The world of auditing is always evolving – driven by remote work, technological advancements, and the increasing integration of multiple management systems. Auditors today are expected to navigate virtual environments, assess complex supply chains, and evaluate performance across disciplines such as quality, safety, environmental, and information security – often all at once.
A cornerstone of auditing practice is ISO 19011, the international standard that provides guidance on auditing management systems. A new revision – ISO 19011:2026 – is currently in draft form and slated for release later this year. This updated version will replace ISO 19011:2018 and is expected to offer updated guidance to support more flexible, efficient, and future-focused auditing practices.
In this article, we explore the most significant changes in the forthcoming ISO 19011:2026, why they matter, and what organisations and auditors can do to prepare.
What is ISO 19011?
ISO 19011 provides guidelines for auditing management systems, including principles of auditing, managing audit programs, and conducting first-, second-, and third-party audits. It is a vital resource for auditors and organisations alike, whether audits are being performed for compliance, certification readiness, or performance improvement.
Why a revision now?
Since the publication of ISO 19011:2018, there has been a significant rise in the use of remote auditing methods, driven not only by technology but also by necessity during global disruptions such as the COVID-19 pandemic. The revised standard reflects these changes and offers structured guidance on modern auditing practices that better align with how organisations operate today.
Key changes in ISO 19011:2026
-
Expanded guidance on remote auditing
One of the most notable updates is expected to be the inclusion of expanded guidance on remote auditing methods. This change will reflect the content of the recently published ISO/IEC TS 17012:2024, which offers technical guidance for conducting remote audits effectively.
The revised standard will recognise that remote audits are no longer a fallback but a legitimate and often preferred method. It should address how to determine audit feasibility, select appropriate technology, and mitigate potential risks related to remote access, data security, and communication challenges.
“The expansion of guidance on remote auditing methods through the introduction of guidance contained in ISO/IEC TS 17012… marks a significant shift in recognising remote audits as part of mainstream auditing practice.”
– ISO/DIS 19011(en), Guidelines for auditing management systems
-
Annex A expanded: Remote auditing & virtual locations
Annex A of the standard, which provides supplementary guidance on auditing techniques, is likely to be expanded to include advice on virtual locations. This addition will be crucial for organisations operating with hybrid teams, cloud-based infrastructure, and global supply chains.
It will provide practical examples of remote audit activities and clarify how auditors should approach evidence collection and site observation when physical access isn’t possible.
-
Combined and integrated auditing approaches
ISO 19011:2026 is expected to embrace the combined audit approach, encouraging the simultaneous auditing of two or more management systems across disciplines – for example, Quality (ISO 9001), Environmental (ISO 14001), and Occupational Health and Safety (ISO 45001).
This change acknowledges the growing trend toward integrated management systems (IMS), where principles and processes are shared across standards. The new guidance supports efficiency, consistency, and value-driven audits.
“When these systems are integrated into a single management system, the principles and processes of auditing remain the same as those for a combined audit.”
– ISO/DIS 19011(en), Guidelines for auditing management systems
-
Broad applicability and relevance
The standard will remain a flexible and valuable resource for a wide range of users including internal auditors, compliance officers, and organisations that conduct audits on external providers for contractual or regulatory purposes. The revised content will reinforce the need for auditors to be adaptable, tech-savvy, and system-aware.
What this means for your organisation
Organisations that already conduct internal or supplier audits should take this upcoming revision as a signal to:
- Review their audit programs and procedures to accommodate remote methods and integrated approaches.
- Invest in auditor training that includes digital literacy and cross-standard understanding.
- Assess their readiness to manage evidence, communication, and compliance in hybrid work environments.
How training and standards-based learning can help
As auditing requirements evolve, so must auditor skill sets. Risk Training Professionals can support your teams with:
- Integrated Management Systems Lead Auditor training (covering ISO 9001, 14001, 45001)
- Audit planning techniques
- eLearn modules on Audit Interview Skills and Report Writing Fundamentals
Preparing for ISO 19011:2026 now ensures you’re not just compliant but also leading with confidence.
Find out more about our Lead Auditor courses
Conclusion
The forthcoming ISO 19011:2026 will reflect a more dynamic, digital, and integrated auditing environment. Whether you’re an internal auditor, a quality manager, or overseeing a multi-standard management system, this update will bring challenges and opportunities to improve the way you assess and assure performance.
To stay ahead, begin aligning your practices and training with the revised guidance and don’t wait until the official release to start adapting.
Further reading
Get some tips on how to write a clear, concise, and impactful audit report
Find out how to harness the Hawthorne Effect in management systems auditing
Learn all about the ISO Harmonised Structure

