Why the Seventh Principle Changes How You Audit
Most auditors learn the seven principles of auditing early in their training. Integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach. These six are straightforward enough. But the seventh, the risk-based approach, is the one that separates auditors who tick boxes from auditors who actually add value.
On this page
ISO 19011:2018 introduced the risk-based approach as a formal auditing principle. The idea is that auditors should apply judgement throughout the audit process, directing attention and effort toward areas where the risks are highest and where findings are most likely to matter. It is not just about planning. It shapes how you allocate time on site, which processes you sample, which records you pull, and how deeply you probe.
This article unpacks what the risk-based approach actually means in practice, how it differs from risk-based thinking in the management system itself, and how to apply it when you are standing on a factory floor or sitting across from a department manager.
What the Risk-Based Approach to Auditing Actually Means
There is a common source of confusion worth clearing up immediately. ISO 9001, ISO 14001, and ISO 45001 all require organisations to apply risk-based thinking to their management systems. That is about how the organisation identifies and addresses risks to its own objectives. The risk-based approach to auditing is a different thing. It is about how the auditor designs and conducts the audit itself.
Put simply, it means you do not treat every process, every clause, and every department as equally important. You make deliberate choices about where to focus your limited audit time based on where the risks of missing something significant are highest.
ISO 19011 describes this as giving priority to matters of significance to the audit client, the auditee, and other interested parties. In practice, that means asking yourself before and during the audit: if something is going wrong here, what is the consequence? And if I only have an hour in this area, where am I most likely to find evidence of a real problem?
Risk in the Audit Programme
The risk-based approach starts before the audit even begins. When an audit programme manager is deciding which areas to audit, how often, and with what depth, those decisions should be driven by risk. A high-volume production process with a history of customer complaints warrants more frequent and thorough auditing than a stable administrative function with a clean track record.
For internal audit programmes, this means your annual audit schedule should not be a rotating roster that gives equal time to every department. It should reflect where the organisation faces the most significant risks to conformity, to its objectives, and to interested parties. If you are running an ISO 45001 system in a manufacturing environment, the shop floor and maintenance department need more attention than the accounts team.
You can read more about how to structure this kind of thinking in our article on risk-based audit scheduling.
Risk in Individual Audit Planning
At the individual audit level, the risk-based approach shapes how you write your audit plan. Before you arrive on site, you should be thinking about what the significant risks are for this particular audit scope. What processes are complex or variable? Where has the organisation struggled in the past? What external factors, regulatory changes, new contracts, recent incidents, could affect conformity?
This does not mean ignoring low-risk areas entirely. It means being proportionate. If you have four hours to audit a warehouse operation, you spend more time on goods inwards verification, stock control, and nonconforming product handling than you do on the office filing system.
Exemplar Global Recognised Training ProviderRTP No. 310970Applying the Risk-Based Approach on the Floor
Where most auditors struggle is translating this principle from a planning concept into something they actually do differently during the audit. Here is how it works in practice.
Following the Evidence, Not the Checklist
A checklist is a starting point, not a script. When you are working through a process and you notice something that does not add up, the risk-based approach tells you to follow that thread rather than move on to the next item on your list. The anomaly you just spotted is a signal. Something in that area carries risk. Pursue it.
For example, you are auditing a construction company under ISO 9001. You ask to see the inspection and test records for a recent project. The supervisor hands you a folder, but you notice the hold point sign-offs are all dated the same day, despite the work spanning three weeks. That is a risk signal. The risk-based approach says you stop, ask questions, and look more carefully. You do not move on to the next clause.
This connects directly to the evidence-based approach principle, but the risk-based approach adds the directional element. It is not just about gathering evidence. It is about gathering evidence in the right places.
Sampling Decisions
Every auditor has to make sampling decisions. You cannot review every record, interview every person, or observe every process. The risk-based approach gives you the framework for deciding what to sample.
Start with the highest-risk items. In a food manufacturing context, that might mean prioritising records related to critical control points over general housekeeping inspections. In an ISO 45001 audit, you focus your permit-to-work sampling on the highest-risk activities, confined space entry, working at heights, hot work, rather than spreading your sample evenly across all permit types.
When you find a nonconformity in your initial sample, the risk-based approach tells you to expand that sample. One missing calibration record might be a one-off. But if you check three more instruments and find two more gaps, you now have evidence of a systemic issue. That escalation of sampling in response to what you find is a direct application of risk-based thinking.
Prioritising Audit Time Across Processes
On a multi-process audit, you will almost always run short of time in some areas. The risk-based approach helps you decide where to cut and where to hold firm. If you are running behind schedule and need to trim something, you cut from the lower-risk areas, not the high-risk ones.
This requires you to have done your homework before the audit. You need to know, going in, which processes are critical to the organisation achieving its objectives and which are supporting functions. That knowledge comes from reviewing the context of the organisation, the risk register, previous audit findings, customer complaints, and any relevant performance data.
Risks and Opportunities: The Full Picture
The seventh principle is not only about risk. It also encompasses opportunities. This is where many auditors leave value on the table.
When you are auditing and you observe a process that is working well, perhaps better than the documented procedure describes, that is worth noting. Not as a nonconformity, but as a potential opportunity for improvement. Maybe this department has found a more effective way of doing something that could be applied elsewhere in the organisation.
The risk-based approach to auditing means you are alert to both ends of the spectrum. You are looking for evidence that things could go wrong, and you are also looking for evidence that things are going particularly right in ways that could benefit the broader system.
This is also relevant when you are auditing an organisation's own risk and opportunity management processes. Under ISO 9001 Clause 6.1, the organisation is required to determine risks and opportunities and plan actions to address them. When you audit this clause, you are not just checking whether a risk register exists. You are applying your own risk-based judgement to assess whether the organisation has identified the right risks, whether the actions are proportionate, and whether the system is genuinely working to address what matters most.
Our article on risk-based thinking with practical examples covers this from the management system perspective and is worth reading alongside this one.
Common Mistakes Auditors Make With This Principle
Understanding the principle is one thing. Applying it consistently under time pressure and with a defensive auditee in front of you is another. Here are the most common failures.
Treating All Areas as Equal
This is the checklist trap. You move through every item at the same pace, give equal time to every department, and end up with a superficial audit that misses the real issues. The risk-based approach requires you to make judgements and act on them. That takes confidence, but it is what separates a competent auditor from someone who is just going through the motions.
Failing to Adjust When the Evidence Changes
You planned your audit based on what you knew before you arrived. But audits surface new information. When the evidence you find on site suggests a higher risk than you anticipated, you need to adjust your plan. Sticking rigidly to the original plan when the evidence is telling you something different is a failure to apply the risk-based approach.
Ignoring Opportunities Entirely
Some auditors treat every audit as a search for nonconformities. The risk-based approach includes looking for opportunities. If you leave an audit without any observations or opportunities for improvement noted, you have probably not been looking hard enough, or you have been looking in the wrong places.
Not Documenting the Rationale
When you make a risk-based decision during an audit, such as expanding a sample or spending more time in one area, document why. Your working papers should reflect your reasoning. This is important for transparency and for demonstrating professional judgement. It also protects you if your decisions are ever questioned.
How This Principle Connects to the Others
The seven principles of auditing are not independent. The risk-based approach works alongside the others.
It supports due professional care by requiring you to exercise judgement rather than just follow a procedure. It reinforces the evidence-based approach by directing you toward the evidence that matters most. It connects to fair presentation by ensuring your audit findings reflect the actual risk profile of the organisation, not just a random sample of what you happened to look at.
It also shapes independence in a subtle way. An auditor who applies the risk-based approach is less likely to be steered by an auditee toward the easy, low-risk areas. You know where you need to look, and you go there regardless of whether it is convenient for the auditee.
If you want a full overview of how all seven principles fit together, our article on the seven principles of auditing covers each one in detail.
Exemplar Global Recognised Training ProviderRTP No. 310970Practical Steps to Build This Into Your Auditing
If you want to genuinely embed the risk-based approach into how you audit, here are some concrete actions.
- Before every audit: Review previous findings, customer complaints, incident data, and any available performance metrics. Build a risk picture before you arrive.
- In your audit plan: Allocate time proportionate to risk. Be explicit about which areas you consider high priority and why.
- During the opening meeting: Ask about recent changes, incidents, or challenges. These are real-time risk signals that should update your plan.
- On the floor: When something does not look right, follow it. Do not let the checklist pull you away from a genuine risk signal.
- In your sampling: Start with the highest-risk items. Expand your sample when you find problems. Reduce it when the evidence consistently shows conformity.
- In your report: Frame your findings in terms of risk and impact. A nonconformity that poses a significant risk to product safety or regulatory compliance should be described differently from a minor documentation gap.
Why This Matters for Your Development as an Auditor
The risk-based approach is ultimately about professional judgement. It is the principle that most clearly distinguishes an experienced auditor from a novice. A new auditor tends to audit what is in front of them. An experienced auditor audits what matters.
Developing this skill takes time and deliberate practice. Every audit is an opportunity to sharpen your risk radar. Over time, you start to recognise patterns. You know which industries tend to have problems in particular areas. You know which process types carry inherent risk. You know what a defensive response from an auditee often signals.
This is also why audit training that focuses on real-world scenarios and practical application is so valuable. Reading about the risk-based approach in a standard is useful. Practising it in a simulated audit environment, with feedback from an experienced lead auditor, is what actually builds the skill.
At Audit Workshop, all training at Internal Auditor and Lead Auditor level incorporates risk-based thinking into the practical exercises. You will not just learn what the principle says. You will practise applying it in the kinds of situations you will actually face on the job. Whether you are working toward your first internal auditor credential or building toward lead auditor certification, understanding and applying the seventh principle is one of the most important skills you can develop. Explore the ISO auditor career path to see how this skill develops across different levels of auditor certification.













