Why ISO 19011:2026 Puts Risk at the Centre of Audit Programme Management
The 2026 edition of ISO 19011 is not a cosmetic update. One of its most significant practical shifts is the way it treats the audit programme itself as something that carries risk. Specifically, the standard now calls out risks to the integrity and credibility of the audit process, and it names undue influence as a concrete threat that audit programme managers must actively manage.
On this page
If you run an internal audit programme, manage a team of auditors, or work as a lead auditor conducting second or third party audits, this change has direct implications for how you plan, assign, and oversee audit activities. This article walks through what the 2026 edition says about audit programme risks, why undue influence is being called out explicitly, and what practical steps you can take to protect the integrity of your programme.
For context on the broader changes in the 2026 edition, the article ISO 19011:2026 Is Here: What Changed from the 2018 Edition provides a solid overview before you dive into this more specific topic.
What the 2026 Edition Says About Audit Programme Risks
Clause 5 of ISO 19011:2026 governs the management of an audit programme. The 2026 edition strengthens the requirement to consider risks when establishing and managing the programme. This is not entirely new territory, but the language is sharper and the examples more specific.
The standard now explicitly requires that audit programme managers identify and address risks that could compromise the audit programme's objectives. It groups these risks into several categories, and undue influence is singled out as one of the most serious threats to auditor independence and audit integrity.
Other risks called out include inadequate auditor competence, conflicts of interest, time and resource pressure, and the growing complexity introduced by remote auditing and digital evidence. Each of these deserves attention, but undue influence gets particular emphasis because it is often invisible until something goes wrong.
Exemplar Global Recognised Training ProviderRTP No. 310970Understanding Undue Influence in the Audit Context
Undue influence occurs when someone with authority, interest, or power over the audit outcome puts pressure on an auditor in a way that compromises their independent judgement. It does not have to be overt. In fact, the most damaging forms of undue influence are subtle.
What Undue Influence Looks Like in Practice
Consider these scenarios, all of which represent real audit situations:
- A senior manager pulls the auditor aside before the closing meeting and suggests that a particular finding would be “embarrassing for the business right now” and asks whether it could be downgraded or deferred.
- An audit programme manager assigns the same internal auditor to audit a department where they have close personal relationships with the team, and the findings consistently come back clean despite known systemic issues.
- A client organisation hosting a second party audit provides lavish hospitality during the audit week, creating social pressure on the auditor to return a favourable outcome.
- A lead auditor working for a certification body is told by their employer that a particular client is commercially important and that losing the client would be a problem. The auditor feels pressure not to raise a major nonconformity.
- An auditee repeatedly challenges the auditor's qualifications, knowledge, or authority during the audit, attempting to undermine confidence and discourage the auditor from pursuing a line of inquiry.
None of these involve a direct instruction to falsify findings. But all of them create conditions where the auditor's independence is compromised. ISO 19011:2026 is asking audit programme managers to recognise these conditions and put structures in place to prevent them.
Why This Is Being Addressed in 2026
The explicit naming of undue influence in the 2026 edition reflects a broader maturation in how the auditing community thinks about audit integrity. Over many years of audit practice across industries and geographies, it became clear that technical competence alone does not guarantee a reliable audit. An auditor can know a standard inside out and still produce a compromised finding if the conditions around the audit are not properly managed.
The 2026 edition also reflects feedback from certification bodies, accreditation bodies, and audit programme managers who observed that existing guidance did not adequately address the social and organisational dynamics that shape audit outcomes. The result is a more honest acknowledgement that auditing is a human activity conducted in complex organisational environments, and that risk management must account for that reality.
Other Audit Programme Risks Addressed in ISO 19011:2026
Undue influence is the headline risk, but it is not the only one. The 2026 edition identifies a broader set of threats that audit programme managers need to consider.
Auditor Competence Gaps
The 2026 edition places greater emphasis on ensuring auditors have the right competence for the specific audit assignment, not just a general qualification. This includes technical knowledge of the processes being audited, familiarity with the industry context, and the personal attributes needed to conduct the audit effectively.
A risk to the audit programme arises when auditors are assigned to audits that exceed their competence. This can happen because of resource pressure, poor planning, or a lack of rigour in competence evaluation. The result is audit findings that miss the point, fail to identify real issues, or cannot be defended when challenged.
Clause 7 of ISO 19011:2026 covers auditor competence in detail. The connection between Clause 7 and the risk management requirements of Clause 5 is explicit: the audit programme manager is responsible for ensuring that auditor selection addresses competence risks, not just availability.
Conflicts of Interest
Conflicts of interest are closely related to undue influence but distinct from it. A conflict of interest exists when an auditor has a personal, financial, or professional stake in the outcome of the audit. Undue influence is what happens when someone exploits that conflict, or when external pressure creates a similar dynamic even without a formal conflict.
The 2026 edition requires that audit programme managers put mechanisms in place to identify and manage conflicts of interest before audit assignments are made. This includes asking auditors to declare any relationships, prior involvement, or interests that could affect their objectivity. It also means being willing to reassign auditors when a conflict is identified, even if that creates scheduling inconvenience.
Resource and Time Pressure
One of the most underappreciated risks to audit programme integrity is inadequate time and resources. When auditors are given insufficient time to conduct a thorough audit, the quality of findings suffers. Sampling becomes too narrow, interviews are rushed, and evidence review is superficial. The audit may technically comply with the programme schedule while producing findings that are essentially meaningless.
This is a systemic risk that audit programme managers often create unintentionally. Audit days are calculated based on certification body formulas or historical norms, but the actual complexity of the processes being audited may demand more time. The 2026 edition asks programme managers to consider this explicitly when planning audit activities.
Remote Auditing and Digital Evidence Risks
The growth of remote auditing since 2020 introduced a new category of risk that the 2018 edition of ISO 19011 was not designed to address. ISO 19011:2026 acknowledges this directly, and the associated technical specification ISO/IEC TS 17012 provides more detailed guidance on remote audit methods.
The risks specific to remote auditing include the inability to directly observe physical processes, the possibility that documents shared electronically have been selectively edited or staged, the difficulty of reading body language and social cues that might indicate evasion, and the potential for technical failures that disrupt audit flow and evidence gathering.
For more on how the 2026 edition handles remote auditing, the article Remote Auditing in ISO 19011:2026 and the Role of ISO/IEC TS 17012 covers this in detail.
Climate Change and Emerging Contextual Factors
The 2026 edition introduces a requirement to consider the effect of changing contexts on the audit programme. Climate change is specifically mentioned as an example. This might seem abstract at first, but it has practical implications. An organisation's environmental risks, legal obligations, and operational priorities can shift significantly as a result of climate related regulation, extreme weather events, or supply chain disruption. An audit programme that was designed for a stable context may not be fit for purpose in a rapidly changing one.
This connects to the broader principle of risk based audit scheduling, which the article Risk Based Audit Scheduling: Deciding What to Audit First addresses in practical terms.
What Audit Programme Managers Must Do Differently
Understanding the risks is only half the job. The 2026 edition expects audit programme managers to take concrete action. Here is what that looks like in practice.
Establish a Formal Risk Assessment for the Audit Programme
The audit programme itself should be subject to a risk assessment. This does not need to be a complex document, but it should systematically consider the threats identified above and the controls in place to manage them. Review this assessment at least annually, or whenever there is a significant change to the audit programme, the organisation, or the audit team.
Implement Auditor Independence Declarations
Every auditor should complete a written declaration of independence before each audit assignment. This declaration should cover personal relationships with auditees, prior involvement in the processes being audited, financial interests, and any other factors that could affect objectivity. The declaration should be reviewed by the audit programme manager, not just filed.
Separate Audit Planning from Operational Management
Where possible, the person responsible for the audit programme should be independent from the operational areas being audited. In large organisations this is straightforward. In small organisations it requires more creative thinking, perhaps using external auditors for high risk areas, rotating audit responsibilities, or using peer review of audit findings.
Set Clear Expectations About Auditor Conduct
Auditors need to understand what to do when they experience pressure. This means having a clear escalation path, knowing they can raise concerns without professional consequences, and understanding that the audit programme manager has a responsibility to support their independence. This is not just a training issue. It requires explicit organisational commitment.
Review Audit Findings for Patterns That Suggest Compromise
An audit programme that consistently produces clean results across high risk areas is a warning sign. Audit programme managers should periodically review findings for patterns that might indicate undue influence, competence gaps, or inadequate sampling. If a particular auditor never raises nonconformities, or if a particular area never receives findings despite known issues, that warrants investigation.
Document the Programme Objectives and Review Them
The 2026 edition strengthens the requirement to define objectives for the audit programme and to review whether those objectives are being achieved. This is not a bureaucratic exercise. It is the mechanism by which the audit programme manager can demonstrate that the programme is functioning as intended and that risks are being managed. The article Managing an Audit Programme Under Clause 5 of ISO 19011:2026 covers these requirements clause by clause.
Exemplar Global Recognised Training ProviderRTP No. 310970Implications for Internal Auditors and Lead Auditors
If you are an internal auditor, the risk management requirements of ISO 19011:2026 are primarily the responsibility of your audit programme manager. But that does not mean you have no role. You are responsible for your own conduct, for declaring conflicts of interest, and for raising concerns if you experience pressure that compromises your independence.
If you are a lead auditor conducting second or third party audits, the implications are more direct. You are responsible for the integrity of the audit team's work. That means setting expectations with team members about independence and conduct, managing the relationship with the audit client professionally, and being willing to push back when you experience pressure to soften or withdraw findings.
The principle of independence is not just an abstract value. It is what makes audit findings credible. An audit finding that was influenced by the auditee is not a finding. It is a negotiated outcome, and it serves no one well in the long run.
Training Implications for 2026 and Beyond
ISO 19011:2026 raises the bar for what audit programme managers and lead auditors need to know. Understanding the technical requirements of a standard is still essential, but it is not sufficient. Auditors now need to understand audit programme risk management, the dynamics of undue influence, and the practical tools for protecting audit integrity.
This is reflected in the competence requirements of Clause 7 of the 2026 edition, which places greater emphasis on personal attributes and professional behaviour alongside technical knowledge. If you are working towards lead auditor certification or looking to update your practice in line with the 2026 edition, training that covers these dimensions is worth prioritising.
At Audit Workshop, our lead auditor courses are built around real audit practice, not just standard text. Dilawar Laghari brings more than 14 years of compliance experience and over 500 external ISO certification audits to the training room, which means the scenarios and challenges covered in the programme reflect what actually happens on audit assignments, including the human dynamics that ISO 19011:2026 is now explicitly addressing. If you are ready to develop your audit programme management skills or prepare for lead auditor certification, explore the courses available at Audit Workshop.













