The ISO Review Podcast
The ISO Review Podcast is a production of SimplifyISO. In each episode, we share the latest International Standards Development, and is your resource for getting the most out of your management systems. Your podcast hosts are Howard Fox & Jim Moran. Howard is a Business Coach and Host of the Success InSight Podcast. Jim is an ISO Management System Professional, celebrating 30-plus years delivering ISO support.
The ISO Review Podcast
ISO 19011:2026 Guidelines for Auditing Management Systems - Clauses 6 & 7
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Welcome to another episode of the ISO Review Podcast, your trusted source for the latest developments in international standards and practical guidance for getting the most out of your management systems.
Join hosts Howard Fox and Jim Moran—an ISO management system professional celebrating 34 years of expertise—as they dive into the newly updated ISO 19011:2026 standard.
In this episode, they break down Section 6 (Conducting an Audit) and Section 7 (Auditor Competence), explore the growing importance of hybrid and remote auditing methods, discuss how evidence reliability and technology skills have become essential, and share tips to ensure your audit process is truly value-adding, not just a box-ticking exercise. Whether you’re an internal auditor, management rep, or just ISO-curious, this episode will help you leverage the latest guidance to make your audit program more effective and resilient.
DISCUSSION
1. Introduction to the ISO Review Podcast
- Purpose of the podcast: sharing developments in international standards and management systems
2. Overview of ISO 19011:2026
- Background: ISO 19011 guidance document for auditing management systems 00:42
- Clarification: It provides guidance, not requirements; cannot be certified to this document 01:58
- Value of the standard: Utility for planning, developing, and implementing audit programs 02:08
- Mention of a new helpful flowchart in the document 02:18
3. Auditing Philosophy and Approach
- Common mistakes: Focusing on procedural compliance (tick box exercise) 02:38
- Key audit questions:
- Is the process getting intended results? 03:12
- Are risks managed effectively? 03:37
- Are there opportunities for improvement? 04:02
- Differences between internal and registrar auditing approaches 04:25
4. Section 6: Conducting an Audit (ISO 19011:2026)
- Audit lifecycle stages: initiating, preparing, conducting, reporting 05:04
- Evolution of the standard: From quality/environmental focus to encompassing all ISO standards 05:15
- Hybrid and remote auditing:
- Increased emphasis since the COVID-19 pandemic 05:42
- Savings in travel costs and flexibility 05:56
- Integration of technology and guidance on data privacy 06:13
- Distinction between remote and hybrid audits 06:29
- Impact of regulatory changes and industry adaptation:
- History of audit day calculations (MD5 document) 06:53
- Automotive sector’s response to remote audits 07:53
- Current spectrum: onsite, virtual, or hybrid depending on organizational context 08:11
- Registrar's use of judgment for effective audits and value addition 08:26
- Applicability to different organization types (manufacturing, services) and handling various forms of evidence 09:03
- Embracing of hybrid delivery and integrated audits 09:44
a. Selecting the Audit Method
- Requirement to specify methods (onsite, remote, hybrid) in the audit plan 10:05
- Planning stage includes method selection, not post-audit justification 11:05
- Critical planning elements: objective, scope, criteria 11:13
- Method selection examples: remote review vs. onsite observation 11:45
- Main auditing techniques:
- Interview 12:20
- Direct observation 12:25
- Records review 12:31
- Paradigm shift: focus on outcomes and improvement, not just procedural adherence 13:01
b. Evidence Reliability and Data Security
- Importance of verifying genuine evidence 14:06
- Shift in terminology from “fact-based” to “evidence-based” decision-making 14:43
- Data security considerations in digital and remote evidence collection 14:51
5. Section 7: Auditor Competence
- Emphasis on competence for registrars (and lessons for internal auditors) 15:14
- Expansion of competence requirements to include technology and information security 15:55
- Ensuring auditors understand and have access/permission for required evidence 16:35
- Identification and management of risks in the audit process 17:01
- Auditor performance evaluation: including feedback from auditees and stakeholders 17:52
- Auditor’s role: collaborator rather than “ISO cop” 18:18
- Historical context: evolution from nonconformance focus to improvement and communication 19:07
- Importance of 2-way and 3-way communication (auditor, auditee, audit planner) 19:40
- Application of Plan-Do-Check-Act to internal audits 20:02
- Using feedback loops to assess and improve audit program effectiveness 20:15
- Ongoing competence maintenance: continuing professional development 20:29
- Scheduling audits throughout the year for skill retention (vs. “audit blitz” before registrar visit) 21:24
- Advantages of flowcharts for process clarity and audit handoffs 22:15
- The 80/20 rule for nonconformances linked to process handoffs 22:45
6. Recap and Key Takeaways
- Lifecycle and method selection for audits 23:18
- Importance of evidence reliability 24:03
- Distinction between requirements and guidance (should vs. shall) 23:32
- Technology competence and digitalization in audit management 24:08
- Feedback loops and competence maintenance (regular training, recertification) 24:37
- Typical recordkeeping practices (3-year retention guidance) 25:28
7. Upcoming Episode Preview
- Next episode to cover Annex A of ISO 19011 25:55
8. Resources and Contact Information
- Jim Moran contact details and resources: simplifyiso.com, imsi.org, imsi-pro.org 26:30
- Additional links to LinkedIn, YouTube, and LinkedIn articles 27:13
- Howard Fox contact: foxcoaching.com 28:10
NEXT STEPS
We appreciate your likes & comments, and shares. Click here to visit the SimplifyISO website.
Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional.
Click here to learn about our new DIY ISO 9001 program using AI
Learn more about Jim on LinkedIn & YouTube.
LinkedIn
LinkedIn Articles
YouTube
Learn about Howard's Coaching and Podcast Services
Website: https://foxcoaching.com
LinkedIn: https://www.linkedin.com/in/foxcoachinginc/
Podcast Discovery Call: https://calendly.com/foxcoachinginc/podcast-discovery-call
KEYWORDS
Jim Moran, Information Security Management System, ISO 19011:2026, ISO Review Podcast, SimplifyISO, Podcast
#JimMoran #InformationSecurityManagementSystem #ISO9011:2026
#ISOReviewPodcast #SimplifyISO #Podcast
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.