ISO 19011:2026 Internal Audit Procedure: 7 Essential Edits

Scope of this guide: This covers the first-party internal audit of an ISO management system — ISO 9001, ISO 13485, ISO 14001, ISO 45001 and ISO 7101 — planned and conducted under ISO 19011:2026. It does not cover internal audit in the financial-controls or IIA sense. Where this article states what a standard requires, it cites the published clause. Where it goes further than the standard requires, it says so and calls it MSI's house standard.

Auditing Management Systems · 2026 Procedure Revisions

Revising your internal audit procedure is the single most practical move an organization can make in response to the 2026 wave of ISO updates, and most teams need a handful of targeted edits rather than a rewrite. Two standards are driving the work at once: ISO 19011:2026, the newly published guidance on how management system audits are designed and delivered, and ISO 14001:2026, which introduces a normative requirement that every internal audit have defined objectives. This article walks through the seven essential edits your procedure needs, what authority sits behind each one, and how to roll them out without disrupting a program that already works.

Direct Answer: Your internal audit procedure needs seven essential edits for the 2026 ISO cycle: (1) make audit objectives a required field for every audit, now a normative ISO 14001:2026 Clause 9.2.2 requirement; (2) add a method-selection step that records the on-site, remote, or hybrid choice and its rationale; (3) require platform-specific auditor competence for remote audits; (4) build in an evidence-reliability and data-security check; (5) make risk change five things about an audit, not just its frequency; (6) update competence records, continuing development, and audit reporting; and (7) bring the audit program itself under document control, because ISO 14001:2026 now requires it to be available as documented information. None of the seven demands a rewrite — they are precise insertions into the procedure you already run.


The Two Drivers

Why Your Internal Audit Procedure Needs Revising in 2026

Two Drivers. One Document.

For most organizations the internal audit procedure is a single controlled document serving every management system the company runs — quality, environmental, safety, healthcare, and medical device alike. That makes it the natural place to absorb the 2026 changes once, cleanly, rather than scattering edits across separate systems. Two distinct forces are pushing on that document this year, and they carry very different weight.

The first driver is guidance. ISO 19011:2026 was published on 27 May 2026 as the fourth edition, withdrawing ISO 19011:2018 on the same day. ISO's own statement of the main changes in the new edition lists exactly two: an expansion of guidance on remote auditing methods through the introduction of guidance contained in ISO/IEC TS 17012, and an expansion of Annex A to cover remote auditing methods and virtual locations. That is a narrower change list than most commentary suggests, and it is worth being precise about, because the readers of an internal audit procedure are auditors — the one audience that will have read the source.

Because ISO 19011 is guidance rather than a requirements standard, it applies immediately. There is no transition period and no window in which both editions remain current. No organization is certified to ISO 19011, and no clause of it can be raised as a nonconformity. The full picture of what shifted is covered in MSI's companion analysis of the ISO 19011:2026 changes; this article translates the guidance into the specific procedure edits it implies.

Nobody will write you a finding against ISO 19011. That is not the mechanism, and any consultant who tells you otherwise is selling urgency rather than accuracy.

The real mechanism is quieter and harder to argue with. ISO 19011 underpins auditor training and certification schemes, so certificated auditors are retrained against the current edition. The auditor sitting across from you has updated expectations even though the requirement has not changed. Where your practice falls short of current auditing good practice, the finding gets written against Clause 9.2 of the standard you are certified to.

The second driver is a hard requirement. ISO 14001:2026, published 15 April 2026, revised the internal audit clause so that defining scope and criteria for each audit is no longer enough — each internal audit must now also state defined objectives, and the audit program itself must be available as documented information. This is a normative “shall,” and certified organizations are working against a transition deadline of 30 April 2029. Revising the internal audit procedure is therefore not optional housekeeping for an environmental certificate holder. MSI's ISO 9001 and 14001 transition guide sets the wider sequencing out, and the ISO 14001 standard overview covers the certificate mechanics.

One correction worth making, because it is repeated widely and it is wrong: per-audit objectives are not a new idea in the ISO standards. ISO 7101:2023 Clause 9.2.2 a) has required audit objectives since 2023, and healthcare organizations have been operating under that requirement for three years. What changed in 2026 is that the obligation arrived in ISO 14001. If you run an integrated system that already includes a healthcare arm, the field you need may already exist in one corner of your business. MSI's ISO 7101 healthcare quality overview covers where that clause sits.

A note on ISO 9001 before the edits. The ISO 9001 FDIS ballot closed on 9 July 2026 with publication expected in September 2026. Technical content is frozen at FDIS, so the direction is settled — but until it publishes, the audit-objectives “shall” belongs to ISO 14001:2026 and to ISO 7101:2023, and nowhere else. Attributing it to ISO 9001 today is the kind of claim a well-read auditor will catch. MSI's read on how the 2026 revisions interlock is set out in its overview of the 2026 revisions and certification strategy.

Measure Before You Edit · Free · No Email

Score Your Internal Audit Program in About Six Minutes

If you would rather measure your program before rewriting anything, the free Internal Audit Maturity Check rates it element by element on how it behaves during a busy week — not on how the procedure reads. Four levels per element, five standard paths, your band and priority order shown immediately, with nothing to enter first. Most teams find the weakest element is not the one they expected, which changes what the first edit to the internal audit procedure should be.

Take the Internal Audit Maturity Check →


Edit 1 · ISO 14001:2026 Clause 9.2.2

Edit 1 — Make Audit Objectives a Required Field in Your Internal Audit Procedure

Define. Document. Deliver.

Direct Answer: The first edit to your internal audit procedure is the most concrete: add a mandatory audit-objectives field to every audit plan. ISO 14001:2026 Clause 9.2.2 now requires each internal audit to define its objectives alongside the scope and criteria that were already required. The objective answers why this audit is happening — what question it is meant to answer — not just what it covers.

Under the prior edition, an internal audit plan defined two things for each audit: the scope, meaning which processes, sites and activities are included, and the criteria, meaning the requirements being audited against. The 2026 revision adds a third. An objective is the purpose of the specific audit — “confirm that corrective actions from the previous environmental audit were effectively implemented,” or “verify that the new change-management process is operating as designed.” Scope tells the auditor where to look; criteria tell the auditor what to measure against; the objective tells the auditor what the audit is trying to learn.

In practice this edit is small but exacting. Your internal audit procedure should require that every audit plan, schedule entry and audit report carries an explicit objective, and that the objective drives the audit design rather than being backfilled afterward. The discipline pays off: audits with a clear objective are sharper, shorter and more useful, because the auditor knows exactly what conclusion the audit is meant to support. This is the same outcome-focused thinking MSI applies in its guide to internal audit planning and in the planning phase of internal audits, where a well-framed objective is what separates a meaningful audit from a checklist traversal.

Write the objective as a question the audit will answer. “Audit the calibration process” is a scope statement wearing an objective's job title. “Determine whether equipment found out of tolerance triggers a retrospective validity assessment of prior results” is an objective — and it tells the auditor what evidence would settle it.

For organizations running an integrated system, building the objectives field into the shared internal audit procedure once means every standard inherits the requirement at the same time. That is the structural efficiency MSI describes in its guide to integrated management system implementation and across the wider integrated management systems family. The equivalent equipment-side discipline is set out in MSI's guide to control of monitoring and measuring equipment, where the same “what would settle this” logic applies.

Edit 2 · Method Selection

Edit 2 — Add a Method-Selection Step to Your Internal Audit Procedure

Choose. Justify. Record.

Direct Answer: The second edit to your internal audit procedure is a method-selection step. ISO 19011:2026 carries a published clause at 5.5.3 on selecting and determining auditing methods, and its two headline changes both concern remote auditing — the introduction of guidance from ISO/IEC TS 17012 and an expanded Annex A on remote methods and virtual locations. Your procedure should require auditors to choose the method deliberately, record which one, and record why.

Before this edition, remote auditing tended to sit awkwardly outside the procedure — something teams did when travel was inconvenient, without a documented basis. Where the 2026 edition puts its two changes tells you where the attention has moved. Your internal audit procedure should add a step recording, for each audit, whether it will be conducted on-site, remotely, or as a hybrid, and the rationale for that choice. A review of records may be done remotely; observing a high-risk operational process may require physical presence. The method is chosen to fit the evidence the objective demands.

ISO/IEC TS 17012:2024 is the underlying document, published as a technical specification on the use of remote auditing methods in auditing management systems, applicable to first-, second- and third-party audits, and addressing the conditions, possibilities and limitations of remote methods. It is worth naming in your procedure's reference list, because it is the source the 2026 guidance points to.

This edit connects directly to Edit 1. Once each audit has a defined objective, the method that best serves that objective becomes easier to choose and justify. For multi-site and dispersed organizations this is where the internal audit procedure earns its keep, because method selection across locations is exactly the coordination challenge remote guidance addresses — a theme MSI explores in its guide to multi-site ISO certification. A procedure that documents method choice gives your certification body a defensible record of why each audit was run the way it was.


Edit 3 · MSI House Standard

Edit 3 — Require Platform-Specific Auditor Competence

Train. On. The-Tool.

Direct Answer: The third edit to your internal audit procedure is the one most teams overlook, and it is MSI's house standard rather than a clause requirement: require auditors to be competent in the specific platform your organization uses for remote audits — not in “remote tools” generally. Recording destinations, host controls and admission settings differ between platforms, and each of those differences affects whether evidence is captured.

A procedure that says “auditors shall be competent in remote auditing tools” is too vague to be auditable. Competence has to be platform-specific, because a remote audit is only as reliable as the auditor's command of the platform carrying it. MSI's house standard, drawn from 200+ audits attended, is that the internal audit procedure names the platform the organization actually uses and requires auditors to be trained on its mechanics: host and presenter controls, screen-sharing and remote-control permissions, recording behavior and where recordings are stored, admission controls, and secure file exchange. When an auditor fumbles a control mid-session, evidence is lost and the audit's credibility erodes.

Teams vs. Zoom — Why the Mechanics Differ for Auditors

The differences are not cosmetic; they change how evidence is gathered and retained. Recording destination is the clearest example. Microsoft Teams typically routes recordings into SharePoint or OneDrive under the organization's retention rules, while Zoom may store them in its cloud or locally depending on configuration — and an audit recording can itself become a controlled record subject to your retention policy. Host and presenter roles differ too, governing who can share a screen, grant remote control, or admit a participant. Lobby and waiting-room settings determine who is admitted and when, which matters when sensitive evidence is on screen. File-exchange paths that IT permits on one platform may be disabled on another, changing how an auditee submits documents mid-session.

Because these mechanics affect evidence capture, retention and confidentiality, MSI's house standard treats platform competence as a prerequisite for conducting remote audits — verified and recorded the same way you record any other auditor qualification. The supporting competence framework sits inside MSI's internal audit services, and the practical skills are taught in the ISO 9001 two-day internal auditing course.

Edit 4 · MSI House Standard

Edit 4 — Build In an Evidence-Reliability and Data-Security Check

Verify. Trace. Protect.

Direct Answer: The fourth edit to your internal audit procedure adds an explicit evidence-reliability and data-security check for remote and digital evidence. ISO/IEC TS 17012 exists precisely because remote methods carry conditions and limitations that on-site methods do not. MSI's house standard requires auditors to confirm that remote evidence is verifiable and traceable to a controlled source before relying on it, and to escalate to on-site verification when it is not.

When evidence arrives through a screen rather than a walk-through, a new question attaches to it: can this be relied upon? A document emailed mid-audit, a screen-shared dashboard, or a remotely demonstrated process each carries a reliability question. Your internal audit procedure should instruct auditors to evaluate whether information collected remotely is verifiable, sufficiently specific and traceable to a source. This protects the audit conclusion from resting on evidence that looked convincing on a video call but could not be confirmed afterward.

The data-security half of the edit matters just as much. When an organization grants an auditor access to live systems, records and recordings, both parties inherit a responsibility to protect that data. The procedure should set expectations for how audit evidence and recordings are handled, stored and retained. This intersects with the governance conversation MSI raises in its work on change management and the audit trail, and with its procedure-first view of ISO compliance automation, where reliable, traceable evidence is designed in rather than reconstructed later.


Edit 5 · The Conformity Anchor

Edit 5 — Make Risk Change Five Things, Not Just Frequency

Focus. Where. Risk-Lives.

Direct Answer: The fifth edit to your internal audit procedure is the one with a real clause behind it. Every standard in the family requires the audit program to take into consideration the importance of the processes concerned — that is what makes risk-based prioritization mandatory rather than a preference. Most programs answer it by adjusting frequency alone, which is the least useful of the five things risk should change.

Start with what is citable. ISO 9001:2015 Clause 9.2.2 a) requires the audit program to take into consideration the importance of the processes concerned, changes affecting the organization, and the results of previous audits. ISO 19011:2026 carries a published clause at 5.3 titled “audit programme risks and opportunities” — ISO’s spelling, kept here because it is the clause title. Those are structural facts about where the topic lives. What neither document does is tell you what to do about the importance you have considered — and that is where most audit programs quietly stop.

MSI's house standard, developed across 28 years and 200+ audits attended, is that risk should change five properties of an audit. Frequency is only the first, and on its own it changes almost nothing about what the audit finds.

What Varies Higher Risk Lower Risk
Frequency Every cycle, re-audited early where findings recur Longer interval, with the basis recorded
Depth Walked end to end, including the handoffs Key controls sampled
Sample size Large enough to conclude about the system Sufficient to confirm the control operates
Method On-site, including the shift where supervision is thinnest Records reviewed remotely
Auditor Most experienced available Any qualified auditor on the register

A low-risk process and a high-risk process both audited annually, with the same checklist and the same two-hour slot, have not been differentiated in any way that changes what the audit finds.

The practical edit is to write those five levers into the planning section of your internal audit procedure, with the risk basis recorded per process rather than asserted for the program as a whole. Mature teams already concentrate effort where exposure is greatest rather than auditing everything on a flat cycle — a discipline MSI details in its analysis of internal audit risk mitigation strategies and applies at the aspect level in its guide to ISO 14001 environmental aspects. MSI client experience suggests teams that vary all five levers get more from fewer audit days than teams that vary only the calendar.

Edit 6 · Competence and Reporting

Edit 6 — Update Competence Records, CPD, and Reporting in Your Internal Audit Procedure

Record. Renew. Report.

Direct Answer: The sixth edit to your internal audit procedure updates how competence, continuing development and reporting are documented. ISO 19011:2026 carries published clauses at 7.2.3 on knowledge and skills and 7.6 on maintaining and improving auditor competence. MSI's house standard is that qualification records name the remote-audit platform, and that every audit report records the objective, the method used, and whether the objective was met.

Many auditor competence frameworks were built around discipline knowledge alone — what the auditor knows about the standard and the processes being audited. MSI's house standard broadens that to include the platform competencies covered in Edit 3 and the evidence judgment covered in Edit 4, and requires that auditor qualification records reflect them explicitly rather than by implication. Continuing professional development should include audit methods and digital techniques, so competence stays current rather than freezing at the point of initial qualification. Auditing a culture-and-behavior requirement takes the same evidence discipline, as MSI sets out in its guide to auditing quality culture.

Reporting closes the loop. Because objectives and methods are now first-class elements of audit design, your report template should record them: what the audit set out to learn, how it was conducted, and whether the objective was met. That makes the audit program self-documenting and gives management review a cleaner read on how the system is performing — the record-keeping discipline MSI builds into its management review procedure guide. Strong reporting also feeds the follow-up that turns findings into improvement, covered in MSI's guide to internal audit follow-up. ISO 19011:2026 carries a published clause at 6.7 on audit follow-up, which is where that thread belongs in your procedure's structure.


Edit 7 · The Harder 2026 Change

Edit 7 — Bring the Audit Program Itself Under Document Control

Available. Not. Retained.

Direct Answer: The seventh edit to your internal audit procedure is the harder of the two ISO 14001:2026 changes and the one most transition plans miss. ISO 14001:2015 required the organization to retain documented information as evidence of the implementation of the audit program and the audit results — two items, both retrospective. ISO 14001:2026 requires three things to be available, and the first of them is the audit program itself.

In most organizations the audit program is a spreadsheet on the program manager's desktop: uncontrolled, unversioned, and not in the document system at all. Making it available as documented information means bringing it under document control. That takes planning, where adding an objectives field takes ten minutes — which is exactly why this edit belongs on the plan early and the objectives edit does not.

The two words also carry different tests. Retained means kept — you can produce it when asked. Available means current, retrievable and under control: the version an auditor sees is the version the program is actually running to, with a revision history, an owner and a review trigger. A spreadsheet with four people's edits and no version number satisfies neither test convincingly, and it is the single most common piece of an internal audit procedure that never made it into the document management system.

The tell: ask who owns the current version of your audit program and how you would know if someone changed it. If the answer involves an email thread, this edit is your longest-lead item.

The edit itself is a cross-reference: your internal audit procedure names the audit program as a controlled document, assigns its owner, states its revision trigger, and points at your document control procedure for the mechanics. Organizations that already run a mature document control process will find this a half-day change. Organizations whose program lives in one person's files will find it is the change the 2029 deadline was really about. MSI's guide to evaluation of compliance covers the parallel available-versus-retained distinction on the compliance side of ISO 14001, and the ISO 14001 continual improvement guide shows where the audit program feeds the wider loop.

Now Available · Editable Word · $149 Single Standard · $249 Combined

The 2026-Ready Internal Audit Procedure Template, Written to Your Standard

The waitlist is closed because the templates are finished. Each one is a complete, editable internal audit procedure with all seven edits already made: a mandatory per-audit objectives field, an on-site / remote / hybrid method-selection step with the rationale captured, platform-specific competence criteria, an evidence-reliability and data-security check, the five risk levers written into program planning, competence and reporting records, and the audit program itself defined as a controlled document. Written as a finished working document rather than an outline — the decisions already made and explained, with bracketed placeholders everywhere a value is genuinely yours to set.

ISO 9001 internal audit procedure · ISO 13485 · ISO 14001:2026 · ISO 45001 · ISO 7101
Combined: ISO 9001 + 13485 · ISO 14001 + 45001 · ISO 9001 + 14001 + 45001

See the ISO 14001:2026 Internal Audit Procedure →


One Procedure · Five Standards

What Each Standard Requires of Your Internal Audit Procedure

Same Clause. Different Teeth.

Direct Answer: A shared internal audit procedure must satisfy the strictest requirement in the set, not the average. ISO 13485 is the only one that mandates a documented procedure by name and requires conformity to be measured against applicable regulatory requirements. ISO 45001 puts worker consultation inside the program. ISO 7101 sets a twelve-month maximum interval. ISO 14001:2026 adds objectives and document control. ISO 9001:2015 is the least prescriptive of the five, which is why building the shared procedure to the 9001 baseline alone fails an integrated audit.

This is the part most integrated procedures get subtly wrong. The clause numbers line up neatly, which creates the impression the requirements do too. They do not, and each standard has one requirement that quietly vanishes when a procedure is written from another standard's template.

Standard The Requirement Your Procedure Must Carry
ISO 9001:2015
9.2.2
The program considers importance of processes, changes affecting the organization, and previous results. Clause 9.2.2 e) requires correction and corrective action without undue delay — two obligations, not one.
ISO 13485:2016
8.2.4
Mandates a documented procedure by name. Conformity measured against applicable regulatory requirements. Interval and methods recorded. Auditors shall not audit their own work. Records identify areas audited and the conclusions. Follow-up includes verification and the reporting of verification results.
ISO 14001:2026
9.2.2
New: audit objectives required per audit. New: three documented information items must be available, the first being the audit program itself. No corrective action requirement sits inside Clause 9.2.
ISO 45001:2018
9.2.1 – 9.2.2
Consultation sits inside the program. OH&S policy and objectives are conformity criteria. Relevant results are reported to workers and workers' representatives. Action cross-references Clause 10 by name.
ISO 7101:2023
9.2.2
Audits at a minimum of once every twelve months. Conducted by trained and qualified individuals. Results reported in a timely manner. Audit objectives required since 2023.

One more distinction worth writing down, because assuming otherwise is a common error. The February 2024 climate action amendment added climate change wording to Clauses 4.1 and 4.2 of more than thirty management system standards, including ISO 9001:2015, ISO 14001:2015 and ISO 45001:2018, and certification bodies have sampled against it since March 2024. ISO 13485 is not among them — it is not built on the harmonized structure and was not amended. If your internal audit procedure treats all five standards as having received the amendment, an ISO 13485 auditor will notice.

US Device Manufacturers

Why QMSR Changes the Stakes on Your Internal Audit Procedure

Inspectable. Now. Not-Later.

Direct Answer: For US medical device manufacturers, the internal audit procedure now governs records an FDA investigator can ask to see. Since 2 February 2026, ISO 13485:2016 is incorporated by reference into 21 CFR Part 820, and the former § 820.180(c) exemption was not carried across. FDA's own QMSR guidance confirms the agency has authority to review management review, quality audit and supplier audit reports.

For twenty-five years, internal audit reports sat behind an exemption. A device manufacturer could audit itself honestly, write findings plainly, and know the report would not be read across the table during an inspection. That changed with the Quality Management System Regulation final rule, and the practical consequence lands squarely on the internal audit procedure: the report template, the language convention for findings, and the retention rule are now decisions with regulatory weight.

The wrong response is to soften the findings. An internal audit program that stops writing honest nonconformities stops working, and an investigator reading a year of clean audits in a facility with open complaint trends draws exactly the conclusion you were trying to avoid. MSI's house standard is the opposite: write the finding precisely, close it with evidence, and let the closure record carry the weight. That is the discipline MSI teaches throughout its ISO consulting engagements, and it is what makes an audit trail defensible rather than merely tidy.


Seven Edits · One Audit

What Does a 2026-Ready Internal Audit Procedure Look Like in Practice?

One Audit. Seven Edits.

The seven edits are easiest to understand when you watch them work together across a single audit. Picture a mid-sized manufacturer running an integrated management system, preparing to audit its corrective-action process. Under a 2026-ready internal audit procedure the audit begins not with a checklist but with an objective: confirm that corrective actions raised in the last cycle were implemented and proved effective. That objective — now required under ISO 14001:2026, and required under ISO 7101 since 2023 — immediately shapes every decision that follows.

With the objective set, the auditor chooses a method and records why. Much of this audit is document and record review, which can be done remotely, so the auditor schedules a remote session for the corrective-action records and reserves a short on-site visit to verify that one physical control was actually installed. The method-selection step captures that reasoning. Before the remote session the platform-competence prerequisite applies: the auditor is confirmed competent on the organization's chosen platform, knows where the session recording will be stored under the retention policy, and holds the host controls needed to manage screen-sharing and admission cleanly.

During the session the evidence-reliability check shapes how the auditor treats what appears on screen. A screen-shared corrective-action log is useful, but the auditor confirms it is the controlled version, traceable to the document management system, before relying on it — and notes where a remote view was insufficient and on-site confirmation was needed. The five risk levers had already done their work upstream: this process carried elevated risk after a recent change, so it earned a deeper sample, the most experienced auditor available, and an on-site component rather than simply an earlier date on the calendar.

The report records the objective, the method used and whether the objective was met, feeding cleanly into management review. And the schedule that placed this audit where it sits is itself a controlled document with an owner and a revision history — which is what lets the auditor demonstrate, without opening a spreadsheet nobody can version, that the program was planned rather than assembled. Every one of the seven edits played a visible role, and none required a new document.

That is the practical test of a good revision: not whether the internal audit procedure reads well, but whether it produces audits that deliver reliable conclusions in the way organizations actually work. Across 200+ audits attended, the procedures that hold up are the ones written for how the work really happens.

Organizations that want to benchmark their own document against this standard will find the supporting context in MSI's guide to ISO 14001 certification, its view of why a durable quality management mindset outperforms compliance theater, and its account of how a government internal audit program matures from event to intelligence. The wider audit lifecycle — internal, surveillance and certification — is mapped in MSI's guide to the ISO audit.

Rollout

How to Roll These Internal Audit Procedure Edits Out Without Disruption

Edit. Approve. Train.

None of the seven edits requires rebuilding your internal audit procedure from scratch. They are targeted insertions into a document that already works: an objectives field, a method-selection step, a platform-competence prerequisite, an evidence-reliability check, five risk levers in the planning section, updated competence and reporting records, and the audit program brought under document control. Treat the revision the way you would any controlled-document change — draft the edits, route them through your normal review and approval, update the version, and communicate what changed.

Sequence matters more than speed. Edit 7 is the long-lead item because it touches document control; start it first. Edits 1 and 2 are same-week changes. Edits 3, 4 and 6 land in your competence and reporting records and can move alongside your next training cycle. Edit 5 is a planning-section rewrite best timed to your next program cycle, when you are setting the schedule anyway.

Then train to the revised procedure. Your internal auditors and any supplier auditors you rely on should understand the objectives field, the method-selection logic and the platform-competence expectation before their next scheduled audit. For ISO 14001-certified organizations, both 2026 edits should be in place well before the transition audit, since they are requirements rather than guidance. Teams that prefer a guided path can lean on MSI's approach to certification audits, its SurePath turnkey certification program, or the year-round maintenance rhythm of SureResults. For an independent read on where the system actually stands, The Portrait is MSI's operational assessment.

Every Procedure the System Needs

Twenty-Eight Years of Practice, Written Down

The internal audit procedure is one document in a system that needs many, and the expensive part of documenting a management system is not writing any single procedure — it is making them agree with each other: the same records referenced the same way, the same review triggers, interfaces named on both sides. MSI's procedure templates and guides cover the full set across five standards and their combinations, every one built to the same section architecture, editable Word, with the judgment calls already made.

See the ISO Procedure Templates and Guides →

Need to Revise Your Procedure Before Your Next Audit?

If your internal audit procedure, competence criteria or auditor training need to catch up with the 2026 ISO updates, MSI can map the exact edits that matter for your standards and your operation — and help you make them before a transition audit rather than during one. Begin with a planning session: a working conversation, not a sales script.

Call 760-434-9141 to plan a session.


Frequently Asked Questions

Revising Your Internal Audit Procedure for 2026

Ask. Answer. Apply.

Does ISO 14001:2026 really require objectives for every internal audit?

Yes. ISO 14001:2026 revised Clause 9.2.2 so that defining scope and criteria for each audit is no longer sufficient — each internal audit must also state defined objectives. This is a normative requirement, and certified organizations should build a mandatory objectives field into the internal audit procedure ahead of their transition audit, within a window closing 30 April 2029. Worth knowing: ISO 7101:2023 Clause 9.2.2 a) has required audit objectives since 2023, so this is new to ISO 14001 rather than new to the standards.

Can a certification body write a finding against ISO 19011:2026?

No. ISO 19011 is guidance, not a requirements standard. No organization is certified to it, no clause can be raised as a nonconformity, and there is no transition period. The real mechanism is indirect: ISO 19011 underpins auditor training and certification schemes, so certificated auditors are retrained against the current edition and arrive with updated expectations. Where practice falls short of current auditing good practice, the finding is written against Clause 9.2 of the standard you are certified to.

What actually changed in ISO 19011:2026?

ISO 19011:2026 was published on 27 May 2026 as the fourth edition, withdrawing ISO 19011:2018. ISO's statement of the main changes lists two: expanded guidance on remote auditing methods through the introduction of guidance contained in ISO/IEC TS 17012, and an expanded Annex A covering remote auditing methods and virtual locations. The edition also states that it adopts the combined audit approach, where two or more management systems of different disciplines are audited together. Much of the wider commentary circulating about the 2026 edition goes beyond what ISO has actually published.

Do I need to rewrite my internal audit procedure for these changes?

No. The seven edits are targeted insertions into your existing internal audit procedure: an objectives field, a method-selection step, a platform-specific competence prerequisite, an evidence-reliability and data-security check, five risk levers in program planning, updated competence and reporting records, and the audit program brought under document control. Route them through your normal controlled-document review, update the version, and train your auditors to the revised procedure.

What does “available” mean compared with “retained” for the audit program?

Retained means kept — you can produce it when asked. Available means current, retrievable and under control: the version an auditor sees is the version the program is running to, with a revision history, a named owner and a review trigger. ISO 14001:2015 required evidence of the implementation of the audit program and the audit results to be retained. ISO 14001:2026 requires three items to be available, the first of which is the audit program itself, which for most organizations means moving a desktop spreadsheet into the document management system.

Why does the platform matter for remote audits — isn't competence in remote tools enough?

Generic “remote tools” competence is too vague to be auditable, because the mechanics that affect evidence differ by platform. Recording destination and retention, host and presenter controls, admission settings and file-exchange paths all behave differently between Microsoft Teams and Zoom, and an audit recording can itself become a controlled record. Naming the specific platform and requiring auditors to be trained on its mechanics is MSI's house standard, and it makes the competence expectation concrete and verifiable.

Does ISO 9001:2026 also require audit objectives?

Not yet, because ISO 9001:2026 has not published. The FDIS ballot closed on 9 July 2026 with publication expected in September 2026, and technical content is frozen at the FDIS stage. Until publication, the per-audit objectives requirement should be attributed to ISO 14001:2026 and ISO 7101:2023 only. Organizations running integrated systems can future-proof by adding the objectives field to the shared internal audit procedure now, which satisfies ISO 14001:2026 immediately.

Are internal audit reports now inspectable by FDA?

For US medical device manufacturers, yes. Since 2 February 2026 ISO 13485:2016 has been incorporated by reference into 21 CFR Part 820, and the former § 820.180(c) exemption that shielded quality audit reports was not carried across. FDA's QMSR guidance confirms the agency has authority to review management review, quality audit and supplier audit reports. The right response is a sharper internal audit procedure and better closure records — not softer findings.

Which management systems does a single internal audit procedure cover?

Most organizations run one internal audit procedure across every management system they hold — ISO 9001 quality, ISO 14001 environmental, ISO 45001 occupational health and safety, ISO 13485 medical device and ISO 7101 healthcare. The efficiency is real, but the shared procedure has to satisfy the strictest requirement in the set rather than the average: ISO 13485 mandates a documented procedure by name, ISO 45001 puts worker consultation inside the program, and ISO 7101 sets a twelve-month maximum interval.

How can MSI help us revise our internal audit procedure?

MSI translates the 2026 updates into the specific edits your internal audit procedure, competence criteria and training actually need — without overcorrecting. With 28 years of experience, 80+ certifications supported, 200+ audits attended and 600+ professionals trained, MSI can revise your procedure, update your auditor qualification path and prepare your team ahead of a transition audit. Start with the free Internal Audit Maturity Check, take the finished procedure template for your standard, or call 760-434-9141 to plan a session.


Related Reading

Build the Program, Not Just the Procedure

Plan. Audit. Improve.

References & Authoritative Sources

About Management Systems International (MSI)

Diana Lynn is President and Principal ISO Consultant at Management Systems International, LLC, a veteran-owned, female-owned ISO consulting firm she co-founded in 1998. Across 28 years of experience, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

msi-international.com · 760-434-9141

Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 13 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply