Buy the GCP R3 course & get a FREE eBook— your complete ICH-GCP R3 reference guide. Book Now →

  • Preclinical & Laboratory Foundations Learning Path
  • Phase I – First-in-Human Trials Learning Path
  • Phase II & III – Efficacy & Pivotal Trials Learning Path
  • Clinical Trials Foundation PathNew
  • Regulatory Submission & Approval

About

ISO 19011:2026 provides internationally recognised guidance for auditing management systems and serves as the foundation for planning, conducting, reporting, and improving internal audits across multiple management system standards. The updated guidance supports organisations in performing effective onsite, remote, and hybrid audits while promoting risk-based thinking, auditor competence, and continual improvement of audit programmes.
This ISO 19011:2026 Auditing Management Systems (Internal Auditor) Training Course & Certification provides comprehensive knowledge of the updated ISO 19011:2026 guidance, auditing principles, audit programme management, audit planning and preparation, evidence collection, sampling, interview techniques, onsite, remote and hybrid auditing, audit findings, reporting, corrective action follow-up, auditor competence, and the practical application of internal auditing across quality, environmental, occupational health and safety, information security, and GxP management systems. Upon successful completion, learners receive a certification demonstrating their understanding of ISO 19011:2026 internal auditing principles and best practices.

Who Should Enrol?

  • Internal Auditors and Lead Internal Auditors
  • Quality Assurance and Quality Management Professionals
  • Compliance, Risk Management, and Governance Professionals
  • Management System Coordinators and Process Owners
  • Regulatory Affairs and GxP Compliance Professionals
  • Managers, Supervisors, and Continuous Improvement Teams
  • Professionals responsible for implementing or maintaining ISO management systems
  • Anyone seeking to develop competence in internal management system auditing in accordance with ISO 19011:2026
📢 Every purchase also includes our FREE companion ISO 19011:2026 - Auditing Management Systems eBook, designed to help you apply principles in real-world inspection readiness settings.

What you will learn

Understand the principles of ISO 19011:2026, the auditing process, risk-based thinking, and the competencies required to perform effective internal management system audits.

Learn how to establish and manage audit programmes, plan and prepare audits, conduct onsite, remote, and hybrid audits, and gather objective evidence using appropriate sampling techniques.

Develop knowledge of audit communication, interview techniques, audit findings, nonconformity reporting, corrective action follow-up, auditor behaviour, and continual improvement of the audit process.

Gain practical understanding of auditor competence, audit documentation, reporting, and the application of ISO 19011:2026 across quality, environmental, health and safety, information security, and GxP management systems.

Course Syllabus

  1. 1.1 The purpose of ISO 19011:2026
  2. 1.1 Why this course focuses on the internal auditor
  3. 1.1 What management-system auditing means
  4. 1.1 Where the guidance applies
  5. 1.1 Programme management and auditor competence
  6. 1.1 Sector-neutral by design
  7. 1.2 Why a shared vocabulary matters
  8. 1.2 Audit and audit programme
  9. 1.2 Criteria, scope and objectives
  10. 1.2 Evidence, findings and conclusions
  11. 1.2 Audit client and auditee
  12. 1.2 Auditor, audit team and team leader
  13. 1.2 Technical expert, guide and observer
  14. 1.2 Terminology quick reference
  15. 1.3 Why audit type shapes everything
  16. 1.3 First, second and third party
  17. 1.3 Combined, joint and integrated audits
  18. 1.3 Onsite, remote and hybrid
  19. 1.3 Choosing modality by risk
  20. 1.4 ISO 19011 as the common auditing method
  21. 1.4 Alongside quality, environment, safety, security
  22. 1.4 In regulated life sciences
  23. 1.4 The certification-body boundary (17021)
  24. 1.4 Requirement versus guidance - the habit
  25. 1.5 Why the standard was revised
  26. 1.5 Change-status labels we will use
  27. 1.5 Remote and hybrid methods
  28. 1.5 Virtual locations
  29. 1.5 Digital technologies and digital evidence
  30. 1.5 Information security and confidentiality
  31. 1.5 Competence for modern technology
  32. 1.5 Audit-programme risk
  33. 1.5 Climate considerations
  34. 1.5 Alignment with TS 17012
  35. 1.6 Clearing common misconceptions
  36. 1.6 Myth - it certifies auditors or organisations
  37. 1.6 Myth - audit everything every year
  38. 1.6 Myth - every supplier onsite, remote always equal
  39. 1.6 Myth - fixed grading and auditor-written CAPA

  1. The principles of auditing
  2. Principles versus procedures
  3. Why principles protect the auditee too
  4. 2.1 Integrity - the foundation
  5. Integrity - honesty and responsibility
  6. Competence limits and declaring uncertainty
  7. Reporting truthfully under pressure
  8. 2.2 Fair presentation
  9. Reporting obstacles and limitations
  10. Diverging opinions and unresolved issues
  11. 2.3 Due professional care
  12. Proportionate effort and preparation
  13. Judgement and evaluating evidence
  14. 2.4 Confidentiality - security of information
  15. Categories of sensitive information
  16. Digital sharing and secure storage
  17. Remote access, retention and destruction
  18. 2.5 Independence, objectivity, impartiality
  19. Self-review threats and conflicts of interest
  20. Reporting lines and organisational independence
  21. Small-organisation limits and external auditors
  22. 2.6 Evidence-based approach
  23. Verifiable evidence and its qualities
  24. Sampling as a principle-level idea
  25. Traceability and contradictory evidence
  26. 2.7 Risk-based approach
  27. Programme risk - what raises it
  28. Method risk - remote, hybrid and outsourced
  29. 2.8 Auditor behaviour
  30. Openness, observation and perception
  31. Diplomacy, collaboration and cultural sensitivity
  32. Tenacity, decisiveness and self-reliance
  33. Principles across first-, second- and third-party audits
  34. Due care in preparation
  35. Confidentiality - legal and contractual duties
  36. Objectivity - recognising and managing bias
  37. Reliability of digital evidence
  38. Ethical conduct and professional demeanour
  39. The principles as one system
  40. Applying the principles in GxP settings

  1. What an audit programme is
  2. Why a programme exists: organisational objectives
  3. Purpose: regulatory and customer drivers
  4. Purpose: improvement and change oversight
  5. First-, second- and third-party programmes
  6. Writing a programme purpose statement
  7. Setting programme objectives
  8. Objectives: conformity and effectiveness
  9. Objectives: risk controls and suppliers
  10. Objectives: supporting improvement and integration
  11. Assessing the degree of implementation
  12. Writing measurable programme objectives
  13. Defining programme scope
  14. Scope: sites, functions and processes
  15. Scope: suppliers and jurisdictions
  16. Scope: remote, shared and cloud environments
  17. Stating boundaries and exclusions
  18. Interfaces and integrated systems in scope
  19. The risk-based approach to scheduling
  20. Risk inputs: criticality and impact
  21. Risk inputs: history and performance
  22. Risk inputs: change and new technology
  23. Risk inputs: suppliers and continuity
  24. Turning risk inputs into a schedule
  25. Frequency versus depth
  26. Data integrity as a scheduling driver
  27. Documenting and defending the schedule
  28. Risks to the programme itself
  29. Programme risks: planning and competence
  30. Programme risks: sampling and technology
  31. Programme risks: access and follow-up
  32. Opportunities to strengthen the programme
  33. Confidentiality and information security
  34. Resourcing the programme
  35. Resources: people and expertise
  36. Resources: time, budget and travel
  37. Resources: technology and secure access
  38. Selecting competent auditors
  39. Independence and objectivity in resourcing
  40. Who does what in the programme
  41. The audit-programme manager
  42. Audit client, lead auditor and team
  43. Technical experts, owners and quality
  44. Senior management's part in the programme
  45. Mapping responsibilities across the programme
  46. Monitoring the programme
  47. KPIs: delivery and timeliness
  48. KPIs: quality and outcomes
  49. KPIs: feedback, resources and remote effectiveness
  50. From measures to improvement
  51. Trending results into management review

  1. Initiating the individual audit
  2. Audit authority and the audit client
  3. Testing feasibility before you commit
  4. Initial contact with the auditee
  5. Independence and impartiality in preparation
  6. Competence for this particular audit
  7. Access, resources and confidentiality
  8. Why audit objectives come first
  9. Common types of audit objective
  10. Writing a measurable objective
  11. What audit scope defines
  12. Boundaries, inclusions and exclusions
  13. Sites, virtual locations and technologies
  14. Outsourced activities in scope
  15. What audit criteria are
  16. Selecting the right criteria
  17. How objective, scope and criteria connect
  18. Guidance is not the criterion
  19. Why review documents before the audit
  20. What documented information to review
  21. Reviewing electronic and system information
  22. Judging adequacy from the documents
  23. Planning around processes, not just clauses
  24. Analysing a process for the plan
  25. Interfaces and hand-offs
  26. Conformity and effectiveness together
  27. What an audit trail is
  28. Types of audit trail
  29. Forward versus backward tracing
  30. Following a data or electronic trail
  31. What checklists are good for
  32. The checklist trap
  33. Adapting questions during the audit
  34. Asking effective audit questions
  35. Why auditors sample
  36. The main sampling methods
  37. Judgement versus statistical sampling
  38. Risk-based and stratified sampling
  39. Sampling electronic records and large datasets
  40. Sample size, rationale and records
  41. One sample never proves universal conformity
  42. The purpose of the audit plan
  43. What goes into an audit plan
  44. Making the plan proportionate
  45. Timetable, sequence and logistics
  46. Confidentiality and information handling
  47. Communicating and agreeing the plan
  48. Building in flexibility and contingency
  49. Preparation as one connected discipline

  1. Purpose of the opening meeting
  2. Introductions and roles
  3. Confirming objectives, scope and criteria
  4. Schedule, logistics and communication
  5. Confidentiality, safety and escalation
  6. Guides and observers
  7. Reporting arrangements and escalation route
  8. Keeping the audit team aligned
  9. Progress updates to the auditee
  10. Emerging issues, scope changes and obstacles
  11. Immediate risks, disagreements and confidentiality
  12. Questioning as an evidence tool
  13. Open, probing and clarifying questions
  14. Closed and reflective questions
  15. Structuring an interview - the funnel
  16. Silence, active listening and neutral language
  17. Reading difficult interviews
  18. Defensive, talkative and minimal-answer auditees
  19. Contradictions and hostile behaviour
  20. Language, seniority and emotion
  21. Why observation is powerful evidence
  22. What to observe
  23. Status, segregation and physical controls
  24. Behaviour, records-in-the-making and the observer effect
  25. Recording what you observe
  26. Documents versus records
  27. Approved, obsolete and version-controlled documents
  28. Records - signatures, metadata and audit trails
  29. Access logs, calculations, trends and exceptions
  30. Judging the reliability of digital evidence
  31. Cross-referencing documents, records and reality
  32. Objective, verifiable evidence
  33. Triangulation - combining sources
  34. When evidence conflicts
  35. Onsite, remote or hybrid - the decision
  36. Feasibility - objectives and the need to observe
  37. Feasibility - technology, connectivity and time zones
  38. Feasibility - confidentiality, legal and data sensitivity
  39. Feasibility - auditee competence and evidence availability
  40. The remote toolkit
  41. Choosing the right remote method for the objective
  42. Virtual tours and live system demonstrations
  43. Remote interviews and recorded evidence
  44. Data analytics and collaborative tools
  45. Protecting digital information remotely
  46. Platforms, encryption and access control
  47. Temporary access, recording and download restrictions
  48. Identity, data location, retention and incident response
  49. What a hybrid audit is
  50. Dividing the activities
  51. Sequencing and handover in a hybrid audit
  52. Remote is not onsite - inherent limits
  53. Connection failure and camera coverage
  54. Selected-evidence bias and informal practice
  55. Restricted system access and contingency planning
  56. Converting to onsite and documenting limitations

  1. What counts as audit evidence
  2. Nine qualities of sound evidence
  3. Relevance and reliability
  4. Sufficiency: how much is enough
  5. Verifiability, accuracy and completeness
  6. Timeliness, traceability and representativeness
  7. Triangulation: corroborate across sources
  8. Digital evidence: the modern default
  9. Authenticity and source system
  10. User identity and access controls
  11. Metadata, time stamps and audit trails
  12. Version history and data extraction
  13. Manipulation risk and completeness
  14. From evidence to finding: a disciplined method
  15. Steps 1-3: criterion, expectation, evidence
  16. Steps 4-6: verify, compare, decide gap
  17. Steps 7-8: scope, significance and discussion
  18. Steps 9-10: record evidence and conclude
  19. The ten steps at a glance
  20. Recognising conformity
  21. Effective implementation, not just documented
  22. Good practices and strengths
  23. What a nonconformity requires
  24. Nonconformity is not disagreement
  25. Objective evidence: the second leg
  26. Structuring the nonconformity statement
  27. A worked nonconformity statement
  28. Describe the requirement, do not copy it
  29. Link every finding to its criterion
  30. Grading: no universal ISO model
  31. Grade to defined, consistent criteria
  32. What legitimately drives severity
  33. Do not inflate findings
  34. Do not blindly combine weak findings
  35. Grading judgement: a summary
  36. Observations and opportunities for improvement
  37. OFI versus nonconformity
  38. Do not disguise a nonconformity as an OFI
  39. Do not drift into consultancy
  40. OFIs: value with discipline
  41. Findings versus root cause
  42. Auditors may test the investigation
  43. Do not prescribe the corrective action
  44. Why the boundary protects the audit
  45. Staying helpful without crossing the line
  46. Common weak findings: an overview
  47. Missing criterion or missing evidence
  48. Opinion as fact, and vague wording
  49. Excessive narrative and unsupported generalisation
  50. Prescribed solutions and person-focused blame
  51. Wrong grading, mixed issues, and lazy phrases
  52. Self-review before the closing meeting
  53. Weighting sources: records, statements, observation
  54. Handling evidence in remote and hybrid audits
  55. Recording evidence so findings survive
  56. From evidence and findings to the report

  1. From findings to audit conclusions
  2. Revisit objectives, scope and criteria before you conclude
  3. Weighing the body of evidence
  4. Degree of conformity and system effectiveness
  5. Uncertainty and sampling limitations
  6. Recurring issues and unresolved differences
  7. Purpose of the closing meeting
  8. Who attends and setting the tone
  9. Presenting scope, method and positive findings
  10. Presenting nonconformities and observations
  11. Limitations, reporting process, deadlines and follow-up
  12. Questions and handling disagreement in the room
  13. Why disagreements arise
  14. Listen, clarify the evidence, review the criteria
  15. Audit-team discussion and recording unresolved views
  16. Escalation and maintaining professionalism
  17. The audit report - purpose and qualities
  18. Report identification and context
  19. Audit team, participants and methods
  20. Summary, findings and conclusions
  21. Stating limitations clearly
  22. Distribution, confidentiality and follow-up
  23. The response lifecycle - an overview
  24. Correction and containment
  25. Root cause analysis
  26. Corrective action versus correction - the critical distinction
  27. Preventive improvement and extending the fix
  28. Owners, due dates and evidence
  29. The auditor's role - evaluate, never own
  30. Immediate control and impact assessment
  31. Root-cause adequacy and scope
  32. Proportionality, responsibilities and timelines
  33. Evidence, recurrence risk and systemic impact
  34. Choosing a follow-up method
  35. Documentary and remote follow-up
  36. Targeted onsite follow-up and re-audit
  37. Sampling, data review, interview and the routine next audit
  38. What closure means
  39. The evidence required to close
  40. Close on effectiveness, not merely on completion
  41. Approval and updated records
  42. Why trend audit results
  43. What to trend - findings, processes, sites and suppliers
  44. Trending the harder signals
  45. Trending remote-audit limitations honestly
  46. Turning audits into value
  47. Identifying meaningful risk and supporting results
  48. Improving performance and preventing recurrence
  49. Informing management and strengthening supplier oversight
  50. Supporting continual improvement and programme performance

  1. 8.1 Competence is fitness for the audit at hand
  2. 8.1 The two halves: personal attributes and knowledge/skills
  3. 8.1 Personal behaviour under pressure
  4. 8.1 Knowledge and skills the modern auditor needs
  5. 8.1 Management-system and sector knowledge
  6. 8.1 Legal, regulatory and process awareness
  7. 8.1 New in 2026: technology, digital and remote-audit competence
  8. 8.1 Communication and the human skills
  9. 8.2 A four-step approach to evaluating competence
  10. 8.2 The evaluation methods - and what each reveals
  11. 8.2 Witnessed audits and interviews
  12. 8.2 Setting proportionate evaluation criteria
  13. 8.3 Competence decays without maintenance
  14. 8.3 Continuing professional development
  15. 8.3 Peer review, calibration and audit-log maintenance
  16. 8.3 Re-evaluation when the ground shifts
  17. 8.4 The lead auditor's job in one line
  18. 8.4 Selecting and allocating the team
  19. 8.4 Coordinating the team during fieldwork
  20. 8.4 Assuring finding consistency across the team
  21. 8.4 Managing difficult interviews and conflict
  22. 8.5 What a technical expert is - and is not
  23. 8.5 Directing an expert without losing control
  24. 8.5 Independence and confidentiality for experts
  25. 8.6 What an integrated audit is
  26. 8.6 Combining evidence, avoiding duplication
  27. 8.6 Criteria-specific findings
  28. 8.6 Clear reporting for integrated audits
  29. 8.7 Technology competence: awareness, not certification
  30. 8.7 Cloud platforms and electronic records
  31. 8.7 Video platforms and secure remote access
  32. 8.7 Data analytics as an evidence source
  33. 8.7 Automated and AI-supported processes - what the auditor does
  34. 8.7 Cybersecurity and information-protection awareness
  35. 8.8 The 2024 Climate Action Amendment in context
  36. 8.8 Determining whether climate is applicable
  37. 8.8 Reviewing evidence against defined criteria
  38. 8.9 Applying the guidance across the GxP world
  39. 8.10 A ten-step roadmap to adopt ISO 19011:2026
  40. 8.10 Steps 1-3: gap assessment, procedures, programme
  41. 8.10 Steps 4-6: remote controls, competence matrix, training
  42. 8.10 Steps 7-8: template revision and pilot audit
  43. 8.10 Steps 9-10: metrics and management review

  1. 📘 Bonus:ISO 19011:2026 - Auditing Management Systems eBook (Free with purchase)

Course Benefits

Benefits ebook icon
Free eBook

Get our exclusive eBook with every purchase - a complete companion guide to the course, yours to keep forever

Benefits cpd_points icon
CPD Points

Gain Continuing Professional Development (CPD) Points, accredited by The Faculty of Pharmaceutical Medicine of the Royal College of Physicians of the United Kingdom. These can be used to count towards the distance learning element of any scheme that comes under the umbrella of The Academy of Medical Royal Colleges or any other scheme for which there is mutual recognition.

Benefits certification icon
Certification

Receive a personal certificate to show your subject knowledge on course completion.

Benefits affordable icon
Affordable

You get excellent value through our cost-effective prices. We can also offer you group discounts on larger purchases.

Benefits flexible icon
Flexibility

The course saves you time through the convenience of online availability. This lets you complete the interactive course at your own comfort.

Benefits up_to_date icon
Keep Up to Date

You will stay up to date with developments around ISO 19011:2026, ISO/IEC TS 17012:2024 on remote auditing, the 2024 Climate Action Amendment and related GxP expectations, as our training courses are constantly monitored, reviewed and updated.

Benefits industry_experts icon
Learn from Industry Experts

The course content has been developed by quality-assurance and auditing practitioners to ensure that learners can plan, conduct and follow up management-system audits in line with the guidance of ISO 19011:2026.


Our Certified Customers

novartis
NHS
takeda
roche
dhl

Learner Rating & Reviews

4.7
Average Rating
536 global ratings
87.0%
5.0%
3.0%
3.0%
2.0%
RC

Working with Whitehall training for the last two years of partnership has been a very successful experience – I have fast access to all the GCP course...

SM

I have finalised the demo for the ICH-GCP E6 R3 refresher course. Overall, I liked the content and the interface. I also want to thank Whitehall Train...