What ISO 19011 Requires of an Internal Auditor
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
6 min read
Contents
Strictly, nothing. ISO 19011 is titled guidelines for auditing management systems, and guidance is what it contains. It sets out no requirements, issues no obligations and cannot be conformed to. There is no such thing as an audit that complies with ISO 19011.
That is not a technicality, because the document people actually have to satisfy is a different one, and confusing the two produces an audit programme built against the wrong yardstick.
First, check which edition your procedure names
ISO 19011:2018 was withdrawn. ISO published the fourth edition, ISO 19011:2026, on 27 May 2026, and the 2018 edition now shows as Withdrawn on ISO's own catalogue.
This is worth two minutes of your time rather than two seconds of embarrassment. Internal audit procedures, audit plans and competence matrices routinely name the standard and its year. The 2018 edition was current for close to eight years, so citing it is a well-formed habit rather than carelessness, and a great deal of published material still does. It is simply now out of date, and an auditor reading your procedure will notice a superseded reference before they notice anything else in it.
I have not read the 2026 text. It is not published free of charge, and this article does not speculate about what changed between editions. What can be stated is what ISO publishes: fourth edition, 27 May 2026, 46 pages, guidance on the principles of auditing, managing an audit programme, conducting audits and evaluating the competence of the people involved.
What actually binds you is clause 9.2 of your own standard
The obligation comes from ISO/IEC 42001 if you are certifying an AI Management System, or ISO/IEC 27001 if it is an information security management system. Clause 9.2 in each requires the organisation to run internal audits at planned intervals and to keep the audit programme objective and impartial.
Notice where that sits. It is a requirement on the organisation, not on the auditor and not on whoever you hired. Your supplier cannot discharge it for you by asserting they were objective, and this is a different question from whether your implementer is permitted to do the work.
So what does an internal auditor actually need?
Three things, none of which is a certificate.
Competence in auditing, and competence in the subject. These are separable and both are needed. Somebody who audits well but has never read Annex A of ISO 42001 will produce a tidy report about the wrong things. Somebody who knows the standard cold but has never audited will collect documents rather than evidence.
Independence of the activity being audited, so far as it is achievable. In a large organisation this is an organisational chart question. In a company of twenty it may be genuinely impossible, and the guidance does not pretend otherwise.
The ability to record what was examined, not only what was concluded. An internal audit report that gives findings without the sample, the interviews, the dates and the evidence examined cannot be assessed by anybody. It asks to be believed.
The certificate question, since it is the one that gets asked
Clause 9.2 does not require a Lead Auditor certificate. No accredited management system standard makes a training certificate a condition of running an internal audit, and any consultancy telling you otherwise, including this one, is describing a preference rather than a requirement.
What a certificate does is evidence competence quickly, which is worth something when an external auditor is deciding how much weight to give your audit programme. It is one route to demonstrating competence, not the only one, and it is not a substitute for the two other things above.
Why ISO 19011 still matters even though it requires nothing
Because it is the yardstick your certification body reads your audit programme against.
When an external auditor assesses whether your internal audits were adequate, they are applying professional expectations about audit planning, sampling, evidence and reporting. Those expectations are the ones described in ISO 19011. The document has no authority over you and enormous influence on how your work is read.
That is the useful way to hold it. Not a rulebook you must obey, but the shared description of what competent auditing looks like, written down where both sides can see it.
What to do this week
Open your internal audit procedure and check three things. Which edition of ISO 19011 it names. Whether it records how auditor competence is established, rather than just who the auditor is. Whether your last audit report shows the evidence examined or only the conclusions reached.
If the answer to the first one is 2018, that is now a superseded reference, and it is the cheapest correction on this list.
Sources
- ISO catalogue entry for ISO 19011:2026, guidelines for auditing management systems, fourth edition, published 27 May 2026, 46 pages, technical committee ISO/TMBG. Read 1 September 2026.
- ISO catalogue entry for ISO 19011:2018, third edition, published July 2018, status Withdrawn. Read 1 September 2026.
- ISO/IEC 42001:2023 and ISO/IEC 27001:2022, clause 9.2. These standards, and the text of ISO 19011:2026, are not published free of charge. Nothing above is quoted from them. Their requirements are characterised, and where the characterisation is load bearing the article says so.
Alfred Obeng
Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.
Related reading
8 min read
Can the Consultancy That Built Your AIMS Also Audit It?
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
The rule everyone quotes is about your certification body, not your consultant. What ISO/IEC 17021-1 actually restricts, and where the real constraint lands.
- ISO 42001
- Internal Audit
- Certification
- AI Governance
7 min read
What a Stage 2 Auditor Asks About Clause 9.2
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Seven questions your internal audit programme has to answer, in the order they become answerable, and the three patterns that draw the most attention.
- Internal Audit
- ISO 42001
- Certification
- ISO 27001
6 min read
ISO 42001 Internal Audit versus Pre-Certification Readiness Audit
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Bought at the same point, priced similarly, and routinely assumed to be the same thing. One discharges clause 9.2. The other cannot, and the sequencing is where the money leaks.
- Internal Audit
- ISO 42001
- Certification
6 min read
Readiness Assessment, Internal Audit, Certification Audit: Three Different Things
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Three exercises, three purposes, three different answers to who is allowed to perform them. The test that cuts through it is asking what the report is evidence of, and to whom.
- Certification
- Internal Audit
- ISO 27001
- ISO 42001
