Why Clause 4 Matters More Than Most Auditors Realise
If you ask most auditors which part of ISO 19011 they use most often, they will point to the audit process guidance in Clause 6, or perhaps the programme management content in Clause 5. Clause 4 rarely gets the same attention. That is a mistake.
On this page
Clause 4 of ISO 19011:2026 sets out the principles of auditing. These are not abstract ideals printed at the front of a document to satisfy a committee. They are the foundation that every audit decision, every finding, every interview, and every report should rest on. When audits go wrong, and they do go wrong, it is almost always because one or more of these principles was ignored, compromised, or misunderstood.
This article walks through each principle in Clause 4, explains what it means in practice, and shows you where it shows up in real audit situations. Whether you are preparing for your first internal audit or refining your approach as an experienced lead auditor, getting clear on these principles will make you a sharper and more credible auditor.
For broader context on how ISO 19011:2026 is structured and what changed in the 2026 edition, see our article on what changed from the 2018 edition to now.
The Seven Principles of Auditing in Clause 4
ISO 19011:2026 identifies seven principles of auditing. These have remained largely consistent across editions of the standard, with some refinement in how they are expressed. The 2026 edition retains all seven and reinforces their application in the context of modern audit challenges including remote auditing, digital evidence, and risk based programme planning.
The seven principles are:
- Integrity
- Fair presentation
- Due professional care
- Confidentiality
- Independence
- Evidence based approach
- Risk based approach
Each one is worth examining on its own terms.
Exemplar Global Recognised Training ProviderRTP No. 310970Integrity: The Foundation of Professional Trust
Integrity is listed first in Clause 4, and that ordering is deliberate. Without integrity, none of the other principles function properly. The standard describes integrity as performing work ethically, with honesty and responsibility, only undertaking audit activities within your competence, and being transparent about any limitations.
In practice, integrity shows up in small decisions throughout every audit. It means telling an auditee you are not competent to assess a specific technical process rather than bluffing your way through. It means raising a finding even when the auditee is senior to you and clearly unhappy about it. It means not softening a major nonconformity into an observation because the client is under pressure from their certification body.
Integrity also means being honest about what you observed versus what you inferred. Auditors who write findings based on gut feeling rather than evidence are compromising their integrity, even if their instinct happens to be correct. The finding needs to be grounded in something you actually saw, heard, or read during the audit.
One situation that tests integrity regularly is when an auditor finds a nonconformity in a process managed by a senior manager who is also the audit client. The pressure to soften or omit the finding can be significant. Integrity means the finding gets documented regardless. For a deeper look at this principle in isolation, read our post on integrity as the foundation of professional audit practice.
Fair Presentation: Reporting What You Actually Found
Fair presentation requires that audit findings, conclusions, and reports accurately reflect the audit activities and their results. It covers both positive and negative findings. It also means that obstacles encountered during the audit, unresolved issues, and divergent opinions between audit team members and the auditee are reported truthfully.
This principle is frequently misapplied in two directions. Some auditors report only problems and ignore genuine evidence of a well functioning system. Others, under pressure to maintain a relationship with the client, report only good news and downplay or omit legitimate nonconformities. Both approaches violate fair presentation.
Fair presentation also applies to how findings are worded. A nonconformity report that uses vague or exaggerated language does not fairly represent what was found. A finding that says the entire documented information system is inadequate when you only reviewed three records is not a fair representation of the evidence. The scope of the finding must match the evidence gathered.
In audit reports, fair presentation means the overall audit conclusion should reflect the full picture. If a system has strong controls in most areas but a significant gap in one, the report should say both things clearly. Presenting only the positives to soften the message, or only the negatives to appear thorough, both undermine the credibility of the audit.
Due Professional Care: Applying Diligence and Judgement
Due professional care refers to the diligence and judgement an auditor applies throughout the audit. It means planning the audit properly, gathering sufficient evidence to support conclusions, and exercising sound professional judgement at every stage.
This principle is what separates a thorough auditor from one who goes through the motions. Due professional care means you do not accept the first answer you receive. You probe. You verify. You sample broadly enough to form a reasonable conclusion. You do not skip a process because it looks fine from a distance.
It also means recognising the limits of your own knowledge and asking for technical support when you need it. An auditor assessing a specialised chemical process who does not understand the process cannot exercise due professional care without either doing some preparation or bringing in a technical expert. Proceeding without that support and then reaching conclusions about conformity is not diligent, it is reckless.
Due professional care requires that the effort you put into an audit is proportionate to the risk and importance of what is being audited. A high risk process in a critical part of the supply chain warrants more time and deeper sampling than a low risk administrative function. Applying the same level of effort regardless of risk is a failure of professional judgement.
Confidentiality: Handling Information with Discretion
Auditors have access to sensitive information during the course of an audit. Financial data, personnel records, strategic plans, customer complaints, incident histories, and proprietary processes are all examples of information that may surface during an audit. The confidentiality principle requires that auditors handle this information with discretion and do not disclose it without appropriate authorisation.
This is particularly relevant for external auditors and lead auditors who work across multiple organisations. Information gathered during an audit of one organisation must not be shared with another, even informally. Comparing what one client does with what a competitor does, even without naming the competitor, can breach confidentiality.
Confidentiality also applies within organisations. An internal auditor who shares findings from a sensitive audit with colleagues who have no need to know that information is breaching this principle. The audit report goes to the appropriate stakeholders. It does not become general conversation.
In the context of digital auditing, confidentiality takes on additional dimensions. Screenshots, shared documents, and remote access to systems all create risks of inadvertent disclosure. Auditors need to be deliberate about how they store, transmit, and delete audit working papers. For more on this, see our post on how auditors should handle sensitive information with care.
Independence: The Basis for Impartiality
Independence is the structural underpinning of objectivity. For internal auditors, full independence from the activities being audited is not always possible, but the standard requires that auditors be free from bias and conflicts of interest to the greatest extent possible. For external auditors, independence is a formal requirement and a condition of certification body accreditation.
The most obvious application of this principle is the rule that auditors should not audit their own work. If you designed a process, implemented a procedure, or are responsible for the outcomes of a function, you should not be auditing that function. The findings of such an audit are inherently compromised because the auditor has a personal stake in the outcome.
Independence also extends to relationships. An auditor who has a close personal relationship with the auditee, a financial interest in the outcome, or a prior consulting relationship with the organisation has a conflict of interest that should be declared and managed. In some cases, the auditor should step aside entirely.
In practice, maintaining independence requires ongoing vigilance. Auditors who conduct the same internal audits year after year in the same organisation can develop familiarity that gradually erodes their objectivity. Rotating auditors, using external support, or pairing auditors with different backgrounds are all ways to manage this risk.
Evidence Based Approach: Conclusions Must Rest on Verifiable Facts
The evidence based approach principle states that audit conclusions should be based on verifiable information. Audit evidence is gathered through interviews, document review, and observation. It must be sufficient, relevant, and reliable enough to support the findings and conclusions drawn from it.
This principle is what distinguishes auditing from inspection or assessment by opinion. An auditor who concludes that a process is nonconforming because it does not feel right, without being able to point to specific evidence, has not conducted an audit. They have offered an opinion. Audit findings must be traceable back to something the auditor actually observed, recorded, or verified.
The evidence based approach also requires that auditors gather enough evidence before reaching a conclusion. Sampling one record and concluding the entire system is nonconforming is not evidence based. Equally, sampling only records that appear compliant and ignoring warning signs is a form of cherry picking that also violates this principle.
Good auditors document their evidence as they go. They record what they saw, what they were told, and what documents they reviewed. When a finding is challenged, the evidence trail supports the conclusion. When the evidence does not support a finding, the finding should not be raised. This discipline is fundamental to audit credibility. For practical guidance on gathering evidence that holds up, see our article on gathering audit evidence through sampling, interviews and document review.
Risk Based Approach: Directing Audit Effort Where It Matters
The seventh principle, the risk based approach, was added to ISO 19011 in the 2018 edition and carried through into 2026. It recognises that audit effort should be directed toward areas of greatest risk and significance, both in the design of the audit programme and in the conduct of individual audits.
At the programme level, this means that processes, sites, or functions with higher risk profiles should be audited more frequently, more thoroughly, and with greater scrutiny than lower risk areas. A manufacturing line handling hazardous materials warrants more audit attention than the stationery procurement process.
At the individual audit level, the risk based approach influences how an auditor allocates time during the audit day. If an initial interview reveals unexpected gaps in a particular area, a risk based auditor will adjust the plan and spend more time there, rather than mechanically following the original schedule regardless of what they are finding.
The risk based approach also means that the audit objectives, scope, and criteria should reflect the risk profile of the organisation and its management system. An audit that treats all clauses and all processes as equally important, regardless of their actual risk to the organisation, is not applying this principle.
This principle connects directly to how audit programmes should be planned and updated. When significant changes occur in the organisation, when incidents happen, or when previous audits have revealed systemic problems, the audit programme should respond. A static programme that does not adjust to changing risk is not risk based in any meaningful sense.
Exemplar Global Recognised Training ProviderRTP No. 310970How the Principles Work Together in Practice
These seven principles are not independent of each other. They work together, and a failure in one often creates pressure on the others.
Consider an auditor who discovers a significant nonconformity late in the day, just before the closing meeting. The auditee is visibly stressed and the audit client has indicated they need a clean result for a tender. The pressure to soften or omit the finding is real. In that moment, integrity requires the auditor to report it. Fair presentation requires it to be described accurately. Independence requires the auditor to resist the pressure from the client. Due professional care requires that the evidence gathered is sufficient to support the finding before it is raised.
Or consider an internal auditor who is auditing a process they helped design three years ago. Independence is already compromised. If they proceed without disclosing that relationship, integrity is also compromised. If they then write a report that glosses over weaknesses in that process, fair presentation and the evidence based approach are both violated.
The principles are a coherent framework. Applying them consistently is what makes an audit trustworthy. Ignoring any one of them, even occasionally, undermines the value of the entire audit.
What Clause 4 Means for Auditor Development
Understanding these principles intellectually is the starting point. Applying them under pressure, in real audit situations, with real stakes, is a different matter entirely. That gap between knowing the principles and embodying them is where auditor development actually happens.
For new auditors, the most common challenges are around independence (not knowing how to manage conflicts of interest), the evidence based approach (confusing observation with conclusion), and integrity (not knowing how to raise a difficult finding professionally). These are skills that develop through practice, reflection, and good training.
For experienced auditors, the risks are different. Familiarity can erode independence. Efficiency pressures can compromise due professional care. Relationship building with clients can subtly shift fair presentation. Experienced auditors need to revisit these principles regularly, not just during training, but as part of their ongoing professional practice.
At Audit Workshop, the principles of auditing from Clause 4 of ISO 19011:2026 are woven throughout all auditor training programmes, from the Foundation level through to Lead Auditor courses across ISO 9001, ISO 14001, and ISO 45001. The goal is not just to teach auditors what the principles say, but to build the judgement and habits that allow them to apply those principles in the complex, pressured, and sometimes ambiguous situations that real audits present. If you are ready to build that foundation, explore the training options at auditworkshop.com.










