If you plan, run or manage management system audits, ISO 19011:2026 is the edition you now work from. ISO published this fourth edition on 27 May 2026, and it replaces ISO 19011:2018, which is withdrawn. The revision is focused: the official Foreword lists two main changes, and both concern remote auditing.
That focus matters, because several summaries in circulation describe the 2026 edition as far broader than it is. This article sticks to what the published text says, keeps it apart from Abilene's own practitioner advice, and shows what each audit role should do with it. If you want a refresher on what the guideline covers in general, start with what ISO 19011 covers for internal audits. Here we deal only with what is new.
What are the key facts about ISO 19011:2026?
ISO 19011:2026 key facts at a glance
Topic: Edition
Topic: Publication date
Topic: Replaces
Topic: Scope
Topic: Audit types
Topic: Development
Topic: Languages from ISO
Topic: What changed
Topic: What did not change
Topic: Transition period
Topic: Auditor certificates
Topic: Who is affected
What changed in ISO 19011:2026?
The Foreword of the 2026 edition names two main changes. The first is expanded guidance on remote auditing methods, which draws on ISO/IEC TS 17012. The second is an expanded Annex A that covers remote auditing methods and virtual locations. Everything else in the revision should be read in the light of those two changes.
New definition 3.4: remote auditing method
A method used for conducting audit activities from any place other than the location of the auditee.
Two further changes in the text follow the same theme. Definition 3.6, audit scope, now includes physical and virtual locations, which gives you a defined place to name the online environments you audit alongside the sites. Clause 5.1 asks the audit programme to consider the application of technology such as digital tools, together with information security and confidentiality requirements.
Read together, these changes treat remote auditing as an ordinary audit method that has to be planned, justified and protected. For most audit teams the practical work sits in three places: the scope statement, the audit plan template and the programme's rules for choosing and securing tools.
The scope statement moved as well. The 2018 abstract described the guideline as applicable to organizations that plan and conduct internal or external audits. The 2026 abstract simply refers to audits, and adds that using it for other types of audit needs special attention to both the competence required and the objectives to be achieved. ISO itself presents the guideline as relevant to first-party, second-party and third-party auditors alike.
If you want to check every textual change yourself, ISO offers the 2026 edition in English, French and Spanish, with an optional redline version that marks the changes, from its official catalogue page for ISO 19011:2026. In our experience, a lead auditor who reads the redline against their own audit procedure learns more in an afternoon than from any summary, this one included.
ISO 19011:2018 compared with ISO 19011:2026
Area: Status
Area: Scope wording
Area: Remote auditing guidance
Area: Annex A
Area: Remote auditing method
Area: Audit scope (3.6)
Area: Audit programme (5.1)
Area: Risk-based approach (4.8)
Area: Certification
What did not change in ISO 19011:2026?
The seven auditing principles remain the foundation of the guideline. The risk-based approach in clause 4.8 is one of them, and it was already a principle in the 2018 edition. If a briefing presents risk-based auditing as the headline of the 2026 revision, it has the history wrong.
The status of the document has not changed either. ISO 19011 is a guidance standard, which is why organizations cannot be certified to it and why the new edition comes without a transition period.
Check the claims you read
The Foreword lists two main changes, both about remote auditing. Treat any summary that presents ISO 19011:2026 as an AI auditing standard, a new competence regime for auditors or a new risk principle with caution, and check it against the published text. Where this article mentions AI tools in audits, it gives Abilene's practitioner view, which is not an ISO requirement.
Is there a transition period, and is my lead auditor certificate still valid?
There is no transition period. ISO 19011 gives guidance on auditing and organizations cannot be certified to it, so there is no certificate that has to move from one edition to the next in the way a certified management system does.
Existing auditor certificates remain valid. What changes is the reference point your next audit plan should use, especially if you audit remotely or across sites and online environments.
Whether you need retraining depends on how you audit. Auditors who regularly run remote or hybrid audits should work through the expanded guidance and Annex A, and new auditors are better served by learning the 2026 edition from the start. Our Certified Management Systems Internal Auditor training covers internal audit competence under ISO 19011 and suits both situations.
Expert view: Géraldine Rayet, lead QHSE trainer
Your certificate did not expire on 27 May. What changed is what a credible audit plan looks like when part of the work is remote: the method, its limitations, the evidence obtained, and the confidentiality arrangements need to be visible.
Géraldine Rayet is the lead QHSE trainer at Abilene Academy and teaches our auditor courses for quality, environment, and health and safety.
How does ISO 19011 differ from ISO/IEC 17021-1?
The two documents answer different questions. ISO/IEC 17021-1 sets requirements for certification bodies, the organizations that audit and certify management systems. ISO 19011 is guidance for auditing, written for anyone who plans, manages or conducts management system audits.
A certification body auditor works within the requirements of ISO/IEC 17021-1 and can draw on ISO 19011 for how to conduct the audit itself. For a worked example of how the two fit together with a management system standard, see how ISO 22301, ISO 19011 and ISO/IEC 17021-1 relate in an audit.
When should an audit be on-site, remote or hybrid?
The 2026 edition gives remote methods a defined place in the guideline, so the choice of method deserves to be a recorded decision rather than a habit. The visual below is Abilene's practitioner way of structuring that decision. It builds on the remote auditing guidance and clause 5.1, and it does not reproduce the text of the standard.
Decision visual in three steps. Step 1: can the evidence be observed and verified reliably from another place? If not, audit those activities on site. Step 2: do the remote tools meet the information security and confidentiality requirements agreed for the audit? If not, secure the tools first or audit on site. Step 3: does the audit scope combine physical and virtual locations? If yes, run a hybrid audit; if every activity can be audited from another place, run a remote audit. Abilene practitioner view built on the remote auditing guidance of ISO 19011:2026, including definition 3.4, definition 3.6 and clause 5.1.
In our experience the middle question is the one teams skip. Clause 5.1 asks the audit programme to consider digital tools together with information security and confidentiality requirements, which makes the tooling for a remote audit part of the programme decision, agreed with the auditee before the opening meeting.
What is a virtual location?
Definition 3.6 now places virtual locations inside the audit scope alongside physical ones. In practice, auditors use the term for places where the auditee performs work or holds information that are not a physical site, such as a cloud platform or an online collaboration workspace. Naming them in the scope tells everyone which online environments the audit team will examine and on what terms.
Expert view: Alexis Hirschhorn, information security and AI governance trainer
In an ISMS audit, the screen share is itself an information flow. The meeting platform, shared evidence, chat, recordings, and auditor access all need an owner, a purpose, agreed retention, and controlled access.
Alexis Hirschhorn leads information security and AI governance training at Abilene Academy, including the lead auditor programmes for ISO/IEC 27001 and ISO/IEC 42001.
If you audit information security or AI management systems remotely, confidentiality becomes part of the subject matter as well as a condition of the method. The ISO 27001 Lead Auditor course and the ISO 42001 Lead Auditor course both work through audit evidence for these systems, and our evidence playbook for ISO 42001 audits goes deeper into what an AI management system audit asks for.
How does ISO 19011:2026 line up with the ISO 9001:2026 transition?
Quality auditors face two revisions in the same year. ISO 19011:2026 updates the guidance on how audits are conducted, and ISO 9001:2026, published on 16 September 2026, updates the requirements those audits check against.
The ISO 9001 dates come from Global ACI: new certifications are issued only to the 2026 edition from 31 March 2028, and the transition deadline is 30 September 2029. ISO 19011:2026 has no equivalent dates, because a guidance standard has no transition period.
Timeline of five milestones. ISO 19011:2018, the third edition, now withdrawn. 27 May 2026: ISO 19011:2026 published as the fourth edition, 46 pages, with no transition period. 16 September 2026: ISO 9001:2026 published. 31 March 2028: new ISO 9001 certifications only to the 2026 edition, according to Global ACI. 30 September 2029: ISO 9001 transition deadline set by Global ACI.
Plan the two together. An internal audit programme updated for ISO 9001:2026 should also reflect the 2026 audit guidance, so that the gap analysis and the audit method move at the same pace. For the full picture on the quality standard, read our complete guide to ISO 9001:2026, and if you need to bring your own competence up to date on the new requirements, the ISO 9001 Transition course is built for that.
Expert view: Géraldine Rayet, lead QHSE trainer
Before anyone updates a checklist, put the audit programme on the table. For every remote or hybrid audit, I want to see why that method was chosen, what cannot be verified adequately on screen, how evidence will be obtained and protected, and what the auditee has agreed about access, recordings, and confidentiality.
Read more about Géraldine Rayet's background and the courses she teaches.
What changes for each audit role?
The revision touches each role differently. The table shows where each one should put its attention first.
What ISO 19011:2026 changes for each role
Role: Internal auditor
Role: Lead auditor
Role: Audit programme manager
Role: Certification body
What should you do now?
If you are an internal auditor, start with definitions 3.4 and 3.6 and with Annex A, and check whether your audit plans name the virtual locations you already audit. If you are new to internal auditing, learn the 2026 edition from the start through our internal auditor certification for management systems. Auditors working on occupational health and safety will find related training and guidance in our ISO 45001 training hub.
If you are a lead auditor, update your audit plan template so that it records the choice of on-site, remote or hybrid methods and the reasons for it, and revise your scope wording to cover virtual locations. The ISO 9001 Lead Auditor certification and the ISO 45001 Lead Auditor certification teach the full audit cycle for quality and for occupational health and safety.
If you manage an audit programme, review it against clause 5.1. List the digital tools your auditors use, agree the information security and confidentiality requirements with auditees, and decide who approves a remote method. Abilene's practitioner view, which goes beyond the standard: if your team uses AI-assisted tools for document review or sampling, treat them as digital tools under clause 5.1 and apply the same confidentiality checks. This is our recommendation and not an ISO requirement. When the programme spans several management systems, keeping evidence, owners and findings in one place makes those method decisions traceable from one audit to the next. Acuna GRC, the GRC platform of our sister company in the Abilene Group, does this in its audit readiness and evidence module, where each piece of evidence is linked to its control and its owner. Programme managers running an integrated quality and environmental system may also want to plan the ISO 14001 transition training in the same cycle.
If you work for a certification body, your requirements still come from ISO/IEC 17021-1. Use the 2026 edition of ISO 19011 as the reference for audit method guidance in auditor briefings and internal training.
Frequently asked questions
The questions below are the ones auditors ask us most often about the 2026 edition. If you audit AI management systems, also read how ISO 19011 shapes AI management system audits.
Take the next step
Whatever your role, the useful move is to bring your audit method and your competence onto the 2026 edition at the same time. Browse our upcoming training sessions or start with the course that matches your role in the list below.




