Why Remote Auditing Now Has a Formal Framework
Remote auditing did not begin with ISO 19011:2026. It was already happening in practice, accelerated by necessity during the pandemic years, and quietly embedded into audit programmes long before any standard formally addressed it. What ISO 19011:2026 does is give remote auditing a proper structural home, and point auditors and audit programme managers toward a companion technical specification, ISO/IEC TS 17012, that provides the operational detail the guidelines themselves do not carry.
On this page
If you are running an internal audit programme, working as a lead auditor for a certification body, or managing supplier audits across multiple sites, this matters directly to you. Remote auditing is no longer an improvised workaround. It is a recognised audit method with defined requirements, known limitations, and specific competence expectations for the people conducting it.
This article walks through what ISO 19011:2026 says about remote auditing, what ISO/IEC TS 17012 adds, and what both documents mean for how you plan and conduct audits in practice.
What ISO 19011:2026 Actually Says About Remote Auditing
The 2026 edition of ISO 19011 integrates remote auditing considerations throughout the audit programme and audit conduct guidance, rather than treating it as a special case buried in an annex. This is a deliberate shift from the 2018 edition, which acknowledged remote methods but gave them limited structural weight.
Remote Methods as a Standard Planning Consideration
Under Clause 5, which covers audit programme management, ISO 19011:2026 requires audit programme managers to consider the methods used to conduct audits as part of programme planning. Remote auditing, on-site auditing, and combinations of both are all treated as legitimate options. The decision about which method to use should be based on factors including the nature of the audit objectives, the complexity of the processes being audited, the availability of digital infrastructure, and the risk profile of the auditee.
This means audit programme managers can no longer default to on-site auditing simply out of habit. They need to make an active, documented decision about method, and that decision needs to be defensible against the criteria the programme has established.
Clause 6 and the Conduct of Remote Audits
Clause 6 of ISO 19011:2026, which covers the conduct of individual audits, includes specific considerations for remote methods. These touch on how audit plans are communicated, how evidence is collected, how interviews are conducted, and how the audit team maintains control of the audit when physical presence is absent.
One area that receives explicit attention is the opening and closing meeting. Even when conducted remotely, these meetings retain their function. They establish the audit scope and objectives, introduce the audit team, confirm logistics, and give the auditee an opportunity to raise concerns. Running them effectively via video conference requires the same preparation as an on-site meeting, and the same discipline to keep them focused and professional. Our article on running an effective opening meeting covers the structure in detail, and most of that guidance applies equally to remote delivery.
Audit Evidence and Remote Collection
Collecting audit evidence remotely introduces constraints that on-site auditors do not face. You cannot walk a production floor, observe a physical process, or pick up a document from a filing cabinet. ISO 19011:2026 acknowledges this directly. It notes that remote methods may limit the types of evidence available and that this limitation needs to be factored into audit planning and conclusions.
In practice, this means remote auditors rely more heavily on document review, screen sharing, video observation of processes, and interviews. The audit plan needs to account for these methods explicitly, and the audit team needs to be honest in the audit report about any limitations on evidence gathering that arose from the remote format. Our article on gathering audit evidence through sampling, interviews and document review covers the practical techniques that translate well to remote delivery.
Exemplar Global Recognised Training ProviderRTP No. 310970ISO/IEC TS 17012: The Technical Specification That Fills the Gaps
ISO/IEC TS 17012 is a technical specification developed specifically to address remote auditing in conformity assessment. It is not a management system standard, and it does not replace ISO 19011. Think of it as the operational manual that sits alongside the guidelines. Where ISO 19011:2026 tells you that remote auditing needs to be considered and planned appropriately, ISO/IEC TS 17012 tells you how to do it.
Scope and Purpose of ISO/IEC TS 17012
The technical specification applies to any organisation conducting audits or assessments remotely, including internal audit teams, second party auditors conducting supplier assessments, and third party certification bodies. Its scope is deliberately broad because remote auditing raises common challenges regardless of whether it is a first, second, or third party context.
The specification covers the planning of remote audits, the technology requirements, the competence of auditors conducting remote audits, information security considerations, and the communication of results. Each of these areas gets practical guidance that you can apply directly to your audit programme or individual audit plans.
Technology Requirements and Infrastructure
One of the most practical contributions of ISO/IEC TS 17012 is its treatment of technology. The specification requires that the technology used for remote auditing is fit for purpose, agreed upon in advance with the auditee, and tested before the audit begins. This sounds obvious, but in practice it is frequently handled poorly.
Common technology failures in remote audits include video platforms that drop out during interviews, screen sharing that cannot display documents at sufficient resolution, and audio quality that makes it impossible to conduct a proper interview. ISO/IEC TS 17012 pushes audit teams to treat technology as a critical audit resource, not an afterthought. Before a remote audit begins, the audit team should confirm platform compatibility, test connection quality, establish a backup communication method, and agree on how documents will be shared during the session.
Information Security in Remote Auditing
Remote auditing involves the transfer and review of potentially sensitive organisational information across digital channels. ISO/IEC TS 17012 gives this explicit attention. Audit teams need to consider how documents are shared, how interview recordings are handled if recordings are made, where audit working papers are stored, and how access to shared materials is controlled after the audit concludes.
For organisations that are themselves certified to ISO 27001, this is familiar territory. For others, it can be an area of genuine risk. An audit team that receives confidential supplier records via an unsecured file sharing link, reviews them on a personal device, and stores them in a personal cloud account is creating an information security problem. ISO/IEC TS 17012 requires these risks to be identified and managed as part of audit planning.
Auditor Competence for Remote Delivery
ISO/IEC TS 17012 makes clear that conducting a remote audit requires competencies beyond those needed for on-site auditing. An auditor who is highly effective in a face-to-face environment may struggle when the physical cues, environmental observations, and natural conversation flow of an on-site audit are removed.
The specific competencies the specification highlights include the ability to manage technology platforms during an audit, skill in conducting effective interviews via video, the ability to review and navigate documents efficiently in a shared screen environment, and the capacity to maintain auditee engagement across a remote session that can feel more formal and less natural than a site visit.
Audit programme managers evaluating auditor competence under Clause 7 of ISO 19011:2026 need to include remote delivery skills in that evaluation. An auditor who has only ever worked on-site should not be assigned a fully remote audit without preparation and, ideally, some supervised remote audit experience first.
Hybrid Auditing: The Practical Middle Ground
In practice, most audit programmes are moving toward hybrid approaches rather than purely remote or purely on-site models. A hybrid audit might involve a remote document review and planning session before an on-site visit, a combination of remote interviews with some staff and on-site observation of critical processes, or a remote closing meeting after an on-site audit day.
ISO 19011:2026 supports this approach. The standard does not prescribe a single method and actively encourages audit programme managers to select methods based on what will best achieve the audit objectives. Hybrid auditing allows teams to use remote methods where they are efficient and effective, while preserving on-site time for activities that genuinely require physical presence, such as process observation, facility inspection, and interviews with shop floor workers who are not comfortable on video.
When Remote Auditing Is Not Appropriate
It is worth being direct about the limitations. Remote auditing is not suitable for every situation. If the audit objectives include verifying physical conditions, observing a process that cannot be adequately captured on video, or assessing workplace culture through direct observation, then a remote audit will not deliver the same quality of evidence as an on-site visit.
ISO 19011:2026 and ISO/IEC TS 17012 both acknowledge these limitations. The guidance is not that remote auditing should replace on-site auditing, but that it should be used where it is appropriate and planned carefully when it is. An audit conclusion drawn from evidence gathered remotely needs to be honest about what was and was not verifiable through that method.
For certification bodies, this has practical consequences. Accreditation bodies have issued guidance on when remote audits are acceptable for certification purposes and when they are not. Audit programme managers working in that context need to be familiar with their accreditation body's position, not just the ISO documents.
Exemplar Global Recognised Training ProviderRTP No. 310970Practical Implications for Audit Programme Managers
If you manage an internal audit programme or oversee second party audits, the combined guidance from ISO 19011:2026 and ISO/IEC TS 17012 has several direct implications for how you run your programme.
Update Your Audit Programme Documentation
Your audit programme documentation should now explicitly address remote auditing as a method. This includes criteria for when remote methods will be used, technology standards that remote audits must meet, information security requirements for document handling, and competence requirements for auditors conducting remote audits. If your current programme documentation treats remote auditing as an exception that gets handled case by case, it needs updating.
Build Remote Audit Skills Into Your Team
Evaluate your internal auditors against the remote delivery competencies identified in ISO/IEC TS 17012. Where gaps exist, address them through training, supervised practice, or pairing less experienced remote auditors with more experienced team members for their first few remote assignments.
This is also worth considering when selecting external auditors for supplier assessments. Ask specifically about their experience with remote delivery and what technology platforms they are comfortable using. A lead auditor who has conducted hundreds of on-site audits but never run a remote session is not automatically competent for remote delivery.
Plan Remote Audits More Carefully Than On-Site Audits
Remote audits require more detailed upfront planning than on-site audits, not less. The logistics of technology, document sharing, interview scheduling, and backup arrangements all need to be confirmed before the audit begins. The audit plan for a remote audit should include the technology platform to be used, the process for sharing documents during the session, the schedule for each interview and its video link, and the contingency plan if technology fails.
Our article on planning an ISO audit step by step covers the planning process in detail, and most of that framework applies directly to remote audit planning with the addition of these technology considerations.
What This Means for Lead Auditor Training
The integration of remote auditing guidance into ISO 19011:2026, supported by ISO/IEC TS 17012, has direct implications for lead auditor training. Any lead auditor course that was developed against the 2018 edition of ISO 19011 and has not been updated will not cover these requirements adequately.
When evaluating a lead auditor course, look for content that addresses remote audit planning and conduct, technology management during audits, information security in remote delivery, and auditor competence evaluation for remote methods. These are not optional extras. They are now part of what a competent lead auditor needs to understand.
At Audit Workshop, our lead auditor courses are built around current ISO 19011:2026 guidance and include practical coverage of remote and hybrid audit delivery. Trainer Dilawar Laghari has conducted remote audits across multiple jurisdictions and brings that direct experience into the training, not just the theory from the standard. If you are looking to build or refresh your remote auditing skills alongside your lead auditor qualification, our courses cover both. You can explore the available training at auditworkshop.com.













