Section 3.2: The 7 Auditing Principles of ISO 19011

Key Takeaways

  • Integrity and fair presentation serve as the ethical core of auditing, demanding honesty, responsibility, and the truthful, accurate, and objective reporting of all key audit findings, obstacles, and unresolved opinions.
  • Due professional care and confidentiality require applying diligence, reasoned judgment, and strict discretion to protect sensitive and proprietary organization information.
  • Independence is the foundation of audit impartiality and objectivity, requiring that auditors remain completely free from bias, conflict of interest, and self-auditing activities.
  • The evidence-based approach ensures that audit conclusions are reliable, consistent, and reproducible, resting solely on verifiable samples of objective audit evidence.
  • The risk-based approach guides audit planning, execution, and reporting, focusing resources and efforts on processes of the highest operational significance and risk.
Last updated: July 2026

Section 3.2: The 7 Auditing Principles of ISO 19011

The ISO 19011:2018 guidelines establish seven core principles for auditing management systems. These principles are not merely suggestions; they form the operational foundation of any professional audit. They ensure that audits are reliable, consistent, and reproducible, allowing an organization to rely on the audit conclusions to make critical business decisions. A lead auditor must understand how to apply these principles and recognize potential breaches in auditing practice.

The Seven Auditing Principles Explained

1. Integrity: The Foundation of Professionalism

Integrity is the absolute core of auditing professionalism. Auditors must perform their work with honesty, diligence, and responsibility.

  • Key Requirements: Auditors must observe and comply with all applicable legal requirements, demonstrate technical competence, perform their duties impartially, and remain sensitive to any influences that could affect their judgment.
  • Breach Scenario: An auditor notices a critical calibration error but agrees to omit it from the audit report after the plant manager promises to correct it immediately without formal documentation. This compromises the auditor's integrity and the reliability of the report.

2. Fair Presentation: The Obligation to Report Truthfully and Accurately

Fair presentation requires that all audit findings, conclusions, and reports truthfully, accurately, and objectively reflect the audit activities.

  • Key Requirements: The auditor must report significant obstacles encountered during the audit and any unresolved diverging opinions between the audit team and the auditee. The communication must be truthful, accurate, objective, timely, clear, and complete.
  • Breach Scenario: An auditor summarizes a complex set of conflicting interviews by stating "all staff are fully aware of the policy," ignoring the fact that several operators expressed confusion. This is a failure of fair presentation.

3. Due Professional Care: The Application of Diligence and Judgment

Auditors must exercise care in accordance with the importance of the task they perform and the confidence placed in them by the audit client and other interested parties.

  • Key Requirements: This principle requires due diligence and reasoned judgment. An auditor must have the necessary competence and apply it conscientiously. They must make reasoned judgments in all audit situations.
  • Breach Scenario: An auditor spends the majority of a limited audit timeframe chatting with the operations manager and rushes through the verification of production records at the very end, missing key defects. This represents a failure to exercise due professional care.

4. Confidentiality: Security of Information

Auditors must exercise discretion in the use and protection of information acquired in the course of their duties.

  • Key Requirements: Audit information should not be used inappropriately for personal gain by the auditor or the audit client, or in a manner detrimental to the legitimate interests of the auditee. This extends to protecting proprietary technical specifications and customer lists.
  • Breach Scenario: A contract auditor takes photos of a proprietary assembly machine and shares them on social media as an example of "good manufacturing practices." This is a direct breach of confidentiality.

5. Independence: The Basis for Impartiality and Objectivity

Independence is the foundation for the impartiality of the audit and the objectivity of the audit conclusions.

  • Key Requirements: Auditors must be independent of the activity being audited wherever practicable, and must in all cases act in a manner that is free from bias and conflict of interest. For internal audits (first-party), this means the auditor must not audit their own department. For external audits (third-party), this requires complete commercial and financial separation.
  • Breach Scenario: A lead auditor is assigned to audit the quality control department of an organization where their spouse is the Quality Control Manager. This direct conflict of interest violates the independence principle.

6. Evidence-Based Approach: The Rational Method for Reaching Reliable Conclusions

An evidence-based approach is the only rational method for reaching reliable and reproducible audit conclusions in a systematic audit process.

  • Key Requirements: Audit evidence must be verifiable. It must be based on samples of the information available, as an audit is conducted during a finite period and with limited resources. The conclusions must rest on objective evidence—such as records, observation, and measurements—never on hearsay, assumptions, or personal opinions.
  • Breach Scenario: An auditor documents a nonconformity stating "the warehouse is disorganized and processes seem poorly managed," without citing specific misplaced items, missing documents, or corresponding requirements. This subjective finding breaches the evidence-based approach.

7. Risk-Based Approach: Focus on What Matters

The risk-based approach is a relatively recent addition to the principles, aligning with the risk-based thinking introduced in ISO 9001:2015.

  • Key Requirements: The risk-based approach should substantively influence the planning, conducting, and reporting of audits. It ensures that audits are focused on matters that are significant for the audit client, and for achieving the audit programme objectives.
  • Breach Scenario: An auditor dedicates half of a two-day QMS audit to reviewing the employee training logs for office administrative staff, while allocating only two hours to the high-complexity cleanroom packaging process. This is a failure to apply a risk-based approach.
PrincipleCore Operational FocusCommon Auditor Challenge
IntegrityEthical conduct, honesty, responsibilityAvoiding complacency and personal bias
Fair PresentationObjective and complete reportingDocumenting controversial or unpopular findings
Due Professional CareDiligent planning and executionManaging tight schedules without cutting corners
ConfidentialityProtection of proprietary dataPreventing accidental sharing of client records
IndependenceFreedom from bias and conflict of interestSeparating personal relationships from professional roles
Evidence-BasedVerifiable, sample-based conclusionsResisting the urge to base findings on intuition or opinion
Risk-BasedFocusing on high-impact areasAvoiding repetitive, low-value compliance checklists

Interrelation of the Principles

These seven principles do not operate in isolation. For instance, an auditor cannot achieve an evidence-based approach without exercising due professional care to gather reliable samples. Similarly, fair presentation relies heavily on the auditor's integrity to report issues that the auditee might prefer to hide. A professional lead auditor uses these principles as a constant sanity check throughout the audit lifecycle, ensuring that the final audit report stands up to technical scrutiny.

Test Your Knowledge

An auditor is conducting a QMS audit at a manufacturing plant. During planning, the auditor notices that the company has recently introduced a brand-new, complex automation process for manufacturing its flagship product. The auditor adjusts the audit plan to allocate more time to this automated line and less time to the stable, mature processes. Which auditing principle is the auditor applying?

A
B
C
D
Test Your Knowledge

While reviewing documentation, an auditor notices that the records for final inspection are missing for a batch of products shipped last week. Instead of writing a nonconformity, the auditor accepts the supervisor's verbal assurance that the inspections were performed. Which auditing principle did the auditor fail to uphold?

A
B
C
D
Test Your Knowledge

An independent auditor is hired to conduct a Stage 2 certification audit of a manufacturing firm. The auditor discovers that their former employer of six months ago is a major supplier of the firm, and the auditor had personally drafted the quality agreement between the two firms. What action should the auditor take to maintain the principles of auditing?

A
B
C
D