Back to briefings
    Briefing

    Remote auditing under ISO 19011:2026: what changes for the auditee

    What the 2026 edition changed about remote auditing, and what the auditee decides: method, virtual locations, evidence over a channel, the agreement.

    Compliance6 Sept 20269 min read

    ISO 19011:2026ISO/IEC 17021-1:2015ISO/IEC 27001:2022ISO/IEC 27002:2022ISO/IEC TS 17012:2024
    On this page

    What it is

    ISO 19011:2026, Guidelines for auditing management systems, is the fourth edition. It cancels the 2018 edition after a technical revision. The Foreword lists two changes: remote-method guidance widened from ISO/IEC TS 17012, and an Annex A extended to remote methods and virtual locations 1.

    Clause 3.4 defines a remote auditing method as one running audit activities away from the auditee's location. Remote and on-site methods can combine. Remote methods can also serve a virtual location: an online environment where work is performed or a service delivered, whatever the physical whereabouts 2. A scope description generally names virtual and physical locations alike 3.

    The principles do not move: Clauses 5 to 7 still rest on the seven principles numbered 4.2 to 4.8 4. The method moves, and carries three owners. Governance settles that a remote method is acceptable, and signs the agreement. Risk owns the choice, and what a channel exposes. Compliance shows the auditor what still verifies. One loop, not three silos.

    Who is affected (decision test)

    Five questions; the written answers are the record.

    1. A certification body, auditing against a management system standard? Then ISO/IEC 17021-1:2015 governs. Clause 9.4.1 admits audit parts done by electronic means, and virtual sites, on two conditions: competent personnel, and evidence sufficient for an informed decision 5.
    2. The internal audit programme under ISO/IEC 27001:2022 clause 9.2? Then no certification body's requirements apply. Auditor objectivity and impartiality still bind 6.
    3. A virtual location in scope? Where work is performed online and no premises exist, remote methods can be necessary rather than convenient 7.
    4. Evidence that exists only inside a console? Location decides the method here: information is available to the audit team wherever it is reached, not where it was created, used or stored 8.
    5. A supplier audit the organisation runs itself? Then it manages the programme, whose information names the methods to be employed, remote included 9.
    OutcomeWhat it meansNext step
    Remote method availableAccess, competence and evidence sufficiency can be shownName the method in the agreement, per activity
    On-site still neededThe site or observed work carries the evidencePlan the visit; keep remote for records
    Needs the body's rulingA scheme or accreditation condition may bindAsk in writing before planning

    Choosing the method

    The choice is risk-based before it is practical. The team leader plans that way, weighing sampling technique and the risk the audit creates for the auditee 10. Audits may run on site, remotely, or as a mix, and that balance should rest on the associated risks and opportunities 11. Method selection is itself a listed programme risk, judged on whether the method can achieve the audit objective; an unsuitable or unsecured platform is another 12.

    Annex A's Table A.1 sorts methods on two axes. One is where the auditor sits: at the auditee's location, or anywhere else. The other is how far the auditee's people are involved — activities that engage them, and activities engaging only equipment, facilities and documentation. Each of the four combinations carries example activities, usable singly or together; a multi-member team can work both ways at once. Feasibility of a remote method turns on the risk to the objectives, the confidence between the parties, and regulatory requirements 13.

    On-site remains the answer where evidence is the place. The guidance on visiting assumes access permissions, safety information, and an agreement on mobile devices and cameras covering photographs, screen copies and video 14. Interviews travel better than observation: non-verbal cues are of limited use in virtual settings, so question design carries more weight 15. Governance decides which activities may move, risk prices what is lost, compliance records the answer.

    Evidence over a channel

    Verification does not relax. Information is collected by appropriate sampling and verified as far as practicable, and only what can be verified to some degree becomes audit evidence 16. Annex A asks whether the information is complete, correct, consistent and current. Then it adds what matters most on a shared screen. Where information arrives in an unexpected manner, from other people or in other media, the integrity of the evidence is assessed 17.

    Sampling is where a remote audit quietly changes hands. It exists because examining everything is impractical, and its risk is a sample that does not represent the population 18. On site, an auditor can watch a query run. Over a channel the export is produced by the auditee, so population completeness is an auditee assertion until something independent supports it. Keep the query, the filter and the run time beside the file; logs and monitoring records are the usual support 19.

    Confidentiality is the other half. Annex A warns about data outside the audit scope sitting inside the same document, and about disposing of evidence once retention has lapsed 17. Evidence crossing a channel is an information transfer, and remote work is its own control 20. The body carries a matching duty: confidential information handled securely, records transferred so confidentiality holds 21. This adds two columns to the evidence index in Running the external audit.

    The audit agreement

    ElementWhat the 2026 text asksWhat the auditee decidesWho owns it
    Methods per activityProgramme information names the methods to be employed, remote included 9Which activities it hosts remotelyGovernance body
    Locations, physical and virtualPlanning addresses locations, dates and duration 22; the plan names the sites for on-site work and any remote activity 23Which locations are virtual, and how each is evidencedManagement system owner
    Tools and accessAgreed access protocols, devices and software; technical checks beforehand; contingency plans and extra time 7The platform, the access route, who provisions itIT lead
    Guides and observersGuides are appointed by the auditee; observer access and confidentiality are settled between audit client and auditee 24Who guides each session, who observesManagement system owner
    Recording and retentionPermission is asked in advance for screen copies or recordings, and audit information holding images and recordings is safeguarded 25Whether sessions may be recorded, and for how longCompliance lead

    Dates (verified)

    DateWhat happensSource
    2026-05ISO 19011:2026 published as the fourth edition, 46 pages26
    2026-05ISO 19011:2018 withdrawn, replaced by the fourth edition27
    NoneNo obligation date: this is guidance, not a requirements standard28

    17021-1 sets conditions for audit parts run by electronic means; it obliges no body to offer them 5.

    Mapping

    ActivityISO 19011:2026ISO/IEC 17021-1:2015ISO/IEC 27001 or 27002:2022Gap
    Deciding the method5.5.3; 5.39.1.4, audit time, counting sites and geographyClause 9.2Decision has no named owner
    Naming locations6.3.2.29.2.3.2Clause 9.2Virtual locations missing from the scope
    Access to information6.4.59.4.17.5.3Nobody can produce the record live
    Verifying what arrivesA.5; 6.4.79.4.48.15 LoggingUnexpected medium, integrity unchecked
    Sampling from an exportA.69.4.48.16 Monitoring activitiesPopulation completeness unevidenced
    Protecting the channelA.16; A.58.4.7; 9.9.35.14 Information transfer; 6.7 Remote workingScreen sharing outside the transfer rule

    Clause numbers are as printed 29. The other two sources likewise 30 31.

    Next 90 days

    WeekActionOwnerOutput
    1List every location in scope; mark the virtual onesManagement system ownerLocation register
    1-2Name who may accept a remote method, for which auditsGovernance bodyDecision-rights entry
    2-3Add the holding system and the exporting role to each evidence rowEvidence index ownerTwo new index columns
    3-4Assess remote-evidence risk: authenticity, screen confidentiality, export completenessRisk ownerRisk entries with treatments
    4-5Put the method question into the agreement checklist, per activityCompliance leadRevised checklist
    5-6Agree platform, access and contingency; run a technical checkIT leadTechnical check record
    6-8Set the rule for screen copies and recordings, with disposalCompliance leadRecording rule
    8-10Brief guides for remote sessions, one per auditorManagement system ownerGuide roster
    10-12Run one internal audit session remotely; log what could not be verifiedInternal audit leadRehearsal note; gap list

    References

    1. ISO. Guidelines for auditing management systems. ISO 19011:2026, fourth edition, 2026-05, ISO/PC 302. https://www.iso.org/standard/19011 1
    2. ISO and IEC. Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements. ISO/IEC 17021-1:2015. https://www.iso.org/standard/61651.html 5
    3. ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 6
    4. ISO/IEC. Information security, cybersecurity and privacy protection — Information security controls. ISO/IEC 27002:2022. https://www.iso.org/standard/75652.html 20
    5. ISO/IEC TS 17012:2024 — named in the 2026 edition as the source of its remote-method guidance; not read here 32

    Sources

    1. 1ISO 19011:2026 Foreword and title page, licensed copy · verified 2026-09-06
    2. 2ISO 19011:2026 clause 3.4, licensed copy · verified 2026-09-06
    3. 3ISO 19011:2026 clause 3.6, licensed copy · verified 2026-09-06
    4. 4ISO 19011:2026 clause 4.1, licensed copy · verified 2026-09-06
    5. 5ISO/IEC 17021-1:2015 clause 9.4.1, licensed copy · verified 2026-09-06
    6. 6ISO/IEC 27001:2022 clause 9.2, iso.org/obp · verified 2026-09-03
    7. 7ISO 19011:2026 clause A.16, licensed copy · verified 2026-09-06
    8. 8ISO 19011:2026 clause 6.4.5, licensed copy · verified 2026-09-06
    9. 9ISO 19011:2026 clause 5.1, licensed copy · verified 2026-09-06
    10. 10ISO 19011:2026 clause 6.3.2.1, licensed copy · verified 2026-09-06
    11. 11ISO 19011:2026 clause 5.5.3, licensed copy · verified 2026-09-06
    12. 12ISO 19011:2026 clause 5.3, licensed copy · verified 2026-09-06
    13. 13ISO 19011:2026 clause A.1, licensed copy · verified 2026-09-06
    14. 14ISO 19011:2026 clause A.15, licensed copy · verified 2026-09-06
    15. 15ISO 19011:2026 clause A.17, licensed copy · verified 2026-09-06
    16. 16ISO 19011:2026 clause 6.4.7, licensed copy · verified 2026-09-06
    17. 17ISO 19011:2026 clause A.5, licensed copy · verified 2026-09-06
    18. 18ISO 19011:2026 clause A.6, licensed copy · verified 2026-09-06
    19. 19ISO/IEC 27002:2022 controls 8.15 Logging and 8.16 Monitoring activities, licensed copy · verified 2026-09-06
    20. 20ISO/IEC 27002:2022 controls 5.14 Information transfer and 6.7 Remote working, licensed copy · verified 2026-09-06
    21. 21ISO/IEC 17021-1:2015 clauses 8.4.7 and 9.9.3, licensed copy · verified 2026-09-06
    22. 22ISO 19011:2026 clause 6.3.2.2, licensed copy · verified 2026-09-06
    23. 23ISO/IEC 17021-1:2015 clause 9.2.3.2, licensed copy · verified 2026-09-06
    24. 24ISO 19011:2026 clause 6.4.2, licensed copy · verified 2026-09-06
    25. 25ISO 19011:2026 clauses A.16 and 6.3.4, licensed copy · verified 2026-09-06
    26. 26iso.org catalogue, ISO 19011:2026 page, live browser session · verified 2026-09-06
    27. 27iso.org catalogue, ISO 19011:2018 page, live browser session · verified 2026-09-06
    28. 28ISO 19011:2026 Introduction, licensed copy · verified 2026-09-06
    29. 29ISO 19011:2026 Annex A and clauses 5 to 6, licensed copy · verified 2026-09-06
    30. 30ISO/IEC 17021-1:2015 clauses 8.4, 9.1, 9.2, 9.4 and 9.9, licensed copy · verified 2026-09-06
    31. 31ISO/IEC 27001:2022 clauses 9.2 and 7.5.3, iso.org/obp · verified 2026-09-03
    32. 32ISO 19011:2026 Introduction, clause A.16 and Bibliography, licensed copy · verified 2026-09-06