The ISO Review Podcast

ISO 19011:2026 Guidelines for Auditing Management Systems - Clauses 3-5

Jim Moran, Howard Fox Episode 86

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 41:12

Welcome to another episode of the ISO Review Podcast, presented by Simplify ISO. Join hosts Jim Moran and Howard Fox as they explore the latest developments in international standards and offer practical guidance for maximizing your management systems. 

In this episode, Jim Moran shares insights into the newly released 2026 edition of ISO 19011, the key auditing standard for management systems. Together, they break down the history and evolution of auditing guidelines, clarify the difference between requirements and guidelines, and provide an overview of critical topics such as audit principles, program management, and auditor competence. 

Whether you're an internal auditor, a seasoned quality professional, or new to the world of ISO, this episode delivers essential tips on planning, conducting, and improving your audit programs. Stay tuned for clear explanations, actionable advice, and a roadmap for getting the most from your management system audits.

DISCUSSION

1. History of Auditing Standards

  • ISO 19011 standard: name and editions (2002, 2011, 2018, 2026) 02:28
  • Prior standards: ISO 10011, ISO 14001, and related documents 02:54
  • Merging of past standards into ISO 19011 03:40
  • Historical purpose and evolution of auditing guidelines 02:54

2. Structure of ISO 19011:2026 Auditing Standard

  • Overview of major clauses and their roles:
    • Clause 3: Definitions 04:15
    • Clause 4: Auditing Principles 04:22
    • Clause 5: Management System Overview 04:30
  • Preview of next episodes covering Clause 6 (Conducting Audits) and Clause 7 (Auditor Competence), and Annex A 05:17

3. Purpose and Nature of ISO 19011

  • Explanation of guidance vs. requirements in standards 07:23
  • Difference between “should” (guidelines) and “shall” (requirements) 07:37
  • Applicability for different types of audits and management systems 07:56
  • Use of ISO 19011 by registrars 08:50
  • Relationship to other ISO standards and structures 06:10

4. Clause 3: Terms and Definitions

  • Focus on importance of definitions for clarity in audits 10:07
  • Key terms defined: audit, combined audit, joint audit, remote audit, objective evidence, risk, effectiveness, etc. 10:27
  • Role of verifiable evidence and statements of fact 11:08
  • Practical exercises for auditors based on definitions 11:56

5. Clause 4: Principles of Auditing

  • Explanation of auditing principles versus rules/techniques 12:27
  • List and discussion of seven core principles:
    • Integrity 12:44
    • Objectivity 13:39
    • Fair Presentation 13:42
    • Due Professional Care 14:43
    • Confidentiality 16:30
    • Independence 17:23
    • Evidence-based Approach 18:50
    • Risk-based Approach 19:23
  • Integrity and the importance of evidence-based conclusions 13:08
  • The evolution from fact-based to evidence-based auditing 20:15

6. Clause 5: Managing an Audit Program

  • Planning and organizing an audit program 21:14
    • Plan-Do-Check-Act framework 21:28
    • Consideration of organizational size, scope, complexity, and risk 21:45
    • Audit scheduling across quarters/year 21:45
  • Functionality and complexity differences for various industries 22:58
    • Single location vs. multinational organization considerations 22:44
    • Industry-specific competence and language needs 24:13
  • Context and external/internal issues, including technology and information security 24:52
  • Focus of internal audits: looking for conformance, not nonconformance 25:35
  • Value of flowcharts in process and auditing 26:31
  • Auditor competence and impartiality 27:09
    • Maintaining objectivity and addressing potential biases 28:01
    • Auditor records, logbooks, and tracking industry experience 27:43
  • Training and preparation of auditors 29:07

7. Steps in Managing an Audit Program (Clause 5 Specifics)

  • Establishing objectives, evaluating program risks/opportunities 29:36
  • Implementing and monitoring the audit program 29:47
  • Flowchart use for organizing and documenting audits 30:30
  • Review and improvement of the audit program 30:53
  • Setting program objectives: results, risk management, and improvement 33:19
  • Evaluating resources, team selection, communication, competence 33:36
  • Documentation: audit scope, criteria, resources, and evidence 34:43
  • Authority and competence of audit program manager 34:09

8. Review and Preview of Next Episodes

  • Howard Fox summarizes the episode focus and praises structure 37:31
  • Emphasis on difference between “should” (guidance) and “shall” (requirement), and auditing implications 38:11
  • Teaser for next podcast: conducting audits and auditor competence, plus in-depth look at Annex A 38:03

9. Closing and Resources

  • Where to learn more: simplifyiso.com, IMSI, other links 39:12
  • Encouragement for next episode and outro 40:43

NEXT STEPS

We appreciate your likes & comments, and shares.  Click here to visit the SimplifyISO website. 

Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional.

Click here to learn about our new DIY ISO 9001 program using AI

Learn more about Jim on LinkedIn & YouTube.

LinkedIn
LinkedIn Articles
YouTube

Learn about Howard's Coaching and Podcast Services

Website: https://foxcoaching.com
LinkedIn
: https://www.linkedin.com/in/foxcoachinginc/
Podcast Discovery Call: https://calendly.com/foxcoachinginc/podcast-discovery-call

KEYWORDS

Jim Moran, Information Security Management System, ISO 19011:2026, ISO Review Podcast, SimplifyISO, Podcast

#JimMoran #InformationSecurityManagementSystem #ISO9011:2026 
#ISOReviewPodcast #SimplifyISO #Podcast

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.