Guidelines for Auditing Management Systems
Provides guidance on auditing management systems — the principles of auditing, managing an audit programme, conducting audits, and evaluating the competence of auditors. The 2018 (third) edition added a risk-based approach and applies to any management system, making it the method standard behind internal and supplier audit programmes.
What this does not cover
stated in the document's own scope- Provides guidance for first- and second-party (internal and supplier) audits; certification-body (third-party) audits are governed by ISO/IEC 17021.
- Is guidance on how to audit, not a set of management-system requirements to be audited against.
- Covers the auditing method generally; the criteria audited against come from the applicable standard, regulation, or procedure.
Always verify against the current published text before relying on it for a submission or inspection.
Overview
ISO 19011 provides guidance on auditing management systems: the principles of auditing, how to establish and manage an audit programme, how to plan and conduct an audit, and how to evaluate and develop the competence of auditors. It is the method standard that internal-audit and supplier-quality functions rely on across GxP, applicable to any management system rather than a single discipline. The 2018 third edition strengthened the risk-based approach to both the audit programme and individual audits, and expanded the guidance on auditor competence.
Scope & applicability
Anyone running or performing management-system audits — internal audit functions, supplier-quality auditors, and audit-programme managers across GxP disciplines. It is guidance for first- and second-party audits; certification (third-party) audits also draw on ISO/IEC 17021.
Legal basis & how it acquires force
ISO 19011 is voluntary guidance, not a certifiable requirement and not law. It is the recognised good-practice reference for first-party (internal) and second-party (supplier) audits; third-party certification audits are governed instead by ISO/IEC 17021. GMP quality systems and ISO 9001/13485 all expect a functioning internal-audit programme, and ISO 19011 is how organisations design and run it. The current edition is ISO 19011:2018.
Document structure
| Part | Covers |
|---|---|
| Principles of auditing | Integrity, fair presentation, due professional care, confidentiality, independence, and evidence-/risk-based auditing |
| Managing an audit programme | Programme objectives, risks and opportunities, resources, implementation, monitoring, and review |
| Conducting an audit | Initiation, preparation, on-site activities, evidence collection, findings, reporting, and follow-up |
| Competence and evaluation of auditors | Determining, evaluating, and maintaining the competence of auditors and audit teams |
Key requirements
- Audit principles: integrity, fair presentation, due professional care, confidentiality, independence, and a risk-based, evidence-based approach
- A managed audit programme with defined objectives, risks and opportunities, resources, and monitoring
- A defined audit process from initiation and preparation through conduct, reporting, and follow-up
- Evaluation and continual development of auditor competence
International alignment
ISO 19011 is the auditing method behind the internal- and supplier-audit expectations of ISO 9001, ISO 13485, and GMP quality systems, and it supports the audit and self-inspection provisions of ICH Q10. It complements — and is distinct from — ISO/IEC 17021, which governs third-party certification bodies.
ISO 19011:2018: frequently asked questions
Quick answers to common questions about ISO 19011:2018.
What is ISO 19011 used for?
It is the guidance organisations use to run internal (first-party) and supplier (second-party) audits of their management systems — the principles, the audit programme, how to conduct an audit, and auditor competence.
Is ISO 19011 a certifiable standard?
No. It is guidance, not a requirements standard, so organisations are not certified to it. Certification (third-party) auditing is governed by ISO/IEC 17021 instead.
What changed in the 2018 edition?
The third edition strengthened the risk-based approach to the audit programme and individual audits and expanded the guidance on determining and evaluating auditor competence.