Auditing and Management Systems
ISO 19011: Guidelines for Auditing Management Systems
ISO 19011 gives guidance on auditing management systems. It is not a requirements standard and organizations don't seek certification to it. It is the reference for planning an audit program, running individual audits well and judging whether auditors are competent.
At a Glance
- Standard
- ISO 19011
- Subject
- Guidelines for Auditing Management Systems
- Group
- Auditing and Management Systems
- Industries
- 1 industry guides reference it
A plain-language summary of scope, not the standard itself. Buy the current edition from the publisher and check which edition your auditor or market expects.
What It Covers
The guidance starts with principles of auditing, such as integrity, fair presentation, due professional care, confidentiality, independence and an evidence-based approach, along with a risk-based approach to the audit itself. It then covers managing an audit program: setting objectives, identifying the program's risks and opportunities, assigning resources, and monitoring and improving the program over time.
For individual audits, it describes initiating, preparing, conducting (opening meeting, collecting and verifying information, generating findings, closing meeting), reporting and follow-up. It also addresses auditor competence: the knowledge and skills auditors need, including knowledge of the discipline being audited, and how to evaluate them.
Device manufacturers use it to design internal audit programs and supplier audits that hold up to scrutiny. Under the QMSR, internal audit and supplier audit records are open to FDA inspection, so an audit program that follows a recognized approach and produces clear, evidence-based findings matters more than it used to.
Who It Applies To
- Quality teams designing or rebuilding an internal audit program
- Supplier quality engineers planning supplier audits
- Auditors who need a reference for audit conduct and competence
- Organizations auditing integrated management systems
What Auditors Check
Risk-Based Audit Schedule
A schedule that covers the whole QMS over a defined period and shifts attention toward problem areas and recent changes.
Auditor Independence
Auditors who don't audit their own work, and documented reasoning where a small team makes that difficult.
Auditor Competence
Training and qualification records showing each auditor's knowledge of auditing and of the processes they audit.
Audit Plans and Evidence
A plan for each audit, and working notes or checklists that show what was actually sampled.
Findings and Follow-Up
Clear findings tied to objective evidence, followed by corrections, corrective actions and verification of their effectiveness.
Program Review
Periodic review of the audit program itself, with changes made based on what the audits found.
Related Services
Internal Audit Program
A risk-based internal audit program, run by your team or our advisors, with reports written for FDA to read.
Supplier Audits and Supplier Controls
Risk-based supplier selection, quality agreements, monitoring and supplier audits that hold up under QMSR.
Mock FDA Inspection
A practice FDA inspection in our Inspection Simulator, with an advisor playing the investigator.
Industry Guides That Reference ISO 19011
Questions
Is ISO 19011 mandatory for our internal audits?
No. ISO 13485 and the QMSR require an internal audit program, but neither makes ISO 19011 mandatory. It's widely used as guidance because it gives a clear, recognized structure for planning, running and following up audits and for qualifying auditors.
Can FDA see our internal audit reports now?
Yes. Under the QMSR, internal audit, management review and supplier audit records are open to FDA inspection, because the former exception for them was removed. The quality of your audit findings and follow-up is now visible to investigators.
Do our internal auditors need an outside credential?
No specific external credential is required. What you need is documented evidence that each auditor is competent in auditing and in the processes they audit, and is independent of the work being audited. ISO 19011's competence guidance is a practical way to define and record that.
How is a mock inspection different from an internal audit?
An internal audit samples the QMS against requirements using a planned approach. A mock inspection is a practice exercise that simulates how an FDA investigator works: document requests on a clock, interviews and a closeout. The two complement each other, and both can feed findings into the same action plan.
ISO 19011
Check Your Quality System Against ISO 19011
An AI-assisted first pass maps your existing documents against the requirements in scope, and an advisor reviews every result. Please don't send confidential documents yet: secure upload is set up after onboarding.


