ISO 19011:2026: What Changed for Auditors, and What Did Not
audit-certification
regulatory-updates

ISO 19011:2026: What Changed for Auditors, and What Did Not

ISO 19011:2026 was published on 27 May 2026 with expanded guidance on remote auditing. What changed, what did not, and what internal auditors, lead auditors and programme managers should do.

Géraldine RAYET
Géraldine RAYET
9 min read

If you plan, run or manage management system audits, ISO 19011:2026 is the edition you now work from. ISO published this fourth edition on 27 May 2026, and it replaces ISO 19011:2018, which is withdrawn. The revision is focused: the official Foreword lists two main changes, and both concern remote auditing.

That focus matters, because several summaries in circulation describe the 2026 edition as far broader than it is. This article sticks to what the published text says, keeps it apart from Abilene's own practitioner advice, and shows what each audit role should do with it. If you want a refresher on what the guideline covers in general, start with what ISO 19011 covers for internal audits. Here we deal only with what is new.

What are the key facts about ISO 19011:2026?

ISO 19011:2026 key facts at a glance

Topic: Edition

ISO 19011:2026Fourth edition, 46 pages

Topic: Publication date

ISO 19011:202627 May 2026

Topic: Replaces

ISO 19011:2026ISO 19011:2018, the third edition, which is withdrawn

Topic: Scope

ISO 19011:2026Principles of auditing, managing an audit programme, conducting audits, and evaluating the competence of the people involved

Topic: Audit types

ISO 19011:2026First-party, second-party and third-party audits

Topic: Development

ISO 19011:2026Project approved February 2024, DIS ballot in 2025, final draft approved April 2026

Topic: Languages from ISO

ISO 19011:2026English, French and Spanish, with an optional redline version

Topic: What changed

ISO 19011:2026Expanded guidance on remote auditing methods, drawing on ISO/IEC TS 17012, and an expanded Annex A covering remote auditing methods and virtual locations

Topic: What did not change

ISO 19011:2026The auditing principles, including the risk-based approach in clause 4.8, and the status of the document as guidance

Topic: Transition period

ISO 19011:2026None, because organizations cannot be certified to ISO 19011

Topic: Auditor certificates

ISO 19011:2026Existing certificates remain valid

Topic: Who is affected

ISO 19011:2026Internal auditors, lead auditors, audit programme managers and certification body auditors who use the guideline

What changed in ISO 19011:2026?

The Foreword of the 2026 edition names two main changes. The first is expanded guidance on remote auditing methods, which draws on ISO/IEC TS 17012. The second is an expanded Annex A that covers remote auditing methods and virtual locations. Everything else in the revision should be read in the light of those two changes.

New definition 3.4: remote auditing method

A method used for conducting audit activities from any place other than the location of the auditee.

Two further changes in the text follow the same theme. Definition 3.6, audit scope, now includes physical and virtual locations, which gives you a defined place to name the online environments you audit alongside the sites. Clause 5.1 asks the audit programme to consider the application of technology such as digital tools, together with information security and confidentiality requirements.

Read together, these changes treat remote auditing as an ordinary audit method that has to be planned, justified and protected. For most audit teams the practical work sits in three places: the scope statement, the audit plan template and the programme's rules for choosing and securing tools.

The scope statement moved as well. The 2018 abstract described the guideline as applicable to organizations that plan and conduct internal or external audits. The 2026 abstract simply refers to audits, and adds that using it for other types of audit needs special attention to both the competence required and the objectives to be achieved. ISO itself presents the guideline as relevant to first-party, second-party and third-party auditors alike.

If you want to check every textual change yourself, ISO offers the 2026 edition in English, French and Spanish, with an optional redline version that marks the changes, from its official catalogue page for ISO 19011:2026. In our experience, a lead auditor who reads the redline against their own audit procedure learns more in an afternoon than from any summary, this one included.

ISO 19011:2018 compared with ISO 19011:2026

Area: Status

ISO 19011:2018Third edition, now withdrawn
ISO 19011:2026Fourth edition, published 27 May 2026
What it means for youUpdate references in your audit procedures and programme

Area: Scope wording

ISO 19011:2018For organizations that plan and conduct internal or external audits
ISO 19011:2026For organizations that plan and conduct audits; use for other audit types needs attention to competence and to the objectives
What it means for youCheck that the scope statement of your audit procedure still matches

Area: Remote auditing guidance

ISO 19011:2018Earlier guidance, superseded by the 2026 text
ISO 19011:2026Expanded guidance on remote auditing methods, drawing on ISO/IEC TS 17012
What it means for youReview how you choose and plan remote methods

Area: Annex A

ISO 19011:2018Earlier annex, superseded
ISO 19011:2026Expanded to cover remote auditing methods and virtual locations
What it means for youUse it when you plan remote and hybrid audits

Area: Remote auditing method

ISO 19011:2018No definition 3.4 for this term
ISO 19011:2026New definition 3.4: audit activities conducted from any place other than the auditee's location
What it means for youUse the defined term in plans and reports

Area: Audit scope (3.6)

ISO 19011:2018Did not include this wording
ISO 19011:2026Includes physical and virtual locations
What it means for youName virtual locations in the scope

Area: Audit programme (5.1)

ISO 19011:2018Earlier wording, superseded
ISO 19011:2026Considers technology such as digital tools, and information security and confidentiality requirements
What it means for youAssess tools and confidentiality when you build the programme

Area: Risk-based approach (4.8)

ISO 19011:2018Already an auditing principle
ISO 19011:2026Still one of seven principles, with the same status
What it means for youNo new principle to adopt

Area: Certification

ISO 19011:2018Guidance only, no certification
ISO 19011:2026Guidance only, no certification
What it means for youNo transition period

What did not change in ISO 19011:2026?

The seven auditing principles remain the foundation of the guideline. The risk-based approach in clause 4.8 is one of them, and it was already a principle in the 2018 edition. If a briefing presents risk-based auditing as the headline of the 2026 revision, it has the history wrong.

The status of the document has not changed either. ISO 19011 is a guidance standard, which is why organizations cannot be certified to it and why the new edition comes without a transition period.

Check the claims you read

The Foreword lists two main changes, both about remote auditing. Treat any summary that presents ISO 19011:2026 as an AI auditing standard, a new competence regime for auditors or a new risk principle with caution, and check it against the published text. Where this article mentions AI tools in audits, it gives Abilene's practitioner view, which is not an ISO requirement.

Is there a transition period, and is my lead auditor certificate still valid?

There is no transition period. ISO 19011 gives guidance on auditing and organizations cannot be certified to it, so there is no certificate that has to move from one edition to the next in the way a certified management system does.

Existing auditor certificates remain valid. What changes is the reference point your next audit plan should use, especially if you audit remotely or across sites and online environments.

Whether you need retraining depends on how you audit. Auditors who regularly run remote or hybrid audits should work through the expanded guidance and Annex A, and new auditors are better served by learning the 2026 edition from the start. Our Certified Management Systems Internal Auditor training covers internal audit competence under ISO 19011 and suits both situations.

Expert view: Géraldine Rayet, lead QHSE trainer

Your certificate did not expire on 27 May. What changed is what a credible audit plan looks like when part of the work is remote: the method, its limitations, the evidence obtained, and the confidentiality arrangements need to be visible.

Géraldine Rayet is the lead QHSE trainer at Abilene Academy and teaches our auditor courses for quality, environment, and health and safety.

How does ISO 19011 differ from ISO/IEC 17021-1?

The two documents answer different questions. ISO/IEC 17021-1 sets requirements for certification bodies, the organizations that audit and certify management systems. ISO 19011 is guidance for auditing, written for anyone who plans, manages or conducts management system audits.

A certification body auditor works within the requirements of ISO/IEC 17021-1 and can draw on ISO 19011 for how to conduct the audit itself. For a worked example of how the two fit together with a management system standard, see how ISO 22301, ISO 19011 and ISO/IEC 17021-1 relate in an audit.

When should an audit be on-site, remote or hybrid?

The 2026 edition gives remote methods a defined place in the guideline, so the choice of method deserves to be a recorded decision rather than a habit. The visual below is Abilene's practitioner way of structuring that decision. It builds on the remote auditing guidance and clause 5.1, and it does not reproduce the text of the standard.

Widget

Decision visual in three steps. Step 1: can the evidence be observed and verified reliably from another place? If not, audit those activities on site. Step 2: do the remote tools meet the information security and confidentiality requirements agreed for the audit? If not, secure the tools first or audit on site. Step 3: does the audit scope combine physical and virtual locations? If yes, run a hybrid audit; if every activity can be audited from another place, run a remote audit. Abilene practitioner view built on the remote auditing guidance of ISO 19011:2026, including definition 3.4, definition 3.6 and clause 5.1.

In our experience the middle question is the one teams skip. Clause 5.1 asks the audit programme to consider digital tools together with information security and confidentiality requirements, which makes the tooling for a remote audit part of the programme decision, agreed with the auditee before the opening meeting.

What is a virtual location?

Definition 3.6 now places virtual locations inside the audit scope alongside physical ones. In practice, auditors use the term for places where the auditee performs work or holds information that are not a physical site, such as a cloud platform or an online collaboration workspace. Naming them in the scope tells everyone which online environments the audit team will examine and on what terms.

Expert view: Alexis Hirschhorn, information security and AI governance trainer

In an ISMS audit, the screen share is itself an information flow. The meeting platform, shared evidence, chat, recordings, and auditor access all need an owner, a purpose, agreed retention, and controlled access.

Alexis Hirschhorn leads information security and AI governance training at Abilene Academy, including the lead auditor programmes for ISO/IEC 27001 and ISO/IEC 42001.

If you audit information security or AI management systems remotely, confidentiality becomes part of the subject matter as well as a condition of the method. The ISO 27001 Lead Auditor course and the ISO 42001 Lead Auditor course both work through audit evidence for these systems, and our evidence playbook for ISO 42001 audits goes deeper into what an AI management system audit asks for.

How does ISO 19011:2026 line up with the ISO 9001:2026 transition?

Quality auditors face two revisions in the same year. ISO 19011:2026 updates the guidance on how audits are conducted, and ISO 9001:2026, published on 16 September 2026, updates the requirements those audits check against.

The ISO 9001 dates come from Global ACI: new certifications are issued only to the 2026 edition from 31 March 2028, and the transition deadline is 30 September 2029. ISO 19011:2026 has no equivalent dates, because a guidance standard has no transition period.

Widget

Timeline of five milestones. ISO 19011:2018, the third edition, now withdrawn. 27 May 2026: ISO 19011:2026 published as the fourth edition, 46 pages, with no transition period. 16 September 2026: ISO 9001:2026 published. 31 March 2028: new ISO 9001 certifications only to the 2026 edition, according to Global ACI. 30 September 2029: ISO 9001 transition deadline set by Global ACI.

Plan the two together. An internal audit programme updated for ISO 9001:2026 should also reflect the 2026 audit guidance, so that the gap analysis and the audit method move at the same pace. For the full picture on the quality standard, read our complete guide to ISO 9001:2026, and if you need to bring your own competence up to date on the new requirements, the ISO 9001 Transition course is built for that.

Expert view: Géraldine Rayet, lead QHSE trainer

Before anyone updates a checklist, put the audit programme on the table. For every remote or hybrid audit, I want to see why that method was chosen, what cannot be verified adequately on screen, how evidence will be obtained and protected, and what the auditee has agreed about access, recordings, and confidentiality.

Read more about Géraldine Rayet's background and the courses she teaches.

What changes for each audit role?

The revision touches each role differently. The table shows where each one should put its attention first.

What ISO 19011:2026 changes for each role

Role: Internal auditor

What changesRemote methods now have a definition and expanded guidance, and scopes can name virtual locations
What stays the sameThe auditing principles and your existing certificate
Where to startReread Annex A before your next remote or hybrid audit

Role: Lead auditor

What changesRemote and hybrid audit plans should reflect the expanded guidance and the new scope definition
What stays the sameThe auditing principles and your existing certificate
Where to startUpdate your audit plan template and scope wording

Role: Audit programme manager

What changesClause 5.1 asks the programme to consider digital tools and information security and confidentiality requirements
What stays the sameThe seven principles, including the risk-based approach
Where to startDocument how the programme chooses audit methods and secures tools

Role: Certification body

What changesISO 19011:2026 is the current audit guidance to draw on
What stays the sameRequirements still come from ISO/IEC 17021-1
Where to startAlign auditor briefings and internal training with the 2026 edition

What should you do now?

If you are an internal auditor, start with definitions 3.4 and 3.6 and with Annex A, and check whether your audit plans name the virtual locations you already audit. If you are new to internal auditing, learn the 2026 edition from the start through our internal auditor certification for management systems. Auditors working on occupational health and safety will find related training and guidance in our ISO 45001 training hub.

If you are a lead auditor, update your audit plan template so that it records the choice of on-site, remote or hybrid methods and the reasons for it, and revise your scope wording to cover virtual locations. The ISO 9001 Lead Auditor certification and the ISO 45001 Lead Auditor certification teach the full audit cycle for quality and for occupational health and safety.

If you manage an audit programme, review it against clause 5.1. List the digital tools your auditors use, agree the information security and confidentiality requirements with auditees, and decide who approves a remote method. Abilene's practitioner view, which goes beyond the standard: if your team uses AI-assisted tools for document review or sampling, treat them as digital tools under clause 5.1 and apply the same confidentiality checks. This is our recommendation and not an ISO requirement. When the programme spans several management systems, keeping evidence, owners and findings in one place makes those method decisions traceable from one audit to the next. Acuna GRC, the GRC platform of our sister company in the Abilene Group, does this in its audit readiness and evidence module, where each piece of evidence is linked to its control and its owner. Programme managers running an integrated quality and environmental system may also want to plan the ISO 14001 transition training in the same cycle.

If you work for a certification body, your requirements still come from ISO/IEC 17021-1. Use the 2026 edition of ISO 19011 as the reference for audit method guidance in auditor briefings and internal training.

Frequently asked questions

The questions below are the ones auditors ask us most often about the 2026 edition. If you audit AI management systems, also read how ISO 19011 shapes AI management system audits.

Take the next step

Whatever your role, the useful move is to bring your audit method and your competence onto the 2026 edition at the same time. Browse our upcoming training sessions or start with the course that matches your role in the list below.

Frequently Asked Questions

ISO 19011:2026, the fourth edition, was published on 27 May 2026 and replaces ISO 19011:2018. Its Foreword lists two main changes: expanded guidance on remote auditing methods, drawing on ISO/IEC TS 17012, and an expanded Annex A covering remote auditing methods and virtual locations. It also adds definition 3.4, remote auditing method.

No. ISO 19011 is a guidance standard, so organizations cannot be certified to it and there is no transition period. ISO 19011:2026 replaces the 2018 edition, which is withdrawn. Audit procedures and programmes that cite the 2018 edition should be updated to reference the 2026 text.

Yes. Existing auditor certificates remain valid, and there is no transition period because ISO 19011 is a guidance standard. What changes is the guidance you work from, especially for remote and hybrid audits, so lead auditors should review the expanded remote auditing guidance and Annex A before planning their next audit.

Retraining is not mandatory, because existing auditor certificates remain valid and there is no transition period. Auditors who run remote or hybrid audits should study the expanded remote auditing guidance and Annex A. New auditors are best served by training that teaches the 2026 edition from the start.

Treat the method as a recorded decision. ISO 19011:2026 defines a remote auditing method as conducting audit activities from any place other than the auditee's location, and clause 5.1 asks the programme to consider digital tools and information security and confidentiality requirements. Confirm the evidence can be verified remotely, secure the tools, and name virtual locations in the scope.

In ISO 19011:2026, the definition of audit scope (3.6) includes physical and virtual locations. In practice, auditors use virtual location for an online environment where the auditee performs work or holds information, such as a cloud platform or a collaboration workspace. Naming virtual locations in the scope makes clear which online environments the audit will examine.

ISO/IEC 17021-1 sets requirements for certification bodies that audit and certify management systems. ISO 19011 is guidance for auditing management systems, and organizations cannot be certified to it. A certification body auditor works within ISO/IEC 17021-1 requirements and can draw on ISO 19011 for guidance on how to conduct audits.

No. ISO 19011 is a guidance standard for auditing management systems, so organizations cannot be certified to it. Organizations use it to organize audit programmes and individual audits, and auditors use it to guide how they conduct audits. Certification bodies work to the requirements of ISO/IEC 17021-1 instead.

ISO/IEC TS 17012 is the technical specification that ISO 19011:2026 draws on for its expanded guidance on remote auditing methods. For auditors, the practical point is that the remote auditing guidance and the expanded Annex A of ISO 19011:2026, which covers remote auditing methods and virtual locations, build on it.

Related Training

Courses referenced in this article

Certified MS Internal Auditor

This three-day course teaches you how to conduct and manage management system internal audits in line with ISO 19011 guidance and related best practices. You learn internal audit concepts, auditor competence and behavior, and common requirements across management system standards.

View Course

ISO 9001 Lead Auditor

This ISO 9001 Lead Auditor course is designed for professionals who must conduct audits that withstand certification scrutiny and deliver operational value. In a context where quality audits are increasingly challenged for being procedural rather than insightful, this training focuses on evidence-.

View Course

ISO 27001 Lead Auditor

This ISO/IEC 27001 Lead Auditor training prepares experienced professionals to conduct and lead ISMS audits that stand up to regulatory, contractual, and certification scrutiny. The course focuses on audit execution, evidence evaluation, and decision-making under real-world constraints.

View Course

ISO 42001 Lead Auditor

This ISO/IEC 42001 Lead Auditor training prepares audit, risk, and compliance professionals to assess Artificial Intelligence Management Systems (AIMS) in a structured, defensible way. The course focuses on planning, conducting, and closing ISO/IEC 42001 audits in real organizational environments, addressing governance, ethical use of AI, risk management, and regulatory expectations shaping 2024–2025. Participants learn to interpret ISO/IEC 42001 requirements from an auditor’s perspective, evaluate objective evidence, and formulate audit conclusions that stand up to certification scrutiny and executive review.

View Course

ISO 45001 Lead Auditor

ISO 45001 Lead Auditor is a four-day course to build the competence to plan, conduct, and close Occupational Health and Safety Management System (OH&S MS) audits based on ISO 45001:2018.

View Course

ISO 9001 Transition

This course prepares participants to identify every change between ISO 9001:2015 and ISO 9001:2026 and to update an existing quality management system so it conforms to the revised edition. The 2026 revision keeps the process approach and PDCA structure but adds explicit requirements on quality culture, ethical behavior, change planning, and the separate treatment of risks and opportunities. Most certified organizations need a gap analysis and a documented update plan before their next surveillance or recertification audit. Abilene Academy trainers are active QMS consultants and auditors who run clause-by-clause comparisons against real management system documentation. The course suits quality managers, internal auditors, and consultants maintaining ISO 9001 certificates.

View Course

ISO 14001 Transition

This course prepares EMS managers, auditors, and consultants to identify, plan, and implement every requirement change introduced in ISO 14001:2026. ISO 14001 had not been revised for over a decade, and the 2026 edition raises expectations across clause 4 context analysis, clause 6.3 planning of changes, and life cycle thinking in environmental aspects identification. Abilene's trainers are active EMS consultants who work through clause-by-clause comparison exercises drawn from live implementation projects, not hypothetical scenarios. The course targets professionals responsible for maintaining or upgrading a certified EMS before surveillance or recertification audits require conformity to the 2026 edition.

View Course

Related Questions

Expert answers referenced in this article

Get Certified

ISO 27001, NIS2, AI governance & more. Join 2,500+ professionals.

View Courses
Ask our AI Assistant

Related Articles

Continue exploring topics that matter to your organization

We use cookies to improve your experience

Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.