Contact

What are you looking for?

ISO 19011 Internal Auditing: Why Most Audits Miss the Real Problems

SGS North America BlogCertificationAugust 17, 2026

Was this ISO standard written as a prescription for conducting audits, or does it allow flexibility in how we conduct internal audits? Do you want to try a fun activity and impress your peers? Open ISO 19011:2018 and search for the term “shall.”

It appears only once, on page v, in ISO’s boilerplate language:

“ISO shall not be held responsible for identifying any or all such patent rights.”

There is only one “shall” statement, and it concerns patent rights, not auditing.

“Should” indicates a recommendation (n = 257), “may” indicates permission (n = 47), and “can” indicates a possibility (n = 104).

Does that mean I have complete flexibility to implement internal auditing procedures in line with ISO 19011:2018’s recommendations, permissions, and possibilities? Yes!

One of the most common misconceptions about internal auditing is that its goal is to verify whether procedures exist.

That approach may generate audit checklists and completed forms, but it often fails to answer the question that regulators, certification bodies, and executive leadership actually care about:

“Does the management system truly work in practice?”

That distinction is critical. ISO 19011:2018 was developed to guide the management of audit programs using a process-based, risk-focused approach. The key word is “process.” Organizations do not fail because of missing clauses here and there. They fail because of broken processes and weak interactions between systems.

Why Objective Evidence Matters So Much

Objective evidence serves as the basis for analyzing data to determine whether audit criteria have been met. Audit criteria may include subclauses in an ISO or IEC standard, steps in a standard operating procedure (SOP) or work instruction (WI), requirements in a supplier contract, and more.

But how do you move from an audit criterion to objective evidence?

Ask open-ended questions during interviews and while reading and analyzing documents, records, or statistical analysis tables.

What types of evidence does ISO 19011 focus on? Because ISO 19011 is not sector-specific, its focus is very high-level:

  • Documents: “Please show me how the steps in your SOP or WI were followed.”
  • Records: “Please explain how this report meets the intent of this audit criterion.”
  • Observations: An auditor’s observations while walking through a facility can serve as evidence.
  • Interviews: “I have read your SOP. As the process owner, please walk me through the steps that must be followed.”
    “I see that the SOP was revised. Please walk me through the steps that led to this revision and its final approval.”
  • Process outputs: “Please explain how the outputs of this process become inputs for other processes.”
    “How does the organization identify and define the processes necessary for its management system?”
  • Measurable performance, such as metrics or key performance indicators (KPIs): “What approaches does top management use to ensure that quality objectives are established and maintained?”
    “Please provide an example of where this engagement led to significant improvements.”

Why It Is Important to Highlight What Is Going Well

Regulators and certification bodies increasingly want organizations to identify not only what is wrong, but also what is going well.

How can you do that? Here are questions you can ask during an audit and then incorporate into the closing meeting and final audit report:

  1. What sets this organization apart?
  2. What does the organization do exceptionally well?
  3. What practices create a competitive advantage?
  4. Where are there examples of brilliance?
  5. Who was responsible for maintaining the clean, well-organized areas, such as receiving, chemical storage, and laboratories?
  6. Is the organization’s management, or a specific leader, fully engaged?
  7. Does the production team develop effective corrective actions?
  8. What detailed action plans exist for achieving objectives within the purchasing, supplier qualification, receiving, and document control departments?

In some organizations, audits become highly administrative exercises that generate reports but fail to drive improvement. This is one reason mature organizations increasingly focus on audit effectiveness rather than audit completion.

Conclusion: Internal Audits Should Expose Problems Before Regulators or Certification Bodies Do

ISO 19011 gives auditors tremendous flexibility, but that flexibility is not a free pass for weak auditing. The standard uses “shall” only once, and it has absolutely nothing to do with auditing. However, your organization, regulators, customers, and leadership teams will still expect your audits to uncover real risks, real weaknesses, and genuine opportunities for improvement. Using “shall” statements in your internal procedures is acceptable. ISO 19011 gives auditors the flexibility to design audits that reflect how organizations operate in the real world.

The true purpose of internal auditing is not to confirm that procedures exist. It is to determine whether the organization’s management system is:

  1. Functioning effectively
  2. Controlling risk
  3. Producing consistent outcomes

The uncomfortable reality is this:

If your internal audits never identify meaningful weaknesses, your audit program may not be working.

Learn More With SGS Training

Want to learn more? Visit the SGS Training Academy:

SGS USA Training

SGS Canada Training

News & Insights

  • SGS - USA - Bloomfield

400 Broadacres Drive,

Suite 200, 2nd Floor,

Bloomfield, New Jersey, 07003,

United States