8.1 Seven Principles of Auditing under ISO 19011
Key Takeaways
- ISO 19011:2018 Clause 4 articulates seven foundational principles that underpin the credibility, reliability, and reproducibility of management system audits.
- Integrity is the foundation of professionalism, mandating that auditors perform duties honestly, ethically, competently, and impartially without bowing to undue influence.
- Fair presentation establishes an affirmative obligation to report audit findings, conclusions, obstacles, and unresolved diverging opinions truthfully and accurately.
- Independence is the prerequisite for audit impartiality and objectivity, requiring auditors to remain free from bias, operational conflict of interest, and the auditing of their own work.
- The risk-based approach introduced in the 2018 revision requires auditors to substantively focus audit planning, sampling, and effort on matters of high significance to OH&S performance.
8.1 Seven Principles of Auditing under ISO 19011
Lead Auditor Core Concept: Auditing is a systematic, independent, and documented process for obtaining objective evidence and evaluating it impartially against criteria. The seven principles in ISO 19011:2018 Clause 4 form the foundation of auditing, ensuring independent auditors examining similar evidence reach consistent, reliable, and defensible conclusions.
1. Normative Role and Authority of ISO 19011 Clause 4
While ISO 45001:2018 specifies requirements for an OH&S management system (OH&S MS), auditing methodology is governed by ISO 19011:2018 (Guidelines for auditing management systems). For third-party certification bodies, ISO/IEC 17021-1:2015 makes these principles mandatory. An audit violating Clause 4 principles is fundamentally flawed: findings lack credibility, and conclusions fail to provide leadership with a reliable reflection of workplace safety risks.
2. Deconstruction of the Seven Principles
ISO 19011:2018 Clause 4 defines seven core principles that guide auditor judgment and behavior:
1. Integrity: The Foundation of Professionalism
Integrity requires auditors and programme managers to perform their work with honesty, diligence, and responsibility. Auditors must:
- Comply with all applicable legal, regulatory, and professional ethical standards.
- Undertake assignments only if technically competent in the relevant industry sector.
- Remain fair, objective, and unbiased across all findings and auditee interactions.
- Resist commercial, financial, or political inducements that could influence professional judgment.
2. Fair Presentation: Obligation to Report Truthfully and Accurately
Audit findings, conclusions, and reports must truthfully and accurately reflect audit activities:
- Ensure statements of conformity or nonconformity are supported by verifiable objective evidence.
- Fully disclose significant obstacles encountered, including denied facility access or withheld documents.
- Explicitly record unresolved diverging opinions between the audit team and auditee. Auditors must never suppress valid nonconformities to maintain artificial harmony with auditee management.
3. Due Professional Care: Application of Diligence and Judgment
Auditors must exercise care commensurate with the importance of the task and stakeholder confidence:
- Apply reasoned professional judgment when evaluating hazard severity and risk controls.
- Maintain vigilance against flawed conclusions stemming from sampling errors or incomplete records.
- Possess sector-specific competence to interpret complex technical processes and statutory safety mandates.
4. Confidentiality: Security of Information
Auditors routinely access proprietary engineering data, secret chemical formulas, worker medical surveillance records, and internal incident reports. Confidentiality requires:
- Discretion in handling and protecting information obtained during audit activities.
- Never disclosing audit information to third parties without explicit client authorization or legal mandate.
- Never utilizing audit information for personal or commercial advantage.
- Ensuring secure storage and transmission of digital and paper audit working papers.
5. Independence: Basis for Impartiality and Objectivity
Independence ensures conclusions are derived strictly from objective evidence without bias or conflict of interest:
- Internal Audits (1st Party): Auditors must be independent of the operating function audited whenever practicable. Personnel must never audit their own work (e.g., safety coordinators cannot audit safety inspections they personally execute).
- External Audits (2nd/3rd Party): Auditors must remain independent of commercial and organizational relationships. Under ISO/IEC 17021-1, auditors must not audit any organization where they provided safety consulting or held employment within the preceding two years.
6. Evidence-Based Approach: Rational Method for Reproducible Conclusions
An audit relies on empirical inquiry rather than subjective speculation:
- Audit conclusions must be based solely on audit evidence that is verifiable through observation, interview corroboration, and physical records.
- Because audits are conducted within finite timeframes, evidence is inherently based on samples of available data.
- Sampling techniques (statistical or judgment-based) must be mathematically sound, representative of operations, and transparently documented.
7. Risk-Based Approach: Auditing Considering Risks and Opportunities
Introduced in ISO 19011:2018, this principle substantively directs audit planning, execution, and reporting:
- Audit focus and resources must prioritize matters of greatest significance to the auditee's OH&S risks and strategic objectives.
- High-hazard operations (e.g., confined space entry, chemical synthesis, molten metal handling) receive concentrated scrutiny over low-risk administrative functions.
- The approach also addresses risks to the audit itself, including auditor safety, facility access disruptions, and language barriers.
3. Comparative Matrix of the Seven Audit Principles
| Principle | ISO 19011 Clause 4 Tenet | Operational Lead Auditor Behavior | Direct Audit Violation / Ethical Failure |
|---|---|---|---|
| Integrity | Honesty, diligence, ethical conduct | Refusing commercial inducements and auditing within competence | Accepting consulting offers or gifts during an active audit |
| Fair Presentation | Truthful, complete, accurate reporting | Documenting all nonconformities and logging auditee disagreements | Suppressing a near-miss finding to preserve client relations |
| Due Professional Care | Diligence, reasoned judgment | Rigorously verifying instrument calibration against physical sensors | Accepting superficial checklists without checking field operations |
| Confidentiality | Security and discretion with data | Encrypting audit records and safeguarding employee medical files | Sharing auditee proprietary procedures with outside competitors |
| Independence | Freedom from bias and self-review | Recusing oneself from auditing processes previously managed | Auditing an OH&S training programme developed 12 months prior |
| Evidence-Based | Verifiable data and sound sampling | Corroborating verbal statements with physical operational logs | Raising a Major Nonconformity based on uncorroborated rumors |
| Risk-Based | Prioritizing high-significance risks | Allocating 70% of audit time to high-hazard chemical and rigging units | Spending 60% of audit time inspecting office desk ergonomics |
4. Real-World Audit Scenario: Ethical Conflicts on an Offshore Rig
Audit Context: During a Stage 2 ISO 45001 audit on an offshore drilling platform, a Lead Auditor finds four hot-work permits over fuel storage tanks lacking mandatory atmospheric gas testing records.
Audit Complications:
- The Rig Superintendent offers the auditor a paid consulting contract next quarter if the finding is reduced to an informal observation.
- The auditor notes the facility's confined space procedure was written 14 months ago by the auditor's current business associate.
- The Superintendent insists gas testing occurred via two-way radio and refuses to sign the finding sheet.
Lead Auditor Evaluation & Required Actions:
- Integrity: The auditor must reject the consulting offer; soliciting or accepting work during an audit violates impartiality.
- Independence: The auditor must recuse themselves from auditing the confined space procedure due to a conflict of interest under ISO/IEC 17021-1.
- Evidence-Based Approach: Unsubstantiated verbal statements do not constitute verifiable audit evidence. Lacking mandatory gas testing records represents a critical breakdown in Clause 8.1.2 operational control.
- Fair Presentation: The auditor must log a Major Nonconformity, fully document the evidence, and explicitly record the auditee's dissenting opinion in the final audit report.
5. Common Exam Traps & Candidate Pitfalls
- Internal Independence Fallacy: Assuming internal auditors must be external contractors. Employees may audit their company, provided they are independent of the specific activity audited.
- The Consensus Myth: Believing reports require auditee agreement. Fair presentation requires logging unresolved diverging opinions when consensus cannot be reached.
- The 100% Verification Trap: Assuming due care demands examining every single record. Auditing relies on representative sampling and reasoned judgment.
- Uniform Time Allocation: Distributing audit hours equally across departments. The risk-based approach requires focusing heavily on high-hazard operations.
During an OH&S audit of a metal foundry, an auditor notices that crane inspection logs were backdated by the maintenance supervisor to conceal overdue load-testing certifications. When confronted, the supervisor requests that the auditor omit the finding in exchange for access to proprietary contractor safety manuals. Which fundamental auditing principle under ISO 19011:2018 Clause 4 is most directly compromised if the auditor agrees to suppress this finding?
During an on-site ISO 45001 audit, the audit team and the facility safety director disagree on whether an unlabelled chemical decanting station constitutes a major nonconformity. Despite extensive discussions, the facility director refuses to accept the finding. How should the Lead Auditor apply the principle of 'Fair presentation' under ISO 19011:2018 Clause 4?
An audit team has five business days to audit an enterprise with 4,000 workers across twelve operating facilities. Rather than inspecting every workstation equally, the Lead Auditor concentrates 70% of on-site audit hours on high-pressure steam boilers, hazardous chemical processing, and working-at-height operations. Which ISO 19011:2018 auditing principle is being operationalized?