In short: The third edition of ISO 19011 introduces a risk-based approach to auditing and extends guidance to all types of management systems.
ISO has published the third edition of ISO 19011:2018, Guidelines for auditing management systems.
Key updates
- Addition of the risk-based approach to the principles of auditing
- Expanded guidance on managing an audit programme, including audit programme risk
- Expanded guidance on conducting an audit, particularly audit planning
- Expanded generic competence requirements for auditors
- Adjusted terminology to reflect the process rather than the object (“thing”) being audited
- Removal of the annex containing competence requirements for auditing specific management system disciplines
Why it matters for auditors
ISO 19011 is the foundation for first-party (internal) and second-party (supplier) audits across quality, environment, health and safety and other management systems. Auditors and audit programme managers should update their practices accordingly.
ISO 19011 is a core reference for the CQA and CQLA certifications.