ISO 19011:2018
- By : Admin
- 15 October 18, 14:37
ISO 19011 is an international standard that puts forward the guidelines for auditing management systems. The standard is applicable to a wide range of users, including, among others, organizations that need to conduct internal and/or external management system (MS) audits and manage audit programs. The standard covers the principles of auditing and provides a broader harmonized approach to management system auditing and comprehensive guidance on how to conduct a management system audit. Notwithstanding that this guidance is intended to be flexible, it should be adapted as appropriate to the scope, complexity and scale of the audit program and/or the organization to be audited. While ISO/IEC 17021-1 sets forth the requirements for bodies providing audit and certification of management systems, it can also provide additional guidance on how to conduct management system audits. ISO 19011 was first published in 2002 and it was used as a guideline for quality (ISO 9001) and/or environmental (ISO 14001) management systems auditing. The number of management system standards that have a common structure and core definitions has increased, along with the need to consider a broader approach to the audit of management systems. To reflect both the structure and the content of new management system standards, ISO 19011 has been updated.
The 2018 version of the standard has placed an enhanced focus on the utmost newly added principle – the risk-based approach – which considers risks and opportunities during the planning, conducting and reporting phases of an audit. In order to ensure that audits are focused on matters that are significant for the audit client, and for achieving the audit programme objectives, the risk needs to be considered from the design of the audit programme to the issue of the audit report. The application of the risk-based approach can serve as a tool for risk prevention, and optimization of the efficiency and effectiveness of the audit process and its outcome(s).
This principle has intertwined with the structure of the rest of the document, specifically Section 5 – Managing an audit programme, which suggests that when preparing an audit programme, moderate consideration should be given to the identified risks and opportunities, as well as the actions taken to address them.