ISORegulatory IntelligenceStandard
ISO 19011:2018

Guidelines for Auditing Management Systems

Provides guidance on auditing management systems — the principles of auditing, managing an audit programme, conducting audits, and evaluating the competence of auditors. The 2018 (third) edition added a risk-based approach and applies to any management system, making it the method standard behind internal and supplier audit programmes.

LAST REVISED
July 2018
PRODUCT AREAS
SterileSolid DoseApiBiotechDevicesFood

What this does not cover

stated in the document's own scope
  • Provides guidance for first- and second-party (internal and supplier) audits; certification-body (third-party) audits are governed by ISO/IEC 17021.
  • Is guidance on how to audit, not a set of management-system requirements to be audited against.
  • Covers the auditing method generally; the criteria audited against come from the applicable standard, regulation, or procedure.
SOURCE & PROVENANCE
ISSUING BODY
International Organization for Standardization
JURISDICTION
International
DOCUMENT ID
ISO 19011:2018
Official site — International Organization for Standardization

Always verify against the current published text before relying on it for a submission or inspection.

Overview

ISO 19011 provides guidance on auditing management systems: the principles of auditing, how to establish and manage an audit programme, how to plan and conduct an audit, and how to evaluate and develop the competence of auditors. It is the method standard that internal-audit and supplier-quality functions rely on across GxP, applicable to any management system rather than a single discipline. The 2018 third edition strengthened the risk-based approach to both the audit programme and individual audits, and expanded the guidance on auditor competence.

Scope & applicability

Anyone running or performing management-system audits — internal audit functions, supplier-quality auditors, and audit-programme managers across GxP disciplines. It is guidance for first- and second-party audits; certification (third-party) audits also draw on ISO/IEC 17021.

Legal basis & how it acquires force

ISO 19011 is voluntary guidance, not a certifiable requirement and not law. It is the recognised good-practice reference for first-party (internal) and second-party (supplier) audits; third-party certification audits are governed instead by ISO/IEC 17021. GMP quality systems and ISO 9001/13485 all expect a functioning internal-audit programme, and ISO 19011 is how organisations design and run it. The current edition is ISO 19011:2018.

Document structure

PartCovers
Principles of auditingIntegrity, fair presentation, due professional care, confidentiality, independence, and evidence-/risk-based auditing
Managing an audit programmeProgramme objectives, risks and opportunities, resources, implementation, monitoring, and review
Conducting an auditInitiation, preparation, on-site activities, evidence collection, findings, reporting, and follow-up
Competence and evaluation of auditorsDetermining, evaluating, and maintaining the competence of auditors and audit teams

Key requirements

  • Audit principles: integrity, fair presentation, due professional care, confidentiality, independence, and a risk-based, evidence-based approach
  • A managed audit programme with defined objectives, risks and opportunities, resources, and monitoring
  • A defined audit process from initiation and preparation through conduct, reporting, and follow-up
  • Evaluation and continual development of auditor competence
CHECKING ACCESS

Checking your Professional access…

ISO 19011:2018: frequently asked questions

Quick answers to common questions about ISO 19011:2018.

What is ISO 19011 used for?

It is the guidance organisations use to run internal (first-party) and supplier (second-party) audits of their management systems — the principles, the audit programme, how to conduct an audit, and auditor competence.

Is ISO 19011 a certifiable standard?

No. It is guidance, not a requirements standard, so organisations are not certified to it. Certification (third-party) auditing is governed by ISO/IEC 17021 instead.

What changed in the 2018 edition?

The third edition strengthened the risk-based approach to the audit programme and individual audits and expanded the guidance on determining and evaluating auditor competence.