Remote auditing under ISO 19011:2026: what changes for the auditee
What the 2026 edition changed about remote auditing, and what the auditee decides: method, virtual locations, evidence over a channel, the agreement.
Compliance6 Sept 20269 min read
On this page
What it is
ISO 19011:2026, Guidelines for auditing management systems, is the fourth edition. It cancels the 2018 edition after a technical revision. The Foreword lists two changes: remote-method guidance widened from ISO/IEC TS 17012, and an Annex A extended to remote methods and virtual locations 1.
Clause 3.4 defines a remote auditing method as one running audit activities away from the auditee's location. Remote and on-site methods can combine. Remote methods can also serve a virtual location: an online environment where work is performed or a service delivered, whatever the physical whereabouts 2. A scope description generally names virtual and physical locations alike 3.
The principles do not move: Clauses 5 to 7 still rest on the seven principles numbered 4.2 to 4.8 4. The method moves, and carries three owners. Governance settles that a remote method is acceptable, and signs the agreement. Risk owns the choice, and what a channel exposes. Compliance shows the auditor what still verifies. One loop, not three silos.
Who is affected (decision test)
Five questions; the written answers are the record.
- A certification body, auditing against a management system standard? Then ISO/IEC 17021-1:2015 governs. Clause 9.4.1 admits audit parts done by electronic means, and virtual sites, on two conditions: competent personnel, and evidence sufficient for an informed decision 5.
- The internal audit programme under ISO/IEC 27001:2022 clause 9.2? Then no certification body's requirements apply. Auditor objectivity and impartiality still bind 6.
- A virtual location in scope? Where work is performed online and no premises exist, remote methods can be necessary rather than convenient 7.
- Evidence that exists only inside a console? Location decides the method here: information is available to the audit team wherever it is reached, not where it was created, used or stored 8.
- A supplier audit the organisation runs itself? Then it manages the programme, whose information names the methods to be employed, remote included 9.
| Outcome | What it means | Next step |
|---|---|---|
| Remote method available | Access, competence and evidence sufficiency can be shown | Name the method in the agreement, per activity |
| On-site still needed | The site or observed work carries the evidence | Plan the visit; keep remote for records |
| Needs the body's ruling | A scheme or accreditation condition may bind | Ask in writing before planning |
Choosing the method
The choice is risk-based before it is practical. The team leader plans that way, weighing sampling technique and the risk the audit creates for the auditee 10. Audits may run on site, remotely, or as a mix, and that balance should rest on the associated risks and opportunities 11. Method selection is itself a listed programme risk, judged on whether the method can achieve the audit objective; an unsuitable or unsecured platform is another 12.
Annex A's Table A.1 sorts methods on two axes. One is where the auditor sits: at the auditee's location, or anywhere else. The other is how far the auditee's people are involved — activities that engage them, and activities engaging only equipment, facilities and documentation. Each of the four combinations carries example activities, usable singly or together; a multi-member team can work both ways at once. Feasibility of a remote method turns on the risk to the objectives, the confidence between the parties, and regulatory requirements 13.
On-site remains the answer where evidence is the place. The guidance on visiting assumes access permissions, safety information, and an agreement on mobile devices and cameras covering photographs, screen copies and video 14. Interviews travel better than observation: non-verbal cues are of limited use in virtual settings, so question design carries more weight 15. Governance decides which activities may move, risk prices what is lost, compliance records the answer.
Evidence over a channel
Verification does not relax. Information is collected by appropriate sampling and verified as far as practicable, and only what can be verified to some degree becomes audit evidence 16. Annex A asks whether the information is complete, correct, consistent and current. Then it adds what matters most on a shared screen. Where information arrives in an unexpected manner, from other people or in other media, the integrity of the evidence is assessed 17.
Sampling is where a remote audit quietly changes hands. It exists because examining everything is impractical, and its risk is a sample that does not represent the population 18. On site, an auditor can watch a query run. Over a channel the export is produced by the auditee, so population completeness is an auditee assertion until something independent supports it. Keep the query, the filter and the run time beside the file; logs and monitoring records are the usual support 19.
Confidentiality is the other half. Annex A warns about data outside the audit scope sitting inside the same document, and about disposing of evidence once retention has lapsed 17. Evidence crossing a channel is an information transfer, and remote work is its own control 20. The body carries a matching duty: confidential information handled securely, records transferred so confidentiality holds 21. This adds two columns to the evidence index in Running the external audit.
The audit agreement
| Element | What the 2026 text asks | What the auditee decides | Who owns it |
|---|---|---|---|
| Methods per activity | Programme information names the methods to be employed, remote included 9 | Which activities it hosts remotely | Governance body |
| Locations, physical and virtual | Planning addresses locations, dates and duration 22; the plan names the sites for on-site work and any remote activity 23 | Which locations are virtual, and how each is evidenced | Management system owner |
| Tools and access | Agreed access protocols, devices and software; technical checks beforehand; contingency plans and extra time 7 | The platform, the access route, who provisions it | IT lead |
| Guides and observers | Guides are appointed by the auditee; observer access and confidentiality are settled between audit client and auditee 24 | Who guides each session, who observes | Management system owner |
| Recording and retention | Permission is asked in advance for screen copies or recordings, and audit information holding images and recordings is safeguarded 25 | Whether sessions may be recorded, and for how long | Compliance lead |
Dates (verified)
17021-1 sets conditions for audit parts run by electronic means; it obliges no body to offer them 5.
Mapping
| Activity | ISO 19011:2026 | ISO/IEC 17021-1:2015 | ISO/IEC 27001 or 27002:2022 | Gap |
|---|---|---|---|---|
| Deciding the method | 5.5.3; 5.3 | 9.1.4, audit time, counting sites and geography | Clause 9.2 | Decision has no named owner |
| Naming locations | 6.3.2.2 | 9.2.3.2 | Clause 9.2 | Virtual locations missing from the scope |
| Access to information | 6.4.5 | 9.4.1 | 7.5.3 | Nobody can produce the record live |
| Verifying what arrives | A.5; 6.4.7 | 9.4.4 | 8.15 Logging | Unexpected medium, integrity unchecked |
| Sampling from an export | A.6 | 9.4.4 | 8.16 Monitoring activities | Population completeness unevidenced |
| Protecting the channel | A.16; A.5 | 8.4.7; 9.9.3 | 5.14 Information transfer; 6.7 Remote working | Screen sharing outside the transfer rule |
Clause numbers are as printed 29. The other two sources likewise 30 31.
Next 90 days
| Week | Action | Owner | Output |
|---|---|---|---|
| 1 | List every location in scope; mark the virtual ones | Management system owner | Location register |
| 1-2 | Name who may accept a remote method, for which audits | Governance body | Decision-rights entry |
| 2-3 | Add the holding system and the exporting role to each evidence row | Evidence index owner | Two new index columns |
| 3-4 | Assess remote-evidence risk: authenticity, screen confidentiality, export completeness | Risk owner | Risk entries with treatments |
| 4-5 | Put the method question into the agreement checklist, per activity | Compliance lead | Revised checklist |
| 5-6 | Agree platform, access and contingency; run a technical check | IT lead | Technical check record |
| 6-8 | Set the rule for screen copies and recordings, with disposal | Compliance lead | Recording rule |
| 8-10 | Brief guides for remote sessions, one per auditor | Management system owner | Guide roster |
| 10-12 | Run one internal audit session remotely; log what could not be verified | Internal audit lead | Rehearsal note; gap list |
Related
- Running the external audit — the audit run, and the evidence index.
- Control testing and ITGC — populations, samples, workpapers.
- Building an ISMS people actually use — where the records come from.
References
- ISO. Guidelines for auditing management systems. ISO 19011:2026, fourth edition, 2026-05, ISO/PC 302. https://www.iso.org/standard/19011 1
- ISO and IEC. Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements. ISO/IEC 17021-1:2015. https://www.iso.org/standard/61651.html 5
- ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 6
- ISO/IEC. Information security, cybersecurity and privacy protection — Information security controls. ISO/IEC 27002:2022. https://www.iso.org/standard/75652.html 20
- ISO/IEC TS 17012:2024 — named in the 2026 edition as the source of its remote-method guidance; not read here 32
Sources
- 1ISO 19011:2026 Foreword and title page, licensed copy · verified 2026-09-06
- 2ISO 19011:2026 clause 3.4, licensed copy · verified 2026-09-06
- 3ISO 19011:2026 clause 3.6, licensed copy · verified 2026-09-06
- 4ISO 19011:2026 clause 4.1, licensed copy · verified 2026-09-06
- 5ISO/IEC 17021-1:2015 clause 9.4.1, licensed copy · verified 2026-09-06
- 6ISO/IEC 27001:2022 clause 9.2, iso.org/obp · verified 2026-09-03
- 7ISO 19011:2026 clause A.16, licensed copy · verified 2026-09-06
- 8ISO 19011:2026 clause 6.4.5, licensed copy · verified 2026-09-06
- 9ISO 19011:2026 clause 5.1, licensed copy · verified 2026-09-06
- 10ISO 19011:2026 clause 6.3.2.1, licensed copy · verified 2026-09-06
- 11ISO 19011:2026 clause 5.5.3, licensed copy · verified 2026-09-06
- 12ISO 19011:2026 clause 5.3, licensed copy · verified 2026-09-06
- 13ISO 19011:2026 clause A.1, licensed copy · verified 2026-09-06
- 14ISO 19011:2026 clause A.15, licensed copy · verified 2026-09-06
- 15ISO 19011:2026 clause A.17, licensed copy · verified 2026-09-06
- 16ISO 19011:2026 clause 6.4.7, licensed copy · verified 2026-09-06
- 17ISO 19011:2026 clause A.5, licensed copy · verified 2026-09-06
- 18ISO 19011:2026 clause A.6, licensed copy · verified 2026-09-06
- 19ISO/IEC 27002:2022 controls 8.15 Logging and 8.16 Monitoring activities, licensed copy · verified 2026-09-06
- 20ISO/IEC 27002:2022 controls 5.14 Information transfer and 6.7 Remote working, licensed copy · verified 2026-09-06
- 21ISO/IEC 17021-1:2015 clauses 8.4.7 and 9.9.3, licensed copy · verified 2026-09-06
- 22ISO 19011:2026 clause 6.3.2.2, licensed copy · verified 2026-09-06
- 23ISO/IEC 17021-1:2015 clause 9.2.3.2, licensed copy · verified 2026-09-06
- 24ISO 19011:2026 clause 6.4.2, licensed copy · verified 2026-09-06
- 25ISO 19011:2026 clauses A.16 and 6.3.4, licensed copy · verified 2026-09-06
- 26iso.org catalogue, ISO 19011:2026 page, live browser session · verified 2026-09-06
- 27iso.org catalogue, ISO 19011:2018 page, live browser session · verified 2026-09-06
- 28ISO 19011:2026 Introduction, licensed copy · verified 2026-09-06
- 29ISO 19011:2026 Annex A and clauses 5 to 6, licensed copy · verified 2026-09-06
- 30ISO/IEC 17021-1:2015 clauses 8.4, 9.1, 9.2, 9.4 and 9.9, licensed copy · verified 2026-09-06
- 31ISO/IEC 27001:2022 clauses 9.2 and 7.5.3, iso.org/obp · verified 2026-09-03
- 32ISO 19011:2026 Introduction, clause A.16 and Bibliography, licensed copy · verified 2026-09-06