Effective auditing serves as the backbone of any robust management system. Whether you’re verifying quality processes or environmental compliance, having a consistent approach to audits ensures that organizations can identify gaps, drive improvements, and maintain credibility with stakeholders. ISO 19011:2002 emerged as a groundbreaking standard that unified auditing guidance for both quality and environmental management systems, replacing six older standards and offering organizations a streamlined, harmonized approach to evaluating their operations.

Table of Contents

What is ISO 19011:2002?

ISO 19011:2002, titled “Guidelines for Quality and/or Environmental Management Systems Auditing,” was developed by the International Organization for Standardization to provide comprehensive guidance on auditing management systems. This standard consolidated previously separate auditing guidelines from the ISO 9000 (quality) and ISO 14000 (environment) families into a single, cohesive document.

The standard covers four essential areas that organizations need to master for effective audit management. First, it offers a clear explanation of auditing principles. Second, it provides guidance on managing audit programs. Third, it addresses the conduct of internal or external audits. Fourth, it delivers advice on evaluating auditor competence.

Who should use this standard?

ISO 19011 is applicable to all organizations that need to conduct internal or external audits of quality and environmental management systems, or those that manage audit programs. The intended users include auditors conducting first-, second-, or third-party audits, organizations implementing quality or environmental management systems, certification bodies, training organizations, and accreditation bodies involved in conformity assessment.

The unified scope of ISO 19011:2002

Before ISO 19011:2002, organizations had to navigate multiple standards when conducting quality and environmental audits. The ISO 9000 family had its own set of auditing guidelines (ISO 10011 series), while the ISO 14000 family had separate documents (ISO 14010, ISO 14011, and ISO 14012). This fragmented approach created inefficiencies and inconsistencies in audit practices.

ISO 19011:2002 changed this landscape by providing a single reference document. According to auditing experts, this unified approach helps user organizations optimize their management systems, facilitates the integration of quality and environmental management, and allows single audits of both systems-ultimately saving money and decreasing disruption to work units being audited.

Key areas covered by the scope

The standard’s scope encompasses guidance on the management of audit programs, including establishing objectives, defining responsibilities, allocating resources, and maintaining records. It also covers the conduct of management system audits, from initiating the audit through reporting findings. Additionally, it addresses the competence and evaluation of auditors, ensuring that those conducting audits possess the necessary skills and knowledge.

Principles of auditing

ISO 19011:2002 establishes fundamental principles that make audits effective and reliable tools for supporting management policies and controls. These principles help auditors working independently reach similar conclusions in similar circumstances, ensuring consistency across the organization.

Integrity and fair presentation

Auditors must perform their work ethically, with honesty and responsibility. They should only undertake audit activities for which they are competent and remain fair and unbiased in all their dealings. The principle of fair presentation requires that audit findings, conclusions, and reports reflect the audit activities truthfully and accurately. Significant obstacles encountered during audits and unresolved differences of opinion between the audit team and the auditee should be reported.

Due professional care and confidentiality

Auditors must exercise diligence and judgment appropriate to the importance of the task they perform. They should be capable of making reasoned judgments through all audit situations. Equally important is the protection of confidential information obtained during audit activities. This includes proper handling of sensitive data and ensuring information security throughout the audit process.

Independence and evidence-based approach

Independence forms the basis for impartiality and objectivity of audit conclusions. Auditors should be independent of the activity being audited wherever practicable and act in a manner free from bias and conflict of interest. The evidence-based approach ensures that auditors reach reliable and reproducible conclusions by basing their findings on verifiable, objective evidence obtained through systematic sampling techniques.

Managing an audit program

ISO 19011:2002 provides detailed guidance on establishing, implementing, monitoring, and improving audit programs. Effective audit program management requires clear objectives, defined scope and criteria, appropriate methods, and sufficient resources.

Establishing audit program objectives

Organizations should begin by determining the objectives of their audit program. These objectives should be consistent with the organization’s overall strategy and evaluate the performance of the management system. If management systems have changed, these modifications must be considered when establishing objectives. Results from previous audits should also inform program design.

Implementing and monitoring the program

The implementation phase involves assigning responsibilities, allocating resources, scheduling audits, and maintaining proper records. The person managing the audit program should ensure that auditors are selected based on their competence, availability, and impartiality. Records should be maintained to demonstrate implementation of the audit program and should be properly safeguarded. Regular monitoring and review help assess whether objectives are being achieved and identify opportunities for improvement.

Conducting management system audits

ISO 19011:2002 outlines a systematic process for conducting audits, from initiation through follow-up. This structured approach ensures consistency and effectiveness in audit activities.

Planning and preparation

Each audit should be based on defined objectives, scope, and criteria that are consistent with the overall audit program objectives. The planning phase involves determining audit objectives, forming and selecting qualified audit team members, designating roles and responsibilities, preparing checklists, identifying the scope and frequency of audits, and establishing review procedures.

Executing the audit

During execution, auditors collect, examine, and verify evidence through various methods including interviews, observations, and document reviews. The audit team evaluates evidence against established criteria to identify conformities and non-conformities. Once the assessment is complete, auditors prepare a report summarizing their findings and conclusions, which is then communicated to relevant stakeholders.

Reporting and follow-up

Audit reports should accurately reflect the audit objectives, scope, criteria, findings, and conclusions. Beyond reporting, the auditing process includes follow-up activities to verify that corrective actions have been implemented effectively. This continuous cycle ensures that identified issues are addressed and that the management system improves over time.

Auditor competence and evaluation

One of the most significant contributions of ISO 19011:2002 is its comprehensive framework for auditor competence. The standard specifies that organizations should assess the competence of those involved in the audit process during audit activities.

Knowledge and skills requirements

Auditors should possess knowledge of audit principles, procedures, and techniques to enable them to apply appropriate methods consistently. They need understanding of management system standards, relevant technical and business concepts, and applicable legal requirements. Auditors must demonstrate knowledge of relevant management system standards, possess personal attributes needed for impartial and effective auditing, and have practical auditing experience.

Personal attributes

Beyond technical knowledge, auditors need specific personal attributes to act in accordance with auditing principles. These include ethical behavior, open-mindedness, diplomacy, tenacity, and the ability to communicate effectively and work in teams. Audit team leaders must additionally be able to delegate tasks according to team members’ competencies, discuss strategic issues with top management, and guide audit team members.

Evaluation process

The standard provides a framework for organizations to establish their own competence requirements and related auditor evaluation processes. This recognizes that competence requirements vary according to the nature, scope, and complexity of each audit. Organizations should define evaluation criteria, select appropriate evaluation methods, and conduct regular assessments to maintain and improve auditor competence.

Benefits of implementing ISO 19011:2002

Adopting ISO 19011:2002 delivers tangible benefits for organizations. It provides a more integrated and balanced view of operations, making it an excellent tool for continuous improvement toward business excellence. The unified approach enables organizations to conduct combined audits of quality and environmental systems, reducing costs and minimizing disruption.

For external audits, the standard provides certification bodies with a uniform approach that facilitates combined assessment of management systems. This consistency builds stakeholder trust and demonstrates the organization’s commitment to maintaining high standards across both quality and environmental dimensions.

Evolution of the standard

While ISO 19011:2002 established the foundation for unified management system auditing, the standard has since been revised to address evolving organizational needs. The current version, ISO 19011:2018, has expanded the scope beyond quality and environmental systems to cover any type of management system. It has also introduced a risk-based approach to auditing principles and expanded guidance on remote auditing techniques.

Organizations currently using ISO 19011:2002 should consider transitioning to the latest version to take advantage of these enhancements while retaining the core principles and structured approach that made the original standard so valuable.

What do you think? How has your organization approached the integration of quality and environmental audits? Have you found that a unified auditing framework improves efficiency and consistency in your audit activities?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.iso.org/standard/31169.html
  2. https://en.wikipedia.org/wiki/ISO_19011
  3. https://safetyculture.com/topics/iso-19011
  4. https://www.certaintysoftware.com/iso-19011/
  5. https://preteshbiswas.com/2023/11/28/iso-190112018-clause-4-principles-of-auditing/
  6. https://stendard.com/en-sg/blog/iso-19011/
  7. https://blog.johner-institute.com/regulatory-affairs/iso-19011/
  8. https://goaudits.com/blog/iso-19011-audits/
  9. https://www.dqsglobal.com/en/explore/blog/iso-19011-how-to-manage-audits-competently

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Food Safety and Quality Management Systems

1 Introduction to Management systems

  1. Introduction to ISO 9001
  2. ISO 9000
  3. Introduction to ISO 14001:2004
  4. How to Use ISO 14001
  5. Introduction to OHSAS 18001:2007
  6. How to Use OHSAS 18001:2007
  7. Introduction to ISO/IEC 27001
  8. The PDCA Model

2 Auditing

  1. Clause 1 – Scope of the Standard
  2. Clause 2 – Normative References
  3. Clause 3 – Terms and Definitions
  4. Clause 4 – Principles of Auditing
  5. Clause 5 – Managing an Audit Program
  6. Clause 6 – Audit Activities
  7. Clause 7 – Competence and Evaluation of Auditors

3 Standardization and Accreditation

  1. International Accreditation Forum (IAF)
  2. International Laboratory Accreditation Cooperation (ILAC)
  3. Quality Council of India (QCI)
  4. National Accreditation Board for Testing and Calibration Laboratories (NABL)
  5. ISO/TS 22003:2007 Food Safety Management System
  6. ISO Guide 65: General Requirements for Bodies Operating Product Certification Systems
  7. ISO/IEC 17020:1998 General Criteria for the Operation of Various Types of Bodies Performing Inspections
  8. ISO/IEC 17021:2006 – Conformity Assessment-Requirements for Bodies Providing Audit and Certification of Management Systems
  9. ISO 17025:2005 General Requirements for the Competence of Testing and Calibration Laboratories

4 ISO 9001-2000 – An Overview

  1. ISO 9000
  2. Quality Management Principles
  3. ISO 9000:2005, Quality Management Systems: Fundamentals and Vocabulary
  4. ISO 9001:2000, Quality Management Systems: Requirements
  5. Steps for Implementing Quality Management Systems
  6. Benefits of ISO 9001:2000
  7. ISO 9004:2000, Quality Management Systems: Guidelines for Performance Improvements
  8. Relationship with ISO 9001:2000
  9. Self-assessment Model

5 ISO 9001-2000 – Structure

  1. Documentation Structure of ISO 9001:2000
  2. Quality Manual
  3. Mandatory Procedures
  4. Standard Operating Procedures (SOPs)
  5. Process Definition Documents
  6. Work Instructions
  7. Miscellaneous Documents
  8. Formats and Records
  9. ISO 9001:2000 Clauses

6 Clause wise interpretation of ISO 9001-2000

  1. Clause 1: Scope
  2. Clause 2: Normative Reference
  3. Clause 3: Terms and Definitions
  4. Clause 4: Quality Management System
  5. Clause 5: Management Responsibility
  6. Clause 6: Resource Management
  7. Clause 7: Product Realization
  8. Clause 8: Measurement, Analysis and Improvement

7 ISO 9001-2000 – Case Studies

  1. Engineering Job Work Organisation
  2. Software Development Organisation
  3. Management Review in Engineering
  4. Customer-Related Processes in Software
  5. Internal Audits in Engineering
  6. Design and Development in Software
  7. Corrective and Preventive Actions in Software
  8. Customer Property Management in Engineering

8 ISO 22000-2005 – An Overview

  1. What Does ISO 22000 Bring to the HACCP Method?
  2. System Components
  3. Communication between Participants in the Food Industry
  4. ISO 22000: A Passport for Exporting?
  5. Why do Companies Commit themselves to an ISO 22000 Approach?
  6. Who Should Use ISO 22000:2005?
  7. Why Use ISO 22000:2005?
  8. ISO 22000 and HACCP
  9. Codex Alimentarius
  10. Key Elements and Benefits of ISO 22000

9 ISO 22000-2005 – Structure

  1. Economic Loss due to Food Borne Illness
  2. ISO 22000: 2005 Clauses
  3. FSMS Documentation Structure
  4. Food Safety Team Structure
  5. Food Safety Manual
  6. Mandatory Procedures
  7. Standard Operating Procedures (SOP)/Work Instructions
  8. HACCP Pre-steps Related Documents
  9. HACCP Principles Related Documents
  10. Miscellaneous Documents
  11. Formats and Records

10 Clause-wise interpretation of ISO 22000- 2005

  1. Clause 1: Scope
  2. Clause 2: Normative References
  3. Clause 3: Terms and Definitions
  4. Clause 4: Food Safety Management System
  5. Clause 5: Management Responsibility
  6. Clause 6: Resource Management
  7. Clause 7: Planning and Realization of Safe Products
  8. Clause 8: Validation, Verification and Improvement of the FSMS

11 ISO 22000-2005-Case Studies

  1. Kick-off meeting
  2. Introduction to the standard
  3. Formation of food safety team
  4. Description of product and its intended use
  5. PRP (Pre-requisite programme)
  6. Flow diagrams, process steps and control measures
  7. Control measure assessment
  8. Verification of food safety management system
  9. Traceability system
  10. External communication
  11. Internal communication
  12. Management Reviews

12 An Overview and Requirements of ISO 17025

  1. Introduction to the ISO/IEC 17025 Standard
  2. Scope of ISO/IEC 17025
  3. Normative References
  4. Terms and Definitions
  5. General Requirements
  6. Structural Requirements
  7. Resource Requirements
  8. Process Requirements
  9. Management System Requirements

13 Requirements specific to Food testing laboratories – Physical and chemical Parameters

  1. Introduction
  2. Quality and Safety Requirements of Food Products
  3. Chemical and Physical Testing Requirements of Food Products
  4. Laboratory Quality Management System
  5. Management Requirements (Clause 4 of ISO 17025)
  6. Technical Requirements (Clause 5 of ISO 17025)
  7. Traceability of Measurement
  8. Sampling
  9. Handling Test and Calibration Items
  10. Assuring the Quality of Test and Calibration Results

14 Requirements specific to Food testing laboratories – Biological parameters

  1. Introduction
  2. Quality and Safety Requirements of Food Products
  3. Biological Testing Requirements of Food Products

15 General topics- related to Food testing laboratories

  1. Method Validation
  2. Ruggedness
  3. Uncertainty of Measurement
  4. International Accreditation Aspects

16 BRC Food and BRC/IOP Standards – An Overview

  1. BRC Global Standard – Food (Issue 5, January 2005)
  2. Introduction to BRC Food Standard
  3. Legislative Requirements
  4. Benefits of the BRC Global Standard – Food
  5. Principles of the BRC Global Standard – Food
  6. The Standard Technical Advisory Committee
  7. Scope of the BRC Global Standard – Food
  8. The Format of the BRC Global Standard – Food
  9. Application
  10. Structure and Interpretation of the Standard
  11. BRC / IOP Global Standard Issue 3 2001 (Food Packaging and Other Packaging Materials)
  12. IOP: The Institute of Packaging
  13. BRC/IOP Relationship
  14. Benefits of BRC/IOP Packaging Standard
  15. Principles of BRC/IOP Packaging Standard
  16. Application
  17. Structure of BRC / IOP Global Standard – Food Packaging and Other Packaging Materials

17 International Food Standard

  1. Background of the IFS
  2. Service Protocol of the IFS ISSUE 5
  3. Contractual Arrangements – Selection of Certifying Body
  4. Audit Notification
  5. Scope of the Audit
  6. Audit Flow – Preparing the Audit Plan
  7. Level Determination – KO, Major NC’s, NA
  8. Scores, Issuing the Audit Report and Certification
  9. Audit Frequency
  10. Audit Report
  11. Awarding of Certificate
  12. Distribution of the Audit Report
  13. Supplementary Action
  14. Appeal Procedure
  15. Complaints
  16. IFS – Catalogue of Requirements
  17. Management of Quality System
  18. Management Responsibility
  19. Resource Management
  20. Product Realization
  21. Measurements, Analysis and Improvements
  22. Requirements for Certification Bodies and Auditors
  23. Report

18 SQF 1000 And SQF 2000

  1. SQF 1000
  2. Interpretation of SQF 1000 Standard
  3. SQF 2000
  4. Interpretation of SQF 2000 Standard
  5. Let Us Sum Up

19 Global GAP and India GAP

  1. Potential Benefits and Challenges Related to Good Agricultural Practices (GAP)
  2. Description of the FAO/GAPs
  3. USDA GAP/GHP Programme
  4. Global GAP
  5. India GAP