7.3 Audit Principles (ISO 19011)
Key Takeaways
- ISO 19011 sets out seven audit principles: integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, and risk-based approach
- Integrity and fair presentation require honest, accurate reporting of findings — including uncomfortable nonconformities
- Confidentiality protects auditee information; independence protects objectivity from bias and conflicts of interest
- Evidence-based auditing relies on verifiable objective evidence; risk-based auditing focuses effort where misstatements or EMS failures matter most
- Lead auditors apply all seven principles together throughout planning, execution, and reporting of ISO 14001 audits
7.3 Audit Principles (ISO 19011)
Quick Answer: ISO 19011’s seven principles — integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, and risk-based approach — are the ethical and methodological foundation of auditing. On the ISO 14001 Lead Auditor exam, expect scenarios that test whether you can name, distinguish, and apply each principle in EMS situations.
These principles are not optional soft skills. They underpin auditor competence, programme credibility, and certification integrity. If a principle is breached, audit conclusions become unreliable even when checklists look complete.
Overview of the Seven Principles
| Principle | Core idea | EMS one-liner |
|---|---|---|
| Integrity | Foundation of professionalism | Be honest even when a major spill-control failure will upset plant management |
| Fair presentation | Obligation to report truthfully and accurately | Report nonconformities and unresolved diverging opinions clearly |
| Due professional care | Diligence and judgment in auditing | Apply appropriate care given the importance of the task and auditee confidence |
| Confidentiality | Security of information | Do not share the auditee’s aspect register or permit data outside authorized channels |
| Independence | Basis for impartiality and objectivity | Do not audit your own environmental operational controls |
| Evidence-based approach | Rational method for reliable conclusions | Base findings on verifiable records, observations, and interviews |
| Risk-based approach | Focus on matters that matter | Sample high-significance aspects and weak controls more deeply |
1. Integrity
Integrity is the foundation of professionalism. Auditors should perform their work with honesty, diligence, and responsibility; observe legal requirements; demonstrate competence; remain impartial; and be sensitive to influences that may pressure judgment.
EMS example: During a certification audit, the plant manager offers to “take care of” hotel upgrades if the auditor softens wording on a missing evaluation-of-compliance record. Integrity requires declining the inducement and reporting the evidence-based finding. Integrity also means not accepting an audit assignment beyond your competence — for example, leading a complex multi-site ISO 14001 audit alone when you lack sector knowledge of chemical process safety environmental controls.
Integrity failures destroy trust faster than technical mistakes. A technically sharp auditor who conceals conflicts or alters findings is unfit for lead auditor roles.
2. Fair Presentation
Fair presentation is the obligation to report truthfully and accurately. Findings, conclusions, and reports should reflect the audit activities. Significant obstacles, unresolved diverging opinions between the audit team and auditee, and differing auditor opinions should be communicated.
EMS example: The audit team finds that environmental objectives were not updated after a major process change that introduced new solvent emissions. The auditee argues it is “only a paperwork lag.” Fair presentation means describing the condition against criteria (e.g., ISO 14001 clauses on objectives and planning of changes), not burying it as a vague suggestion. If one auditor believes the issue is a major nonconformity and another believes minor, the lead auditor ensures the divergence is resolved using evidence — or reported appropriately — rather than silently dropped.
Fair presentation also forbids selective reporting: omitting unfavorable findings while highlighting only positive observations to please the client.
3. Due Professional Care
Due professional care is the application of diligence and judgment in auditing. Auditors should exercise care in accordance with the importance of the task and the confidence placed in them by audit clients and other interested parties. Having the necessary competence is integral to this principle.
EMS example: Auditing a hazardous-waste accumulation area requires more than a quick glance at labels. Due care means checking accumulation dates, compatibility, secondary containment, training records for handlers, and emergency equipment — proportional to the environmental and compliance risk. Conversely, spending half the audit on office recycling bins while barely sampling wastewater treatment may fail due care relative to significant aspects.
Due professional care is not perfection. It is reasonable care by a competent auditor under the circumstances, including knowing when to escalate limitations (denied access, missing records, safety constraints).
4. Confidentiality
Confidentiality is the security of information. Auditors should be prudent with information obtained during the audit and not use it inappropriately for personal gain or in a manner harmful to the auditee’s legitimate interests. This includes handling sensitive documented information appropriately.
EMS example: An internal auditor copies the full compliance-obligations register and supplier audit scores onto a personal USB drive “to finish the report at home,” then loses the drive. That breaches confidentiality. Proper practice uses approved secure systems, limits distribution of draft findings, and avoids discussing another site’s nonconformities as gossip in the break room.
Confidentiality is balanced with legal duties: if law requires disclosure (e.g., imminent serious environmental harm reporting obligations in some jurisdictions), auditors follow applicable legal requirements and programme rules — integrity and due care still apply.
5. Independence
Independence is the basis for impartiality and objectivity. Auditors should be independent of the activity being audited wherever practicable, and should act in a manner free from bias and conflict of interest. For internal audits, auditors should be independent from the operating managers of the function being audited. Independence allows auditors to reach impartial conclusions.
EMS example: The corporate sustainability director who personally designed and still operates the corporate carbon-accounting tool should not lead the internal audit of that same tool’s effectiveness. A second-party customer auditor who receives a bonus solely for “supplier pass rates” faces a conflict that threatens independence. A third-party auditor who recently consulted on writing the auditee’s EMS manual for the same scope typically has an unacceptable conflict under certification rules.
Independence is both organizational (roles and reporting lines) and personal (attitudes, relationships, gifts). Document conflicts and recuse when needed.
6. Evidence-Based Approach
The evidence-based approach is the rational method for reaching reliable and reproducible audit conclusions in a systematic audit process. Audit evidence should be verifiable. It is generally based on samples of available information, so confidence is linked to proper sampling.
EMS example: An operator says, “We always check pH before discharge.” That statement alone is weak evidence. Stronger evidence combines interview + observation of the check being performed + review of pH log sheets + calibration records for the meter. If logs show missing weekend entries, the finding rests on records and observation, not on dislike of the operator.
Evidence-based auditing rejects conclusions drawn only from assumptions, rumors, or the auditor’s preferred practices that are not in the criteria.
7. Risk-Based Approach
The risk-based approach means focusing audit effort on matters that are significant for the audit client and for achieving the audit objectives. Resources are directed toward higher risks of inadequate planning, misstatement, weak control, or failure to achieve EMS intended outcomes.
EMS example: For a refinery EMS audit with limited hours, risk-based planning prioritizes oil-spill controls, air-emission monitoring, and change management for process modifications over low-significance office paper use — unless the objectives specifically target those lower-risk areas. In planning interviews, the lead auditor allocates more time to process owners of significant aspects and known prior nonconformities.
Risk-based does not mean ignoring entire ISO 14001 clauses permanently. It means intelligent prioritization within the agreed scope and programme so that the most important risks to reliable conclusions are addressed.
Applying the Principles Together
Real audits activate multiple principles at once. Suppose surveillance sampling reveals untreated effluent bypassing the treatment plant at night:
- Integrity / fair presentation — report the condition accurately despite pressure.
- Due professional care — gather enough evidence (photos where permitted, times, interviews, data) before concluding.
- Confidentiality — control distribution of sensitive evidence.
- Independence — resist auditee attempts to redefine the issue away without evidence.
- Evidence-based — verify with objective evidence, not allegations alone.
- Risk-based — expand sampling of related discharge controls because risk just increased.
Exam Pitfalls to Avoid
- Confusing independence (freedom from bias) with third-party status (external body)
- Treating confidentiality as a reason to hide nonconformities from the audit client
- Calling a preference “evidence” without verifiable information
- Using risk-based as an excuse to skip obvious high-risk areas
- Knowing principle names but failing to match them to EMS scenarios
Memorize all seven, then practice applying each to spills, permits, supplier audits, and certification pressures. That combination is what ISO 14001 Lead Auditor questions target.
Which ISO 19011 principle is primarily concerned with reporting audit findings truthfully and accurately, including significant obstacles and unresolved diverging opinions?
An EMS auditor concludes that spill kits are inadequate based only on a personal preference for a brand used at a previous employer, without checking the organization’s procedure or inspecting actual kits. Which principle is most clearly violated?
A lead auditor allocates extra time to wastewater treatment and hazardous-waste storage because those areas present higher environmental and compliance risk, while sampling office recycling more lightly within the same scope. Which principle does this best illustrate?
Which scenario best demonstrates a breach of the confidentiality principle during an ISO 14001 audit?