The Key to Successful Audits Using the ISO 19011:2018 Framework | Intertek SAI Global Australia (2024)

The recently updated ISO 19011:2018, provides excellent guidelines for the risk-based management of internal and external audit programs and auditors.

One of the primary drivers for the creation of ISO 19011:2018 was to synchronise the audit process with the philosophy and intent behind the recent revisions to the management system Standards.

The ISO 19011:2018 Standard includes seven auditing principles:

  1. Integrity
  2. Fair presentation
  3. Due professional care
  4. Confidentiality
  5. Independence
  6. Evidence-based approach
  7. Risk-based approach

These principles, when implemented effectively, provide the guidance needed to successfully manage and conduct audits of ISO management systems.

5 tips to conducting value-added audits with ISO 19011:2018:

When audits detect problematic issues (often referred to as non-conformances), it is very important that management response includes the effective;

1. Align the audit program with the business’s objectives

Clause 5 of the ISO 19011:2018 Standard concerns managing an audit program, recognising there is more involved than creating an audit schedule. The audit program should consider a management systems functionality, complexity, maturity and the type of risks and opportunities associated with it.

2. Adopt a risk-based approach to audit planning

Clause 6.3.2 of the ISO 19011:2018 Standard provides guidance on audit planning. By adopting a risk-based approach to planning, auditors can consider the risks of the audit activities and not achieving the audit objectives. A common problem is allocating sufficient time and resources. Many leaders do not understand the time required; they see auditors interviewing team members and believe this, plus some time to compile a report, is all that auditing involves.

3. Use the right people for the job

For the audit program to be effective in achieving its objectives, you need to have competent and qualified auditors to conduct the audit activities. Clause 7 in ISO 19011: 2018 discusses the evaluation of auditor competence and performance. If the audit team lacks knowledge or expertise, a technical expert should be used to close the knowledge gap. Auditors do not have to be experts in every single process, but they should understand the organisations;

  • Key organisational goals and issues
  • Management systems and requirements (and how they might interact)
  • Core business processes and how they impact each other
  • Risk-based approach to management at all levels
  • Regulatory frameworks

4. Audit the audit program

The audit process itself must be audited, and like all other processes, opportunities to improve it should be identified and implemented. The audit process ideally then becomes an opportunity to confirm the capability of the processes under audit, and to identify and share best practices within the business.

Conducting internal audits using ISO 19011:2018

Download Now

5. Don’t just treat the symptom

When audits detect problematic issues (often referred to as non-conformances), it is very important that management response includes the effective;

  • Containment and Correction of the problem
  • Corrective Action
  • Mitigation of any emerging risks related to actions taken

All of the above actions are important but conducting an effective corrective action process, including thorough root cause analysis, is absolutely vital to drive continual improvement. Businesses are often quick to react to the issue by treating the symptoms and are therefore likely to experience the issue again. Instead, the business should take a step back and understand the broader issue, working to resolve the root cause and eliminating the issue from reoccurring.

Audits are not simply a process to ensure your business management functions and processes are operational and effective, they also allows your organisation to assess the condition of other management programs and risk management processes, as well as assist in compliance with applicable regulations, standards and other key requirements.

Similar to how an internal audit reviews the condition of your organisation, the audit program itself must be assessed and treated as an opportunity for enhancement and optimisation.

ISO 19011: 2018 is a catalyst for these objectives and also identifies and distinguishes the potential impact that advancements in technology can have on the audit process, such as virtual or remote technology enabled audits.

Contact us to discuss improving your Internal Audit Program

Contact Us

Related News & Resources

Explore our library of News & Resources below.

ISO Certification Readiness

Tuesday October 25, 2022 – ISO Certification Expert Erica Smith discussed what does my organisation need for certification readiness?

SAI Global Assurance Now Delivering Costco Audits in New Zealand

As a Costco-approved Certification Body, SAI Global is committed to delivering best-in-class audit experience in alignment with the Costco requirementsand can offer a combined GFSI audit.

Cybersecurity: The Basics

Download this whitepaper to learn about the cyber risks your organisation should be aware of and how you can protect it against cyber threats.

The Key to Successful Audits Using the ISO 19011:2018 Framework | Intertek SAI Global Australia (2024)

FAQs

How to conduct effective audit ISO 19011? ›

ISO 19011 offers guidance on every step of auditing a management system or audit program, including:
  1. Defining program objectives. Ensuring you understand the specific objectives you hope to achieve. ...
  2. Completing the audits needed. Planning and reviewing internal documents. ...
  3. Reviewing the results and process.

What are the audit principles detailed in ISO 19011 2018 standard? ›

Clause 6.3. 2 of the ISO 19011:2018 Standard provides guidance on audit planning. By adopting a risk-based approach to planning, auditors can consider the risks of the audit activities and not achieving the audit objectives. A common problem is allocating sufficient time and resources.

What is the purpose of ISO 19011 2018? ›

This document provides guidance on auditing management systems, including the principles of auditing, managing an audit programme and conducting management system audits, as well as guidance on the evaluation of competence of individuals involved in the audit process.

What are the auditor characteristics of ISO 19011? ›

ISO 19011 enumerates the following as being emblematic behavior for a competent and qualified auditor: ethical, open-minded, diplomatic, observant, perceptive, versatile, tenacious, decisive, self-reliant, acting with fortitude, open to improvement, culturally sensitive, and collaborative.

What is needed for a successful audit? ›

A successful audit starts with adequate preparation and a focus on making things easier for all involved, has continuous support from management, and leads to a change in course or other corrective action.

What are the steps that follow for successful audit? ›

  • Plan ahead. ...
  • Stay up-to-date on accounting standards. ...
  • Assess changes in activities. ...
  • Learn from the past. ...
  • Develop timeline and assign responsibility. ...
  • Organize data. ...
  • Ask questions. ...
  • Perform a self-review.

What are the 7 principles of auditing why it must be followed? ›

The principles of independence, objectivity, competence, confidentiality, professionalism, due professional care, and continuous improvement are essential for the internal audit function to fulfill its role as a trusted advisor to the organization.

What is the correct definition of an audit according to ISO 19011? ›

That means that an auditor or audit team looks at what a company is doing, collects evidence, and compares that evidence to the controls the organization is supposed to be doing.

What is key audit matters standard on auditing? ›

Key audit matters are those matters that, in the auditor's professional judgment, were of most significance in the audit of the financial statements of the current period.

What does ISO 19011 2018 concentrate on? ›

This document concentrates on internal audits (first party) and audits conducted by organizations on their external providers and other external interested parties (second party). This document can also be useful for external audits conducted for purposes other than third party management system certification.

Is ISO 19011 2018 the latest version? ›

ISO 19011 is an international standard that sets forth guidelines for management systems auditing. The current version is ISO 19011:2018. It is developed by the International Organization for Standardization. Originally it was published in 1990 as ISO 10011-1 and in 2002 took the current ISO 19011 numbering.

What does an ISO audit look for? ›

An ISO audit is an activity that companies conduct to evaluate, confirm, and verify processes related to the quality, security and safety of products and services so that companies are able to ensure the management system has been effectively implemented.

What are the six characteristics of reliable audit evidence? ›

Relevance – must pertain to the audit objective being tested. Effectiveness of client internal controls – good internal controls can mean better information. Auditor direct knowledge – auditor determinations are stronger that client comments. Qualifications – individual is a qualified source.

What are the characteristics of good audit working? ›

The basic principles of auditing are confidentiality, integrity, objectivity, independence, skills and competence, work performed by others, documentation, planning, audit evidence, accounting system and internal control, and audit reporting.

What are the types of audit in ISO? ›

There are three types of ISO audits: internal audits (first-party audits), supplier audits (second-party audits), and external audits (third-party audits).

How do you conduct an ISO audit? ›

6 tips to ace your ISO audit
  1. Be well-prepared. The ISO certification should be a living management process that is constantly updated and optimized. ...
  2. Take internal audits seriously. ...
  3. Implement corrective actions. ...
  4. Don't forget your management review. ...
  5. Correctly monitor objectives. ...
  6. Ensure that everything is clean.

What is the ISO standard for conducting audits? ›

Moreover, the ISO 19011 standard enables organizations to enhance their management systems through a rigorous auditing arm. It ensures conformity to ISO's management system standards such as but not limited to the following: ISO 9001 – Quality Management System (QMS) ISO 14001 – Environmental Management System (EMS)

What are the 5 steps of the audit process? ›

Audit Process
  • What happens during an audit? Internal audit conducts assurance audits through a five-phase process which includes selection, planning, conducting fieldwork, reporting results, and following up on corrective action plans.
  • Selection. ...
  • Planning. ...
  • Fieldwork. ...
  • Reporting. ...
  • Follow-up.

Top Articles
Latest Posts
Article information

Author: Prof. An Powlowski

Last Updated:

Views: 6182

Rating: 4.3 / 5 (44 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Prof. An Powlowski

Birthday: 1992-09-29

Address: Apt. 994 8891 Orval Hill, Brittnyburgh, AZ 41023-0398

Phone: +26417467956738

Job: District Marketing Strategist

Hobby: Embroidery, Bodybuilding, Motor sports, Amateur radio, Wood carving, Whittling, Air sports

Introduction: My name is Prof. An Powlowski, I am a charming, helpful, attractive, good, graceful, thoughtful, vast person who loves writing and wants to share my knowledge and understanding with you.