ISO 19011:2026 · Internal Auditor Competence
By Diana Lynn, President and Principal ISO Consultant, MSI · Updated September 28, 2026
ISO internal audits are first-party audits an organization conducts on its own management system to check that it conforms and works as intended.
Direct Answer: ISO internal audits are only as trustworthy as the person conducting them. ISO 9001:2026 and ISO 14001:2026 require auditors selected to ensure objectivity and impartiality, and ISO 19011:2026 supplies the competence guidance that makes it provable. Seven marks separate a real internal auditor from someone holding a checklist: independence, documented competence, evidence discipline, consistent classification, defensible sampling, useful reporting and verified follow-through. Score your auditors against all seven before your next cycle.
Key Takeaways
- ISO 9001:2026, published September 16, 2026, joins ISO 14001:2026 in requiring audit objectives, criteria and scope to be defined for each audit (Clause 9.2.2 a).
- ISO 19011:2026, published May 27, 2026, replaced the 2018 edition with no transition period and remains the primary guidance for internal audits.
- ISO 19011:2026 Clause 7.2.3.2 lists auditor skills that include using information and communications technology tools, including AI-based evaluation tools, and maintaining information security.
- Auditors are persons doing work under the organization’s control, so ISO 9001:2026 Clause 7.2 requires their competence to be determined and evidenced.
- ISO 14001:2026 is the only one of the three common standards that requires the audit program itself to be available as documented information.
- MSI’s Seven-Mark Internal Auditor Scorecard rates each auditor from 0 to 14 so gaps in independence, evidence and follow-through become visible.
The uncomfortable truth about ISO internal audits is that two organizations can run identical ISO internal audits on identical schedules, produce identical report templates, and log identical numbers of findings — and one of those programs is protecting the business while the other is manufacturing paperwork. The difference is almost never the procedure. It is the person.
A certification body auditor figures this out in roughly twenty minutes. They ask to see the ISO internal audits records for one process, read three findings, and ask the internal auditor a single follow-up question about how a sample was selected. The answer tells them whether the internal audit function is a genuine control or a ritual. Everything after that in the certification audit is calibrated to what they learned in those twenty minutes.
This article is the evaluation framework — seven marks, each one testable this week, each one anchored to something a standard or an accreditation rule actually requires. It applies whether the person running your ISO internal audits is a colleague from another department, a full-time quality professional, or an outside specialist you contract. And it applies to ISO 9001, ISO 13485, ISO 14001, ISO 45001, and ISO 7101 alike, because auditor competence is the one requirement none of them let you scope out.


The Requirement Behind the Requirement
What Do ISO Internal Audits Actually Require of the Auditor?
Competent. Independent. Accountable.
Direct Answer: Every management system standard requires ISO internal audits conducted by auditors selected to ensure objectivity and impartiality, but none of them tell you how to prove it. That proof comes from ISO 19011:2026, the international guidance on auditing management systems, which defines the competence criteria, the seven auditing principles, and the evaluation process a credible program uses to qualify its people.
The requirements clauses governing ISO internal audits are short to the point of being unhelpful. ISO 9001:2026 and ISO 14001:2026 both require the organization to define the audit objectives, criteria and scope for each audit, and to select auditors and conduct audits so as to ensure objectivity and the impartiality of the audit process (Clause 9.2.2 a and b). ISO 45001 layers on worker consultation. None of them define auditor competence in detail. None of them tell you what independence looks like operationally.
That vacuum is deliberate, and it is why so many ISO internal audits are conducted by people nobody ever qualified. The detail lives in ISO 19011, whose fourth edition published on 27 May 2026 and withdrew the 2018 edition immediately, with no transition period. Because ISO 19011 is guidance rather than a requirements standard, nobody is audited against it — which is precisely why so many programs never opened it. MSI covers the full clause-level picture in its breakdown of the ISO 19011:2026 changes and the edits your internal audit procedure needs to absorb them.
The seven principles ISO 19011 sets out in Clause 4 — integrity, fair presentation, due professional care, confidentiality, independence, the evidence-based approach, and the risk-based approach — carry forward intact into the 2026 edition. They are not aspirational language. They are the criteria against which a mature program evaluates the people running its ISO internal audits, and they map cleanly onto the seven marks below.
| What the text addresses | Where | Status |
|---|---|---|
| Define audit objectives, criteria and scope for each audit | ISO 9001:2026 and ISO 14001:2026, 9.2.2 a) | Requirement |
| Select auditors and conduct audits to ensure objectivity and impartiality | ISO 9001:2026 and ISO 14001:2026, 9.2.2 b) | Requirement |
| Report audit results to relevant managers | ISO 9001:2026 and ISO 14001:2026, 9.2.2 c) | Requirement |
| Take correction and corrective action without undue delay | ISO 9001:2026, 9.2.2 d) | Requirement |
| Audit program itself available as documented information | ISO 14001:2026, 9.2.2 | Requirement (ISO 14001 only) |
| Determine and evidence the competence of people doing work under the organization’s control, auditors included | ISO 9001:2026, 7.2 | Requirement |
| Seven principles of auditing | ISO 19011:2026, Clause 4 | Guidance (“should”) |
| Auditor skills including ICT and AI-based tools, and information security | ISO 19011:2026, 7.2.3.2 | Guidance (“should”) |
| Auditor personal behaviours (ethical, diplomatic, open-minded and more) | ISO 19011:2026, 7.2.2 | Guidance (“should”) |
| Independence written as a decision test; periodic auditor evaluation records | MSI practice | MSI recommendation |
A certification body cannot cite you for failing ISO 19011. It can, and routinely does, cite you for an internal audit program whose auditors cannot demonstrate the competence the organization itself defined as necessary.
This is the trap most programs fall into. The organization writes a procedure saying the auditors conducting its ISO internal audits shall be competent, defines no criteria, keeps no evaluation records, and then discovers during a surveillance audit that it has raised a nonconformity against its own documented requirement. The finding is not about auditing skill. It is about the absence of evidence.
The Framework
The 7 Proven Marks of a Real Internal Auditor
Test. Observe. Decide.
Direct Answer: The seven marks of an auditor who can be trusted with ISO internal audits are: independence written as a decision test rather than an intention; competence defined against criteria and evidenced in records; evidence discipline that separates observation from inference; finding classification that means the same thing regardless of who raised it; sampling judgment that can be explained; reporting that gives management review something to act on; and follow-through that verifies effectiveness rather than accepting a status update.
Each mark below includes what to look for in ISO internal audits, and the specific question that exposes its absence. The questions are the useful part — they take under a minute each and they are almost impossible to bluff.
Mark 1 — Independence Written as a Decision Test
In ISO internal audits, independence is the principle everyone claims and almost nobody documents. The standard language — auditors shall not audit their own work — is easy to write and surprisingly hard to apply in a forty-person company where the quality manager wrote every procedure in the system.
A real program converts the principle into a rule that produces the same answer regardless of who applies it. Something closer to: an auditor may not audit a process in which they hold approval authority, wrote or approved the controlling document within the current revision cycle, or report to the process owner. That is a test. “Auditors should be objective” is a wish.
The question: Show me the rule that would have disqualified you from this audit, and show me a time it did. A program that has never disqualified anyone either has no rule or does not apply it. In organizations too small for clean separation, the honest answer is a documented compensating control — an external reviewer, a second-auditor sign-off, or an outsourced audit for the highest-risk processes. MSI’s internal audit services exist substantially for that case.
Mark 2 — Competence Defined, Evaluated, and Recorded
ISO 19011 describes competence as a combination of knowledge and skills evaluated against criteria the organization sets. The 2026 edition expands what belongs in those criteria. Clause 7.2.3.2 now lists understanding the appropriateness and consequences of using information and communications technology tools and emerging technology, including AI-based evaluation tools, alongside maintaining the confidentiality and security of information and awareness of data protection and information security requirements.
Because auditors are people doing work under the organization’s control, ISO 9001:2026 Clause 7.2 applies to them directly: necessary competence must be determined, and documented information must be available as evidence of it. Certificates matter less in ISO internal audits than most people assume. A training certificate evidences attendance and, in a good course, a demonstrated practice audit. It does not evidence continuing competence three years later.
Mature programs evaluate auditors periodically against the criteria, using observation during a live audit, review of finding quality, and auditee feedback — and they keep the records. The interpersonal side matters as much as the technical: ISO 19011:2026 Clause 7.2.2 describes auditors who are diplomatic, open-minded and culturally sensitive, which MSI unpacks in its guide to mandatory soft skills. MSI’s ISO Internal Auditor Workshop and its ISO Internal Auditor training both build toward a documented qualification rather than an attendance slip, and the deeper picture of what the role demands is covered in MSI’s internal auditor guide.
The question: What are the competence criteria for this role, and when was this auditor last evaluated against them?
Mark 3 — Evidence Discipline
Audit evidence in ISO internal audits is records, statements of fact, or other verifiable information relevant to the audit criteria. The operative word is verifiable. A weak auditor writes findings built on impressions — the area seemed disorganized, training appeared inconsistent. A strong auditor writes findings that another person could confirm from the same records without having been in the room.
The 2026 edition sharpened this for digital evidence, listing the ability to verify the relevance and accuracy of collected information and to assess factors that can affect the reliability of findings. A screenshot from a live system raises questions a paper record never did: was the view filtered, who has edit rights, is this the controlled revision. Programs auditing software-mediated processes — and by now that is most of them — need an evidence-reliability step built into the procedure, not improvised at the desk. MSI’s work on auditing AI agents pushes this further, into processes where the thing being audited makes decisions on its own.
The question: Take any finding from the last cycle. Can a second person reach the same conclusion from the evidence cited alone?
Mark 4 — Finding Classification That Holds Its Meaning
In too many ISO internal audits, whether something is a major nonconformity, a minor, or an observation depends entirely on who wrote it and how the week was going. That inconsistency destroys the data. Trend analysis across cycles becomes meaningless, management review sees noise, and the corrective action system receives work sorted by mood rather than severity.
A real program publishes classification criteria — typically some combination of whether a requirement is absent versus imperfectly applied, whether the failure is systemic or isolated, and whether the effect reaches the customer, the environment, the patient, or the worker. Written down, the criteria make the classification arguable, which is the point. Arguable beats arbitrary.
The question: Two auditors, same evidence — would they classify it the same way, and what document says so?
Mark 5 — Sampling Judgment That Can Be Explained
Ask an auditor running your ISO internal audits why they pulled those six records and not another six. The answer separates the professional from the amateur faster than any other question in this article. “They were the ones on top” is a real answer that real auditors give. So is “the system exported them in that order.”
Defensible sampling reflects risk: recent changes, processes with corrective action history, high-consequence steps, periods spanning a personnel or system transition, and a deliberate random component so the sample cannot be curated by the auditee. This is the same risk logic that governs program-level scheduling, which MSI lays out in its guide to internal audit planning and its treatment of internal audit risk mitigation strategies.
The question: Why these records? Reconstruct the reasoning.
Mark 6 — Reporting That Survives Management Review
An audit report from ISO internal audits that lists findings has done half the job. An audit report that states what the audit set out to learn, how it was conducted, whether the objective was met, and what the pattern across findings suggests has given leadership something to decide with.
This matters more now that ISO 14001:2026 and ISO 9001:2026 both require objectives to be defined for each audit — an audit without a stated objective now has a conformity problem, not just a quality problem. Reporting is also the handoff point into management review, where audit results are a required input under every one of the standards MSI implements. MSI’s ISO Management Review Toolkits are built around exactly that handoff, and the wider connection is explored in MSI’s work on government internal audit, where audit output becomes leadership input.
The question: What did the last audit report change?
Mark 7 — Follow-Through to Verified Effectiveness
The seventh mark is where most ISO internal audits quietly fail. A finding is raised, a corrective action is entered, someone marks it complete, and the loop closes on a status field rather than on evidence. The next cycle raises the same finding, and nobody connects the two.
Verified effectiveness means the auditor returns to evidence: the updated procedure, the training record, the output of the process running the new way, the metric before and after. Closure is a judgment, not a checkbox. MSI covers the full mechanics in its guide to internal audit follow-up, and the program-level view in building an internal audit program.
The question: Show me a finding closed last year and the evidence that it stayed fixed.
MSI Original Asset
The Seven-Mark Internal Auditor Scorecard
Score each auditor on each mark: 0 when nothing exists, 1 when the expectation is written down but not evidenced, 2 when a record proves it. Use the records, not the auditor’s description of them.
| Mark | Record that earns a 2 | Score |
|---|---|---|
| 1. Independence | A written disqualification rule and at least one assignment it changed | 0 · 1 · 2 |
| 2. Competence | Criteria covering 2026 digital and remote skills, plus a dated evaluation | 0 · 1 · 2 |
| 3. Evidence discipline | Findings that cite specific, retrievable evidence a second person can verify | 0 · 1 · 2 |
| 4. Classification | Published major, minor and observation criteria applied consistently | 0 · 1 · 2 |
| 5. Sampling | A recorded rationale for each sample, including a random component | 0 · 1 · 2 |
| 6. Reporting | Reports that state the audit objective and whether it was met | 0 · 1 · 2 |
| 7. Follow-through | Closed findings with before-and-after effectiveness evidence | 0 · 1 · 2 |
Reading the total (0 to 14). A score of 0 to 6 means the function is a ritual: audits happen, but little in them could be relied on. A score of 7 to 11 means developing: the intent is written down, and the records are catching up. A score of 12 to 14 means the internal audit function is a genuine control that management review can trust. For a program-level view, MSI’s free internal audit maturity check scores the whole process in about six minutes.
“I have always felt that integrity is at the center of all ISO standards.”
— Diana Lynn, President and Principal ISO Consultant, Management Systems International (MSI)
ISO 19011:2026 opens its principles with the same idea, calling integrity the foundation of professionalism. Every one of the seven marks is integrity made visible: an auditor who will disqualify themselves, cite only what the evidence supports, and refuse to close a finding on a status field.
Across 28 years, 200+ audits attended, 80+ certifications supported and 600+ professionals trained, the single most common root cause MSI observes behind a struggling internal audit program is not incompetence. It is an auditor who was never given criteria, never evaluated, and never told what “good” looked like — then held responsible when the program stopped finding anything useful.
The Build-or-Buy Decision
Should ISO Internal Audits Be Run In-House or Outsourced?
Capacity. Independence. Depth.
Direct Answer: Run ISO internal audits in-house when you have enough separation of duties to satisfy Mark 1 and enough audit volume to keep auditors current. Bring in an outside auditor when the organization is too small for genuine independence, when the highest-risk processes are owned by the people who would otherwise audit them, when internal capacity cannot cover the cycle, or when the program needs an honest calibration against what a certification body will see.
The choice of who conducts ISO internal audits is usually framed as cost, which is the least interesting variable. The real variables are three.
Independence capacity. Below roughly forty people, most organizations cannot construct a clean audit assignment for their core processes. Everyone with the knowledge to audit purchasing also approves purchase orders. This is not a failure of will; it is arithmetic. An outsourced auditor solves it structurally.
Currency. An auditor who conducts two audits a year does not build judgment. They build a routine. Sampling instinct, interview technique, and the ability to recognize when an answer is being managed all come from volume. If the program cannot supply volume, the auditors need either external practice or external help.
Blind spots. An internal auditor knows the system’s stories — why that exception exists, what the workaround is for. That knowledge is an asset for efficiency and a liability for detection. Organizations typically report that the first outside audit of a mature system surfaces findings the internal team had stopped seeing years earlier.
Most healthy programs land on a blend: internal auditors handle the routine cycle, an outside auditor takes the two or three highest-consequence processes and the annual calibration. Multi-site organizations face this most acutely, since the cycle must cover every site plus the central function — a capacity problem MSI addresses in its guide to multi-site ISO certification. Externally provided processes complicate it further, as MSI’s work on purchasing and supplier control and ISO 14001 externally provided processes both document.
A quick way to decide
Write down your three highest-consequence processes. For each, name the person who would audit it and the person who owns it. If any name appears twice, you have located the part of your program that needs outside help — and you have located it in about ninety seconds.
What the Registrar Opens
What Does a Certification Body Check in Your ISO Internal Audits?
Program. People. Proof.
Direct Answer: A certification body examining your ISO internal audits looks for four things in sequence: the audit program itself and evidence it was implemented, the competence records for the people who conducted the audits, the findings and their classification, and the corrective actions with evidence of effectiveness. Certification bodies accredited to ISO/IEC 17021-1 cover internal audits in their surveillance activities because the function tells them how much of the rest of your system they can trust.
Certification bodies operate under ISO/IEC 17021-1, accredited by bodies whose international coordination now sits with Global ACI, which commenced operations on 1 January 2026 replacing both IAF and ILAC. In the United States, ANAB is the accreditation body most organizations encounter. None of these permit a registrar to skip the internal audit function.
The sequence of what a registrar samples in ISO internal audits matters more than the list. The registrar starts with the program because it reveals intent — does the schedule reflect risk, or is it twelve processes divided by twelve months? They move to competence records because the program is only as good as its people. Then findings, because finding quality reveals auditor skill more reliably than any certificate. Then corrective action, because closure quality reveals whether the organization takes its own audits seriously.
One under-appreciated detail: ISO 14001:2026 requires the audit program itself to be available as documented information, alongside evidence of its implementation and of the audit results. ISO 9001:2026 requires documented information to be available as evidence of implementation and results only, and ISO 45001:2018 requires retained evidence of the same. Organizations running an integrated system frequently satisfy the lighter obligation and assume it covers all three. It does not. MSI’s guidance on ISO procedure order works through where these divergences sit, and the broader lifecycle view is in MSI’s overview of the ISO audit and its perspective on ISO consulting for confident certification audits.
The Silent Failure
The Auditor Qualification Records Trap in ISO Internal Audits
Written. Undone. Fixed.
Direct Answer: The most common nonconformity MSI observes against ISO internal audits is not a missed audit — it is an organization that defined auditor qualification requirements in its own procedure and then kept no evidence of meeting them. The procedure becomes the finding. Either evidence the requirement or rewrite the requirement to something you will actually maintain.
The pattern repeats across ISO internal audits with unusual consistency. A procedure written years ago, often copied from a template, states that internal auditors shall complete formal internal auditor training, shall have three years of relevant experience, and shall be evaluated annually. Nobody checks whether that sentence describes reality. Three certification cycles later, an auditor asks for the annual evaluations, and there are none.
This is entirely avoidable, and the fix takes an afternoon. Read your own internal audit procedure as if you were the registrar. Every “shall” applying to auditors is a commitment you must evidence.
Then make one of two choices for each: produce the evidence going forward, or amend the procedure to state a requirement you will genuinely maintain. Both are legitimate. Leaving the mismatch in place is not.
Ready-made procedure text helps here, because a well-built template states the qualification requirement at a level an organization can actually sustain and names the record that evidences it. MSI’s ISO Procedure Templates and Guides handle this across fifteen procedure topics and five standards. The ISO 9001 Internal Audit Procedure Template and Guide builds the audit program as a controlled document with re-planning triggers, and the IMS Internal Audit Procedure Template and Guide writes auditor independence as a decision test rather than an intention — the exact construction Mark 1 calls for. The companion ISO manual templates cover the layer above.
What Changed in 2026
How the 2026 Standards Raised the Bar for ISO Internal Audits
Remote. Digital. Accountable.
Direct Answer: Three 2026 publications changed ISO internal audits. ISO 19011:2026 embedded remote and hybrid auditing across the audit lifecycle and added technology and information-security skills to auditor competence. ISO 14001:2026 and ISO 9001:2026 both require objectives, criteria and scope to be defined for each audit. As of September 28, 2026, competence criteria and audit plans written before these editions are almost certainly incomplete.
In ISO internal audits, remote auditing moved from a pandemic workaround to a designed method. The practical consequence for evaluation is that method selection is now an auditor competence — knowing when a process can be audited remotely, when it cannot, and how to compensate. An auditor who defaults to video calls because they are convenient is making a competence error, not a logistics choice.
The information-security dimension is the genuinely new one for ISO internal audits. Granting an auditor access to live systems creates obligations that did not exist when audits ran on paper and a conference room. Tool-specific competence, evidence-reliability judgment, and data-handling discipline all now belong in the criteria. Most organizations have not updated the criteria, which means most organizations are evaluating auditors against a 2018 edition that has been withdrawn.
Two other 2026 currents shape the same work. ISO 14001:2026 published on 15 April 2026 with a transition deadline of 30 April 2029. ISO 9001:2026 published on 16 September 2026, and Global ACI transition requirements give certified organizations until 30 September 2029 to transition (as of 28 September 2026). Its Clause 9.2.2 a) now asks for audit objectives for each audit, just as ISO 14001:2026 does, so audit programs built this year are already auditing a revised quality standard. Organizations that treat ISO internal audits as the place where transition readiness gets tested will find the transition considerably less eventful than those that do not.
Related reading
ISO 19011:2026 Changes · Internal Audit Procedure: The Essential Edits · Internal Audit Skills · Auditing Quality Culture · Integrated Management Systems · ISO Overview
Ninety Days
A 90-Day Sequence to Qualify the People Running Your ISO Internal Audits
Define. Evaluate. Evidence.
Direct Answer: Qualifying the people who conduct your ISO internal audits takes about ninety days of part-time effort: three weeks to define criteria and reconcile them with your existing procedure, four weeks to train or refresh, four weeks to evaluate through observed audits, and a final two weeks to build the record set and wire the outputs into management review.
Weeks 1–3 — Define and reconcile. Write competence criteria covering standard knowledge, audit method including remote and hybrid, sector or process knowledge, and digital evidence handling. Then read your existing internal audit procedure against them and resolve every mismatch. This is the step that prevents the qualification records trap.
Weeks 4–7 — Train or refresh. Formal training for new auditors; a targeted refresh on the 2026 changes for experienced ones. Experienced auditors resist this and should not: the digital and remote content is genuinely new, and they are the ones most likely to be auditing on autopilot.
Weeks 8–11 — Evaluate through observation. Every auditor conducts one audit with an experienced observer present. The observer scores against the criteria, using the Seven-Mark Internal Auditor Scorecard, and writes it down. This single step produces more improvement in finding quality than any classroom hour, and it produces the record a registrar will ask for.
Weeks 12–13 — Evidence and wire in. Build the competence record set — criteria, training, evaluation, and a review date for each auditor. Then confirm the reporting format gives management review what it needs, because an audit program that does not reach leadership is an expense rather than a control.
Organizations that would rather not run the qualification of their ISO internal audits alone have options across the spectrum. SureFinish compresses advisory into six weeks. SurePath delivers certification turnkey. SureResults maintains the system year-round once certified, including quarterly internal audits. And The Portrait provides the independent operational read that Mark 1 asks for when internal separation is not available.
Choose Your Path
Five Ways to Strengthen Your ISO Internal Audits This Quarter
Templates. Training. Judgment.
1 — Get the procedure that already makes the judgment calls
Twenty-eight years of practice, written down. Fifteen procedure topics across five standards and their combinations, editable Word, with the decisions already made — including the auditor independence rule written as a decision test rather than a hope. Not sure where your program stands? Score it free first.
See the ISO Procedure Templates and Guides → · Take the free internal audit maturity check →
2 — Rebuild the internal audit procedure itself, integrated
One procedure serving ISO 9001, ISO 14001:2026, and ISO 45001 together, with the clause obligations cross-referenced, every divergence resolved to the stricter standard, and a scoreable eight-element maturity ladder built in. Written for the organization that has to satisfy three registrar expectations with one document.
3 — Bring in an independent auditor for the processes you cannot audit yourself
If Mark 1 exposed a process whose auditor and owner are the same person, that is the process to outsource first. MSI conducts internal audits as a service and assesses the maturity of existing programs — an independent read that surfaces the finding while you still control the timeline.
4 — Build the bench, and get the record that proves it
The ISO Internal Auditor Workshop is the low-commitment on-ramp; the two-day ISO 9001 internal auditing course goes to the depth a lead auditor needs. Both finish with a documented qualification a registrar will recognize — which is the part an online certificate does not give you.
ISO Internal Auditor Workshop → · 2-Day ISO 9001 Internal Auditing →
5 — Close the loop into management review
Audit results are a required management review input under ISO 9001, ISO 13485, and ISO 14001. If your audit output arrives as a stack of findings rather than a read on system performance, the toolkits fix the format — a clause-anchored deck and matching minutes form, with the ISO 9001 toolkit shipping both the 2015 and 2026 editions.
Compare the ISO Management Review Toolkits → · ISO 9001 Management Review Tool Kit →
Not sure which of the five you need?
A thirty-minute planning session will tell you whether your internal audit function needs a procedure, a person, or a rebuild. No prepared materials required — bring your last audit report and your internal audit procedure.
Call 760-434-9141 · See how MSI ISO consulting works → · Contact MSI →
Questions
ISO Internal Audits: Frequently Asked Questions
Ask. Answer. Apply.
Who is allowed to conduct ISO internal audits?
Anyone the organization has determined to be competent, provided they do not audit their own work. ISO internal audits may be conducted by employees from other departments, by a dedicated quality function, or by contracted external auditors acting on the organization’s behalf — ISO 19011:2026 notes that internal audits are conducted by, or on behalf of, the organization itself. There is no requirement for an external certificate; there is a requirement that the organization determine competence and hold evidence that its auditors meet it.
How often must ISO internal audits be conducted?
At planned intervals, determined by risk rather than by calendar convenience. No standard specifies a frequency; ISO 9001:2026 asks the organization to consider the importance of the processes concerned, the results of previous audits and changes affecting the organization. In practice most certified organizations cover every process and every clause across an annual cycle, weighting higher-risk processes more often. ISO internal audits should also be triggered by events such as a significant process change or a new site coming into scope.
Does ISO 19011:2026 apply to internal audits?
Yes, and it is the primary guidance for them. ISO 19011:2026 states that it concentrates on internal (first-party) audits and on audits organizations conduct on their external providers (second-party). It is guidance rather than a requirements standard, so you are not audited against it directly — but it supplies the competence criteria, auditing principles, and program management approach that make ISO internal audits defensible. The 2026 edition published on 27 May 2026 and withdrew the 2018 edition with no transition period.
Can the same person write a procedure and audit it?
Not without a compensating control. Auditing a document you authored within the current revision cycle fails the independence principle, and a registrar will treat it as an objectivity concern. Small organizations that cannot avoid this should document the compensating control explicitly — a second-auditor review, an external reviewer, or outsourcing that specific audit. ISO internal audits tolerate constrained resources; they do not tolerate an undocumented conflict.
What records must be kept for ISO internal audits?
ISO 9001:2026 requires documented information to be available as evidence of implementing the audit program and of the audit results. ISO 14001:2026 additionally requires the audit program itself to be available. Alongside these, keep auditor competence records under Clause 7.2: criteria, qualification evidence, evaluation results, and a review date. ISO internal audits lose most of their defensibility when the competence records are the missing piece.
How do the 2026 standard revisions change ISO internal audits?
Three ways, as of 28 September 2026. ISO 19011:2026 raised competence expectations to include technology, AI-based tools, information security and remote methods. ISO 14001:2026, published 15 April 2026 with a 30 April 2029 transition deadline, requires audit objectives and an available audit program. ISO 9001:2026, published 16 September 2026 with a Global ACI transition deadline of 30 September 2029, also requires objectives for each audit. ISO internal audits are the natural place to test transition readiness while you still control the timeline.
References and further reading
ISO 19011:2026, Guidelines for auditing management systems, fourth edition. International Organization for Standardization. iso.org
ISO 9001:2026, Quality management systems — Requirements. International Organization for Standardization. iso.org
ISO launches ISO 9001:2026, 16 September 2026. ISO news. iso.org
Global ACI transition requirements for ISO 9001:2026. global-aci.org
ISO 14001:2026, Environmental management systems — Requirements with guidance for use. International Organization for Standardization. iso.org
ISO 45001, Occupational health and safety management systems. International Organization for Standardization. iso.org
ISO 13485, Medical devices — Quality management systems. International Organization for Standardization. iso.org
ISO/IEC 17021-1, Requirements for bodies providing audit and certification of management systems. iso.org
ISO Online Browsing Platform — terms and definitions. iso.org/obp
Global Accreditation Cooperation Incorporated (Global ACI). global-aci.org
ANSI National Accreditation Board (ANAB) — management systems accreditation. anab.ansi.org
American Society for Quality — auditing resources. asq.org
The Institute of Internal Auditors — Global Internal Audit Standards. theiia.org
ISO 19011:2026 revision guidance. CQI | IRCA Knowledge Hub. quality.org
U.S. Food and Drug Administration — Quality Management System Regulation (QMSR). fda.gov
21 CFR Part 820 — Quality Management System Regulation. Electronic Code of Federal Regulations. ecfr.gov
About Management Systems International (MSI)
Diana Lynn, President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she founded in 1998. With 28 years of experience, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality. MSI is veteran-owned and female-owned.
msi-international.com · 760-434-9141
