BS EN ISO 19011:2026, Guidelines for auditing management systems, is the current British Standard. ISO published the revision on 27 May 2026 and BSI adopted it on 9 June 2026, superseding BS EN ISO 19011:2018, which is now withdrawn. If your internal audit procedure cites the 2018 edition, the citation is out of date. Whether your audits are out of date is a different question, and mostly the answer is no.
What ISO 19011 is, and is not
ISO 19011 is guidance. It is not a requirements standard and nobody is certified to it. ISO 9001:2015 does not even list it as a normative reference; it appears in the bibliography. The requirement to audit comes from clause 9.2 of ISO 9001, and its equivalents in ISO 45001 and ISO 14001: plan an audit programme, define criteria and scope, select auditors who are objective and impartial, report to management, correct what is found, keep the records. ISO 19011 tells you how to do those things well. So a change to ISO 19011 changes the advice, not the obligation.
What we have and have not checked
We have verified that the 2026 edition is current and that the 2018 edition is withdrawn, on the NBS Publication Index and against the release dates on en-standard.eu. We have not yet walked the 2026 text against the 2018 text line by line, and until we have we are not going to tell you which clauses moved or what new guidance was added. The 2018 edition set out seven principles of auditing (integrity, fair presentation, due professional care, confidentiality, independence, the evidence-based approach and, new in 2018, the risk-based approach), a clause on managing the audit programme, one on conducting an audit and one on auditor competence. Whether the 2026 text keeps that shape we cannot say yet. When we have read it, we will say so here.
In the meantime we have changed the citations. The internal audit procedure in the Quality Audit & Reporting Pack (QA-201) and the audit checklist Read Me in the ISO 45001 Construction OHSMS now cite ISO 19011:2026, with a note that the checklist questions were written to the 2018 process and have not yet been checked against the 2026 text. A note that admits what has not been done is worth more to an auditor than a citation that pretends.
The audit programme steps that do not depend on the text
These are the things that make an internal audit programme work on a construction contractor, and none of them will be changed by a revision of the guidance, because they come from the requirements standards and from what auditors actually find.
- Plan by risk, not by calendar. An audit programme that visits every clause once a year in alphabetical order is a calendar, not a programme. Weight it towards the processes where failure costs most: hold points, subcontractor control, calibration, nonconformance, and the trade with the most NCRs last quarter. Record the reasoning on the programme so an external auditor can see it.
- Write the criteria before the audit. Every checklist question names the requirement and where it comes from: the ITP line, the specification clause, the standard and its clause at the current edition. A question that does not cite its source cannot be failed fairly.
- Audit evidence, not opinion. Each finding records the objective evidence: the document number, the location, the photograph, the name of the person interviewed. "Housekeeping poor" is an opinion. "Cable drums stored on bare ground at grid C4, contrary to the materials control plan section 5, photograph 12" is a finding.
- Independence. The person who runs a process does not audit it. On a small contractor that means the site manager audits the office, the QS audits the site, and the director audits neither. If there is genuinely nobody independent, a half-day from an external auditor once a year is cheaper than a major nonconformity.
- Grade findings consistently. Major, minor, observation, with the definitions written on the checklist. A major is a requirement absent or broken down; a minor is an isolated lapse in a process that otherwise works; an observation conforms but carries a risk.
- Root cause before close-out. An NCR closed with "operative reminded" will reopen. Ask why until the answer is a process, a resource or a decision, and correct that.
- Report upwards and prove it. Audit results are a required input to management review. Take the findings, the trends and the overdue actions into the review and minute what was decided.
- Auditor competence on record. A training record, a witnessed audit, or a lead auditor certificate. The auditor's competence is one of the first things a certification body checks.
What to do this month
Change the citation in your internal audit procedure to ISO 19011:2026, add a note that the process has not yet been reviewed against the new text, and put the review on your document register as a planned change with a date. Buy the standard when your budget allows; it is guidance, so nobody will fail you for not owning it, but you cannot check your procedure against text you have not read. Then keep auditing. A programme with completed audits, findings closed at root cause and results in management review satisfies clause 9.2 whatever edition of the guidance is on the shelf.
ISO 9001 itself has also been revised this month. That one does carry obligations, and it has its own post.
Where this leaves you
The Quality Audit & Reporting Pack has ten scored trade audit checklists, the programme builder, the findings tracker and the monthly report, cited at the current edition and with the ISO 19011:2026 note in the procedure. Read the free ITP first if you want to see the standard of the writing.
Written by Craig Collier, MCIOB, CQP MCQI, MAPM, Director of StructAssure Ltd. Published 14 September 2026; standards and regulations as read on that date.
