I have finalised the demo for the ICH-GCP E6 R3 refresher course. Overall, I liked the content and the interface. I also want to thank Whitehall Train...
About
ISO 19011:2026 provides internationally recognised guidance for auditing management systems and serves as the foundation for planning, conducting, reporting, and improving internal audits across multiple management system standards. The updated guidance supports organisations in performing effective onsite, remote, and hybrid audits while promoting risk-based thinking, auditor competence, and continual improvement of audit programmes.
This ISO 19011:2026 Auditing Management Systems (Internal Auditor) Training Course & Certification provides comprehensive knowledge of the updated ISO 19011:2026 guidance, auditing principles, audit programme management, audit planning and preparation, evidence collection, sampling, interview techniques, onsite, remote and hybrid auditing, audit findings, reporting, corrective action follow-up, auditor competence, and the practical application of internal auditing across quality, environmental, occupational health and safety, information security, and GxP management systems. Upon successful completion, learners receive a certification demonstrating their understanding of ISO 19011:2026 internal auditing principles and best practices.
- Internal Auditors and Lead Internal Auditors
- Quality Assurance and Quality Management Professionals
- Compliance, Risk Management, and Governance Professionals
- Management System Coordinators and Process Owners
- Regulatory Affairs and GxP Compliance Professionals
- Managers, Supervisors, and Continuous Improvement Teams
- Professionals responsible for implementing or maintaining ISO management systems
- Anyone seeking to develop competence in internal management system auditing in accordance with ISO 19011:2026
What you will learn
Understand the principles of ISO 19011:2026, the auditing process, risk-based thinking, and the competencies required to perform effective internal management system audits.
Learn how to establish and manage audit programmes, plan and prepare audits, conduct onsite, remote, and hybrid audits, and gather objective evidence using appropriate sampling techniques.
Develop knowledge of audit communication, interview techniques, audit findings, nonconformity reporting, corrective action follow-up, auditor behaviour, and continual improvement of the audit process.
Gain practical understanding of auditor competence, audit documentation, reporting, and the application of ISO 19011:2026 across quality, environmental, health and safety, information security, and GxP management systems.
Course Syllabus
- 1.1 The purpose of ISO 19011:2026
- 1.1 Why this course focuses on the internal auditor
- 1.1 What management-system auditing means
- 1.1 Where the guidance applies
- 1.1 Programme management and auditor competence
- 1.1 Sector-neutral by design
- 1.2 Why a shared vocabulary matters
- 1.2 Audit and audit programme
- 1.2 Criteria, scope and objectives
- 1.2 Evidence, findings and conclusions
- 1.2 Audit client and auditee
- 1.2 Auditor, audit team and team leader
- 1.2 Technical expert, guide and observer
- 1.2 Terminology quick reference
- 1.3 Why audit type shapes everything
- 1.3 First, second and third party
- 1.3 Combined, joint and integrated audits
- 1.3 Onsite, remote and hybrid
- 1.3 Choosing modality by risk
- 1.4 ISO 19011 as the common auditing method
- 1.4 Alongside quality, environment, safety, security
- 1.4 In regulated life sciences
- 1.4 The certification-body boundary (17021)
- 1.4 Requirement versus guidance - the habit
- 1.5 Why the standard was revised
- 1.5 Change-status labels we will use
- 1.5 Remote and hybrid methods
- 1.5 Virtual locations
- 1.5 Digital technologies and digital evidence
- 1.5 Information security and confidentiality
- 1.5 Competence for modern technology
- 1.5 Audit-programme risk
- 1.5 Climate considerations
- 1.5 Alignment with TS 17012
- 1.6 Clearing common misconceptions
- 1.6 Myth - it certifies auditors or organisations
- 1.6 Myth - audit everything every year
- 1.6 Myth - every supplier onsite, remote always equal
- 1.6 Myth - fixed grading and auditor-written CAPA
- The principles of auditing
- Principles versus procedures
- Why principles protect the auditee too
- 2.1 Integrity - the foundation
- Integrity - honesty and responsibility
- Competence limits and declaring uncertainty
- Reporting truthfully under pressure
- 2.2 Fair presentation
- Reporting obstacles and limitations
- Diverging opinions and unresolved issues
- 2.3 Due professional care
- Proportionate effort and preparation
- Judgement and evaluating evidence
- 2.4 Confidentiality - security of information
- Categories of sensitive information
- Digital sharing and secure storage
- Remote access, retention and destruction
- 2.5 Independence, objectivity, impartiality
- Self-review threats and conflicts of interest
- Reporting lines and organisational independence
- Small-organisation limits and external auditors
- 2.6 Evidence-based approach
- Verifiable evidence and its qualities
- Sampling as a principle-level idea
- Traceability and contradictory evidence
- 2.7 Risk-based approach
- Programme risk - what raises it
- Method risk - remote, hybrid and outsourced
- 2.8 Auditor behaviour
- Openness, observation and perception
- Diplomacy, collaboration and cultural sensitivity
- Tenacity, decisiveness and self-reliance
- Principles across first-, second- and third-party audits
- Due care in preparation
- Confidentiality - legal and contractual duties
- Objectivity - recognising and managing bias
- Reliability of digital evidence
- Ethical conduct and professional demeanour
- The principles as one system
- Applying the principles in GxP settings
- What an audit programme is
- Why a programme exists: organisational objectives
- Purpose: regulatory and customer drivers
- Purpose: improvement and change oversight
- First-, second- and third-party programmes
- Writing a programme purpose statement
- Setting programme objectives
- Objectives: conformity and effectiveness
- Objectives: risk controls and suppliers
- Objectives: supporting improvement and integration
- Assessing the degree of implementation
- Writing measurable programme objectives
- Defining programme scope
- Scope: sites, functions and processes
- Scope: suppliers and jurisdictions
- Scope: remote, shared and cloud environments
- Stating boundaries and exclusions
- Interfaces and integrated systems in scope
- The risk-based approach to scheduling
- Risk inputs: criticality and impact
- Risk inputs: history and performance
- Risk inputs: change and new technology
- Risk inputs: suppliers and continuity
- Turning risk inputs into a schedule
- Frequency versus depth
- Data integrity as a scheduling driver
- Documenting and defending the schedule
- Risks to the programme itself
- Programme risks: planning and competence
- Programme risks: sampling and technology
- Programme risks: access and follow-up
- Opportunities to strengthen the programme
- Confidentiality and information security
- Resourcing the programme
- Resources: people and expertise
- Resources: time, budget and travel
- Resources: technology and secure access
- Selecting competent auditors
- Independence and objectivity in resourcing
- Who does what in the programme
- The audit-programme manager
- Audit client, lead auditor and team
- Technical experts, owners and quality
- Senior management's part in the programme
- Mapping responsibilities across the programme
- Monitoring the programme
- KPIs: delivery and timeliness
- KPIs: quality and outcomes
- KPIs: feedback, resources and remote effectiveness
- From measures to improvement
- Trending results into management review
- Initiating the individual audit
- Audit authority and the audit client
- Testing feasibility before you commit
- Initial contact with the auditee
- Independence and impartiality in preparation
- Competence for this particular audit
- Access, resources and confidentiality
- Why audit objectives come first
- Common types of audit objective
- Writing a measurable objective
- What audit scope defines
- Boundaries, inclusions and exclusions
- Sites, virtual locations and technologies
- Outsourced activities in scope
- What audit criteria are
- Selecting the right criteria
- How objective, scope and criteria connect
- Guidance is not the criterion
- Why review documents before the audit
- What documented information to review
- Reviewing electronic and system information
- Judging adequacy from the documents
- Planning around processes, not just clauses
- Analysing a process for the plan
- Interfaces and hand-offs
- Conformity and effectiveness together
- What an audit trail is
- Types of audit trail
- Forward versus backward tracing
- Following a data or electronic trail
- What checklists are good for
- The checklist trap
- Adapting questions during the audit
- Asking effective audit questions
- Why auditors sample
- The main sampling methods
- Judgement versus statistical sampling
- Risk-based and stratified sampling
- Sampling electronic records and large datasets
- Sample size, rationale and records
- One sample never proves universal conformity
- The purpose of the audit plan
- What goes into an audit plan
- Making the plan proportionate
- Timetable, sequence and logistics
- Confidentiality and information handling
- Communicating and agreeing the plan
- Building in flexibility and contingency
- Preparation as one connected discipline
- Purpose of the opening meeting
- Introductions and roles
- Confirming objectives, scope and criteria
- Schedule, logistics and communication
- Confidentiality, safety and escalation
- Guides and observers
- Reporting arrangements and escalation route
- Keeping the audit team aligned
- Progress updates to the auditee
- Emerging issues, scope changes and obstacles
- Immediate risks, disagreements and confidentiality
- Questioning as an evidence tool
- Open, probing and clarifying questions
- Closed and reflective questions
- Structuring an interview - the funnel
- Silence, active listening and neutral language
- Reading difficult interviews
- Defensive, talkative and minimal-answer auditees
- Contradictions and hostile behaviour
- Language, seniority and emotion
- Why observation is powerful evidence
- What to observe
- Status, segregation and physical controls
- Behaviour, records-in-the-making and the observer effect
- Recording what you observe
- Documents versus records
- Approved, obsolete and version-controlled documents
- Records - signatures, metadata and audit trails
- Access logs, calculations, trends and exceptions
- Judging the reliability of digital evidence
- Cross-referencing documents, records and reality
- Objective, verifiable evidence
- Triangulation - combining sources
- When evidence conflicts
- Onsite, remote or hybrid - the decision
- Feasibility - objectives and the need to observe
- Feasibility - technology, connectivity and time zones
- Feasibility - confidentiality, legal and data sensitivity
- Feasibility - auditee competence and evidence availability
- The remote toolkit
- Choosing the right remote method for the objective
- Virtual tours and live system demonstrations
- Remote interviews and recorded evidence
- Data analytics and collaborative tools
- Protecting digital information remotely
- Platforms, encryption and access control
- Temporary access, recording and download restrictions
- Identity, data location, retention and incident response
- What a hybrid audit is
- Dividing the activities
- Sequencing and handover in a hybrid audit
- Remote is not onsite - inherent limits
- Connection failure and camera coverage
- Selected-evidence bias and informal practice
- Restricted system access and contingency planning
- Converting to onsite and documenting limitations
- What counts as audit evidence
- Nine qualities of sound evidence
- Relevance and reliability
- Sufficiency: how much is enough
- Verifiability, accuracy and completeness
- Timeliness, traceability and representativeness
- Triangulation: corroborate across sources
- Digital evidence: the modern default
- Authenticity and source system
- User identity and access controls
- Metadata, time stamps and audit trails
- Version history and data extraction
- Manipulation risk and completeness
- From evidence to finding: a disciplined method
- Steps 1-3: criterion, expectation, evidence
- Steps 4-6: verify, compare, decide gap
- Steps 7-8: scope, significance and discussion
- Steps 9-10: record evidence and conclude
- The ten steps at a glance
- Recognising conformity
- Effective implementation, not just documented
- Good practices and strengths
- What a nonconformity requires
- Nonconformity is not disagreement
- Objective evidence: the second leg
- Structuring the nonconformity statement
- A worked nonconformity statement
- Describe the requirement, do not copy it
- Link every finding to its criterion
- Grading: no universal ISO model
- Grade to defined, consistent criteria
- What legitimately drives severity
- Do not inflate findings
- Do not blindly combine weak findings
- Grading judgement: a summary
- Observations and opportunities for improvement
- OFI versus nonconformity
- Do not disguise a nonconformity as an OFI
- Do not drift into consultancy
- OFIs: value with discipline
- Findings versus root cause
- Auditors may test the investigation
- Do not prescribe the corrective action
- Why the boundary protects the audit
- Staying helpful without crossing the line
- Common weak findings: an overview
- Missing criterion or missing evidence
- Opinion as fact, and vague wording
- Excessive narrative and unsupported generalisation
- Prescribed solutions and person-focused blame
- Wrong grading, mixed issues, and lazy phrases
- Self-review before the closing meeting
- Weighting sources: records, statements, observation
- Handling evidence in remote and hybrid audits
- Recording evidence so findings survive
- From evidence and findings to the report
- From findings to audit conclusions
- Revisit objectives, scope and criteria before you conclude
- Weighing the body of evidence
- Degree of conformity and system effectiveness
- Uncertainty and sampling limitations
- Recurring issues and unresolved differences
- Purpose of the closing meeting
- Who attends and setting the tone
- Presenting scope, method and positive findings
- Presenting nonconformities and observations
- Limitations, reporting process, deadlines and follow-up
- Questions and handling disagreement in the room
- Why disagreements arise
- Listen, clarify the evidence, review the criteria
- Audit-team discussion and recording unresolved views
- Escalation and maintaining professionalism
- The audit report - purpose and qualities
- Report identification and context
- Audit team, participants and methods
- Summary, findings and conclusions
- Stating limitations clearly
- Distribution, confidentiality and follow-up
- The response lifecycle - an overview
- Correction and containment
- Root cause analysis
- Corrective action versus correction - the critical distinction
- Preventive improvement and extending the fix
- Owners, due dates and evidence
- The auditor's role - evaluate, never own
- Immediate control and impact assessment
- Root-cause adequacy and scope
- Proportionality, responsibilities and timelines
- Evidence, recurrence risk and systemic impact
- Choosing a follow-up method
- Documentary and remote follow-up
- Targeted onsite follow-up and re-audit
- Sampling, data review, interview and the routine next audit
- What closure means
- The evidence required to close
- Close on effectiveness, not merely on completion
- Approval and updated records
- Why trend audit results
- What to trend - findings, processes, sites and suppliers
- Trending the harder signals
- Trending remote-audit limitations honestly
- Turning audits into value
- Identifying meaningful risk and supporting results
- Improving performance and preventing recurrence
- Informing management and strengthening supplier oversight
- Supporting continual improvement and programme performance
- 8.1 Competence is fitness for the audit at hand
- 8.1 The two halves: personal attributes and knowledge/skills
- 8.1 Personal behaviour under pressure
- 8.1 Knowledge and skills the modern auditor needs
- 8.1 Management-system and sector knowledge
- 8.1 Legal, regulatory and process awareness
- 8.1 New in 2026: technology, digital and remote-audit competence
- 8.1 Communication and the human skills
- 8.2 A four-step approach to evaluating competence
- 8.2 The evaluation methods - and what each reveals
- 8.2 Witnessed audits and interviews
- 8.2 Setting proportionate evaluation criteria
- 8.3 Competence decays without maintenance
- 8.3 Continuing professional development
- 8.3 Peer review, calibration and audit-log maintenance
- 8.3 Re-evaluation when the ground shifts
- 8.4 The lead auditor's job in one line
- 8.4 Selecting and allocating the team
- 8.4 Coordinating the team during fieldwork
- 8.4 Assuring finding consistency across the team
- 8.4 Managing difficult interviews and conflict
- 8.5 What a technical expert is - and is not
- 8.5 Directing an expert without losing control
- 8.5 Independence and confidentiality for experts
- 8.6 What an integrated audit is
- 8.6 Combining evidence, avoiding duplication
- 8.6 Criteria-specific findings
- 8.6 Clear reporting for integrated audits
- 8.7 Technology competence: awareness, not certification
- 8.7 Cloud platforms and electronic records
- 8.7 Video platforms and secure remote access
- 8.7 Data analytics as an evidence source
- 8.7 Automated and AI-supported processes - what the auditor does
- 8.7 Cybersecurity and information-protection awareness
- 8.8 The 2024 Climate Action Amendment in context
- 8.8 Determining whether climate is applicable
- 8.8 Reviewing evidence against defined criteria
- 8.9 Applying the guidance across the GxP world
- 8.10 A ten-step roadmap to adopt ISO 19011:2026
- 8.10 Steps 1-3: gap assessment, procedures, programme
- 8.10 Steps 4-6: remote controls, competence matrix, training
- 8.10 Steps 7-8: template revision and pilot audit
- 8.10 Steps 9-10: metrics and management review
- 📘 Bonus:ISO 19011:2026 - Auditing Management Systems eBook (Free with purchase)
Course Benefits

Get our exclusive eBook with every purchase - a complete companion guide to the course, yours to keep forever
Gain Continuing Professional Development (CPD) Points, accredited by The Faculty of Pharmaceutical Medicine of the Royal College of Physicians of the United Kingdom. These can be used to count towards the distance learning element of any scheme that comes under the umbrella of The Academy of Medical Royal Colleges or any other scheme for which there is mutual recognition.
Receive a personal certificate to show your subject knowledge on course completion.
You get excellent value through our cost-effective prices. We can also offer you group discounts on larger purchases.
The course saves you time through the convenience of online availability. This lets you complete the interactive course at your own comfort.
You will stay up to date with developments around ISO 19011:2026, ISO/IEC TS 17012:2024 on remote auditing, the 2024 Climate Action Amendment and related GxP expectations, as our training courses are constantly monitored, reviewed and updated.
The course content has been developed by quality-assurance and auditing practitioners to ensure that learners can plan, conduct and follow up management-system audits in line with the guidance of ISO 19011:2026.
Our Certified Customers
Learner Rating & Reviews
Recommended Courses

Essentials of EU MDR
Professional
Good Clinical Laboratory Practice (GCLP)
Intermediate
Computer System Validation - Validation, Data Integrity & Compliance (GAMP 5 & Annex 11)
Intermediate
Good Documentation Practices and Data Integrity
Beginner


