the objective existing. The remote-audit protocol, competence criteria and reporting updates can move alongside your next training cycle. The management review agenda is best timed to your next review, when you are rebuilding it anyway.

Then train to the ISO 19011:2026 changes. Your internal auditors and any supplier auditors you rely on should understand what changed, what did not, and where MSI’s house standards go beyond the text — that last distinction is what keeps a well-read auditor on your side. MSI’s internal audit follow-up framework and its continuous-improvement follow-up guidance are built to close exactly this loop, and every finding hands off to a corrective action procedure that has to hold.

For a guided route, look to MSI’s approach to certification audits, the SurePath turnkey certification program, the year-round rhythm of SureResults, or The Portrait for an independent read on where the system actually stands. How internal, surveillance and certification audits fit together is covered in MSI’s ISO audit guide, and the program-level view sits in building an internal audit program. For the system-level document the procedures hang from, see the ISO manual templates and guides.

Ready to Update Your Audit Program Without Overcorrecting?

The hardest part of a revision like this is knowing what to leave alone. If your audit program, objectives, competence criteria, management review agenda or auditor training need to catch up with the ISO 19011:2026 changes — and with the ISO 9001:2026 and ISO 14001:2026 requirements behind them — MSI will map the few adjustments that matter for your standards and your operation, and name the ones the commentary invented. Begin with a planning session: a working conversation with a consultant who has attended 200+ audits, not a sales script.

Call 760-434-9141 to plan a session.

Book your planning session →

Prefer to start with documents? Compare your procedures against MSI’s finished templates first — the purchase price is credited in full toward consulting.


Frequently Asked Questions

Common Questions About the ISO 19011:2026 Changes

Ask. Answer. Apply.

Is it ISO 19001 or ISO 19011?

There is no ISO 19001. The auditing guidance standard is ISO 19011, and its current edition is the fourth, published 27 May 2026. The number is easy to mistype because ISO 9001 — the quality management requirements standard — is the one most people reach for first, and ISO 9001:2026 published on 16 September 2026. If you are looking for how to plan and conduct audits, you want ISO 19011:2026. If you are looking for what a quality management system must contain, you want ISO 9001.

Can I download ISO 19011:2026 as a free PDF?

No. ISO 19011:2026 is a copyrighted standard, and the official PDF is sold by ISO and by national standards bodies such as ANSI in the United States. Copies offered as a free download on file-sharing sites are not authorized. What you can download free is MSI’s Internal Audit Program Checksheet (PDF). It turns the ISO 19011:2026 changes and ISO 9001:2026 clause 9.2 into yes/no checks for your audit program: per-audit objectives, method selection, remote-audit controls and the program under document control. Get the free checksheet.

What exactly are the ISO 19011:2026 changes?

ISO states two main changes: an expansion of guidance on remote auditing methods through the introduction of guidance contained in ISO/IEC TS 17012, and an expansion of Annex A to cover remote auditing methods and virtual locations. The edition also states that it adopts the combined audit approach. Claims that the revision expanded supply-chain guidance, strengthened the risk-based approach, or added digital competence requirements do not appear in ISO’s statement of changes.

When was ISO 19011:2026 published, and is there a transition period?

It was published on 27 May 2026 as the fourth edition, withdrawing ISO 19011:2018 the same day. Because ISO 19011 is a guidance standard rather than a requirements standard, there is no transition period and no window in which both editions remain current. No organization certifies to ISO 19011, so no certificate or deadline is at stake. Audit program documents still citing the 2018 edition are citing a withdrawn standard.

Do the ISO 19011:2026 changes require me to redesign my audit program?

No. The structure and the seven principles carry over from the 2018 edition, so programs built on the prior guidance do not need a rebuild. The practical work is a focused refresh: add defined objectives to every audit plan, bring the audit program under document control, record how audit methods are chosen, adopt a short remote-audit protocol, update competence criteria to name your platform, and check that the management review agenda still receives what the program now produces.

Do I now need an objective for every internal audit?

Yes, if you hold ISO 9001 or ISO 14001. ISO 19011:2026 is guidance and only recommends, but ISO 14001:2026 (published 15 April 2026) and ISO 9001:2026 (published 16 September 2026) both revised Clause 9.2.2 a) so each internal audit must define its objectives in addition to criteria and scope. ISO 7101:2023 has required audit objectives since 2023. ISO 45001:2018 and ISO 13485:2016 do not, though an integrated audit program will usually adopt the stricter rule for every system it covers.

Does ISO 19011:2026 make remote auditing mandatory?

No. The revision does not mandate remote auditing; it formalizes how to plan and conduct remote and hybrid audits well when you choose to use them. The decision between on-site, remote and hybrid should be driven by risk, audit objectives, scope and the quality of evidence each method can deliver. On-site auditing remains entirely appropriate, and sometimes essential, where physical observation is the only reliable way to gather evidence.

Can auditors take screenshots or record a remote audit under ISO 19011:2026?

They can, with care. Annex A.16 advises asking for permission in advance before taking screenshots of documented information or making any kind of recording, and considering confidentiality and security when doing so. The audit-preparation guidance adds that images and audiovisual recordings containing confidential information should be safeguarded by the audit team at all times. MSI recommends writing both points into the internal audit procedure, including where captured evidence is stored and when it is destroyed.

Does ISO 19011:2026 apply to certification body audits?

Only as supplementary guidance. The fourth edition concentrates on first-party internal audits and second-party audits of external providers. Third-party certification audits are governed by ISO/IEC 17021-1, and certification bodies using remote technology must also conform to IAF MD 4:2025, a legacy document that remains valid under Global ACI. ISO 19011 can still provide useful additional guidance to certification auditors.

How do the ISO 19011:2026 changes affect the management review?

Audit results are a mandatory management review input in every standard MSI implements, so improving the audit program changes what arrives at the review table. ISO 14001:2026 restructured Clause 9.3 into three subclauses, renamed outputs as results, and now asks for environmental performance information framed as trends, including trends in audit results. Reporting a trend requires audits that measure comparable things across cycles — which is what defined objectives and documented method choices deliver.

How do the ISO 19011:2026 changes relate to ISO 9001:2026?

ISO 9001:2026 published on 16 September 2026 and retains the Harmonized Structure, so terminology stays aligned with the auditing guidance. Its Clause 9.2.2 now requires defined objectives for each internal audit and carries a note pointing to ISO 19011 for guidance. The other audit-relevant addition is quality culture and ethical behavior at Clause 5.1.1 i) and Clause 7.3 e). Auditing something behavioral still requires verifiable records, so the practical work is identifying which existing records evidence culture.

How can MSI help my organization adapt to the ISO 19011:2026 changes?

MSI translates the revision into the specific adjustments your audit program, objectives, competence criteria, management review record and training actually need — and, just as usefully, identifies the ones the commentary invented. With 28 years of experience, 80+ certifications supported, 200+ audits attended and 600+ professionals trained, MSI can refresh your program, update your auditor qualification path and align your approach with the standards you operate under. Start with the ISO procedure templates, take the free Internal Audit Maturity Check, or call 760-434-9141 to plan a session.


Related Reading

Keep Going: The Audit Cluster

Read. Connect. Apply.

References & Authoritative Sources

About Management Systems International (MSI)

Diana Lynn is President and Principal ISO Consultant at Management Systems International, LLC, a veteran-owned, female-owned ISO consulting firm she founded in 1998. Across 28 years of experience, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

msi-international.com · 760-434-9141

Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 15 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply