ISO 19011:2026 Training
Notes from my auditing training
The three kinds of audit:
- First-party audits: internal audits, done by or on behalf of the organization itself.
- Second-party audits: conducted by someone with a direct interest in the organization, most commonly a customer auditing a supplier.
- Third-party audits: conducted by an independent outside body, such as a certification organization or a government agency.
The key principles that ISO 19011 is built on:
- Integrity: taking tasks based on competence, and staying impartial.
- Fair presentation: reporting holistically, including unresolved disagreements.
- Due professional care: applying diligence and sound judgment consistently.
- Confidentiality: protecting information gathered during the audit.
- Independence: staying free of bias and conflicts of interest.
- Evidence-based approach: conclusions come from verifiable evidence.
- Risk-based approach: let risk and significance shape where the attention goes.
Audit evidence has to be verifiable. The standard draws a careful line between objective evidence (data supporting that something is true) and the narrower audit evidence (the subset that’s both relevant to the audit criteria and verifiable).
Sampling is inherent. Because audits happen in finite time with finite resources, they almost always rely on examining a sample rather than everything. The standard is explicit that this introduces real uncertainty, and it distinguishes between judgment-based sampling and statistical sampling.
Remote and virtual audits are fully legitimate, with conditions. The standard treats remote methods as usable on their own or combined with on-site work, provided the associated risks and opportunities have been properly weighed.
The auditor still owns the judgment, even with new tools. The standard notes that auditors should understand the implications of using information technology and emerging tools (including AI-based evaluation tools) in their work. But using such a tool doesn’t relieve the auditor of the responsibility to judge whether the resulting findings are actually reliable and sufficient.
Verification: does the design input = design output? Validation: does the design work in the intended application?

(Yes the image is based on ISO 19011:2018, let’s move on)