Why Clause 6 Is the Heart of ISO 19011
If you have ever wondered exactly what you are supposed to do once you arrive on site, open your laptop, and start an audit, Clause 6 of ISO 19011:2026 is the clause that answers that question. It covers the full execution of an individual audit, from initiating the audit through to completing it and distributing the report. Everything in Clause 5 is about managing the audit programme over time. Clause 6 is about what happens inside a single audit event.
On this page
The 2026 edition of ISO 19011 brought some important refinements to this clause, including tighter expectations around how nonconformities are reported at the closing meeting, clearer language around remote and combined audits, and updated guidance on grading findings. If you have been auditing for years using the 2018 edition as your reference, it is worth reviewing what has changed and where your practice may need to catch up.
This walkthrough moves through Clause 6 in sequence, explaining what each subclause requires, what it looks like in practice, and where auditors commonly go wrong. Whether you are preparing for your first lead auditor course or you are an experienced practitioner looking to sharpen your approach, this article will give you a practical foundation to work from.
Clause 6.2: Initiating the Audit
Before any fieldwork begins, the audit has to be formally initiated. Clause 6.2 covers the steps that happen before the audit team sets foot on site or opens a remote session.
Establishing Contact with the Auditee
The lead auditor, or the audit programme manager depending on the arrangement, establishes initial contact with the auditee. This is more than a courtesy. The purpose is to confirm that the audit can proceed, that the right people will be available, and that access to relevant areas, processes, and information has been arranged. In practice this means confirming dates, identifying the auditee's point of contact, and flagging any access requirements or site safety inductions that need to be completed in advance.
On external audits this step also involves confirming the scope and objectives with the audit client. Do not assume these are settled just because they appear in the audit programme. Circumstances change, and it is the lead auditor's job to verify that what was planned is still what is needed.
Determining the Feasibility of the Audit
Clause 6.2 requires the lead auditor to confirm that the audit is feasible before committing to proceed. Feasibility depends on whether sufficient and appropriate information is available for audit preparation, whether the auditee will cooperate, and whether the time and resources allocated are adequate for the scope.
If something is missing, for example the organisation cannot provide documented information for review ahead of the audit, or key personnel will be unavailable, the lead auditor needs to flag this with the audit client. Proceeding with an infeasible audit wastes everyone's time and produces unreliable conclusions. Raising the issue early is always the right call.
Exemplar Global Recognised Training ProviderRTP No. 310970Clause 6.3: Preparing Audit Activities
Preparation is where audits are won or lost. Auditors who skip or rush preparation tend to arrive on site without a clear plan, rely too heavily on checklists, and miss the systemic issues that matter most. Clause 6.3 sets out what thorough preparation looks like.
Reviewing Documented Information
Before the audit begins, the audit team reviews relevant documented information. This includes the management system documentation, previous audit reports, corrective action records, and any other information that helps the auditor understand the system and identify areas of risk or prior concern. For a certification audit this might include the Stage 1 report. For an internal audit it might include the previous cycle's findings and the current risk register.
The purpose of this review is not to tick a box. It is to build enough understanding of the organisation's system that the audit team can ask intelligent questions and follow meaningful threads on site. If you arrive knowing nothing about the organisation, you will spend the first hour of the audit learning things you could have learned from a document review the day before.
Preparing the Audit Plan
The audit plan is the lead auditor's tool for organising the audit. It sets out the objectives, scope, criteria, timing, locations, processes to be audited, and the allocation of responsibilities across the audit team. For a multi auditor engagement it also specifies who is auditing what and when.
ISO 19011:2026 is clear that the audit plan should be communicated to the auditee in advance and that the auditee should have the opportunity to raise concerns. If the auditee objects to an element of the plan, the lead auditor and audit client need to resolve the issue before the audit begins. Surprises on site rarely lead to productive audits.
For practical guidance on writing audit plans that actually focus your work, see our article on how to write audit objectives that actually focus your audit.
Assigning Work to the Audit Team
On audits involving more than one auditor, the lead auditor assigns specific processes, areas, or clauses to each team member. This assignment should be based on competence. An auditor with a background in environmental management should not be assigned to audit the calibration process unless they have the technical knowledge to do it properly. The lead auditor is responsible for ensuring the right person is covering the right ground.
Preparing Audit Checklists and Work Documents
Checklists and sampling plans are prepared during this phase. ISO 19011 treats these as tools to support the auditor, not as scripts to be followed mechanically. A well prepared checklist captures the key questions and evidence points the auditor wants to explore. It should be informed by the document review and by any risk areas identified during preparation.
The trap many auditors fall into is treating the checklist as a complete list of everything to audit. It is not. It is a starting point. The audit should follow the evidence wherever it leads, even if that takes you away from the checklist. If you find something unexpected, explore it.
Clause 6.4: Conducting the Audit Activities
This is the largest subclause in Clause 6 and covers everything that happens during the audit itself, from the opening meeting through to the closing meeting.
Roles and Responsibilities During the Audit
The lead auditor is responsible for managing the audit team, maintaining focus on the audit objectives, and making decisions about findings and conclusions. Individual auditors are responsible for gathering evidence in their assigned areas and reporting back to the lead auditor. Guides and observers have defined roles too. Guides facilitate access and introductions but do not influence what the auditor looks at or how they interpret evidence.
Opening Meeting
Clause 6.4 requires an opening meeting at the start of the audit. The purpose is to confirm the scope, objectives, and criteria with the auditee, explain the audit process, confirm the agenda, and give the auditee an opportunity to ask questions. It is also the point at which the lead auditor establishes the tone for the audit.
A good opening meeting is brief, professional, and reassuring. It sets clear expectations and gives the auditee confidence that the audit will be conducted fairly. A poor opening meeting is either too long and bureaucratic, or too casual and leaves the auditee uncertain about what is going to happen. For a detailed guide to running this meeting well, see our article on how to run an opening meeting that sets the tone.
Gathering and Verifying Information
The core of the audit is gathering and verifying information. ISO 19011:2026 is explicit that audit evidence must be verifiable. That means it must be traceable back to something objective, whether that is a document, a record, an observation, or a statement that can be corroborated. Personal impressions and gut feelings are not audit evidence.
The standard identifies three primary methods for gathering evidence: reviewing documents and records, interviewing personnel, and observing activities and conditions. Effective auditors use all three and triangulate between them. If a procedure says one thing, an operator describes something different, and the records show a third picture, that discrepancy is itself a finding worth exploring.
Sampling is an important part of this process. You cannot review every record or interview every person. The auditor selects a sample that is representative of the population being audited. The size and method of sampling should be appropriate to the risk and complexity of the area being audited. A high risk process with a history of nonconformities warrants a larger sample than a low risk administrative process with a clean track record.
Generating Audit Findings
As evidence is gathered, the audit team generates findings. ISO 19011:2026 distinguishes between conformities, nonconformities, and opportunities for improvement. The 2026 edition includes updated guidance on grading nonconformities as major or minor, which is relevant particularly for certification audits. A major nonconformity indicates a systemic failure or the absence of a required element. A minor nonconformity indicates an isolated or partial failure.
Every nonconformity must be supported by objective evidence. The finding should identify the requirement that has not been met, describe the evidence that demonstrates the nonconformity, and be specific enough that the auditee can understand exactly what the issue is. Vague findings like
procedures are not being followedare not acceptable. Which procedure? Which requirement? What evidence was observed?
For a detailed look at how to classify findings correctly, our article on what is an audit finding vs observation vs nonconformity walks through the distinctions in plain terms.
Preparing Audit Conclusions
Before the closing meeting, the audit team meets to review findings, agree on conclusions, and prepare the closing presentation. The lead auditor is responsible for this process. Conclusions address whether the management system conforms to the audit criteria, whether it has been effectively implemented and maintained, and whether the audit objectives have been achieved.
This is also the point at which the lead auditor determines the overall audit outcome. For a certification audit that means a recommendation. For an internal audit it means a summary assessment of the system's effectiveness. The conclusion must be based on the totality of evidence gathered, not just the most dramatic finding of the day.
Closing Meeting
The closing meeting is where the audit team presents findings and conclusions to the auditee. ISO 19011:2026 tightened the requirements around this meeting in the 2026 edition. Nonconformities must now be presented in a way that is clear and unambiguous, and the auditee must have the opportunity to seek clarification or raise concerns about factual accuracy.
The lead auditor should present findings in a structured way, starting with positives if there are any, then moving through nonconformities and observations. Avoid reading out a list of problems without context. Give the auditee enough information to understand what was found and why it matters. If the auditee disputes a finding, note the dispute but do not retract the finding without a genuine factual basis for doing so.
For a practical guide to running the closing meeting without surprises, see our article on how to run a closing meeting without surprises.
Clause 6.5: Preparing and Distributing the Audit Report
The audit report is the permanent record of the audit. It documents what was audited, how it was audited, what was found, and what conclusions were reached. Clause 6.5 sets out what the report must contain and how it should be handled.
What the Report Must Include
ISO 19011:2026 specifies the minimum content of an audit report. This includes the audit objectives, scope, and criteria, the audit dates and locations, the names of the audit team members and auditee representatives, a summary of the audit process including any obstacles encountered, the audit findings and the evidence supporting them, the audit conclusions, and any follow up actions agreed during the audit.
The report should be accurate, concise, and complete. It should be written in a way that someone who was not present at the audit can understand what happened and what was found. Avoid jargon, avoid ambiguity, and avoid the temptation to soften findings in the written report after a difficult closing meeting. What was presented at the closing meeting should be reflected faithfully in the report.
Distributing the Report
The report is distributed to the audit client and, where agreed, to the auditee. The timing and distribution arrangements should be agreed before the audit begins. In most cases the report is issued within a defined timeframe after the closing meeting, often within five to ten business days for external audits, though internal audit programmes may specify different timeframes.
Confidentiality applies to audit reports. The information in the report belongs to the audit client. The audit team must not share it with third parties without authorisation.
Clause 6.6: Completing the Audit
The audit is formally complete when all planned activities have been carried out and the audit report has been approved and distributed. Clause 6.6 is brief but important. It confirms that the audit is closed and that all working documents, including checklists, notes, and records, are retained or disposed of in accordance with the agreed arrangements.
Retaining working papers matters. If a finding is later disputed or if a corrective action is contested, the auditor needs to be able to demonstrate the evidence trail that supported the finding. Good record keeping is not bureaucracy. It is professional protection.
Clause 6.7: Conducting Audit Follow Up
Clause 6.7 addresses what happens after the audit is closed. If the audit produced nonconformities, the auditee is required to take corrective action within an agreed timeframe. The audit team may be asked to verify that the corrective actions have been completed and are effective.
Follow up can take different forms. For internal audits it might involve reviewing the corrective action records at the next audit. For certification audits it might involve a dedicated follow up audit or a desktop review of evidence. The method should be proportionate to the nature and severity of the nonconformity.
One of the most common failures in audit programmes is the absence of effective follow up. Nonconformities are raised, corrective actions are proposed, and then nothing is verified. The next audit cycle arrives and the same issues are found again. ISO 19011:2026 is clear that follow up is part of the audit process, not an optional extra.
Remote and Combined Audits Under Clause 6
The 2026 edition of ISO 19011 explicitly addresses remote auditing within Clause 6, reflecting the significant shift in audit practice that occurred in recent years. Remote audits use digital tools to conduct interviews, review documents, and observe activities without the auditor being physically present. The standard acknowledges that remote auditing can be effective but notes that it introduces specific considerations around technology reliability, data security, and the ability to observe physical conditions.
Combined audits, where two or more management systems are audited simultaneously, are also addressed. The audit plan for a combined audit needs to be carefully structured so that interactions between systems are examined, not just each system in isolation. An integrated management system covering quality, environment, and safety should be audited in a way that tests how the systems work together, not just whether each one has its own documents in order.
Exemplar Global Recognised Training ProviderRTP No. 310970Common Mistakes Auditors Make in Clause 6 Activities
After conducting hundreds of audits across multiple industries, the patterns of error are consistent. Here are the ones that come up most often.
- Inadequate preparation. Auditors who skip the document review arrive on site without context and spend valuable audit time catching up. Review the documented information before you arrive.
- Over reliance on checklists. A checklist is a guide, not a script. If the evidence takes you somewhere unexpected, follow it.
- Vague findings. Every nonconformity needs a specific requirement, specific evidence, and a clear description of the gap. If you cannot write it clearly, you probably have not gathered enough evidence yet.
- Failing to triangulate. Do not rely on a single source of evidence. If someone tells you something, verify it against a document or an observation.
- Rushing the closing meeting. The closing meeting is not just an administrative formality. It is the point at which the auditee hears the conclusions for the first time. Take the time to present findings clearly and give the auditee the opportunity to respond.
- Ignoring follow up. Raising findings without verifying corrective actions is like diagnosing a problem and never checking whether the treatment worked.
Building Your Clause 6 Competence Through Training
Understanding Clause 6 in theory is one thing. Applying it under real audit conditions is another. The decisions you make during an audit, about what evidence to pursue, how to grade a finding, how to handle a defensive auditee, how to present conclusions clearly, all of these require practised judgement, not just knowledge of the standard.
At Audit Workshop, our ISO auditor training courses are built around developing that practical competence. The Internal Auditor and Lead Auditor courses for ISO 9001, ISO 14001, and ISO 45001 all use real audit scenarios to give participants experience with the full Clause 6 process, from planning and preparation through to reporting and follow up. Training is available live online and self paced, and all courses are delivered by Dilawar Laghari, a certified lead auditor with over 14 years of experience and more than 500 external certification audits completed across Australia, the Middle East, and South Asia.
If you are working toward auditor certification or simply want to audit with more confidence and rigour, the training at Audit Workshop is designed to get you there.













